Vir Facebook prosim o pomoc
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Vir Facebook prosim o pomoc
Davam log z programu RIST, prosím o pomoc
Logfile of random's system information tool 1.09 (written by random/random)
Run by Daniela at 2011-08-01 20:10:18
Microsoft Windows 7 Ultimate
System drive C: has 62 GB (41%) free of 153 GB
Total RAM: 895 MB (29% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:10:34, on 1.8.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal
Running processes:
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Opera\opera.exe
C:\Program Files\trend micro\Daniela.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: (no name) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: IplexToALLPlayer - {DF925EF3-7A87-44E4-9CAF-8D7B280BF616} - C:\PROGRA~2\ALLPLA~1\Iplex\IPLEXT~1.DLL
O3 - Toolbar: (no name) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - (no file)
O3 - Toolbar: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [a-squared] "C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2guard.exe" /d=60
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [ALLUpdate] "C:\Program Files (x86)\ALLPlayer\ALLUpdate.exe" "sleep"
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files (x86)\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files (x86)\ICQ7.5\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\nwprovau.dll' missing
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Emsisoft Anti-Malware 5.1 - Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 8133 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=consrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=consrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe"
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files (x86)\Bonjour\mDNSResponder.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe"
C:\Windows\System32\tcpsvcs.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-ca79fd3c-69b4-47f8-8c28-26065dd174d1 -SystemEventPortName:HostProcess-7e88268a-e07b-4fd5-af39-3a3b95a0e41f -IoCancelEventPortName:HostProcess-01a7ffef-3fe6-4fb4-adf6-401074ef7e80 -NonStateChangingEventPortName:HostProcess-94188206-9cb2-455d-9caf-c79a3d8f0b3a -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:bcf85ecc-f29d-42e8-9898-6538929db81c
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Windows\system32\wuauclt.exe"
"C:\Program Files (x86)\Opera\opera.exe"
"C:\Users\Daniela\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Daniela\AppData\Roaming\Mozilla\Firefox\Profiles\db4lnk7y.default
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 9
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Users\Daniela\AppData\Roaming\Mozilla\Firefox\Profiles\db4lnk7y.default\extensions\
IplextoALL@ALLPlayer.org
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-07-04 978496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2011-07-31 75656]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-07-04 820864]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-07-31 42272]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DF925EF3-7A87-44E4-9CAF-8D7B280BF616}]
IplexToALLPlayer - C:\PROGRA~2\ALLPLA~1\Iplex\IPLEXT~1.DLL [2011-02-09 400384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17}
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-07-04 978496]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}
{30F9B915-B755-4826-820B-08FBA6BD249D}
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll [2010-11-21 1054520]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-07-04 820864]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"combofix"=C:\ComboFix\CF15101.cfxxe /c C:\ComboFix\Combobatch.bat []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ALLUpdate"=C:\Program Files (x86)\ALLPlayer\ALLUpdate.exe [2011-02-08 1362944]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"a-squared"=C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2guard.exe [2011-06-23 3321232]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-07-04 3493720]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2011-04-08 254696]
"Malwarebytes' Anti-Malware"=C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe [2011-07-06 449584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableSecureUIAPaths"=0
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"NoRun"=0
"NoDriveTypeAutoRun "=0
"NoViewContextMenu "=0
"NoDriveTypeAutoRun"=0
"NoViewContextMenu"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.inf - open - %SystemRoot%\SysWow64\NOTEPAD.EXE %1
.inf - install - %SystemRoot%\SysWow64\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - %SystemRoot%\SysWow64\WScript.exe "%1" %*
.vbs - open - %SystemRoot%\SysWow64\WScript.exe "%1" %*
.cpl - cplopen - %SystemRoot%\SysWow64\control.exe "%1",%*
======List of files/folders created in the last 1 month======
2011-08-01 19:48:45 ----D---- C:\Program Files (x86)\Super Klikacz
2011-08-01 19:47:44 ----A---- C:\Windows\SYSWOW64\libFLAC.dll
2011-08-01 19:47:34 ----D---- C:\Program Files (x86)\ALLPlayer
2011-08-01 19:33:11 ----D---- C:\Users\Daniela\AppData\Roaming\EurekaLog
2011-08-01 19:22:08 ----D---- C:\$RECYCLE.BIN
2011-08-01 19:01:39 ----A---- C:\Windows\zip.exe
2011-08-01 19:01:39 ----A---- C:\Windows\SWREG.exe
2011-08-01 19:01:39 ----A---- C:\Windows\PEV.exe
2011-08-01 19:01:39 ----A---- C:\Windows\NIRCMD.exe
2011-08-01 19:01:39 ----A---- C:\Windows\MBR.exe
2011-08-01 19:01:39 ----A---- C:\Windows\grep.exe
2011-08-01 19:01:38 ----A---- C:\Windows\SWSC.exe
2011-08-01 19:01:38 ----A---- C:\Windows\sed.exe
2011-08-01 19:01:14 ----D---- C:\Windows\ERDNT
2011-08-01 19:00:46 ----D---- C:\Qoobox
2011-08-01 19:00:17 ----SD---- C:\32788R22FWJFW
2011-08-01 18:38:41 ----D---- C:\Users\Daniela\AppData\Roaming\Malwarebytes
2011-08-01 18:38:29 ----A---- C:\Windows\SYSWOW64\drivers\mbamswissarmy.sys
2011-08-01 18:38:27 ----D---- C:\ProgramData\Malwarebytes
2011-08-01 18:38:23 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-08-01 18:38:23 ----A---- C:\Windows\system32\drivers\mbam.sys
2011-08-01 00:01:24 ----D---- C:\Program Files\trend micro
2011-08-01 00:01:22 ----D---- C:\rsit
2011-07-31 23:45:29 ----D---- C:\_OTL
2011-07-31 22:47:31 ----A---- C:\Windows\system32\javaws.exe
2011-07-31 22:47:31 ----A---- C:\Windows\system32\javaw.exe
2011-07-31 22:47:31 ----A---- C:\Windows\system32\java.exe
2011-07-31 22:47:31 ----A---- C:\Windows\system32\deployJava1.dll
2011-07-31 22:46:41 ----D---- C:\Program Files\Java
2011-07-31 18:53:04 ----D---- C:\Users\Daniela\AppData\Roaming\TrojanHunter
2011-07-31 16:30:25 ----D---- C:\ProgramData\TrojanHunter
2011-07-31 16:30:17 ----D---- C:\Program Files (x86)\TrojanHunter 5.3
2011-07-31 15:53:44 ----D---- C:\SDFix
2011-07-31 15:05:09 ----D---- C:\Spybot - Search & Destroy
2011-07-31 15:05:09 ----D---- C:\ProgramData\Spybot - Search & Destroy
2011-07-31 13:43:35 ----D---- C:\ProgramData\Sun
2011-07-31 13:43:00 ----A---- C:\Windows\SYSWOW64\javaws.exe
2011-07-31 13:43:00 ----A---- C:\Windows\SYSWOW64\javaw.exe
2011-07-31 13:43:00 ----A---- C:\Windows\SYSWOW64\deployJava1.dll
2011-07-31 13:42:59 ----A---- C:\Windows\SYSWOW64\java.exe
2011-07-31 13:41:39 ----D---- C:\Program Files (x86)\Java
2011-07-31 00:46:04 ----A---- C:\Windows\nsreg.dat
2011-07-31 00:45:32 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-07-30 23:42:07 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2011-07-30 23:42:06 ----A---- C:\Windows\system32\drivers\aswSP.sys
2011-07-30 23:41:56 ----A---- C:\Windows\system32\drivers\aswRdr.sys
2011-07-30 23:41:54 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2011-07-30 23:41:53 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2011-07-30 23:41:49 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2011-07-30 23:40:12 ----A---- C:\Windows\avastSS.scr
2011-07-30 23:40:05 ----A---- C:\Windows\SYSWOW64\aswBoot.exe
2011-07-30 16:12:13 ----D---- C:\Users\Daniela\AppData\Roaming\Opera
2011-07-30 16:11:05 ----D---- C:\Program Files (x86)\Opera
2011-07-30 14:40:04 ----D---- C:\ProgramData\AVAST Software
2011-07-30 14:40:03 ----D---- C:\Program Files\AVAST Software
2011-07-29 23:25:49 ----D---- C:\Program Files\GridinSoft Trojan Killer
2011-07-29 21:49:43 ----HD---- C:\Windows\AxInstSV
2011-07-28 19:58:02 ----D---- C:\ProgramData\Alwil Software
2011-07-28 19:29:39 ----A---- C:\index.ini
2011-07-27 22:35:05 ----D---- C:\Program Files (x86)\Emsisoft Anti-Malware
2011-07-22 11:06:55 ----D---- C:\Windows\ufa
2011-07-21 20:47:35 ----D---- C:\Windows\system64
2011-07-21 20:45:27 ----HD---- C:\Windows\update.tray-15-0-lnk
2011-07-21 20:45:27 ----HD---- C:\Windows\update.tray-15-0
2011-07-21 20:34:23 ----A---- C:\Windows\unrar.exe
2011-07-21 20:31:39 ----D---- C:\Windows\av_ico
2011-07-21 20:30:05 ----HD---- C:\Windows\update.tray-7-0-lnk
2011-07-21 20:30:05 ----HD---- C:\Windows\update.tray-7-0
2011-07-13 16:08:09 ----A---- C:\Windows\system32\KernelBase.dll
2011-07-13 16:07:59 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2011-07-13 16:07:54 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-07-13 16:07:53 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2011-07-13 16:07:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2011-07-13 16:07:33 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-07-13 16:07:33 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-07-13 16:07:33 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-13 16:07:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2011-07-13 16:07:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2011-07-13 16:07:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-07-13 16:07:32 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2011-07-13 16:07:32 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2011-07-13 16:07:32 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2011-07-13 16:07:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2011-07-13 16:07:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2011-07-13 16:07:31 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-07-13 16:07:31 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2011-07-13 16:07:31 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2011-07-13 16:07:30 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2011-07-13 16:07:30 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2011-07-13 16:07:30 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2011-07-13 16:07:30 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2011-07-13 16:07:30 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2011-07-13 16:07:30 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2011-07-13 16:07:30 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2011-07-13 16:07:29 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2011-07-13 16:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2011-07-13 16:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2011-07-13 16:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2011-07-13 16:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2011-07-13 16:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2011-07-13 16:07:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2011-07-13 16:07:25 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2011-07-13 16:07:25 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2011-07-13 16:07:25 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2011-07-13 16:07:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2011-07-13 16:07:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2011-07-13 16:07:24 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2011-07-13 16:07:23 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2011-07-13 16:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2011-07-13 16:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2011-07-13 16:07:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2011-07-13 16:07:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2011-07-13 16:07:22 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2011-07-13 16:07:22 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2011-07-13 16:07:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2011-07-13 16:07:21 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2011-07-13 16:07:20 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2011-07-13 16:07:20 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2011-07-13 16:07:19 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2011-07-13 16:07:19 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-13 16:07:19 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-07-13 16:07:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2011-07-13 16:07:17 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2011-07-13 16:07:17 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2011-07-13 16:07:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2011-07-13 16:07:16 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2011-07-13 16:06:29 ----A---- C:\Windows\system32\win32k.sys
2011-07-13 16:05:46 ----A---- C:\Windows\system32\kernel32.dll
2011-07-13 16:05:45 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2011-07-13 16:05:43 ----A---- C:\Windows\system32\wow64win.dll
2011-07-13 16:05:43 ----A---- C:\Windows\system32\winsrv.dll
2011-07-13 16:05:43 ----A---- C:\Windows\system32\conhost.exe
2011-07-13 16:05:36 ----A---- C:\Windows\SYSWOW64\setup16.exe
2011-07-13 16:05:36 ----A---- C:\Windows\system32\wow64.dll
2011-07-13 16:05:33 ----A---- C:\Windows\system32\ntvdm64.dll
2011-07-13 16:05:31 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2011-07-13 16:05:27 ----A---- C:\Windows\system32\wow64cpu.dll
2011-07-13 16:05:25 ----A---- C:\Windows\SYSWOW64\instnm.exe
2011-07-13 16:05:24 ----A---- C:\Windows\SYSWOW64\wow32.dll
2011-07-13 16:04:58 ----A---- C:\Windows\SYSWOW64\user.exe
======List of files/folders modified in the last 1 month======
2011-08-01 20:09:33 ----D---- C:\Windows\Temp
2011-08-01 19:48:45 ----RD---- C:\Program Files (x86)
2011-08-01 19:47:44 ----D---- C:\Windows\SysWOW64
2011-08-01 19:45:55 ----D---- C:\Windows\system32\config
2011-08-01 19:34:54 ----D---- C:\Windows
2011-08-01 19:33:38 ----D---- C:\Windows\system32\drivers
2011-08-01 19:23:10 ----A---- C:\Windows\system.ini
2011-08-01 19:22:45 ----D---- C:\Windows\Prefetch
2011-08-01 19:21:53 ----D---- C:\Windows\system32\drivers\etc
2011-08-01 19:09:49 ----D---- C:\Windows\SYSWOW64\drivers
2011-08-01 19:09:49 ----D---- C:\Windows\System32
2011-08-01 19:09:49 ----D---- C:\Windows\AppPatch
2011-08-01 19:09:46 ----D---- C:\Program Files\Common Files
2011-08-01 19:09:46 ----D---- C:\Program Files (x86)\Common Files
2011-08-01 18:38:27 ----D---- C:\ProgramData
2011-08-01 07:38:11 ----D---- C:\Windows\Tasks
2011-08-01 07:38:11 ----D---- C:\Windows\system32\wfp
2011-08-01 07:38:11 ----D---- C:\Windows\system32\DriverStore
2011-08-01 07:38:11 ----D---- C:\Windows\system32\CodeIntegrity
2011-08-01 07:38:11 ----D---- C:\Windows\system32\catroot2
2011-08-01 07:37:03 ----D---- C:\Windows\system32\wbem
2011-08-01 07:37:03 ----D---- C:\Windows\registration
2011-08-01 07:36:56 ----D---- C:\Windows\system32\Tasks
2011-08-01 00:01:24 ----RD---- C:\Program Files
2011-07-31 23:45:53 ----D---- C:\Program Files (x86)\ConduitEngine
2011-07-31 22:48:12 ----SHD---- C:\Windows\Installer
2011-07-31 22:46:31 ----SHD---- C:\System Volume Information
2011-07-31 21:48:57 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-07-31 21:48:56 ----D---- C:\Windows\inf
2011-07-31 14:12:53 ----D---- C:\Users\Daniela\AppData\Roaming\Skype
2011-07-31 14:06:08 ----D---- C:\ProgramData\Easybits GO
2011-07-31 14:05:57 ----D---- C:\Users\Daniela\AppData\Roaming\go
2011-07-31 09:21:11 ----D---- C:\ProgramData\PMB Files
2011-07-31 09:21:10 ----D---- C:\Program Files (x86)\ICQ7.5
2011-07-31 01:02:53 ----D---- C:\Windows\winsxs
2011-07-31 01:02:47 ----D---- C:\Windows\system32\en-US
2011-07-31 01:02:47 ----D---- C:\Windows\system32\cs-CZ
2011-07-31 00:49:27 ----D---- C:\Windows\system32\NDF
2011-07-31 00:46:13 ----D---- C:\Users\Daniela\AppData\Roaming\Mozilla
2011-07-30 23:34:27 ----D---- C:\Program Files\Internet Explorer
2011-07-30 23:34:27 ----D---- C:\Program Files (x86)\Internet Explorer
2011-07-30 12:54:40 ----D---- C:\Windows\system32\drivers\UMDF
2011-07-30 12:54:33 ----D---- C:\ProgramData\Adobe
2011-07-30 12:54:32 ----D---- C:\Program Files\Bonjour
2011-07-30 12:54:30 ----D---- C:\Program Files (x86)\Bonjour
2011-07-30 12:54:02 ----D---- C:\Windows\system32\catroot
2011-07-30 12:52:42 ----SD---- C:\Users\Daniela\AppData\Roaming\Microsoft
2011-07-30 12:52:36 ----SD---- C:\ProgramData\Microsoft
2011-07-30 03:40:48 ----RSD---- C:\Windows\assembly
2011-07-30 03:40:48 ----D---- C:\Windows\Microsoft.NET
2011-07-29 21:20:58 ----D---- C:\ProgramData\NVIDIA
2011-07-28 19:44:37 ----D---- C:\Users\Daniela\AppData\Roaming\uTorrent
2011-07-28 03:11:49 ----D---- C:\Windows\SYSWOW64\en-US
2011-07-28 03:11:14 ----D---- C:\Program Files (x86)\Microsoft.NET
2011-07-27 22:33:23 ----D---- C:\programy
2011-07-27 22:12:10 ----D---- C:\Windows\debug
2011-07-22 16:11:51 ----D---- C:\Users\Daniela\AppData\Roaming\ICQ
2011-07-21 21:15:10 ----D---- C:\Windows\Logs
2011-07-20 07:05:23 ----D---- C:\ProgramData\DAEMON Tools Lite
2011-07-13 16:24:28 ----A---- C:\Windows\system32\MRT.exe
2011-07-13 16:24:23 ----D---- C:\ProgramData\Microsoft Help
2011-07-04 13:43:42 ----A---- C:\Windows\system32\aswBoot.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 nvstor64;nvstor64; C:\Windows\system32\DRIVERS\nvstor64.sys [2009-06-22 240672]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-05-27 834544]
R1 a2injectiondriver;a2injectiondriver; \??\C:\Program Files (x86)\Emsisoft Anti-Malware\a2dix64.sys [2010-09-05 48216]
R1 a2util;a-squared Malware-IDS utility driver; \??\C:\Program Files (x86)\Emsisoft Anti-Malware\a2util64.sys [2010-05-05 14720]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-07-04 31064]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-07-04 600920]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-07-04 288088]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-07-04 45400]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-01-26 254528]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-07-04 22360]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-07-04 64856]
R3 a2acc;a2acc; \??\C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2accx64.sys [2011-02-20 85800]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 34152]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-08-04 1973792]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2011-07-06 25912]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2011-06-08 33344]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 TFsExDisk;TFsExDisk; \??\C:\Windows\System32\Drivers\TFsExDisk.sys []
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2011-02-18 51712]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 a2AntiMalware;Emsisoft Anti-Malware 5.1 - Service; C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe [2011-06-30 3029208]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2011-02-18 37664]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-07-04 42184]
R2 Bonjour Service;Bonjour Service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2010-10-07 345376]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ICQ Service;ICQ Service; C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe [2010-11-21 247608]
R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-07-06 366640]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-09-27 383592]
R2 simptcp;@%SystemRoot%\system32\simptcp.dll,-200; C:\Windows\System32\tcpsvcs.exe [2009-07-14 10240]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-10-16 136176]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-10-16 136176]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2011-03-07 934176]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-05-27 1255736]
-----------------EOF-----------------
Logfile of random's system information tool 1.09 (written by random/random)
Run by Daniela at 2011-08-01 20:10:18
Microsoft Windows 7 Ultimate
System drive C: has 62 GB (41%) free of 153 GB
Total RAM: 895 MB (29% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:10:34, on 1.8.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal
Running processes:
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Opera\opera.exe
C:\Program Files\trend micro\Daniela.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: (no name) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: IplexToALLPlayer - {DF925EF3-7A87-44E4-9CAF-8D7B280BF616} - C:\PROGRA~2\ALLPLA~1\Iplex\IPLEXT~1.DLL
O3 - Toolbar: (no name) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - (no file)
O3 - Toolbar: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [a-squared] "C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2guard.exe" /d=60
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [ALLUpdate] "C:\Program Files (x86)\ALLPlayer\ALLUpdate.exe" "sleep"
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files (x86)\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files (x86)\ICQ7.5\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\nwprovau.dll' missing
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Emsisoft Anti-Malware 5.1 - Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 8133 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=consrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=consrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe"
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files (x86)\Bonjour\mDNSResponder.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe"
C:\Windows\System32\tcpsvcs.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-ca79fd3c-69b4-47f8-8c28-26065dd174d1 -SystemEventPortName:HostProcess-7e88268a-e07b-4fd5-af39-3a3b95a0e41f -IoCancelEventPortName:HostProcess-01a7ffef-3fe6-4fb4-adf6-401074ef7e80 -NonStateChangingEventPortName:HostProcess-94188206-9cb2-455d-9caf-c79a3d8f0b3a -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:bcf85ecc-f29d-42e8-9898-6538929db81c
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Windows\system32\wuauclt.exe"
"C:\Program Files (x86)\Opera\opera.exe"
"C:\Users\Daniela\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Daniela\AppData\Roaming\Mozilla\Firefox\Profiles\db4lnk7y.default
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 9
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Users\Daniela\AppData\Roaming\Mozilla\Firefox\Profiles\db4lnk7y.default\extensions\
IplextoALL@ALLPlayer.org
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-07-04 978496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2011-07-31 75656]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-07-04 820864]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-07-31 42272]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DF925EF3-7A87-44E4-9CAF-8D7B280BF616}]
IplexToALLPlayer - C:\PROGRA~2\ALLPLA~1\Iplex\IPLEXT~1.DLL [2011-02-09 400384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17}
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-07-04 978496]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}
{30F9B915-B755-4826-820B-08FBA6BD249D}
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll [2010-11-21 1054520]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-07-04 820864]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"combofix"=C:\ComboFix\CF15101.cfxxe /c C:\ComboFix\Combobatch.bat []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ALLUpdate"=C:\Program Files (x86)\ALLPlayer\ALLUpdate.exe [2011-02-08 1362944]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"a-squared"=C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2guard.exe [2011-06-23 3321232]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-07-04 3493720]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2011-04-08 254696]
"Malwarebytes' Anti-Malware"=C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe [2011-07-06 449584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableSecureUIAPaths"=0
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"NoRun"=0
"NoDriveTypeAutoRun "=0
"NoViewContextMenu "=0
"NoDriveTypeAutoRun"=0
"NoViewContextMenu"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.inf - open - %SystemRoot%\SysWow64\NOTEPAD.EXE %1
.inf - install - %SystemRoot%\SysWow64\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - %SystemRoot%\SysWow64\WScript.exe "%1" %*
.vbs - open - %SystemRoot%\SysWow64\WScript.exe "%1" %*
.cpl - cplopen - %SystemRoot%\SysWow64\control.exe "%1",%*
======List of files/folders created in the last 1 month======
2011-08-01 19:48:45 ----D---- C:\Program Files (x86)\Super Klikacz
2011-08-01 19:47:44 ----A---- C:\Windows\SYSWOW64\libFLAC.dll
2011-08-01 19:47:34 ----D---- C:\Program Files (x86)\ALLPlayer
2011-08-01 19:33:11 ----D---- C:\Users\Daniela\AppData\Roaming\EurekaLog
2011-08-01 19:22:08 ----D---- C:\$RECYCLE.BIN
2011-08-01 19:01:39 ----A---- C:\Windows\zip.exe
2011-08-01 19:01:39 ----A---- C:\Windows\SWREG.exe
2011-08-01 19:01:39 ----A---- C:\Windows\PEV.exe
2011-08-01 19:01:39 ----A---- C:\Windows\NIRCMD.exe
2011-08-01 19:01:39 ----A---- C:\Windows\MBR.exe
2011-08-01 19:01:39 ----A---- C:\Windows\grep.exe
2011-08-01 19:01:38 ----A---- C:\Windows\SWSC.exe
2011-08-01 19:01:38 ----A---- C:\Windows\sed.exe
2011-08-01 19:01:14 ----D---- C:\Windows\ERDNT
2011-08-01 19:00:46 ----D---- C:\Qoobox
2011-08-01 19:00:17 ----SD---- C:\32788R22FWJFW
2011-08-01 18:38:41 ----D---- C:\Users\Daniela\AppData\Roaming\Malwarebytes
2011-08-01 18:38:29 ----A---- C:\Windows\SYSWOW64\drivers\mbamswissarmy.sys
2011-08-01 18:38:27 ----D---- C:\ProgramData\Malwarebytes
2011-08-01 18:38:23 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-08-01 18:38:23 ----A---- C:\Windows\system32\drivers\mbam.sys
2011-08-01 00:01:24 ----D---- C:\Program Files\trend micro
2011-08-01 00:01:22 ----D---- C:\rsit
2011-07-31 23:45:29 ----D---- C:\_OTL
2011-07-31 22:47:31 ----A---- C:\Windows\system32\javaws.exe
2011-07-31 22:47:31 ----A---- C:\Windows\system32\javaw.exe
2011-07-31 22:47:31 ----A---- C:\Windows\system32\java.exe
2011-07-31 22:47:31 ----A---- C:\Windows\system32\deployJava1.dll
2011-07-31 22:46:41 ----D---- C:\Program Files\Java
2011-07-31 18:53:04 ----D---- C:\Users\Daniela\AppData\Roaming\TrojanHunter
2011-07-31 16:30:25 ----D---- C:\ProgramData\TrojanHunter
2011-07-31 16:30:17 ----D---- C:\Program Files (x86)\TrojanHunter 5.3
2011-07-31 15:53:44 ----D---- C:\SDFix
2011-07-31 15:05:09 ----D---- C:\Spybot - Search & Destroy
2011-07-31 15:05:09 ----D---- C:\ProgramData\Spybot - Search & Destroy
2011-07-31 13:43:35 ----D---- C:\ProgramData\Sun
2011-07-31 13:43:00 ----A---- C:\Windows\SYSWOW64\javaws.exe
2011-07-31 13:43:00 ----A---- C:\Windows\SYSWOW64\javaw.exe
2011-07-31 13:43:00 ----A---- C:\Windows\SYSWOW64\deployJava1.dll
2011-07-31 13:42:59 ----A---- C:\Windows\SYSWOW64\java.exe
2011-07-31 13:41:39 ----D---- C:\Program Files (x86)\Java
2011-07-31 00:46:04 ----A---- C:\Windows\nsreg.dat
2011-07-31 00:45:32 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-07-30 23:42:07 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2011-07-30 23:42:06 ----A---- C:\Windows\system32\drivers\aswSP.sys
2011-07-30 23:41:56 ----A---- C:\Windows\system32\drivers\aswRdr.sys
2011-07-30 23:41:54 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2011-07-30 23:41:53 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2011-07-30 23:41:49 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2011-07-30 23:40:12 ----A---- C:\Windows\avastSS.scr
2011-07-30 23:40:05 ----A---- C:\Windows\SYSWOW64\aswBoot.exe
2011-07-30 16:12:13 ----D---- C:\Users\Daniela\AppData\Roaming\Opera
2011-07-30 16:11:05 ----D---- C:\Program Files (x86)\Opera
2011-07-30 14:40:04 ----D---- C:\ProgramData\AVAST Software
2011-07-30 14:40:03 ----D---- C:\Program Files\AVAST Software
2011-07-29 23:25:49 ----D---- C:\Program Files\GridinSoft Trojan Killer
2011-07-29 21:49:43 ----HD---- C:\Windows\AxInstSV
2011-07-28 19:58:02 ----D---- C:\ProgramData\Alwil Software
2011-07-28 19:29:39 ----A---- C:\index.ini
2011-07-27 22:35:05 ----D---- C:\Program Files (x86)\Emsisoft Anti-Malware
2011-07-22 11:06:55 ----D---- C:\Windows\ufa
2011-07-21 20:47:35 ----D---- C:\Windows\system64
2011-07-21 20:45:27 ----HD---- C:\Windows\update.tray-15-0-lnk
2011-07-21 20:45:27 ----HD---- C:\Windows\update.tray-15-0
2011-07-21 20:34:23 ----A---- C:\Windows\unrar.exe
2011-07-21 20:31:39 ----D---- C:\Windows\av_ico
2011-07-21 20:30:05 ----HD---- C:\Windows\update.tray-7-0-lnk
2011-07-21 20:30:05 ----HD---- C:\Windows\update.tray-7-0
2011-07-13 16:08:09 ----A---- C:\Windows\system32\KernelBase.dll
2011-07-13 16:07:59 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2011-07-13 16:07:54 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-07-13 16:07:53 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2011-07-13 16:07:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2011-07-13 16:07:33 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-07-13 16:07:33 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-07-13 16:07:33 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-13 16:07:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2011-07-13 16:07:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2011-07-13 16:07:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-07-13 16:07:32 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2011-07-13 16:07:32 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2011-07-13 16:07:32 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2011-07-13 16:07:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2011-07-13 16:07:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2011-07-13 16:07:31 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-07-13 16:07:31 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2011-07-13 16:07:31 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2011-07-13 16:07:30 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2011-07-13 16:07:30 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2011-07-13 16:07:30 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2011-07-13 16:07:30 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2011-07-13 16:07:30 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2011-07-13 16:07:30 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2011-07-13 16:07:30 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2011-07-13 16:07:29 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2011-07-13 16:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2011-07-13 16:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2011-07-13 16:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2011-07-13 16:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2011-07-13 16:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2011-07-13 16:07:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2011-07-13 16:07:25 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2011-07-13 16:07:25 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2011-07-13 16:07:25 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2011-07-13 16:07:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2011-07-13 16:07:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2011-07-13 16:07:24 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2011-07-13 16:07:23 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2011-07-13 16:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2011-07-13 16:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2011-07-13 16:07:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2011-07-13 16:07:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2011-07-13 16:07:22 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2011-07-13 16:07:22 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2011-07-13 16:07:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2011-07-13 16:07:21 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2011-07-13 16:07:20 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2011-07-13 16:07:20 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2011-07-13 16:07:19 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2011-07-13 16:07:19 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-13 16:07:19 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-07-13 16:07:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2011-07-13 16:07:17 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2011-07-13 16:07:17 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2011-07-13 16:07:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2011-07-13 16:07:16 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2011-07-13 16:06:29 ----A---- C:\Windows\system32\win32k.sys
2011-07-13 16:05:46 ----A---- C:\Windows\system32\kernel32.dll
2011-07-13 16:05:45 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2011-07-13 16:05:43 ----A---- C:\Windows\system32\wow64win.dll
2011-07-13 16:05:43 ----A---- C:\Windows\system32\winsrv.dll
2011-07-13 16:05:43 ----A---- C:\Windows\system32\conhost.exe
2011-07-13 16:05:36 ----A---- C:\Windows\SYSWOW64\setup16.exe
2011-07-13 16:05:36 ----A---- C:\Windows\system32\wow64.dll
2011-07-13 16:05:33 ----A---- C:\Windows\system32\ntvdm64.dll
2011-07-13 16:05:31 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2011-07-13 16:05:27 ----A---- C:\Windows\system32\wow64cpu.dll
2011-07-13 16:05:25 ----A---- C:\Windows\SYSWOW64\instnm.exe
2011-07-13 16:05:24 ----A---- C:\Windows\SYSWOW64\wow32.dll
2011-07-13 16:04:58 ----A---- C:\Windows\SYSWOW64\user.exe
======List of files/folders modified in the last 1 month======
2011-08-01 20:09:33 ----D---- C:\Windows\Temp
2011-08-01 19:48:45 ----RD---- C:\Program Files (x86)
2011-08-01 19:47:44 ----D---- C:\Windows\SysWOW64
2011-08-01 19:45:55 ----D---- C:\Windows\system32\config
2011-08-01 19:34:54 ----D---- C:\Windows
2011-08-01 19:33:38 ----D---- C:\Windows\system32\drivers
2011-08-01 19:23:10 ----A---- C:\Windows\system.ini
2011-08-01 19:22:45 ----D---- C:\Windows\Prefetch
2011-08-01 19:21:53 ----D---- C:\Windows\system32\drivers\etc
2011-08-01 19:09:49 ----D---- C:\Windows\SYSWOW64\drivers
2011-08-01 19:09:49 ----D---- C:\Windows\System32
2011-08-01 19:09:49 ----D---- C:\Windows\AppPatch
2011-08-01 19:09:46 ----D---- C:\Program Files\Common Files
2011-08-01 19:09:46 ----D---- C:\Program Files (x86)\Common Files
2011-08-01 18:38:27 ----D---- C:\ProgramData
2011-08-01 07:38:11 ----D---- C:\Windows\Tasks
2011-08-01 07:38:11 ----D---- C:\Windows\system32\wfp
2011-08-01 07:38:11 ----D---- C:\Windows\system32\DriverStore
2011-08-01 07:38:11 ----D---- C:\Windows\system32\CodeIntegrity
2011-08-01 07:38:11 ----D---- C:\Windows\system32\catroot2
2011-08-01 07:37:03 ----D---- C:\Windows\system32\wbem
2011-08-01 07:37:03 ----D---- C:\Windows\registration
2011-08-01 07:36:56 ----D---- C:\Windows\system32\Tasks
2011-08-01 00:01:24 ----RD---- C:\Program Files
2011-07-31 23:45:53 ----D---- C:\Program Files (x86)\ConduitEngine
2011-07-31 22:48:12 ----SHD---- C:\Windows\Installer
2011-07-31 22:46:31 ----SHD---- C:\System Volume Information
2011-07-31 21:48:57 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-07-31 21:48:56 ----D---- C:\Windows\inf
2011-07-31 14:12:53 ----D---- C:\Users\Daniela\AppData\Roaming\Skype
2011-07-31 14:06:08 ----D---- C:\ProgramData\Easybits GO
2011-07-31 14:05:57 ----D---- C:\Users\Daniela\AppData\Roaming\go
2011-07-31 09:21:11 ----D---- C:\ProgramData\PMB Files
2011-07-31 09:21:10 ----D---- C:\Program Files (x86)\ICQ7.5
2011-07-31 01:02:53 ----D---- C:\Windows\winsxs
2011-07-31 01:02:47 ----D---- C:\Windows\system32\en-US
2011-07-31 01:02:47 ----D---- C:\Windows\system32\cs-CZ
2011-07-31 00:49:27 ----D---- C:\Windows\system32\NDF
2011-07-31 00:46:13 ----D---- C:\Users\Daniela\AppData\Roaming\Mozilla
2011-07-30 23:34:27 ----D---- C:\Program Files\Internet Explorer
2011-07-30 23:34:27 ----D---- C:\Program Files (x86)\Internet Explorer
2011-07-30 12:54:40 ----D---- C:\Windows\system32\drivers\UMDF
2011-07-30 12:54:33 ----D---- C:\ProgramData\Adobe
2011-07-30 12:54:32 ----D---- C:\Program Files\Bonjour
2011-07-30 12:54:30 ----D---- C:\Program Files (x86)\Bonjour
2011-07-30 12:54:02 ----D---- C:\Windows\system32\catroot
2011-07-30 12:52:42 ----SD---- C:\Users\Daniela\AppData\Roaming\Microsoft
2011-07-30 12:52:36 ----SD---- C:\ProgramData\Microsoft
2011-07-30 03:40:48 ----RSD---- C:\Windows\assembly
2011-07-30 03:40:48 ----D---- C:\Windows\Microsoft.NET
2011-07-29 21:20:58 ----D---- C:\ProgramData\NVIDIA
2011-07-28 19:44:37 ----D---- C:\Users\Daniela\AppData\Roaming\uTorrent
2011-07-28 03:11:49 ----D---- C:\Windows\SYSWOW64\en-US
2011-07-28 03:11:14 ----D---- C:\Program Files (x86)\Microsoft.NET
2011-07-27 22:33:23 ----D---- C:\programy
2011-07-27 22:12:10 ----D---- C:\Windows\debug
2011-07-22 16:11:51 ----D---- C:\Users\Daniela\AppData\Roaming\ICQ
2011-07-21 21:15:10 ----D---- C:\Windows\Logs
2011-07-20 07:05:23 ----D---- C:\ProgramData\DAEMON Tools Lite
2011-07-13 16:24:28 ----A---- C:\Windows\system32\MRT.exe
2011-07-13 16:24:23 ----D---- C:\ProgramData\Microsoft Help
2011-07-04 13:43:42 ----A---- C:\Windows\system32\aswBoot.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 nvstor64;nvstor64; C:\Windows\system32\DRIVERS\nvstor64.sys [2009-06-22 240672]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-05-27 834544]
R1 a2injectiondriver;a2injectiondriver; \??\C:\Program Files (x86)\Emsisoft Anti-Malware\a2dix64.sys [2010-09-05 48216]
R1 a2util;a-squared Malware-IDS utility driver; \??\C:\Program Files (x86)\Emsisoft Anti-Malware\a2util64.sys [2010-05-05 14720]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-07-04 31064]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-07-04 600920]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-07-04 288088]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-07-04 45400]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-01-26 254528]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-07-04 22360]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-07-04 64856]
R3 a2acc;a2acc; \??\C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2accx64.sys [2011-02-20 85800]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 34152]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-08-04 1973792]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2011-07-06 25912]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2011-06-08 33344]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 TFsExDisk;TFsExDisk; \??\C:\Windows\System32\Drivers\TFsExDisk.sys []
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2011-02-18 51712]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 a2AntiMalware;Emsisoft Anti-Malware 5.1 - Service; C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe [2011-06-30 3029208]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2011-02-18 37664]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-07-04 42184]
R2 Bonjour Service;Bonjour Service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2010-10-07 345376]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ICQ Service;ICQ Service; C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe [2010-11-21 247608]
R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-07-06 366640]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-09-27 383592]
R2 simptcp;@%SystemRoot%\system32\simptcp.dll,-200; C:\Windows\System32\tcpsvcs.exe [2009-07-14 10240]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-10-16 136176]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-10-16 136176]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2011-03-07 934176]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-05-27 1255736]
-----------------EOF-----------------
Re: Vir Facebook prosim o pomoc
Zdravim a pekny vecer preji
vy umite aplikovat ComboFix, lustit jeho log a nasledne jej i docistit pomoci skriptu - asi moc ne, kdyz tam mate stale havet. A to se CF pouzivat jen na doporuceni - vizte nize
Nebezpeci CFka
vidim nainstalovany MBAM - delal jste sken 
- Je urcen primarne pro radce - jeho svevolnym pouzitim ztracite narok na podporu
- Maze stopy po haveti, takze v logu z RSIT neni nic videt
- Jeho log je treba dolustit, jelikoz neumi smazat vse - to ovsem tezko zvladnete pokud k tomu nejste vyskolen
- CF muze mit bug = sunda Vam system, pokud nevite kam co uklada, jak co obnovit, mate system v kytkam a ceka Vas reinstal
- CF taky bohuzel prozatim nekontroluje nektere dulezite knihovny (napr. hal.dll) - ty treba mazou nektere typy haveti (napr. angela) - smaze Vam po restartu hal.dll = nenajede Vam system a jste o radek vyse = reinstal
Re: Vir Facebook prosim o pomoc
Skan MBAM-prominte ze v Polštině
Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org
Wersja bazy: 7346
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
1.8.2011 23:32:42
mbam-log-2011-08-01 (23-32-42).txt
Typ skanowania: Szybkie skanowanie
Przeskanowano obiektów: 168266
Upłynęło: 5 minut(y), 9 sekund(y)
Zainfekowanych procesów w pamięci: 0
Zainfekowanych modułów w pamięci: 0
Zainfekowanych kluczy rejestru: 0
Zainfekowanych wartości rejestru: 0
Zainfekowane informacje rejestru systemowego: 0
Zainfekowanych folderów: 0
Zainfekowanych plików: 0
Zainfekowanych procesów w pamięci:
(Nie znaleziono zagrożeń)
Zainfekowanych modułów w pamięci:
(Nie znaleziono zagrożeń)
Zainfekowanych kluczy rejestru:
(Nie znaleziono zagrożeń)
Zainfekowanych wartości rejestru:
(Nie znaleziono zagrożeń)
Zainfekowane informacje rejestru systemowego:
(Nie znaleziono zagrożeń)
Zainfekowanych folderów:
(Nie znaleziono zagrożeń)
Zainfekowanych plików:
(Nie znaleziono zagrożeń)
Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org
Wersja bazy: 7346
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
1.8.2011 23:32:42
mbam-log-2011-08-01 (23-32-42).txt
Typ skanowania: Szybkie skanowanie
Przeskanowano obiektów: 168266
Upłynęło: 5 minut(y), 9 sekund(y)
Zainfekowanych procesów w pamięci: 0
Zainfekowanych modułów w pamięci: 0
Zainfekowanych kluczy rejestru: 0
Zainfekowanych wartości rejestru: 0
Zainfekowane informacje rejestru systemowego: 0
Zainfekowanych folderów: 0
Zainfekowanych plików: 0
Zainfekowanych procesów w pamięci:
(Nie znaleziono zagrożeń)
Zainfekowanych modułów w pamięci:
(Nie znaleziono zagrożeń)
Zainfekowanych kluczy rejestru:
(Nie znaleziono zagrożeń)
Zainfekowanych wartości rejestru:
(Nie znaleziono zagrożeń)
Zainfekowane informacje rejestru systemowego:
(Nie znaleziono zagrożeń)
Zainfekowanych folderów:
(Nie znaleziono zagrożeń)
Zainfekowanych plików:
(Nie znaleziono zagrożeń)
Re: Vir Facebook prosim o pomoc
Jen takovy skromny dotaz - proc v polstine
A co muj dotaz ohledne ComboFixu
A co muj dotaz ohledne ComboFixu
Re: Vir Facebook prosim o pomoc
Proč v Polštině ? Protoře kamarad je z Polska .
S CF moc to neumime proto se radime na tak dobrem forum.
A co byste nam poradil že mame udělat teď.
Děkuji Seboš.
S CF moc to neumime proto se radime na tak dobrem forum.
A co byste nam poradil že mame udělat teď.
Děkuji Seboš.
Re: Vir Facebook prosim o pomoc
- Ukoncete vsechny programy
- Pokud pouzivate Win Vista ci W7, kliknete na RogueKiller pravym a dejte Run As Administrator ci Spustit jako spravce
- Zvolte moznost 2 a potvrte enterem
- Utilita provede svou cinnost a da log - ten sem vlozte
- Nyni znovu, ale zvolte moznost 3 a pote jeste 4 - logy opet vlozte
Re: Vir Facebook prosim o pomoc
Cau. Tak jsem stahl Rouerkiller. Chcu ho spustit jako spravce, ale napise mi to ze neni pltatna aplikace win32 prosim o pomoc dik.
Re: Vir Facebook prosim o pomoc
Ani obycejne dvojklikem spustit nejde
Prejmenujte jej na cokoliv.com
Re: Vir Facebook prosim o pomoc
RogueKiller V5.3.0 [08/01/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html
Operating System: Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User: Daniela [Admin rights]
Mode: Remove -- Date : 08/03/2011 22:14:48
Bad processes: 0
Registry Entries: 12
[BLACKLIST] HKLM\[...]\services : srvbtcclient (C:\Windows\update.5.0\svchost.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : srviecheck (C:\Windows\update.2\svchost.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : srvsysdriver32 (C:\Windows\sysdriver32.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : wxpdrivers (C:\Windows\update.1\svchost.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : srvbtcclient (C:\Windows\update.5.0\svchost.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : srviecheck (C:\Windows\update.2\svchost.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : srvsysdriver32 (C:\Windows\sysdriver32.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : wxpdrivers (C:\Windows\update.1\svchost.exe srv) -> DELETED
[SUSP PATH] {71F8F1D0-91AB-4707-938B-39A7381231D6}.job : c:\users\daniela\desktop\setup_av_free.exe -> DELETED
[SUSP PATH] {BFF0FB28-3C03-401D-BF8D-77E02C399FAC}.job : c:\users\daniela\desktop\roguekiller.exe -> DELETED
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
HOSTS File:
127.0.0.1 localhost
127.0.0.1 vkontakte.ru
127.0.0.1 www.vkontakte.ru
127.0.0.1 login.vk.com
127.0.0.1 vk.com
127.0.0.1 www.vk.com
127.0.0.1 odnoklassniki.ru
127.0.0.1 www.odnoklassniki.ru
127.0.0.1 facebook.com
127.0.0.1 www.facebook.com
127.0.0.1 af-za.facebook.com
127.0.0.1 az-az.facebook.com
127.0.0.1 id-id.facebook.com
127.0.0.1 ms-my.facebook.com
127.0.0.1 bs-ba.facebook.com
127.0.0.1 ca-es.facebook.com
127.0.0.1 cs-cz.facebook.com
127.0.0.1 cy-gb.facebook.com
127.0.0.1 da-dk.facebook.com
127.0.0.1 de-de.facebook.com
[...]
Finished : << RKreport[1].txt >>
RKreport[1].txt
RogueKiller V5.3.0 [08/01/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html
Operating System: Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User: Daniela [Admin rights]
Mode: HOSTSFix -- Date : 08/03/2011 22:18:24
Bad processes: 0
HOSTS File:
127.0.0.1 localhost
127.0.0.1 vkontakte.ru
127.0.0.1 www.vkontakte.ru
127.0.0.1 login.vk.com
127.0.0.1 vk.com
127.0.0.1 www.vk.com
127.0.0.1 odnoklassniki.ru
127.0.0.1 www.odnoklassniki.ru
127.0.0.1 facebook.com
127.0.0.1 www.facebook.com
127.0.0.1 af-za.facebook.com
127.0.0.1 az-az.facebook.com
127.0.0.1 id-id.facebook.com
127.0.0.1 ms-my.facebook.com
127.0.0.1 bs-ba.facebook.com
127.0.0.1 ca-es.facebook.com
127.0.0.1 cs-cz.facebook.com
127.0.0.1 cy-gb.facebook.com
127.0.0.1 da-dk.facebook.com
127.0.0.1 de-de.facebook.com
[...]
Resetted HOSTS:
127.0.0.1 localhost
Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
RogueKiller V5.3.0 [08/01/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html
Operating System: Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User: Daniela [Admin rights]
Mode: ProxyFix -- Date : 08/03/2011 22:19:36
Bad processes: 0
Registry Entries: 0
Finished : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html
Operating System: Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User: Daniela [Admin rights]
Mode: Remove -- Date : 08/03/2011 22:14:48
Bad processes: 0
Registry Entries: 12
[BLACKLIST] HKLM\[...]\services : srvbtcclient (C:\Windows\update.5.0\svchost.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : srviecheck (C:\Windows\update.2\svchost.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : srvsysdriver32 (C:\Windows\sysdriver32.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : wxpdrivers (C:\Windows\update.1\svchost.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : srvbtcclient (C:\Windows\update.5.0\svchost.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : srviecheck (C:\Windows\update.2\svchost.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : srvsysdriver32 (C:\Windows\sysdriver32.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : wxpdrivers (C:\Windows\update.1\svchost.exe srv) -> DELETED
[SUSP PATH] {71F8F1D0-91AB-4707-938B-39A7381231D6}.job : c:\users\daniela\desktop\setup_av_free.exe -> DELETED
[SUSP PATH] {BFF0FB28-3C03-401D-BF8D-77E02C399FAC}.job : c:\users\daniela\desktop\roguekiller.exe -> DELETED
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
HOSTS File:
127.0.0.1 localhost
127.0.0.1 vkontakte.ru
127.0.0.1 www.vkontakte.ru
127.0.0.1 login.vk.com
127.0.0.1 vk.com
127.0.0.1 www.vk.com
127.0.0.1 odnoklassniki.ru
127.0.0.1 www.odnoklassniki.ru
127.0.0.1 facebook.com
127.0.0.1 www.facebook.com
127.0.0.1 af-za.facebook.com
127.0.0.1 az-az.facebook.com
127.0.0.1 id-id.facebook.com
127.0.0.1 ms-my.facebook.com
127.0.0.1 bs-ba.facebook.com
127.0.0.1 ca-es.facebook.com
127.0.0.1 cs-cz.facebook.com
127.0.0.1 cy-gb.facebook.com
127.0.0.1 da-dk.facebook.com
127.0.0.1 de-de.facebook.com
[...]
Finished : << RKreport[1].txt >>
RKreport[1].txt
RogueKiller V5.3.0 [08/01/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html
Operating System: Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User: Daniela [Admin rights]
Mode: HOSTSFix -- Date : 08/03/2011 22:18:24
Bad processes: 0
HOSTS File:
127.0.0.1 localhost
127.0.0.1 vkontakte.ru
127.0.0.1 www.vkontakte.ru
127.0.0.1 login.vk.com
127.0.0.1 vk.com
127.0.0.1 www.vk.com
127.0.0.1 odnoklassniki.ru
127.0.0.1 www.odnoklassniki.ru
127.0.0.1 facebook.com
127.0.0.1 www.facebook.com
127.0.0.1 af-za.facebook.com
127.0.0.1 az-az.facebook.com
127.0.0.1 id-id.facebook.com
127.0.0.1 ms-my.facebook.com
127.0.0.1 bs-ba.facebook.com
127.0.0.1 ca-es.facebook.com
127.0.0.1 cs-cz.facebook.com
127.0.0.1 cy-gb.facebook.com
127.0.0.1 da-dk.facebook.com
127.0.0.1 de-de.facebook.com
[...]
Resetted HOSTS:
127.0.0.1 localhost
Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
RogueKiller V5.3.0 [08/01/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html
Operating System: Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User: Daniela [Admin rights]
Mode: ProxyFix -- Date : 08/03/2011 22:19:36
Bad processes: 0
Registry Entries: 0
Finished : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt
Re: Vir Facebook prosim o pomoc
Fajn, jdeme dale
PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
- Pokud mate Win XP spustte pod uctem Spravce\Administratora
- Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
- Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
- Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
- Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
- Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
- Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
- Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
Re: Vir Facebook prosim o pomoc
ComboFix 11-08-03.03 - Daniela 03.08.2011 22:46:30.1.1 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1033.18.895.152 [GMT 2:00]
Spuštěný z: c:\users\Daniela\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: Emsisoft Anti-Malware *Disabled/Updated* {0ADC9F7D-20C1-240F-01E2-43466EBA893A}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Emsisoft Anti-Malware *Disabled/Updated* {B1BD7E99-06FB-2B81-3B52-7834153DC387}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Daniela\AppData\Local\TempDIR
c:\users\Daniela\AppData\Local\TempDIR\GFInstaller\GFInstaller.exe
c:\users\Daniela\AppData\Roaming\EurekaLog
c:\users\Daniela\AppData\Roaming\EurekaLog\a2guard\a2guard.elf
c:\windows\btc_client_iplist.txt
c:\windows\ddh_iplist.txt
c:\windows\front_ip_list.txt
c:\windows\geoiplist
c:\windows\geoiplist.rar
c:\windows\iecheck_iplist.txt
c:\windows\info1
c:\windows\iplist.txt
c:\windows\iun6002.exe
c:\windows\loader2.exe_ok
c:\windows\phoenix
c:\windows\phoenix.rar
c:\windows\phoenix\kernels\phatk\__init__.py
c:\windows\phoenix\kernels\phatk\__init__.pyc
c:\windows\phoenix\kernels\phatk\BFIPatcher.py
c:\windows\phoenix\kernels\phatk\kernel.cl
c:\windows\phoenix\kernels\poclbm\__init__.py
c:\windows\phoenix\kernels\poclbm\__init__.pyc
c:\windows\phoenix\kernels\poclbm\BFIPatcher.py
c:\windows\phoenix\kernels\poclbm\kernel.cl
c:\windows\phoenix\phoenix.exe
c:\windows\rpcminer
c:\windows\rpcminer.rar
c:\windows\rpcminer\bitcoinminercuda_10.cubin
c:\windows\rpcminer\bitcoinminercuda_11.cubin
c:\windows\rpcminer\bitcoinminercuda_20.cubin
c:\windows\rpcminer\bitcoinmineropencl.cl
c:\windows\rpcminer\cudart32_32_16.dll
c:\windows\rpcminer\curllib.dll
c:\windows\rpcminer\libeay32.dll
c:\windows\rpcminer\libsasl.dll
c:\windows\rpcminer\openldap.dll
c:\windows\rpcminer\rpcminer-4way.exe
c:\windows\rpcminer\rpcminer-cpu.exe
c:\windows\rpcminer\rpcminer-cuda.exe
c:\windows\rpcminer\rpcminer-opencl.exe
c:\windows\rpcminer\ssleay32.dll
c:\windows\system32\consrv.dll
c:\windows\system32\drivers\etc\HSTS~1
c:\windows\System64
c:\windows\ufa.rar
c:\windows\winlog-dirs.txt
c:\windows\winlog-ids.txt
.
---- Předchozí spuštění -------
.
c:\users\Daniela\AppData\Local\TempDIR\GFInstaller\AppName.txt
c:\users\Daniela\AppData\Local\TempDIR\GFInstaller\DownloadURL.txt
c:\users\Daniela\AppData\Local\TempDIR\GFInstaller\GFInstaller.exe
c:\users\Daniela\AppData\Local\TempDIR\GFInstaller\Channel.txt
c:\windows\btc_client_iplist.txt
c:\windows\ddh_iplist.txt
c:\windows\front_ip_list.txt
c:\windows\geoiplist
c:\windows\geoiplist.rar
c:\windows\iecheck_iplist.txt
c:\windows\info1
c:\windows\iplist.txt
c:\windows\iun6002.exe
c:\windows\loader2.exe_ok
c:\windows\phoenix.rar
c:\windows\phoenix\kernels\phatk\__init__.py
c:\windows\phoenix\kernels\phatk\__init__.pyc
c:\windows\phoenix\kernels\phatk\BFIPatcher.py
c:\windows\phoenix\kernels\phatk\kernel.cl
c:\windows\phoenix\kernels\poclbm\__init__.py
c:\windows\phoenix\kernels\poclbm\__init__.pyc
c:\windows\phoenix\kernels\poclbm\BFIPatcher.py
c:\windows\phoenix\kernels\poclbm\kernel.cl
c:\windows\phoenix\phoenix.exe
c:\windows\rpcminer.rar
c:\windows\system32\drivers\etc\HSTS~1
c:\windows\ufa.rar
c:\windows\winlog-dirs.txt
c:\windows\winlog-ids.txt
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_srviecheck
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-03 do 2011-08-03 )))))))))))))))))))))))))))))))
.
.
2011-08-03 20:59 . 2011-08-03 20:59 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-02 21:26 . 2011-07-13 04:53 8578896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3CBACF8F-094D-4267-9026-A64AC32114B4}\mpengine.dll
2011-08-01 17:48 . 2011-08-01 17:48 -------- d-----w- c:\users\Daniela\AppData\Local\Clicks
2011-08-01 17:48 . 2011-08-03 07:15 -------- d-----w- c:\program files (x86)\Super Klikacz
2011-08-01 17:47 . 2011-08-03 07:15 -------- d-----w- c:\users\Daniela\AppData\Local\ALLPlayer
2011-08-01 17:47 . 2011-08-03 07:15 -------- d-----w- c:\program files (x86)\ALLPlayer
2011-08-01 16:38 . 2011-08-01 16:38 -------- d-----w- c:\users\Daniela\AppData\Roaming\Malwarebytes
2011-08-01 16:38 . 2011-08-03 06:42 -------- d-----w- c:\programdata\Malwarebytes
2011-08-01 16:38 . 2011-08-03 07:15 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-07-31 22:01 . 2011-08-03 07:15 -------- d-----w- c:\program files\trend micro
2011-07-31 22:01 . 2011-07-31 22:09 -------- d-----w- C:\rsit
2011-07-31 21:45 . 2011-08-03 06:41 -------- d-----w- C:\_OTL
2011-07-31 20:46 . 2011-08-03 06:42 -------- d-----w- c:\program files\Java
2011-07-31 16:53 . 2011-07-31 16:53 -------- d-----w- c:\users\Daniela\AppData\Roaming\TrojanHunter
2011-07-31 14:30 . 2011-07-31 14:30 -------- d-----w- c:\programdata\TrojanHunter
2011-07-31 14:30 . 2011-08-01 05:37 -------- d-----w- c:\program files (x86)\TrojanHunter 5.3
2011-07-31 13:53 . 2011-08-01 05:37 -------- d-----w- C:\SDFix
2011-07-31 13:05 . 2011-08-01 05:37 -------- d-----w- C:\Spybot - Search & Destroy
2011-07-31 13:05 . 2011-08-01 05:37 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-07-31 11:43 . 2011-07-31 11:43 -------- d-----w- c:\program files (x86)\Common Files\Java
2011-07-31 11:43 . 2011-07-31 11:42 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-07-31 11:41 . 2011-07-31 11:41 -------- d-----w- c:\program files (x86)\Java
2011-07-30 22:46 . 2011-07-30 22:46 -------- d-----w- c:\users\Daniela\AppData\Local\Mozilla
2011-07-30 21:42 . 2011-07-04 11:32 22360 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-07-30 21:42 . 2011-07-04 11:36 288088 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-07-30 21:41 . 2011-07-04 11:32 31064 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-07-30 21:41 . 2011-07-04 11:35 45400 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-07-30 21:41 . 2011-07-04 11:36 600920 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-07-30 21:41 . 2011-07-04 11:32 64856 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-07-30 21:40 . 2011-07-04 11:43 40112 ----a-w- c:\windows\avastSS.scr
2011-07-30 21:40 . 2011-07-04 11:43 199304 ----a-w- c:\windows\SysWow64\aswBoot.exe
2011-07-30 14:12 . 2011-07-30 14:12 -------- d-----w- c:\users\Daniela\AppData\Local\Opera
2011-07-30 14:11 . 2011-07-30 21:56 -------- d-----w- c:\program files (x86)\Opera
2011-07-30 12:40 . 2011-07-30 12:40 -------- d-----w- c:\programdata\AVAST Software
2011-07-30 12:40 . 2011-07-30 12:40 -------- d-----w- c:\program files\AVAST Software
2011-07-29 21:25 . 2011-07-30 10:54 -------- d-----w- c:\program files\GridinSoft Trojan Killer
2011-07-29 19:49 . 2011-07-29 19:49 -------- d--h--w- c:\windows\AxInstSV
2011-07-28 17:58 . 2011-07-30 10:52 -------- d-----w- c:\programdata\Alwil Software
2011-07-27 20:35 . 2011-08-03 19:26 -------- d-----w- c:\program files (x86)\Emsisoft Anti-Malware
2011-07-22 09:06 . 2011-08-01 05:38 -------- d-----w- c:\windows\ufa
2011-07-21 18:45 . 2011-08-03 07:15 -------- d--h--w- c:\windows\update.tray-15-0-lnk
2011-07-21 18:45 . 2011-07-30 06:06 -------- d--h--w- c:\windows\update.tray-15-0
2011-07-21 18:34 . 2011-07-22 09:06 246272 ----a-w- c:\windows\unrar.exe
2011-07-21 18:31 . 2011-07-30 10:54 -------- d-----w- c:\windows\av_ico
2011-07-21 18:30 . 2011-07-30 06:06 -------- d--h--w- c:\windows\update.tray-7-0
2011-07-21 18:30 . 2011-07-30 06:06 -------- d--h--w- c:\windows\update.tray-7-0-lnk
2011-07-13 14:08 . 2011-06-02 06:39 422400 ----a-w- c:\windows\system32\KernelBase.dll
2011-07-13 14:06 . 2011-06-11 02:56 3134464 ----a-w- c:\windows\system32\win32k.sys
2011-07-13 14:05 . 2011-06-02 06:45 362496 ----a-w- c:\windows\system32\wow64win.dll
2011-07-13 14:05 . 2011-06-02 06:44 214528 ----a-w- c:\windows\system32\winsrv.dll
2011-07-13 14:05 . 2011-06-02 06:35 338944 ----a-w- c:\windows\system32\conhost.exe
2011-07-13 14:05 . 2011-06-02 06:45 243200 ----a-w- c:\windows\system32\wow64.dll
2011-07-13 14:05 . 2011-06-02 05:56 25600 ----a-w- c:\windows\SysWow64\setup16.exe
2011-07-13 14:05 . 2011-06-02 06:42 16384 ----a-w- c:\windows\system32\ntvdm64.dll
2011-07-13 14:05 . 2011-06-02 05:59 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll
2011-07-13 14:05 . 2011-06-02 06:45 13312 ----a-w- c:\windows\system32\wow64cpu.dll
2011-07-13 14:05 . 2011-06-02 03:51 7680 ----a-w- c:\windows\SysWow64\instnm.exe
2011-07-13 14:05 . 2011-06-02 05:54 5120 ----a-w- c:\windows\SysWow64\wow32.dll
2011-07-13 14:04 . 2011-06-02 03:50 2048 ----a-w- c:\windows\SysWow64\user.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-04 11:43 . 2011-02-27 11:52 253888 ----a-w- c:\windows\system32\aswBoot.exe
2011-06-30 18:52 . 2011-06-30 11:49 2829 ----a-w- c:\windows\War3Unin.pif
2011-06-30 18:52 . 2011-06-30 11:49 139264 ----a-w- c:\windows\War3Unin.exe
2011-06-08 16:35 . 2011-06-08 16:35 33344 ----a-w- c:\windows\system32\drivers\hamachi.sys
2011-06-02 05:56 . 2011-07-13 14:05 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-05-28 03:25 . 2011-06-16 15:05 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-05-28 03:00 . 2011-06-16 15:05 1638912 ----a-w- c:\windows\SysWow64\mshtml.tlb
2011-05-24 17:14 . 2010-05-27 05:50 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-05-24 11:21 . 2011-06-29 09:27 404992 ----a-w- c:\windows\system32\umpnpmgr.dll
2011-05-24 10:34 . 2011-06-29 09:27 64512 ----a-w- c:\windows\SysWow64\devobj.dll
2011-05-24 10:34 . 2011-06-29 09:27 44544 ----a-w- c:\windows\SysWow64\devrtl.dll
2011-05-24 10:34 . 2011-06-29 09:27 145920 ----a-w- c:\windows\SysWow64\cfgmgr32.dll
2011-05-24 10:32 . 2011-06-29 09:27 252928 ----a-w- c:\windows\SysWow64\drvinst.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-11-29 14:26 3908192 ----a-w- c:\program files (x86)\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files (x86)\ConduitEngine\ConduitEngine.dll" [2010-11-29 3908192]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
"ForceActiveDesktopOn"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
SetupExecute REG_MULTI_SZ \0
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"systemup"="c:\windows\systemup.exe" stand
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"DisableThumbnailCache"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-16 136176]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-16 136176]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 a2injectiondriver;a2injectiondriver;c:\program files (x86)\Emsisoft Anti-Malware\a2dix64.sys [2010-09-05 48216]
S1 a2util;a-squared Malware-IDS utility driver;c:\program files (x86)\Emsisoft Anti-Malware\a2util64.sys [2010-05-05 14720]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S2 a2AntiMalware;Emsisoft Anti-Malware 5.1 - Service;c:\program files (x86)\Emsisoft Anti-Malware\a2service.exe [2011-06-30 3029208]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 ICQ Service;ICQ Service;c:\program files (x86)\ICQ6Toolbar\ICQ Service.exe [2010-11-21 247608]
S3 a2acc;a2acc;c:\program files (x86)\EMSISOFT ANTI-MALWARE\a2accx64.sys [2011-02-20 85800]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2011-08-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-16 19:00]
.
2011-08-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-16 19:00]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-07-04 11:43 134384 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF605.cfxxe" [X]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.seznam.cz/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: WikiKomentáře Google... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files (x86)\ICQ7.5\ICQ.exe
FF - ProfilePath - c:\users\Daniela\AppData\Roaming\Mozilla\Firefox\Profiles\db4lnk7y.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
URLSearchHooks-{a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - (no file)
BHO-{a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - (no file)
Toolbar-{a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{A1E75A0E-4397-4BA8-BB50-E19FB66890F4} - (no file)
WebBrowser-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
AddRemove-Cool's_Codec_pack_4.12 - c:\windows\iun6002.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10e.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10e.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
.
**************************************************************************
.
Celkový čas: 2011-08-03 23:18:20 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-08-03 21:18
.
Před spuštěním: Volných bajtů: 64 963 346 432
Po spuštění: Volných bajtů: 64 323 072 000
.
- - End Of File - - 1A46E17FB40743BCA208B5EFFCFD17C2
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1033.18.895.152 [GMT 2:00]
Spuštěný z: c:\users\Daniela\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: Emsisoft Anti-Malware *Disabled/Updated* {0ADC9F7D-20C1-240F-01E2-43466EBA893A}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Emsisoft Anti-Malware *Disabled/Updated* {B1BD7E99-06FB-2B81-3B52-7834153DC387}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Daniela\AppData\Local\TempDIR
c:\users\Daniela\AppData\Local\TempDIR\GFInstaller\GFInstaller.exe
c:\users\Daniela\AppData\Roaming\EurekaLog
c:\users\Daniela\AppData\Roaming\EurekaLog\a2guard\a2guard.elf
c:\windows\btc_client_iplist.txt
c:\windows\ddh_iplist.txt
c:\windows\front_ip_list.txt
c:\windows\geoiplist
c:\windows\geoiplist.rar
c:\windows\iecheck_iplist.txt
c:\windows\info1
c:\windows\iplist.txt
c:\windows\iun6002.exe
c:\windows\loader2.exe_ok
c:\windows\phoenix
c:\windows\phoenix.rar
c:\windows\phoenix\kernels\phatk\__init__.py
c:\windows\phoenix\kernels\phatk\__init__.pyc
c:\windows\phoenix\kernels\phatk\BFIPatcher.py
c:\windows\phoenix\kernels\phatk\kernel.cl
c:\windows\phoenix\kernels\poclbm\__init__.py
c:\windows\phoenix\kernels\poclbm\__init__.pyc
c:\windows\phoenix\kernels\poclbm\BFIPatcher.py
c:\windows\phoenix\kernels\poclbm\kernel.cl
c:\windows\phoenix\phoenix.exe
c:\windows\rpcminer
c:\windows\rpcminer.rar
c:\windows\rpcminer\bitcoinminercuda_10.cubin
c:\windows\rpcminer\bitcoinminercuda_11.cubin
c:\windows\rpcminer\bitcoinminercuda_20.cubin
c:\windows\rpcminer\bitcoinmineropencl.cl
c:\windows\rpcminer\cudart32_32_16.dll
c:\windows\rpcminer\curllib.dll
c:\windows\rpcminer\libeay32.dll
c:\windows\rpcminer\libsasl.dll
c:\windows\rpcminer\openldap.dll
c:\windows\rpcminer\rpcminer-4way.exe
c:\windows\rpcminer\rpcminer-cpu.exe
c:\windows\rpcminer\rpcminer-cuda.exe
c:\windows\rpcminer\rpcminer-opencl.exe
c:\windows\rpcminer\ssleay32.dll
c:\windows\system32\consrv.dll
c:\windows\system32\drivers\etc\HSTS~1
c:\windows\System64
c:\windows\ufa.rar
c:\windows\winlog-dirs.txt
c:\windows\winlog-ids.txt
.
---- Předchozí spuštění -------
.
c:\users\Daniela\AppData\Local\TempDIR\GFInstaller\AppName.txt
c:\users\Daniela\AppData\Local\TempDIR\GFInstaller\DownloadURL.txt
c:\users\Daniela\AppData\Local\TempDIR\GFInstaller\GFInstaller.exe
c:\users\Daniela\AppData\Local\TempDIR\GFInstaller\Channel.txt
c:\windows\btc_client_iplist.txt
c:\windows\ddh_iplist.txt
c:\windows\front_ip_list.txt
c:\windows\geoiplist
c:\windows\geoiplist.rar
c:\windows\iecheck_iplist.txt
c:\windows\info1
c:\windows\iplist.txt
c:\windows\iun6002.exe
c:\windows\loader2.exe_ok
c:\windows\phoenix.rar
c:\windows\phoenix\kernels\phatk\__init__.py
c:\windows\phoenix\kernels\phatk\__init__.pyc
c:\windows\phoenix\kernels\phatk\BFIPatcher.py
c:\windows\phoenix\kernels\phatk\kernel.cl
c:\windows\phoenix\kernels\poclbm\__init__.py
c:\windows\phoenix\kernels\poclbm\__init__.pyc
c:\windows\phoenix\kernels\poclbm\BFIPatcher.py
c:\windows\phoenix\kernels\poclbm\kernel.cl
c:\windows\phoenix\phoenix.exe
c:\windows\rpcminer.rar
c:\windows\system32\drivers\etc\HSTS~1
c:\windows\ufa.rar
c:\windows\winlog-dirs.txt
c:\windows\winlog-ids.txt
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_srviecheck
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-03 do 2011-08-03 )))))))))))))))))))))))))))))))
.
.
2011-08-03 20:59 . 2011-08-03 20:59 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-02 21:26 . 2011-07-13 04:53 8578896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3CBACF8F-094D-4267-9026-A64AC32114B4}\mpengine.dll
2011-08-01 17:48 . 2011-08-01 17:48 -------- d-----w- c:\users\Daniela\AppData\Local\Clicks
2011-08-01 17:48 . 2011-08-03 07:15 -------- d-----w- c:\program files (x86)\Super Klikacz
2011-08-01 17:47 . 2011-08-03 07:15 -------- d-----w- c:\users\Daniela\AppData\Local\ALLPlayer
2011-08-01 17:47 . 2011-08-03 07:15 -------- d-----w- c:\program files (x86)\ALLPlayer
2011-08-01 16:38 . 2011-08-01 16:38 -------- d-----w- c:\users\Daniela\AppData\Roaming\Malwarebytes
2011-08-01 16:38 . 2011-08-03 06:42 -------- d-----w- c:\programdata\Malwarebytes
2011-08-01 16:38 . 2011-08-03 07:15 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-07-31 22:01 . 2011-08-03 07:15 -------- d-----w- c:\program files\trend micro
2011-07-31 22:01 . 2011-07-31 22:09 -------- d-----w- C:\rsit
2011-07-31 21:45 . 2011-08-03 06:41 -------- d-----w- C:\_OTL
2011-07-31 20:46 . 2011-08-03 06:42 -------- d-----w- c:\program files\Java
2011-07-31 16:53 . 2011-07-31 16:53 -------- d-----w- c:\users\Daniela\AppData\Roaming\TrojanHunter
2011-07-31 14:30 . 2011-07-31 14:30 -------- d-----w- c:\programdata\TrojanHunter
2011-07-31 14:30 . 2011-08-01 05:37 -------- d-----w- c:\program files (x86)\TrojanHunter 5.3
2011-07-31 13:53 . 2011-08-01 05:37 -------- d-----w- C:\SDFix
2011-07-31 13:05 . 2011-08-01 05:37 -------- d-----w- C:\Spybot - Search & Destroy
2011-07-31 13:05 . 2011-08-01 05:37 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-07-31 11:43 . 2011-07-31 11:43 -------- d-----w- c:\program files (x86)\Common Files\Java
2011-07-31 11:43 . 2011-07-31 11:42 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-07-31 11:41 . 2011-07-31 11:41 -------- d-----w- c:\program files (x86)\Java
2011-07-30 22:46 . 2011-07-30 22:46 -------- d-----w- c:\users\Daniela\AppData\Local\Mozilla
2011-07-30 21:42 . 2011-07-04 11:32 22360 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-07-30 21:42 . 2011-07-04 11:36 288088 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-07-30 21:41 . 2011-07-04 11:32 31064 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-07-30 21:41 . 2011-07-04 11:35 45400 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-07-30 21:41 . 2011-07-04 11:36 600920 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-07-30 21:41 . 2011-07-04 11:32 64856 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-07-30 21:40 . 2011-07-04 11:43 40112 ----a-w- c:\windows\avastSS.scr
2011-07-30 21:40 . 2011-07-04 11:43 199304 ----a-w- c:\windows\SysWow64\aswBoot.exe
2011-07-30 14:12 . 2011-07-30 14:12 -------- d-----w- c:\users\Daniela\AppData\Local\Opera
2011-07-30 14:11 . 2011-07-30 21:56 -------- d-----w- c:\program files (x86)\Opera
2011-07-30 12:40 . 2011-07-30 12:40 -------- d-----w- c:\programdata\AVAST Software
2011-07-30 12:40 . 2011-07-30 12:40 -------- d-----w- c:\program files\AVAST Software
2011-07-29 21:25 . 2011-07-30 10:54 -------- d-----w- c:\program files\GridinSoft Trojan Killer
2011-07-29 19:49 . 2011-07-29 19:49 -------- d--h--w- c:\windows\AxInstSV
2011-07-28 17:58 . 2011-07-30 10:52 -------- d-----w- c:\programdata\Alwil Software
2011-07-27 20:35 . 2011-08-03 19:26 -------- d-----w- c:\program files (x86)\Emsisoft Anti-Malware
2011-07-22 09:06 . 2011-08-01 05:38 -------- d-----w- c:\windows\ufa
2011-07-21 18:45 . 2011-08-03 07:15 -------- d--h--w- c:\windows\update.tray-15-0-lnk
2011-07-21 18:45 . 2011-07-30 06:06 -------- d--h--w- c:\windows\update.tray-15-0
2011-07-21 18:34 . 2011-07-22 09:06 246272 ----a-w- c:\windows\unrar.exe
2011-07-21 18:31 . 2011-07-30 10:54 -------- d-----w- c:\windows\av_ico
2011-07-21 18:30 . 2011-07-30 06:06 -------- d--h--w- c:\windows\update.tray-7-0
2011-07-21 18:30 . 2011-07-30 06:06 -------- d--h--w- c:\windows\update.tray-7-0-lnk
2011-07-13 14:08 . 2011-06-02 06:39 422400 ----a-w- c:\windows\system32\KernelBase.dll
2011-07-13 14:06 . 2011-06-11 02:56 3134464 ----a-w- c:\windows\system32\win32k.sys
2011-07-13 14:05 . 2011-06-02 06:45 362496 ----a-w- c:\windows\system32\wow64win.dll
2011-07-13 14:05 . 2011-06-02 06:44 214528 ----a-w- c:\windows\system32\winsrv.dll
2011-07-13 14:05 . 2011-06-02 06:35 338944 ----a-w- c:\windows\system32\conhost.exe
2011-07-13 14:05 . 2011-06-02 06:45 243200 ----a-w- c:\windows\system32\wow64.dll
2011-07-13 14:05 . 2011-06-02 05:56 25600 ----a-w- c:\windows\SysWow64\setup16.exe
2011-07-13 14:05 . 2011-06-02 06:42 16384 ----a-w- c:\windows\system32\ntvdm64.dll
2011-07-13 14:05 . 2011-06-02 05:59 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll
2011-07-13 14:05 . 2011-06-02 06:45 13312 ----a-w- c:\windows\system32\wow64cpu.dll
2011-07-13 14:05 . 2011-06-02 03:51 7680 ----a-w- c:\windows\SysWow64\instnm.exe
2011-07-13 14:05 . 2011-06-02 05:54 5120 ----a-w- c:\windows\SysWow64\wow32.dll
2011-07-13 14:04 . 2011-06-02 03:50 2048 ----a-w- c:\windows\SysWow64\user.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-04 11:43 . 2011-02-27 11:52 253888 ----a-w- c:\windows\system32\aswBoot.exe
2011-06-30 18:52 . 2011-06-30 11:49 2829 ----a-w- c:\windows\War3Unin.pif
2011-06-30 18:52 . 2011-06-30 11:49 139264 ----a-w- c:\windows\War3Unin.exe
2011-06-08 16:35 . 2011-06-08 16:35 33344 ----a-w- c:\windows\system32\drivers\hamachi.sys
2011-06-02 05:56 . 2011-07-13 14:05 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-05-28 03:25 . 2011-06-16 15:05 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-05-28 03:00 . 2011-06-16 15:05 1638912 ----a-w- c:\windows\SysWow64\mshtml.tlb
2011-05-24 17:14 . 2010-05-27 05:50 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-05-24 11:21 . 2011-06-29 09:27 404992 ----a-w- c:\windows\system32\umpnpmgr.dll
2011-05-24 10:34 . 2011-06-29 09:27 64512 ----a-w- c:\windows\SysWow64\devobj.dll
2011-05-24 10:34 . 2011-06-29 09:27 44544 ----a-w- c:\windows\SysWow64\devrtl.dll
2011-05-24 10:34 . 2011-06-29 09:27 145920 ----a-w- c:\windows\SysWow64\cfgmgr32.dll
2011-05-24 10:32 . 2011-06-29 09:27 252928 ----a-w- c:\windows\SysWow64\drvinst.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-11-29 14:26 3908192 ----a-w- c:\program files (x86)\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files (x86)\ConduitEngine\ConduitEngine.dll" [2010-11-29 3908192]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
"ForceActiveDesktopOn"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
SetupExecute REG_MULTI_SZ \0
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"systemup"="c:\windows\systemup.exe" stand
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"DisableThumbnailCache"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-16 136176]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-16 136176]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 a2injectiondriver;a2injectiondriver;c:\program files (x86)\Emsisoft Anti-Malware\a2dix64.sys [2010-09-05 48216]
S1 a2util;a-squared Malware-IDS utility driver;c:\program files (x86)\Emsisoft Anti-Malware\a2util64.sys [2010-05-05 14720]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S2 a2AntiMalware;Emsisoft Anti-Malware 5.1 - Service;c:\program files (x86)\Emsisoft Anti-Malware\a2service.exe [2011-06-30 3029208]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 ICQ Service;ICQ Service;c:\program files (x86)\ICQ6Toolbar\ICQ Service.exe [2010-11-21 247608]
S3 a2acc;a2acc;c:\program files (x86)\EMSISOFT ANTI-MALWARE\a2accx64.sys [2011-02-20 85800]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2011-08-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-16 19:00]
.
2011-08-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-16 19:00]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-07-04 11:43 134384 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF605.cfxxe" [X]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.seznam.cz/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: WikiKomentáře Google... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files (x86)\ICQ7.5\ICQ.exe
FF - ProfilePath - c:\users\Daniela\AppData\Roaming\Mozilla\Firefox\Profiles\db4lnk7y.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
URLSearchHooks-{a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - (no file)
BHO-{a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - (no file)
Toolbar-{a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{A1E75A0E-4397-4BA8-BB50-E19FB66890F4} - (no file)
WebBrowser-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
AddRemove-Cool's_Codec_pack_4.12 - c:\windows\iun6002.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10e.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10e.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
.
**************************************************************************
.
Celkový čas: 2011-08-03 23:18:20 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-08-03 21:18
.
Před spuštěním: Volných bajtů: 64 963 346 432
Po spuštění: Volných bajtů: 64 323 072 000
.
- - End Of File - - 1A46E17FB40743BCA208B5EFFCFD17C2
Re: Vir Facebook prosim o pomoc
- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
KillAll:: Folder:: c:\windows\ufa c:\windows\av_ico c:\windows\update.tray-7-0 c:\windows\update.tray-7-0-lnk c:\windows\update.tray-15-0 c:\windows\update.tray-15-0-lnk c:\users\Daniela\AppData\Roaming\TrojanHunter c:\programdata\TrojanHunter c:\program files (x86)\TrojanHunter 5.3 C:\SDFix c:\Spybot - Search & Destroy c:\programdata\Spybot - Search & Destroy c:\program files (x86)\Emsisoft Anti-Malware c:\program files (x86)\ICQ6Toolbar c:\program files\GridinSoft Trojan Killer File:: c:\windows\unrar.exe c:\windows\Tasks\GoogleUpdateTaskMachineCore.job c:\windows\Tasks\GoogleUpdateTaskMachineUA.job Collect:: c:\windows\systemup.exe Registry:: [HKEY_LOCAL_MACHINE\software\microsoft\security center] "DisableThumbnailCache"=dword:00000000 [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-] "systemup"=- [-HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "SunJavaUpdateSched"=- Driver:: a2injectiondriver a2util a2AntiMalware a2acc ICQ Service gupdate gupdatem SecCenter:: AV: Emsisoft Anti-Malware *Disabled/Updated* {0ADC9F7D-20C1-240F-01E2-43466EBA893A} SP: Emsisoft Anti-Malware *Disabled/Updated* {B1BD7E99-06FB-2B81-3B52-7834153DC387} RegLock:: [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}] [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation] [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32] [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib] [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}] [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32] [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib] [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] Reboot::- Ulozte vytvoreny TXT jako CFScript.txt
- Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)

- Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
Re: Vir Facebook prosim o pomoc
ComboFix 11-08-03.03 - Daniela 04.08.2011 0:39.2.1 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1033.18.895.350 [GMT 2:00]
Spuštěný z: c:\users\Daniela\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Daniela\Desktop\CFScript.txt.txt
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\unrar.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Emsisoft Anti-Malware
c:\program files (x86)\Emsisoft Anti-Malware\a2acc.dll
c:\program files (x86)\Emsisoft Anti-Malware\a2accx64.sys
c:\program files (x86)\Emsisoft Anti-Malware\a2accx86.sys
c:\program files (x86)\Emsisoft Anti-Malware\a2cmd.exe
c:\program files (x86)\Emsisoft Anti-Malware\a2cmd_readme.txt
c:\program files (x86)\Emsisoft Anti-Malware\a2contmenu.dll
c:\program files (x86)\Emsisoft Anti-Malware\a2contmenu64.dll
c:\program files (x86)\Emsisoft Anti-Malware\a2core32.dll
c:\program files (x86)\Emsisoft Anti-Malware\a2core64.dll
c:\program files (x86)\Emsisoft Anti-Malware\a2dix64.dll
c:\program files (x86)\Emsisoft Anti-Malware\a2dix64.sys
c:\program files (x86)\Emsisoft Anti-Malware\a2dix86.dll
c:\program files (x86)\Emsisoft Anti-Malware\a2dix86.sys
c:\program files (x86)\Emsisoft Anti-Malware\a2framework.dll
c:\program files (x86)\Emsisoft Anti-Malware\a2guard.exe
c:\program files (x86)\Emsisoft Anti-Malware\a2heur.dat
c:\program files (x86)\Emsisoft Anti-Malware\a2HiJackFree.exe
c:\program files (x86)\Emsisoft Anti-Malware\a2hooks32.dll
c:\program files (x86)\Emsisoft Anti-Malware\a2hooks64.dll
c:\program files (x86)\Emsisoft Anti-Malware\a2hosts.dat
c:\program files (x86)\Emsisoft Anti-Malware\a2mor.dll
c:\program files (x86)\Emsisoft Anti-Malware\a2scan.exe
c:\program files (x86)\Emsisoft Anti-Malware\a2service.exe
c:\program files (x86)\Emsisoft Anti-Malware\a2start.exe
c:\program files (x86)\Emsisoft Anti-Malware\a2trust.dat
c:\program files (x86)\Emsisoft Anti-Malware\a2update.dll
c:\program files (x86)\Emsisoft Anti-Malware\a2updateproxy.exe
c:\program files (x86)\Emsisoft Anti-Malware\a2updateproxy_default.ini
c:\program files (x86)\Emsisoft Anti-Malware\a2util32.sys
c:\program files (x86)\Emsisoft Anti-Malware\a2util64.sys
c:\program files (x86)\Emsisoft Anti-Malware\a2wizard.exe
c:\program files (x86)\Emsisoft Anti-Malware\a2wl.dat
c:\program files (x86)\Emsisoft Anti-Malware\a2wsc.dll
c:\program files (x86)\Emsisoft Anti-Malware\BlitzBlank.exe
c:\program files (x86)\Emsisoft Anti-Malware\engine.dll
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{4075281306213137}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{40752813063486104}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{40752813064420258}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{40752813066627292}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{40752813068167165}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{40752813069131869}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{40752813070416179}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{40752813071537223}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{40752813072742567}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{4075281307388201}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{40752813075147479}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{4075281307647056}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{40752813077884085}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{4075281307945972}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{40752813080529329}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{40752813083691728}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{40752813084836790}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{40752813086177466}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{40752813087432792}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{40752813088569767}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\index.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814411784417}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814412871798}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814413930664}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814415016262}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814415932949}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814417046602}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814418224665}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814419282567}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814420227902}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814421148176}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814422214918}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814423387433}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814424228729}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814425177275}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814426297645}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814427149252}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814428088793}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814429182727}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{4075281443002029}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814431114105}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814432514350}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814433450080}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{4075281443542167}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\index.ini
c:\program files (x86)\Emsisoft Anti-Malware\LANGUAGES\pl-pl.lng
c:\program files (x86)\Emsisoft Anti-Malware\Logs\a-squared.db3
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100901.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100902.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100903.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100906.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100907.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100909.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100911.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100913.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100914.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100916.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100917.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100920.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100921.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100922.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100923.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100924.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100927.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100928.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100929.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100930.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101001.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101004.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101005.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101006.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101007.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101009.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101011.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101012.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101013.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101015.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101016.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101018.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101019.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101020.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101021.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101023.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101025.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101026.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101027.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101028.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101029.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101101.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101103.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101104.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101105.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101108.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101109.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101110.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101111.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101112.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101115.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101116.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101118.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101119.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101122.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101123.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101124.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101125.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101127.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101129.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101130.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101202.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101203.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101207.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101208.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101209.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101211.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101213.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101214.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101215.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101216.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101217.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101220.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101221.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101222.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101223.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101224.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101227.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101228.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101230.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110101.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110103.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110104.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110105.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110106.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110107.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110110.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110111.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110112.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110113.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110114.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110117.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110118.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110119.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110120.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110121.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110124.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110125.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110127.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110128.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110131.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110201.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110202.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110203.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110204.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110207.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110208.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110209.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110210.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110211.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110214.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110216.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110217.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110218.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110221.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110222.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110223.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110224.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110225.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110228.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110301.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110302.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110303.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110304.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110307.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110308.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110309.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110310.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110312.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110313.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110314.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110315.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110316.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110318.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110320.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110321.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110324.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110325.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110329.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110331.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110402.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110403.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110404.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110405.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110406.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110407.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110408.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110411.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110412.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110413.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110414.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110415.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110418.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110419.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110420.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110421.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110422.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110426.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110427.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110428.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110429.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110502.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110503.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110504.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110505.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110506.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110510.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110511.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110512.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110513.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110516.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110517.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110518.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110519.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110520.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110523.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110524.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110525.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110527.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110528.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110530.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110601.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110602.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110603.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110604.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110606.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110607.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110608.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110609.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110610.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110613.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110614.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110615.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110616.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110617.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110621.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110622.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110623.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110625.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110627.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110628.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110630.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110701.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110702.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110704.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110705.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110706.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110707.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110709.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110712.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110714.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110715.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110716.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110718.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110719.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110721.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110723.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110726.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110728.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110729.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110802.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000101.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000102.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000103.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000104.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000105.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000106.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000107.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000108.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000109.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000110.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000111.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000112.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000113.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000114.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000115.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000116.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000117.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000118.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000119.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000120.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000121.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000122.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000123.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000124.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000125.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000126.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000127.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000128.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000129.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000201.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000202.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000203.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000204.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000205.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000206.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000207.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000208.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000209.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000210.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000211.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000212.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000213.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000214.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000215.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000216.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000217.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000301.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000401.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000601.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000602.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000701.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000702.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\t3sigs.vdb
c:\program files (x86)\Emsisoft Anti-Malware\t3.dll
c:\program files (x86)\Emsisoft Anti-Malware\unins000.exe
c:\program files (x86)\Emsisoft Anti-Malware\vdbupdate.dll
c:\program files (x86)\ICQ6Toolbar
c:\program files (x86)\ICQ6Toolbar\config.xml
c:\program files (x86)\ICQ6Toolbar\Icons.bmp
c:\program files (x86)\ICQ6Toolbar\ICQ Service.exe
c:\program files (x86)\ICQ6Toolbar\icq6Toolbar.ico
c:\program files (x86)\ICQ6Toolbar\ICQToolBar.dll
c:\program files (x86)\ICQ6Toolbar\ICQUnToolbar.exe
c:\program files (x86)\ICQ6Toolbar\logo_small.gif
c:\program files (x86)\ICQ6Toolbar\ServiceStarter.exe
c:\program files (x86)\ICQ6Toolbar\short.wav
c:\program files (x86)\ICQ6Toolbar\Version.txt
c:\program files (x86)\ICQ6Toolbar\voucher.bmp
c:\program files (x86)\ICQ6Toolbar\voucher2.bmp
c:\program files (x86)\TrojanHunter 5.3
c:\program files (x86)\TrojanHunter 5.3\Debug.log
c:\program files (x86)\TrojanHunter 5.3\Doc\LicenseInstall.rtf
c:\program files (x86)\TrojanHunter 5.3\Doc\Welcome.rtf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\Cumulative20060322.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060322_0800.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060331_0444.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060409_1917.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060417_1740.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060422_1609.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060429_0134.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060504_0530.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060510_1522.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060520_0846.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060528_2029.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060606_0904.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060612_2002.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060619_2213.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060627_1340.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060707_1649.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060717_2356.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060728_1243.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060807_1400.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060817_1509.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060825_1530.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060902_1407.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060911_1127.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060919_1438.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060928_1013.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20061005_1432.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20061012_2234.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20061023_1121.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20061030_1702.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20061107_1033.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20061116_0952.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20061125_1021.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20061203_0254.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20061212_2302.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20061220_1027.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20061228_1031.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070104_1030.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070111_1513.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070119_1149.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070125_1420.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070203_1141.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070210_1039.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070218_1105.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070226_2039.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070306_1255.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070314_0833.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070322_1154.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070402_1157.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070411_1534.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070420_1145.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070428_1233.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070506_1124.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070513_1209.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070524_1054.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070529_2214.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070604_1137.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070613_1102.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070621_2034.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070629_1051.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070708_2040.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070717_1120.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070727_1137.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070805_1157.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070813_1018.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070821_0541.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070902_1137.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070914_0811.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070925_1425.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20071005_1617.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20071015_1518.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20071029_1142.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20071114_1753.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20071126_1231.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20071209_1219.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20071220_1307.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080104_1125.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080116_1312.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080131_1229.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080213_1424.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080224_1244.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080309_0549.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080318_1136.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080324_1309.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080331_1330.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080410_1549.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080417_0514.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080424_1921.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080503_0937.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080511_1218.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080522_1235.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080605_0954.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080611_1219.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080620_1204.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080630_1105.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080712_1123.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080724_1845.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080803_1700.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080814_1221.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080825_1541.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080904_0441.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080916_0332.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080927_1212.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20081005_0308.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20081016_1141.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20081025_1916.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20081109_0630.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20081120_1217.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20081203_1254.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20081220_1556.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090102_0326.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090114_0849.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090129_1201.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090214_1143.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090302_1116.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090316_1149.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090328_0517.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090417_1141.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090504_0302.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090522_2119.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090530_2005.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090610_1300.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090625_0137.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090708_1721.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090717_1507.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090801_1108.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090814_0406.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090828_1018.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090907_0053.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090923_1541.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20091004_0702.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20091019_2107.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20091031_1616.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20091117_2143.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20091130_1157.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20091210_1152.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20091226_1115.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100108_1238.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100114_1321.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100124_2038.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100206_1718.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100216_1714.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100227_1048.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100311_1008.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100323_1708.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100413_1137.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100425_1226.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100502_1113.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100509_1310.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100516_1011.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100524_1133.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100603_1154.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100613_2143.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100619_1659.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100623_1154.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100626_2309.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100629_2238.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100704_2351.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100715_1505.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100721_1127.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100728_1058.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100804_1231.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100813_1435.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100822_2144.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100826_2209.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100904_2301.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100913_1058.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100924_1411.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20101004_1316.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20101013_0043.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20101014_1334.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20101029_1109.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20101106_0110.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20101108_2225.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20101109_1345.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20101110_1946.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20101118_1633.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20101120_2002.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20101124_1520.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20101129_2132.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20101204_1056.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20101208_1443.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20101216_1148.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20101223_1215.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110101_2244.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110201_0231.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110209_0028.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110217_1809.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110227_1320.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110304_1313.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110312_1213.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110321_1233.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110329_1830.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110403_0728.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110410_1210.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110419_1340.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110429_1201.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110511_1355.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110518_2011.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110525_0723.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110531_1054.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110608_2358.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110618_1709.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110618_1933.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110711_0740.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110721_1627.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110727_2342.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20111001_2303.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20111801_0912.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20112401_0551.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\HeuristicRules.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\M20060322_0800.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\M20101012_1621.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\M20101012_1622.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\M20101102_0921.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\M20101108_1952.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\UpdateList.txt
c:\program files (x86)\TrojanHunter 5.3\Scan Reports\2011-07-31_1850.txt
c:\program files (x86)\TrojanHunter 5.3\TrojanHunter.url
c:\program files (x86)\TrojanHunter 5.3\unins000.dat
c:\program files\GridinSoft Trojan Killer
c:\program files\GridinSoft Trojan Killer\acprotect.z
c:\program files\GridinSoft Trojan Killer\activex.a
c:\program files\GridinSoft Trojan Killer\amd.c
c:\program files\GridinSoft Trojan Killer\armadillo.z
c:\program files\GridinSoft Trojan Killer\ascrypt.z
c:\program files\GridinSoft Trojan Killer\asmd.c
c:\program files\GridinSoft Trojan Killer\aspack.z
c:\program files\GridinSoft Trojan Killer\aspr.z
c:\program files\GridinSoft Trojan Killer\bho.a
c:\program files\GridinSoft Trojan Killer\english.lng
c:\program files\GridinSoft Trojan Killer\execrypt.z
c:\program files\GridinSoft Trojan Killer\heur.b
c:\program files\GridinSoft Trojan Killer\ieb.a
c:\program files\GridinSoft Trojan Killer\md.c
c:\program files\GridinSoft Trojan Killer\mew.z
c:\program files\GridinSoft Trojan Killer\mslrh.z
c:\program files\GridinSoft Trojan Killer\naco.c
c:\program files\GridinSoft Trojan Killer\npack.z
c:\program files\GridinSoft Trojan Killer\pk.z
c:\program files\GridinSoft Trojan Killer\pl.a
c:\program files\GridinSoft Trojan Killer\ps.z
c:\program files\GridinSoft Trojan Killer\psign.z
c:\program files\GridinSoft Trojan Killer\rico.c
c:\program files\GridinSoft Trojan Killer\rlpack.z
c:\program files\GridinSoft Trojan Killer\service.a
c:\program files\GridinSoft Trojan Killer\sesi.a
c:\program files\GridinSoft Trojan Killer\smd.c
c:\program files\GridinSoft Trojan Killer\spl.a
c:\program files\GridinSoft Trojan Killer\startup.a
c:\program files\GridinSoft Trojan Killer\swl.c
c:\program files\GridinSoft Trojan Killer\trojanKiller.chm
c:\program files\GridinSoft Trojan Killer\unins000.dat
c:\program files\GridinSoft Trojan Killer\upack.z
c:\program files\GridinSoft Trojan Killer\upx.z
c:\program files\GridinSoft Trojan Killer\vs.c
c:\program files\GridinSoft Trojan Killer\wl.c
c:\program files\GridinSoft Trojan Killer\xpack.z
c:\program files\GridinSoft Trojan Killer\yoda.z
c:\programdata\Spybot - Search & Destroy
c:\programdata\Spybot - Search & Destroy\Excludes\Bots.sbe
c:\programdata\Spybot - Search & Destroy\Excludes\Cookies.sbe
c:\programdata\Spybot - Search & Destroy\Excludes\FileExt.sbe
c:\programdata\Spybot - Search & Destroy\Excludes\Links.sbe
c:\programdata\Spybot - Search & Destroy\Excludes\Single.sbe
c:\programdata\Spybot - Search & Destroy\Excludes\SystemInternals.sbe
c:\programdata\Spybot - Search & Destroy\Excludes\UpdateDL.sbe
c:\programdata\Spybot - Search & Destroy\Excludes\WaitFor.sbe
c:\programdata\Spybot - Search & Destroy\Logs\Fixes.110731-1539.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.110731-1516.log
c:\programdata\Spybot - Search & Destroy\Logs\Checks.110731-1537.txt
c:\programdata\Spybot - Search & Destroy\Logs\Resident.log
c:\programdata\Spybot - Search & Destroy\Logs\Update downloads.log
c:\programdata\Spybot - Search & Destroy\ProcCache.sbc
c:\programdata\TrojanHunter
C:\SDFix
c:\sdfix\apps\ERDNT.E_E
c:\sdfix\apps\ERDNTDOS.LOC
c:\sdfix\apps\ERDNTWIN.LOC
c:\sdfix\apps\ERUNT.LOC
c:\sdfix\apps\Installed.txt
c:\sdfix\apps\leg2.txt
c:\sdfix\apps\legacy.txt
c:\sdfix\apps\legacybk.txt
c:\sdfix\apps\Rem.txt
c:\sdfix\apps\Rem2.txt
c:\sdfix\apps\Replace\w2k\AUTOEXEC.NT
c:\sdfix\apps\Replace\w2k\CONFIG.NT
c:\sdfix\apps\Replace\xp\AUTOEXEC.NT
c:\sdfix\apps\Replace\xp\CONFIG.NT
c:\sdfix\apps\srv2.txt
c:\sdfix\apps\srv2bk.txt
c:\sdfix\apps\svc.txt
c:\sdfix\apps\svcbk.txt
c:\sdfix\SDFIX_ReadMe_Online.url
c:\Spybot - Search & Destroy
c:\spybot - search & destroy\Dummies\dummy.dap.gif
c:\spybot - search & destroy\Dummies\dummy.data.xml
c:\spybot - search & destroy\Dummies\dummy.default.gif
c:\spybot - search & destroy\Dummies\dummy.related.htm
c:\spybot - search & destroy\Help\Brasil.license.txt
c:\spybot - search & destroy\Help\Cesky.license.txt
c:\spybot - search & destroy\Help\Deutsch.license.txt
c:\spybot - search & destroy\Help\English.chm
c:\spybot - search & destroy\Help\English.license.txt
c:\spybot - search & destroy\Help\Espanol.license.txt
c:\spybot - search & destroy\Help\Francais.license.txt
c:\spybot - search & destroy\Help\Hellenic.license.txt
c:\spybot - search & destroy\Help\Italiano.license.txt
c:\spybot - search & destroy\Help\Japanese.license.ansi.txt
c:\spybot - search & destroy\Help\Japanese.license.txt
c:\spybot - search & destroy\Help\Korean.license.txt
c:\spybot - search & destroy\Help\Nederlands.license.txt
c:\spybot - search & destroy\Help\Polski.license.txt
c:\spybot - search & destroy\Help\Russkiy.license.txt
c:\spybot - search & destroy\Help\Slovensky.license.txt
c:\spybot - search & destroy\Help\Srpski.license.txt
c:\spybot - search & destroy\Help\Suomi.license.txt
c:\spybot - search & destroy\Includes\Adware.sbi
c:\spybot - search & destroy\Includes\AdwareC.sbi
c:\spybot - search & destroy\Includes\Browserpages.sbs
c:\spybot - search & destroy\Includes\CLSIDs.sbs
c:\spybot - search & destroy\Includes\Cookies.sbi
c:\spybot - search & destroy\Includes\Cookies.sbs
c:\spybot - search & destroy\Includes\Dialer.sbi
c:\spybot - search & destroy\Includes\Dialer.sbs
c:\spybot - search & destroy\Includes\DialerC.sbi
c:\spybot - search & destroy\Includes\Domains.sbs
c:\spybot - search & destroy\Includes\HeavyDuty.sbi
c:\spybot - search & destroy\Includes\Hijackers.sbi
c:\spybot - search & destroy\Includes\HijackersC.sbi
c:\spybot - search & destroy\Includes\iPhone.sbi
c:\spybot - search & destroy\Includes\Keyloggers.sbi
c:\spybot - search & destroy\Includes\KeyloggersC.sbi
c:\spybot - search & destroy\Includes\Logs.uts
c:\spybot - search & destroy\Includes\LSP.sbi
c:\spybot - search & destroy\Includes\LSP.sbs
c:\spybot - search & destroy\Includes\Malware.sbi
c:\spybot - search & destroy\Includes\MalwareC.sbi
c:\spybot - search & destroy\Includes\OperaPlugins.sbs
c:\spybot - search & destroy\Includes\ProcWatch.sbs
c:\spybot - search & destroy\Includes\PUPS.sbi
c:\spybot - search & destroy\Includes\PUPSC.sbi
c:\spybot - search & destroy\Includes\RegWatch.sbs
c:\spybot - search & destroy\Includes\RegXLinks.sbs
c:\spybot - search & destroy\Includes\Revision.sbi
c:\spybot - search & destroy\Includes\Revision.sbs
c:\spybot - search & destroy\Includes\Searchpages.sbs
c:\spybot - search & destroy\Includes\Security.sbi
c:\spybot - search & destroy\Includes\SecurityC.sbi
c:\spybot - search & destroy\Includes\Services.sbs
c:\spybot - search & destroy\Includes\Spybots.sbi
c:\spybot - search & destroy\Includes\SpybotsC.sbi
c:\spybot - search & destroy\Includes\Spyware.sbi
c:\spybot - search & destroy\Includes\SpywareC.sbi
c:\spybot - search & destroy\Includes\Startup.tnfo
c:\spybot - search & destroy\Includes\Tracks.uti
c:\spybot - search & destroy\Includes\Trojans.sbi
c:\spybot - search & destroy\Includes\TrojansC-02.sbi
c:\spybot - search & destroy\Includes\TrojansC-03.sbi
c:\spybot - search & destroy\Includes\TrojansC-04.sbi
c:\spybot - search & destroy\Includes\TrojansC-05.sbi
c:\spybot - search & destroy\Includes\TrojansC.sbi
c:\spybot - search & destroy\Includes\TTLASSH.sbs
c:\spybot - search & destroy\Includes\URL-Blacklist.sbs
c:\spybot - search & destroy\Includes\X509White.sbs
c:\spybot - search & destroy\Languages\Afrikaans.sbl
c:\spybot - search & destroy\Languages\Arabic.sbl
c:\spybot - search & destroy\Languages\Azeri.sbl
c:\spybot - search & destroy\Languages\Bahasa Indonesia.sbl
c:\spybot - search & destroy\Languages\Belarusskiy.sbl
c:\spybot - search & destroy\Languages\Bosanski.sbl
c:\spybot - search & destroy\Languages\Brasil.sbl
c:\spybot - search & destroy\Languages\Bulgarski.sbl
c:\spybot - search & destroy\Languages\Catalan.sbl
c:\spybot - search & destroy\Languages\Cesky.sbl
c:\spybot - search & destroy\Languages\Dansk.sbl
c:\spybot - search & destroy\Languages\Deutsch.sbl
c:\spybot - search & destroy\Languages\Eesti.sbl
c:\spybot - search & destroy\Languages\English.sbl
c:\spybot - search & destroy\Languages\Espanol.sbl
c:\spybot - search & destroy\Languages\Esperanto.sbl
c:\spybot - search & destroy\Languages\Euskera.sbl
c:\spybot - search & destroy\Languages\Farsi.sbl
c:\spybot - search & destroy\Languages\Francais.sbl
c:\spybot - search & destroy\Languages\Furlan.sbl
c:\spybot - search & destroy\Languages\Galego.sbl
c:\spybot - search & destroy\Languages\Hebrew.sbl
c:\spybot - search & destroy\Languages\Hellenic.sbl
c:\spybot - search & destroy\Languages\Hindi.sbl
c:\spybot - search & destroy\Languages\Hrvatski.sbl
c:\spybot - search & destroy\Languages\Chinese (simplified).sbl
c:\spybot - search & destroy\Languages\Chinese (traditional).sbl
c:\spybot - search & destroy\Languages\Islenska.sbl
c:\spybot - search & destroy\Languages\Italiano.sbl
c:\spybot - search & destroy\Languages\Japanese.sbl
c:\spybot - search & destroy\Languages\Korean.sbl
c:\spybot - search & destroy\Languages\Latvian.sbl
c:\spybot - search & destroy\Languages\Letzebuergesch.sbl
c:\spybot - search & destroy\Languages\Lietuviu.sbl
c:\spybot - search & destroy\Languages\Magyar.sbl
c:\spybot - search & destroy\Languages\Makedonski.sbl
c:\spybot - search & destroy\Languages\Melayu.sbl
c:\spybot - search & destroy\Languages\Nederlands.sbl
c:\spybot - search & destroy\Languages\Norsk.sbl
c:\spybot - search & destroy\Languages\Polski.sbl
c:\spybot - search & destroy\Languages\Portugues.sbl
c:\spybot - search & destroy\Languages\Romaneste.sbl
c:\spybot - search & destroy\Languages\Russkiy.sbl
c:\spybot - search & destroy\Languages\Shqip.sbl
c:\spybot - search & destroy\Languages\Slovenscina.sbl
c:\spybot - search & destroy\Languages\Slovensky.sbl
c:\spybot - search & destroy\Languages\Srpski.sbl
c:\spybot - search & destroy\Languages\Suomi.sbl
c:\spybot - search & destroy\Languages\Svenska.sbl
c:\spybot - search & destroy\Languages\Thai.sbl
c:\spybot - search & destroy\Languages\Turkce.sbl
c:\spybot - search & destroy\Languages\Ukrainian.sbl
c:\spybot - search & destroy\Languages\Uzbek.sbl
c:\spybot - search & destroy\messages.zres
c:\spybot - search & destroy\Skins\Italia.jpg
c:\spybot - search & destroy\Skins\Peace.jpg
c:\spybot - search & destroy\unins000.dat
c:\spybot - search & destroy\unins000.msg
c:\spybot - search & destroy\Updates\advcheck165.zip
c:\spybot - search & destroy\Updates\clsid.zip
c:\spybot - search & destroy\Updates\online.ini.uiz
c:\spybot - search & destroy\Updates\teatimer166.zip
c:\users\Daniela\AppData\Roaming\TrojanHunter
c:\users\Daniela\AppData\Roaming\TrojanHunter\TreeState.dat
c:\windows\av_ico
c:\windows\av_ico\ico_avast_desktop.ico
c:\windows\av_ico\ico_avast_start.ico
c:\windows\av_ico\ico_defender_start.ico
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
c:\windows\ufa
c:\windows\ufa\ufa.exe
c:\windows\unrar.exe
c:\windows\update.tray-15-0-lnk
c:\windows\update.tray-15-0-lnk\svchost.exe
c:\windows\update.tray-15-0
c:\windows\update.tray-7-0-lnk
c:\windows\update.tray-7-0
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_A2ACC
-------\Legacy_A2INJECTIONDRIVER
-------\Legacy_A2UTIL
-------\Service_a2acc
-------\Service_a2AntiMalware
-------\Service_a2injectiondriver
-------\Service_a2util
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_ICQ Service
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-03 do 2011-08-03 )))))))))))))))))))))))))))))))
.
.
2011-08-03 22:51 . 2011-08-03 22:51 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-02 21:26 . 2011-07-13 04:53 8578896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3CBACF8F-094D-4267-9026-A64AC32114B4}\mpengine.dll
2011-08-01 17:48 . 2011-08-01 17:48 -------- d-----w- c:\users\Daniela\AppData\Local\Clicks
2011-08-01 17:48 . 2011-08-03 07:15 -------- d-----w- c:\program files (x86)\Super Klikacz
2011-08-01 17:47 . 2011-08-03 07:15 -------- d-----w- c:\users\Daniela\AppData\Local\ALLPlayer
2011-08-01 17:47 . 2011-08-03 07:15 -------- d-----w- c:\program files (x86)\ALLPlayer
2011-08-01 16:38 . 2011-08-01 16:38 -------- d-----w- c:\users\Daniela\AppData\Roaming\Malwarebytes
2011-08-01 16:38 . 2011-08-03 06:42 -------- d-----w- c:\programdata\Malwarebytes
2011-08-01 16:38 . 2011-08-03 07:15 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-07-31 22:01 . 2011-08-03 07:15 -------- d-----w- c:\program files\trend micro
2011-07-31 22:01 . 2011-07-31 22:09 -------- d-----w- C:\rsit
2011-07-31 21:45 . 2011-08-03 06:41 -------- d-----w- C:\_OTL
2011-07-31 20:46 . 2011-08-03 06:42 -------- d-----w- c:\program files\Java
2011-07-31 11:43 . 2011-07-31 11:43 -------- d-----w- c:\program files (x86)\Common Files\Java
2011-07-31 11:43 . 2011-07-31 11:42 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-07-31 11:41 . 2011-07-31 11:41 -------- d-----w- c:\program files (x86)\Java
2011-07-30 22:46 . 2011-07-30 22:46 -------- d-----w- c:\users\Daniela\AppData\Local\Mozilla
2011-07-30 21:42 . 2011-07-04 11:32 22360 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-07-30 21:42 . 2011-07-04 11:36 288088 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-07-30 21:41 . 2011-07-04 11:32 31064 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-07-30 21:41 . 2011-07-04 11:35 45400 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-07-30 21:41 . 2011-07-04 11:36 600920 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-07-30 21:41 . 2011-07-04 11:32 64856 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-07-30 21:40 . 2011-07-04 11:43 40112 ----a-w- c:\windows\avastSS.scr
2011-07-30 21:40 . 2011-07-04 11:43 199304 ----a-w- c:\windows\SysWow64\aswBoot.exe
2011-07-30 14:12 . 2011-07-30 14:12 -------- d-----w- c:\users\Daniela\AppData\Local\Opera
2011-07-30 14:11 . 2011-07-30 21:56 -------- d-----w- c:\program files (x86)\Opera
2011-07-30 12:40 . 2011-07-30 12:40 -------- d-----w- c:\programdata\AVAST Software
2011-07-30 12:40 . 2011-07-30 12:40 -------- d-----w- c:\program files\AVAST Software
2011-07-29 19:49 . 2011-07-29 19:49 -------- d--h--w- c:\windows\AxInstSV
2011-07-28 17:58 . 2011-07-30 10:52 -------- d-----w- c:\programdata\Alwil Software
2011-07-13 14:08 . 2011-06-02 06:39 422400 ----a-w- c:\windows\system32\KernelBase.dll
2011-07-13 14:06 . 2011-06-11 02:56 3134464 ----a-w- c:\windows\system32\win32k.sys
2011-07-13 14:05 . 2011-06-02 06:45 362496 ----a-w- c:\windows\system32\wow64win.dll
2011-07-13 14:05 . 2011-06-02 06:44 214528 ----a-w- c:\windows\system32\winsrv.dll
2011-07-13 14:05 . 2011-06-02 06:35 338944 ----a-w- c:\windows\system32\conhost.exe
2011-07-13 14:05 . 2011-06-02 06:45 243200 ----a-w- c:\windows\system32\wow64.dll
2011-07-13 14:05 . 2011-06-02 05:56 25600 ----a-w- c:\windows\SysWow64\setup16.exe
2011-07-13 14:05 . 2011-06-02 06:42 16384 ----a-w- c:\windows\system32\ntvdm64.dll
2011-07-13 14:05 . 2011-06-02 05:59 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll
2011-07-13 14:05 . 2011-06-02 06:45 13312 ----a-w- c:\windows\system32\wow64cpu.dll
2011-07-13 14:05 . 2011-06-02 03:51 7680 ----a-w- c:\windows\SysWow64\instnm.exe
2011-07-13 14:05 . 2011-06-02 05:54 5120 ----a-w- c:\windows\SysWow64\wow32.dll
2011-07-13 14:04 . 2011-06-02 03:50 2048 ----a-w- c:\windows\SysWow64\user.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-04 11:43 . 2011-02-27 11:52 253888 ----a-w- c:\windows\system32\aswBoot.exe
2011-06-30 18:52 . 2011-06-30 11:49 2829 ----a-w- c:\windows\War3Unin.pif
2011-06-30 18:52 . 2011-06-30 11:49 139264 ----a-w- c:\windows\War3Unin.exe
2011-06-08 16:35 . 2011-06-08 16:35 33344 ----a-w- c:\windows\system32\drivers\hamachi.sys
2011-06-02 05:56 . 2011-07-13 14:05 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-05-28 03:25 . 2011-06-16 15:05 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-05-28 03:00 . 2011-06-16 15:05 1638912 ----a-w- c:\windows\SysWow64\mshtml.tlb
2011-05-24 17:14 . 2010-05-27 05:50 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-05-24 11:21 . 2011-06-29 09:27 404992 ----a-w- c:\windows\system32\umpnpmgr.dll
2011-05-24 10:34 . 2011-06-29 09:27 64512 ----a-w- c:\windows\SysWow64\devobj.dll
2011-05-24 10:34 . 2011-06-29 09:27 44544 ----a-w- c:\windows\SysWow64\devrtl.dll
2011-05-24 10:34 . 2011-06-29 09:27 145920 ----a-w- c:\windows\SysWow64\cfgmgr32.dll
2011-05-24 10:32 . 2011-06-29 09:27 252928 ----a-w- c:\windows\SysWow64\drvinst.exe
.
.
((((((((((((((((((((((((((((( SnapShot@2011-08-03_21.04.27 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-07-14 04:54 . 2011-08-03 21:04 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2011-08-03 22:54 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2011-08-03 22:54 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-08-03 21:04 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-08-03 21:04 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-08-03 22:54 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-05-27 05:25 . 2011-08-03 21:05 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-05-27 05:25 . 2011-08-03 20:44 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-05-27 05:25 . 2011-08-03 20:44 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-05-27 05:25 . 2011-08-03 21:05 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-05-27 05:25 . 2011-08-03 20:44 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-05-27 05:25 . 2011-08-03 21:05 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-05-27 05:29 . 2011-08-03 22:00 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-05-27 05:29 . 2011-08-03 20:44 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-05-27 05:29 . 2011-08-03 22:00 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-05-27 05:29 . 2011-08-03 20:44 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-08-03 22:53 . 2011-08-03 22:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-08-03 21:02 . 2011-08-03 21:02 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-08-03 22:53 . 2011-08-03 22:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-08-03 21:02 . 2011-08-03 21:02 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 05:01 . 2011-08-03 21:01 390348 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2011-08-03 22:52 390348 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 02:34 . 2011-08-03 21:12 10485760 c:\windows\system32\SMI\Store\Machine\schema.dat
- 2009-07-14 02:34 . 2011-08-03 20:52 10485760 c:\windows\system32\SMI\Store\Machine\schema.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-11-29 14:26 3908192 ----a-w- c:\program files (x86)\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files (x86)\ConduitEngine\ConduitEngine.dll" [2010-11-29 3908192]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-07-04 11:43 134384 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF21985.cfxxe" [X]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.seznam.cz/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: WikiKomentáře Google... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files (x86)\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
FF - ProfilePath - c:\users\Daniela\AppData\Roaming\Mozilla\Firefox\Profiles\db4lnk7y.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - (no file)
Toolbar-{a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
AddRemove-Emsisoft Anti-Malware_is1 - c:\program files (x86)\Emsisoft Anti-Malware\unins000.exe
AddRemove-ICQToolbar - c:\program files (x86)\ICQ6Toolbar\ICQUnToolbar.exe
.
.
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
.
**************************************************************************
.
Celkový čas: 2011-08-04 01:04:28 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-08-03 23:04
ComboFix2.txt 2011-08-03 21:18
.
Před spuštěním: Volných bajtů: 65 398 317 056
Po spuštění: Volných bajtů: 65 579 429 888
.
- - End Of File - - 2AFF19007142B7AC3A9C2F7543B28339
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1033.18.895.350 [GMT 2:00]
Spuštěný z: c:\users\Daniela\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Daniela\Desktop\CFScript.txt.txt
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\unrar.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Emsisoft Anti-Malware
c:\program files (x86)\Emsisoft Anti-Malware\a2acc.dll
c:\program files (x86)\Emsisoft Anti-Malware\a2accx64.sys
c:\program files (x86)\Emsisoft Anti-Malware\a2accx86.sys
c:\program files (x86)\Emsisoft Anti-Malware\a2cmd.exe
c:\program files (x86)\Emsisoft Anti-Malware\a2cmd_readme.txt
c:\program files (x86)\Emsisoft Anti-Malware\a2contmenu.dll
c:\program files (x86)\Emsisoft Anti-Malware\a2contmenu64.dll
c:\program files (x86)\Emsisoft Anti-Malware\a2core32.dll
c:\program files (x86)\Emsisoft Anti-Malware\a2core64.dll
c:\program files (x86)\Emsisoft Anti-Malware\a2dix64.dll
c:\program files (x86)\Emsisoft Anti-Malware\a2dix64.sys
c:\program files (x86)\Emsisoft Anti-Malware\a2dix86.dll
c:\program files (x86)\Emsisoft Anti-Malware\a2dix86.sys
c:\program files (x86)\Emsisoft Anti-Malware\a2framework.dll
c:\program files (x86)\Emsisoft Anti-Malware\a2guard.exe
c:\program files (x86)\Emsisoft Anti-Malware\a2heur.dat
c:\program files (x86)\Emsisoft Anti-Malware\a2HiJackFree.exe
c:\program files (x86)\Emsisoft Anti-Malware\a2hooks32.dll
c:\program files (x86)\Emsisoft Anti-Malware\a2hooks64.dll
c:\program files (x86)\Emsisoft Anti-Malware\a2hosts.dat
c:\program files (x86)\Emsisoft Anti-Malware\a2mor.dll
c:\program files (x86)\Emsisoft Anti-Malware\a2scan.exe
c:\program files (x86)\Emsisoft Anti-Malware\a2service.exe
c:\program files (x86)\Emsisoft Anti-Malware\a2start.exe
c:\program files (x86)\Emsisoft Anti-Malware\a2trust.dat
c:\program files (x86)\Emsisoft Anti-Malware\a2update.dll
c:\program files (x86)\Emsisoft Anti-Malware\a2updateproxy.exe
c:\program files (x86)\Emsisoft Anti-Malware\a2updateproxy_default.ini
c:\program files (x86)\Emsisoft Anti-Malware\a2util32.sys
c:\program files (x86)\Emsisoft Anti-Malware\a2util64.sys
c:\program files (x86)\Emsisoft Anti-Malware\a2wizard.exe
c:\program files (x86)\Emsisoft Anti-Malware\a2wl.dat
c:\program files (x86)\Emsisoft Anti-Malware\a2wsc.dll
c:\program files (x86)\Emsisoft Anti-Malware\BlitzBlank.exe
c:\program files (x86)\Emsisoft Anti-Malware\engine.dll
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{4075281306213137}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{40752813063486104}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{40752813064420258}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{40752813066627292}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{40752813068167165}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{40752813069131869}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{40752813070416179}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{40752813071537223}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{40752813072742567}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{4075281307388201}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{40752813075147479}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{4075281307647056}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{40752813077884085}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{4075281307945972}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{40752813080529329}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{40752813083691728}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{40752813084836790}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{40752813086177466}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{40752813087432792}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\{40752813088569767}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Autorun\index.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814411784417}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814412871798}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814413930664}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814415016262}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814415932949}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814417046602}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814418224665}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814419282567}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814420227902}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814421148176}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814422214918}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814423387433}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814424228729}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814425177275}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814426297645}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814427149252}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814428088793}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814429182727}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{4075281443002029}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814431114105}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814432514350}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{40752814433450080}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\{4075281443542167}.ini
c:\program files (x86)\Emsisoft Anti-Malware\HiJackFree\Clsid\index.ini
c:\program files (x86)\Emsisoft Anti-Malware\LANGUAGES\pl-pl.lng
c:\program files (x86)\Emsisoft Anti-Malware\Logs\a-squared.db3
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100901.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100902.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100903.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100906.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100907.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100909.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100911.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100913.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100914.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100916.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100917.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100920.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100921.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100922.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100923.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100924.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100927.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100928.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100929.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20100930.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101001.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101004.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101005.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101006.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101007.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101009.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101011.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101012.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101013.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101015.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101016.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101018.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101019.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101020.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101021.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101023.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101025.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101026.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101027.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101028.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101029.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101101.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101103.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101104.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101105.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101108.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101109.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101110.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101111.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101112.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101115.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101116.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101118.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101119.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101122.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101123.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101124.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101125.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101127.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101129.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101130.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101202.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101203.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101207.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101208.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101209.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101211.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101213.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101214.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101215.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101216.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101217.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101220.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101221.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101222.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101223.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101224.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101227.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101228.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20101230.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110101.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110103.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110104.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110105.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110106.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110107.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110110.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110111.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110112.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110113.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110114.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110117.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110118.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110119.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110120.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110121.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110124.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110125.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110127.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110128.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110131.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110201.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110202.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110203.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110204.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110207.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110208.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110209.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110210.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110211.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110214.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110216.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110217.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110218.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110221.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110222.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110223.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110224.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110225.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110228.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110301.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110302.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110303.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110304.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110307.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110308.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110309.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110310.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110312.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110313.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110314.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110315.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110316.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110318.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110320.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110321.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110324.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110325.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110329.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110331.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110402.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110403.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110404.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110405.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110406.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110407.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110408.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110411.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110412.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110413.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110414.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110415.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110418.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110419.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110420.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110421.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110422.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110426.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110427.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110428.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110429.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110502.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110503.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110504.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110505.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110506.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110510.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110511.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110512.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110513.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110516.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110517.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110518.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110519.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110520.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110523.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110524.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110525.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110527.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110528.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110530.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110601.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110602.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110603.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110604.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110606.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110607.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110608.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110609.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110610.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110613.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110614.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110615.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110616.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110617.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110621.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110622.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110623.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110625.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110627.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110628.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110630.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110701.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110702.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110704.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110705.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110706.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110707.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110709.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110712.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110714.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110715.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110716.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110718.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110719.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110721.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110723.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110726.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110728.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110729.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\20110802.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000101.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000102.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000103.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000104.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000105.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000106.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000107.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000108.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000109.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000110.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000111.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000112.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000113.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000114.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000115.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000116.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000117.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000118.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000119.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000120.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000121.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000122.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000123.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000124.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000125.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000126.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000127.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000128.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000129.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000201.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000202.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000203.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000204.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000205.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000206.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000207.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000208.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000209.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000210.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000211.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000212.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000213.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000214.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000215.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000216.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000217.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000301.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000401.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000601.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000602.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000701.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\30000702.sig
c:\program files (x86)\Emsisoft Anti-Malware\Signatures\t3sigs.vdb
c:\program files (x86)\Emsisoft Anti-Malware\t3.dll
c:\program files (x86)\Emsisoft Anti-Malware\unins000.exe
c:\program files (x86)\Emsisoft Anti-Malware\vdbupdate.dll
c:\program files (x86)\ICQ6Toolbar
c:\program files (x86)\ICQ6Toolbar\config.xml
c:\program files (x86)\ICQ6Toolbar\Icons.bmp
c:\program files (x86)\ICQ6Toolbar\ICQ Service.exe
c:\program files (x86)\ICQ6Toolbar\icq6Toolbar.ico
c:\program files (x86)\ICQ6Toolbar\ICQToolBar.dll
c:\program files (x86)\ICQ6Toolbar\ICQUnToolbar.exe
c:\program files (x86)\ICQ6Toolbar\logo_small.gif
c:\program files (x86)\ICQ6Toolbar\ServiceStarter.exe
c:\program files (x86)\ICQ6Toolbar\short.wav
c:\program files (x86)\ICQ6Toolbar\Version.txt
c:\program files (x86)\ICQ6Toolbar\voucher.bmp
c:\program files (x86)\ICQ6Toolbar\voucher2.bmp
c:\program files (x86)\TrojanHunter 5.3
c:\program files (x86)\TrojanHunter 5.3\Debug.log
c:\program files (x86)\TrojanHunter 5.3\Doc\LicenseInstall.rtf
c:\program files (x86)\TrojanHunter 5.3\Doc\Welcome.rtf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\Cumulative20060322.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060322_0800.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060331_0444.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060409_1917.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060417_1740.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060422_1609.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060429_0134.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060504_0530.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060510_1522.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060520_0846.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060528_2029.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060606_0904.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060612_2002.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060619_2213.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060627_1340.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060707_1649.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060717_2356.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060728_1243.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060807_1400.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060817_1509.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060825_1530.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060902_1407.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060911_1127.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060919_1438.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20060928_1013.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20061005_1432.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20061012_2234.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20061023_1121.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20061030_1702.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20061107_1033.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20061116_0952.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20061125_1021.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20061203_0254.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20061212_2302.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20061220_1027.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20061228_1031.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070104_1030.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070111_1513.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070119_1149.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070125_1420.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070203_1141.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070210_1039.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070218_1105.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070226_2039.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070306_1255.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070314_0833.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070322_1154.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070402_1157.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070411_1534.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070420_1145.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070428_1233.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070506_1124.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070513_1209.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070524_1054.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070529_2214.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070604_1137.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070613_1102.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070621_2034.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070629_1051.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070708_2040.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070717_1120.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070727_1137.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070805_1157.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070813_1018.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070821_0541.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070902_1137.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070914_0811.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20070925_1425.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20071005_1617.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20071015_1518.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20071029_1142.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20071114_1753.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20071126_1231.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20071209_1219.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20071220_1307.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080104_1125.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080116_1312.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080131_1229.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080213_1424.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080224_1244.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080309_0549.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080318_1136.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080324_1309.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080331_1330.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080410_1549.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080417_0514.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080424_1921.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080503_0937.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080511_1218.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080522_1235.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080605_0954.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080611_1219.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080620_1204.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080630_1105.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080712_1123.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080724_1845.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080803_1700.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080814_1221.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080825_1541.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080904_0441.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080916_0332.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20080927_1212.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20081005_0308.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20081016_1141.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20081025_1916.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20081109_0630.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20081120_1217.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20081203_1254.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20081220_1556.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090102_0326.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090114_0849.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090129_1201.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090214_1143.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090302_1116.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090316_1149.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090328_0517.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090417_1141.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090504_0302.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090522_2119.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090530_2005.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090610_1300.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090625_0137.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090708_1721.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090717_1507.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090801_1108.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090814_0406.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090828_1018.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090907_0053.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20090923_1541.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20091004_0702.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20091019_2107.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20091031_1616.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20091117_2143.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20091130_1157.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20091210_1152.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20091226_1115.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100108_1238.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100114_1321.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100124_2038.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100206_1718.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100216_1714.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100227_1048.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100311_1008.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100323_1708.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100413_1137.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100425_1226.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100502_1113.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100509_1310.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100516_1011.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100524_1133.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100603_1154.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100613_2143.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100619_1659.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100623_1154.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100626_2309.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100629_2238.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100704_2351.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100715_1505.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100721_1127.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100728_1058.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100804_1231.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100813_1435.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100822_2144.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100826_2209.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100904_2301.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100913_1058.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20100924_1411.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20101004_1316.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20101013_0043.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20101014_1334.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20101029_1109.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20101106_0110.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20101108_2225.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20101109_1345.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20101110_1946.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20101118_1633.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20101120_2002.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20101124_1520.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20101129_2132.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20101204_1056.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20101208_1443.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20101216_1148.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20101223_1215.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110101_2244.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110201_0231.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110209_0028.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110217_1809.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110227_1320.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110304_1313.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110312_1213.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110321_1233.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110329_1830.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110403_0728.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110410_1210.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110419_1340.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110429_1201.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110511_1355.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110518_2011.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110525_0723.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110531_1054.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110608_2358.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110618_1709.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110618_1933.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110711_0740.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110721_1627.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20110727_2342.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20111001_2303.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20111801_0912.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\G20112401_0551.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\HeuristicRules.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\M20060322_0800.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\M20101012_1621.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\M20101012_1622.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\M20101102_0921.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\M20101108_1952.trf
c:\program files (x86)\TrojanHunter 5.3\RuleFiles\UpdateList.txt
c:\program files (x86)\TrojanHunter 5.3\Scan Reports\2011-07-31_1850.txt
c:\program files (x86)\TrojanHunter 5.3\TrojanHunter.url
c:\program files (x86)\TrojanHunter 5.3\unins000.dat
c:\program files\GridinSoft Trojan Killer
c:\program files\GridinSoft Trojan Killer\acprotect.z
c:\program files\GridinSoft Trojan Killer\activex.a
c:\program files\GridinSoft Trojan Killer\amd.c
c:\program files\GridinSoft Trojan Killer\armadillo.z
c:\program files\GridinSoft Trojan Killer\ascrypt.z
c:\program files\GridinSoft Trojan Killer\asmd.c
c:\program files\GridinSoft Trojan Killer\aspack.z
c:\program files\GridinSoft Trojan Killer\aspr.z
c:\program files\GridinSoft Trojan Killer\bho.a
c:\program files\GridinSoft Trojan Killer\english.lng
c:\program files\GridinSoft Trojan Killer\execrypt.z
c:\program files\GridinSoft Trojan Killer\heur.b
c:\program files\GridinSoft Trojan Killer\ieb.a
c:\program files\GridinSoft Trojan Killer\md.c
c:\program files\GridinSoft Trojan Killer\mew.z
c:\program files\GridinSoft Trojan Killer\mslrh.z
c:\program files\GridinSoft Trojan Killer\naco.c
c:\program files\GridinSoft Trojan Killer\npack.z
c:\program files\GridinSoft Trojan Killer\pk.z
c:\program files\GridinSoft Trojan Killer\pl.a
c:\program files\GridinSoft Trojan Killer\ps.z
c:\program files\GridinSoft Trojan Killer\psign.z
c:\program files\GridinSoft Trojan Killer\rico.c
c:\program files\GridinSoft Trojan Killer\rlpack.z
c:\program files\GridinSoft Trojan Killer\service.a
c:\program files\GridinSoft Trojan Killer\sesi.a
c:\program files\GridinSoft Trojan Killer\smd.c
c:\program files\GridinSoft Trojan Killer\spl.a
c:\program files\GridinSoft Trojan Killer\startup.a
c:\program files\GridinSoft Trojan Killer\swl.c
c:\program files\GridinSoft Trojan Killer\trojanKiller.chm
c:\program files\GridinSoft Trojan Killer\unins000.dat
c:\program files\GridinSoft Trojan Killer\upack.z
c:\program files\GridinSoft Trojan Killer\upx.z
c:\program files\GridinSoft Trojan Killer\vs.c
c:\program files\GridinSoft Trojan Killer\wl.c
c:\program files\GridinSoft Trojan Killer\xpack.z
c:\program files\GridinSoft Trojan Killer\yoda.z
c:\programdata\Spybot - Search & Destroy
c:\programdata\Spybot - Search & Destroy\Excludes\Bots.sbe
c:\programdata\Spybot - Search & Destroy\Excludes\Cookies.sbe
c:\programdata\Spybot - Search & Destroy\Excludes\FileExt.sbe
c:\programdata\Spybot - Search & Destroy\Excludes\Links.sbe
c:\programdata\Spybot - Search & Destroy\Excludes\Single.sbe
c:\programdata\Spybot - Search & Destroy\Excludes\SystemInternals.sbe
c:\programdata\Spybot - Search & Destroy\Excludes\UpdateDL.sbe
c:\programdata\Spybot - Search & Destroy\Excludes\WaitFor.sbe
c:\programdata\Spybot - Search & Destroy\Logs\Fixes.110731-1539.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.110731-1516.log
c:\programdata\Spybot - Search & Destroy\Logs\Checks.110731-1537.txt
c:\programdata\Spybot - Search & Destroy\Logs\Resident.log
c:\programdata\Spybot - Search & Destroy\Logs\Update downloads.log
c:\programdata\Spybot - Search & Destroy\ProcCache.sbc
c:\programdata\TrojanHunter
C:\SDFix
c:\sdfix\apps\ERDNT.E_E
c:\sdfix\apps\ERDNTDOS.LOC
c:\sdfix\apps\ERDNTWIN.LOC
c:\sdfix\apps\ERUNT.LOC
c:\sdfix\apps\Installed.txt
c:\sdfix\apps\leg2.txt
c:\sdfix\apps\legacy.txt
c:\sdfix\apps\legacybk.txt
c:\sdfix\apps\Rem.txt
c:\sdfix\apps\Rem2.txt
c:\sdfix\apps\Replace\w2k\AUTOEXEC.NT
c:\sdfix\apps\Replace\w2k\CONFIG.NT
c:\sdfix\apps\Replace\xp\AUTOEXEC.NT
c:\sdfix\apps\Replace\xp\CONFIG.NT
c:\sdfix\apps\srv2.txt
c:\sdfix\apps\srv2bk.txt
c:\sdfix\apps\svc.txt
c:\sdfix\apps\svcbk.txt
c:\sdfix\SDFIX_ReadMe_Online.url
c:\Spybot - Search & Destroy
c:\spybot - search & destroy\Dummies\dummy.dap.gif
c:\spybot - search & destroy\Dummies\dummy.data.xml
c:\spybot - search & destroy\Dummies\dummy.default.gif
c:\spybot - search & destroy\Dummies\dummy.related.htm
c:\spybot - search & destroy\Help\Brasil.license.txt
c:\spybot - search & destroy\Help\Cesky.license.txt
c:\spybot - search & destroy\Help\Deutsch.license.txt
c:\spybot - search & destroy\Help\English.chm
c:\spybot - search & destroy\Help\English.license.txt
c:\spybot - search & destroy\Help\Espanol.license.txt
c:\spybot - search & destroy\Help\Francais.license.txt
c:\spybot - search & destroy\Help\Hellenic.license.txt
c:\spybot - search & destroy\Help\Italiano.license.txt
c:\spybot - search & destroy\Help\Japanese.license.ansi.txt
c:\spybot - search & destroy\Help\Japanese.license.txt
c:\spybot - search & destroy\Help\Korean.license.txt
c:\spybot - search & destroy\Help\Nederlands.license.txt
c:\spybot - search & destroy\Help\Polski.license.txt
c:\spybot - search & destroy\Help\Russkiy.license.txt
c:\spybot - search & destroy\Help\Slovensky.license.txt
c:\spybot - search & destroy\Help\Srpski.license.txt
c:\spybot - search & destroy\Help\Suomi.license.txt
c:\spybot - search & destroy\Includes\Adware.sbi
c:\spybot - search & destroy\Includes\AdwareC.sbi
c:\spybot - search & destroy\Includes\Browserpages.sbs
c:\spybot - search & destroy\Includes\CLSIDs.sbs
c:\spybot - search & destroy\Includes\Cookies.sbi
c:\spybot - search & destroy\Includes\Cookies.sbs
c:\spybot - search & destroy\Includes\Dialer.sbi
c:\spybot - search & destroy\Includes\Dialer.sbs
c:\spybot - search & destroy\Includes\DialerC.sbi
c:\spybot - search & destroy\Includes\Domains.sbs
c:\spybot - search & destroy\Includes\HeavyDuty.sbi
c:\spybot - search & destroy\Includes\Hijackers.sbi
c:\spybot - search & destroy\Includes\HijackersC.sbi
c:\spybot - search & destroy\Includes\iPhone.sbi
c:\spybot - search & destroy\Includes\Keyloggers.sbi
c:\spybot - search & destroy\Includes\KeyloggersC.sbi
c:\spybot - search & destroy\Includes\Logs.uts
c:\spybot - search & destroy\Includes\LSP.sbi
c:\spybot - search & destroy\Includes\LSP.sbs
c:\spybot - search & destroy\Includes\Malware.sbi
c:\spybot - search & destroy\Includes\MalwareC.sbi
c:\spybot - search & destroy\Includes\OperaPlugins.sbs
c:\spybot - search & destroy\Includes\ProcWatch.sbs
c:\spybot - search & destroy\Includes\PUPS.sbi
c:\spybot - search & destroy\Includes\PUPSC.sbi
c:\spybot - search & destroy\Includes\RegWatch.sbs
c:\spybot - search & destroy\Includes\RegXLinks.sbs
c:\spybot - search & destroy\Includes\Revision.sbi
c:\spybot - search & destroy\Includes\Revision.sbs
c:\spybot - search & destroy\Includes\Searchpages.sbs
c:\spybot - search & destroy\Includes\Security.sbi
c:\spybot - search & destroy\Includes\SecurityC.sbi
c:\spybot - search & destroy\Includes\Services.sbs
c:\spybot - search & destroy\Includes\Spybots.sbi
c:\spybot - search & destroy\Includes\SpybotsC.sbi
c:\spybot - search & destroy\Includes\Spyware.sbi
c:\spybot - search & destroy\Includes\SpywareC.sbi
c:\spybot - search & destroy\Includes\Startup.tnfo
c:\spybot - search & destroy\Includes\Tracks.uti
c:\spybot - search & destroy\Includes\Trojans.sbi
c:\spybot - search & destroy\Includes\TrojansC-02.sbi
c:\spybot - search & destroy\Includes\TrojansC-03.sbi
c:\spybot - search & destroy\Includes\TrojansC-04.sbi
c:\spybot - search & destroy\Includes\TrojansC-05.sbi
c:\spybot - search & destroy\Includes\TrojansC.sbi
c:\spybot - search & destroy\Includes\TTLASSH.sbs
c:\spybot - search & destroy\Includes\URL-Blacklist.sbs
c:\spybot - search & destroy\Includes\X509White.sbs
c:\spybot - search & destroy\Languages\Afrikaans.sbl
c:\spybot - search & destroy\Languages\Arabic.sbl
c:\spybot - search & destroy\Languages\Azeri.sbl
c:\spybot - search & destroy\Languages\Bahasa Indonesia.sbl
c:\spybot - search & destroy\Languages\Belarusskiy.sbl
c:\spybot - search & destroy\Languages\Bosanski.sbl
c:\spybot - search & destroy\Languages\Brasil.sbl
c:\spybot - search & destroy\Languages\Bulgarski.sbl
c:\spybot - search & destroy\Languages\Catalan.sbl
c:\spybot - search & destroy\Languages\Cesky.sbl
c:\spybot - search & destroy\Languages\Dansk.sbl
c:\spybot - search & destroy\Languages\Deutsch.sbl
c:\spybot - search & destroy\Languages\Eesti.sbl
c:\spybot - search & destroy\Languages\English.sbl
c:\spybot - search & destroy\Languages\Espanol.sbl
c:\spybot - search & destroy\Languages\Esperanto.sbl
c:\spybot - search & destroy\Languages\Euskera.sbl
c:\spybot - search & destroy\Languages\Farsi.sbl
c:\spybot - search & destroy\Languages\Francais.sbl
c:\spybot - search & destroy\Languages\Furlan.sbl
c:\spybot - search & destroy\Languages\Galego.sbl
c:\spybot - search & destroy\Languages\Hebrew.sbl
c:\spybot - search & destroy\Languages\Hellenic.sbl
c:\spybot - search & destroy\Languages\Hindi.sbl
c:\spybot - search & destroy\Languages\Hrvatski.sbl
c:\spybot - search & destroy\Languages\Chinese (simplified).sbl
c:\spybot - search & destroy\Languages\Chinese (traditional).sbl
c:\spybot - search & destroy\Languages\Islenska.sbl
c:\spybot - search & destroy\Languages\Italiano.sbl
c:\spybot - search & destroy\Languages\Japanese.sbl
c:\spybot - search & destroy\Languages\Korean.sbl
c:\spybot - search & destroy\Languages\Latvian.sbl
c:\spybot - search & destroy\Languages\Letzebuergesch.sbl
c:\spybot - search & destroy\Languages\Lietuviu.sbl
c:\spybot - search & destroy\Languages\Magyar.sbl
c:\spybot - search & destroy\Languages\Makedonski.sbl
c:\spybot - search & destroy\Languages\Melayu.sbl
c:\spybot - search & destroy\Languages\Nederlands.sbl
c:\spybot - search & destroy\Languages\Norsk.sbl
c:\spybot - search & destroy\Languages\Polski.sbl
c:\spybot - search & destroy\Languages\Portugues.sbl
c:\spybot - search & destroy\Languages\Romaneste.sbl
c:\spybot - search & destroy\Languages\Russkiy.sbl
c:\spybot - search & destroy\Languages\Shqip.sbl
c:\spybot - search & destroy\Languages\Slovenscina.sbl
c:\spybot - search & destroy\Languages\Slovensky.sbl
c:\spybot - search & destroy\Languages\Srpski.sbl
c:\spybot - search & destroy\Languages\Suomi.sbl
c:\spybot - search & destroy\Languages\Svenska.sbl
c:\spybot - search & destroy\Languages\Thai.sbl
c:\spybot - search & destroy\Languages\Turkce.sbl
c:\spybot - search & destroy\Languages\Ukrainian.sbl
c:\spybot - search & destroy\Languages\Uzbek.sbl
c:\spybot - search & destroy\messages.zres
c:\spybot - search & destroy\Skins\Italia.jpg
c:\spybot - search & destroy\Skins\Peace.jpg
c:\spybot - search & destroy\unins000.dat
c:\spybot - search & destroy\unins000.msg
c:\spybot - search & destroy\Updates\advcheck165.zip
c:\spybot - search & destroy\Updates\clsid.zip
c:\spybot - search & destroy\Updates\online.ini.uiz
c:\spybot - search & destroy\Updates\teatimer166.zip
c:\users\Daniela\AppData\Roaming\TrojanHunter
c:\users\Daniela\AppData\Roaming\TrojanHunter\TreeState.dat
c:\windows\av_ico
c:\windows\av_ico\ico_avast_desktop.ico
c:\windows\av_ico\ico_avast_start.ico
c:\windows\av_ico\ico_defender_start.ico
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
c:\windows\ufa
c:\windows\ufa\ufa.exe
c:\windows\unrar.exe
c:\windows\update.tray-15-0-lnk
c:\windows\update.tray-15-0-lnk\svchost.exe
c:\windows\update.tray-15-0
c:\windows\update.tray-7-0-lnk
c:\windows\update.tray-7-0
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_A2ACC
-------\Legacy_A2INJECTIONDRIVER
-------\Legacy_A2UTIL
-------\Service_a2acc
-------\Service_a2AntiMalware
-------\Service_a2injectiondriver
-------\Service_a2util
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_ICQ Service
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-03 do 2011-08-03 )))))))))))))))))))))))))))))))
.
.
2011-08-03 22:51 . 2011-08-03 22:51 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-02 21:26 . 2011-07-13 04:53 8578896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3CBACF8F-094D-4267-9026-A64AC32114B4}\mpengine.dll
2011-08-01 17:48 . 2011-08-01 17:48 -------- d-----w- c:\users\Daniela\AppData\Local\Clicks
2011-08-01 17:48 . 2011-08-03 07:15 -------- d-----w- c:\program files (x86)\Super Klikacz
2011-08-01 17:47 . 2011-08-03 07:15 -------- d-----w- c:\users\Daniela\AppData\Local\ALLPlayer
2011-08-01 17:47 . 2011-08-03 07:15 -------- d-----w- c:\program files (x86)\ALLPlayer
2011-08-01 16:38 . 2011-08-01 16:38 -------- d-----w- c:\users\Daniela\AppData\Roaming\Malwarebytes
2011-08-01 16:38 . 2011-08-03 06:42 -------- d-----w- c:\programdata\Malwarebytes
2011-08-01 16:38 . 2011-08-03 07:15 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-07-31 22:01 . 2011-08-03 07:15 -------- d-----w- c:\program files\trend micro
2011-07-31 22:01 . 2011-07-31 22:09 -------- d-----w- C:\rsit
2011-07-31 21:45 . 2011-08-03 06:41 -------- d-----w- C:\_OTL
2011-07-31 20:46 . 2011-08-03 06:42 -------- d-----w- c:\program files\Java
2011-07-31 11:43 . 2011-07-31 11:43 -------- d-----w- c:\program files (x86)\Common Files\Java
2011-07-31 11:43 . 2011-07-31 11:42 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-07-31 11:41 . 2011-07-31 11:41 -------- d-----w- c:\program files (x86)\Java
2011-07-30 22:46 . 2011-07-30 22:46 -------- d-----w- c:\users\Daniela\AppData\Local\Mozilla
2011-07-30 21:42 . 2011-07-04 11:32 22360 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-07-30 21:42 . 2011-07-04 11:36 288088 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-07-30 21:41 . 2011-07-04 11:32 31064 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-07-30 21:41 . 2011-07-04 11:35 45400 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-07-30 21:41 . 2011-07-04 11:36 600920 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-07-30 21:41 . 2011-07-04 11:32 64856 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-07-30 21:40 . 2011-07-04 11:43 40112 ----a-w- c:\windows\avastSS.scr
2011-07-30 21:40 . 2011-07-04 11:43 199304 ----a-w- c:\windows\SysWow64\aswBoot.exe
2011-07-30 14:12 . 2011-07-30 14:12 -------- d-----w- c:\users\Daniela\AppData\Local\Opera
2011-07-30 14:11 . 2011-07-30 21:56 -------- d-----w- c:\program files (x86)\Opera
2011-07-30 12:40 . 2011-07-30 12:40 -------- d-----w- c:\programdata\AVAST Software
2011-07-30 12:40 . 2011-07-30 12:40 -------- d-----w- c:\program files\AVAST Software
2011-07-29 19:49 . 2011-07-29 19:49 -------- d--h--w- c:\windows\AxInstSV
2011-07-28 17:58 . 2011-07-30 10:52 -------- d-----w- c:\programdata\Alwil Software
2011-07-13 14:08 . 2011-06-02 06:39 422400 ----a-w- c:\windows\system32\KernelBase.dll
2011-07-13 14:06 . 2011-06-11 02:56 3134464 ----a-w- c:\windows\system32\win32k.sys
2011-07-13 14:05 . 2011-06-02 06:45 362496 ----a-w- c:\windows\system32\wow64win.dll
2011-07-13 14:05 . 2011-06-02 06:44 214528 ----a-w- c:\windows\system32\winsrv.dll
2011-07-13 14:05 . 2011-06-02 06:35 338944 ----a-w- c:\windows\system32\conhost.exe
2011-07-13 14:05 . 2011-06-02 06:45 243200 ----a-w- c:\windows\system32\wow64.dll
2011-07-13 14:05 . 2011-06-02 05:56 25600 ----a-w- c:\windows\SysWow64\setup16.exe
2011-07-13 14:05 . 2011-06-02 06:42 16384 ----a-w- c:\windows\system32\ntvdm64.dll
2011-07-13 14:05 . 2011-06-02 05:59 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll
2011-07-13 14:05 . 2011-06-02 06:45 13312 ----a-w- c:\windows\system32\wow64cpu.dll
2011-07-13 14:05 . 2011-06-02 03:51 7680 ----a-w- c:\windows\SysWow64\instnm.exe
2011-07-13 14:05 . 2011-06-02 05:54 5120 ----a-w- c:\windows\SysWow64\wow32.dll
2011-07-13 14:04 . 2011-06-02 03:50 2048 ----a-w- c:\windows\SysWow64\user.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-04 11:43 . 2011-02-27 11:52 253888 ----a-w- c:\windows\system32\aswBoot.exe
2011-06-30 18:52 . 2011-06-30 11:49 2829 ----a-w- c:\windows\War3Unin.pif
2011-06-30 18:52 . 2011-06-30 11:49 139264 ----a-w- c:\windows\War3Unin.exe
2011-06-08 16:35 . 2011-06-08 16:35 33344 ----a-w- c:\windows\system32\drivers\hamachi.sys
2011-06-02 05:56 . 2011-07-13 14:05 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-05-28 03:25 . 2011-06-16 15:05 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-05-28 03:00 . 2011-06-16 15:05 1638912 ----a-w- c:\windows\SysWow64\mshtml.tlb
2011-05-24 17:14 . 2010-05-27 05:50 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-05-24 11:21 . 2011-06-29 09:27 404992 ----a-w- c:\windows\system32\umpnpmgr.dll
2011-05-24 10:34 . 2011-06-29 09:27 64512 ----a-w- c:\windows\SysWow64\devobj.dll
2011-05-24 10:34 . 2011-06-29 09:27 44544 ----a-w- c:\windows\SysWow64\devrtl.dll
2011-05-24 10:34 . 2011-06-29 09:27 145920 ----a-w- c:\windows\SysWow64\cfgmgr32.dll
2011-05-24 10:32 . 2011-06-29 09:27 252928 ----a-w- c:\windows\SysWow64\drvinst.exe
.
.
((((((((((((((((((((((((((((( SnapShot@2011-08-03_21.04.27 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-07-14 04:54 . 2011-08-03 21:04 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2011-08-03 22:54 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2011-08-03 22:54 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-08-03 21:04 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-08-03 21:04 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-08-03 22:54 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-05-27 05:25 . 2011-08-03 21:05 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-05-27 05:25 . 2011-08-03 20:44 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-05-27 05:25 . 2011-08-03 20:44 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-05-27 05:25 . 2011-08-03 21:05 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-05-27 05:25 . 2011-08-03 20:44 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-05-27 05:25 . 2011-08-03 21:05 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-05-27 05:29 . 2011-08-03 22:00 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-05-27 05:29 . 2011-08-03 20:44 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-05-27 05:29 . 2011-08-03 22:00 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-05-27 05:29 . 2011-08-03 20:44 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-08-03 22:53 . 2011-08-03 22:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-08-03 21:02 . 2011-08-03 21:02 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-08-03 22:53 . 2011-08-03 22:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-08-03 21:02 . 2011-08-03 21:02 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 05:01 . 2011-08-03 21:01 390348 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2011-08-03 22:52 390348 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 02:34 . 2011-08-03 21:12 10485760 c:\windows\system32\SMI\Store\Machine\schema.dat
- 2009-07-14 02:34 . 2011-08-03 20:52 10485760 c:\windows\system32\SMI\Store\Machine\schema.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-11-29 14:26 3908192 ----a-w- c:\program files (x86)\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files (x86)\ConduitEngine\ConduitEngine.dll" [2010-11-29 3908192]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-07-04 11:43 134384 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF21985.cfxxe" [X]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.seznam.cz/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: WikiKomentáře Google... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files (x86)\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
FF - ProfilePath - c:\users\Daniela\AppData\Roaming\Mozilla\Firefox\Profiles\db4lnk7y.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - (no file)
Toolbar-{a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
AddRemove-Emsisoft Anti-Malware_is1 - c:\program files (x86)\Emsisoft Anti-Malware\unins000.exe
AddRemove-ICQToolbar - c:\program files (x86)\ICQ6Toolbar\ICQUnToolbar.exe
.
.
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
.
**************************************************************************
.
Celkový čas: 2011-08-04 01:04:28 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-08-03 23:04
ComboFix2.txt 2011-08-03 21:18
.
Před spuštěním: Volných bajtů: 65 398 317 056
Po spuštění: Volných bajtů: 65 579 429 888
.
- - End Of File - - 2AFF19007142B7AC3A9C2F7543B28339
Re: Vir Facebook prosim o pomoc
No ale zkusebni doba NODu (30 dni) jiz vyprsela ze
Odinstalujte Combofix
T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
OTC http://oldtimer.geekstogo.com/OTC.exe
TFC http://oldtimer.geekstogo.com/TFC.exe
Stahnete Ccleaner (viz muj podpis)
Panel čistič
v nouzovem rezimu (restart PC, mackat F8, zvolit Stav nouze s praci v siti) projedte PC timto utilitami at se zbavime zbytku poskozeneho antiviru http://files.avast.com/files/eng/aswclear.exe
Nainstalujte Avast free http://www.avast.com/cs-cz/free-antivirus-download
Napiste co PC a dejte novy log z RSIT
- Prejmenujte ComboFix na Uninstall
- Spustte jej
- Tohle smaze Combofix a jeho slozky
- Stahnete a spustte
- Pro potvrzeni volby mackejte A, Enter
- Po pouziti utilitu smazte
- Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
- Stahnete a spustte
- Kliknete na CleanUp a potvrdte YES
- Program uklidi a restartuje PC
- Stahnete a spustte
- Kliknete na Start a potvrdte OK
- Program uklidi a restartuje pc
- Po pouziti utilitu smazte
Panel čistič
- Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
- dejte Hledej problémy
- nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
- postup opakujte dokud nebude bez problemu - vetsinou cca 3x
- Zde muzete odinstalovat nepotrebne programy
Re: Vir Facebook prosim o pomoc
Logfile of random's system information tool 1.09 (written by random/random)
Run by Daniela at 2011-08-04 20:49:48
Microsoft Windows 7 Ultimate
System drive C: has 70 GB (46%) free of 153 GB
Total RAM: 895 MB (18% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:49:59, on 4.8.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Opera\opera.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\trend micro\Daniela.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - (no file)
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: (no name) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - (no file)
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
O3 - Toolbar: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - (no file)
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files (x86)\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files (x86)\ICQ7.5\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\nwprovau.dll' missing
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 7124 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\svchost.exe -k NetworkService
taskeng.exe {DD60F4E0-C8AC-41A1-8F0D-CDD90AECCD9E}
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files (x86)\Bonjour\mDNSResponder.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\tcpsvcs.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-162a4eca-f935-43de-af7d-011efc267c4b -SystemEventPortName:HostProcess-8b7ebfa7-7d87-4b66-8b8f-616be97593c2 -IoCancelEventPortName:HostProcess-2f1e86f4-1e2b-4487-b1c2-dd33c54e418a -NonStateChangingEventPortName:HostProcess-db51c080-4375-46e3-8a76-ecdf6e856680 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:67ffc9bc-76ab-4ab2-9ee1-0f40e3617d1b
"taskhost.exe"
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Opera\opera.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Windows\system32\wuauclt.exe"
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /welcome
"C:\Users\Daniela\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\Daniela\AppData\Roaming\Mozilla\Firefox\Profiles\db4lnk7y.default
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 9
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-07-04 978496]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll [2010-11-29 3908192]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-07-04 820864]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-07-31 42272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17}
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-07-04 978496]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}
{30F9B915-B755-4826-820B-08FBA6BD249D} - Conduit Engine - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll [2010-11-29 3908192]
{855F3B16-6D32-4FE6-8A56-BBB695989046}
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-07-04 820864]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\a-squared]
C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2guard.exe /d=60 []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast]
C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-07-04 3493720]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-07-04 3493720]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2009-07-14 290304]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableSecureUIAPaths"=0
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun "=0
"NoViewContextMenu "=0
"NoDriveTypeAutoRun"=0
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2011-08-04 20:49:48 ----D---- C:\rsit
2011-08-04 20:39:06 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2011-08-04 20:39:04 ----A---- C:\Windows\system32\drivers\aswSP.sys
2011-08-04 20:38:55 ----A---- C:\Windows\system32\drivers\aswRdr.sys
2011-08-04 20:38:53 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2011-08-04 20:38:48 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2011-08-04 20:38:45 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2011-08-04 20:38:44 ----A---- C:\Windows\system32\aswBoot.exe
2011-08-04 01:04:37 ----D---- C:\Windows\temp
2011-08-04 00:54:43 ----D---- C:\$RECYCLE.BIN
2011-08-03 22:35:34 ----D---- C:\Windows\ERDNT
2011-08-01 19:48:45 ----D---- C:\Program Files (x86)\Super Klikacz
2011-08-01 19:47:34 ----D---- C:\Program Files (x86)\ALLPlayer
2011-08-01 18:38:41 ----D---- C:\Users\Daniela\AppData\Roaming\Malwarebytes
2011-08-01 18:38:27 ----D---- C:\ProgramData\Malwarebytes
2011-08-01 18:38:23 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-08-01 00:01:24 ----D---- C:\Program Files\trend micro
2011-07-31 22:46:41 ----D---- C:\Program Files\Java
2011-07-31 13:43:35 ----D---- C:\ProgramData\Sun
2011-07-31 13:43:00 ----A---- C:\Windows\SYSWOW64\javaws.exe
2011-07-31 13:43:00 ----A---- C:\Windows\SYSWOW64\javaw.exe
2011-07-31 13:43:00 ----A---- C:\Windows\SYSWOW64\deployJava1.dll
2011-07-31 13:42:59 ----A---- C:\Windows\SYSWOW64\java.exe
2011-07-31 13:41:39 ----D---- C:\Program Files (x86)\Java
2011-07-31 00:46:04 ----A---- C:\Windows\nsreg.dat
2011-07-31 00:45:32 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-07-30 23:40:12 ----A---- C:\Windows\avastSS.scr
2011-07-30 23:40:05 ----A---- C:\Windows\SYSWOW64\aswBoot.exe
2011-07-30 16:12:13 ----D---- C:\Users\Daniela\AppData\Roaming\Opera
2011-07-30 16:11:05 ----D---- C:\Program Files (x86)\Opera
2011-07-30 14:40:04 ----D---- C:\ProgramData\AVAST Software
2011-07-30 14:40:03 ----D---- C:\Program Files\AVAST Software
2011-07-29 21:49:43 ----HD---- C:\Windows\AxInstSV
2011-07-28 19:58:02 ----D---- C:\ProgramData\Alwil Software
2011-07-28 19:29:39 ----A---- C:\index.ini
2011-07-13 16:08:09 ----A---- C:\Windows\system32\KernelBase.dll
2011-07-13 16:07:59 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2011-07-13 16:07:54 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-07-13 16:07:53 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2011-07-13 16:07:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2011-07-13 16:07:33 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-07-13 16:07:33 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-07-13 16:07:33 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-13 16:07:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2011-07-13 16:07:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2011-07-13 16:07:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-07-13 16:07:32 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2011-07-13 16:07:32 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2011-07-13 16:07:32 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2011-07-13 16:07:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2011-07-13 16:07:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2011-07-13 16:07:31 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-07-13 16:07:31 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2011-07-13 16:07:31 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2011-07-13 16:07:30 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2011-07-13 16:07:30 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2011-07-13 16:07:30 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2011-07-13 16:07:30 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2011-07-13 16:07:30 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2011-07-13 16:07:30 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2011-07-13 16:07:30 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2011-07-13 16:07:29 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2011-07-13 16:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2011-07-13 16:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2011-07-13 16:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2011-07-13 16:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2011-07-13 16:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2011-07-13 16:07:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2011-07-13 16:07:25 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2011-07-13 16:07:25 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2011-07-13 16:07:25 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2011-07-13 16:07:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2011-07-13 16:07:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2011-07-13 16:07:24 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2011-07-13 16:07:23 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2011-07-13 16:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2011-07-13 16:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2011-07-13 16:07:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2011-07-13 16:07:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2011-07-13 16:07:22 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2011-07-13 16:07:22 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2011-07-13 16:07:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2011-07-13 16:07:21 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2011-07-13 16:07:20 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2011-07-13 16:07:20 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2011-07-13 16:07:19 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2011-07-13 16:07:19 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-13 16:07:19 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-07-13 16:07:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2011-07-13 16:07:17 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2011-07-13 16:07:17 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2011-07-13 16:07:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2011-07-13 16:07:16 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2011-07-13 16:06:29 ----A---- C:\Windows\system32\win32k.sys
2011-07-13 16:05:46 ----A---- C:\Windows\system32\kernel32.dll
2011-07-13 16:05:45 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2011-07-13 16:05:43 ----A---- C:\Windows\system32\wow64win.dll
2011-07-13 16:05:43 ----A---- C:\Windows\system32\winsrv.dll
2011-07-13 16:05:43 ----A---- C:\Windows\system32\conhost.exe
2011-07-13 16:05:36 ----A---- C:\Windows\SYSWOW64\setup16.exe
2011-07-13 16:05:36 ----A---- C:\Windows\system32\wow64.dll
2011-07-13 16:05:33 ----A---- C:\Windows\system32\ntvdm64.dll
2011-07-13 16:05:31 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2011-07-13 16:05:27 ----A---- C:\Windows\system32\wow64cpu.dll
2011-07-13 16:05:25 ----A---- C:\Windows\SYSWOW64\instnm.exe
2011-07-13 16:05:24 ----A---- C:\Windows\SYSWOW64\wow32.dll
2011-07-13 16:04:58 ----A---- C:\Windows\SYSWOW64\user.exe
======List of files/folders modified in the last 1 month======
2011-08-04 20:41:06 ----D---- C:\Windows\system32\config
2011-08-04 20:39:06 ----D---- C:\Windows\system32\drivers
2011-08-04 20:38:44 ----D---- C:\Windows\System32
2011-08-04 20:38:36 ----SHD---- C:\Windows\Installer
2011-08-04 20:38:09 ----D---- C:\Windows
2011-08-04 20:38:08 ----D---- C:\Windows\SysWOW64
2011-08-04 20:37:55 ----SHD---- C:\System Volume Information
2011-08-04 20:29:32 ----D---- C:\Windows\system32\catroot2
2011-08-04 00:54:53 ----A---- C:\Windows\system.ini
2011-08-04 00:54:35 ----D---- C:\Windows\system32\drivers\etc
2011-08-04 00:50:09 ----D---- C:\ProgramData
2011-08-04 00:50:08 ----RD---- C:\Program Files (x86)
2011-08-04 00:50:08 ----RD---- C:\Program Files
2011-08-04 00:50:05 ----D---- C:\Windows\Tasks
2011-08-04 00:44:37 ----D---- C:\Windows\SYSWOW64\drivers
2011-08-04 00:44:37 ----D---- C:\Windows\AppPatch
2011-08-04 00:44:35 ----D---- C:\Program Files\Common Files
2011-08-04 00:44:35 ----D---- C:\Program Files (x86)\Common Files
2011-08-03 22:14:43 ----D---- C:\Windows\system32\Tasks
2011-08-03 09:15:33 ----D---- C:\Windows\winsxs
2011-08-03 09:15:33 ----D---- C:\Windows\system32\wfp
2011-08-03 09:15:33 ----D---- C:\Windows\system32\DriverStore
2011-08-03 09:15:33 ----D---- C:\Windows\system32\cs-CZ
2011-08-03 09:15:33 ----D---- C:\Windows\system32\CodeIntegrity
2011-08-03 09:15:32 ----D---- C:\Program Files (x86)\ConduitEngine
2011-08-03 09:14:35 ----D---- C:\Windows\registration
2011-08-03 09:14:22 ----RD---- C:\Users
2011-08-03 09:14:17 ----D---- C:\Users\Daniela\AppData\Roaming\Skype
2011-08-03 09:14:02 ----D---- C:\ProgramData\Easybits GO
2011-08-03 00:58:35 ----D---- C:\Windows\rescache
2011-08-03 00:49:10 ----D---- C:\Windows\Prefetch
2011-08-02 00:02:52 ----D---- C:\Users\Daniela\AppData\Roaming\go
2011-08-01 07:37:03 ----D---- C:\Windows\system32\wbem
2011-07-31 21:48:57 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-07-31 21:48:56 ----D---- C:\Windows\inf
2011-07-31 09:21:11 ----D---- C:\ProgramData\PMB Files
2011-07-31 09:21:10 ----D---- C:\Program Files (x86)\ICQ7.5
2011-07-31 01:02:47 ----D---- C:\Windows\system32\en-US
2011-07-31 00:49:27 ----D---- C:\Windows\system32\NDF
2011-07-31 00:46:13 ----D---- C:\Users\Daniela\AppData\Roaming\Mozilla
2011-07-30 23:34:27 ----D---- C:\Program Files\Internet Explorer
2011-07-30 23:34:27 ----D---- C:\Program Files (x86)\Internet Explorer
2011-07-30 12:54:40 ----D---- C:\Windows\system32\drivers\UMDF
2011-07-30 12:54:33 ----D---- C:\ProgramData\Adobe
2011-07-30 12:54:32 ----D---- C:\Program Files\Bonjour
2011-07-30 12:54:30 ----D---- C:\Program Files (x86)\Bonjour
2011-07-30 12:54:02 ----D---- C:\Windows\system32\catroot
2011-07-30 12:52:42 ----SD---- C:\Users\Daniela\AppData\Roaming\Microsoft
2011-07-30 12:52:36 ----SD---- C:\ProgramData\Microsoft
2011-07-30 03:40:48 ----RSD---- C:\Windows\assembly
2011-07-30 03:40:48 ----D---- C:\Windows\Microsoft.NET
2011-07-29 21:20:58 ----D---- C:\ProgramData\NVIDIA
2011-07-28 19:44:37 ----D---- C:\Users\Daniela\AppData\Roaming\uTorrent
2011-07-28 03:11:49 ----D---- C:\Windows\SYSWOW64\en-US
2011-07-28 03:11:14 ----D---- C:\Program Files (x86)\Microsoft.NET
2011-07-27 22:33:23 ----D---- C:\programy
2011-07-27 22:12:10 ----D---- C:\Windows\debug
2011-07-22 16:11:51 ----D---- C:\Users\Daniela\AppData\Roaming\ICQ
2011-07-21 21:15:10 ----D---- C:\Windows\Logs
2011-07-20 07:05:23 ----D---- C:\ProgramData\DAEMON Tools Lite
2011-07-13 16:24:28 ----A---- C:\Windows\system32\MRT.exe
2011-07-13 16:24:23 ----D---- C:\ProgramData\Microsoft Help
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 nvstor64;nvstor64; C:\Windows\system32\DRIVERS\nvstor64.sys [2009-06-22 240672]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-05-27 834544]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-07-04 31064]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-07-04 288088]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-07-04 45400]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-01-26 254528]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-07-04 22360]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-07-04 64856]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 34152]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-08-04 1973792]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
S1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-07-04 600920]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2011-06-08 33344]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 TFsExDisk;TFsExDisk; \??\C:\Windows\System32\Drivers\TFsExDisk.sys []
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2011-02-18 51712]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2011-02-18 37664]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-07-04 42184]
R2 Bonjour Service;Bonjour Service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2010-10-07 345376]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-09-27 383592]
R2 simptcp;@%SystemRoot%\system32\simptcp.dll,-200; C:\Windows\System32\tcpsvcs.exe [2009-07-14 10240]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2011-03-07 934176]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-05-27 1255736]
-----------------EOF-----------------
Run by Daniela at 2011-08-04 20:49:48
Microsoft Windows 7 Ultimate
System drive C: has 70 GB (46%) free of 153 GB
Total RAM: 895 MB (18% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:49:59, on 4.8.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Opera\opera.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\trend micro\Daniela.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - (no file)
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: (no name) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - (no file)
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
O3 - Toolbar: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - (no file)
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files (x86)\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files (x86)\ICQ7.5\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\nwprovau.dll' missing
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 7124 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\svchost.exe -k NetworkService
taskeng.exe {DD60F4E0-C8AC-41A1-8F0D-CDD90AECCD9E}
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files (x86)\Bonjour\mDNSResponder.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\tcpsvcs.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-162a4eca-f935-43de-af7d-011efc267c4b -SystemEventPortName:HostProcess-8b7ebfa7-7d87-4b66-8b8f-616be97593c2 -IoCancelEventPortName:HostProcess-2f1e86f4-1e2b-4487-b1c2-dd33c54e418a -NonStateChangingEventPortName:HostProcess-db51c080-4375-46e3-8a76-ecdf6e856680 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:67ffc9bc-76ab-4ab2-9ee1-0f40e3617d1b
"taskhost.exe"
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Opera\opera.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Windows\system32\wuauclt.exe"
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /welcome
"C:\Users\Daniela\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\Daniela\AppData\Roaming\Mozilla\Firefox\Profiles\db4lnk7y.default
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 9
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-07-04 978496]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll [2010-11-29 3908192]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-07-04 820864]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-07-31 42272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17}
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-07-04 978496]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}
{30F9B915-B755-4826-820B-08FBA6BD249D} - Conduit Engine - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll [2010-11-29 3908192]
{855F3B16-6D32-4FE6-8A56-BBB695989046}
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-07-04 820864]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\a-squared]
C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2guard.exe /d=60 []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast]
C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-07-04 3493720]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-07-04 3493720]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2009-07-14 290304]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableSecureUIAPaths"=0
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun "=0
"NoViewContextMenu "=0
"NoDriveTypeAutoRun"=0
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2011-08-04 20:49:48 ----D---- C:\rsit
2011-08-04 20:39:06 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2011-08-04 20:39:04 ----A---- C:\Windows\system32\drivers\aswSP.sys
2011-08-04 20:38:55 ----A---- C:\Windows\system32\drivers\aswRdr.sys
2011-08-04 20:38:53 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2011-08-04 20:38:48 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2011-08-04 20:38:45 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2011-08-04 20:38:44 ----A---- C:\Windows\system32\aswBoot.exe
2011-08-04 01:04:37 ----D---- C:\Windows\temp
2011-08-04 00:54:43 ----D---- C:\$RECYCLE.BIN
2011-08-03 22:35:34 ----D---- C:\Windows\ERDNT
2011-08-01 19:48:45 ----D---- C:\Program Files (x86)\Super Klikacz
2011-08-01 19:47:34 ----D---- C:\Program Files (x86)\ALLPlayer
2011-08-01 18:38:41 ----D---- C:\Users\Daniela\AppData\Roaming\Malwarebytes
2011-08-01 18:38:27 ----D---- C:\ProgramData\Malwarebytes
2011-08-01 18:38:23 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-08-01 00:01:24 ----D---- C:\Program Files\trend micro
2011-07-31 22:46:41 ----D---- C:\Program Files\Java
2011-07-31 13:43:35 ----D---- C:\ProgramData\Sun
2011-07-31 13:43:00 ----A---- C:\Windows\SYSWOW64\javaws.exe
2011-07-31 13:43:00 ----A---- C:\Windows\SYSWOW64\javaw.exe
2011-07-31 13:43:00 ----A---- C:\Windows\SYSWOW64\deployJava1.dll
2011-07-31 13:42:59 ----A---- C:\Windows\SYSWOW64\java.exe
2011-07-31 13:41:39 ----D---- C:\Program Files (x86)\Java
2011-07-31 00:46:04 ----A---- C:\Windows\nsreg.dat
2011-07-31 00:45:32 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-07-30 23:40:12 ----A---- C:\Windows\avastSS.scr
2011-07-30 23:40:05 ----A---- C:\Windows\SYSWOW64\aswBoot.exe
2011-07-30 16:12:13 ----D---- C:\Users\Daniela\AppData\Roaming\Opera
2011-07-30 16:11:05 ----D---- C:\Program Files (x86)\Opera
2011-07-30 14:40:04 ----D---- C:\ProgramData\AVAST Software
2011-07-30 14:40:03 ----D---- C:\Program Files\AVAST Software
2011-07-29 21:49:43 ----HD---- C:\Windows\AxInstSV
2011-07-28 19:58:02 ----D---- C:\ProgramData\Alwil Software
2011-07-28 19:29:39 ----A---- C:\index.ini
2011-07-13 16:08:09 ----A---- C:\Windows\system32\KernelBase.dll
2011-07-13 16:07:59 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2011-07-13 16:07:54 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-07-13 16:07:53 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2011-07-13 16:07:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2011-07-13 16:07:33 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-07-13 16:07:33 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-07-13 16:07:33 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-13 16:07:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2011-07-13 16:07:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2011-07-13 16:07:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-07-13 16:07:32 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2011-07-13 16:07:32 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2011-07-13 16:07:32 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2011-07-13 16:07:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2011-07-13 16:07:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2011-07-13 16:07:31 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-07-13 16:07:31 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2011-07-13 16:07:31 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2011-07-13 16:07:30 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2011-07-13 16:07:30 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2011-07-13 16:07:30 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2011-07-13 16:07:30 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2011-07-13 16:07:30 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2011-07-13 16:07:30 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2011-07-13 16:07:30 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2011-07-13 16:07:29 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2011-07-13 16:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2011-07-13 16:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2011-07-13 16:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2011-07-13 16:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2011-07-13 16:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2011-07-13 16:07:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2011-07-13 16:07:25 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2011-07-13 16:07:25 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2011-07-13 16:07:25 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2011-07-13 16:07:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2011-07-13 16:07:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2011-07-13 16:07:24 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2011-07-13 16:07:23 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2011-07-13 16:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2011-07-13 16:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2011-07-13 16:07:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2011-07-13 16:07:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2011-07-13 16:07:22 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2011-07-13 16:07:22 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2011-07-13 16:07:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2011-07-13 16:07:21 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2011-07-13 16:07:20 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2011-07-13 16:07:20 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2011-07-13 16:07:19 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2011-07-13 16:07:19 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-13 16:07:19 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-07-13 16:07:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2011-07-13 16:07:17 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2011-07-13 16:07:17 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2011-07-13 16:07:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2011-07-13 16:07:16 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2011-07-13 16:06:29 ----A---- C:\Windows\system32\win32k.sys
2011-07-13 16:05:46 ----A---- C:\Windows\system32\kernel32.dll
2011-07-13 16:05:45 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2011-07-13 16:05:43 ----A---- C:\Windows\system32\wow64win.dll
2011-07-13 16:05:43 ----A---- C:\Windows\system32\winsrv.dll
2011-07-13 16:05:43 ----A---- C:\Windows\system32\conhost.exe
2011-07-13 16:05:36 ----A---- C:\Windows\SYSWOW64\setup16.exe
2011-07-13 16:05:36 ----A---- C:\Windows\system32\wow64.dll
2011-07-13 16:05:33 ----A---- C:\Windows\system32\ntvdm64.dll
2011-07-13 16:05:31 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2011-07-13 16:05:27 ----A---- C:\Windows\system32\wow64cpu.dll
2011-07-13 16:05:25 ----A---- C:\Windows\SYSWOW64\instnm.exe
2011-07-13 16:05:24 ----A---- C:\Windows\SYSWOW64\wow32.dll
2011-07-13 16:04:58 ----A---- C:\Windows\SYSWOW64\user.exe
======List of files/folders modified in the last 1 month======
2011-08-04 20:41:06 ----D---- C:\Windows\system32\config
2011-08-04 20:39:06 ----D---- C:\Windows\system32\drivers
2011-08-04 20:38:44 ----D---- C:\Windows\System32
2011-08-04 20:38:36 ----SHD---- C:\Windows\Installer
2011-08-04 20:38:09 ----D---- C:\Windows
2011-08-04 20:38:08 ----D---- C:\Windows\SysWOW64
2011-08-04 20:37:55 ----SHD---- C:\System Volume Information
2011-08-04 20:29:32 ----D---- C:\Windows\system32\catroot2
2011-08-04 00:54:53 ----A---- C:\Windows\system.ini
2011-08-04 00:54:35 ----D---- C:\Windows\system32\drivers\etc
2011-08-04 00:50:09 ----D---- C:\ProgramData
2011-08-04 00:50:08 ----RD---- C:\Program Files (x86)
2011-08-04 00:50:08 ----RD---- C:\Program Files
2011-08-04 00:50:05 ----D---- C:\Windows\Tasks
2011-08-04 00:44:37 ----D---- C:\Windows\SYSWOW64\drivers
2011-08-04 00:44:37 ----D---- C:\Windows\AppPatch
2011-08-04 00:44:35 ----D---- C:\Program Files\Common Files
2011-08-04 00:44:35 ----D---- C:\Program Files (x86)\Common Files
2011-08-03 22:14:43 ----D---- C:\Windows\system32\Tasks
2011-08-03 09:15:33 ----D---- C:\Windows\winsxs
2011-08-03 09:15:33 ----D---- C:\Windows\system32\wfp
2011-08-03 09:15:33 ----D---- C:\Windows\system32\DriverStore
2011-08-03 09:15:33 ----D---- C:\Windows\system32\cs-CZ
2011-08-03 09:15:33 ----D---- C:\Windows\system32\CodeIntegrity
2011-08-03 09:15:32 ----D---- C:\Program Files (x86)\ConduitEngine
2011-08-03 09:14:35 ----D---- C:\Windows\registration
2011-08-03 09:14:22 ----RD---- C:\Users
2011-08-03 09:14:17 ----D---- C:\Users\Daniela\AppData\Roaming\Skype
2011-08-03 09:14:02 ----D---- C:\ProgramData\Easybits GO
2011-08-03 00:58:35 ----D---- C:\Windows\rescache
2011-08-03 00:49:10 ----D---- C:\Windows\Prefetch
2011-08-02 00:02:52 ----D---- C:\Users\Daniela\AppData\Roaming\go
2011-08-01 07:37:03 ----D---- C:\Windows\system32\wbem
2011-07-31 21:48:57 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-07-31 21:48:56 ----D---- C:\Windows\inf
2011-07-31 09:21:11 ----D---- C:\ProgramData\PMB Files
2011-07-31 09:21:10 ----D---- C:\Program Files (x86)\ICQ7.5
2011-07-31 01:02:47 ----D---- C:\Windows\system32\en-US
2011-07-31 00:49:27 ----D---- C:\Windows\system32\NDF
2011-07-31 00:46:13 ----D---- C:\Users\Daniela\AppData\Roaming\Mozilla
2011-07-30 23:34:27 ----D---- C:\Program Files\Internet Explorer
2011-07-30 23:34:27 ----D---- C:\Program Files (x86)\Internet Explorer
2011-07-30 12:54:40 ----D---- C:\Windows\system32\drivers\UMDF
2011-07-30 12:54:33 ----D---- C:\ProgramData\Adobe
2011-07-30 12:54:32 ----D---- C:\Program Files\Bonjour
2011-07-30 12:54:30 ----D---- C:\Program Files (x86)\Bonjour
2011-07-30 12:54:02 ----D---- C:\Windows\system32\catroot
2011-07-30 12:52:42 ----SD---- C:\Users\Daniela\AppData\Roaming\Microsoft
2011-07-30 12:52:36 ----SD---- C:\ProgramData\Microsoft
2011-07-30 03:40:48 ----RSD---- C:\Windows\assembly
2011-07-30 03:40:48 ----D---- C:\Windows\Microsoft.NET
2011-07-29 21:20:58 ----D---- C:\ProgramData\NVIDIA
2011-07-28 19:44:37 ----D---- C:\Users\Daniela\AppData\Roaming\uTorrent
2011-07-28 03:11:49 ----D---- C:\Windows\SYSWOW64\en-US
2011-07-28 03:11:14 ----D---- C:\Program Files (x86)\Microsoft.NET
2011-07-27 22:33:23 ----D---- C:\programy
2011-07-27 22:12:10 ----D---- C:\Windows\debug
2011-07-22 16:11:51 ----D---- C:\Users\Daniela\AppData\Roaming\ICQ
2011-07-21 21:15:10 ----D---- C:\Windows\Logs
2011-07-20 07:05:23 ----D---- C:\ProgramData\DAEMON Tools Lite
2011-07-13 16:24:28 ----A---- C:\Windows\system32\MRT.exe
2011-07-13 16:24:23 ----D---- C:\ProgramData\Microsoft Help
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 nvstor64;nvstor64; C:\Windows\system32\DRIVERS\nvstor64.sys [2009-06-22 240672]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-05-27 834544]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-07-04 31064]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-07-04 288088]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-07-04 45400]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-01-26 254528]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-07-04 22360]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-07-04 64856]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 34152]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-08-04 1973792]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
S1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-07-04 600920]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2011-06-08 33344]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 TFsExDisk;TFsExDisk; \??\C:\Windows\System32\Drivers\TFsExDisk.sys []
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2011-02-18 51712]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2011-02-18 37664]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-07-04 42184]
R2 Bonjour Service;Bonjour Service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2010-10-07 345376]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-09-27 383592]
R2 simptcp;@%SystemRoot%\system32\simptcp.dll,-200; C:\Windows\System32\tcpsvcs.exe [2009-07-14 10240]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2011-03-07 934176]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-05-27 1255736]
-----------------EOF-----------------



Přispějete na provoz fóra?