Pravdepodobne vírus

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Zpráva
Autor
BuXo
Návštěvník
Návštěvník
Příspěvky: 78
Registrován: 19 Srp 2011 20:27

Pravdepodobne vírus

#1 Příspěvek od BuXo »

Zdravím, mám v PC pravdepodobne vírus, pri kontrole počítača Microsoft Essentials Security sa antivírus sám vypne, pri zapnutí PC vyhadzuje sťahovanie súboru svcchost.exe, prosím o kontrolu logu:


Logfile of random's system information tool 1.09 (written by random/random)
Run by Mato at 2012-08-15 12:37:52
Systém Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 22 GB (22%) free of 100 GB
Total RAM: 2047 MB (55% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:38:09, on 15. 8. 2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\SweetIM\Messenger\SweetIM.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Valve\Steam\Steam.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Diar\Diar.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\GamersFirst\LIVE!\Live.exe
C:\Program Files\Protector by IB\ExtensionUpdaterService.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Documents and Settings\Mato\Application Data\Dropbox\bin\Dropbox.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Pando Networks\Media Booster\PMB.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Documents and Settings\Mato\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Mato\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
D:\RSIT.exe
C:\Program Files\trend micro\Mato.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll
O2 - BHO: Protector by IB Helper - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Protector by IB\Extension32.dll
O2 - BHO: Incredibar.com Helper Object - {6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} - C:\Program Files\Incredibar.com\incredibar\1.5.11.14\bh\incredibar.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: IEExtension.VDownloaderBHO - {7b523e7c-f096-4e36-a0cb-7efeb5c675c1} - mscoree.dll (file missing)
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo\YontooIEClient.dll
O3 - Toolbar: SweetPacks Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: Incredibar Toolbar - {F9639E4A-801B-4843-AEE3-03D9DA199E77} - C:\Program Files\Incredibar.com\incredibar\1.5.11.14\incredibarTlbr.dll
O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [VDownloader] C:\Program Files\VDownloader\VDownloader.exe /silent
O4 - HKLM\..\Run: [Microsoft Windows Service Host!] C:\WINDOWS\explorer.exe "C:\WINDOWS\Config\svcchost.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Mato\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Valve\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [Diar.exe] C:\Program Files\Diar\Diar.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Dropbox.lnk = C:\Documents and Settings\Mato\Application Data\Dropbox\bin\Dropbox.exe
O4 - Global Startup: GamersFirst LIVE!.lnk = C:\Program Files\GamersFirst\LIVE!\Live.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube Download - C:\Documents and Settings\Mato\Application Data\DVDVideoSoftIEHelpers\freeytvdownloader.htm
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Documents and Settings\Mato\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O8 - Extra context menu item: Search the Web - C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 2935436640
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Inkjet Printer/Scanner Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Protector by IB Updater - Unknown owner - C:\Program Files\Protector by IB\ExtensionUpdaterService.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

--
End of file - 10434 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-1078145449-839522115-1007Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-1078145449-839522115-1007UA.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{C3F05B38-74F2-43F3-AC79-E2DA93584543}.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Mato\Application Data\Mozilla\Firefox\Profiles\q2j5jg21.default

"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff
"support@vdownloader.com"=C:\Program Files\VDownloader\Addons\FireFox
"{336D0C35-8A85-403a-B9D2-65C292C39087}"=C:\Program Files\Protector by IB\Firefox


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.3.300.270 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_270.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@gamersfirst.com/LiveLauncher]
"Description"=GamersFirst LIVE! Web Launcher
"Path"=C:\Program Files\GamersFirst\LIVE!\nplivelauncher.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@idsoftware.com/QuakeLive]
"Description"=
"Path"=C:\Documents and Settings\All Users\Application Data\id Software\QuakeLive\npquakezero.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.0]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
ffxtlbr@babylon.com
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files\Mozilla Firefox\searchplugins\
babylon.xml
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-04-04 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B}]
Babylon toolbar helper - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll [2011-08-14 270960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}]
Protector by IB - C:\Program Files\Protector by IB\Extension32.dll [2012-04-24 163328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99}]
Incredibar.com Helper Object - C:\Program Files\Incredibar.com\incredibar\1.5.11.14\bh\incredibar.dll [2012-01-22 261632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2012-04-06 325408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7b523e7c-f096-4e36-a0cb-7efeb5c675c1}]
IEExtension.VDownloaderBHO - C:\WINDOWS\system32\mscoree.dll [2009-11-07 297808]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2012-04-06 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2012-04-06 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
SweetPacks Browser Helper - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2012-01-15 1330480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
Yontoo - C:\Program Files\Yontoo\YontooIEClient.dll [2012-03-27 792864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EEE6C35B-6118-11DC-9C72-001320C79847} - SweetPacks Toolbar for Internet Explorer - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2012-01-15 1330480]
{F9639E4A-801B-4843-AEE3-03D9DA199E77} - Incredibar Toolbar - C:\Program Files\Incredibar.com\incredibar\1.5.11.14\incredibarTlbr.dll [2012-01-22 270336]
{98889811-442D-49dd-99D7-DC866BE87DBC} - Babylon Toolbar - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll [2011-08-14 237680]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2010-10-16 110696]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2010-10-16 13851752]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe []
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-01-03 843712]
"CanonSolutionMenu"=C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [2008-03-10 689488]
"CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2008-03-03 1848648]
"SweetIM"=C:\Program Files\SweetIM\Messenger\SweetIM.exe [2012-01-19 114992]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-01-18 254696]
"APSDaemon"=C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2012-02-20 59240]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2012-03-06 421736]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2012-03-26 931200]
"VDownloader"=C:\Program Files\VDownloader\VDownloader.exe /silent []
"Microsoft Windows Service Host!"=C:\WINDOWS\explorer.exe [2008-04-14 1033728]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Google Update"=C:\Documents and Settings\Mato\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-03-28 116648]
"Steam"=C:\Program Files\Valve\Steam\Steam.exe [2012-08-04 1353080]
"uTorrent"=C:\Program Files\uTorrent\uTorrent.exe [2012-05-19 880496]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2012-02-15 17146504]
"Diar.exe"=C:\Program Files\Diar\Diar.exe [2006-11-01 1523200]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2012-04-17 3671872]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
GamersFirst LIVE!.lnk - C:\Program Files\GamersFirst\LIVE!\Live.exe
McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe

C:\Documents and Settings\Mato\Start Menu\Programs\Startup
Dropbox.lnk - C:\Documents and Settings\Mato\Application Data\Dropbox\bin\Dropbox.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"ConsentPromptBehaviorAdmin"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Documents and Settings\Tomas\My Documents\Stažené soubory\Valve\game.exe"="C:\Documents and Settings\Tomas\My Documents\Stažené soubory\Valve\game.exe:*:Enabled:Game Launcher by Martin.cz"
"C:\Program Files\SopCast\SopCast.exe"="C:\Program Files\SopCast\SopCast.exe:*:Enabled:SopCast Main Application"
"C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe"="C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe:*:Enabled:NEXON_EU_Downloader_Engine"
"C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\netsession_win.exe"="C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\netsession_win.exe:*:Enabled:Akamai NetSession Client"
"C:\Program Files\Outspark\ProjectPowder\Run.exe"="C:\Program Files\Outspark\ProjectPowder\Run.exe:*:Enabled:ProjectPowder"
"C:\Program Files\Sega\Virtua Tennis 4\VT4.exe"="C:\Program Files\Sega\Virtua Tennis 4\VT4.exe:*:Enabled:Virtua Tennis 4™"
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe"="C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service"
"C:\Program Files\Java\jre6\bin\java.exe"="C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\TeamViewer\Version7\TeamViewer.exe"="C:\Program Files\TeamViewer\Version7\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application"
"C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe"="C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe:*:Enabled:Teamviewer Remote Control Service"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Java\jre6\bin\javaw.exe"="C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Documents and Settings\All Users\Application Data\Electronic Arts\Need For Speed World\Data\nfsw.exe"="C:\Documents and Settings\All Users\Application Data\Electronic Arts\Need For Speed World\Data\nfsw.exe:*:Enabled:Need for Speed World"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"D:\The Witcher 2 Enhanced Edition\bin\witcher2.exe"="D:\The Witcher 2 Enhanced Edition\bin\witcher2.exe:*:Enabled:The Witcher 2: Assasins of Kings"
"D:\The Witcher 2 (CZ)\bin\witcher2.exe"="D:\The Witcher 2 (CZ)\bin\witcher2.exe:*:Enabled:The Witcher 2: Assasins of Kings"
"C:\Program Files\Valve\Steam\SteamApps\buxo170\counter-strike\hl.exe"="C:\Program Files\Valve\Steam\SteamApps\buxo170\counter-strike\hl.exe:*:Enabled:Counter-Strike"
"C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe"="C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe:*:Enabled:Ubisoft Game Launcher"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Documents and Settings\Mato\Application Data\GameRanger\GameRanger\GameRanger.exe"="C:\Documents and Settings\Mato\Application Data\GameRanger\GameRanger\GameRanger.exe:*:Enabled:GameRanger"
"C:\WINDOWS\system32\dplaysvr.exe"="C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"D:\Stronghold-Crusader\Stronghold Crusader\Stronghold Crusader.exe"="D:\Stronghold-Crusader\Stronghold Crusader\Stronghold Crusader.exe:*:Enabled:Stronghold Crusader"
"D:\Saints Row The Third\saintsrowthethird.exe"="D:\Saints Row The Third\saintsrowthethird.exe:*:Enabled:Saints Row: the Third"
"C:\Program Files\xampp\apache\bin\httpd.exe"="C:\Program Files\xampp\apache\bin\httpd.exe:*:Enabled:Apache HTTP Server"
"D:\Assassin's Creed Brotherhood\ACBSP.exe"="D:\Assassin's Creed Brotherhood\ACBSP.exe:*:Enabled:Assassin's Creed Brotherhood"
"D:\Assassin's Creed Brotherhood\ACBMP.exe"="D:\Assassin's Creed Brotherhood\ACBMP.exe:*:Enabled:Assassin's Creed Brotherhood Multiplayer"
"D:\Assassin's Creed Brotherhood\AssassinsCreedBrotherhood.exe"="D:\Assassin's Creed Brotherhood\AssassinsCreedBrotherhood.exe:*:Enabled:Assassin's Creed Brotherhood Update"
"D:\Assassin's Creed Brotherhood\UPlayBrowser.exe"="D:\Assassin's Creed Brotherhood\UPlayBrowser.exe:*:Enabled:Assassin's Creed Brotherhood Uplay"
"F:\Binaries\APB.EXE"="F:\Binaries\APB.EXE:*:Enabled:APB: APB.exe"
"F:\Binaries\VIVOXVOICESERVICE.EXE"="F:\Binaries\VIVOXVOICESERVICE.EXE:*:Enabled:APB: VivoxVoiceService.exe"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
"C:\WINDOWS\system32\javaw.exe"="C:\WINDOWS\system32\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"D:\APB Reloaded\Binaries\APB.exe"="D:\APB Reloaded\Binaries\APB.exe:*:Enabled:APB: APB.exe"
"D:\APB Reloaded\Binaries\VivoxVoiceService.exe"="D:\APB Reloaded\Binaries\VivoxVoiceService.exe:*:Enabled:APB: VivoxVoiceService.exe"
"C:\Documents and Settings\Mato\Application Data\Dropbox\bin\Dropbox.exe"="C:\Documents and Settings\Mato\Application Data\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App"
"C:\totalcmd\TOTALCMD.EXE"="C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit"
"D:\Ubisoft\Assassin's Creed II\AssassinsCreedIIGame.exe"="D:\Ubisoft\Assassin's Creed II\AssassinsCreedIIGame.exe:*:Enabled:Assassin's Creed II"
"D:\Ubisoft\Assassin's Creed II\AssassinsCreedII.exe"="D:\Ubisoft\Assassin's Creed II\AssassinsCreedII.exe:*:Enabled:Assassin's Creed II Update"
"D:\Ubisoft\Assassin's Creed II\UPlayBrowser.exe"="D:\Ubisoft\Assassin's Creed II\UPlayBrowser.exe:*:Enabled:Assassin's Creed II Uplay"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.l3fhg"=mp3fhg.acm
"VIDC.XVID"=xvidvfw.dll
"VIDC.YV12"=xvidvfw.dll
"msacm.ac3acm"=ac3acm.acm
"VIDC.FFDS"=ff_vfw.dll

======List of files/folders created in the last 1 month======

2012-08-15 12:25:56 ----D---- C:\Program Files\trend micro
2012-08-15 12:25:54 ----D---- C:\rsit
2012-08-13 21:31:25 ----RSH---- C:\Program Files\Common Files\svcchost.exe
2012-08-10 00:14:40 ----D---- C:\totalcmd
2012-08-10 00:14:40 ----D---- C:\Documents and Settings\Mato\Application Data\GHISLER
2012-08-09 13:00:09 ----D---- C:\Drivers
2012-08-09 12:39:04 ----SHD---- C:\Config.Msi
2012-08-09 12:17:42 ----D---- C:\Swsetup
2012-08-08 00:35:41 ----D---- C:\Program Files\Dropbox
2012-08-08 00:34:20 ----D---- C:\Documents and Settings\Mato\Application Data\Dropbox
2012-08-04 23:12:12 ----D---- C:\Documents and Settings\Mato\Application Data\NVIDIA
2012-08-04 23:10:36 ----A---- C:\WINDOWS\system32\drivers\PnkBstrK.sys
2012-08-04 23:10:32 ----A---- C:\Documents and Settings\Mato\Application Data\PnkBstrK.sys
2012-08-04 23:09:25 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2012-08-04 18:07:07 ----D---- C:\Program Files\GamersFirst
2012-08-02 10:41:08 ----D---- C:\Documents and Settings\Mato\Application Data\Ubisoft
2012-08-02 10:33:26 ----D---- C:\Documents and Settings\All Users\Application Data\Solidshield
2012-08-02 10:32:27 ----D---- C:\Documents and Settings\Mato\Application Data\PunkBuster
2012-07-26 23:53:02 ----D---- C:\Documents and Settings\Mato\Application Data\PSpad
2012-07-26 23:47:56 ----D---- C:\Program Files\PSPad editor
2012-07-26 23:15:16 ----D---- C:\Program Files\EasyPHP-12.0
2012-07-26 19:00:39 ----D---- C:\Documents and Settings\Mato\Application Data\MySQL
2012-07-26 18:46:16 ----D---- C:\Program Files\MySQL
2012-07-26 18:46:06 ----D---- C:\Documents and Settings\All Users\Application Data\MySQL
2012-07-26 17:59:43 ----D---- C:\Program Files\Apache
2012-07-25 21:23:28 ----D---- C:\Documents and Settings\Mato\Application Data\GameRanger
2012-07-24 20:28:14 ----D---- C:\Documents and Settings\All Users\Application Data\Ubisoft
2012-07-24 19:54:01 ----A---- C:\WINDOWS\system32\PnkBstrB.exe
2012-07-24 19:54:00 ----A---- C:\WINDOWS\system32\PnkBstrA.exe
2012-07-24 19:53:21 ----D---- C:\Program Files\Ubisoft
2012-07-24 14:33:44 ----A---- C:\WINDOWS\system32\drivers\dtsoftbus01.sys
2012-07-24 14:33:40 ----D---- C:\Documents and Settings\Mato\Application Data\DAEMON Tools Lite
2012-07-24 14:33:11 ----D---- C:\Program Files\DAEMON Tools Lite
2012-07-24 14:32:37 ----D---- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
2012-07-21 00:27:14 ----D---- C:\Documents and Settings\Mato\Application Data\VDownloader
2012-07-17 22:25:33 ----D---- C:\Documents and Settings\Mato\Application Data\Need for Speed World
2012-07-16 12:35:34 ----D---- C:\Program Files\Microsoft.NET

======List of files/folders modified in the last 1 month======

2012-08-15 12:37:03 ----D---- C:\Documents and Settings\Mato\Application Data\uTorrent
2012-08-15 12:36:26 ----D---- C:\Documents and Settings\Mato\Application Data\Skype
2012-08-15 12:35:33 ----D---- C:\WINDOWS\Prefetch
2012-08-15 12:35:25 ----D---- C:\WINDOWS\Temp
2012-08-15 12:35:07 ----D---- C:\WINDOWS\system32\CatRoot2
2012-08-15 12:34:44 ----D---- C:\WINDOWS
2012-08-15 12:27:22 ----D---- C:\WINDOWS\system32
2012-08-15 12:27:20 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2012-08-15 12:25:56 ----RD---- C:\Program Files
2012-08-15 12:11:54 ----SD---- C:\WINDOWS\Tasks
2012-08-15 12:06:33 ----D---- C:\Nexon
2012-08-15 12:04:31 ----D---- C:\WINDOWS\Config
2012-08-15 11:47:03 ----HD---- C:\WINDOWS\inf
2012-08-15 11:46:59 ----HD---- C:\WINDOWS\$hf_mig$
2012-08-15 07:59:00 ----A---- C:\WINDOWS\SchedLgU.Txt
2012-08-15 07:32:35 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2012-08-14 17:11:15 ----D---- C:\Documents and Settings\All Users\Application Data\PMB Files
2012-08-14 07:47:03 ----D---- C:\WINDOWS\system
2012-08-14 07:46:05 ----HDC---- C:\WINDOWS\$NtUninstallKB2584146$
2012-08-13 22:04:29 ----D---- C:\WINDOWS\system32\drivers
2012-08-13 21:49:21 ----D---- C:\Program Files\Microsoft Office
2012-08-13 21:35:38 ----D---- C:\Program Files\Common Files
2012-08-13 19:09:05 ----D---- C:\Program Files\Windows Media Player
2012-08-12 12:45:26 ----D---- C:\WINDOWS\network diagnostic
2012-08-12 12:10:23 ----D---- C:\Documents and Settings\Mato\Application Data\Mozilla
2012-08-11 15:40:57 ----SHD---- C:\WINDOWS\Installer
2012-08-11 15:40:41 ----D---- C:\WINDOWS\system32\DirectX
2012-08-11 15:40:07 ----RSD---- C:\WINDOWS\assembly
2012-08-11 15:34:15 ----HD---- C:\Program Files\InstallShield Installation Information
2012-08-11 15:15:27 ----RSD---- C:\WINDOWS\Fonts
2012-08-11 14:31:27 ----D---- C:\Documents and Settings\Mato\Application Data\Adobe
2012-08-11 11:01:02 ----D---- C:\WINDOWS\Minidump
2012-08-09 13:03:05 ----D---- C:\WINDOWS\system32\config
2012-08-09 13:02:47 ----D---- C:\WINDOWS\system32\wbem
2012-08-09 13:02:47 ----D---- C:\WINDOWS\Registration
2012-08-09 13:01:56 ----D---- C:\WINDOWS\system32\Restore
2012-08-09 12:53:20 ----D---- C:\Program Files\Analog Devices
2012-08-04 23:11:24 ----D---- C:\WINDOWS\WinSxS
2012-08-04 23:09:33 ----D---- C:\Program Files\NVIDIA Corporation
2012-08-04 18:28:01 ----D---- C:\Documents and Settings\Mato\Application Data\.minecraft
2012-08-01 00:57:21 ----D---- C:\Documents and Settings\All Users\Application Data\CanonIJPLM
2012-07-26 22:57:04 ----SD---- C:\Documents and Settings\Mato\Application Data\Microsoft
2012-07-26 21:36:49 ----D---- C:\WINDOWS\Microsoft.NET
2012-07-26 19:29:18 ----A---- C:\WINDOWS\ODBCINST.INI
2012-07-26 18:48:29 ----D---- C:\Program Files\Common Files\Microsoft Shared
2012-07-25 17:21:17 ----D---- C:\Documents and Settings\Mato\Application Data\DVDVideoSoft
2012-07-25 12:06:33 ----D---- C:\Program Files\Outspark
2012-07-24 19:54:00 ----D---- C:\WINDOWS\system32\LogFiles
2012-07-24 13:53:27 ----D---- C:\Program Files\OpenOffice.org 3
2012-07-20 07:20:55 ----D---- C:\Program Files\Mozilla Maintenance Service
2012-07-19 07:10:42 ----D---- C:\Program Files\Mozilla Firefox
2012-07-16 12:35:43 ----D---- C:\WINDOWS\system32\en-us
2012-07-16 02:06:06 ----D---- C:\Program Files\Diar

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 MpFilter;Microsoft Malware Protection Driver; C:\WINDOWS\system32\DRIVERS\MpFilter.sys [2012-03-20 171064]
R0 nvgts;nvgts; C:\WINDOWS\system32\DRIVERS\nvgts.sys [2010-04-09 168040]
R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-02 36864]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2012-07-24 242240]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R2 npf;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2010-01-27 50704]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2008-03-24 331264]
R3 AEAudio;AE Audio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2007-07-13 94976]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 HDAudBus;Драйвер шины Microsoft UAA для High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2010-10-22 9623680]
R3 NVENETFD;NVIDIA nForce 10/100/1000 Mbps Ethernet ; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2010-03-04 70912]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2010-03-04 13824]
R3 SenFiltService;SenFilt Service; C:\WINDOWS\system32\drivers\Senfilt.sys [2006-03-17 392960]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 GGSAFERDriver;GGSAFER Driver; \??\C:\Program Files\Garena Plus\Room\safedrv.sys []
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2012-02-15 43520]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S3 XDva375;XDva375; \??\C:\WINDOWS\system32\XDva375.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2012-02-27 55144]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 390504]
R2 IJPLMSVC;Inkjet Printer/Scanner Extended Survey Program; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2008-01-22 103808]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2012-04-06 153376]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\MsMpEng.exe [2012-03-26 11552]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2010-10-16 156776]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2012-08-04 76888]
R2 Protector by IB Updater;Protector by IB Updater; C:\Program Files\Protector by IB\ExtensionUpdaterService.exe [2012-04-24 185856]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 1529728]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2012-03-06 821608]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-02-15 158856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-15 250056]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-19 113120]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Pravdepodobne vírus

#2 Příspěvek od vyosek »

Zdravim a pekny den preji,
Vas log se studuje Obrázek a pracuje se na nem Obrázek.
Prosim o strpeni!Obrázek
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Pravdepodobne vírus

#3 Příspěvek od vyosek »

:arrow: Doporucuji odinstalovat (pokud nepouzivate) toolbary (listy prohlizecu) v Přidat nebo odebrat programy

:arrow: Stahnete RKill http://download.bleepingcomputer.com/grinler/rkill.com PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

BuXo
Návštěvník
Návštěvník
Příspěvky: 78
Registrován: 19 Srp 2011 20:27

Re: Pravdepodobne vírus

#4 Příspěvek od BuXo »

Tu je log z Rkill:

Rkill 2.0.3 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2012 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 08/15/2012 12:55:08 PM in x86 mode.
Windows Version: Windows XP

Checking for Windows services to stop.

* No malware services found to stop.

Checking for processes to terminate.

* No malware processes found to kill.

Checking Registry for malware related settings.

* No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks.

* No issues found.

Restarting Explorer.exe in order to apply changes.

Program finished at: 08/15/2012 12:55:17 PM
Execution time: 0 hours(s), 0 minute(s), and 9 seconds(s)

A tu je log z Combofixu:

ComboFix 12-08-14.05 - Mato . 08. 2012 13:04:49.1.2 - x86
Systém Microsoft Windows XP Home Edition 5.1.2600.3.1250.421.1033.18.2047.1388 [GMT 2:00]
Running from: c:\documents and settings\Mato\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TheBflix
c:\documents and settings\All Users\Application Data\TheBflix\background.html
c:\documents and settings\All Users\Application Data\TheBflix\bhoclass.dll
c:\documents and settings\All Users\Application Data\TheBflix\content.js
c:\documents and settings\All Users\Application Data\TheBflix\pmholphmkflmlgknogfaflfkknjegfje.crx
c:\documents and settings\All Users\Application Data\TheBflix\settings.ini
c:\program files\Protector by IB\ExTEnsion32.dll
c:\windows\config\svcchost.exe
c:\windows\system\svcchost.exe
c:\windows\system32\dllcache\dlimport.exe
c:\windows\system32\MUI\041b\tourstart.exe
D:\Autorun.inf
.
.
((((((((((((((((((((((((( Files Created from 2012-07-15 to 2012-08-15 )))))))))))))))))))))))))))))))
.
.
2012-08-15 11:00 . 2012-08-15 11:00 29904 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{089DDDB6-3071-4F3B-9681-D30927234EC9}\MpKsl4426f647.sys
2012-08-15 10:35 . 2012-08-15 10:35 56200 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{089DDDB6-3071-4F3B-9681-D30927234EC9}\offreg.dll
2012-08-15 10:25 . 2012-08-15 10:38 -------- d-----w- c:\program files\trend micro
2012-08-15 10:25 . 2012-08-15 10:38 -------- d-----w- C:\rsit
2012-08-15 09:56 . 2012-06-29 08:44 6891424 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{089DDDB6-3071-4F3B-9681-D30927234EC9}\mpengine.dll
2012-08-14 05:46 . 2012-06-29 08:44 6891424 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-08-13 19:31 . 2012-08-13 19:31 2598449 --sh--r- c:\program files\Common Files\svcchost.exe
2012-08-13 17:06 . 2012-08-13 17:06 2598449 --sh--r- c:\program files\Windows Media Player\svcchost.exe
2012-08-12 10:10 . 2012-08-12 10:10 -------- d-----w- c:\documents and settings\Mato\Local Settings\Application Data\Mozilla
2012-08-11 17:29 . 2012-08-11 17:30 -------- d-----w- c:\documents and settings\Tomas\Music
2012-08-09 22:14 . 2012-08-09 22:15 -------- d-----w- c:\documents and settings\Mato\Application Data\GHISLER
2012-08-09 22:14 . 2012-08-09 22:14 -------- d-----w- C:\totalcmd
2012-08-09 11:02 . 2012-08-09 11:02 -------- d-----w- c:\windows\system32\wbem\Repository
2012-08-09 11:00 . 2012-08-09 11:00 -------- d-----w- C:\Drivers
2012-08-09 10:17 . 2012-08-09 10:36 -------- d-----w- C:\Swsetup
2012-08-07 22:35 . 2012-08-07 22:35 -------- d-----w- c:\program files\Dropbox
2012-08-07 22:34 . 2012-08-15 10:35 -------- d-----w- c:\documents and settings\Mato\Application Data\Dropbox
2012-08-07 16:58 . 2012-08-07 16:58 -------- d-----w- c:\documents and settings\Ocino\Application Data\NVIDIA
2012-08-05 15:45 . 2012-08-05 15:46 -------- d-----w- c:\documents and settings\Mamina\Local Settings\Application Data\GamersFirst LIVE!
2012-08-05 15:35 . 2012-08-05 15:35 -------- d-----w- c:\documents and settings\Mamina\Local Settings\Application Data\Pando_Temp
2012-08-05 12:25 . 2012-08-05 12:25 -------- d-----w- c:\documents and settings\Ocino\Local Settings\Application Data\GamersFirst LIVE!
2012-08-05 12:01 . 2012-08-05 12:01 -------- d-----w- c:\documents and settings\Ocino\Local Settings\Application Data\Pando_Temp
2012-08-04 21:13 . 2012-08-05 17:25 281288 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-08-04 21:13 . 2012-08-04 21:13 -------- d-----w- c:\documents and settings\Mato\Local Settings\Application Data\PunkBuster
2012-08-04 21:12 . 2012-08-04 21:12 -------- d-----w- c:\documents and settings\Mato\Application Data\NVIDIA
2012-08-04 21:10 . 2012-08-05 17:25 138992 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-08-04 21:10 . 2012-08-04 21:10 138904 ----a-w- c:\documents and settings\Mato\Application Data\PnkBstrK.sys
2012-08-04 21:09 . 2012-08-04 21:09 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2012-08-04 16:10 . 2012-08-04 16:11 -------- d-----w- c:\documents and settings\Mato\Local Settings\Application Data\GamersFirst LIVE!
2012-08-04 16:10 . 2012-08-15 11:10 -------- d-----w- c:\documents and settings\Mato\Local Settings\Application Data\PMB Files
2012-08-04 16:10 . 2012-08-04 16:10 -------- d-----w- c:\documents and settings\Mato\Local Settings\Application Data\Pando_Temp
2012-08-04 16:07 . 2012-08-04 16:07 -------- d-----w- c:\program files\GamersFirst
2012-08-02 08:41 . 2012-08-02 08:41 -------- d-----w- c:\documents and settings\Mato\Application Data\Ubisoft
2012-08-02 08:33 . 2012-08-02 14:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Solidshield
2012-08-02 08:32 . 2012-08-02 08:32 -------- d-----w- c:\documents and settings\Mato\Application Data\PunkBuster
2012-07-26 21:53 . 2012-07-26 21:53 -------- d-----w- c:\documents and settings\Mato\Application Data\PSpad
2012-07-26 21:47 . 2012-07-26 21:51 -------- d-----w- c:\program files\PSPad editor
2012-07-26 21:15 . 2012-07-26 21:16 -------- d-----w- c:\program files\EasyPHP-12.0
2012-07-26 17:00 . 2012-07-26 17:05 -------- d-----w- c:\documents and settings\Mato\Application Data\MySQL
2012-07-26 16:46 . 2012-07-26 17:34 -------- d-----w- c:\program files\MySQL
2012-07-26 16:46 . 2012-07-26 17:31 -------- d-----w- c:\documents and settings\All Users\Application Data\MySQL
2012-07-26 15:59 . 2012-07-26 17:26 -------- d-----w- c:\program files\Apache
2012-07-25 19:23 . 2012-07-25 19:23 -------- d-----w- c:\documents and settings\Mato\Application Data\GameRanger
2012-07-25 15:21 . 2012-07-25 15:21 -------- d-----w- c:\documents and settings\Mato\Local Settings\Application Data\DVDVideoSoft_Ltd
2012-07-25 09:34 . 2012-07-25 09:34 -------- d-----w- c:\documents and settings\Mato\Local Settings\Application Data\Ubisoft Game Launcher
2012-07-24 18:28 . 2012-08-11 16:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Ubisoft
2012-07-24 17:54 . 2012-08-05 17:25 281288 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-07-24 17:54 . 2012-08-05 05:27 281288 ----a-w- c:\windows\system32\PnkBstrB.ex0
2012-07-24 17:54 . 2012-08-04 21:10 76888 ----a-w- c:\windows\system32\PnkBstrA.exe
2012-07-24 17:53 . 2012-07-24 17:53 -------- d-----w- c:\program files\Ubisoft
2012-07-24 12:40 . 2012-07-24 12:40 -------- d-----w- c:\documents and settings\Mato\Local Settings\Application Data\Focus Home Interactive
2012-07-24 12:33 . 2012-07-24 12:33 242240 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-07-24 12:33 . 2012-07-24 12:39 -------- d-----w- c:\documents and settings\Mato\Application Data\DAEMON Tools Lite
2012-07-24 12:33 . 2012-07-24 12:33 -------- d-----w- c:\program files\DAEMON Tools Lite
2012-07-24 12:32 . 2012-07-24 12:39 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2012-07-22 18:33 . 2012-07-22 18:36 -------- d-----w- c:\documents and settings\Ocino\Local Settings\Application Data\VDownloader
2012-07-22 18:33 . 2012-07-22 18:33 -------- d-----w- c:\documents and settings\Ocino\Application Data\VDownloader
2012-07-22 08:35 . 2012-07-22 09:45 -------- d-----w- c:\documents and settings\Mamina\Application Data\VDownloader
2012-07-22 08:35 . 2012-07-22 18:33 -------- d-----w- c:\documents and settings\Mamina\Local Settings\Application Data\VDownloader
2012-07-20 22:27 . 2012-07-20 22:27 -------- d-----w- c:\documents and settings\Mato\Application Data\VDownloader
2012-07-20 22:27 . 2012-07-21 08:53 -------- d-----w- c:\documents and settings\Mato\Local Settings\Application Data\VDownloader
2012-07-17 20:25 . 2012-07-17 20:25 -------- d-----w- c:\documents and settings\Mato\Application Data\Need for Speed World
2012-07-17 20:24 . 2012-07-17 20:24 -------- d-----w- c:\documents and settings\Mato\Local Settings\Application Data\Electronic_Arts_Inc
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-15 10:27 . 2012-03-29 19:29 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-15 10:27 . 2012-03-28 11:33 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-22 14:32 . 2012-07-05 10:51 405144 ----a-w- c:\windows\system32\Newtonsoft.Json.Net20.dll
2012-06-13 13:19 . 2006-02-28 12:00 1866112 ----a-w- c:\windows\system32\win32k.sys
2012-06-05 15:50 . 2012-03-28 11:13 1372672 ----a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:50 . 2006-02-28 12:00 1172480 ----a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2006-02-28 12:00 152576 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 13:19 . 2009-08-06 17:24 22040 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 13:19 . 2012-03-28 10:34 329240 ----a-w- c:\windows\system32\wucltui.dll
2012-06-02 13:19 . 2012-03-28 10:34 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 13:19 . 2012-03-28 10:34 210968 ----a-w- c:\windows\system32\wuweb.dll
2012-06-02 13:19 . 2009-08-06 17:24 15384 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 13:19 . 2012-03-28 10:34 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 13:19 . 2012-03-28 10:34 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 13:19 . 2009-08-06 17:24 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 13:19 . 2009-08-06 17:24 15384 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 13:19 . 2006-02-28 12:00 97304 ----a-w- c:\windows\system32\cdm.dll
2012-06-02 13:19 . 2009-08-06 17:24 17944 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 13:19 . 2012-03-28 10:34 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 13:19 . 2012-03-28 10:34 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 13:18 . 2012-03-29 12:03 275696 ----a-w- c:\windows\system32\mucltui.dll
2012-06-02 13:18 . 2012-03-29 12:03 17136 ----a-w- c:\windows\system32\mucltui.dll.mui
2012-06-02 13:18 . 2009-08-06 17:23 214256 ----a-w- c:\windows\system32\muweb.dll
2012-05-31 13:22 . 2006-02-28 12:00 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-16 13:12 . 2012-04-13 20:33 3623592 ----a-w- c:\program files\Common Files\ApnToolbarInstaller.exe
2011-09-16 13:12 . 2012-04-13 20:33 143240 ----a-w- c:\program files\Common Files\ApnStub.exe
2012-07-19 05:10 . 2012-03-29 16:23 136672 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\documents and settings\Mato\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\documents and settings\Mato\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\documents and settings\Mato\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\documents and settings\Mato\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\Valve\Steam\Steam.exe" [2012-08-04 1353080]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2012-05-19 880496]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-02-15 17146504]
"Diar.exe"="c:\program files\Diar\Diar.exe" [2006-11-01 1523200]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2012-04-17 3671872]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-10-16 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-10-16 13851752]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2008-03-10 689488]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2008-03-03 1848648]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2012-01-19 114992]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-03-06 421736]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200]
"Microsoft Windows Service Host!"="c:\windows\explorer.exe" [2008-04-14 1033728]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\Mato\Start Menu\Programs\Startup\
Dropbox.lnk - c:\documents and settings\Mato\Application Data\Dropbox\bin\Dropbox.exe [2012-7-25 26909544]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
GamersFirst LIVE!.lnk - c:\program files\GamersFirst\LIVE!\Live.exe [2012-6-22 2720408]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Documents and Settings\\Tomas\\Local Settings\\Application Data\\Akamai\\netsession_win.exe"=
"c:\\Program Files\\Sega\\Virtua Tennis 4\\VT4.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\TeamViewer\\Version7\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version7\\TeamViewer_Service.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Electronic Arts\\Need For Speed World\\Data\\nfsw.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\buxo170\\counter-strike\\hl.exe"=
"c:\\Program Files\\Ubisoft\\Ubisoft Game Launcher\\UbisoftGameLauncher.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Documents and Settings\\Mato\\Application Data\\GameRanger\\GameRanger\\GameRanger.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"d:\\Stronghold-Crusader\\Stronghold Crusader\\Stronghold Crusader.exe"=
"d:\\Saints Row The Third\\saintsrowthethird.exe"=
"d:\\Assassin's Creed Brotherhood\\ACBSP.exe"=
"d:\\Assassin's Creed Brotherhood\\ACBMP.exe"=
"d:\\Assassin's Creed Brotherhood\\AssassinsCreedBrotherhood.exe"=
"d:\\Assassin's Creed Brotherhood\\UPlayBrowser.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\WINDOWS\\system32\\javaw.exe"=
"c:\\Documents and Settings\\Mato\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"57638:TCP"= 57638:TCP:Pando Media Booster
"57638:UDP"= 57638:UDP:Pando Media Booster
"3306:TCP"= 3306:TCP:MySQL5
"56180:TCP"= 56180:TCP:Pando Media Booster
"56180:UDP"= 56180:UDP:Pando Media Booster
"2193:TCP"= 2193:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [24. 7. 2012 14:33 242240]
R1 MpKsl4426f647;MpKsl4426f647;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{089DDDB6-3071-4F3B-9681-D30927234EC9}\MpKsl4426f647.sys [15. 8. 2012 13:00 29904]
R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [27. 1. 2010 4:09 50704]
S2 Protector by IB Updater;Protector by IB Updater;c:\program files\Protector by IB\ExtensionUpdaterService.exe [26. 4. 2012 17:12 185856]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [15. 2. 2012 13:30 158856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [29. 3. 2012 21:29 250056]
S3 GGSAFERDriver;GGSAFER Driver;\??\c:\program files\Garena Plus\Room\safedrv.sys --> c:\program files\Garena Plus\Room\safedrv.sys [?]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [15. 1. 2010 14:49 227232]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [4. 5. 2012 15:32 113120]
S3 XDva375;XDva375;\??\c:\windows\system32\XDva375.sys --> c:\windows\system32\XDva375.sys [?]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - MPKSL4426F647
.
Contents of the 'Scheduled Tasks' folder
.
2012-08-15 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-29 10:27]
.
2012-08-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
.
2012-08-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-1078145449-839522115-1007Core.job
- c:\documents and settings\Mato\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-03-28 17:50]
.
2012-08-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-1078145449-839522115-1007UA.job
- c:\documents and settings\Mato\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-03-28 17:50]
.
2012-08-15 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-03-26 15:03]
.
2012-08-15 c:\windows\Tasks\User_Feed_Synchronization-{C3F05B38-74F2-43F3-AC79-E2DA93584543}.job
- c:\windows\system32\msfeedssync.exe [2012-03-28 02:31]
.
.
------- Supplementary Scan -------
.
mStart Page = hxxp://home.sweetim.com
uInternet Settings,ProxyOverride = *.local
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\documents and settings\Mato\Application Data\DVDVideoSoftIEHelpers\freeytvdownloader.htm
IE: Free YouTube to MP3 Converter - c:\documents and settings\Mato\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Search the Web - c:\program files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\Mato\Application Data\Mozilla\Firefox\Profiles\q2j5jg21.default\
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
HKLM-Run-SoundMAXPnP - c:\program files\Analog Devices\Core\smax4pnp.exe
HKLM-Run-VDownloader - c:\program files\VDownloader\VDownloader.exe
AddRemove-APB Reloaded - d:\apb reloaded\Uninstall.exe
AddRemove-PunkBusterSvc - d:\apb reloaded\Binaries\pbsvc_apb.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-15 13:10
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2012-08-15 13:12:12
ComboFix-quarantined-files.txt 2012-08-15 11:12
.
Pre-Run: 22 704 250 880 bytes free
Post-Run: 25 855 873 024 bytes free
.
- - End Of File - - B1D9EEB7289ABFAF1C91D8DDE444217E

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Pravdepodobne vírus

#5 Příspěvek od vyosek »

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    Collect::
    c:\program files\Common Files\svcchost.exe
    c:\program files\Windows Media Player\svcchost.exe
    c:\windows\explorer.exe
    c:\windows\system32\XDva375.sys
    
    Folder::
    C:\Program Files\BabylonToolbar
    c:\program files\SweetIM
    
    File::
    c:\documents and settings\All Users\Start Menu\Programs\Startup\GamersFirst LIVE!.lnk
    c:\documents and settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
    C:\WINDOWS\tasks\Adobe Flash Player Updater.job
    C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-1078145449-839522115-1007Core.job
    C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-1078145449-839522115-1007UA.job
    C:\WINDOWS\tasks\User_Feed_Synchronization-{C3F05B38-74F2-43F3-AC79-E2DA93584543}.jo
    
    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Steam"=-
    "uTorrent"=-
    "Skype"=-
    "DAEMON Tools Lite"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Adobe ARM"=-
    "SweetIM"=-
    "SunJavaUpdateSched"=-
    "iTunesHelper"=-
    "Microsoft Windows Service Host!"=-
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "2193:TCP"=-
    "5000:UDP"=-
    
    Driver::
    XDva375
    
    DDS::
    mStart Page = hxxp://home.sweetim.com
    IE: Search the Web - c:\program files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
    
    Reboot::
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Pokud vyskoci hlaska "Pokus pouzit neplatnou operaci na klic registru, ktery je oznacen pro odstraneni", tak jen restartujte PC - registr se da do kupy - jedna se o vnitrni chybu, kterou zpusobuje CF a autor ji zatim neumi bohuzel opravit

:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

BuXo
Návštěvník
Návštěvník
Příspěvky: 78
Registrován: 19 Srp 2011 20:27

Re: Pravdepodobne vírus

#6 Příspěvek od BuXo »

Podľa pokynov som aplikoval script, po reštartovaní PC nezobrazilo plochu, tak som skúsil reštart namačkal som F8 a zvolil poslednú možnosť ale plochu nezobrazuje aj tak, nevyhodilo ani log.

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Pravdepodobne vírus

#7 Příspěvek od vyosek »

:arrow: Nasledujici soubory otestujte na VirusTotalu https://www.virustotal.com/cs/
  • c:\windows\explorer.exe
  • Kliknete na Choose file
  • Soubor nehledejte, jen vlozte cestu souboru, ktery chci otestovat
  • Kliknete na Scan It
  • Pokud na Vas vyskoci obrazovka jako je nize, tak kliknete na ReAnalyse
    Obrázek
  • Vysledek analyzy sem vlozte (jako odkaz)
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

BuXo
Návštěvník
Návštěvník
Příspěvky: 78
Registrován: 19 Srp 2011 20:27

Re: Pravdepodobne vírus

#8 Příspěvek od BuXo »


Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Pravdepodobne vírus

#9 Příspěvek od vyosek »

Pouzijte pro CF tento (upraveny) skript

Kód: Vybrat vše

KillAll::

Collect::
c:\program files\Common Files\svcchost.exe
c:\program files\Windows Media Player\svcchost.exe
c:\windows\system32\XDva375.sys

Restore::
c:\windows\explorer.exe

Folder::
C:\Program Files\BabylonToolbar
c:\program files\SweetIM

File::
c:\documents and settings\All Users\Start Menu\Programs\Startup\GamersFirst LIVE!.lnk
c:\documents and settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-1078145449-839522115-1007Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-1078145449-839522115-1007UA.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{C3F05B38-74F2-43F3-AC79-E2DA93584543}.jo

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"=-
"uTorrent"=-
"Skype"=-
"DAEMON Tools Lite"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=-
"SweetIM"=-
"SunJavaUpdateSched"=-
"iTunesHelper"=-
"Microsoft Windows Service Host!"=-
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2193:TCP"=-
"5000:UDP"=-

Driver::
XDva375

DDS::
mStart Page = hxxp://home.sweetim.com
IE: Search the Web - c:\program files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html

Reboot::
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

BuXo
Návštěvník
Návštěvník
Příspěvky: 78
Registrován: 19 Srp 2011 20:27

Re: Pravdepodobne vírus

#10 Příspěvek od BuXo »

Plochu stále nie je vidno a takisto nevyhodilo ani log.

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Pravdepodobne vírus

#11 Příspěvek od vyosek »

Spustte tedy prosim ComboFix bez skriptu, podobne jako poprve
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

BuXo
Návštěvník
Návštěvník
Příspěvky: 78
Registrován: 19 Srp 2011 20:27

Re: Pravdepodobne vírus

#12 Příspěvek od BuXo »

ComboFix 12-08-16.01 - Mato . 08. 2012 11:57:34.4.2 - x86
Systém Microsoft Windows XP Home Edition 5.1.2600.3.1250.421.1033.18.2047.1620 [GMT 2:00]
Running from: c:\documents and settings\Mato\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_XDVA375
-------\Service_XDva375
.
.
((((((((((((((((((((((((( Files Created from 2012-07-16 to 2012-08-16 )))))))))))))))))))))))))))))))
.
.
2012-08-16 09:56 . 2012-08-16 09:56 29904 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{089DDDB6-3071-4F3B-9681-D30927234EC9}\MpKsl476d73fd.sys
2012-08-15 23:17 . 2008-04-13 22:16 48128 -c--a-w- c:\windows\system32\dllcache\61883.sys
2012-08-15 23:17 . 2001-08-17 12:55 38400 -c--a-w- c:\windows\system32\dllcache\8514a.dll
2012-08-15 23:17 . 2008-04-13 22:10 12288 -c--a-w- c:\windows\system32\dllcache\4mmdat.sys
2012-08-15 23:17 . 2001-08-17 10:48 148352 -c--a-w- c:\windows\system32\dllcache\3dfxvsm.sys
2012-08-15 23:17 . 2001-08-17 12:55 689216 -c--a-w- c:\windows\system32\dllcache\3dfxvs.dll
2012-08-15 23:17 . 2001-08-17 11:28 762780 -c--a-w- c:\windows\system32\dllcache\3cwmcru.sys
2012-08-15 23:17 . 2008-04-13 22:16 53376 -c--a-w- c:\windows\system32\dllcache\1394bus.sys
2012-08-15 23:17 . 2001-08-17 12:06 11264 -c--a-w- c:\windows\system32\dllcache\1394vdbg.sys
2012-08-15 23:17 . 2001-08-17 12:56 66048 -c--a-w- c:\windows\system32\dllcache\s3legacy.dll
2012-08-15 23:09 . 2012-08-15 23:09 -------- d-----w- c:\program files\Yamicsoft
2012-08-15 22:44 . 2012-08-15 22:44 29904 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{089DDDB6-3071-4F3B-9681-D30927234EC9}\MpKslc068e922.sys
2012-08-15 22:44 . 2012-08-16 09:55 56200 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{089DDDB6-3071-4F3B-9681-D30927234EC9}\offreg.dll
2012-08-15 11:27 . 2012-08-15 11:27 9826504 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2012-08-15 10:25 . 2012-08-15 10:38 -------- d-----w- c:\program files\trend micro
2012-08-15 10:25 . 2012-08-15 10:38 -------- d-----w- C:\rsit
2012-08-15 09:56 . 2012-06-29 08:44 6891424 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{089DDDB6-3071-4F3B-9681-D30927234EC9}\mpengine.dll
2012-08-14 05:46 . 2012-06-29 08:44 6891424 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-08-12 10:10 . 2012-08-12 10:10 -------- d-----w- c:\documents and settings\Mato\Local Settings\Application Data\Mozilla
2012-08-11 17:29 . 2012-08-11 17:30 -------- d-----w- c:\documents and settings\Tomas\Music
2012-08-09 22:14 . 2012-08-09 22:15 -------- d-----w- c:\documents and settings\Mato\Application Data\GHISLER
2012-08-09 22:14 . 2012-08-09 22:14 -------- d-----w- C:\totalcmd
2012-08-09 11:02 . 2012-08-09 11:02 -------- d-----w- c:\windows\system32\wbem\Repository
2012-08-09 11:00 . 2012-08-09 11:00 -------- d-----w- C:\Drivers
2012-08-09 10:17 . 2012-08-09 10:36 -------- d-----w- C:\Swsetup
2012-08-07 22:35 . 2012-08-07 22:35 -------- d-----w- c:\program files\Dropbox
2012-08-07 22:34 . 2012-08-15 10:35 -------- d-----w- c:\documents and settings\Mato\Application Data\Dropbox
2012-08-07 16:58 . 2012-08-07 16:58 -------- d-----w- c:\documents and settings\Ocino\Application Data\NVIDIA
2012-08-05 15:45 . 2012-08-05 15:46 -------- d-----w- c:\documents and settings\Mamina\Local Settings\Application Data\GamersFirst LIVE!
2012-08-05 15:35 . 2012-08-05 15:35 -------- d-----w- c:\documents and settings\Mamina\Local Settings\Application Data\Pando_Temp
2012-08-05 12:25 . 2012-08-05 12:25 -------- d-----w- c:\documents and settings\Ocino\Local Settings\Application Data\GamersFirst LIVE!
2012-08-05 12:01 . 2012-08-05 12:01 -------- d-----w- c:\documents and settings\Ocino\Local Settings\Application Data\Pando_Temp
2012-08-04 21:13 . 2012-08-05 17:25 281288 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-08-04 21:13 . 2012-08-04 21:13 -------- d-----w- c:\documents and settings\Mato\Local Settings\Application Data\PunkBuster
2012-08-04 21:12 . 2012-08-04 21:12 -------- d-----w- c:\documents and settings\Mato\Application Data\NVIDIA
2012-08-04 21:10 . 2012-08-05 17:25 138992 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-08-04 21:10 . 2012-08-04 21:10 138904 ----a-w- c:\documents and settings\Mato\Application Data\PnkBstrK.sys
2012-08-04 21:09 . 2012-08-04 21:09 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2012-08-04 16:10 . 2012-08-04 16:11 -------- d-----w- c:\documents and settings\Mato\Local Settings\Application Data\GamersFirst LIVE!
2012-08-04 16:10 . 2012-08-15 17:52 -------- d-----w- c:\documents and settings\Mato\Local Settings\Application Data\PMB Files
2012-08-04 16:10 . 2012-08-04 16:10 -------- d-----w- c:\documents and settings\Mato\Local Settings\Application Data\Pando_Temp
2012-08-04 16:07 . 2012-08-04 16:07 -------- d-----w- c:\program files\GamersFirst
2012-08-02 08:41 . 2012-08-02 08:41 -------- d-----w- c:\documents and settings\Mato\Application Data\Ubisoft
2012-08-02 08:33 . 2012-08-02 14:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Solidshield
2012-08-02 08:32 . 2012-08-02 08:32 -------- d-----w- c:\documents and settings\Mato\Application Data\PunkBuster
2012-07-26 21:53 . 2012-07-26 21:53 -------- d-----w- c:\documents and settings\Mato\Application Data\PSpad
2012-07-26 21:47 . 2012-07-26 21:51 -------- d-----w- c:\program files\PSPad editor
2012-07-26 21:15 . 2012-07-26 21:16 -------- d-----w- c:\program files\EasyPHP-12.0
2012-07-26 17:00 . 2012-07-26 17:05 -------- d-----w- c:\documents and settings\Mato\Application Data\MySQL
2012-07-26 16:46 . 2012-07-26 17:34 -------- d-----w- c:\program files\MySQL
2012-07-26 16:46 . 2012-07-26 17:31 -------- d-----w- c:\documents and settings\All Users\Application Data\MySQL
2012-07-26 15:59 . 2012-07-26 17:26 -------- d-----w- c:\program files\Apache
2012-07-25 19:23 . 2012-07-25 19:23 -------- d-----w- c:\documents and settings\Mato\Application Data\GameRanger
2012-07-25 15:21 . 2012-07-25 15:21 -------- d-----w- c:\documents and settings\Mato\Local Settings\Application Data\DVDVideoSoft_Ltd
2012-07-25 09:34 . 2012-07-25 09:34 -------- d-----w- c:\documents and settings\Mato\Local Settings\Application Data\Ubisoft Game Launcher
2012-07-24 18:28 . 2012-08-11 16:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Ubisoft
2012-07-24 17:54 . 2012-08-05 17:25 281288 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-07-24 17:54 . 2012-08-05 05:27 281288 ----a-w- c:\windows\system32\PnkBstrB.ex0
2012-07-24 17:54 . 2012-08-04 21:10 76888 ----a-w- c:\windows\system32\PnkBstrA.exe
2012-07-24 17:53 . 2012-07-24 17:53 -------- d-----w- c:\program files\Ubisoft
2012-07-24 12:40 . 2012-07-24 12:40 -------- d-----w- c:\documents and settings\Mato\Local Settings\Application Data\Focus Home Interactive
2012-07-24 12:33 . 2012-07-24 12:33 242240 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-07-24 12:33 . 2012-07-24 12:39 -------- d-----w- c:\documents and settings\Mato\Application Data\DAEMON Tools Lite
2012-07-24 12:33 . 2012-07-24 12:33 -------- d-----w- c:\program files\DAEMON Tools Lite
2012-07-24 12:32 . 2012-07-24 12:39 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2012-07-22 18:33 . 2012-07-22 18:36 -------- d-----w- c:\documents and settings\Ocino\Local Settings\Application Data\VDownloader
2012-07-22 18:33 . 2012-07-22 18:33 -------- d-----w- c:\documents and settings\Ocino\Application Data\VDownloader
2012-07-22 08:35 . 2012-07-22 09:45 -------- d-----w- c:\documents and settings\Mamina\Application Data\VDownloader
2012-07-22 08:35 . 2012-07-22 18:33 -------- d-----w- c:\documents and settings\Mamina\Local Settings\Application Data\VDownloader
2012-07-20 22:27 . 2012-07-20 22:27 -------- d-----w- c:\documents and settings\Mato\Application Data\VDownloader
2012-07-20 22:27 . 2012-07-21 08:53 -------- d-----w- c:\documents and settings\Mato\Local Settings\Application Data\VDownloader
2012-07-17 20:25 . 2012-07-17 20:25 -------- d-----w- c:\documents and settings\Mato\Application Data\Need for Speed World
2012-07-17 20:24 . 2012-07-17 20:24 -------- d-----w- c:\documents and settings\Mato\Local Settings\Application Data\Electronic_Arts_Inc
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-15 11:27 . 2012-03-29 19:29 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-15 11:27 . 2012-03-28 11:33 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-06 13:58 . 2006-02-28 12:00 78336 ----a-w- c:\windows\system32\browser.dll
2012-07-04 14:05 . 2012-03-28 10:33 139784 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-07-03 13:40 . 2006-02-28 12:00 1866112 ----a-w- c:\windows\system32\win32k.sys
2012-07-02 17:49 . 2006-02-28 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-07-02 17:49 . 2006-02-28 12:00 43520 ------w- c:\windows\system32\licmgr10.dll
2012-07-02 17:49 . 2006-02-28 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-07-02 12:05 . 2006-02-28 12:00 385024 ------w- c:\windows\system32\html.iec
2012-06-22 14:32 . 2012-07-05 10:51 405144 ----a-w- c:\windows\system32\Newtonsoft.Json.Net20.dll
2012-06-06 18:59 . 2012-06-06 18:59 1070152 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2012-06-05 15:50 . 2012-03-28 11:13 1372672 ----a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:50 . 2006-02-28 12:00 1172480 ----a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2006-02-28 12:00 152576 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 13:19 . 2009-08-06 17:24 22040 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 13:19 . 2012-03-28 10:34 329240 ----a-w- c:\windows\system32\wucltui.dll
2012-06-02 13:19 . 2012-03-28 10:34 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 13:19 . 2012-03-28 10:34 210968 ----a-w- c:\windows\system32\wuweb.dll
2012-06-02 13:19 . 2009-08-06 17:24 15384 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 13:19 . 2012-03-28 10:34 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 13:19 . 2012-03-28 10:34 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 13:19 . 2009-08-06 17:24 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 13:19 . 2009-08-06 17:24 15384 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 13:19 . 2006-02-28 12:00 97304 ----a-w- c:\windows\system32\cdm.dll
2012-06-02 13:19 . 2009-08-06 17:24 17944 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 13:19 . 2012-03-28 10:34 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 13:19 . 2012-03-28 10:34 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 13:18 . 2012-03-29 12:03 275696 ----a-w- c:\windows\system32\mucltui.dll
2012-06-02 13:18 . 2012-03-29 12:03 17136 ----a-w- c:\windows\system32\mucltui.dll.mui
2012-06-02 13:18 . 2009-08-06 17:23 214256 ----a-w- c:\windows\system32\muweb.dll
2012-05-31 13:22 . 2006-02-28 12:00 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-16 13:12 . 2012-04-13 20:33 3623592 ----a-w- c:\program files\Common Files\ApnToolbarInstaller.exe
2011-09-16 13:12 . 2012-04-13 20:33 143240 ----a-w- c:\program files\Common Files\ApnStub.exe
2012-07-19 05:10 . 2012-03-29 16:23 136672 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2008-04-14 03:42 . CF78AC5F4D4EE837F9E9086DAB9FBE5A . 1033728 . . [------] . . c:\windows\explorer.exe
[7] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\erdnt\cache\explorer.exe
[7] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe
[7] 2006-02-28 . A0732187050030AE399B241436565E64 . 1032192 . . [6.00.2900.2180] . . c:\windows\$NtServicePackUninstall$\explorer.exe
.
((((((((((((((((((((((((((((( SnapShot@2012-08-15_11.10.44 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-08-16 05:24 . 2012-08-16 05:24 16384 c:\windows\temp\Perflib_Perfdata_440.dat
- 2006-02-28 12:00 . 2012-08-15 10:38 85392 c:\windows\system32\perfc009.dat
+ 2006-02-28 12:00 . 2012-08-16 05:28 85392 c:\windows\system32\perfc009.dat
+ 2006-02-28 12:00 . 2012-07-02 17:49 67072 c:\windows\system32\mshtmled.dll
- 2006-02-28 12:00 . 2012-05-11 14:42 67072 c:\windows\system32\mshtmled.dll
+ 2012-03-28 11:36 . 2012-07-02 17:49 55296 c:\windows\system32\msfeedsbs.dll
- 2012-03-28 11:36 . 2012-05-11 14:42 55296 c:\windows\system32\msfeedsbs.dll
+ 2006-02-28 12:00 . 2012-07-02 17:49 25600 c:\windows\system32\jsproxy.dll
- 2006-02-28 12:00 . 2012-05-11 14:42 25600 c:\windows\system32\jsproxy.dll
- 2012-03-28 11:36 . 2012-05-11 14:42 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2012-03-28 11:36 . 2012-07-02 17:49 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2006-02-28 12:00 . 2008-04-14 03:42 30749 c:\windows\system32\dllcache\vbajet32.dll
+ 2007-04-02 20:06 . 2007-04-02 20:06 16384 c:\windows\system32\dllcache\tcptsat.dll
+ 2008-04-14 03:42 . 2008-04-14 03:42 32827 c:\windows\system32\dllcache\tcptest.exe
+ 2006-02-28 12:00 . 2008-04-14 03:42 25088 c:\windows\system32\dllcache\slayerxp.dll
+ 2008-04-14 03:42 . 2008-04-14 03:42 16437 c:\windows\system32\dllcache\shtml.exe
+ 2008-04-14 03:42 . 2008-04-14 03:42 20536 c:\windows\system32\dllcache\shtml.dll
+ 2006-02-28 12:00 . 2008-04-14 03:42 65024 c:\windows\system32\dllcache\shimeng.dll
+ 2006-02-28 12:00 . 2008-04-14 03:42 77312 c:\windows\system32\dllcache\sdbinst.exe
+ 2006-02-28 12:00 . 2008-04-14 03:42 64000 c:\windows\system32\dllcache\samlib.dll
+ 2006-02-28 12:00 . 2008-04-14 03:42 84992 c:\windows\system32\dllcache\olepro32.dll
+ 2012-03-28 10:34 . 2008-04-14 03:42 65536 c:\windows\system32\dllcache\oledb32r.dll
+ 2006-02-28 12:00 . 2008-04-14 03:42 20511 c:\windows\system32\dllcache\odtext32.dll
+ 2006-02-28 12:00 . 2008-04-14 03:42 20510 c:\windows\system32\dllcache\odpdx32.dll
+ 2006-02-28 12:00 . 2008-04-14 03:42 20510 c:\windows\system32\dllcache\odfox32.dll
+ 2006-02-28 12:00 . 2008-04-14 03:42 20510 c:\windows\system32\dllcache\odexl32.dll
+ 2006-02-28 12:00 . 2008-04-14 03:42 20511 c:\windows\system32\dllcache\oddbse32.dll
+ 2006-02-28 12:00 . 2008-04-14 03:40 53279 c:\windows\system32\dllcache\odbcji32.dll
+ 2006-02-28 12:00 . 2008-04-13 20:56 94208 c:\windows\system32\dllcache\odbcint.dll
+ 2006-02-28 12:00 . 2008-04-14 03:42 65536 c:\windows\system32\dllcache\odbccu32.dll
+ 2006-02-28 12:00 . 2008-04-14 03:42 65536 c:\windows\system32\dllcache\odbccr32.dll
+ 2006-02-28 12:00 . 2008-04-14 03:42 69632 c:\windows\system32\dllcache\odbcconf.exe
+ 2006-02-28 12:00 . 2008-04-14 03:42 32768 c:\windows\system32\dllcache\odbcad32.exe
+ 2006-02-28 12:00 . 2008-04-14 03:42 16384 c:\windows\system32\dllcache\odbc32gt.dll
+ 2006-02-28 12:00 . 2008-04-14 03:42 67584 c:\windows\system32\dllcache\ocmanage.dll
+ 2006-02-28 12:00 . 2008-04-13 22:50 91520 c:\windows\system32\dllcache\ndiswan.sys
+ 2012-03-28 10:34 . 2008-04-14 03:42 24576 c:\windows\system32\dllcache\msxactps.dll
+ 2006-02-28 12:00 . 2008-04-13 22:00 61440 c:\windows\system32\dllcache\msvcrt40.dll
+ 2006-02-28 12:00 . 2007-04-02 16:19 60192 c:\windows\system32\dllcache\msjter40.dll
+ 2012-03-28 11:36 . 2012-07-02 17:49 67072 c:\windows\system32\dllcache\mshtmled.dll
- 2012-03-28 11:36 . 2012-05-11 14:42 67072 c:\windows\system32\dllcache\mshtmled.dll
- 2012-03-28 11:36 . 2012-05-11 14:42 55296 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2012-03-28 11:36 . 2012-07-02 17:49 55296 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2012-03-28 10:34 . 2008-04-14 03:42 36864 c:\windows\system32\dllcache\msdfmap.dll
+ 2012-03-28 10:34 . 2008-04-14 03:42 20480 c:\windows\system32\dllcache\msdatt.dll
+ 2012-03-28 10:34 . 2008-04-13 20:56 16384 c:\windows\system32\dllcache\msdasqlr.dll
+ 2012-03-28 10:34 . 2008-04-13 20:56 16384 c:\windows\system32\dllcache\msdaremr.dll
+ 2012-03-28 10:34 . 2008-04-13 20:56 16384 c:\windows\system32\dllcache\msdaprsr.dll
+ 2012-03-28 10:34 . 2008-04-14 03:42 77824 c:\windows\system32\dllcache\msdaosp.dll
+ 2006-02-28 12:00 . 2008-04-14 03:42 36864 c:\windows\system32\dllcache\mscpxl32.dll
+ 2012-03-28 10:34 . 2008-04-14 03:42 57344 c:\windows\system32\dllcache\msadrh15.dll
+ 2012-03-28 10:34 . 2008-04-14 03:42 57344 c:\windows\system32\dllcache\msador15.dll
+ 2012-03-28 10:34 . 2008-04-13 20:56 24576 c:\windows\system32\dllcache\msader15.dll
+ 2012-03-28 10:34 . 2008-04-13 20:56 24576 c:\windows\system32\dllcache\msaddsr.dll
+ 2012-03-28 10:34 . 2008-04-14 03:42 53248 c:\windows\system32\dllcache\msadcs.dll
+ 2012-03-28 10:34 . 2008-04-13 20:55 16384 c:\windows\system32\dllcache\msadcor.dll
+ 2012-03-28 10:34 . 2008-04-13 20:55 16384 c:\windows\system32\dllcache\msadcfr.dll
+ 2012-03-28 10:34 . 2008-04-14 03:42 61440 c:\windows\system32\dllcache\msadcf.dll
+ 2012-03-28 10:34 . 2008-04-13 20:55 20480 c:\windows\system32\dllcache\msadcer.dll
+ 2006-02-28 12:00 . 2008-04-14 03:41 22528 c:\windows\system32\dllcache\mfcsubs.dll
+ 2012-03-28 11:36 . 2012-07-02 17:49 43520 c:\windows\system32\dllcache\licmgr10.dll
- 2012-03-28 11:36 . 2012-05-11 14:42 43520 c:\windows\system32\dllcache\licmgr10.dll
+ 2006-02-28 12:00 . 2012-07-02 17:49 25600 c:\windows\system32\dllcache\jsproxy.dll
- 2012-03-28 11:36 . 2012-05-11 14:42 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2006-02-28 12:00 . 2008-04-13 22:49 75264 c:\windows\system32\dllcache\ipsec.sys
+ 2006-02-28 12:00 . 2008-04-14 03:41 36921 c:\windows\system32\dllcache\imeshare.dll
+ 2008-04-14 03:42 . 2008-04-14 03:42 20538 c:\windows\system32\dllcache\fpremadm.exe
+ 2008-04-14 03:41 . 2008-04-14 03:41 20541 c:\windows\system32\dllcache\fpexedll.dll
+ 2008-04-14 03:42 . 2008-04-14 03:42 15120 c:\windows\system32\dllcache\fp98sadm.exe
+ 2008-04-14 03:41 . 2008-04-14 03:41 49212 c:\windows\system32\dllcache\fp4awebs.dll
+ 2008-04-14 03:41 . 2008-04-14 03:41 32826 c:\windows\system32\dllcache\fp4avss.dll
+ 2008-04-14 03:41 . 2008-04-14 03:41 41020 c:\windows\system32\dllcache\fp4avnb.dll
+ 2008-04-14 03:41 . 2008-04-14 03:41 49210 c:\windows\system32\dllcache\fp4areg.dll
+ 2008-04-14 03:41 . 2008-04-14 03:41 82035 c:\windows\system32\dllcache\fp4anscp.dll
+ 2006-02-28 12:00 . 2008-04-14 03:41 16384 c:\windows\system32\dllcache\ds32gt.dll
+ 2006-02-28 12:00 . 2008-04-14 03:41 32768 c:\windows\system32\dllcache\dispex.dll
+ 2012-03-28 11:13 . 2008-04-14 03:41 39936 c:\windows\system32\dllcache\dimsroam.dll
+ 2012-03-28 11:13 . 2008-04-14 03:41 19456 c:\windows\system32\dllcache\dimsntfy.dll
+ 2006-02-28 12:00 . 2008-04-14 03:41 62464 c:\windows\system32\dllcache\cryptsvc.dll
+ 2006-02-28 12:00 . 2008-04-14 03:41 64512 c:\windows\system32\dllcache\cryptnet.dll
+ 2006-02-28 12:00 . 2008-04-14 03:41 53760 c:\windows\system32\dllcache\cryptext.dll
+ 2006-02-28 12:00 . 2008-04-14 03:41 33280 c:\windows\system32\dllcache\cryptdll.dll
+ 2006-02-28 12:00 . 2008-04-14 03:41 74752 c:\windows\system32\dllcache\cryptdlg.dll
+ 2006-02-28 12:00 . 2008-04-14 03:39 16896 c:\windows\system32\dllcache\cfgmgr32.dll
+ 2012-07-06 13:58 . 2012-07-06 13:58 78336 c:\windows\system32\dllcache\browser.dll
+ 2008-04-14 03:42 . 2008-04-14 03:42 16439 c:\windows\system32\dllcache\author.exe
+ 2008-04-14 03:41 . 2008-04-14 03:41 20540 c:\windows\system32\dllcache\author.dll
+ 2006-02-28 12:00 . 2008-04-14 03:41 30208 c:\windows\system32\dllcache\atmlib.dll
+ 2006-02-28 12:00 . 2010-03-05 14:37 65536 c:\windows\system32\dllcache\asycfilt.dll
- 2010-03-05 14:37 . 2010-03-05 14:37 65536 c:\windows\system32\dllcache\asycfilt.dll
+ 2012-03-28 11:11 . 2008-04-13 22:06 43008 c:\windows\system32\dllcache\amdagp.sys
+ 2012-08-15 23:18 . 2001-08-17 10:11 16969 c:\windows\system32\dllcache\amb8002.sys
+ 2006-02-28 12:00 . 2008-04-14 03:41 17408 c:\windows\system32\dllcache\alrsvc.dll
+ 2012-03-28 11:11 . 2008-04-13 22:06 42752 c:\windows\system32\dllcache\alim1541.sys
+ 2012-08-15 23:18 . 2001-08-17 11:49 26624 c:\windows\system32\dllcache\alifir.sys
+ 2012-08-15 23:18 . 2001-08-17 10:11 27678 c:\windows\system32\dllcache\ali5261.sys
+ 2006-02-28 12:00 . 2008-04-14 03:42 44544 c:\windows\system32\dllcache\alg.exe
+ 2012-08-15 23:18 . 2001-08-17 12:07 56960 c:\windows\system32\dllcache\aic78xx.sys
+ 2012-08-15 23:18 . 2001-08-17 12:07 55168 c:\windows\system32\dllcache\aic78u2.sys
+ 2006-02-28 12:00 . 2008-04-14 03:42 98304 c:\windows\system32\dllcache\ahui.exe
+ 2012-08-15 23:18 . 2001-08-17 11:52 12800 c:\windows\system32\dllcache\aha154x.sys
+ 2006-02-28 12:00 . 2008-04-14 03:41 24064 c:\windows\system32\dllcache\agtintl.dll
+ 2006-02-28 12:00 . 2007-04-02 21:56 20480 c:\windows\system32\dllcache\agt0c0a.dll
+ 2006-02-28 12:00 . 2007-04-02 21:56 20992 c:\windows\system32\dllcache\agt0816.dll
+ 2012-03-28 11:13 . 2007-04-02 21:56 19456 c:\windows\system32\dllcache\agt0804.dll
+ 2012-03-28 12:28 . 2007-04-02 21:56 19456 c:\windows\system32\dllcache\agt041f.dll
+ 2006-02-28 12:00 . 2007-04-02 21:56 19456 c:\windows\system32\dllcache\agt041d.dll
+ 2012-03-28 12:28 . 2007-04-02 21:56 19456 c:\windows\system32\dllcache\agt0419.dll
+ 2006-02-28 12:00 . 2007-04-02 21:56 20480 c:\windows\system32\dllcache\agt0416.dll
+ 2012-03-28 12:28 . 2007-04-02 21:56 19456 c:\windows\system32\dllcache\agt0415.dll
+ 2006-02-28 12:00 . 2007-04-02 21:56 19456 c:\windows\system32\dllcache\agt0414.dll
+ 2006-02-28 12:00 . 2007-04-02 21:56 20992 c:\windows\system32\dllcache\agt0413.dll
+ 2012-03-28 11:12 . 2007-04-02 21:56 19456 c:\windows\system32\dllcache\agt0412.dll
+ 2012-03-28 11:13 . 2007-04-02 21:56 19456 c:\windows\system32\dllcache\agt0411.dll
+ 2006-02-28 12:00 . 2007-04-02 21:56 20992 c:\windows\system32\dllcache\agt0410.dll
+ 2012-03-28 12:28 . 2007-04-02 21:56 19968 c:\windows\system32\dllcache\agt040e.dll
+ 2012-03-28 11:12 . 2007-04-02 21:56 19456 c:\windows\system32\dllcache\agt040d.dll
+ 2006-02-28 12:00 . 2007-04-02 21:56 21504 c:\windows\system32\dllcache\agt040c.dll
+ 2006-02-28 12:00 . 2007-04-02 21:56 19456 c:\windows\system32\dllcache\agt040b.dll
+ 2006-02-28 12:00 . 2008-04-13 21:02 19968 c:\windows\system32\dllcache\agt0409.dll
+ 2012-03-28 12:28 . 2007-04-02 21:56 22016 c:\windows\system32\dllcache\agt0408.dll
+ 2006-02-28 12:00 . 2007-04-02 21:56 21504 c:\windows\system32\dllcache\agt0407.dll
+ 2006-02-28 12:00 . 2007-04-02 21:56 19456 c:\windows\system32\dllcache\agt0406.dll
+ 2012-03-28 12:28 . 2007-04-02 21:56 19456 c:\windows\system32\dllcache\agt0405.dll
+ 2012-03-28 11:13 . 2007-04-02 21:56 19456 c:\windows\system32\dllcache\agt0404.dll
+ 2012-03-28 11:12 . 2007-04-02 21:56 19456 c:\windows\system32\dllcache\agt0401.dll
+ 2012-03-28 11:11 . 2008-04-13 22:06 44928 c:\windows\system32\dllcache\agpcpq.sys
+ 2012-03-28 11:11 . 2008-04-13 22:06 42368 c:\windows\system32\dllcache\agp440.sys
+ 2006-02-28 12:00 . 2008-04-14 03:41 44032 c:\windows\system32\dllcache\agentsr.dll
+ 2006-02-28 12:00 . 2008-04-14 03:41 24064 c:\windows\system32\dllcache\agentpsh.dll
+ 2006-02-28 12:00 . 2008-04-14 03:41 49152 c:\windows\system32\dllcache\agentmpx.dll
+ 2006-02-28 12:00 . 2008-04-14 03:41 57344 c:\windows\system32\dllcache\agentdpv.dll
+ 2006-02-28 12:00 . 2008-04-14 03:41 42496 c:\windows\system32\dllcache\agentdp2.dll
+ 2006-02-28 12:00 . 2008-04-14 03:41 24064 c:\windows\system32\dllcache\agentanm.dll
+ 2006-02-28 12:00 . 2008-04-14 03:41 68096 c:\windows\system32\dllcache\adsmsext.dll
+ 2012-08-15 23:18 . 2001-08-17 10:11 46112 c:\windows\system32\dllcache\adptsf50.sys
- 2012-03-28 11:36 . 2009-03-08 02:32 72704 c:\windows\system32\dllcache\admparse.dll
+ 2006-02-28 12:00 . 2009-03-08 02:32 72704 c:\windows\system32\dllcache\admparse.dll
+ 2012-08-15 23:18 . 2008-04-13 20:06 10880 c:\windows\system32\dllcache\admjoy.sys
+ 2008-04-14 03:42 . 2008-04-14 03:42 16439 c:\windows\system32\dllcache\admin.exe
+ 2008-04-14 03:41 . 2008-04-14 03:41 20540 c:\windows\system32\dllcache\admin.dll
+ 2012-08-15 23:18 . 2001-08-17 10:11 20160 c:\windows\system32\dllcache\adm8511.sys
+ 2006-02-28 12:00 . 2008-04-14 03:41 98304 c:\windows\system32\dllcache\actxprxy.dll
+ 2006-02-28 12:00 . 2006-02-28 12:00 11648 c:\windows\system32\dllcache\acpiec.sys
+ 2012-08-15 23:18 . 2001-08-17 20:36 61440 c:\windows\system32\dllcache\acerscad.dll
+ 2012-08-15 23:18 . 2008-04-13 20:06 84480 c:\windows\system32\dllcache\ac97via.sys
+ 2012-08-15 23:18 . 2001-08-17 10:20 96256 c:\windows\system32\dllcache\ac97intc.sys
+ 2012-08-15 23:18 . 2001-08-17 11:52 23552 c:\windows\system32\dllcache\abp480n5.sys
+ 2012-03-28 11:22 . 2001-08-17 20:36 98304 c:\windows\system32\dllcache\a3d.dll
+ 2012-03-28 11:22 . 2001-08-17 20:36 98304 c:\windows\system32\a3d.dll
- 2012-03-29 16:47 . 2012-07-12 05:34 35088 c:\windows\Installer\{90120000-0012-0000-0000-0000000FF1CE}\oisicon.exe
+ 2012-03-29 16:47 . 2012-08-16 05:07 35088 c:\windows\Installer\{90120000-0012-0000-0000-0000000FF1CE}\oisicon.exe
- 2012-03-29 16:47 . 2012-07-12 05:34 18704 c:\windows\Installer\{90120000-0012-0000-0000-0000000FF1CE}\mspicons.exe
+ 2012-03-29 16:47 . 2012-08-16 05:07 18704 c:\windows\Installer\{90120000-0012-0000-0000-0000000FF1CE}\mspicons.exe
+ 2012-03-29 16:47 . 2012-08-16 05:07 20240 c:\windows\Installer\{90120000-0012-0000-0000-0000000FF1CE}\cagicon.exe
- 2012-03-29 16:47 . 2012-07-12 05:34 20240 c:\windows\Installer\{90120000-0012-0000-0000-0000000FF1CE}\cagicon.exe
+ 2012-08-16 05:05 . 2012-05-11 14:42 12800 c:\windows\ie8updates\KB2722913-IE8\xpshims.dll
+ 2012-08-16 05:05 . 2012-05-11 14:42 67072 c:\windows\ie8updates\KB2722913-IE8\mshtmled.dll
+ 2012-08-16 05:05 . 2012-05-11 14:42 55296 c:\windows\ie8updates\KB2722913-IE8\msfeedsbs.dll
+ 2012-08-16 05:05 . 2012-05-11 14:42 43520 c:\windows\ie8updates\KB2722913-IE8\licmgr10.dll
+ 2012-08-16 05:05 . 2012-05-11 14:42 25600 c:\windows\ie8updates\KB2722913-IE8\jsproxy.dll
+ 2006-02-28 12:00 . 2008-04-14 03:42 5120 c:\windows\system32\dllcache\sfc.dll
+ 2012-03-28 10:34 . 2008-04-14 03:42 4096 c:\windows\system32\dllcache\msdaurl.dll
+ 2012-03-28 10:34 . 2008-04-14 03:42 4096 c:\windows\system32\dllcache\msdasc.dll
+ 2012-03-28 10:34 . 2008-04-14 03:42 4096 c:\windows\system32\dllcache\msdaer.dll
+ 2012-03-28 10:34 . 2008-04-14 03:42 4096 c:\windows\system32\dllcache\msdaenum.dll
+ 2012-03-28 10:34 . 2008-04-14 03:42 4096 c:\windows\system32\dllcache\msdadc.dll
+ 2012-03-28 11:13 . 2008-04-14 03:39 6144 c:\windows\system32\dllcache\kbdpash.dll
+ 2012-03-28 11:13 . 2008-04-14 03:39 6144 c:\windows\system32\dllcache\kbdnepr.dll
+ 2012-03-28 11:13 . 2008-04-14 03:39 6144 c:\windows\system32\dllcache\kbdiultn.dll
+ 2012-03-28 11:13 . 2008-04-14 03:39 6144 c:\windows\system32\dllcache\kbdbhc.dll
+ 2012-03-28 11:13 . 2008-04-14 03:41 7168 c:\windows\system32\dllcache\bitsprx4.dll
+ 2012-08-15 23:18 . 2001-08-17 11:51 5248 c:\windows\system32\dllcache\aliide.sys
+ 2012-03-28 11:11 . 2008-04-14 03:41 3775 c:\windows\system32\dllcache\adv11nt5.dll
+ 2012-03-28 11:11 . 2008-04-14 03:41 3711 c:\windows\system32\dllcache\adv09nt5.dll
+ 2012-03-28 11:11 . 2008-04-14 03:41 3135 c:\windows\system32\dllcache\adv08nt5.dll
+ 2012-03-28 11:11 . 2008-04-14 03:41 3647 c:\windows\system32\dllcache\adv07nt5.dll
+ 2012-03-28 11:11 . 2008-04-14 03:41 3615 c:\windows\system32\dllcache\adv05nt5.dll
+ 2012-03-28 11:11 . 2008-04-14 03:41 3967 c:\windows\system32\dllcache\adv02nt5.dll
+ 2012-03-28 11:11 . 2008-04-14 03:41 4255 c:\windows\system32\dllcache\adv01nt5.dll
+ 2012-08-15 23:18 . 2001-08-17 11:53 7424 c:\windows\system32\dllcache\adicvls.sys
+ 2006-02-28 12:00 . 2008-04-14 03:42 4096 c:\windows\system32\dllcache\actmovie.exe
+ 2006-02-28 12:00 . 2012-07-02 17:49 105984 c:\windows\system32\url.dll
- 2006-02-28 12:00 . 2012-05-11 14:42 105984 c:\windows\system32\url.dll
- 2006-02-28 12:00 . 2012-08-15 10:38 496908 c:\windows\system32\perfh009.dat
+ 2006-02-28 12:00 . 2012-08-16 05:28 496908 c:\windows\system32\perfh009.dat
+ 2006-02-28 12:00 . 2012-07-02 17:49 206848 c:\windows\system32\occache.dll
- 2006-02-28 12:00 . 2012-05-11 14:42 206848 c:\windows\system32\occache.dll
+ 2006-02-28 12:00 . 2012-07-06 13:58 337920 c:\windows\system32\netapi32.dll
- 2006-02-28 12:00 . 2012-05-11 14:42 611840 c:\windows\system32\mstime.dll
+ 2006-02-28 12:00 . 2012-07-02 17:49 611840 c:\windows\system32\mstime.dll
- 2012-03-28 11:36 . 2012-05-11 14:42 629760 c:\windows\system32\msfeeds.dll
+ 2012-03-28 11:36 . 2012-07-02 17:49 629760 c:\windows\system32\msfeeds.dll
+ 2012-08-15 11:27 . 2012-08-15 11:27 686792 c:\windows\system32\Macromed\Flash\FlashUtil32_11_3_300_271_Plugin.exe
+ 2012-03-29 19:29 . 2012-08-15 11:27 250056 c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
- 2012-03-29 19:29 . 2012-08-15 10:27 250056 c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
+ 2006-02-28 12:00 . 2012-05-14 09:22 345600 c:\windows\system32\localspl.dll
- 2006-02-28 12:00 . 2009-05-07 15:32 345600 c:\windows\system32\localspl.dll
+ 2006-02-28 12:00 . 2012-07-02 17:49 184320 c:\windows\system32\iepeers.dll
- 2006-02-28 12:00 . 2012-05-11 14:42 184320 c:\windows\system32\iepeers.dll
- 2006-02-28 12:00 . 2012-05-11 14:42 387584 c:\windows\system32\iedkcs32.dll
+ 2006-02-28 12:00 . 2012-07-02 17:49 387584 c:\windows\system32\iedkcs32.dll
- 2006-02-28 12:00 . 2012-05-11 11:38 174080 c:\windows\system32\ie4uinit.exe
+ 2006-02-28 12:00 . 2012-07-02 12:05 174080 c:\windows\system32\ie4uinit.exe
+ 2012-03-28 12:27 . 2012-08-16 05:23 414264 c:\windows\system32\FNTCACHE.DAT
- 2012-03-28 12:27 . 2012-08-12 04:51 414264 c:\windows\system32\FNTCACHE.DAT
- 2009-12-24 06:59 . 2012-02-29 14:10 177664 c:\windows\system32\dllcache\wintrust.dll
+ 2006-02-28 12:00 . 2012-02-29 14:10 177664 c:\windows\system32\dllcache\wintrust.dll
+ 2006-02-28 12:00 . 2008-04-14 03:42 507904 c:\windows\system32\dllcache\winlogon.exe
- 2012-03-28 11:36 . 2012-05-16 15:08 916992 c:\windows\system32\dllcache\wininet.dll
+ 2006-02-28 12:00 . 2012-07-02 17:49 916992 c:\windows\system32\dllcache\wininet.dll
+ 2006-02-28 12:00 . 2011-03-04 06:37 420864 c:\windows\system32\dllcache\vbscript.dll
- 2012-03-28 11:36 . 2011-03-04 06:37 420864 c:\windows\system32\dllcache\vbscript.dll
- 2012-03-28 11:36 . 2012-05-11 14:42 105984 c:\windows\system32\dllcache\url.dll
+ 2006-02-28 12:00 . 2012-07-02 17:49 105984 c:\windows\system32\dllcache\url.dll
+ 2006-02-28 12:00 . 2008-04-14 03:42 123392 c:\windows\system32\dllcache\umpnpmgr.dll
+ 2006-02-28 12:00 . 2008-04-14 03:42 106496 c:\windows\system32\dllcache\sysocmgr.exe
+ 2006-02-28 12:00 . 2012-06-04 04:32 152576 c:\windows\system32\dllcache\schannel.dll
- 2009-06-25 08:25 . 2012-06-04 04:32 152576 c:\windows\system32\dllcache\schannel.dll
+ 2006-02-28 12:00 . 2008-04-14 03:42 985088 c:\windows\system32\dllcache\setupapi.dll
- 2008-05-09 10:53 . 2008-05-09 10:53 172032 c:\windows\system32\dllcache\scrrun.dll
+ 2006-02-28 12:00 . 2008-05-09 10:53 172032 c:\windows\system32\dllcache\scrrun.dll
+ 2006-02-28 12:00 . 2008-05-09 10:53 180224 c:\windows\system32\dllcache\scrobj.dll
- 2008-05-09 10:53 . 2008-05-09 10:53 180224 c:\windows\system32\dllcache\scrobj.dll
+ 2006-02-28 12:00 . 2008-04-14 03:42 415744 c:\windows\system32\dllcache\samsrv.dll
+ 2006-02-28 12:00 . 2008-04-13 21:07 208384 c:\windows\system32\dllcache\rsaenh.dll
+ 2006-02-28 12:00 . 2008-04-14 03:42 433664 c:\windows\system32\dllcache\riched20.dll
+ 2012-03-28 11:28 . 2012-07-04 14:05 139784 c:\windows\system32\dllcache\rdpwd.sys
+ 2012-03-28 10:34 . 2008-04-14 03:42 487424 c:\windows\system32\dllcache\oledb32.dll
- 2010-12-20 17:32 . 2010-12-20 17:32 551936 c:\windows\system32\dllcache\oleaut32.dll
+ 2006-02-28 12:00 . 2010-12-20 17:32 551936 c:\windows\system32\dllcache\oleaut32.dll
+ 2006-02-28 12:00 . 2008-04-14 03:42 147456 c:\windows\system32\dllcache\odbctrac.dll
+ 2006-02-28 12:00 . 2008-04-14 03:42 278559 c:\windows\system32\dllcache\odbcjt32.dll
+ 2006-02-28 12:00 . 2008-04-14 03:42 106496 c:\windows\system32\dllcache\odbccp32.dll
+ 2006-02-28 12:00 . 2008-04-14 03:42 135168 c:\windows\system32\dllcache\odbcconf.dll
- 2010-11-09 14:52 . 2010-11-09 14:52 249856 c:\windows\system32\dllcache\odbc32.dll
+ 2006-02-28 12:00 . 2010-11-09 14:52 249856 c:\windows\system32\dllcache\odbc32.dll
+ 2012-03-28 11:36 . 2012-07-02 17:49 206848 c:\windows\system32\dllcache\occache.dll
- 2012-03-28 11:36 . 2012-05-11 14:42 206848 c:\windows\system32\dllcache\occache.dll
+ 2006-02-28 12:00 . 2008-04-13 22:45 574976 c:\windows\system32\dllcache\ntfs.sys
+ 2006-02-28 12:00 . 2010-12-09 15:15 718336 c:\windows\system32\dllcache\ntdll.dll
- 2012-03-28 11:55 . 2010-12-09 15:15 718336 c:\windows\system32\dllcache\ntdll.dll
+ 2006-02-28 12:00 . 2012-07-06 13:58 337920 c:\windows\system32\dllcache\netapi32.dll
+ 2006-02-28 12:00 . 2007-04-02 16:22 355104 c:\windows\system32\dllcache\msxbde40.dll
+ 2006-02-28 12:00 . 2007-04-02 16:21 621344 c:\windows\system32\dllcache\mswstr10.dll
+ 2006-02-28 12:00 . 2007-04-02 16:21 838432 c:\windows\system32\dllcache\mswdat10.dll
+ 2006-02-28 12:00 . 2008-04-14 03:42 343040 c:\windows\system32\dllcache\msvcrt.dll
+ 2012-03-28 11:36 . 2012-07-02 17:49 611840 c:\windows\system32\dllcache\mstime.dll
- 2012-03-28 11:36 . 2012-05-11 14:42 611840 c:\windows\system32\dllcache\mstime.dll
+ 2006-02-28 12:00 . 2007-04-02 16:21 264992 c:\windows\system32\dllcache\mstext40.dll
+ 2006-02-28 12:00 . 2007-04-02 16:21 559904 c:\windows\system32\dllcache\msrepl40.dll
+ 2006-02-28 12:00 . 2007-04-02 16:20 322336 c:\windows\system32\dllcache\msrd3x40.dll
+ 2006-02-28 12:00 . 2007-04-02 16:20 432928 c:\windows\system32\dllcache\msrd2x40.dll
+ 2006-02-28 12:00 . 2007-04-02 16:20 355104 c:\windows\system32\dllcache\mspbde40.dll
+ 2006-02-28 12:00 . 2008-04-14 03:42 143360 c:\windows\system32\dllcache\msorcl32.dll
+ 2006-02-28 12:00 . 2007-04-02 16:19 219936 c:\windows\system32\dllcache\msltus40.dll
+ 2006-02-28 12:00 . 2007-04-02 16:19 248608 c:\windows\system32\dllcache\msjtes40.dll
+ 2012-03-28 10:34 . 2010-11-09 14:52 102400 c:\windows\system32\dllcache\msjro.dll
- 2010-11-09 14:52 . 2010-11-09 14:52 102400 c:\windows\system32\dllcache\msjro.dll
+ 2006-02-28 12:00 . 2008-04-14 03:42 151583 c:\windows\system32\dllcache\msjint40.dll
+ 2012-03-28 11:36 . 2012-07-02 17:49 629760 c:\windows\system32\dllcache\msfeeds.dll
- 2012-03-28 11:36 . 2012-05-11 14:42 629760 c:\windows\system32\dllcache\msfeeds.dll
+ 2006-02-28 12:00 . 2007-04-02 16:17 518944 c:\windows\system32\dllcache\msexch40.dll
+ 2006-02-28 12:00 . 2007-04-02 16:18 326432 c:\windows\system32\dllcache\msexcl40.dll
+ 2012-03-28 10:34 . 2008-04-14 03:42 315392 c:\windows\system32\dllcache\msdasql.dll
+ 2012-03-28 10:34 . 2008-04-14 03:42 118784 c:\windows\system32\dllcache\msdarem.dll
+ 2012-03-28 10:34 . 2008-04-14 03:42 204800 c:\windows\system32\dllcache\msdaps.dll
+ 2012-03-28 10:34 . 2008-04-14 03:42 200704 c:\windows\system32\dllcache\msdaprst.dll
+ 2012-03-28 10:34 . 2008-04-14 03:42 233472 c:\windows\system32\dllcache\msdaora.dll
- 2010-11-09 14:52 . 2010-11-09 14:52 200704 c:\windows\system32\dllcache\msadox.dll
+ 2012-03-28 10:34 . 2010-11-09 14:52 200704 c:\windows\system32\dllcache\msadox.dll
+ 2012-03-28 10:34 . 2010-11-09 14:52 180224 c:\windows\system32\dllcache\msadomd.dll
- 2010-11-09 14:52 . 2010-11-09 14:52 180224 c:\windows\system32\dllcache\msadomd.dll
- 2010-11-09 14:52 . 2012-05-28 18:16 536576 c:\windows\system32\dllcache\msado15.dll
+ 2012-03-28 10:34 . 2012-05-28 18:16 536576 c:\windows\system32\dllcache\msado15.dll
+ 2012-03-28 10:34 . 2008-04-14 03:42 155648 c:\windows\system32\dllcache\msadds.dll
+ 2012-03-28 10:34 . 2010-11-09 14:52 143360 c:\windows\system32\dllcache\msadco.dll
- 2010-11-09 14:52 . 2010-11-09 14:52 143360 c:\windows\system32\dllcache\msadco.dll
- 2012-03-28 11:54 . 2008-05-01 14:33 331776 c:\windows\system32\dllcache\msadce.dll
+ 2012-03-28 10:34 . 2008-05-01 14:33 331776 c:\windows\system32\dllcache\msadce.dll
+ 2006-02-28 12:00 . 2011-02-08 13:33 974848 c:\windows\system32\dllcache\mfc42u.dll
- 2010-09-18 10:23 . 2011-02-08 13:33 974848 c:\windows\system32\dllcache\mfc42u.dll
- 2012-03-28 11:32 . 2011-02-08 13:33 978944 c:\windows\system32\dllcache\mfc42.dll
+ 2006-02-28 12:00 . 2011-02-08 13:33 978944 c:\windows\system32\dllcache\mfc42.dll
+ 2006-02-28 12:00 . 2010-09-18 06:53 953856 c:\windows\system32\dllcache\mfc40u.dll
- 2012-03-28 11:32 . 2010-09-18 06:53 953856 c:\windows\system32\dllcache\mfc40u.dll
- 2012-03-28 11:55 . 2010-12-20 17:26 730112 c:\windows\system32\dllcache\lsasrv.dll
+ 2006-02-28 12:00 . 2010-12-20 17:26 730112 c:\windows\system32\dllcache\lsasrv.dll
- 2009-05-07 15:32 . 2009-05-07 15:32 345600 c:\windows\system32\dllcache\localspl.dll
+ 2009-05-07 15:32 . 2012-05-14 09:22 345600 c:\windows\system32\dllcache\localspl.dll
- 2009-03-21 14:06 . 2009-03-21 14:06 989696 c:\windows\system32\dllcache\kernel32.dll
+ 2006-02-28 12:00 . 2009-03-21 14:06 989696 c:\windows\system32\dllcache\kernel32.dll
+ 2012-06-13 11:02 . 2012-07-02 17:49 521728 c:\windows\system32\dllcache\jsdbgui.dll
- 2012-06-13 11:02 . 2012-05-11 14:42 521728 c:\windows\system32\dllcache\jsdbgui.dll
- 2012-03-28 11:36 . 2011-03-04 06:37 726528 c:\windows\system32\dllcache\jscript.dll
+ 2006-02-28 12:00 . 2011-03-04 06:37 726528 c:\windows\system32\dllcache\jscript.dll
+ 2006-02-28 12:00 . 2008-04-14 03:41 138240 c:\windows\system32\dllcache\itss.dll
+ 2006-02-28 12:00 . 2008-04-14 03:41 155136 c:\windows\system32\dllcache\itircl.dll
- 2012-03-28 11:36 . 2012-05-11 14:42 247808 c:\windows\system32\dllcache\ieproxy.dll
+ 2012-03-28 11:36 . 2012-07-02 17:49 247808 c:\windows\system32\dllcache\ieproxy.dll
+ 2012-03-28 11:36 . 2012-07-02 17:49 184320 c:\windows\system32\dllcache\iepeers.dll
- 2012-03-28 11:36 . 2012-05-11 14:42 184320 c:\windows\system32\dllcache\iepeers.dll
- 2012-03-28 11:36 . 2012-05-11 14:42 743424 c:\windows\system32\dllcache\iedvtool.dll
+ 2012-03-28 11:36 . 2012-07-02 17:49 743424 c:\windows\system32\dllcache\iedvtool.dll
+ 2012-03-28 11:36 . 2012-07-02 17:49 387584 c:\windows\system32\dllcache\iedkcs32.dll
- 2012-03-28 11:36 . 2012-05-11 14:42 387584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2012-03-28 11:36 . 2012-07-02 12:05 174080 c:\windows\system32\dllcache\ie4uinit.exe
- 2012-03-28 11:36 . 2012-05-11 11:38 174080 c:\windows\system32\dllcache\ie4uinit.exe
+ 2007-04-02 20:06 . 2007-04-02 20:06 208896 c:\windows\system32\dllcache\fpmmcsat.dll
+ 2008-04-14 03:41 . 2008-04-14 03:41 598071 c:\windows\system32\dllcache\fpmmc.dll
+ 2008-04-14 03:42 . 2008-04-14 03:42 188494 c:\windows\system32\dllcache\fpcount.exe
+ 2008-04-14 03:42 . 2008-04-14 03:42 109840 c:\windows\system32\dllcache\fp98swin.exe
+ 2008-04-14 03:41 . 2008-04-14 03:41 876653 c:\windows\system32\dllcache\fp4awel.dll
+ 2008-04-14 03:41 . 2008-04-14 03:41 102509 c:\windows\system32\dllcache\fp4atxt.dll
+ 2008-04-14 03:41 . 2008-04-14 03:41 147513 c:\windows\system32\dllcache\fp4apws.dll
+ 2008-04-14 03:41 . 2008-04-14 03:41 184435 c:\windows\system32\dllcache\fp4amsft.dll
+ 2006-02-28 12:00 . 2008-04-13 22:44 143744 c:\windows\system32\dllcache\fastfat.sys
+ 2006-02-28 12:00 . 2008-04-14 03:41 380445 c:\windows\system32\dllcache\expsrv.dll
+ 2006-02-28 12:00 . 2008-04-13 21:07 138752 c:\windows\system32\dllcache\dssenh.dll
+ 2012-03-28 10:34 . 2008-01-19 14:34 554008 c:\windows\system32\dllcache\dao360.dll
+ 2006-02-28 12:00 . 2008-04-14 03:41 512512 c:\windows\system32\dllcache\cryptui.dll
- 2011-09-28 07:06 . 2012-05-31 13:22 599040 c:\windows\system32\dllcache\crypt32.dll
+ 2006-02-28 12:00 . 2012-05-31 13:22 599040 c:\windows\system32\dllcache\crypt32.dll
+ 2006-02-28 12:00 . 2008-04-14 03:41 252928 c:\windows\system32\dllcache\compatui.dll
+ 2006-02-28 12:00 . 2008-04-14 03:41 276992 c:\windows\system32\dllcache\comdlg32.dll
- 2012-03-28 12:01 . 2010-08-23 16:12 617472 c:\windows\system32\dllcache\comctl32.dll
+ 2006-02-28 12:00 . 2010-08-23 16:12 617472 c:\windows\system32\dllcache\comctl32.dll
+ 2008-04-14 03:42 . 2008-04-14 03:42 188480 c:\windows\system32\dllcache\cfgwiz.exe
+ 2012-03-28 11:13 . 2008-04-14 03:41 233472 c:\windows\system32\dllcache\azroles.dll
+ 2006-02-28 12:00 . 2008-04-14 03:41 125952 c:\windows\system32\dllcache\apphelp.dll
+ 2006-02-28 12:00 . 2008-04-14 03:42 256512 c:\windows\system32\dllcache\agentsvr.exe
+ 2006-02-28 12:00 . 2008-04-14 03:41 214016 c:\windows\system32\dllcache\agentctl.dll
- 2008-10-16 14:43 . 2011-08-17 13:49 138496 c:\windows\system32\dllcache\afd.sys
+ 2006-02-28 12:00 . 2011-08-17 13:49 138496 c:\windows\system32\dllcache\afd.sys
- 2012-03-28 11:36 . 2009-03-08 02:32 128512 c:\windows\system32\dllcache\advpack.dll
+ 2006-02-28 12:00 . 2009-03-08 02:32 128512 c:\windows\system32\dllcache\advpack.dll
+ 2006-02-28 12:00 . 2009-02-09 12:10 617472 c:\windows\system32\dllcache\advapi32.dll
- 2012-03-28 11:55 . 2009-02-09 12:10 617472 c:\windows\system32\dllcache\advapi32.dll
+ 2006-02-28 12:00 . 2008-04-14 03:41 263680 c:\windows\system32\dllcache\adsnt.dll
+ 2006-02-28 12:00 . 2008-04-14 03:41 143360 c:\windows\system32\dllcache\adsldpc.dll
+ 2006-02-28 12:00 . 2008-04-14 03:41 175616 c:\windows\system32\dllcache\adsldp.dll
+ 2012-08-15 23:18 . 2001-08-17 12:07 101888 c:\windows\system32\dllcache\adpu160m.sys
+ 2012-08-15 23:18 . 2001-08-17 10:19 747392 c:\windows\system32\dllcache\adm8830.sys
+ 2012-08-15 23:18 . 2001-08-17 10:19 553984 c:\windows\system32\dllcache\adm8820.sys
+ 2012-08-15 23:18 . 2001-08-17 10:19 584448 c:\windows\system32\dllcache\adm8810.sys
+ 2006-02-28 12:00 . 2008-04-14 03:41 116224 c:\windows\system32\dllcache\acxtrnal.dll
+ 2006-02-28 12:00 . 2008-04-14 03:41 193536 c:\windows\system32\dllcache\activeds.dll
+ 2006-02-28 12:00 . 2008-04-14 03:41 245248 c:\windows\system32\dllcache\acspecfc.dll
+ 2006-02-28 12:00 . 2008-04-13 22:06 187776 c:\windows\system32\dllcache\acpi.sys
+ 2006-02-28 12:00 . 2008-04-14 03:41 115712 c:\windows\system32\dllcache\aclui.dll
+ 2006-02-28 12:00 . 2008-04-14 03:41 141312 c:\windows\system32\dllcache\aclua.dll
+ 2006-02-28 12:00 . 2009-11-21 15:51 471552 c:\windows\system32\dllcache\aclayers.dll
- 2012-03-28 12:23 . 2009-11-21 15:51 471552 c:\windows\system32\dllcache\aclayers.dll
+ 2012-03-28 10:33 . 2008-04-14 03:42 184320 c:\windows\system32\dllcache\accwiz.exe
+ 2012-08-15 23:18 . 2001-08-17 10:20 297728 c:\windows\system32\dllcache\ac97sis.sys
+ 2012-08-15 23:18 . 2008-04-13 20:06 231552 c:\windows\system32\dllcache\ac97ali.sys
+ 2012-03-28 11:13 . 2008-04-14 03:41 136192 c:\windows\system32\dllcache\aaclient.dll
+ 2012-08-15 23:18 . 2001-08-17 20:36 462848 c:\windows\system32\dllcache\a3dapi.dll
- 2010-02-12 04:33 . 2010-02-12 04:33 100864 c:\windows\system32\dllcache\6to4svc.dll
+ 2006-02-28 12:00 . 2010-02-12 04:33 100864 c:\windows\system32\dllcache\6to4svc.dll
+ 2012-08-15 23:09 . 2012-08-15 23:09 739840 c:\windows\Installer\e3eec.msi
+ 2012-07-18 13:46 . 2012-07-18 13:46 593408 c:\windows\Installer\3ca8a.msp
- 2012-03-29 16:47 . 2012-07-12 05:34 888080 c:\windows\Installer\{90120000-0012-0000-0000-0000000FF1CE}\wordicon.exe
+ 2012-03-29 16:47 . 2012-08-16 05:07 888080 c:\windows\Installer\{90120000-0012-0000-0000-0000000FF1CE}\wordicon.exe
+ 2012-03-29 16:47 . 2012-08-16 05:07 922384 c:\windows\Installer\{90120000-0012-0000-0000-0000000FF1CE}\pptico.exe
- 2012-03-29 16:47 . 2012-07-12 05:34 922384 c:\windows\Installer\{90120000-0012-0000-0000-0000000FF1CE}\pptico.exe
- 2012-03-29 16:47 . 2012-07-12 05:34 845584 c:\windows\Installer\{90120000-0012-0000-0000-0000000FF1CE}\outicon.exe
+ 2012-03-29 16:47 . 2012-08-16 05:07 845584 c:\windows\Installer\{90120000-0012-0000-0000-0000000FF1CE}\outicon.exe
+ 2012-03-29 16:47 . 2012-08-16 05:07 217864 c:\windows\Installer\{90120000-0012-0000-0000-0000000FF1CE}\misc.exe
- 2012-03-29 16:47 . 2012-07-12 05:34 217864 c:\windows\Installer\{90120000-0012-0000-0000-0000000FF1CE}\misc.exe
+ 2011-06-23 07:54 . 2011-06-23 07:54 119160 c:\windows\Installer\$PatchCache$\Managed\00002109210000000000000000F01FEC\12.0.6612\MSCONV97.DLL
+ 2012-08-16 05:05 . 2012-05-16 15:08 916992 c:\windows\ie8updates\KB2722913-IE8\wininet.dll
+ 2012-08-16 05:05 . 2012-05-11 14:42 105984 c:\windows\ie8updates\KB2722913-IE8\url.dll
+ 2012-08-16 05:05 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2722913-IE8\spuninst\updspapi.dll
+ 2012-08-16 05:05 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2722913-IE8\spuninst\spuninst.exe
+ 2012-08-16 05:05 . 2012-05-11 14:42 206848 c:\windows\ie8updates\KB2722913-IE8\occache.dll
+ 2012-08-16 05:05 . 2012-05-11 14:42 611840 c:\windows\ie8updates\KB2722913-IE8\mstime.dll
+ 2012-08-16 05:05 . 2012-05-11 14:42 629760 c:\windows\ie8updates\KB2722913-IE8\msfeeds.dll
+ 2012-08-16 05:05 . 2012-05-11 14:42 521728 c:\windows\ie8updates\KB2722913-IE8\jsdbgui.dll
+ 2012-08-16 05:05 . 2012-05-11 14:42 247808 c:\windows\ie8updates\KB2722913-IE8\ieproxy.dll
+ 2012-08-16 05:05 . 2012-05-11 14:42 184320 c:\windows\ie8updates\KB2722913-IE8\iepeers.dll
+ 2012-08-16 05:05 . 2012-05-11 14:42 743424 c:\windows\ie8updates\KB2722913-IE8\iedvtool.dll
+ 2012-08-16 05:05 . 2012-05-11 14:42 387584 c:\windows\ie8updates\KB2722913-IE8\iedkcs32.dll
+ 2012-08-16 05:05 . 2012-05-11 11:38 174080 c:\windows\ie8updates\KB2722913-IE8\ie4uinit.exe
+ 2006-02-28 12:00 . 2012-07-02 17:49 1212416 c:\windows\system32\urlmon.dll
- 2006-02-28 12:00 . 2012-05-11 14:42 1212416 c:\windows\system32\urlmon.dll
+ 2006-02-28 12:00 . 2012-07-02 17:49 6008320 c:\windows\system32\mshtml.dll
+ 2012-08-15 11:27 . 2012-08-15 11:27 9465032 c:\windows\system32\Macromed\Flash\NPSWF32_11_3_300_271.dll
- 2012-03-28 11:36 . 2012-05-11 14:42 2000384 c:\windows\system32\iertutil.dll
+ 2012-03-28 11:36 . 2012-07-02 17:49 2000384 c:\windows\system32\iertutil.dll
- 2012-03-28 12:06 . 2012-06-13 13:19 1866112 c:\windows\system32\dllcache\win32k.sys
+ 2012-03-28 12:06 . 2012-07-03 13:40 1866112 c:\windows\system32\dllcache\win32k.sys
+ 2006-02-28 12:00 . 2012-07-02 17:49 1212416 c:\windows\system32\dllcache\urlmon.dll
- 2012-03-28 11:36 . 2012-05-11 14:42 1212416 c:\windows\system32\dllcache\urlmon.dll
+ 2006-02-28 12:00 . 2008-04-14 03:42 1614848 c:\windows\system32\dllcache\sfcfiles.dll
+ 2006-02-28 12:00 . 2011-11-01 16:07 1288704 c:\windows\system32\dllcache\ole32.dll
- 2010-07-16 12:05 . 2011-11-01 16:07 1288704 c:\windows\system32\dllcache\ole32.dll
+ 2006-02-28 12:00 . 2012-05-04 13:16 2148352 c:\windows\system32\dllcache\ntkrnlmp.exe
- 2012-03-28 11:54 . 2012-05-04 13:16 2148352 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2006-02-28 12:00 . 2007-10-22 13:00 1516568 c:\windows\system32\dllcache\msjet40.dll
+ 2012-03-28 11:36 . 2012-07-02 17:49 6008320 c:\windows\system32\dllcache\mshtml.dll
- 2012-03-28 11:36 . 2012-05-11 14:42 2000384 c:\windows\system32\dllcache\iertutil.dll
+ 2012-03-28 11:36 . 2012-07-02 17:49 2000384 c:\windows\system32\dllcache\iertutil.dll
+ 2006-02-28 12:00 . 2008-04-14 03:41 1852928 c:\windows\system32\dllcache\acgenral.dll
+ 2012-06-26 16:03 . 2012-06-26 16:03 3875840 c:\windows\Installer\3caae.msp
+ 2012-07-18 13:53 . 2012-07-18 13:53 5009920 c:\windows\Installer\3ca66.msp
- 2012-03-29 16:47 . 2012-07-12 05:34 1172240 c:\windows\Installer\{90120000-0012-0000-0000-0000000FF1CE}\xlicons.exe
+ 2012-03-29 16:47 . 2012-08-16 05:07 1172240 c:\windows\Installer\{90120000-0012-0000-0000-0000000FF1CE}\xlicons.exe
+ 2012-08-16 05:05 . 2012-05-11 14:42 1212416 c:\windows\ie8updates\KB2722913-IE8\urlmon.dll
+ 2012-08-16 05:05 . 2012-05-11 14:42 6007808 c:\windows\ie8updates\KB2722913-IE8\mshtml.dll
+ 2012-08-16 05:05 . 2012-05-11 14:42 2000384 c:\windows\ie8updates\KB2722913-IE8\iertutil.dll
+ 2012-03-28 11:36 . 2012-07-02 21:19 11111424 c:\windows\system32\ieframe.dll
- 2012-03-28 11:36 . 2012-05-11 18:12 11111424 c:\windows\system32\ieframe.dll
- 2012-03-28 11:36 . 2012-05-11 18:12 11111424 c:\windows\system32\dllcache\ieframe.dll
+ 2012-03-28 11:36 . 2012-07-02 21:19 11111424 c:\windows\system32\dllcache\ieframe.dll
+ 2012-07-25 14:59 . 2012-07-25 14:59 11032064 c:\windows\Installer\3ca9c.msp
+ 2012-07-18 13:53 . 2012-07-18 13:53 10937344 c:\windows\Installer\3ca78.msp
+ 2011-08-03 17:53 . 2011-08-03 17:53 17324928 c:\windows\Installer\$PatchCache$\Managed\00002109210000000000000000F01FEC\12.0.6612\MSO.DLL
+ 2012-08-16 05:05 . 2012-05-11 18:12 11111424 c:\windows\ie8updates\KB2722913-IE8\ieframe.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\documents and settings\Mato\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\documents and settings\Mato\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\documents and settings\Mato\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\documents and settings\Mato\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Diar.exe"="c:\program files\Diar\Diar.exe" [2006-11-01 1523200]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-10-16 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-10-16 13851752]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2008-03-10 689488]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2008-03-03 1848648]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\Mato\Start Menu\Programs\Startup\
Dropbox.lnk - c:\documents and settings\Mato\Application Data\Dropbox\bin\Dropbox.exe [2012-7-25 26909544]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Documents and Settings\\Tomas\\Local Settings\\Application Data\\Akamai\\netsession_win.exe"=
"c:\\Program Files\\Sega\\Virtua Tennis 4\\VT4.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\TeamViewer\\Version7\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version7\\TeamViewer_Service.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Electronic Arts\\Need For Speed World\\Data\\nfsw.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\buxo170\\counter-strike\\hl.exe"=
"c:\\Program Files\\Ubisoft\\Ubisoft Game Launcher\\UbisoftGameLauncher.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Documents and Settings\\Mato\\Application Data\\GameRanger\\GameRanger\\GameRanger.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"d:\\Stronghold-Crusader\\Stronghold Crusader\\Stronghold Crusader.exe"=
"d:\\Saints Row The Third\\saintsrowthethird.exe"=
"d:\\Assassin's Creed Brotherhood\\ACBSP.exe"=
"d:\\Assassin's Creed Brotherhood\\ACBMP.exe"=
"d:\\Assassin's Creed Brotherhood\\AssassinsCreedBrotherhood.exe"=
"d:\\Assassin's Creed Brotherhood\\UPlayBrowser.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\WINDOWS\\system32\\javaw.exe"=
"c:\\Documents and Settings\\Mato\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"57638:TCP"= 57638:TCP:Pando Media Booster
"57638:UDP"= 57638:UDP:Pando Media Booster
"3306:TCP"= 3306:TCP:MySQL5
"56180:TCP"= 56180:TCP:Pando Media Booster
"56180:UDP"= 56180:UDP:Pando Media Booster
"3837:TCP"= 3837:TCP:Akamai NetSession Interface
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [24. 7. 2012 14:33 242240]
R1 MpKsl476d73fd;MpKsl476d73fd;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{089DDDB6-3071-4F3B-9681-D30927234EC9}\MpKsl476d73fd.sys [16. 8. 2012 11:56 29904]
R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [27. 1. 2010 4:09 50704]
S2 Protector by IB Updater;Protector by IB Updater;c:\program files\Protector by IB\ExtensionUpdaterService.exe [26. 4. 2012 17:12 185856]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [15. 2. 2012 13:30 158856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [29. 3. 2012 21:29 250056]
S3 GGSAFERDriver;GGSAFER Driver;\??\c:\program files\Garena Plus\Room\safedrv.sys --> c:\program files\Garena Plus\Room\safedrv.sys [?]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [15. 1. 2010 14:49 227232]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [4. 5. 2012 15:32 113120]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - MPKSL476D73FD
.
Contents of the 'Scheduled Tasks' folder
.
2012-08-16 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-03-26 15:03]
.
2012-08-16 c:\windows\Tasks\User_Feed_Synchronization-{C3F05B38-74F2-43F3-AC79-E2DA93584543}.job
- c:\windows\system32\msfeedssync.exe [2012-03-28 02:31]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\documents and settings\Mato\Application Data\DVDVideoSoftIEHelpers\freeytvdownloader.htm
IE: Free YouTube to MP3 Converter - c:\documents and settings\Mato\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\Mato\Application Data\Mozilla\Firefox\Profiles\q2j5jg21.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-16 12:04
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2012-08-16 12:05:44
ComboFix-quarantined-files.txt 2012-08-16 10:05
ComboFix2.txt 2012-08-15 11:12
.
Pre-Run: 25 601 171 456 bytes free
Post-Run: 15 adresárov, 25 685 626 880 voľných bajtov
.
- - End Of File - - 7C86CAF43EF9723AA03BB949139D9519
Upload was successful

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Pravdepodobne vírus

#13 Příspěvek od vyosek »

:arrow: Skript pro ComboFix

Kód: Vybrat vše

KillAll::

FCopy::
c:\windows\ServicePackFiles\i386\explorer.exe | c:\windows\explorer.exe

Folder::
C:\Program Files\BabylonToolbar
c:\program files\SweetIM

File::
c:\documents and settings\All Users\Start Menu\Programs\Startup\GamersFirst LIVE!.lnk
c:\documents and settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-1078145449-839522115-1007Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-1078145449-839522115-1007UA.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{C3F05B38-74F2-43F3-AC79-E2DA93584543}.jo

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"=-
"uTorrent"=-
"Skype"=-
"DAEMON Tools Lite"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=-
"SweetIM"=-
"SunJavaUpdateSched"=-
"iTunesHelper"=-
"Microsoft Windows Service Host!"=-
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2193:TCP"=-
"5000:UDP"=-

DDS::
mStart Page = hxxp://home.sweetim.com
IE: Search the Web - c:\program files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html

Reboot::
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

BuXo
Návštěvník
Návštěvník
Příspěvky: 78
Registrován: 19 Srp 2011 20:27

Re: Pravdepodobne vírus

#14 Příspěvek od BuXo »

Ok, plochu je opäť vidieť a tu je log z CF:


ComboFix 12-08-16.01 - Mato . 08. 2012 12:55:07.5.2 - x86
Systém Microsoft Windows XP Home Edition 5.1.2600.3.1250.421.1033.18.2047.1555 [GMT 2:00]
Running from: c:\documents and settings\Mato\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Mato\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
FILE ::
"c:\documents and settings\All Users\Start Menu\Programs\Startup\GamersFirst LIVE!.lnk"
"c:\documents and settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk"
"c:\windows\tasks\Adobe Flash Player Updater.job"
"c:\windows\tasks\AppleSoftwareUpdate.job"
"c:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-1078145449-839522115-1007Core.job"
"c:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-1078145449-839522115-1007UA.job"
"c:\windows\tasks\User_Feed_Synchronization-{C3F05B38-74F2-43F3-AC79-E2DA93584543}.jo"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
--------------- FCopy ---------------
.
c:\windows\ServicePackFiles\i386\explorer.exe --> c:\windows\explorer.exe
.
((((((((((((((((((((((((( Files Created from 2012-07-16 to 2012-08-16 )))))))))))))))))))))))))))))))
.
.
2012-08-16 09:56 . 2012-08-16 09:56 29904 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{089DDDB6-3071-4F3B-9681-D30927234EC9}\MpKsl476d73fd.sys
2012-08-15 23:17 . 2008-04-13 22:16 48128 -c--a-w- c:\windows\system32\dllcache\61883.sys
2012-08-15 23:17 . 2001-08-17 12:55 38400 -c--a-w- c:\windows\system32\dllcache\8514a.dll
2012-08-15 23:17 . 2008-04-13 22:10 12288 -c--a-w- c:\windows\system32\dllcache\4mmdat.sys
2012-08-15 23:17 . 2001-08-17 10:48 148352 -c--a-w- c:\windows\system32\dllcache\3dfxvsm.sys
2012-08-15 23:17 . 2001-08-17 12:55 689216 -c--a-w- c:\windows\system32\dllcache\3dfxvs.dll
2012-08-15 23:17 . 2001-08-17 11:28 762780 -c--a-w- c:\windows\system32\dllcache\3cwmcru.sys
2012-08-15 23:17 . 2008-04-13 22:16 53376 -c--a-w- c:\windows\system32\dllcache\1394bus.sys
2012-08-15 23:17 . 2001-08-17 12:06 11264 -c--a-w- c:\windows\system32\dllcache\1394vdbg.sys
2012-08-15 23:17 . 2001-08-17 12:56 66048 -c--a-w- c:\windows\system32\dllcache\s3legacy.dll
2012-08-15 23:09 . 2012-08-15 23:09 -------- d-----w- c:\program files\Yamicsoft
2012-08-15 22:44 . 2012-08-15 22:44 29904 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{089DDDB6-3071-4F3B-9681-D30927234EC9}\MpKslc068e922.sys
2012-08-15 22:44 . 2012-08-16 09:55 56200 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{089DDDB6-3071-4F3B-9681-D30927234EC9}\offreg.dll
2012-08-15 11:27 . 2012-08-15 11:27 9826504 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2012-08-15 10:25 . 2012-08-15 10:38 -------- d-----w- c:\program files\trend micro
2012-08-15 10:25 . 2012-08-15 10:38 -------- d-----w- C:\rsit
2012-08-15 09:56 . 2012-06-29 08:44 6891424 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{089DDDB6-3071-4F3B-9681-D30927234EC9}\mpengine.dll
2012-08-14 05:46 . 2012-06-29 08:44 6891424 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-08-12 10:10 . 2012-08-12 10:10 -------- d-----w- c:\documents and settings\Mato\Local Settings\Application Data\Mozilla
2012-08-11 17:29 . 2012-08-11 17:30 -------- d-----w- c:\documents and settings\Tomas\Music
2012-08-09 22:14 . 2012-08-09 22:15 -------- d-----w- c:\documents and settings\Mato\Application Data\GHISLER
2012-08-09 22:14 . 2012-08-09 22:14 -------- d-----w- C:\totalcmd
2012-08-09 11:02 . 2012-08-09 11:02 -------- d-----w- c:\windows\system32\wbem\Repository
2012-08-09 11:00 . 2012-08-09 11:00 -------- d-----w- C:\Drivers
2012-08-09 10:17 . 2012-08-09 10:36 -------- d-----w- C:\Swsetup
2012-08-07 22:35 . 2012-08-07 22:35 -------- d-----w- c:\program files\Dropbox
2012-08-07 22:34 . 2012-08-15 10:35 -------- d-----w- c:\documents and settings\Mato\Application Data\Dropbox
2012-08-07 16:58 . 2012-08-07 16:58 -------- d-----w- c:\documents and settings\Ocino\Application Data\NVIDIA
2012-08-05 15:45 . 2012-08-05 15:46 -------- d-----w- c:\documents and settings\Mamina\Local Settings\Application Data\GamersFirst LIVE!
2012-08-05 15:35 . 2012-08-05 15:35 -------- d-----w- c:\documents and settings\Mamina\Local Settings\Application Data\Pando_Temp
2012-08-05 12:25 . 2012-08-05 12:25 -------- d-----w- c:\documents and settings\Ocino\Local Settings\Application Data\GamersFirst LIVE!
2012-08-05 12:01 . 2012-08-05 12:01 -------- d-----w- c:\documents and settings\Ocino\Local Settings\Application Data\Pando_Temp
2012-08-04 21:13 . 2012-08-05 17:25 281288 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-08-04 21:13 . 2012-08-04 21:13 -------- d-----w- c:\documents and settings\Mato\Local Settings\Application Data\PunkBuster
2012-08-04 21:12 . 2012-08-04 21:12 -------- d-----w- c:\documents and settings\Mato\Application Data\NVIDIA
2012-08-04 21:10 . 2012-08-05 17:25 138992 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-08-04 21:10 . 2012-08-04 21:10 138904 ----a-w- c:\documents and settings\Mato\Application Data\PnkBstrK.sys
2012-08-04 21:09 . 2012-08-04 21:09 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2012-08-04 16:10 . 2012-08-04 16:11 -------- d-----w- c:\documents and settings\Mato\Local Settings\Application Data\GamersFirst LIVE!
2012-08-04 16:10 . 2012-08-15 17:52 -------- d-----w- c:\documents and settings\Mato\Local Settings\Application Data\PMB Files
2012-08-04 16:10 . 2012-08-04 16:10 -------- d-----w- c:\documents and settings\Mato\Local Settings\Application Data\Pando_Temp
2012-08-04 16:07 . 2012-08-04 16:07 -------- d-----w- c:\program files\GamersFirst
2012-08-02 08:41 . 2012-08-02 08:41 -------- d-----w- c:\documents and settings\Mato\Application Data\Ubisoft
2012-08-02 08:33 . 2012-08-02 14:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Solidshield
2012-08-02 08:32 . 2012-08-02 08:32 -------- d-----w- c:\documents and settings\Mato\Application Data\PunkBuster
2012-07-26 21:53 . 2012-07-26 21:53 -------- d-----w- c:\documents and settings\Mato\Application Data\PSpad
2012-07-26 21:47 . 2012-07-26 21:51 -------- d-----w- c:\program files\PSPad editor
2012-07-26 21:15 . 2012-07-26 21:16 -------- d-----w- c:\program files\EasyPHP-12.0
2012-07-26 17:00 . 2012-07-26 17:05 -------- d-----w- c:\documents and settings\Mato\Application Data\MySQL
2012-07-26 16:46 . 2012-07-26 17:34 -------- d-----w- c:\program files\MySQL
2012-07-26 16:46 . 2012-07-26 17:31 -------- d-----w- c:\documents and settings\All Users\Application Data\MySQL
2012-07-26 15:59 . 2012-07-26 17:26 -------- d-----w- c:\program files\Apache
2012-07-25 19:23 . 2012-07-25 19:23 -------- d-----w- c:\documents and settings\Mato\Application Data\GameRanger
2012-07-25 15:21 . 2012-07-25 15:21 -------- d-----w- c:\documents and settings\Mato\Local Settings\Application Data\DVDVideoSoft_Ltd
2012-07-25 09:34 . 2012-07-25 09:34 -------- d-----w- c:\documents and settings\Mato\Local Settings\Application Data\Ubisoft Game Launcher
2012-07-24 18:28 . 2012-08-11 16:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Ubisoft
2012-07-24 17:54 . 2012-08-05 17:25 281288 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-07-24 17:54 . 2012-08-05 05:27 281288 ----a-w- c:\windows\system32\PnkBstrB.ex0
2012-07-24 17:54 . 2012-08-04 21:10 76888 ----a-w- c:\windows\system32\PnkBstrA.exe
2012-07-24 17:53 . 2012-07-24 17:53 -------- d-----w- c:\program files\Ubisoft
2012-07-24 12:40 . 2012-07-24 12:40 -------- d-----w- c:\documents and settings\Mato\Local Settings\Application Data\Focus Home Interactive
2012-07-24 12:33 . 2012-07-24 12:33 242240 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-07-24 12:33 . 2012-07-24 12:39 -------- d-----w- c:\documents and settings\Mato\Application Data\DAEMON Tools Lite
2012-07-24 12:33 . 2012-07-24 12:33 -------- d-----w- c:\program files\DAEMON Tools Lite
2012-07-24 12:32 . 2012-07-24 12:39 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2012-07-22 18:33 . 2012-07-22 18:36 -------- d-----w- c:\documents and settings\Ocino\Local Settings\Application Data\VDownloader
2012-07-22 18:33 . 2012-07-22 18:33 -------- d-----w- c:\documents and settings\Ocino\Application Data\VDownloader
2012-07-22 08:35 . 2012-07-22 09:45 -------- d-----w- c:\documents and settings\Mamina\Application Data\VDownloader
2012-07-22 08:35 . 2012-07-22 18:33 -------- d-----w- c:\documents and settings\Mamina\Local Settings\Application Data\VDownloader
2012-07-20 22:27 . 2012-07-20 22:27 -------- d-----w- c:\documents and settings\Mato\Application Data\VDownloader
2012-07-20 22:27 . 2012-07-21 08:53 -------- d-----w- c:\documents and settings\Mato\Local Settings\Application Data\VDownloader
2012-07-17 20:25 . 2012-07-17 20:25 -------- d-----w- c:\documents and settings\Mato\Application Data\Need for Speed World
2012-07-17 20:24 . 2012-07-17 20:24 -------- d-----w- c:\documents and settings\Mato\Local Settings\Application Data\Electronic_Arts_Inc
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-15 11:27 . 2012-03-29 19:29 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-15 11:27 . 2012-03-28 11:33 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-06 13:58 . 2006-02-28 12:00 78336 ----a-w- c:\windows\system32\browser.dll
2012-07-04 14:05 . 2012-03-28 10:33 139784 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-07-03 13:40 . 2006-02-28 12:00 1866112 ----a-w- c:\windows\system32\win32k.sys
2012-07-02 17:49 . 2006-02-28 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-07-02 17:49 . 2006-02-28 12:00 43520 ------w- c:\windows\system32\licmgr10.dll
2012-07-02 17:49 . 2006-02-28 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-07-02 12:05 . 2006-02-28 12:00 385024 ------w- c:\windows\system32\html.iec
2012-06-22 14:32 . 2012-07-05 10:51 405144 ----a-w- c:\windows\system32\Newtonsoft.Json.Net20.dll
2012-06-06 18:59 . 2012-06-06 18:59 1070152 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2012-06-05 15:50 . 2012-03-28 11:13 1372672 ----a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:50 . 2006-02-28 12:00 1172480 ----a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2006-02-28 12:00 152576 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 13:19 . 2009-08-06 17:24 22040 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 13:19 . 2012-03-28 10:34 329240 ----a-w- c:\windows\system32\wucltui.dll
2012-06-02 13:19 . 2012-03-28 10:34 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 13:19 . 2012-03-28 10:34 210968 ----a-w- c:\windows\system32\wuweb.dll
2012-06-02 13:19 . 2009-08-06 17:24 15384 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 13:19 . 2012-03-28 10:34 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 13:19 . 2012-03-28 10:34 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 13:19 . 2009-08-06 17:24 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 13:19 . 2009-08-06 17:24 15384 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 13:19 . 2006-02-28 12:00 97304 ----a-w- c:\windows\system32\cdm.dll
2012-06-02 13:19 . 2009-08-06 17:24 17944 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 13:19 . 2012-03-28 10:34 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 13:19 . 2012-03-28 10:34 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 13:18 . 2012-03-29 12:03 275696 ----a-w- c:\windows\system32\mucltui.dll
2012-06-02 13:18 . 2012-03-29 12:03 17136 ----a-w- c:\windows\system32\mucltui.dll.mui
2012-06-02 13:18 . 2009-08-06 17:23 214256 ----a-w- c:\windows\system32\muweb.dll
2012-05-31 13:22 . 2006-02-28 12:00 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-16 13:12 . 2012-04-13 20:33 3623592 ----a-w- c:\program files\Common Files\ApnToolbarInstaller.exe
2011-09-16 13:12 . 2012-04-13 20:33 143240 ----a-w- c:\program files\Common Files\ApnStub.exe
2012-07-19 05:10 . 2012-03-29 16:23 136672 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot_2012-08-16_10.04.22 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-08-16 11:01 . 2012-08-16 11:01 16384 c:\windows\temp\Perflib_Perfdata_e4.dat
- 2006-02-28 12:00 . 2012-08-16 05:28 85392 c:\windows\system32\perfc009.dat
+ 2006-02-28 12:00 . 2012-08-16 11:02 85392 c:\windows\system32\perfc009.dat
+ 2006-02-28 12:00 . 2012-08-16 11:02 496908 c:\windows\system32\perfh009.dat
- 2006-02-28 12:00 . 2012-08-16 05:28 496908 c:\windows\system32\perfh009.dat
+ 2006-02-28 12:00 . 2008-04-14 03:42 1033728 c:\windows\system32\dllcache\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\documents and settings\Mato\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\documents and settings\Mato\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\documents and settings\Mato\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\documents and settings\Mato\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Diar.exe"="c:\program files\Diar\Diar.exe" [2006-11-01 1523200]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-10-16 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-10-16 13851752]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2008-03-10 689488]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2008-03-03 1848648]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\Mato\Start Menu\Programs\Startup\
Dropbox.lnk - c:\documents and settings\Mato\Application Data\Dropbox\bin\Dropbox.exe [2012-7-25 26909544]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Documents and Settings\\Tomas\\Local Settings\\Application Data\\Akamai\\netsession_win.exe"=
"c:\\Program Files\\Sega\\Virtua Tennis 4\\VT4.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\TeamViewer\\Version7\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version7\\TeamViewer_Service.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Electronic Arts\\Need For Speed World\\Data\\nfsw.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\buxo170\\counter-strike\\hl.exe"=
"c:\\Program Files\\Ubisoft\\Ubisoft Game Launcher\\UbisoftGameLauncher.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Documents and Settings\\Mato\\Application Data\\GameRanger\\GameRanger\\GameRanger.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"d:\\Stronghold-Crusader\\Stronghold Crusader\\Stronghold Crusader.exe"=
"d:\\Saints Row The Third\\saintsrowthethird.exe"=
"d:\\Assassin's Creed Brotherhood\\ACBSP.exe"=
"d:\\Assassin's Creed Brotherhood\\ACBMP.exe"=
"d:\\Assassin's Creed Brotherhood\\AssassinsCreedBrotherhood.exe"=
"d:\\Assassin's Creed Brotherhood\\UPlayBrowser.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\WINDOWS\\system32\\javaw.exe"=
"c:\\Documents and Settings\\Mato\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"57638:TCP"= 57638:TCP:Pando Media Booster
"57638:UDP"= 57638:UDP:Pando Media Booster
"3306:TCP"= 3306:TCP:MySQL5
"56180:TCP"= 56180:TCP:Pando Media Booster
"56180:UDP"= 56180:UDP:Pando Media Booster
"3837:TCP"= 3837:TCP:Akamai NetSession Interface
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [24. 7. 2012 14:33 242240]
R1 MpKsl07aec52e;MpKsl07aec52e;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{089DDDB6-3071-4F3B-9681-D30927234EC9}\MpKsl07aec52e.sys [16. 8. 2012 13:01 29904]
R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [27. 1. 2010 4:09 50704]
R2 Protector by IB Updater;Protector by IB Updater;c:\program files\Protector by IB\ExtensionUpdaterService.exe [26. 4. 2012 17:12 185856]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [15. 2. 2012 13:30 158856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [29. 3. 2012 21:29 250056]
S3 GGSAFERDriver;GGSAFER Driver;\??\c:\program files\Garena Plus\Room\safedrv.sys --> c:\program files\Garena Plus\Room\safedrv.sys [?]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [15. 1. 2010 14:49 227232]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [4. 5. 2012 15:32 113120]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - MPKSL07AEC52E
.
Contents of the 'Scheduled Tasks' folder
.
2012-08-16 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-03-26 15:03]
.
2012-08-16 c:\windows\Tasks\User_Feed_Synchronization-{C3F05B38-74F2-43F3-AC79-E2DA93584543}.job
- c:\windows\system32\msfeedssync.exe [2012-03-28 02:31]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\documents and settings\Mato\Application Data\DVDVideoSoftIEHelpers\freeytvdownloader.htm
IE: Free YouTube to MP3 Converter - c:\documents and settings\Mato\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\Mato\Application Data\Mozilla\Firefox\Profiles\q2j5jg21.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-16 13:01
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(2232)
c:\windows\system32\WININET.dll
c:\documents and settings\Mato\Application Data\Dropbox\bin\DropboxExt.14.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Canon\IJPLM\IJPLMSVC.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2012-08-16 13:05:49 - machine was rebooted
ComboFix-quarantined-files.txt 2012-08-16 11:05
ComboFix2.txt 2012-08-16 10:23
ComboFix3.txt 2012-08-15 11:12
.
Pre-Run: 25 713 242 112 bytes free
Post-Run: 15 adresárov, 25 721 872 384 voľných bajtov
.
- - End Of File - - 4C8BABEE750120FE970435A6E43D9388

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Pravdepodobne vírus

#15 Příspěvek od vyosek »

:arrow: On byl totiz soubor co plochu zajistuje napadeny haveti

:arrow: Nasledujici soubory otestujte na VirusTotalu https://www.virustotal.com/cs/
  • c:\windows\system32\dllcache\61883.sys
    c:\windows\system32\dllcache\8514a.dll
    c:\windows\system32\dllcache\3cwmcru.sys
  • Kliknete na Choose file
  • Soubor nehledejte, jen vlozte cestu souboru, ktery chci otestovat
  • Kliknete na Scan It
  • Pokud na Vas vyskoci obrazovka jako je nize, tak kliknete na ReAnalyse
    Obrázek
  • Vysledek analyzy sem vlozte (jako odkaz)
:arrow: Stahnete SytemLook http://jpshortstuff.247fixes.com/SystemLook.exe a ulozte jej na plochu
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    :folderfind
    Akamai
    
    :regfind
    Akamai
  • Kliknete na Look
  • Tlacitko Look se zmeni na Scanning a zsedne
  • Pockejte pokud se tlacitko Scanning opet nezmeni na Look - tak poznate ze SystemLook dokoncil svou praci
  • Vyskoci na Vas log s nazvem SystemLook (pripadne bude ulozen na plose), jeho obsah mi sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Zamčeno