Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Startup DIALOG a Keylogger

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
dendulo13
Návštěvník
Návštěvník
Příspěvky: 4
Registrován: 15 srp 2013 00:26

Startup DIALOG a Keylogger

#1 Příspěvek od dendulo13 »

Zdravím chcel by som sa spytať ako odstranit tento STARTUP dialog
http://imageshack.com/scaled/large/849/z0ef.jpg vzdy to vyskoci ked sa zapne windows tato tabulka

a potom sa chcem este spytat ako vo windows xp odstranit s tejto ponuky tieto vecicky mam to nainstalovane
koli detom a oni vedia ze sa to tam da pozriet, mozete mi to pomoct nejako odstranit cez system nejak?

http://www.abcreate.sk/2.jpg

Logfile of random's system information tool 1.06 (written by random/random)
Run by Sabrina at 2013-08-15 04:12:29
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 217 GB (91%) free of 238 GB
Total RAM: 3070 MB (86% free)

HijackThis download failed

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"=C:\WINDOWS\system32\WLTRAY.exe [2008-06-02 2220032]
"NtVdmSrv"=C:\WINDOWS\inf\ntvdm.vbe [2013-06-20 1219]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
C:\Program Files\DellTPad\Apoint.exe [2007-12-14 159744]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2008-04-22 139264]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll [2008-07-09 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2013-08-15 09:20:25 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2013-08-15 09:20:16 ----A---- C:\WINDOWS\system32\MSSTDFMT.DLL
2013-08-15 09:20:15 ----A---- C:\WINDOWS\system32\IJL_11.DLL
2013-08-15 08:56:05 ----D---- C:\Program Files\IDT
2013-08-15 08:51:12 ----HDC---- C:\WINDOWS\$NtUninstallWdf01005$
2013-08-15 08:50:55 ----D---- C:\Program Files\DellTPad
2013-08-15 08:50:51 ----A---- C:\WINDOWS\system32\WdfCoInstaller01005.dll
2013-08-15 08:50:51 ----A---- C:\WINDOWS\system32\Vxdif.dll
2013-08-15 08:49:42 ----A---- C:\WINDOWS\system32\OA001Srv.exe
2013-08-15 08:49:42 ----A---- C:\WINDOWS\system32\OA001Pin.dll
2013-08-15 08:49:42 ----A---- C:\WINDOWS\OA001Cfg.exe
2013-08-15 08:49:42 ----A---- C:\WINDOWS\CtDrvIns.exe
2013-08-15 08:42:17 ----A---- C:\WINDOWS\system32\stlang.dll
2013-08-15 08:42:17 ----A---- C:\WINDOWS\system32\stacsv.exe
2013-08-15 08:42:17 ----A---- C:\WINDOWS\sttray.exe
2013-08-15 08:42:05 ----A---- C:\WINDOWS\system32\staco.dll
2013-08-15 08:42:00 ----A---- C:\WINDOWS\system32\stacapi.dll
2013-08-15 08:39:31 ----N---- C:\WINDOWS\system32\ati2sgag.exe
2013-08-15 08:39:20 ----HD---- C:\Program Files\InstallShield Installation Information
2013-08-15 08:39:12 ----D---- C:\Program Files\Common Files\InstallShield
2013-08-15 08:39:07 ----A---- C:\WINDOWS\system32\Oemdspif.dll
2013-08-15 08:39:07 ----A---- C:\WINDOWS\system32\ativvaxx.dll
2013-08-15 08:39:07 ----A---- C:\WINDOWS\system32\ativcoxx.dll
2013-08-15 08:39:07 ----A---- C:\WINDOWS\system32\atitvo32.dll
2013-08-15 08:39:07 ----A---- C:\WINDOWS\system32\atipdlxx.dll
2013-08-15 08:39:07 ----A---- C:\WINDOWS\system32\atiok3x2.dll
2013-08-15 08:39:06 ----A---- C:\WINDOWS\system32\atioglxx.dll
2013-08-15 08:39:05 ----A---- C:\WINDOWS\system32\atioglx2.dll
2013-08-15 08:39:05 ----A---- C:\WINDOWS\system32\atikvmag.dll
2013-08-15 08:39:05 ----A---- C:\WINDOWS\system32\atiiiexx.dll
2013-08-15 08:39:05 ----A---- C:\WINDOWS\system32\ATIDEMGX.dll
2013-08-15 08:39:05 ----A---- C:\WINDOWS\system32\ATIDDC.DLL
2013-08-15 08:39:05 ----A---- C:\WINDOWS\system32\atiadlxx.dll
2013-08-15 08:39:05 ----A---- C:\WINDOWS\system32\ati3duag.dll
2013-08-15 08:39:05 ----A---- C:\WINDOWS\system32\Ati2mdxx.exe
2013-08-15 08:39:05 ----A---- C:\WINDOWS\system32\ati2evxx.exe
2013-08-15 08:39:05 ----A---- C:\WINDOWS\system32\ati2evxx.dll
2013-08-15 08:39:05 ----A---- C:\WINDOWS\system32\ati2edxx.dll
2013-08-15 08:39:05 ----A---- C:\WINDOWS\system32\ati2dvag.dll
2013-08-15 08:39:05 ----A---- C:\WINDOWS\system32\ati2cqag.dll
2013-08-15 08:39:05 ----A---- C:\WINDOWS\system32\amdpcom32.dll
2013-08-15 08:35:03 ----D---- C:\WINDOWS\system32\ReinstallBackups
2013-08-15 08:35:00 ----D---- C:\Program Files\Intel
2013-08-15 08:34:54 ----D---- C:\Intel
2013-08-15 08:34:20 ----D---- C:\Program Files\DIFX
2013-08-15 08:34:18 ----DC---- C:\WINDOWS\system32\DRVSTORE
2013-08-15 08:33:33 ----A---- C:\WINDOWS\system32\BCMLogon.dll
2013-08-15 08:33:31 ----A---- C:\WINDOWS\system32\vcredist_x86.bat
2013-08-15 08:33:30 ----A---- C:\WINDOWS\system32\vcredist_x86.exe
2013-08-15 08:33:30 ----A---- C:\WINDOWS\system32\preflib.dll
2013-08-15 08:33:30 ----A---- C:\WINDOWS\system32\bcmwlu00.exe
2013-08-15 08:33:29 ----A---- C:\WINDOWS\system32\wltrynt.dll
2013-08-15 08:33:29 ----A---- C:\WINDOWS\system32\WLTRAY.EXE
2013-08-15 08:33:29 ----A---- C:\WINDOWS\system32\BCMWLTRY.EXE
2013-08-15 08:33:29 ----A---- C:\WINDOWS\system32\bcmwlpkt.dll
2013-08-15 08:33:28 ----A---- C:\WINDOWS\system32\WLTRYSVC.EXE
2013-08-15 08:33:28 ----A---- C:\WINDOWS\system32\WLBCGCBPRO731.DLL
2013-08-15 08:33:28 ----A---- C:\WINDOWS\system32\bcmwlapi.dll
2013-08-15 08:33:27 ----D---- C:\Program Files\Dell
2013-08-15 08:33:27 ----A---- C:\WINDOWS\system32\bcm1xsup.dll
2013-08-15 08:33:21 ----D---- C:\Documents and Settings\Sabrina\Application Data\InstallShield
2013-08-15 08:33:11 ----D---- C:\dell
2013-08-15 07:09:27 ----D---- C:\Documents and Settings\Sabrina\Application Data\Identities
2013-08-15 07:09:24 ----HD---- C:\Program Files\Uninstall Information
2013-08-15 07:05:03 ----A---- C:\WINDOWS\system32\WMErrSKY.dll
2013-08-15 07:05:01 ----D---- C:\WINDOWS\system32\1051
2013-08-15 07:04:29 ----D---- C:\temp
2013-08-15 07:03:18 ----ASH---- C:\Documents and Settings\Sabrina\Application Data\desktop.ini
2013-08-15 07:03:17 ----SD---- C:\Documents and Settings\Sabrina\Application Data\Microsoft
2013-08-15 06:59:42 ----D---- C:\WINDOWS\SoftwareDistribution
2013-08-15 06:59:39 ----D---- C:\WINDOWS\Prefetch
2013-08-15 06:59:38 ----SD---- C:\WINDOWS\system32\Microsoft
2013-08-15 06:59:38 ----A---- C:\WINDOWS\SchedLgU.Txt
2013-08-15 06:54:04 ----D---- C:\WINDOWS\system32\xircom
2013-08-15 06:54:04 ----D---- C:\Program Files\xerox
2013-08-15 06:54:04 ----D---- C:\Program Files\msn gaming zone
2013-08-15 06:54:04 ----D---- C:\Program Files\microsoft frontpage
2013-08-15 06:53:00 ----D---- C:\WINDOWS\system32\ar-sa
2013-08-15 06:52:58 ----D---- C:\WINDOWS\system32\pt-br
2013-08-15 06:52:58 ----D---- C:\WINDOWS\system32\bg-bg
2013-08-15 06:52:56 ----D---- C:\WINDOWS\system32\zh-cn
2013-08-15 06:52:54 ----D---- C:\WINDOWS\system32\zh-tw
2013-08-15 06:52:52 ----D---- C:\WINDOWS\system32\cs-cz
2013-08-15 06:52:50 ----D---- C:\WINDOWS\system32\da-dk
2013-08-15 06:52:48 ----D---- C:\WINDOWS\system32\el-gr
2013-08-15 06:52:46 ----D---- C:\WINDOWS\system32\es-es
2013-08-15 06:52:44 ----D---- C:\WINDOWS\system32\fi-fi
2013-08-15 06:52:44 ----D---- C:\WINDOWS\system32\et-ee
2013-08-15 06:52:42 ----D---- C:\WINDOWS\system32\fr-fr
2013-08-15 06:52:40 ----D---- C:\WINDOWS\system32\de-de
2013-08-15 06:52:38 ----D---- C:\WINDOWS\system32\he-il
2013-08-15 06:52:36 ----D---- C:\WINDOWS\system32\hu-hu
2013-08-15 06:52:36 ----D---- C:\WINDOWS\system32\hr-hr
2013-08-15 06:52:35 ----D---- C:\WINDOWS\system32\it-it
2013-08-15 06:52:33 ----D---- C:\WINDOWS\system32\ja-jp
2013-08-15 06:52:30 ----D---- C:\WINDOWS\system32\ko-kr
2013-08-15 06:52:29 ----D---- C:\WINDOWS\system32\nl-nl
2013-08-15 06:52:29 ----D---- C:\WINDOWS\system32\lv-lv
2013-08-15 06:52:29 ----D---- C:\WINDOWS\system32\lt-lt
2013-08-15 06:52:27 ----D---- C:\WINDOWS\system32\nb-no
2013-08-15 06:52:25 ----D---- C:\WINDOWS\system32\pl-pl
2013-08-15 06:52:24 ----D---- C:\WINDOWS\system32\pt-pt
2013-08-15 06:52:22 ----D---- C:\WINDOWS\system32\ru-ru
2013-08-15 06:52:22 ----D---- C:\WINDOWS\system32\ro-ro
2013-08-15 06:52:20 ----D---- C:\WINDOWS\system32\sk-sk
2013-08-15 06:52:19 ----D---- C:\WINDOWS\system32\sv-se
2013-08-15 06:52:19 ----D---- C:\WINDOWS\system32\sl-si
2013-08-15 06:52:17 ----D---- C:\WINDOWS\system32\tr-tr
2013-08-15 06:52:17 ----D---- C:\WINDOWS\system32\th-th
2013-08-15 06:51:50 ----D---- C:\WINDOWS\system32\PreInstall
2013-08-15 06:51:49 ----N---- C:\WINDOWS\system32\spmsg.dll
2013-08-15 06:51:49 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2013-08-15 06:51:48 ----HD---- C:\WINDOWS\$hf_mig$
2013-08-15 06:49:10 ----RSD---- C:\WINDOWS\assembly
2013-08-15 06:49:10 ----D---- C:\WINDOWS\Microsoft.NET
2013-08-15 06:49:08 ----D---- C:\WINDOWS\system32\URTTemp
2013-08-15 06:48:14 ----A---- C:\WINDOWS\control.ini
2013-08-15 06:48:14 ----A---- C:\AUTOEXEC.BAT
2013-08-15 06:47:44 ----A---- C:\WINDOWS\system32\mapi32.dll
2013-08-15 06:46:29 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2013-08-15 06:46:25 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2013-08-15 06:46:16 ----HD---- C:\Program Files\WindowsUpdate
2013-08-15 06:45:43 ----D---- C:\WINDOWS\system32\DirectX
2013-08-15 06:45:34 ----A---- C:\WINDOWS\system32\atrace.dll
2013-08-15 06:45:33 ----A---- C:\WINDOWS\system32\desktop.ini
2013-08-15 06:45:32 ----A---- C:\WINDOWS\desktop.ini
2013-08-15 06:45:25 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2013-08-15 06:45:24 ----A---- C:\WINDOWS\system32\acctres.dll
2013-08-15 06:45:23 ----D---- C:\Program Files\Common Files\Services
2013-08-15 06:45:20 ----SD---- C:\WINDOWS\Tasks
2013-08-15 06:45:20 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2013-08-15 06:45:19 ----D---- C:\Program Files\Common Files\MSSoap
2013-08-15 06:45:15 ----D---- C:\WINDOWS\srchasst
2013-08-15 06:45:14 ----D---- C:\WINDOWS\system32\Macromed
2013-08-15 06:45:12 ----A---- C:\WINDOWS\system32\wuweb.dll
2013-08-15 06:45:11 ----A---- C:\WINDOWS\system32\wups.dll
2013-08-15 06:45:11 ----A---- C:\WINDOWS\system32\wucltui.dll
2013-08-15 06:45:11 ----A---- C:\WINDOWS\system32\wuauserv.dll
2013-08-15 06:45:11 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2013-08-15 06:45:11 ----A---- C:\WINDOWS\system32\wuaueng.dll
2013-08-15 06:45:11 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2013-08-15 06:45:11 ----A---- C:\WINDOWS\system32\wuauclt.exe
2013-08-15 06:45:10 ----A---- C:\WINDOWS\system32\wuapi.dll
2013-08-15 06:45:10 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2013-08-15 06:45:10 ----A---- C:\WINDOWS\system32\qmgr.dll
2013-08-15 06:45:10 ----A---- C:\WINDOWS\system32\bitsprx4.dll
2013-08-15 06:45:10 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2013-08-15 06:45:10 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2013-08-15 06:45:05 ----D---- C:\Program Files\Movie Maker
2013-08-15 06:44:44 ----A---- C:\WINDOWS\system32\safrslv.dll
2013-08-15 06:44:44 ----A---- C:\WINDOWS\system32\safrdm.dll
2013-08-15 06:44:44 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2013-08-15 06:44:43 ----A---- C:\WINDOWS\system32\racpldlg.dll
2013-08-15 06:44:39 ----A---- C:\WINDOWS\system32\fltMc.exe
2013-08-15 06:44:39 ----A---- C:\WINDOWS\system32\fltlib.dll
2013-08-15 06:44:38 ----D---- C:\WINDOWS\system32\Restore
2013-08-15 06:44:38 ----A---- C:\WINDOWS\system32\srsvc.dll
2013-08-15 06:44:38 ----A---- C:\WINDOWS\system32\srrstr.dll
2013-08-15 06:44:38 ----A---- C:\WINDOWS\system32\srclient.dll
2013-08-15 06:44:37 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2013-08-15 06:44:37 ----A---- C:\WINDOWS\system32\mnmdd.dll
2013-08-15 06:44:37 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2013-08-15 06:44:37 ----A---- C:\WINDOWS\system32\ils.dll
2013-08-15 06:44:36 ----A---- C:\WINDOWS\system32\msconf.dll
2013-08-15 06:44:36 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2013-08-15 06:44:33 ----D---- C:\Program Files\NetMeeting
2013-08-15 06:44:33 ----A---- C:\WINDOWS\system32\msoert2.dll
2013-08-15 06:44:33 ----A---- C:\WINDOWS\system32\msoeacct.dll
2013-08-15 06:44:31 ----A---- C:\WINDOWS\system32\inetres.dll
2013-08-15 06:44:31 ----A---- C:\WINDOWS\system32\inetcomm.dll
2013-08-15 06:44:29 ----D---- C:\Program Files\Outlook Express
2013-08-15 06:44:29 ----A---- C:\WINDOWS\system32\schedsvc.dll
2013-08-15 06:44:29 ----A---- C:\WINDOWS\system32\mstinit.exe
2013-08-15 06:44:29 ----A---- C:\WINDOWS\system32\mstask.dll
2013-08-15 06:44:28 ----A---- C:\WINDOWS\system32\isign32.dll
2013-08-15 06:44:28 ----A---- C:\WINDOWS\system32\inetcfg.dll
2013-08-15 06:44:28 ----A---- C:\WINDOWS\system32\icwphbk.dll
2013-08-15 06:44:28 ----A---- C:\WINDOWS\system32\icwdial.dll
2013-08-15 06:44:21 ----D---- C:\Program Files\Common Files\System
2013-08-15 06:43:16 ----D---- C:\Program Files\ComPlus Applications
2013-08-15 06:43:11 ----A---- C:\WINDOWS\vbaddin.ini
2013-08-15 06:43:11 ----A---- C:\WINDOWS\vb.ini
2013-08-15 06:43:00 ----D---- C:\WINDOWS\Registration
2013-08-15 06:42:44 ----D---- C:\Program Files\Online Services
2013-08-15 06:42:29 ----A---- C:\WINDOWS\system32\advpack.dll.mui
2013-08-15 06:42:23 ----D---- C:\WINDOWS\Offline Web Pages
2013-08-15 06:42:23 ----A---- C:\WINDOWS\system32\winfxdocobj.exe
2013-08-15 06:42:21 ----SD---- C:\WINDOWS\Downloaded Program Files
2013-08-15 06:42:19 ----D---- C:\WINDOWS\wbem
2013-08-15 06:42:19 ----A---- C:\WINDOWS\system32\msfeedssync.exe
2013-08-15 06:42:14 ----RA---- C:\WINDOWS\system32\msfeedsbs.dll
2013-08-15 06:42:14 ----RA---- C:\WINDOWS\system32\ieframe.dll.mui
2013-08-15 06:42:12 ----D---- C:\Program Files\Internet Explorer
2013-08-15 06:41:57 ----D---- C:\Program Files\Windows Media Connect 2
2013-08-15 06:41:55 ----D---- C:\Program Files\Windows Media Player
2013-08-15 06:41:52 ----D---- C:\Program Files\Messenger
2013-08-15 06:41:52 ----A---- C:\WINDOWS\system32\write.exe
2013-08-15 06:41:52 ----A---- C:\WINDOWS\system32\sndvol32.exe
2013-08-15 06:41:52 ----A---- C:\WINDOWS\system32\hticons.dll
2013-08-15 06:41:52 ----A---- C:\WINDOWS\system32\avwav.dll
2013-08-15 06:41:51 ----A---- C:\WINDOWS\system32\winchat.exe
2013-08-15 06:41:51 ----A---- C:\WINDOWS\system32\avtapi.dll
2013-08-15 06:41:51 ----A---- C:\WINDOWS\system32\avmeter.dll
2013-08-15 06:41:44 ----A---- C:\WINDOWS\system32\charmap.exe
2013-08-15 06:41:44 ----A---- C:\WINDOWS\system32\getuname.dll
2013-08-15 06:41:43 ----A---- C:\WINDOWS\system32\winmine.exe
2013-08-15 06:41:43 ----A---- C:\WINDOWS\system32\sol.exe
2013-08-15 06:41:43 ----A---- C:\WINDOWS\system32\calc.exe
2013-08-15 06:41:42 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2013-08-15 06:41:42 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2013-08-15 06:41:42 ----A---- C:\WINDOWS\system32\tslabels.ini
2013-08-15 06:41:42 ----A---- C:\WINDOWS\system32\tskill.exe
2013-08-15 06:41:42 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2013-08-15 06:41:42 ----A---- C:\WINDOWS\system32\tscon.exe
2013-08-15 06:41:42 ----A---- C:\WINDOWS\system32\reset.exe
2013-08-15 06:41:42 ----A---- C:\WINDOWS\system32\mshearts.exe
2013-08-15 06:41:42 ----A---- C:\WINDOWS\system32\freecell.exe
2013-08-15 06:41:41 ----A---- C:\WINDOWS\system32\shadow.exe
2013-08-15 06:41:41 ----A---- C:\WINDOWS\system32\rwinsta.exe
2013-08-15 06:41:41 ----A---- C:\WINDOWS\system32\regini.exe
2013-08-15 06:41:41 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2013-08-15 06:41:41 ----A---- C:\WINDOWS\system32\qwinsta.exe
2013-08-15 06:41:41 ----A---- C:\WINDOWS\system32\qappsrv.exe
2013-08-15 06:41:41 ----A---- C:\WINDOWS\system32\msg.exe
2013-08-15 06:41:41 ----A---- C:\WINDOWS\system32\logoff.exe
2013-08-15 06:41:41 ----A---- C:\WINDOWS\system32\cdmodem.dll
2013-08-15 06:41:40 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2013-08-15 06:41:34 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2013-08-15 06:41:20 ----D---- C:\Program Files\MSN
2013-08-15 06:41:20 ----A---- C:\WINDOWS\system32\sndrec32.exe
2013-08-15 06:41:19 ----D---- C:\Program Files\Windows NT
2013-08-15 06:41:19 ----A---- C:\WINDOWS\system32\mspaint.exe
2013-08-15 06:41:19 ----A---- C:\WINDOWS\system32\mplay32.exe
2013-08-15 06:41:19 ----A---- C:\WINDOWS\system32\hypertrm.dll
2013-08-15 06:41:18 ----A---- C:\WINDOWS\system32\spider.exe
2013-08-15 06:41:18 ----A---- C:\WINDOWS\system32\clipbrd.exe
2013-08-15 06:41:17 ----D---- C:\WINDOWS\system32\en-US
2013-08-15 06:41:17 ----A---- C:\WINDOWS\system32\tsgqec.dll
2013-08-15 06:41:17 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2013-08-15 06:41:16 ----A---- C:\WINDOWS\system32\rhttpaa.dll
2013-08-15 06:41:16 ----A---- C:\WINDOWS\system32\mstscax.dll
2013-08-15 06:41:16 ----A---- C:\WINDOWS\system32\aaclient.dll
2013-08-15 06:41:15 ----A---- C:\WINDOWS\system32\sessmgr.exe
2013-08-15 06:41:15 ----A---- C:\WINDOWS\system32\remotepg.dll
2013-08-15 06:41:15 ----A---- C:\WINDOWS\system32\rdshost.exe
2013-08-15 06:41:15 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2013-08-15 06:41:15 ----A---- C:\WINDOWS\system32\rdchost.dll
2013-08-15 06:41:15 ----A---- C:\WINDOWS\system32\mstsc.exe
2013-08-15 06:41:14 ----D---- C:\WINDOWS\system32\MsDtc
2013-08-15 06:41:14 ----A---- C:\WINDOWS\system32\termsrv.dll
2013-08-15 06:41:14 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2013-08-15 06:41:14 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2013-08-15 06:41:14 ----A---- C:\WINDOWS\system32\rdpclip.exe
2013-08-15 06:41:14 ----A---- C:\WINDOWS\system32\qprocess.exe
2013-08-15 06:41:14 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2013-08-15 06:41:14 ----A---- C:\WINDOWS\system32\icaapi.dll
2013-08-15 06:41:14 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2013-08-15 06:41:13 ----A---- C:\WINDOWS\system32\xolehlp.dll
2013-08-15 06:41:13 ----A---- C:\WINDOWS\system32\mtxoci.dll
2013-08-15 06:41:13 ----A---- C:\WINDOWS\system32\msdtctm.dll
2013-08-15 06:41:13 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2013-08-15 06:41:12 ----A---- C:\WINDOWS\system32\msdtclog.dll
2013-08-15 06:41:12 ----A---- C:\WINDOWS\system32\msdtc.exe
2013-08-15 06:41:12 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2013-08-15 06:41:11 ----D---- C:\WINDOWS\system32\Com
2013-08-15 06:41:11 ----A---- C:\WINDOWS\system32\stclient.dll
2013-08-15 06:41:11 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2013-08-15 06:41:11 ----A---- C:\WINDOWS\system32\mtxex.dll
2013-08-15 06:41:11 ----A---- C:\WINDOWS\system32\mtxdm.dll
2013-08-15 06:41:11 ----A---- C:\WINDOWS\system32\comrepl.dll
2013-08-15 06:41:11 ----A---- C:\WINDOWS\system32\comaddin.dll
2013-08-15 06:41:11 ----A---- C:\WINDOWS\system32\colbact.dll
2013-08-15 06:41:10 ----A---- C:\WINDOWS\system32\clbcatex.dll
2013-08-15 06:41:10 ----A---- C:\WINDOWS\system32\catsrvut.dll
2013-08-15 06:41:10 ----A---- C:\WINDOWS\system32\catsrvps.dll
2013-08-15 06:41:10 ----A---- C:\WINDOWS\system32\catsrv.dll
2013-08-15 06:41:09 ----A---- C:\WINDOWS\system32\comuid.dll
2013-08-15 06:41:09 ----A---- C:\WINDOWS\system32\comsvcs.dll
2013-08-15 06:41:09 ----A---- C:\WINDOWS\system32\comsnap.dll
2013-08-15 06:41:09 ----A---- C:\WINDOWS\system32\clbcatq.dll
2013-08-15 06:41:01 ----A---- C:\WINDOWS\system32\servdeps.dll
2013-08-15 06:41:01 ----A---- C:\WINDOWS\system32\mmfutil.dll
2013-08-15 06:41:01 ----A---- C:\WINDOWS\system32\licwmi.dll
2013-08-15 06:41:01 ----A---- C:\WINDOWS\system32\cmprops.dll
2013-08-15 04:12:29 ----D---- C:\rsit
2013-08-15 04:12:29 ----D---- C:\Program Files\trend micro
2013-08-15 04:03:23 ----D---- C:\WINDOWS\pss
2013-08-15 03:41:01 ----D---- C:\Program Files\CCleaner
2013-08-15 03:22:35 ----SHD---- C:\Documents and Settings\All Users\Application Data\PWH
2013-08-15 03:21:00 ----D---- C:\Documents and Settings\Sabrina\Application Data\WinRAR
2013-08-15 03:20:59 ----D---- C:\Program Files\WinRAR
2013-08-15 03:19:36 ----D---- C:\Program Files\Ardamax Keylogger 3.8.9 Full Version Serial
2013-08-15 02:18:10 ----A---- C:\WINDOWS\system32\CSVer.dll
2013-08-15 02:10:29 ----A---- C:\WINDOWS\system32\XAudio2_5.dll
2013-08-15 02:10:28 ----A---- C:\WINDOWS\system32\xactengine3_5.dll
2013-08-15 02:10:28 ----A---- C:\WINDOWS\system32\D3DCompiler_42.dll
2013-08-15 02:10:27 ----A---- C:\WINDOWS\system32\d3dx11_42.dll
2013-08-15 02:10:27 ----A---- C:\WINDOWS\system32\d3dx10_42.dll
2013-08-15 02:10:27 ----A---- C:\WINDOWS\system32\d3dcsx_42.dll
2013-08-15 02:10:26 ----A---- C:\WINDOWS\system32\D3DX9_42.dll
2013-08-15 02:10:25 ----A---- C:\WINDOWS\system32\D3DX9_41.dll
2013-08-15 02:10:25 ----A---- C:\WINDOWS\system32\d3dx10_41.dll
2013-08-15 02:10:25 ----A---- C:\WINDOWS\system32\D3DCompiler_41.dll
2013-08-15 02:10:24 ----A---- C:\WINDOWS\system32\XAudio2_4.dll
2013-08-15 02:10:24 ----A---- C:\WINDOWS\system32\XAPOFX1_3.dll
2013-08-15 02:10:24 ----A---- C:\WINDOWS\system32\xactengine3_4.dll
2013-08-15 02:10:24 ----A---- C:\WINDOWS\system32\X3DAudio1_6.dll
2013-08-15 02:10:23 ----A---- C:\WINDOWS\system32\d3dx10_40.dll
2013-08-15 02:10:23 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll
2013-08-15 02:10:22 ----A---- C:\WINDOWS\system32\XAudio2_3.dll
2013-08-15 02:10:22 ----A---- C:\WINDOWS\system32\XAPOFX1_2.dll
2013-08-15 02:10:22 ----A---- C:\WINDOWS\system32\D3DX9_40.dll
2013-08-15 02:10:21 ----A---- C:\WINDOWS\system32\xactengine3_3.dll
2013-08-15 02:10:21 ----A---- C:\WINDOWS\system32\X3DAudio1_5.dll
2013-08-15 02:10:20 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2013-08-15 02:10:20 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2013-08-15 02:10:19 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
2013-08-15 02:10:18 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2013-08-15 02:10:18 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2013-08-15 02:10:18 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2013-08-15 02:10:17 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
2013-08-15 02:10:17 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
2013-08-15 02:10:16 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
2013-08-15 02:10:16 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
2013-08-15 02:10:15 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
2013-08-15 02:10:15 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
2013-08-15 02:10:15 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
2013-08-15 02:10:14 ----A---- C:\WINDOWS\system32\XAudio2_0.dll
2013-08-15 02:10:14 ----A---- C:\WINDOWS\system32\xactengine3_0.dll
2013-08-15 02:10:13 ----A---- C:\WINDOWS\system32\X3DAudio1_3.dll
2013-08-15 02:10:13 ----A---- C:\WINDOWS\system32\D3DX9_37.dll
2013-08-15 02:10:13 ----A---- C:\WINDOWS\system32\d3dx10_37.dll
2013-08-15 02:10:13 ----A---- C:\WINDOWS\system32\D3DCompiler_37.dll
2013-08-15 02:10:12 ----A---- C:\WINDOWS\system32\xactengine2_10.dll
2013-08-15 02:10:11 ----A---- C:\WINDOWS\system32\d3dx9_36.dll
2013-08-15 02:10:11 ----A---- C:\WINDOWS\system32\d3dx10_36.dll
2013-08-15 02:10:11 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll
2013-08-15 02:10:09 ----A---- C:\WINDOWS\system32\xactengine2_9.dll
2013-08-15 02:10:09 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
2013-08-15 02:10:09 ----A---- C:\WINDOWS\system32\d3dx10_35.dll
2013-08-15 02:10:09 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll
2013-08-15 02:10:08 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
2013-08-15 02:10:08 ----A---- C:\WINDOWS\system32\X3DAudio1_2.dll
2013-08-15 02:10:08 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2013-08-15 02:10:08 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2013-08-15 02:10:07 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2013-08-15 02:10:06 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2013-08-15 02:10:06 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
2013-08-15 02:10:05 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2013-08-15 02:10:05 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2013-08-15 02:10:02 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2013-08-15 02:10:01 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2013-08-15 02:10:01 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
2013-08-15 02:10:01 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2013-08-15 02:10:01 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2013-08-15 02:10:01 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
2013-08-15 02:10:00 ----A---- C:\WINDOWS\system32\xinput1_2.dll
2013-08-15 02:10:00 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2013-08-15 02:10:00 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
2013-08-15 02:10:00 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2013-08-15 02:10:00 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2013-08-15 02:10:00 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2013-08-15 02:09:53 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2013-08-15 02:09:53 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2013-08-15 02:09:53 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2013-08-15 02:09:52 ----A---- C:\WINDOWS\system32\xinput9_1_0.dll
2013-08-15 02:09:52 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2013-08-15 02:09:52 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2013-08-15 02:09:52 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2013-08-15 02:09:52 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2013-08-15 02:09:51 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2013-08-15 02:09:50 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2013-08-15 02:09:42 ----D---- C:\WINDOWS\Logs
2013-08-15 01:57:22 ----D---- C:\Program Files\Google
2013-08-15 01:39:30 ----SHD---- C:\RECYCLER
2013-08-15 01:29:38 ----A---- C:\WINDOWS\system32\_IJL11.DLL
2013-08-15 01:01:37 ----HD---- C:\Documents and Settings\All Users\Application Data\k2logs
2013-08-15 01:01:36 ----A---- C:\WINDOWS\system32\4E37A837910D.ini
2013-08-15 01:01:32 ----A---- C:\WINDOWS\system32\wbhelp2.dll
2013-08-15 01:01:32 ----A---- C:\WINDOWS\system32\unicows.dll
2013-08-15 01:01:32 ----A---- C:\WINDOWS\system32\gdiplus.dll
2013-08-15 01:01:32 ----A---- C:\WINDOWS\system32\anim.dll
2013-08-14 23:34:06 ----A---- C:\WINDOWS\system32\h323log.txt
2013-08-14 23:24:10 ----A---- C:\WINDOWS\system32\hidserv.dll
2013-08-14 23:23:52 ----A---- C:\WINDOWS\system32\vfwwdm32.dll
2013-08-14 23:23:52 ----A---- C:\WINDOWS\system32\ksuser.dll
2013-08-14 23:21:49 ----A---- C:\WINDOWS\system32\usbui.dll
2013-08-14 23:19:50 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2013-08-14 23:19:49 ----SHD---- C:\WINDOWS\Installer
2013-08-14 23:19:48 ----D---- C:\Program Files\Common Files\ODBC
2013-08-14 23:19:48 ----A---- C:\WINDOWS\ODBCINST.INI
2013-08-14 23:19:44 ----D---- C:\Program Files\Common Files\SpeechEngines
2013-08-14 23:19:44 ----D---- C:\Program Files\Common Files\Microsoft Shared
2013-08-14 23:19:43 ----RD---- C:\Program Files
2013-08-14 23:19:43 ----D---- C:\Program Files\Common Files
2013-08-14 23:19:41 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2013-08-14 23:19:41 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2013-08-14 23:19:41 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2013-08-14 23:19:39 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2013-08-14 23:19:39 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2013-08-14 23:19:39 ----RA---- C:\WINDOWS\system32\kbdur.dll
2013-08-14 23:19:39 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2013-08-14 23:19:39 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2013-08-14 23:19:39 ----RA---- C:\WINDOWS\system32\kbdru.dll
2013-08-14 23:19:39 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2013-08-14 23:19:39 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2013-08-14 23:19:39 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2013-08-14 23:19:39 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2013-08-14 23:19:39 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2013-08-14 23:19:39 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2013-08-14 23:19:39 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2013-08-14 23:19:37 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2013-08-14 23:19:37 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2013-08-14 23:19:37 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2013-08-14 23:19:37 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2013-08-14 23:19:37 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2013-08-14 23:19:37 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2013-08-14 23:19:37 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2013-08-14 23:19:37 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2013-08-14 23:19:37 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2013-08-14 23:19:37 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2013-08-14 23:19:37 ----RA---- C:\WINDOWS\system32\kbdest.dll
2013-08-14 23:19:35 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2013-08-14 23:19:35 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2013-08-14 23:19:35 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2013-08-14 23:19:35 ----RA---- C:\WINDOWS\system32\kbdro.dll
2013-08-14 23:19:35 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2013-08-14 23:19:35 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2013-08-14 23:19:35 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2013-08-14 23:19:35 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2013-08-14 23:19:35 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
2013-08-14 23:19:35 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
2013-08-14 23:19:35 ----RA---- C:\WINDOWS\system32\kbdcz.dll
2013-08-14 23:19:35 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2013-08-14 23:19:35 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2013-08-14 23:19:28 ----A---- C:\WINDOWS\system32\spxcoins.dll
2013-08-14 23:19:28 ----A---- C:\WINDOWS\system32\irclass.dll
2013-08-14 23:19:28 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2013-08-14 23:19:28 ----A---- C:\WINDOWS\system32\dgsetup.dll
2013-08-14 23:19:28 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2013-08-14 23:19:25 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2013-08-14 23:19:25 ----A---- C:\WINDOWS\TASKMAN.EXE
2013-08-14 23:19:25 ----A---- C:\WINDOWS\system32\batt.dll
2013-08-14 23:19:24 ----A---- C:\WINDOWS\system32\storprop.dll
2013-08-14 23:19:24 ----A---- C:\WINDOWS\NOTEPAD.EXE
2013-08-14 23:19:09 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
2013-08-14 23:19:03 ----RA---- C:\WINDOWS\SET8.tmp
2013-08-14 23:19:00 ----RA---- C:\WINDOWS\SET4.tmp
2013-08-14 23:18:58 ----RA---- C:\WINDOWS\SET3.tmp
2013-08-14 23:18:52 ----D---- C:\WINDOWS\system32\CatRoot2
2013-08-14 23:18:52 ----D---- C:\WINDOWS\system32\CatRoot
2013-08-14 23:18:44 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2013-08-14 23:18:18 ----SHD---- C:\System Volume Information
2013-08-14 23:18:18 ----D---- C:\Documents and Settings
2013-08-14 23:17:37 ----SH---- C:\boot.ini
2013-08-14 23:13:20 ----RSHDC---- C:\WINDOWS\system32\dllcache
2013-08-14 23:13:20 ----RSD---- C:\WINDOWS\Fonts
2013-08-14 23:13:20 ----RD---- C:\WINDOWS\Web
2013-08-14 23:13:20 ----HD---- C:\WINDOWS\inf
2013-08-14 23:13:20 ----D---- C:\WINDOWS\WinSxS
2013-08-14 23:13:20 ----D---- C:\WINDOWS\twain_32
2013-08-14 23:13:20 ----D---- C:\WINDOWS\Temp
2013-08-14 23:13:20 ----D---- C:\WINDOWS\system32\wins
2013-08-14 23:13:20 ----D---- C:\WINDOWS\system32\wbem
2013-08-14 23:13:20 ----D---- C:\WINDOWS\system32\usmt
2013-08-14 23:13:20 ----D---- C:\WINDOWS\system32\spool
2013-08-14 23:13:20 ----D---- C:\WINDOWS\system32\ShellExt
2013-08-14 23:13:20 ----D---- C:\WINDOWS\system32\Setup
2013-08-14 23:13:20 ----D---- C:\WINDOWS\system32\scripting
2013-08-14 23:13:20 ----D---- C:\WINDOWS\system32\ras
2013-08-14 23:13:20 ----D---- C:\WINDOWS\system32\oobe
2013-08-14 23:13:20 ----D---- C:\WINDOWS\system32\npp
2013-08-14 23:13:20 ----D---- C:\WINDOWS\system32\mui
2013-08-14 23:13:20 ----D---- C:\WINDOWS\system32\inetsrv
2013-08-14 23:13:20 ----D---- C:\WINDOWS\system32\IME
2013-08-14 23:13:20 ----D---- C:\WINDOWS\system32\icsxml
2013-08-14 23:13:20 ----D---- C:\WINDOWS\system32\ias
2013-08-14 23:13:20 ----D---- C:\WINDOWS\system32\export
2013-08-14 23:13:20 ----D---- C:\WINDOWS\system32\en
2013-08-14 23:13:20 ----D---- C:\WINDOWS\system32\drivers
2013-08-14 23:13:20 ----D---- C:\WINDOWS\system32\dhcp
2013-08-14 23:13:20 ----D---- C:\WINDOWS\system32\config
2013-08-14 23:13:20 ----D---- C:\WINDOWS\system32\3com_dmi
2013-08-14 23:13:20 ----D---- C:\WINDOWS\system32\3076
2013-08-14 23:13:20 ----D---- C:\WINDOWS\system32\2052
2013-08-14 23:13:20 ----D---- C:\WINDOWS\system32\1054
2013-08-14 23:13:20 ----D---- C:\WINDOWS\system32\1042
2013-08-14 23:13:20 ----D---- C:\WINDOWS\system32\1041
2013-08-14 23:13:20 ----D---- C:\WINDOWS\system32\1037
2013-08-14 23:13:20 ----D---- C:\WINDOWS\system32\1033
2013-08-14 23:13:20 ----D---- C:\WINDOWS\system32\1031
2013-08-14 23:13:20 ----D---- C:\WINDOWS\system32\1028
2013-08-14 23:13:20 ----D---- C:\WINDOWS\system32\1025
2013-08-14 23:13:20 ----D---- C:\WINDOWS\system32
2013-08-14 23:13:20 ----D---- C:\WINDOWS\system
2013-08-14 23:13:20 ----D---- C:\WINDOWS\security
2013-08-14 23:13:20 ----D---- C:\WINDOWS\Resources
2013-08-14 23:13:20 ----D---- C:\WINDOWS\repair
2013-08-14 23:13:20 ----D---- C:\WINDOWS\Provisioning
2013-08-14 23:13:20 ----D---- C:\WINDOWS\pchealth
2013-08-14 23:13:20 ----D---- C:\WINDOWS\PeerNet
2013-08-14 23:13:20 ----D---- C:\WINDOWS\Network Diagnostic
2013-08-14 23:13:20 ----D---- C:\WINDOWS\mui
2013-08-14 23:13:20 ----D---- C:\WINDOWS\msapps
2013-08-14 23:13:20 ----D---- C:\WINDOWS\msagent
2013-08-14 23:13:20 ----D---- C:\WINDOWS\Media
2013-08-14 23:13:20 ----D---- C:\WINDOWS\L2Schemas
2013-08-14 23:13:20 ----D---- C:\WINDOWS\java
2013-08-14 23:13:20 ----D---- C:\WINDOWS\ime
2013-08-14 23:13:20 ----D---- C:\WINDOWS\Help
2013-08-14 23:13:20 ----D---- C:\WINDOWS\ehome
2013-08-14 23:13:20 ----D---- C:\WINDOWS\Driver Cache
2013-08-14 23:13:20 ----D---- C:\WINDOWS\Debug
2013-08-14 23:13:20 ----D---- C:\WINDOWS\Cursors
2013-08-14 23:13:20 ----D---- C:\WINDOWS\Connection Wizard
2013-08-14 23:13:20 ----D---- C:\WINDOWS\Config
2013-08-14 23:13:20 ----D---- C:\WINDOWS\AppPatch
2013-08-14 23:13:20 ----D---- C:\WINDOWS\addins
2013-08-14 23:13:20 ----D---- C:\WINDOWS

======List of files/folders modified in the last 1 months======

2013-08-15 07:07:50 ----A---- C:\WINDOWS\system.ini
2013-08-15 06:48:12 ----A---- C:\WINDOWS\win.ini
2013-08-15 03:15:55 ----HD---- C:\WINDOWS\Qnubbxzrczgnn

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 36352]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-14 8832]
R3 ApfiltrService;Alps Touch Pad Filter Driver for Windows 2000/XP/Vista; C:\WINDOWS\system32\DRIVERS\Apfiltr.sys [2007-12-14 155136]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-08-25 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2008-04-23 3006976]
R3 BCM43XX;Ovládač karty Dell bezdrôtovej WLAN; C:\WINDOWS\system32\DRIVERS\bcmwl5.sys [2008-06-02 1287552]
R3 CmBatt;Microsoft AC Adapter Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-14 13952]
R3 HdAudAddService;ATI Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\AtiHdAud.sys [2006-12-28 84992]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-08-25 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-08-25 61824]
R3 OA001Ufd;Creative Camera OA001 Upper Filter Driver; C:\WINDOWS\system32\DRIVERS\OA001Ufd.sys [2008-06-03 144672]
R3 OA001Vid;Creative Camera OA001 Function Driver; C:\WINDOWS\system32\DRIVERS\OA001Vid.sys [2008-09-19 277440]
R3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2008-04-14 79232]
R3 STHDA;IDT High Definition Audio CODEC; C:\WINDOWS\system32\drivers\sthda.sys [2007-09-14 1248056]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 OA001Afx;Provides a software interface to control audio effects of OA001 camera.; \??\C:\WINDOWS\system32\Drivers\OA001Afx.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 usbvideo;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-14 121984]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2008-07-09 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-07-09 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2008-04-22 540672]
R2 STacSV;Audio Service; C:\WINDOWS\system32\STacSV.exe [2007-09-14 204800]
R2 wltrysvc;Dell Wireless WLAN Tray Service; C:\WINDOWS\System32\WLTRYSVC.EXE [2008-06-02 24064]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2008-06-02 593920]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-08-15 116648]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-08-15 116648]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-19 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]

-----------------EOF-----------------

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Startup DIALOG a Keylogger

#2 Příspěvek od cernohous13 »

Vítám tě u nás Obrázek

:?: Pokud nejsi na dálném východě tak zkontroluj/oprav datum a čas

:???: Na tom druhém obrázku chceš jenom skrýt ikony těch programů v panelu vedle hodin?

:arrow: Stáhni "System Look" - http://jpshortstuff.247fixes.com/SystemLook.exe
Spusť jej a do okna zkopíruj

Kód: Vybrat vše

:dir
C:\WINDOWS\Qnubbxzrczgnn /s
Klik na "Look" a po scanu sem zkopíruj výsledek hledání

:arrow: Stáhni OTM z jednoho odkazu a rozbal nejlépe na plochu.
http://oldtimer.geekstogo.com/OTM.exe
http://www.itxassociates.com/OT-Tools/OTM.exe

Spusť program „OTM.exe“
Do okna pod žlutou čáru vlož celý text zeleným písmem ze „Scriptu“

Klikni na červené „MoveIt!“

Při nabídce restartu „YES“
a log potom najdeš v C:\_OTM\MovedFiles\ - dej mi ho sem na kontrolu
Script OTM

Kód: Vybrat vše

:Commands
[emptytemp]
[emptyflash]
[emptyjava]
[clearallrestorepoints]

:Files
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp /s
C:\WINDOWS\inf\ntvdm.vbe
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NtVdmSrv"=-

:Services
gupdatem
gupdate
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

dendulo13
Návštěvník
Návštěvník
Příspěvky: 4
Registrován: 15 srp 2013 00:26

Re: Startup DIALOG a Keylogger

#3 Příspěvek od dendulo13 »

neodstrani mi to nijak keylogger? ten ardammax? co tam mam nainstalovany? chcem aby to tam bolo len chcem s toho druheho obrazku skryt s toho panelu tie veci aby to nikto nevidel.. ale nie s panelu na liste, ale s toho panelu kde sa to vybera, musi to tam byt nejako v systeme niekde ulozene aby to bolo na vyber.. ako ten keylogger je uplne neviditelny len v tom paneli je na vyber ze akoze sa moze zobrazit

// chcem sa zbavit len tej tabulky na zaciatku + sa zbavit tych programov v tom paneli aby tam neboli to sa musi dat niekde odstranit len nejako zlozitejsie vsak?


(hlavne nech funguju tie veci co tam uz mam)

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Startup DIALOG a Keylogger

#4 Příspěvek od cernohous13 »

1 - System Look by mi ukázal obsah neobvyklé složky "Qnubbxzrczgnn"

2 - Obrázek je právě o skrývaní ikon v Oznamovací oblasti vedle hodin

3 - OTM odstraňuje "Startup dialog" + zbytečnosti - nevšímá si instalovaných programů
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Zamčeno