Pravděpodobně trojan - prosím o kontrolu logu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Odpovědět
Zpráva
Autor
Thooty
Návštěvník
Návštěvník
Příspěvky: 95
Registrován: 08 Dub 2010 14:51

Pravděpodobně trojan - prosím o kontrolu logu

#1 Příspěvek od Thooty »

Po dlouhé době zdravím:)
Naskytl se mi problém, stáhl sem jeden program a spustil, najednou mi Eset smart security napsal něco o trojanu že ho zablokoval ale nesmazal, udělal sem kontrolu i pomocí MBAM a ten mi taky napsal že některé infikované složky odebrat nepůjdou, tak bych poprosil zda by to šlo nějak vymazat.

Log z RSIT
Logfile of random's system information tool 1.07 (written by random/random)
Run by ToRTeEn at 2010-06-25 11:29:40
Microsoft Windows 7 Ultimate Service Pack 3
System drive C: has 11 GB (15%) free of 76 GB
Total RAM: 1023 MB (14% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:29:51, on 25.6.2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Uniblue\SpeedUpMyPC\sump.exe
C:\Users\ToRTeEn\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\ToRTeEn\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\ToRTeEn\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\ToRTeEn\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\ToRTeEn\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\ToRTeEn\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\ToRTeEn\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\ToRTeEn\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\ToRTeEn\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\ToRTeEn\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\ToRTeEn\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\ToRTeEn\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\ToRTeEn\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\ToRTeEn\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\ToRTeEn\Desktop\RSIT.exe
C:\Program Files\trend micro\ToRTeEn.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/skins7/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: (no name) - {074C1DC5-9320-4A9A-947D-C042949C6216} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: FlashGetBHO - {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - C:\Users\ToRTeEn\AppData\Roaming\FlashGetBHO\FlashGetBHO3.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ7.2\ICQ.exe" silent loginmode=4
O4 - HKCU\..\RunOnce: [PowerSuite] "C:\Program Files\Uniblue\PowerSuite\launcher.exe" delay 20000 -m
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: Download all by FlashGet3 - C:\Users\ToRTeEn\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
O8 - Extra context menu item: Download by FlashGet3 - C:\Users\ToRTeEn\AppData\Roaming\FlashGetBHO\GetUrl.htm
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Stahnou vse FlashGet3 - C:\Users\ToRTeEn\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
O8 - Extra context menu item: Stahnout FlashGet3 - C:\Users\ToRTeEn\AppData\Roaming\FlashGetBHO\GetUrl.htm
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O15 - Trusted Zone: http://software.kuaiche.com
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

--
End of file - 6923 bytes

======Scheduled tasks folder======

C:\Windows\tasks\AWC Startup.job
C:\Windows\tasks\AWC Update.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3595803208-3766525656-3816774015-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3595803208-3766525656-3816774015-1000UA.job
C:\Windows\tasks\SmartDefrag.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{074C1DC5-9320-4A9A-947D-C042949C6216}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2010-06-16 341600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0}]
FlashGetBHO - C:\Users\ToRTeEn\AppData\Roaming\FlashGetBHO\FlashGetBHO3.dll [2009-12-22 157232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-05-14 41760]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2010-04-07 2145000]
"AdobeAAMUpdater-1.0"=C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]
"AdobeCS5ServiceManager"=C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-02-22 406992]
"SwitchBoard"=C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2010-04-29 1090952]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1173504]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2010-05-13 26192168]
"ICQ"=C:\Program Files\ICQ7.2\ICQ.exe [2010-06-08 133368]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"PowerSuite"=C:\Program Files\Uniblue\PowerSuite\launcher.exe [2010-06-01 46440]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-02-22 406992]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashGet 3]
C:\Program Files\FlashGet Network\FlashGet 3\Flashget3.exe [2009-12-22 2127408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [2009-11-11 1451520]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PcSync]
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files\Steam\Steam.exe [2010-05-10 1238352]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppInfo]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BFE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\bowser]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dfsc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dot3Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Eaphost]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\IKEEXT]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\KeyIso]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSDrv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb10]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb20]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NativeWifiP]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\netprofm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NlaSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Nsi]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nsiproxy.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NTDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PolicyAgent]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ProfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdbss]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpencdd.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sacsvr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCardSvr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SWPRV]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TabletInputService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TBS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TrustedInstaller]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgr.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgrx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wlansvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\FlashGet Network\FlashGet 3\FlashGet3.exe"="C:\Program Files\FlashGet Network\FlashGet 3\FlashGet3.exe:*:Enabled:Flashget3"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - "C:\Program Files\Adobe\Adobe Dreamweaver CS5\Dreamweaver.exe","%1"

======List of files/folders created in the last 1 months======

2010-06-25 11:25:25 ----D---- C:\Program Files\trend micro
2010-06-25 11:25:23 ----D---- C:\rsit
2010-06-25 10:52:19 ----D---- C:\Users\ToRTeEn\AppData\Roaming\Malwarebytes
2010-06-25 10:51:57 ----D---- C:\ProgramData\Malwarebytes
2010-06-25 10:51:56 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-06-25 10:03:34 ----D---- C:\Program Files\Lavalys
2010-06-23 13:20:34 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2010-06-23 13:20:34 ----A---- C:\Windows\system32\PresentationHost.exe
2010-06-23 13:20:34 ----A---- C:\Windows\system32\netfxperf.dll
2010-06-23 13:20:34 ----A---- C:\Windows\system32\mscoree.dll
2010-06-23 13:20:34 ----A---- C:\Windows\system32\dfshim.dll
2010-06-23 09:38:08 ----A---- C:\Windows\system32\ntdll.dll
2010-06-23 09:37:33 ----A---- C:\Windows\system32\CPFilters.dll
2010-06-23 09:37:26 ----A---- C:\Windows\system32\msdri.dll
2010-06-20 12:10:37 ----A---- C:\Windows\system32\PnkBstrB.exe
2010-06-20 12:10:33 ----A---- C:\Windows\system32\PnkBstrA.exe
2010-06-20 12:10:31 ----A---- C:\Windows\system32\pbsvc.exe
2010-06-20 12:03:16 ----D---- C:\Program Files\Ubisoft
2010-06-19 19:24:10 ----D---- C:\Program Files\OpenAL
2010-06-19 19:24:10 ----A---- C:\Windows\system32\wrap_oal.dll
2010-06-19 19:24:10 ----A---- C:\Windows\system32\OpenAL32.dll
2010-06-19 18:34:37 ----D---- C:\Program Files\SuperHideIP
2010-06-18 17:48:14 ----D---- C:\Users\ToRTeEn\AppData\Roaming\FreeHideIP
2010-06-18 17:48:14 ----D---- C:\ProgramData\FreeHideIP
2010-06-18 17:40:00 ----D---- C:\Users\ToRTeEn\AppData\Roaming\SuperHideIP
2010-06-18 17:40:00 ----D---- C:\ProgramData\SuperHideIP
2010-06-18 15:32:59 ----D---- C:\Program Files\Eagle Dynamics
2010-06-17 22:22:00 ----D---- C:\Program Files\Electronic Arts
2010-06-17 22:21:59 ----A---- C:\Windows\system32\XAudio2_5.dll
2010-06-17 22:21:58 ----A---- C:\Windows\system32\xactengine3_5.dll
2010-06-17 22:21:58 ----A---- C:\Windows\system32\d3dx11_42.dll
2010-06-17 22:21:58 ----A---- C:\Windows\system32\d3dcsx_42.dll
2010-06-17 22:21:58 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2010-06-17 22:21:57 ----A---- C:\Windows\system32\D3DX9_42.dll
2010-06-17 22:21:56 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2010-06-17 22:21:54 ----A---- C:\Windows\system32\XAudio2_3.dll
2010-06-17 22:21:54 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2010-06-17 22:21:54 ----A---- C:\Windows\system32\xactengine3_3.dll
2010-06-17 22:21:53 ----A---- C:\Windows\system32\XAudio2_2.dll
2010-06-17 22:21:53 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2010-06-17 22:21:53 ----A---- C:\Windows\system32\xactengine3_2.dll
2010-06-17 22:21:53 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2010-06-16 17:42:45 ----A---- C:\Windows\system32\clrviddc.dll
2010-06-16 17:36:27 ----A---- C:\Windows\system32\rmoc3260.dll
2010-06-16 17:36:19 ----A---- C:\Windows\system32\pndx5032.dll
2010-06-16 17:36:19 ----A---- C:\Windows\system32\pndx5016.dll
2010-06-16 17:36:03 ----D---- C:\Program Files\Common Files\xing shared
2010-06-16 17:35:43 ----A---- C:\Windows\system32\pncrt.dll
2010-06-16 17:35:37 ----D---- C:\Program Files\Common Files\Real
2010-06-16 17:35:36 ----D---- C:\ProgramData\Real
2010-06-16 17:35:36 ----D---- C:\Program Files\Real
2010-06-16 17:25:35 ----D---- C:\Users\ToRTeEn\AppData\Roaming\Real
2010-06-16 00:12:34 ----A---- C:\Windows\system32\OpenCL.dll
2010-06-16 00:12:32 ----A---- C:\Windows\system32\nvoglv32.dll
2010-06-16 00:12:32 ----A---- C:\Windows\system32\nvencodemft.dll
2010-06-16 00:12:32 ----A---- C:\Windows\system32\nvdecodemft.dll
2010-06-16 00:12:32 ----A---- C:\Windows\system32\nvd3dum.dll
2010-06-16 00:12:32 ----A---- C:\Windows\system32\nvcuvid.dll
2010-06-16 00:12:32 ----A---- C:\Windows\system32\nvcuvenc.dll
2010-06-16 00:12:32 ----A---- C:\Windows\system32\nvcuda.dll
2010-06-16 00:12:30 ----A---- C:\Windows\system32\nvcompiler.dll
2010-06-16 00:12:30 ----A---- C:\Windows\system32\nvcod1921.dll
2010-06-16 00:12:30 ----A---- C:\Windows\system32\nvcod.dll
2010-06-13 19:07:38 ----D---- C:\ProgramData\RealHideIP
2010-06-13 18:53:41 ----D---- C:\ProgramData\AutoHideIP
2010-06-13 14:06:24 ----D---- C:\Program Files\ICQ6Toolbar
2010-06-13 14:06:00 ----D---- C:\ProgramData\ICQ
2010-06-13 14:05:23 ----D---- C:\Users\ToRTeEn\AppData\Roaming\ICQ
2010-06-13 14:04:57 ----D---- C:\Program Files\ICQ7.2
2010-06-09 11:54:50 ----A---- C:\Windows\system32\asycfilt.dll
2010-06-09 11:54:38 ----A---- C:\Windows\system32\mshtml.dll
2010-06-09 11:54:33 ----A---- C:\Windows\system32\ieframe.dll
2010-06-09 11:54:32 ----A---- C:\Windows\system32\mstime.dll
2010-06-09 11:54:31 ----A---- C:\Windows\system32\urlmon.dll
2010-06-09 11:54:29 ----A---- C:\Windows\system32\iedkcs32.dll
2010-06-09 11:54:28 ----A---- C:\Windows\system32\wininet.dll
2010-06-09 11:54:28 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-06-09 11:54:26 ----A---- C:\Windows\system32\jsproxy.dll
2010-06-09 11:53:46 ----A---- C:\Windows\system32\atmfd.dll
2010-06-09 11:53:45 ----A---- C:\Windows\system32\atmlib.dll
2010-06-07 17:48:04 ----A---- C:\Windows\system32\nvvsvc.exe
2010-06-07 17:48:04 ----A---- C:\Windows\system32\nvsvc.dll
2010-06-07 17:48:04 ----A---- C:\Windows\system32\nvmctray.dll
2010-06-07 17:48:04 ----A---- C:\Windows\system32\nvcpl.dll
2010-06-05 14:32:16 ----D---- C:\Program Files\Rockstar Games
2010-06-04 21:38:35 ----D---- C:\Program Files\Common Files\PCSuite
2010-06-04 21:38:28 ----D---- C:\Program Files\Nokia
2010-06-04 21:18:09 ----D---- C:\ProgramData\PC Suite
2010-06-04 16:46:59 ----D---- C:\ProgramData\Uniblue
2010-06-04 16:39:11 ----D---- C:\Users\ToRTeEn\AppData\Roaming\Uniblue
2010-06-04 16:38:20 ----D---- C:\Program Files\Uniblue
2010-06-04 14:29:50 ----A---- C:\Windows\reimage.ini
2010-06-04 14:05:27 ----D---- C:\Program Files\MSXML 4.0
2010-06-03 17:14:16 ----D---- C:\ProgramData\Nokia
2010-06-03 16:55:08 ----D---- C:\Program Files\DIFX
2010-06-03 16:55:00 ----DC---- C:\Windows\system32\DRVSTORE
2010-06-03 16:54:41 ----D---- C:\Program Files\PC Connectivity Solution
2010-06-03 16:50:08 ----D---- C:\ProgramData\Installations
2010-06-03 16:39:23 ----D---- C:\Users\ToRTeEn\AppData\Roaming\Datalayer
2010-05-29 20:01:29 ----D---- C:\Users\ToRTeEn\AppData\Roaming\Notepad++
2010-05-29 20:01:29 ----D---- C:\Program Files\Notepad++
2010-05-28 16:57:29 ----D---- C:\ProgramData\NVIDIA Corporation
2010-05-28 16:03:36 ----A---- C:\Windows\system32\nvcod1920.dll
2010-05-28 06:33:43 ----D---- C:\ProgramData\Ubisoft
2010-05-27 14:56:58 ----RHD---- C:\Users\ToRTeEn\AppData\Roaming\SecuROM
2010-05-27 00:42:58 ----D---- C:\Program Files\Sanny Builder 3
2010-05-26 22:17:24 ----D---- C:\Users\ToRTeEn\AppData\Roaming\esmska
2010-05-26 22:17:11 ----HD---- C:\Program Files\InstallJammer Registry
2010-05-26 22:16:43 ----D---- C:\Program Files\Esmska
2010-05-26 20:45:22 ----D---- C:\ProgramData\IObit
2010-05-26 17:23:35 ----A---- C:\Windows\system32\CmdLineExt.dll
2010-05-26 12:30:03 ----HD---- C:\Windows\msdownld.tmp
2010-05-26 12:29:30 ----D---- C:\Windows\system32\directx
2010-05-26 11:08:51 ----A---- C:\Windows\system32\tzres.dll

======List of files/folders modified in the last 1 months======

2010-06-25 11:29:45 ----D---- C:\Windows\Temp
2010-06-25 11:28:04 ----D---- C:\Windows\Prefetch
2010-06-25 11:25:25 ----RD---- C:\Program Files
2010-06-25 11:24:18 ----D---- C:\Windows\system32\config
2010-06-25 11:22:07 ----D---- C:\Users\ToRTeEn\AppData\Roaming\Skype
2010-06-25 11:21:52 ----D---- C:\Users\ToRTeEn\AppData\Roaming\skypePM
2010-06-25 11:20:42 ----D---- C:\ProgramData\NVIDIA
2010-06-25 11:18:18 ----D---- C:\Windows\system32\drivers
2010-06-25 11:18:18 ----D---- C:\Windows\inf
2010-06-25 11:17:42 ----D---- C:\Windows\system32\Tasks
2010-06-25 11:17:40 ----D---- C:\Windows\Tasks
2010-06-25 10:51:57 ----HD---- C:\ProgramData
2010-06-25 10:33:56 ----SHD---- C:\System Volume Information
2010-06-23 15:35:33 ----D---- C:\Windows\System32
2010-06-23 14:23:14 ----D---- C:\Windows\Microsoft.NET
2010-06-23 14:23:00 ----RSD---- C:\Windows\assembly
2010-06-23 13:26:20 ----D---- C:\Windows\winsxs
2010-06-23 13:24:40 ----D---- C:\Windows\ehome
2010-06-23 13:23:16 ----SHD---- C:\Windows\Installer
2010-06-23 13:23:15 ----D---- C:\Config.Msi
2010-06-23 13:23:14 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-06-23 13:22:08 ----D---- C:\Windows\system32\en-US
2010-06-23 13:21:53 ----D---- C:\Program Files\Microsoft.NET
2010-06-23 13:20:38 ----D---- C:\Windows\system32\catroot
2010-06-23 13:20:22 ----D---- C:\Windows\AppPatch
2010-06-23 09:37:05 ----D---- C:\Windows\system32\catroot2
2010-06-20 12:03:08 ----HD---- C:\Program Files\InstallShield Installation Information
2010-06-19 19:23:42 ----D---- C:\Windows
2010-06-19 18:48:07 ----D---- C:\Windows\system32\NDF
2010-06-19 11:08:58 ----D---- C:\Windows\Logs
2010-06-19 03:00:40 ----D---- C:\Users\ToRTeEn\AppData\Roaming\BITS
2010-06-18 10:13:53 ----D---- C:\Windows\debug
2010-06-17 23:45:52 ----D---- C:\Program Files\Common Files\microsoft shared
2010-06-17 20:49:39 ----RSD---- C:\Windows\Fonts
2010-06-17 16:42:31 ----D---- C:\Program Files\Microsoft Games
2010-06-16 17:36:03 ----D---- C:\Program Files\Common Files
2010-06-16 17:35:43 ----A---- C:\Windows\system32\msvcr71.dll
2010-06-16 17:35:43 ----A---- C:\Windows\system32\msvcp71.dll
2010-06-16 17:34:28 ----D---- C:\Program Files\Internet Explorer
2010-06-16 00:29:13 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-06-16 00:23:08 ----D---- C:\Windows\system32\DriverStore
2010-06-16 00:15:38 ----D---- C:\Program Files\NVIDIA Corporation
2010-06-15 16:15:08 ----D---- C:\Game
2010-06-10 17:11:19 ----D---- C:\Users\ToRTeEn\AppData\Roaming\Nokia
2010-06-09 12:04:30 ----D---- C:\Windows\system32\migration
2010-06-09 12:03:37 ----D---- C:\ProgramData\Microsoft Help
2010-06-08 01:57:00 ----A---- C:\Windows\system32\nvwgf2um.dll
2010-06-08 01:57:00 ----A---- C:\Windows\system32\nvapi.dll
2010-06-04 21:38:29 ----D---- C:\Program Files\Common Files\Nokia
2010-06-04 21:18:25 ----D---- C:\Users\ToRTeEn\AppData\Roaming\PC Suite
2010-06-04 21:18:20 ----SD---- C:\ProgramData\Microsoft
2010-06-04 20:00:59 ----D---- C:\Program Files\Microsoft Silverlight
2010-06-04 14:26:17 ----D---- C:\Windows\system
2010-06-04 14:19:45 ----D---- C:\ProgramData\Downloaded Installations
2010-05-31 10:14:52 ----D---- C:\Fraps
2010-05-29 08:51:25 ----D---- C:\Windows\rescache
2010-05-28 21:37:34 ----A---- C:\Windows\system32\MRT.exe
2010-05-28 18:52:52 ----D---- C:\Program Files\CCleaner
2010-05-28 18:43:38 ----D---- C:\Windows\LiveKernelReports
2010-05-28 10:08:13 ----RD---- C:\Program Files\Skype
2010-05-27 23:24:03 ----D---- C:\Users\ToRTeEn\AppData\Roaming\uTorrent
2010-05-27 21:31:48 ----D---- C:\Users\ToRTeEn\AppData\Roaming\IObit
2010-05-27 14:51:13 ----D---- C:\Windows\system32\LogFiles
2010-05-26 19:05:34 ----D---- C:\Program Files\IObit
2010-05-26 11:18:39 ----D---- C:\Windows\system32\cs-CZ

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 blbdrive;blbdrive; C:\Windows\system32\DRIVERS\blbdrive.sys [2009-07-14 35328]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 DfsC;@%systemroot%\system32\drivers\dfsc.sys,-101; C:\Windows\System32\Drivers\dfsc.sys [2009-07-14 78336]
R1 discache;@%systemroot%\system32\drivers\discache.sys,-102; C:\Windows\System32\drivers\discache.sys [2009-07-14 32256]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-04-07 114984]
R1 nsiproxy;@%SystemRoot%\system32\drivers\nsiproxy.sys,-2; C:\Windows\system32\drivers\nsiproxy.sys [2009-07-14 16896]
R1 RDPENCDD;@%systemroot%\system32\drivers\RDPENCDD.sys,-101; C:\Windows\system32\drivers\rdpencdd.sys [2009-07-14 6656]
R1 RDPREFMP;@%systemroot%\system32\drivers\RdpRefMp.sys,-101; C:\Windows\system32\drivers\rdprefmp.sys [2009-07-14 7168]
R1 tdx;@%SystemRoot%\system32\tcpipcfg.dll,-50004; C:\Windows\system32\DRIVERS\tdx.sys [2009-07-14 74240]
R1 Wanarpv6;@%systemroot%\system32\rascfg.dll,-32012; C:\Windows\system32\DRIVERS\wanarp.sys [2009-07-14 63488]
R1 WfpLwf;WFP Lightweight Filter; C:\Windows\system32\DRIVERS\wfplwf.sys [2009-07-14 9728]
R2 cpuz133;cpuz133; \??\C:\Windows\system32\drivers\cpuz133_x32.sys [2010-03-30 20968]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-04-07 133512]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2010-04-07 134488]
R2 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2010-04-07 41312]
R2 lltdio;Link-Layer Topology Discovery Mapper I/O Driver; C:\Windows\system32\DRIVERS\lltdio.sys [2009-07-14 48128]
R2 luafv;@%systemroot%\system32\drivers\luafv.sys,-100; C:\Windows\system32\drivers\luafv.sys [2009-07-14 86528]
R2 PEAUTH;PEAUTH; C:\Windows\system32\drivers\peauth.sys [2009-07-14 586752]
R2 RMCAST;@%SystemRoot%\system32\wshrm.dll,-102; C:\Windows\system32\DRIVERS\RMCAST.sys [2009-07-14 117248]
R2 rspndr;Link-Layer Topology Discovery Responder; C:\Windows\system32\DRIVERS\rspndr.sys [2009-07-14 60928]
R2 tcpipreg;TCP/IP Registry Compatibility; C:\Windows\System32\drivers\tcpipreg.sys [2009-07-14 34816]
R3 bowser;@%systemroot%\system32\browser.dll,-102; C:\Windows\system32\DRIVERS\bowser.sys [2009-07-14 69632]
R3 CompositeBus;Ovladač rozpoznávacího modulu složené sběrnice; C:\Windows\system32\DRIVERS\CompositeBus.sys [2009-07-14 31232]
R3 DXGKrnl;LDDM Graphics Subsystem; C:\Windows\System32\drivers\dxgkrnl.sys [2009-10-02 728648]
R3 Epfwndis;Eset Personal Firewall; C:\Windows\system32\DRIVERS\Epfwndis.sys [2010-04-07 32584]
R3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2009-07-14 304128]
R3 HDAudBus;Ovladač sběrnice Microsoft UAA pro zvuk High Definition Audio; C:\Windows\system32\DRIVERS\HDAudBus.sys [2009-07-14 108544]
R3 HidUsb;Ovladač třídy standardu HID Microsoft; C:\Windows\system32\DRIVERS\hidusb.sys [2009-07-14 24064]
R3 intelppm;Ovladač procesoru Intel; C:\Windows\system32\DRIVERS\intelppm.sys [2009-07-14 53760]
R3 kbdhid;Ovladač klávesnice standardu HID; C:\Windows\system32\DRIVERS\kbdhid.sys [2009-07-14 28160]
R3 monitor;Služba ovladače funkce třídy monitorů Microsoft; C:\Windows\system32\DRIVERS\monitor.sys [2009-07-14 23552]
R3 mouhid;Ovladač myši standardu HID; C:\Windows\system32\DRIVERS\mouhid.sys [2009-07-14 26112]
R3 mpsdrv;@%SystemRoot%\system32\FirewallAPI.dll,-23092; C:\Windows\System32\drivers\mpsdrv.sys [2009-07-14 60416]
R3 mrxsmb10;@%systemroot%\system32\wkssvc.dll,-1004; C:\Windows\system32\DRIVERS\mrxsmb10.sys [2010-02-27 221696]
R3 mrxsmb20;@%systemroot%\system32\wkssvc.dll,-1006; C:\Windows\system32\DRIVERS\mrxsmb20.sys [2010-02-27 95744]
R3 NativeWifiP;NativeWiFi Filter; C:\Windows\system32\DRIVERS\nwifi.sys [2009-07-14 267264]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda32v.sys [2010-01-28 68200]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2010-06-08 10888168]
R3 RasAgileVpn;WAN Miniport (IKEv2); C:\Windows\system32\DRIVERS\AgileVpn.sys [2009-07-14 49152]
R3 RasSstp;@%systemroot%\system32\sstpsvc.dll,-202; C:\Windows\system32\DRIVERS\rassstp.sys [2009-07-14 75264]
R3 rdpbus;Remote Desktop Device Redirector Bus Driver; C:\Windows\system32\DRIVERS\rdpbus.sys [2009-07-14 18944]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2010-03-04 277536]
R3 srv2;@%systemroot%\system32\srvsvc.dll,-104; C:\Windows\System32\DRIVERS\srv2.sys [2009-07-14 306688]
R3 srvnet;srvnet; C:\Windows\System32\DRIVERS\srvnet.sys [2009-12-08 113664]
R3 umbus;Ovladač sběrnice UMBus Enumerator; C:\Windows\system32\DRIVERS\umbus.sys [2009-07-14 39936]
R3 usbehci;Ovladač miniportu vylepšeného hostitelského řadiče Microsoft USB 2.0; C:\Windows\system32\DRIVERS\usbehci.sys [2009-07-14 41472]
R3 usbhub;Ovladač standardního rozbočovače USB; C:\Windows\system32\DRIVERS\usbhub.sys [2009-07-14 258560]
R3 usbuhci;Ovladač miniportu univerzálního hostitelského řadiče Microsoft USB; C:\Windows\system32\DRIVERS\usbuhci.sys [2009-07-14 24064]
R3 WudfPf;User Mode Driver Frameworks Platform Driver; C:\Windows\system32\drivers\WudfPf.sys [2009-07-14 92672]
S3 1394ohci;1394 OHCI Compliant Host Controller; C:\Windows\system32\DRIVERS\1394ohci.sys [2009-07-14 163328]
S3 AcpiPmi;ACPI Power Meter Driver; C:\Windows\system32\DRIVERS\acpipmi.sys [2009-07-14 9728]
S3 adp94xx;adp94xx; C:\Windows\system32\DRIVERS\adp94xx.sys [2009-07-14 422976]
S3 adpahci;adpahci; C:\Windows\system32\DRIVERS\adpahci.sys [2009-07-14 297552]
S3 adpu320;adpu320; C:\Windows\system32\DRIVERS\adpu320.sys [2009-07-14 146512]
S3 agp440;Intel AGP Bus Filter; C:\Windows\system32\DRIVERS\agp440.sys [2009-07-14 53312]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 amdide;amdide; C:\Windows\system32\DRIVERS\amdide.sys [2009-07-14 14912]
S3 AmdK8;AMD K8 Processor Driver; C:\Windows\system32\DRIVERS\amdk8.sys [2009-07-14 55296]
S3 AmdPPM;AMD Processor Driver; C:\Windows\system32\DRIVERS\amdppm.sys [2009-07-14 52736]
S3 amdsata;amdsata; C:\Windows\system32\DRIVERS\amdsata.sys [2009-07-14 79952]
S3 amdsbs;amdsbs; C:\Windows\system32\DRIVERS\amdsbs.sys [2009-07-14 159312]
S3 AppID;@%systemroot%\system32\appidsvc.dll,-102; C:\Windows\system32\drivers\appid.sys [2009-07-14 50176]
S3 arc;arc; C:\Windows\system32\DRIVERS\arc.sys [2009-07-14 76368]
S3 arcsas;arcsas; C:\Windows\system32\DRIVERS\arcsas.sys [2009-07-14 86608]
S3 atbyil3m;atbyil3m; C:\Windows\system32\drivers\atbyil3m.sys []
S3 b06bdrv;Broadcom NetXtreme II VBD; C:\Windows\system32\DRIVERS\bxvbdx.sys [2009-07-14 430080]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BrFiltLo;Brother USB Mass-Storage Lower Filter Driver; C:\Windows\system32\DRIVERS\BrFiltLo.sys [2009-07-14 13568]
S3 BrFiltUp;Brother USB Mass-Storage Upper Filter Driver; C:\Windows\system32\DRIVERS\BrFiltUp.sys [2009-07-14 5248]
S3 Brserid;Brother MFC Serial Port Interface Driver (WDM); C:\Windows\System32\Drivers\Brserid.sys [2009-07-14 272128]
S3 BrSerWdm;Brother WDM Serial driver; C:\Windows\System32\Drivers\BrSerWdm.sys [2009-07-14 62336]
S3 BrUsbMdm;Brother MFC USB Fax Only Modem; C:\Windows\System32\Drivers\BrUsbMdm.sys [2009-07-14 12160]
S3 BrUsbSer;Brother MFC USB Serial WDM Driver; C:\Windows\System32\Drivers\BrUsbSer.sys [2009-07-14 11904]
S3 BTHMODEM;Bluetooth Serial Communications Driver; C:\Windows\system32\DRIVERS\bthmodem.sys [2009-07-14 56320]
S3 circlass;Consumer IR Devices; C:\Windows\system32\DRIVERS\circlass.sys [2009-07-14 37888]
S3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2009-07-14 14080]
S3 Compbatt;Compbatt; C:\Windows\system32\DRIVERS\compbatt.sys [2009-07-14 19024]
S3 cpuz132;cpuz132; \??\C:\Users\ToRTeEn\AppData\Local\Temp\cpuz132\cpuz132_x32.sys []
S3 DrvAgent32;DrvAgent32; \??\C:\Windows\system32\Drivers\DrvAgent32.sys [2010-06-25 23456]
S3 ebdrv;Broadcom NetXtreme II 10 GigE VBD; C:\Windows\system32\DRIVERS\evbdx.sys [2009-07-14 3100160]
S3 elxstor;elxstor; C:\Windows\system32\DRIVERS\elxstor.sys [2009-07-14 453712]
S3 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\DRIVERS\errdev.sys [2009-07-14 7168]
S3 exfat;exFAT File System Driver; C:\Windows\system32\drivers\exfat.sys [2009-07-14 142336]
S3 Filetrace;@%SystemRoot%\system32\drivers\filetrace.sys,-10001; C:\Windows\system32\drivers\filetrace.sys [2009-07-14 28160]
S3 FsDepends;@%SystemRoot%\system32\drivers\fsdepends.sys,-10001; C:\Windows\System32\drivers\FsDepends.sys [2009-07-14 46160]
S3 gagp30kx;Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms; C:\Windows\system32\DRIVERS\gagp30kx.sys [2009-07-14 57936]
S3 hcw85cir;Hauppauge Consumer Infrared Receiver; C:\Windows\system32\drivers\hcw85cir.sys [2009-07-14 26624]
S3 HidBatt;HID UPS Battery Driver; C:\Windows\system32\DRIVERS\HidBatt.sys [2009-07-14 21504]
S3 HidBth;Microsoft Bluetooth HID Miniport; C:\Windows\system32\DRIVERS\hidbth.sys [2009-07-14 91136]
S3 HidIr;Microsoft Infrared HID Driver; C:\Windows\system32\DRIVERS\hidir.sys [2009-07-14 37888]
S3 HpSAMD;HpSAMD; C:\Windows\system32\DRIVERS\HpSAMD.sys [2009-07-14 67152]
S3 iaStorV;iaStorV; C:\Windows\system32\DRIVERS\iaStorV.sys [2009-07-14 332352]
S3 iirsp;iirsp; C:\Windows\system32\DRIVERS\iirsp.sys [2009-07-14 41040]
S3 IPMIDRV;IPMIDRV; C:\Windows\system32\DRIVERS\IPMIDrv.sys [2009-07-14 65536]
S3 isapnp;isapnp; C:\Windows\system32\DRIVERS\isapnp.sys [2009-07-14 46656]
S3 iScsiPrt;iScsiPort Driver; C:\Windows\system32\DRIVERS\msiscsi.sys [2009-07-14 186960]
S3 LSI_FC;LSI_FC; C:\Windows\system32\DRIVERS\lsi_fc.sys [2009-07-14 95824]
S3 LSI_SAS;LSI_SAS; C:\Windows\system32\DRIVERS\lsi_sas.sys [2009-07-14 89168]
S3 LSI_SAS2;LSI_SAS2; C:\Windows\system32\DRIVERS\lsi_sas2.sys [2009-07-14 54864]
S3 LSI_SCSI;LSI_SCSI; C:\Windows\system32\DRIVERS\lsi_scsi.sys [2009-07-14 96848]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\mbamswissarmy.sys [2010-04-29 38224]
S3 megasas;megasas; C:\Windows\system32\DRIVERS\megasas.sys [2009-07-14 30800]
S3 MegaSR;MegaSR; C:\Windows\system32\DRIVERS\MegaSR.sys [2009-07-14 235584]
S3 mpio;mpio; C:\Windows\system32\DRIVERS\mpio.sys [2009-07-14 130624]
S3 msahci;msahci; C:\Windows\system32\DRIVERS\msahci.sys [2009-07-14 27712]
S3 msdsm;msdsm; C:\Windows\system32\DRIVERS\msdsm.sys [2009-07-14 115792]
S3 mshidkmdf;@%SystemRoot%\system32\drivers\mshidkmdf.sys,-100; C:\Windows\System32\drivers\mshidkmdf.sys [2009-07-14 4096]
S3 MsRPC;MsRPC; C:\Windows\system32\drivers\MsRPC.sys [2009-07-14 162896]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2009-07-14 6144]
S3 MTConfig;Microsoft Input Configuration Driver; C:\Windows\system32\DRIVERS\MTConfig.sys [2009-07-14 12288]
S3 NdisCap;NDIS Capture LightWeight Filter; C:\Windows\system32\DRIVERS\ndiscap.sys [2009-07-14 27136]
S3 nfrd960;nfrd960; C:\Windows\system32\DRIVERS\nfrd960.sys [2009-07-14 44624]
S3 nmwcd;Nokia USB Phone Parent; C:\Windows\system32\drivers\ccdcmb.sys [2010-02-26 18176]
S3 nmwcdc;Nokia USB Generic; C:\Windows\system32\drivers\ccdcmbo.sys [2010-02-26 22528]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent; C:\Windows\system32\drivers\nmwcdnsu.sys [2010-02-26 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic; C:\Windows\system32\drivers\nmwcdnsuc.sys [2010-02-26 8320]
S3 nv_agp;NVIDIA nForce AGP Bus Filter; C:\Windows\system32\DRIVERS\nv_agp.sys [2009-07-14 105024]
S3 nvraid;nvraid; C:\Windows\system32\DRIVERS\nvraid.sys [2009-07-14 117312]
S3 nvstor;nvstor; C:\Windows\system32\DRIVERS\nvstor.sys [2009-07-14 142416]
S3 ohci1394;1394 OHCI Compliant Host Controller (Legacy); C:\Windows\system32\DRIVERS\ohci1394.sys [2009-07-14 62464]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 ql2300;ql2300; C:\Windows\system32\DRIVERS\ql2300.sys [2009-07-14 1383488]
S3 ql40xx;ql40xx; C:\Windows\system32\DRIVERS\ql40xx.sys [2009-07-14 106064]
S3 QWAVEdrv;@%SystemRoot%\system32\drivers\qwavedrv.sys,-1; C:\Windows\system32\drivers\qwavedrv.sys [2009-07-14 31744]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sbp2port;sbp2port; C:\Windows\system32\DRIVERS\sbp2port.sys [2009-07-14 85568]
S3 scfilter;@%SystemRoot%\System32\drivers\scfilter.sys,-11; C:\Windows\System32\DRIVERS\scfilter.sys [2009-07-14 26624]
S3 sermouse;Serial Mouse Driver; C:\Windows\system32\DRIVERS\sermouse.sys [2009-07-14 19968]
S3 sffdisk;Ovladač třídy úložiště SFF; C:\Windows\system32\DRIVERS\sffdisk.sys [2009-07-14 11264]
S3 sffp_mmc;Ovladač protokolu úložiště SFF pro konzolu MMC; C:\Windows\system32\DRIVERS\sffp_mmc.sys [2009-07-14 12288]
S3 sffp_sd;Ovladač protokolu úložiště SFF pro paměť sběrnici SDBus; C:\Windows\system32\DRIVERS\sffp_sd.sys [2009-10-10 12800]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 SiSRaid2;SiSRaid2; C:\Windows\system32\DRIVERS\SiSRaid2.sys [2009-07-14 40016]
S3 SiSRaid4;SiSRaid4; C:\Windows\system32\DRIVERS\sisraid4.sys [2009-07-14 77888]
S3 Smb;@%SystemRoot%\system32\tcpipcfg.dll,-50005; C:\Windows\system32\DRIVERS\smb.sys [2009-07-14 71168]
S3 stexstor;stexstor; C:\Windows\system32\DRIVERS\stexstor.sys [2009-07-14 21072]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 TCPIP6;Microsoft IPv6 Protocol Driver; C:\Windows\system32\DRIVERS\tcpip.sys [2009-07-14 1285712]
S3 tssecsrv;@%SystemRoot%\System32\DRIVERS\tssecsrv.sys,-101; C:\Windows\System32\DRIVERS\tssecsrv.sys [2009-07-14 30208]
S3 tunnel;Microsoft Tunnel Miniport Adapter Driver; C:\Windows\system32\DRIVERS\tunnel.sys [2009-07-14 108544]
S3 uagp35;Microsoft AGPv3.5 Filter; C:\Windows\system32\DRIVERS\uagp35.sys [2009-07-14 55888]
S3 uliagpkx;Uli AGP Bus Filter; C:\Windows\system32\DRIVERS\uliagpkx.sys [2009-07-14 57424]
S3 UmPass;Microsoft UMPass Driver; C:\Windows\system32\DRIVERS\umpass.sys [2009-07-14 8192]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerflt.sys [2010-02-26 8192]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\Windows\system32\DRIVERS\usbccgp.sys [2009-07-14 75264]
S3 usbcir;eHome Infrared Receiver (USBCIR); C:\Windows\system32\DRIVERS\usbcir.sys [2009-07-14 86016]
S3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\Windows\system32\DRIVERS\usbohci.sys [2009-07-14 20480]
S3 usbprint;Microsoft USB PRINTER Class; C:\Windows\system32\DRIVERS\usbprint.sys [2009-07-14 19968]
S3 usbser;USB Modem Driver; C:\Windows\system32\DRIVERS\usbser.sys [2009-07-14 27648]
S3 USBSTOR;USB Mass Storage Driver; C:\Windows\system32\DRIVERS\USBSTOR.SYS [2009-07-14 74752]
S3 vga;vga; C:\Windows\system32\DRIVERS\vgapnp.sys [2009-07-14 26112]
S3 vhdmp;vhdmp; C:\Windows\system32\DRIVERS\vhdmp.sys [2009-07-14 159824]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
S3 vsmraid;vsmraid; C:\Windows\system32\DRIVERS\vsmraid.sys [2009-07-14 141904]
S3 vwifibus;@%SystemRoot%\System32\drivers\vwifibus.sys,-257; C:\Windows\System32\drivers\vwifibus.sys [2009-07-14 19968]
S3 WacomPen;Wacom Serial Pen HID Driver; C:\Windows\system32\DRIVERS\wacompen.sys [2009-07-14 21632]
S3 Wd;Wd; C:\Windows\system32\DRIVERS\wd.sys [2009-07-14 19024]
S3 WIMMount;WIMMount; C:\Windows\system32\drivers\wimmount.sys [2009-07-14 19008]
S3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2009-07-14 11264]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2009-07-14 132224]
S4 crcdisk;Crcdisk Filter Driver; C:\Windows\system32\DRIVERS\crcdisk.sys [2009-07-14 22096]
S4 ws2ifsl;@%systemroot%\System32\drivers\ws2ifsl.sys,-1000; C:\Windows\system32\drivers\ws2ifsl.sys [2009-07-14 16384]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AudioEndpointBuilder;@%SystemRoot%\system32\audiosrv.dll,-204; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 BFE;@%SystemRoot%\system32\bfe.dll,-1001; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 DPS;@%systemroot%\system32\dps.dll,-500; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2010-04-07 810120]
R2 FDResPub;@%systemroot%\system32\fdrespub.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 gpsvc;@gpapi.dll,-112; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 IKEEXT;@%SystemRoot%\system32\ikeext.dll,-501; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 MMCSS;@%systemroot%\system32\mmcss.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 MpsSvc;@%SystemRoot%\system32\FirewallAPI.dll,-23090; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 NlaSvc;@%SystemRoot%\System32\nlasvc.dll,-1; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 nsi;@%SystemRoot%\system32\nsisvc.dll,-200; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2010-06-20 66872]
R2 PnkBstrB;PnkBstrB; C:\Windows\system32\PnkBstrB.exe [2010-06-20 107832]
R2 Power;@%SystemRoot%\system32\umpo.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 ProfSvc;@%systemroot%\system32\profsvc.dll,-300; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 RpcEptMapper;@%windir%\system32\RpcEpMap.dll,-1001; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-06-07 240232]
R2 SysMain;@%SystemRoot%\system32\sysmain.dll,-1000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 UxSms;@%SystemRoot%\system32\dwm.exe,-2000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 WerSvc;@%SystemRoot%\System32\wersvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 WinDefend;@%ProgramFiles%\Windows Defender\MsMpRes.dll,-103; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 wudfsvc;@%SystemRoot%\system32\wudfsvc.dll,-1000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 AeLookupSvc;@%SystemRoot%\system32\aelupsvc.dll,-1; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 Appinfo;@%systemroot%\system32\appinfo.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 fdPHost;@%systemroot%\system32\fdPHost.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 HomeGroupProvider;@%SystemRoot%\System32\provsvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 KeyIso;@keyiso.dll,-100; C:\Windows\system32\lsass.exe [2009-07-14 22528]
R3 netprofm;@%SystemRoot%\system32\netprofm.dll,-202; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 PcaSvc;@%SystemRoot%\system32\pcasvc.dll,-1; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 TrustedInstaller;@%SystemRoot%\servicing\TrustedInstaller.exe,-100; C:\Windows\servicing\TrustedInstaller.exe [2009-07-14 204800]
R3 WdiServiceHost;@%systemroot%\system32\wdi.dll,-502; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 WdiSystemHost;@%systemroot%\system32\wdi.dll,-500; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 WinHttpAutoProxySvc;@%SystemRoot%\system32\winhttp.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 Wlansvc;@%SystemRoot%\System32\wlansvc.dll,-257; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\wmpnetwk.exe [2009-07-14 1121280]
R3 WSearch;Windows Search; C:\Windows\system32\SearchIndexer.exe [2009-07-14 428032]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 sppsvc;@%SystemRoot%\system32\sppsvc.exe,-101; C:\Windows\system32\sppsvc.exe [2009-07-14 3179520]
S3 AppIDSvc;@%systemroot%\system32\appidsvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 AxInstSV;@%SystemRoot%\system32\AxInstSV.dll,-103; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 BDESVC;@%SystemRoot%\system32\bdesvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 bthserv;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 defragsvc;@%SystemRoot%\system32\defragsvc.dll,-101; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 EFS;@%SystemRoot%\system32\efssvc.dll,-100; C:\Windows\System32\lsass.exe [2009-07-14 22528]
S3 ehRecvr;@%SystemRoot%\ehome\ehrecvr.exe,-101; C:\Windows\ehome\ehRecvr.exe [2010-05-09 556032]
S3 ehSched;@%SystemRoot%\ehome\ehsched.exe,-101; C:\Windows\ehome\ehsched.exe [2009-07-14 94720]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2010-04-07 33560]
S3 Fax;@%systemroot%\system32\fxsresm.dll,-118; C:\Windows\system32\fxssvc.exe [2009-07-14 522752]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2009-06-10 42856]
S3 HomeGroupListener;@%SystemRoot%\System32\ListSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 idsvc;@%systemroot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8193; C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2009-06-10 878416]
S3 IPBusEnum;@%systemroot%\system32\IPBusEnum.dll,-102; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 KtmRm;@comres.dll,-2946; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 lltdsvc;@%SystemRoot%\system32\lltdres.dll,-1; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 MatSvc;@%ProgramFiles%\Microsoft Fix it Center\MatsRes.dll,-9000; C:\Program Files\Microsoft Fix it Center\Matsvc.exe [2010-04-10 266544]
S3 MSiSCSI;@%SystemRoot%\system32\iscsidsc.dll,-5000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-06-07 129640]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 p2pimsvc;@%SystemRoot%\system32\pnrpsvc.dll,-8004; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 p2psvc;@%SystemRoot%\system32\p2psvc.dll,-8006; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 pla;@%systemroot%\system32\pla.dll,-500; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 PNRPAutoReg;@%SystemRoot%\system32\pnrpauto.dll,-8002; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 PNRPsvc;@%SystemRoot%\system32\pnrpsvc.dll,-8000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 QWAVE;@%SystemRoot%\system32\qwave.dll,-1; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 SDRSVC;@%SystemRoot%\system32\sdrsvc.dll,-107; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 SensrSvc;@%SystemRoot%\System32\sensrsvc.dll,-1000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-04-27 611840]
S3 SessionEnv;@%SystemRoot%\System32\SessEnv.dll,-1026; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 sppuinotify;@%SystemRoot%\system32\sppuinotify.dll,-103; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 SstpSvc;@%SystemRoot%\system32\sstpsvc.dll,-200; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2010-05-10 390952]
S3 SwitchBoard;SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 TabletInputService;@%SystemRoot%\system32\TabSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 TBS;@%SystemRoot%\system32\tbssvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 THREADORDER;@%systemroot%\system32\mmcss.dll,-102; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 UI0Detect;@%SystemRoot%\system32\ui0detect.exe,-101; C:\Windows\system32\UI0Detect.exe [2009-07-14 35840]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 VaultSvc;@%SystemRoot%\system32\vaultsvc.dll,-1003; C:\Windows\system32\lsass.exe [2009-07-14 22528]
S3 vds;@%SystemRoot%\system32\vds.exe,-100; C:\Windows\System32\vds.exe [2009-07-14 452608]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-05-19 1343400]
S3 wbengine;@%systemroot%\system32\wbengine.exe,-104; C:\Windows\system32\wbengine.exe [2009-07-14 1202688]
S3 WbioSrvc;@%systemroot%\system32\wbiosrvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 wcncsvc;@%SystemRoot%\system32\wcncsvc.dll,-3; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WcsPlugInService;@%SystemRoot%\system32\WcsPlugInService.dll,-200; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 Wecsvc;@%SystemRoot%\system32\wecsvc.dll,-200; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 wercplsupport;@%SystemRoot%\System32\wercplsupport.dll,-101; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WinRM;@%Systemroot%\system32\wsmsvc.dll,-101; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WPCSvc;@%SystemRoot%\system32\wpcsvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 WPDBusEnum;@%SystemRoot%\system32\wpdbusenum.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 WwanSvc;@%SystemRoot%\System32\wwansvc.dll,-257; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S4 CertPropSvc;@%SystemRoot%\System32\certprop.dll,-11; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S4 clr_optimization_v2.0.50727_32;Microsoft .NET Framework NGEN v2.0.50727_X86; C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2009-06-10 66384]
S4 iphlpsvc;@%SystemRoot%\system32\iphlpsvc.dll,-500; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S4 Mcx2Svc;@%SystemRoot%\ehome\ehres.dll,-15501; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S4 NetTcpPortSharing;@%systemroot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8201; C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2009-06-10 128848]
S4 SCPolicySvc;@%SystemRoot%\System32\certprop.dll,-13; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S4 SNMPTRAP;@%SystemRoot%\system32\snmptrap.exe,-3; C:\Windows\System32\snmptrap.exe [2009-07-14 12800]

-----------------EOF-----------------

Log z MBAM
Malwarebytes' Anti-Malware 1.46
http://www.malwarebytes.org

Verze databáze: 4237

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

25.6.2010 11:17:40
mbam-log-2010-06-25 (11-17-40).txt

Typ skenu: Rychlý sken
Skenované objekty: 125481
Uplynulý čas: 24 minuta(y), 26 sekunda(y)

Infikované procesy v paměti: 1
Infikované moduly v paměti: 0
Infikované klíče registru: 1
Infikované hodnoty registru: 0
Infikované datové položky registru: 0
Infikované složky: 0
Infikované soubory: 2

Infikované procesy v paměti:
C:\Users\ToRTeEn\AppData\Local\Temp\Hlg.exe (Trojan.Fraudpack) -> Failed to unload process.

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče registru:
HKEY_CURRENT_USER\SOFTWARE\V71IQL7HI7 (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Infikované hodnoty registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované datové položky registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)

Infikované soubory:
C:\Users\ToRTeEn\AppData\Local\Temp\Hlg.exe (Trojan.Fraudpack) -> Delete on reboot.
C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Quarantined and deleted successfully.

Předem děkuji za pomoc:)

Avatar uživatele
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 Říj 2008 08:02

Re: Pravděpodobně trojan - prosím o kontrolu logu

#2 Příspěvek od motji »

Hezké odpoledne :)

:arrow: Stáhněte na plochu, ukončete všechna aktivní okna a spusťte ComboFix - http://download.bleepingcomputer.com/sUBs/ComboFix.exe


- ComboFix je třeba spustit pod účtem s právy administrátora

- Před použitím vypněte všechny rezidentní bezpečnostní programy - antiviry, firewally, antispywary

- Po spuštění se zobrazí podmínky užití, potvrďte je stiskem tlačítka Ano

- Dále postupujte dle pokynů, během aplikování ComboFixu neklikejte do zobrazujícího se okna :!:

- Po dokončení skenování, trvajícího maximálně 10 minut, by měl program vytvořit log - C:\ComboFix.txt, zkopírujte celý jeho obsah sem
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Thooty
Návštěvník
Návštěvník
Příspěvky: 95
Registrován: 08 Dub 2010 14:51

Re: Pravděpodobně trojan - prosím o kontrolu logu

#3 Příspěvek od Thooty »

Omlouvám se že píší tak pozdě, něco sem měl.
Tady je ten log z ComboFixu
ComboFix 10-06-24.03 - ToRTeEn 25.06.2010 16:28:59.1.1 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1029.18.1023.395 [GMT 2:00]
Spuštěný z: c:\users\ToRTeEn\Desktop\ComboFix.exe
* Rezidentní štít AV je zapnutý

.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\FlashGet Network
c:\program files\FlashGet Network\FlashGet 3\adns.dll
c:\program files\FlashGet Network\FlashGet 3\btcoreu.dll
c:\program files\FlashGet Network\FlashGet 3\BugReport.dll
c:\program files\FlashGet Network\FlashGet 3\BugReport.exe
c:\program files\FlashGet Network\FlashGet 3\cd1.ico
c:\program files\FlashGet Network\FlashGet 3\ckcore.dll
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\14_43260.dll
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\28_83260.dll
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\atrc.dll
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\Codecs.zip
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\cook.dll
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\ddnt3260.dll
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\dnet3260.dll
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\drv1.dll
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\drv2.dll
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\drvc.dll
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\hxltcolor.dll
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\raac.dll
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\ralf.dll
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\rv10.dll
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\rv20.dll
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\rv30.dll
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\rv40.dll
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\sipr.dll
c:\program files\FlashGet Network\FlashGet 3\commonlib.dll
c:\program files\FlashGet Network\FlashGet 3\componentskrnl.dll
c:\program files\FlashGet Network\FlashGet 3\config\clients.met
c:\program files\FlashGet Network\FlashGet 3\config\clients.met.bak
c:\program files\FlashGet Network\FlashGet 3\config\cryptkey.dat
c:\program files\FlashGet Network\FlashGet 3\config\emfriends.met
c:\program files\FlashGet Network\FlashGet 3\config\known.met
c:\program files\FlashGet Network\FlashGet 3\config\known2_64.met
c:\program files\FlashGet Network\FlashGet 3\config\preferences.dat
c:\program files\FlashGet Network\FlashGet 3\config\preferences.ini
c:\program files\FlashGet Network\FlashGet 3\config\server.met
c:\program files\FlashGet Network\FlashGet 3\config\server_met.old
c:\program files\FlashGet Network\FlashGet 3\config\upload.met
c:\program files\FlashGet Network\FlashGet 3\corestat.dll
c:\program files\FlashGet Network\FlashGet 3\dbghelp.dll
c:\program files\FlashGet Network\FlashGet 3\fg.ico
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\default.htm
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\FGResDetector.conf
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\banner.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\bullet.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\close.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\closelabel.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\download-icon.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\explorer.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\ftp.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\image.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\introTextBg.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\loading.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\nextlabel.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\prevlabel.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\software.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\vod.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\FGResDetector.exe
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\image\about.png
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\image\ftplist_tree_icon.png
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\image\option_icon.png
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\image\quickop_hide.png
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\image\quickop_show.png
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\image\statusbar_bk.png
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\image\tasktab_close.png
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\image\toolbar_back.png
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\image\toolbar_bk.png
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\image\toolbar_close.png
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\image\toolbar_forward.png
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\image\toolbar_refresh.png
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\lang\l.eng.xml
c:\program files\FlashGet Network\FlashGet 3\FGSoftware.exe
c:\program files\FlashGet Network\FlashGet 3\Flashget3.exe
c:\program files\FlashGet Network\FlashGet 3\FlashGet3.xpi
c:\program files\FlashGet Network\FlashGet 3\FlashGetBHO3.dll
c:\program files\FlashGet Network\FlashGet 3\FlashGetHook.dll
c:\program files\FlashGet Network\FlashGet 3\fnsArchive.dll
c:\program files\FlashGet Network\FlashGet 3\fnsDirectuix.dll
c:\program files\FlashGet Network\FlashGet 3\fnsLanguage.dll
c:\program files\FlashGet Network\FlashGet 3\fnslanguage_en.dll
c:\program files\FlashGet Network\FlashGet 3\fnsSecurity.dll
c:\program files\FlashGet Network\FlashGet 3\fnsScheduler.dll
c:\program files\FlashGet Network\FlashGet 3\fnsSkinX.dll
c:\program files\FlashGet Network\FlashGet 3\fnsStatistics.dll
c:\program files\FlashGet Network\FlashGet 3\game.ico
c:\program files\FlashGet Network\FlashGet 3\gb2312-unicode.dic
c:\program files\FlashGet Network\FlashGet 3\gdiplus.dll
c:\program files\FlashGet Network\FlashGet 3\GetAllUrl.htm
c:\program files\FlashGet Network\FlashGet 3\GetUrl.htm
c:\program files\FlashGet Network\FlashGet 3\GoogleToolbarInstaller_download_signed.exe
c:\program files\FlashGet Network\FlashGet 3\libem.dll
c:\program files\FlashGet Network\FlashGet 3\license.txt
c:\program files\FlashGet Network\FlashGet 3\lst_tz.bin
c:\program files\FlashGet Network\FlashGet 3\P2PCfg.ini
c:\program files\FlashGet Network\FlashGet 3\p2pcore.dll
c:\program files\FlashGet Network\FlashGet 3\p2score.dll
c:\program files\FlashGet Network\FlashGet 3\PatchWise.bak\fnslanguage_en.dll
c:\program files\FlashGet Network\FlashGet 3\PatchWise.log
c:\program files\FlashGet Network\FlashGet 3\perf.ini
c:\program files\FlashGet Network\FlashGet 3\pncrt.dll
c:\program files\FlashGet Network\FlashGet 3\pstat.dat
c:\program files\FlashGet Network\FlashGet 3\pup.dat
c:\program files\FlashGet Network\FlashGet 3\RdOldDb.dll
c:\program files\FlashGet Network\FlashGet 3\RealMediaSplitter.ax
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\BarSet.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\btn_check.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\btn_normal.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\btn_radio.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\desktoplink.ico
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\login_line.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\menu_icon.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\option_line.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\option_page_line.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\skin.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\SuspendLogo.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\SuspendNoLogo.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\toolbar_backgrand.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\toolbar_cancle.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\toolbar_catgroy.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\toolbar_group.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\toolbar_new.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\toolbar_open.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\toolbar_option.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\toolbar_pause.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\toolbar_recly.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\toolbar_start.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\toolbarbutton_left.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\toolbarbutton_middle.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\toolbarbutton_right.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\top_logotitle.gif
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\torrent.ico
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\userinfo_head.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\VistaStyleListItems.bmp
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\preview.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\skin.xml
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\sound\loginfailed.wav
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\sound\loginsucc.wav
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\sound\msgnotify.wav
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\sound\notify.wav
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\topmain.png
c:\program files\FlashGet Network\FlashGet 3\SnapShot.dll
c:\program files\FlashGet Network\FlashGet 3\storage.dll
c:\program files\FlashGet Network\FlashGet 3\SysOptimize.exe
c:\program files\FlashGet Network\FlashGet 3\uninst.exe
c:\program files\FlashGet Network\FlashGet 3\VodCore.dll
c:\program files\FlashGet Network\FlashGet 3\zlib.dll
c:\users\ToRTeEn\AppData\Roaming\BITS
c:\users\ToRTeEn\AppData\Roaming\BITS\BITS.ini
c:\users\ToRTeEn\AppData\Roaming\BITS\DHTTable.dat
c:\users\ToRTeEn\AppData\Roaming\BITS\ProxyList.ini
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100505223357.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100505223357.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100505223400.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100505223400.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100505223401.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100505223401.torrent.~tmp
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100505223401.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100505223401.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100505223401.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100505223401.torrent.seeds
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100505223401.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100505231334.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100505231334.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100505231337.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100505231337.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100505231338.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100505231338.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100505231338.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100505231338.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100505231338.torrent.seeds
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100505231338.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100506125005.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100506125005.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100507235035.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100507235035.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100507235037.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100507235037.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508025342.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508025342.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508025353.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508025353.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508025354.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508025354.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508025354.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508030257.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508030257.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508030303.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508030303.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508030304.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508030304.torrent.~tmp
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508030304.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508030304.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508030304.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508030304.torrent.seeds
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508030304.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508185119.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508185119.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508185124.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508185124.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508185133.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508185133.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508185134.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508185134.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508185134.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508185134.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508185134.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508202800.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508202800.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508202806.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508202806.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508202807.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508202807.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508202807.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508202807.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508202807.torrent.seeds
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100508202807.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509000548.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509000548.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509000552.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509000552.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509000553.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509000553.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509000553.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509000553.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509000553.torrent.seeds
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509000553.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509005921.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509005921.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509005935.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509005935.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509005936.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509005936.torrent.~tmp
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509005936.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509005936.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509005936.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509005936.torrent.seeds
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509005936.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509124446.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509124446.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509140738.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509140738.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509140743.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509140743.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509140747.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509140747.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509140750.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509140750.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509171840.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509171840.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509171843.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509171843.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509171844.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509171844.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509171844.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509171844.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509171844.torrent.seeds
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509171844.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509172215.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509172215.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509234616.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509234616.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509234637.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509234637.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509234638.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509234638.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509234638.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509234638.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509234638.torrent.seeds
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509234638.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509234908.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509234908.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509234910.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509234910.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509234911.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509234911.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100509234911.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100510214003.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100510214003.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100510214009.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100510214009.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100510214010.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100510214010.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100510214010.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100510215046.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100510215046.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100510215058.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100510215058.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100510215059.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100510215059.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100510215059.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100511171007.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100511171007.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100511171016.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100511171016.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100511171017.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100511171017.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100511171017.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100511171017.torrent.seeds
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100511171017.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513194330.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513194330.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513194337.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513194337.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513194338.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513194338.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513194338.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513195934.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513195934.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513195944.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513195944.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513195945.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513195945.torrent.~tmp
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513195945.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513195945.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513195945.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513195945.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513200134.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513200134.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513200228.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513200228.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513200235.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513200235.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513200236.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513200236.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513202241.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513202241.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513202252.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513202252.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513202253.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513202253.torrent.~tmp
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513202253.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513202253.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513202253.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513202253.torrent.seeds
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513202253.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513202434.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513202434.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513202438.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513202438.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513202439.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513202439.torrent.~tmp
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513202439.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513202439.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513202439.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513202439.torrent.seeds
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513202439.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513203231.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513203231.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513203356.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513203356.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513203401.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513203401.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513203541.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513203541.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513203548.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513203548.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513203548.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513203548.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513203548.torrent.seeds
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513203548.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513203929.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513203929.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513203934.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513203934.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513203935.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513203935.torrent.~tmp
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513203935.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513203935.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513203935.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513203935.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513204057.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513204057.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513204103.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513204103.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513204104.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513204104.torrent.~tmp
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513204104.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513204104.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513204104.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513204104.torrent.seeds
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513204104.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513205651.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513205651.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513205654.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513205654.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513205655.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513205655.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513205655.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513205655.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513205655.torrent.seeds
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513205655.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513205906.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513205906.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513210019.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513210019.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513210030.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513210030.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513210031.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513210031.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100513210031.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100514132649.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100514132649.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100514132702.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100514132702.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100514132703.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100514132703.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100514135610.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100514135610.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100514135617.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100514135617.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100514135618.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100514135618.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100514145614.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100514145614.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100514145617.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100514145617.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100514145618.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100514145618.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100514145618.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100514145618.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100514145618.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100516000536.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100516000536.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100516161602.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100516161602.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100516161612.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100516161612.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100516161613.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100516161613.torrent.~tmp
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100516161613.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100516161613.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100516161613.torrent.seeds
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100516161613.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100516161834.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100516161834.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524162525.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524162525.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524162539.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524162539.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524162540.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524162540.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524162540.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524162642.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524162642.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524181459.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524181459.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524181502.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524181502.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524181503.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524181503.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524181503.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524181503.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524181557.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524181557.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524181623.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524181623.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524181624.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524181624.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524181624.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524181624.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524181624.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524200846.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524200846.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524200910.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524200910.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524200911.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524200911.torrent.~tmp
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524200911.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524200911.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524200911.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524201907.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524201907.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524201916.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524201916.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524201917.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524201917.torrent.~tmp
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524201917.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524201917.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524201917.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524202524.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524202524.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524202526.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524202526.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524202527.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524202527.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524202527.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524202527.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100524202527.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100527230855.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100527230855.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100527230912.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100527230912.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100527230913.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100527230913.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100527230913.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100527230913.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100527231659.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100527231659.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100527232435.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100527232435.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100527232708.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100527232708.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100527232709.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100527232709.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100527232709.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100527232709.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100527233849.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100527233849.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100527233902.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100527233902.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100527233903.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100527233903.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100527233903.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100527233903.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100527233903.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100528011357.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100528011357.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100528011415.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100528011415.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100528011416.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100528011416.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100528011416.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100528011416.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100528082236.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100528082236.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100528082250.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100528082250.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100528082255.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100528082255.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100528082256.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100528082256.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100528101244.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100528101244.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100528101254.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100528101254.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100528101341.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100528101341.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100528101342.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100528101342.torrent.~tmp
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100528101342.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100528101342.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100528101342.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100528101342.torrent.seeds
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100528101342.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100528190428.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100528190428.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100529002736.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100529002736.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100529002859.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100529002859.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100529002900.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100529002900.torrent.~tmp
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100529002900.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100529002900.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100529002900.torrent.seeds
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100529002900.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100529123830.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100529123830.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100529184527.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100529184527.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100529184530.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100529184530.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100529184531.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100529184531.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100529184531.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100604161337.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100604161337.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100606192947.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100606192947.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100606192949.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100606192949.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100606192950.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100606192950.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100606192950.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100606192950.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100606192950.torrent.seeds
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100606192950.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100613184640.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100613184640.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100613184641.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100613184641.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100613184642.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100613184642.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100613184643.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100613184643.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100613184643.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100613184643.torrent.seeds
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100613184643.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100613185045.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100613185045.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100613190135.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100613190135.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100613190137.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100613190137.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100613190138.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100613190138.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100613190138.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100613190138.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100615160811.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100615160811.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100615160839.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100615160839.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100615160857.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100615160857.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100615160858.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100615160858.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100615160858.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100615160858.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100615160858.torrent.seeds
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100615160858.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100617144806.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100617144806.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100617144812.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100617144812.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100617144813.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100617144813.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100617144813.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100617144813.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100617144813.torrent.seeds
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100617144813.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100617164900.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100617164900.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100617164910.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100617164910.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100617164931.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100617164931.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100617164932.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100617164932.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100617164932.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100617164932.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100617164932.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100618000439.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100618000439.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100618000444.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100618000444.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100618000445.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100618000445.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100618000445.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100618000445.torrent.hybridlist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100618000445.torrent.seeds
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100618000445.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100618085412.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100618085412.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100618085418.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100618085418.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100618085419.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100618085419.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100618085419.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100618085419.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100618125224.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100618125224.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100618125227.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100618125227.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100618134301.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100618134301.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100618134302.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100618134302.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100618174131.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100618174131.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100619003347.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100619003347.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100619003354.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100619003354.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100619003356.torrent
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100619003356.torrent.bits
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100619003356.torrent.filelist
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100619003356.torrent.seeds
c:\users\ToRTeEn\AppData\Roaming\BITS\Torrent\20100619003356.torrent.statistic
c:\users\ToRTeEn\AppData\Roaming\FlashGetBHO
c:\users\ToRTeEn\AppData\Roaming\FlashGetBHO\FlashGetBHO3.dll
c:\users\ToRTeEn\AppData\Roaming\FlashGetBHO\FlashGetHook.dll
c:\users\ToRTeEn\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
c:\users\ToRTeEn\AppData\Roaming\FlashGetBHO\GetUrl.htm
c:\windows\system32\Drivers\esoerjvk.sys
c:\windows\system32\secushr.dat
c:\windows\system32\secustat.dat

Thooty
Návštěvník
Návštěvník
Příspěvky: 95
Registrován: 08 Dub 2010 14:51

Re: Pravděpodobně trojan - prosím o kontrolu logu

#4 Příspěvek od Thooty »

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-05-25 do 2010-06-25 )))))))))))))))))))))))))))))))
.

2010-06-25 14:44 . 2010-06-25 14:44 -------- d-----w- c:\users\ToRTeEn\AppData\Local\temp
2010-06-25 14:44 . 2010-06-25 14:44 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-06-25 14:22 . 2010-06-25 14:23 -------- d-----w- C:\32788R22FWJFW
2010-06-25 09:25 . 2010-06-25 09:29 -------- d-----w- c:\program files\trend micro
2010-06-25 09:25 . 2010-06-25 09:30 -------- d-----w- C:\rsit
2010-06-25 08:52 . 2010-06-25 08:52 -------- d-----w- c:\users\ToRTeEn\AppData\Roaming\Malwarebytes
2010-06-25 08:51 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-25 08:51 . 2010-06-25 08:51 -------- d-----w- c:\programdata\Malwarebytes
2010-06-25 08:51 . 2010-06-25 08:52 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-25 08:51 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-06-25 08:32 . 2010-06-25 08:33 -------- d-----w- c:\users\ToRTeEn\AppData\Local\eSupport.com
2010-06-25 08:32 . 2010-06-25 08:32 23456 ----a-w- c:\windows\system32\drivers\DrvAgent32.sys
2010-06-25 08:03 . 2010-06-25 08:03 -------- d-----w- c:\program files\Lavalys
2010-06-23 11:20 . 2009-11-25 10:47 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-06-23 11:20 . 2009-11-25 10:47 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-06-23 11:20 . 2009-11-25 10:47 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-06-23 11:20 . 2009-11-25 10:47 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-06-23 11:20 . 2009-11-25 10:47 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-06-23 07:38 . 2010-03-24 06:37 1286456 ----a-w- c:\windows\system32\ntdll.dll
2010-06-23 07:37 . 2010-05-09 09:14 641536 ----a-w- c:\windows\system32\CPFilters.dll
2010-06-23 07:37 . 2010-05-09 09:14 417792 ----a-w- c:\windows\system32\msdri.dll
2010-06-20 10:49 . 2010-06-20 10:49 -------- d-----w- c:\users\ToRTeEn\AppData\Local\My Games
2010-06-20 10:10 . 2010-06-20 10:10 22328 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-06-20 10:10 . 2010-06-20 10:10 22328 ----a-w- c:\users\ToRTeEn\AppData\Roaming\PnkBstrK.sys
2010-06-20 10:10 . 2010-06-20 10:10 107832 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-06-20 10:10 . 2010-06-20 10:10 66872 ----a-w- c:\windows\system32\PnkBstrA.exe
2010-06-20 10:10 . 2010-06-20 10:10 2250024 ----a-w- c:\windows\system32\pbsvc.exe
2010-06-20 10:03 . 2010-06-20 10:03 -------- d-----w- c:\program files\Ubisoft
2010-06-19 17:31 . 2010-06-19 17:31 -------- d-----w- c:\users\ToRTeEn\AppData\Local\ArmA
2010-06-19 17:24 . 2010-06-19 17:26 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2010-06-19 17:24 . 2010-06-19 17:26 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2010-06-19 17:24 . 2010-06-19 17:26 -------- d-----w- c:\program files\OpenAL
2010-06-19 16:34 . 2010-06-22 20:40 -------- d-----w- c:\program files\SuperHideIP
2010-06-19 08:49 . 2010-06-19 08:49 -------- d-----w- c:\users\ToRTeEn\AppData\Local\ElevatedDiagnostics
2010-06-18 15:48 . 2010-06-18 15:48 -------- d-----w- c:\programdata\FreeHideIP
2010-06-18 15:48 . 2010-06-18 15:48 -------- d-----w- c:\users\ToRTeEn\AppData\Roaming\FreeHideIP
2010-06-18 15:40 . 2010-06-18 18:38 -------- d-----w- c:\programdata\SuperHideIP
2010-06-18 15:40 . 2010-06-18 15:40 -------- d-----w- c:\users\ToRTeEn\AppData\Roaming\SuperHideIP
2010-06-18 13:32 . 2010-06-18 13:32 -------- d-----w- c:\program files\Eagle Dynamics
2010-06-17 20:22 . 2010-06-17 20:22 -------- d-----w- c:\program files\Electronic Arts
2010-06-16 15:42 . 2010-06-16 15:42 203776 ----a-w- c:\windows\system32\clrviddc.dll
2010-06-16 15:35 . 2010-06-16 15:36 -------- d-----w- c:\program files\Common Files\Real
2010-06-16 15:35 . 2010-06-16 15:36 -------- d-----w- c:\program files\Real
2010-06-15 22:12 . 2010-06-07 23:57 10888168 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2010-06-15 22:12 . 2010-06-07 23:57 56936 ----a-w- c:\windows\system32\OpenCL.dll
2010-06-15 22:12 . 2010-06-07 23:57 9712744 ----a-w- c:\windows\system32\nvd3dum.dll
2010-06-15 22:12 . 2010-06-07 23:57 4513384 ----a-w- c:\windows\system32\nvcuda.dll
2010-06-15 22:12 . 2010-06-07 23:57 332392 ----a-w- c:\windows\system32\nvdecodemft.dll
2010-06-15 22:12 . 2010-06-07 23:57 2890856 ----a-w- c:\windows\system32\nvencodemft.dll
2010-06-15 22:12 . 2010-06-07 23:57 2632296 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-06-15 22:12 . 2010-06-07 23:57 2145896 ----a-w- c:\windows\system32\nvcuvid.dll
2010-06-15 22:12 . 2010-06-07 23:57 15764072 ----a-w- c:\windows\system32\nvoglv32.dll
2010-06-15 22:12 . 2010-06-07 23:57 232040 ----a-w- c:\windows\system32\nvcod1921.dll
2010-06-15 22:12 . 2010-06-07 23:57 232040 ----a-w- c:\windows\system32\nvcod.dll
2010-06-15 22:12 . 2010-06-07 23:57 10263144 ----a-w- c:\windows\system32\nvcompiler.dll
2010-06-13 17:07 . 2010-06-13 17:07 -------- d-----w- c:\programdata\RealHideIP
2010-06-13 16:53 . 2010-06-17 18:13 -------- d-----w- c:\programdata\AutoHideIP
2010-06-13 12:06 . 2010-06-13 16:01 -------- d-----w- c:\program files\ICQ6Toolbar
2010-06-13 12:06 . 2010-06-13 12:24 -------- d-----w- c:\programdata\ICQ
2010-06-13 12:05 . 2010-06-25 10:56 -------- d-----w- c:\users\ToRTeEn\AppData\Roaming\ICQ
2010-06-13 12:05 . 2010-06-13 12:05 -------- d-----w- c:\users\ToRTeEn\AppData\Local\AOL
2010-06-13 12:04 . 2010-06-13 12:08 -------- d-----w- c:\program files\ICQ7.2
2010-06-09 09:54 . 2010-03-05 07:42 67584 ----a-w- c:\windows\system32\asycfilt.dll
2010-06-09 09:54 . 2010-05-21 05:18 977920 ----a-w- c:\windows\system32\wininet.dll
2010-06-09 09:54 . 2010-05-01 14:49 2326528 ----a-w- c:\windows\system32\win32k.sys
2010-06-09 09:53 . 2010-05-27 03:49 293888 ----a-w- c:\windows\system32\atmfd.dll
2010-06-09 09:53 . 2010-05-27 07:24 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-06-07 15:48 . 2010-06-07 15:48 13917800 ----a-w- c:\windows\system32\nvcpl.dll
2010-06-07 15:48 . 2010-06-07 15:48 1331816 ----a-w- c:\windows\system32\nvsvc.dll
2010-06-07 15:48 . 2010-06-07 15:48 129640 ----a-w- c:\windows\system32\nvvsvc.exe
2010-06-07 15:48 . 2010-06-07 15:48 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-06-06 19:03 . 2010-06-06 19:03 -------- d-----w- c:\users\ToRTeEn\AppData\Local\PunkBuster
2010-06-05 12:32 . 2010-06-05 12:32 -------- d-----w- c:\program files\Rockstar Games
2010-06-04 19:38 . 2010-06-04 19:38 -------- d-----w- c:\program files\Common Files\PCSuite
2010-06-04 19:38 . 2010-06-04 19:38 -------- d-----w- c:\program files\Nokia
2010-06-04 19:34 . 2010-06-04 19:33 34701512 ----a-w- c:\programdata\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Nokia_PC_Suite_cze_web.exe
2010-06-04 19:18 . 2010-06-04 19:18 -------- d-----w- c:\programdata\PC Suite
2010-06-04 19:08 . 2010-06-04 19:06 34399664 ----a-w- c:\programdata\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Nokia_PC_Suite_eng_web.exe
2010-06-04 19:07 . 2010-06-04 19:07 95232 ----a-w- c:\programdata\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\pcswpcsi.exe
2010-06-04 19:07 . 2010-06-04 19:07 8192 ----a-w- c:\programdata\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstCCD.exe
2010-06-04 19:07 . 2010-06-04 19:07 61440 ----a-w- c:\programdata\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2010-06-04 19:07 . 2010-06-04 19:07 10240 ----a-w- c:\programdata\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstPCS.exe
2010-06-04 14:46 . 2010-06-04 14:46 -------- d-----w- c:\programdata\Uniblue
2010-06-04 14:39 . 2010-06-04 14:46 -------- d-----w- c:\users\ToRTeEn\AppData\Roaming\Uniblue
2010-06-04 14:38 . 2010-06-04 14:38 -------- d-----w- c:\program files\Uniblue
2010-06-04 12:05 . 2010-06-04 12:05 -------- d-----w- c:\program files\MSXML 4.0
2010-06-03 15:14 . 2010-06-03 15:14 -------- d-----w- c:\programdata\Nokia
2010-06-03 14:55 . 2010-06-04 19:10 -------- d-----w- c:\program files\DIFX
2010-06-03 14:55 . 2008-08-26 08:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2010-06-03 14:55 . 2010-06-03 14:55 -------- dc----w- c:\windows\system32\DRVSTORE
2010-06-03 14:54 . 2010-06-03 14:54 -------- d-----w- c:\program files\PC Connectivity Solution
2010-06-03 14:50 . 2010-06-03 14:49 35798536 ----a-w- c:\programdata\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\NokiaSoftwareUpdaterSetup_cs.exe
2010-06-03 14:50 . 2010-06-03 14:50 3351812 ----a-w- c:\programdata\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\Installer\CommonCustomActions\msxml6Exec.exe
2010-06-03 14:50 . 2010-06-03 14:50 36864 ----a-w- c:\programdata\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\Installer\CommonCustomActions\Sleep.exe
2010-06-03 14:50 . 2010-06-03 14:50 3203453 ----a-w- c:\programdata\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\Installer\CommonCustomActions\vcredistExec.exe
2010-06-03 14:50 . 2010-06-04 19:07 -------- d-----w- c:\programdata\Installations
2010-06-03 14:39 . 2010-06-03 14:39 -------- d-----w- c:\users\ToRTeEn\AppData\Roaming\Datalayer
2010-06-03 14:39 . 2010-06-03 15:34 -------- d-----w- c:\users\ToRTeEn\Phone Browser
2010-05-29 18:01 . 2010-05-29 18:10 -------- d-----w- c:\users\ToRTeEn\AppData\Roaming\Notepad++
2010-05-29 18:01 . 2010-05-29 18:01 -------- d-----w- c:\program files\Notepad++
2010-05-28 14:57 . 2010-05-28 14:57 -------- d-----w- c:\programdata\NVIDIA Corporation
2010-05-28 14:03 . 2010-05-22 01:04 232040 ----a-w- c:\windows\system32\nvcod1920.dll
2010-05-28 08:49 . 2010-05-28 08:49 -------- d-----w- c:\users\ToRTeEn\AppData\Local\Activision
2010-05-28 04:34 . 2010-05-28 04:34 -------- d-----w- c:\users\ToRTeEn\AppData\Local\storage
2010-05-28 04:33 . 2010-05-28 04:33 -------- d-----w- c:\programdata\Ubisoft
2010-05-27 12:56 . 2010-05-27 12:56 -------- d--h--r- c:\users\ToRTeEn\AppData\Roaming\SecuROM
2010-05-26 22:42 . 2010-05-26 22:43 -------- d-----w- c:\program files\Sanny Builder 3
2010-05-26 20:17 . 2010-06-07 05:18 -------- d-----w- c:\users\ToRTeEn\AppData\Roaming\esmska
2010-05-26 20:17 . 2010-05-26 20:17 -------- d--h--w- c:\program files\InstallJammer Registry
2010-05-26 20:16 . 2010-05-26 20:16 -------- d-----w- c:\program files\Esmska
2010-05-26 18:45 . 2010-05-26 18:45 -------- d-----w- c:\programdata\IObit
2010-05-26 15:33 . 2010-05-26 15:33 10134 ----a-r- c:\users\ToRTeEn\AppData\Roaming\Microsoft\Installer\{89661B04-C646-4412-B6D3-5E19F02F1F37}\ARPPRODUCTICON.exe
2010-05-26 15:23 . 2010-06-20 10:14 107888 ----a-w- c:\windows\system32\CmdLineExt.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-25 14:25 . 2010-05-04 18:03 -------- d-----w- c:\programdata\NVIDIA
2010-06-25 10:59 . 2010-05-04 19:18 -------- d-----w- c:\users\ToRTeEn\AppData\Roaming\Skype
2010-06-25 10:31 . 2010-05-07 16:00 -------- d-----w- c:\program files\CCleaner
2010-06-25 09:21 . 2010-05-04 19:19 -------- d-----w- c:\users\ToRTeEn\AppData\Roaming\skypePM
2010-06-23 11:23 . 2009-07-14 08:44 631054 ----a-w- c:\windows\system32\perfh005.dat
2010-06-23 11:23 . 2009-07-14 08:44 121708 ----a-w- c:\windows\system32\perfc005.dat
2010-06-23 11:21 . 2010-05-05 12:36 -------- d-----w- c:\program files\Microsoft.NET
2010-06-20 10:03 . 2010-05-04 22:44 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-17 22:04 . 2010-05-04 18:14 88752 ----a-w- c:\users\ToRTeEn\AppData\Local\GDIPFONTCACHEV1.DAT
2010-06-17 14:42 . 2009-07-14 04:52 -------- d-----w- c:\program files\Microsoft Games
2010-06-16 15:36 . 2010-06-16 15:36 49152 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\Components\nprpffbrowserrecordext.dll
2010-06-16 15:36 . 2010-06-16 15:36 45056 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimwmp.dll
2010-06-16 15:36 . 2010-06-16 15:36 45056 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimswf.dll
2010-06-16 15:36 . 2010-06-16 15:36 45056 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimrp.dll
2010-06-16 15:36 . 2010-06-16 15:36 45056 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimqt.dll
2010-06-16 15:36 . 2010-06-16 15:36 40960 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
2010-06-16 15:36 . 2010-06-16 15:36 341600 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
2010-06-16 15:36 . 2010-06-16 15:36 308808 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Common\rpmainbrowserrecordplugin.dll
2010-06-16 15:36 . 2010-06-16 15:36 14848 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
2010-06-16 15:36 . 2010-06-16 15:36 -------- d-----w- c:\program files\Common Files\xing shared
2010-06-16 15:35 . 2010-04-01 11:53 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-06-16 15:35 . 2010-04-01 11:53 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-06-15 22:29 . 2010-05-04 20:15 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-06-15 22:15 . 2010-05-04 17:59 -------- d-----w- c:\program files\NVIDIA Corporation
2010-06-10 15:11 . 2010-05-11 12:41 -------- d-----w- c:\users\ToRTeEn\AppData\Roaming\Nokia
2010-06-09 10:03 . 2010-05-05 12:31 -------- d-----w- c:\programdata\Microsoft Help
2010-06-07 23:57 . 2010-06-15 22:12 10920 ----a-w- c:\windows\system32\drivers\nvBridge.kmd
2010-06-07 23:57 . 2010-04-03 20:55 4967528 ----a-w- c:\windows\system32\nvwgf2um.dll
2010-06-07 23:57 . 2010-04-03 20:55 1592424 ----a-w- c:\windows\system32\nvapi.dll
2010-06-04 19:38 . 2010-05-11 12:25 -------- d-----w- c:\program files\Common Files\Nokia
2010-06-04 19:18 . 2010-05-11 12:24 -------- d-----w- c:\users\ToRTeEn\AppData\Roaming\PC Suite
2010-06-04 19:18 . 2010-06-04 19:18 0 ---ha-w- c:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_07_00.Wdf
2010-06-04 18:00 . 2010-05-04 22:10 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-04 12:19 . 2010-05-11 12:22 -------- d-----w- c:\programdata\Downloaded Installations
2010-06-03 15:15 . 2010-06-03 15:15 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01009.Wdf
2010-05-28 08:08 . 2010-05-04 19:08 -------- d-----r- c:\program files\Skype
2010-05-27 21:24 . 2010-05-14 11:32 -------- d-----w- c:\users\ToRTeEn\AppData\Roaming\uTorrent
2010-05-27 19:31 . 2010-05-10 12:00 -------- d-----w- c:\users\ToRTeEn\AppData\Roaming\IObit
2010-05-26 17:05 . 2010-05-10 12:00 -------- d-----w- c:\program files\IObit
2010-05-23 17:45 . 2010-05-23 17:45 59392 ----a-w- c:\programdata\Skype\Plugins\Plugins\B5403225562D4A258B9F2E4C83852D9F\smpeg.dll
2010-05-23 17:45 . 2010-05-23 17:45 454144 ----a-w- c:\programdata\Skype\Plugins\Plugins\B5403225562D4A258B9F2E4C83852D9F\sndDll.dll
2010-05-23 17:45 . 2010-05-23 17:45 779776 ----a-w- c:\programdata\Skype\Plugins\Plugins\B5403225562D4A258B9F2E4C83852D9F\CallPlayer.dll
2010-05-23 17:45 . 2010-05-23 17:45 103936 ----a-w- c:\programdata\Skype\Plugins\Plugins\B5403225562D4A258B9F2E4C83852D9F\SDL.dll
2010-05-21 12:14 . 2010-05-04 17:46 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-18 20:33 . 2010-05-18 20:33 -------- d-----w- c:\users\ToRTeEn\AppData\Roaming\Artisteer
2010-05-18 20:20 . 2010-05-18 20:20 -------- d-----w- c:\program files\Artisteer 2
2010-05-17 17:32 . 2010-05-06 21:28 -------- d-----w- c:\users\ToRTeEn\AppData\Roaming\HLSW
2010-05-15 22:53 . 2010-05-15 22:37 -------- d-----w- c:\users\ToRTeEn\AppData\Roaming\Azureus
2010-05-15 22:45 . 2010-05-15 22:45 6123008 ----a-w- c:\users\ToRTeEn\AppData\Roaming\Azureus\plugins\azemp\vuzeplayer.exe
2010-05-15 22:37 . 2010-05-15 22:37 -------- d-----w- c:\programdata\Azureus
2010-05-15 17:24 . 2010-05-15 17:24 -------- d-----w- c:\program files\Ashkon Technology
2010-05-14 20:41 . 2010-05-14 20:41 -------- d-----w- c:\program files\Common Files\Java
2010-05-14 20:41 . 2010-05-05 20:04 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-05-14 20:40 . 2010-05-14 20:40 -------- d-----w- c:\program files\Java
2010-05-13 20:37 . 2010-05-13 20:37 -------- d-----w- c:\programdata\ALM
2010-05-13 20:31 . 2010-05-04 20:55 -------- d-----w- c:\program files\Common Files\Adobe
2010-05-13 19:42 . 2010-05-13 19:42 10134 ----a-r- c:\users\ToRTeEn\AppData\Roaming\Microsoft\Installer\{024521CF-C07E-4F8E-8481-0D75695E03AF}\ARPPRODUCTICON.exe
2010-05-13 19:42 . 2010-05-13 19:42 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2010-05-12 17:23 . 2010-05-12 17:23 -------- d-----w- c:\program files\CPUID
2010-05-12 08:07 . 2009-07-14 02:37 -------- d-----w- c:\program files\Windows Mail
2010-05-11 12:40 . 2010-05-11 12:40 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2010-05-10 14:21 . 2010-05-09 22:05 -------- d-----w- c:\program files\Steam
2010-05-09 22:21 . 2010-05-09 22:06 -------- d-----w- c:\program files\Common Files\Steam
2010-05-09 21:36 . 2010-05-09 21:14 -------- d-----w- c:\program files\Ashampoo
2010-05-09 21:35 . 2010-05-09 21:17 -------- d-----w- c:\users\ToRTeEn\AppData\Roaming\Ashampoo
2010-05-09 21:15 . 2010-05-09 21:15 -------- d-----w- c:\programdata\ashampoo
2010-05-09 15:24 . 2010-05-09 15:24 3584 ----a-r- c:\users\ToRTeEn\AppData\Roaming\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe
2010-05-09 15:24 . 2010-05-09 15:24 -------- d-----w- c:\program files\Windows Installer Clean Up
2010-05-09 15:23 . 2010-05-09 15:23 -------- d-----w- c:\program files\MSECACHE
2010-05-09 02:15 . 2010-05-08 00:37 -------- d-----w- c:\programdata\regid.1986-12.com.adobe
2010-05-08 18:56 . 2010-05-08 18:56 -------- d-----w- c:\users\ToRTeEn\AppData\Roaming\Adobe Mini Bridge CS5
2010-05-08 18:56 . 2010-05-08 18:56 -------- d-----w- c:\users\ToRTeEn\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2010-05-08 01:19 . 2010-05-08 01:19 -------- d-----w- c:\program files\ESET
2010-05-07 23:31 . 2010-05-07 23:31 -------- d-----w- c:\program files\Adobe Media Player
2010-05-07 23:24 . 2010-05-07 23:24 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-05-07 23:23 . 2010-05-07 23:24 38784 ----a-w- c:\users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-05-07 22:30 . 2010-05-07 22:27 -------- d-----w- c:\program files\The KMPlayer
2010-05-07 15:11 . 2010-05-07 14:20 -------- d-----w- c:\users\ToRTeEn\AppData\Roaming\DAEMON Tools Lite
2010-05-07 14:22 . 2010-05-07 14:20 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-05-07 14:21 . 2010-05-07 14:21 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-05-07 14:20 . 2010-05-07 14:20 -------- d-----w- c:\programdata\DAEMON Tools Lite
2010-05-06 21:28 . 2010-05-06 21:28 -------- d-s---w- c:\program files\HLSW
2010-05-06 18:03 . 2010-05-06 17:58 -------- d-----w- c:\users\ToRTeEn\AppData\Roaming\GHISLER
2010-05-05 19:48 . 2010-05-05 19:48 -------- d-----w- c:\users\ToRTeEn\AppData\Roaming\FlashGet
2010-05-05 19:29 . 2010-05-05 12:37 -------- d-----w- c:\program files\Microsoft Works
2010-05-04 22:44 . 2010-05-04 21:58 -------- d-----w- c:\program files\Common Files\InstallShield
2010-05-04 22:19 . 2010-05-04 22:19 -------- d-----w- c:\program files\Microsoft Fix it Center
2010-05-04 21:40 . 2009-07-14 04:52 -------- d-----w- c:\program files\Windows Sidebar
2010-05-04 21:40 . 2009-07-14 04:52 -------- d-----w- c:\program files\Windows Photo Viewer
2010-05-04 21:40 . 2009-07-14 04:52 -------- d-----w- c:\program files\DVD Maker
2010-05-04 21:40 . 2009-07-14 09:21 -------- d-----w- c:\program files\Windows Journal
2010-05-04 21:40 . 2009-07-14 04:52 -------- d-----w- c:\program files\Windows Defender
2010-05-04 21:39 . 2010-05-04 21:40 31548 ----a-w- c:\windows\inf\PERFLIB\0409\perfd.dat
2010-05-04 21:39 . 2010-05-04 21:40 31548 ----a-w- c:\windows\inf\PERFLIB\0409\perfc.dat
2010-05-04 21:39 . 2010-05-04 21:40 291294 ----a-w- c:\windows\inf\PERFLIB\0409\perfi.dat
2010-05-04 21:39 . 2010-05-04 21:40 291294 ----a-w- c:\windows\inf\PERFLIB\0409\perfh.dat
2010-05-04 20:41 . 2010-05-04 20:29 -------- d-----w- c:\program files\vReveal
2010-05-04 20:31 . 2010-05-04 20:31 -------- d-----w- c:\users\ToRTeEn\AppData\Roaming\MotionDSP
2010-05-04 20:15 . 2010-05-04 20:15 -------- d-----w- c:\program files\ZOTAC FireStorm
2010-05-04 19:24 . 2010-05-04 19:24 -------- d-----w- c:\program files\Opera
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-05-13 26192168]
"ICQ"="c:\program files\ICQ7.2\ICQ.exe" [2010-06-08 133368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2010-04-07 2145000]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2010-03-06 01:44 500208 ------w- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
2010-02-22 02:57 406992 ----a-w- c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2009-11-11 08:57 1451520 ----a-w- c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2010-05-09 22:06 1238352 ----a-w- c:\program files\Steam\steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
2010-02-19 11:37 517096 ----a-w- c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-05-07 691696]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 DrvAgent32;DrvAgent32;c:\windows\system32\Drivers\DrvAgent32.sys [2010-06-25 23456]
R3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\Microsoft Fix it Center\Matsvc.exe [2010-04-10 266544]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2010-04-29 38224]
R3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2010-02-26 137344]
R3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2010-02-26 8320]
R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-19 1343400]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-04-07 114984]
S2 cpuz133;cpuz133;c:\windows\system32\drivers\cpuz133_x32.sys [2010-03-30 20968]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-04-07 133512]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2010-04-07 810120]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2010-04-07 41312]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-06-07 240232]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2010-01-28 68200]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2010-03-04 277536]

.
Obsah adresáře 'Naplánované úlohy'

2010-06-25 c:\windows\Tasks\AWC Startup.job
- c:\program files\IObit\Advanced SystemCare 3\AWC.exe [2010-05-10 11:14]

2010-06-25 c:\windows\Tasks\AWC Update.job
- c:\program files\IObit\Advanced SystemCare 3\IObitUpdate.exe [2010-05-10 15:20]

2010-06-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3595803208-3766525656-3816774015-1000Core.job
- c:\users\ToRTeEn\AppData\Local\Google\Update\GoogleUpdate.exe [2010-05-04 18:32]

2010-06-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3595803208-3766525656-3816774015-1000UA.job
- c:\users\ToRTeEn\AppData\Local\Google\Update\GoogleUpdate.exe [2010-05-04 18:32]

2010-06-13 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2010-05-26 14:48]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://start.icq.com/skins7/
IE: Download all by FlashGet3 - c:\users\ToRTeEn\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
IE: Download by FlashGet3 - c:\users\ToRTeEn\AppData\Roaming\FlashGetBHO\GetUrl.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: Stahnou vse FlashGet3 - c:\users\ToRTeEn\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
IE: Stahnout FlashGet3 - c:\users\ToRTeEn\AppData\Roaming\FlashGetBHO\GetUrl.htm
IE: {{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - c:\program files\ICQ7.2\ICQ.exe
Trusted Zone: kuaiche.com\software
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
MSConfigStartUp-FlashGet 3 - c:\program files\FlashGet Network\FlashGet 3\Flashget3.exe
MSConfigStartUp-PCSuiteTrayApplication - c:\progra~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
MSConfigStartUp-PcSync - c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe
AddRemove-FlashGet 3.3 - c:\program files\FlashGet Network\FlashGet 3\uninst.exe


.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-3595803208-3766525656-3816774015-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2010-06-25 16:48:36
ComboFix-quarantined-files.txt 2010-06-25 14:48

Před spuštěním: Volných bajtů: 11 553 992 704
Po spuštění: Volných bajtů: 11 557 355 520

- - End Of File - - D3C6C44504CE5F12D59BD954107D4277

Avatar uživatele
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 Říj 2008 08:02

Re: Pravděpodobně trojan - prosím o kontrolu logu

#5 Příspěvek od motji »

Jak to teď vypadá s počítačem? Mbam ten soubor ještě hlásí?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Thooty
Návštěvník
Návštěvník
Příspěvky: 95
Registrován: 08 Dub 2010 14:51

Re: Pravděpodobně trojan - prosím o kontrolu logu

#6 Příspěvek od Thooty »

MBAM infekci už nehlásí, takže mockrát děkuji:)

Avatar uživatele
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 Říj 2008 08:02

Re: Pravděpodobně trojan - prosím o kontrolu logu

#7 Příspěvek od motji »

:arrow: Odinstalujte combofix přes Start - Spustit
- zkopírujte do okénka:

ComboFix /Uninstall

-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.


***********


:arrow: Stáhněte T-Cleaner
http://sweb.cz/Marinus/T-Cleaner.exe

-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir



***********


:arrow: Z mého podpisu stahněte Ccleaner
- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru

Obrázekzáložka čistič
- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner

Obrázekzáložka Registry
- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy :arrow: ok :arrow: zavřít

Obrázek Záložka Nástroje
- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.

Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.


***********



:arrow: Stahněte OTC a použijte
http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech



***********

:arrow: Vložte nový log ze RSIT a řekněte co počítač, jak se chová, už je vše v pořádku?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Odpovědět