Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Vírusy - trójske kone + log z RSIT

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Lukas666
Návštěvník
Návštěvník
Příspěvky: 89
Registrován: 02 lis 2009 17:19

Vírusy - trójske kone + log z RSIT

#1 Příspěvek od Lukas666 »

Aj keď ste mi v mojom poslednom logu zpred 2 dní žiaden vírus nenašli (v inej téme), v PC vírus určite mám, pretože po stlačení ctrl+alt+del mi vyskočilo chybové okno: Správca systému vypol Správcu úloh. A za pomoci strýčka Google sa mi podarilo nájsť, že je to výsledok trójskeho vírusu (podľa nejakého návodu na som to už opravil, ale vírus som tým určite nevymazal). A aj keď som predtým došiel na ten moj zavírovaný web, tak mi ESET zahlásil, že na webe je Trojan.

Cez noc som spravil ESET analýzu a našiel mi na C: 10 infiltrovaných súborov (ktoré zrejme neboli trójske kone, lebo som ich jednoducho odstránil) a na D: 3 trójske kone, pričom jeden z nich je vyliečený a uložený do karantény, no s ďalšími dvoma program nespravil nič.

Pripájam najnovší log + vypísané miesta, kde mi ESET našiel vírusy:
D:\Hry\Ubisoft\Tom Clancy's Splinter Cell Conviction\src\system\ubiorbitapi_r2.dll - variant infiltrácie Win32/Packed.VMProtect.AAA trójsky kôň - vyliečený zmazaním - uložený do karantény [1]
D:\hry-instalacky\Assassins.Creed.II.Crack&Update-SKIDROW\Update+Crack-ASSII.rar » RAR » SKIDROW\ubiorbitapi_r2.dll - variant infiltrácie Win32/Packed.VMProtect.AAA trójsky kôň
D:\hry-instalacky\Need For Speed Carbon\rzr-nfsc.iso » ISO » Keygen.exe - pravdepodobne variant infiltrácie Win32/Agent trójsky kôň
Ešte sa chcem spýtať. Súbory, kde mi našiel ESET vírusy mám v PC už dlkhšie, možno aj pol roka, no PC mi začal blbnúť až teraz. Šarapatia mi v PC teda tieto staré víry, alebo je možné, že sú tu ešte ďalšie, ktoré mi ESET nenašiel?
Logfile of random's system information tool 1.08 (written by random/random)
Run by xp user at 2010-07-23 05:52:53
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 12 GB (21%) free of 60 GB
Total RAM: 3327 MB (83% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:52:58, on 23.7.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18372)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\ASUS\AsSysCtrlService\1.00.00\AsSysCtrlService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\ASUS.SYS\config\DVMExportService.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\ICQ6Toolbar\ICQ Service.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\xp user\Desktop\RSIT.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\trend micro\xp user.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://update.microsoft.com/microsoftupdate
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - D:\Programy\Free Download Manager\iefdm2.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [SNPSTD2] C:\WINDOWS\vsnpstd2.exe
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\xRaidSetup.exe boot
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O4 - HKLM\..\Run: [THGuard] "D:\Programy\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: srvklw32.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Download all with Free Download Manager - file://D:\Programy\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://D:\Programy\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://D:\Programy\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://D:\Programy\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.cyber-deployment.com
O15 - Trusted Zone: http://*.download-soft-package.com
O15 - Trusted Zone: http://*.download-software-package.com
O15 - Trusted Zone: http://*.get-key-se10.com
O15 - Trusted Zone: http://*.is-software-download.com
O15 - Trusted Zone: http://*.cyber-deployment.com (HKLM)
O15 - Trusted Zone: http://*.get-key-se10.com (HKLM)
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://icq.oberon-media.com/Gameshell/G ... meHost.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASUS System Control Service (AsSysCtrlService) - Unknown owner - C:\Program Files\ASUS\AsSysCtrlService\1.00.00\AsSysCtrlService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: C-DillaSrv (byu3loetzryi) - Unknown owner - C:\WINDOWS\system32\woobe.exe (file missing)
O23 - Service: DeviceVM Meta Data Export Service (DvmMDES) - DeviceVM - C:\ASUS.SYS\config\DVMExportService.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe

--
End of file - 8335 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}]
FDMIECookiesBHO Class - D:\Programy\Free Download Manager\iefdm2.dll [2008-12-30 98304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E5A1691B-D188-4419-AD02-90002030B8EE}]
FlashFXP Helper for Internet Explorer - C:\PROGRA~1\FlashFXP\IEFlash.dll [2008-06-16 191096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2008-06-12 958712]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2010-01-11 13666408]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2009-03-19 2029640]
"SNPSTD2"=C:\WINDOWS\vsnpstd2.exe [2004-06-10 286720]
"JMB36X IDE Setup"=C:\WINDOWS\RaidTool\xInsIDE.exe [2007-03-20 36864]
"36X Raid Configurer"=C:\WINDOWS\system32\xRaidSetup.exe [2007-11-19 1970176]
"MSConfig"=C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE [2008-04-14 169984]
"THGuard"=D:\Programy\TrojanHunter 4.2\THGuard.exe [2005-02-19 1089024]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2007-10-10 39792]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe [2009-08-31 2356088]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
D:\Programy\Ares\Ares.exe [2008-11-26 881664]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Update Checker]
C:\Program Files\ASUS\ASUSUpdate\UpdateChecker\UpdateChecker.exe [2008-12-11 114688]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cpu Level Up help]
C:\Program Files\ASUS\AI Suite\CpuLevelUpHelp.exe [2007-11-30 881152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
D:\Programy\DAEMON Tools Lite\daemon.exe [2009-04-23 691656]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HDAudDeck]
C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe [2009-01-09 33570816]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
D:\Programy\ICQ7.0\ICQ.exe silent loginmode=4 []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
D:\Programy\iTunes\iTunesHelper.exe [2010-06-15 141624]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
C:\WINDOWS\system32\NvCpl.dll [2010-01-11 13666408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
C:\WINDOWS\system32\NvMcTray.dll [2010-01-11 110696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /installquiet []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe [2010-03-18 421888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RGSC]
D:\Hry\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe [2009-09-04 306088]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Six Engine]
C:\Program Files\ASUS\EPU-6 Engine\SixEngine.exe [2009-02-10 5993984]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe [2010-03-09 26100520]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Turbo Key]
C:\Program Files\ASUS\Turbo Key\TurboKey.exe [2009-02-17 1753600]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TurboV]
C:\Program Files\ASUS\TurboV\TurboV.exe [2009-02-05 5384192]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xp user^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
C:\PROGRA~1\MICROS~2\Office12\ONENOTEM.EXE [2009-02-26 97680]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"FLEXnet Licensing Service"=3

C:\Documents and Settings\xp user\Start Menu\Programs\Startup
srvklw32.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 190464]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLUA"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDriveAutoRun"=67108863
"NoDrives"=0
"NoSetActiveDesktop"=1
"NoActiveDesktopChanges"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
"NoSetActiveDesktop"=1
"NoActiveDesktopChanges"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"D:\Hry\Gears of War\Binaries\WarGame-G4WLive.exe"="D:\Hry\Gears of War\Binaries\WarGame-G4WLive.exe:*:Enabled:Gears of War"
"D:\Hry\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe"="D:\Hry\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe:*:Enabled:Rockstar Games Social Club"
"D:\Hry\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe"="D:\Hry\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe:*:Enabled:Grand Theft Auto IV"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"D:\Hry\S.T.A.L.K.E.R. - Clear Sky\bin\xrEngine.exe"="D:\Hry\S.T.A.L.K.E.R. - Clear Sky\bin\xrEngine.exe:*:Enabled:S.T.A.L.K.E.R. - Clear Sky (CLI)"
"D:\Hry\S.T.A.L.K.E.R. - Clear Sky\bin\dedicated\xrEngine.exe"="D:\Hry\S.T.A.L.K.E.R. - Clear Sky\bin\dedicated\xrEngine.exe:*:Enabled:S.T.A.L.K.E.R. - Clear Sky (SRV)"
"C:\Program Files\FlashFXP\FlashFXP.exe"="C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"D:\Hry\Steam\Steam.exe"="D:\Hry\Steam\Steam.exe:*:Enabled:Steam"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"D:\Programy\ICQ7.0\ICQ.exe"="D:\Programy\ICQ7.0\ICQ.exe:*:Enabled:ICQ7"
"D:\Programy\ICQ7.0\aolload.exe"="D:\Programy\ICQ7.0\aolload.exe:*:Enabled:aolload.exe"
"D:\Hry\Battlefield Bad Company 2\BFBC2Updater.exe"="D:\Hry\Battlefield Bad Company 2\BFBC2Updater.exe:*:Enabled:Battlefield: Bad Company™ 2"
"D:\Hry\Grand Theft Auto IV - Episodes From Liberty City\EFLC.exe"="D:\Hry\Grand Theft Auto IV - Episodes From Liberty City\EFLC.exe:*:Enabled:Grand Theft Auto IV - Episodes From Liberty City"
"C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe"="C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe:*:Enabled:Ubisoft Game Launcher"
"D:\Hry\Ubisoft\Tom Clancy's Splinter Cell Conviction\src\system\conviction_game.exe"="D:\Hry\Ubisoft\Tom Clancy's Splinter Cell Conviction\src\system\conviction_game.exe:*:Enabled:Tom Clancy's Splinter Cell Conviction"
"D:\Hry\Ubisoft\Tom Clancy's Splinter Cell Conviction\src\system\gu.exe"="D:\Hry\Ubisoft\Tom Clancy's Splinter Cell Conviction\src\system\gu.exe:*:Enabled:Tom Clancy's Splinter Cell Conviction Update"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"D:\Programy\iTunes\iTunes.exe"="D:\Programy\iTunes\iTunes.exe:*:Enabled:iTunes"
"D:\Hry\Singularity(TM)\Binaries\Singularity.exe"="D:\Hry\Singularity(TM)\Binaries\Singularity.exe:*:Enabled:Singularity"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"D:\Hry\ArmA 2 Operation Arrowhead DEMO\ArmA2OA_Demo.exe"="D:\Hry\ArmA 2 Operation Arrowhead DEMO\ArmA2OA_Demo.exe:*:Enabled:ArmA 2 Operation Arrowhead DEMO"
"C:\WINDOWS\system32\nekaquu.exe"="C:\WINDOWS\system32\nekaquu.exe:*:Enabled:nobyv32"
"C:\WINDOWS\system32\lufufommou.exe"="C:\WINDOWS\system32\lufufommou.exe:*:Enabled:nobyv32"
"C:\WINDOWS\system32\hykylofouw.exe"="C:\WINDOWS\system32\hykylofouw.exe:*:Enabled:nobyv32"
"C:\WINDOWS\system32\cotowobij.exe"="C:\WINDOWS\system32\cotowobij.exe:*:Enabled:nobyv32"
"D:\Hry\Steam\steamapps\deadnight_warrior_sk\counter-strike\hl.exe"="D:\Hry\Steam\steamapps\deadnight_warrior_sk\counter-strike\hl.exe:*:Enabled:Counter-Strike"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\FlashFXP\FlashFXP.exe"="C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3"
"D:\Programy\ICQ7.0\ICQ.exe"="D:\Programy\ICQ7.0\ICQ.exe:*:Enabled:ICQ7"
"D:\Programy\ICQ7.0\aolload.exe"="D:\Programy\ICQ7.0\aolload.exe:*:Enabled:aolload.exe"

======List of files/folders created in the last 1 months======

2010-07-22 21:39:35 ----HD---- C:\WINDOWS\system32\GroupPolicy
2010-07-21 19:12:29 ----A---- C:\WINDOWS\system32\drivers\bjlxa.sys
2010-07-16 09:47:48 ----D---- C:\WINDOWS\E10DB5DAE57640EAA7FC1CB2A7B283A6.TMP
2010-07-15 20:07:28 ----D---- C:\Downloads
2010-07-15 00:04:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$
2010-07-11 13:02:09 ----D---- C:\Program Files\iPod
2010-07-11 13:02:02 ----D---- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-07-11 12:58:43 ----D---- C:\Program Files\QuickTime
2010-07-11 12:52:37 ----D---- C:\Program Files\Safari

======List of files/folders modified in the last 1 months======

2010-07-23 05:52:56 ----D---- C:\Program Files\trend micro
2010-07-23 05:52:24 ----D---- C:\WINDOWS\temp
2010-07-23 05:10:35 ----A---- C:\ntservicelogOutlook.txt
2010-07-22 23:04:58 ----D---- C:\WINDOWS\system32
2010-07-22 22:21:22 ----D---- C:\WINDOWS\Prefetch
2010-07-22 21:54:59 ----R---- C:\WINDOWS\streamhlp.dll
2010-07-22 21:54:57 ----D---- C:\WINDOWS
2010-07-22 21:08:08 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-07-22 21:07:19 ----D---- C:\WINDOWS\system32\CatRoot2
2010-07-22 21:05:11 ----RASH---- C:\boot.ini
2010-07-22 21:05:11 ----A---- C:\WINDOWS\win.ini
2010-07-22 21:05:11 ----A---- C:\WINDOWS\system.ini
2010-07-22 21:02:47 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-07-22 20:27:10 ----D---- C:\Program Files\Mozilla Firefox
2010-07-21 22:02:09 ----D---- C:\Documents and Settings\xp user\Application Data\FileZilla
2010-07-21 20:48:50 ----A---- C:\WINDOWS\MBR.exe
2010-07-21 19:12:34 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-07-21 19:12:31 ----D---- C:\WINDOWS\system32\drivers
2010-07-21 11:23:08 ----D---- C:\WINDOWS\system32\DirectX
2010-07-21 11:23:07 ----HD---- C:\WINDOWS\inf
2010-07-21 11:22:47 ----RSD---- C:\WINDOWS\assembly
2010-07-20 21:51:04 ----D---- C:\Documents and Settings\xp user\Application Data\Skype
2010-07-20 19:58:01 ----D---- C:\Documents and Settings\xp user\Application Data\skypePM
2010-07-16 09:47:53 ----SHD---- C:\WINDOWS\Installer
2010-07-16 09:47:53 ----D---- C:\Config.Msi
2010-07-16 09:47:52 ----D---- C:\WINDOWS\WinSxS
2010-07-16 09:47:45 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-07-16 09:43:52 ----HD---- C:\Program Files\InstallShield Installation Information
2010-07-15 21:29:30 ----D---- C:\WINDOWS\pss
2010-07-15 21:15:00 ----D---- C:\Documents and Settings\xp user\Application Data\Free Download Manager
2010-07-15 20:02:07 ----D---- C:\Documents and Settings\xp user\Application Data\DC++
2010-07-15 00:04:49 ----HD---- C:\WINDOWS\$hf_mig$
2010-07-15 00:03:39 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2010-07-11 13:49:53 ----D---- C:\Documents and Settings\xp user\Application Data\Apple Computer
2010-07-11 13:02:09 ----RD---- C:\Program Files
2010-07-11 13:02:05 ----D---- C:\Program Files\Common Files\Apple
2010-07-11 12:56:38 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-07-11 12:56:19 ----D---- C:\Program Files\Bonjour
2010-07-03 19:10:48 ----A---- C:\WINDOWS\NeroDigital.ini
2010-07-02 21:39:05 ----A---- C:\WINDOWS\system32\MRT.exe
2010-07-02 16:32:34 ----D---- C:\Program Files\Opera

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 JRAID;JRAID; C:\WINDOWS\system32\DRIVERS\jraid.sys [2008-11-21 82784]
R0 ohci1394;VIA OHCI Compliant IEEE 1394 Host Controller; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-14 61696]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2007-03-08 43528]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2008-08-28 721904]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 AsIO;AsIO; C:\WINDOWS\system32\drivers\AsIO.sys [2007-12-17 12400]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-03-19 107256]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2009-03-19 55768]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 36352]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2009-11-01 279712]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2009-03-19 113960]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2009-03-19 131976]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2009-11-01 25888]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2009-06-09 60800]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2009-03-19 33096]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2008-08-28 25280]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller; C:\WINDOWS\system32\DRIVERS\l1e51x86.sys [2008-09-23 38400]
R3 monfilt;monfilt; C:\WINDOWS\system32\drivers\monfilt.sys [2008-02-14 1389056]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2009-06-09 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2010-01-12 10276768]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2008-04-13 20992]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\WINDOWS\system32\drivers\viahduaa.sys [2008-12-19 993280]
S3 agxxl33z;agxxl33z; C:\WINDOWS\system32\drivers\agxxl33z.sys []
S3 catchme;catchme; \??\C:\DOCUME~1\XPUSER~1\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 GMSIPCI;GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 PnkBstrK;PnkBstrK; \??\C:\WINDOWS\system32\drivers\PnkBstrK.sys []
S3 s115bus;Sony Ericsson Device 115 driver (WDM); C:\WINDOWS\system32\DRIVERS\s115bus.sys [2007-04-23 83208]
S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s115mdfl.sys [2007-04-23 15112]
S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s115mdm.sys [2007-04-23 108680]
S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s115mgmt.sys [2007-04-23 100488]
S3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s115obex.sys [2007-04-23 98568]
S3 s117bus;Sony Ericsson Device 117 driver (WDM); C:\WINDOWS\system32\DRIVERS\s117bus.sys [2007-06-25 82984]
S3 s716bus;Sony Ericsson Device 716 driver (WDM); C:\WINDOWS\system32\DRIVERS\s716bus.sys [2007-04-04 83208]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 snpstd2;VideoCAM Look; C:\WINDOWS\system32\DRIVERS\snpstd2.sys [2004-07-28 334080]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2010-04-19 41984]
S3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 mchInjDrv;mchInjDrv; \??\C:\DOCUME~1\XPUSER~1\LOCALS~1\Temp\mc2DDE7.tmp []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2010-06-10 144176]
R2 AsSysCtrlService;ASUS System Control Service; C:\Program Files\ASUS\AsSysCtrlService\1.00.00\AsSysCtrlService.exe [2008-08-15 86016]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2010-05-18 345376]
R2 DvmMDES;DeviceVM Meta Data Export Service; C:\ASUS.SYS\config\DVMExportService.exe [2008-11-26 323584]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-03-19 731840]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2008-06-10 222456]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2010-01-11 154216]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2010-02-03 75064]
R2 PnkBstrB;PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [2010-05-15 214808]
R2 PSI_SVC_2;Protexis Licensing V2; C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2007-07-24 185632]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 byu3loetzryi;C-DillaSrv; C:\WINDOWS\system32\woobe.exe []
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2009-03-19 20680]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-08-23 136120]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2010-06-15 540472]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-04-13 792112]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-05-16 271920]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-08-29 654848]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15663
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Vírusy - trójske kone + log z RSIT

#2 Příspěvek od JaRon »

Presun ComboFix
na plochu (ak tam este nie je)

otvor si Poznamkovy blok - notepad

do neho zkopiruj skript z nasledujiceho okna:

Kód: Vybrat vše

Driver::
byu3loetzryi
mchInjDrv


uloz vytvoreny textovy soubor ako CFScript.txt na plochu

po ulozeni uchop vytvoreny skript lavym tlacitkom mysi a presun ho nad ikonu Combofixu, nad nim skript upust:

Obrázek

po aplikacii by mal vzniknut dalsi log, ten vloz sem :)


ak chces aby som to cital dalsie logy nevkladaj do code
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

Lukas666
Návštěvník
Návštěvník
Příspěvky: 89
Registrován: 02 lis 2009 17:19

Re: Vírusy - trójske kone + log z RSIT

#3 Příspěvek od Lukas666 »

Ospravedlňujem sa, nevedel som. Myslel som, že je to prehľadnejšie, keď to oddelím od ostatného textu. Každopádne, tu je log z ComboFixu (musim ho rozdeliť do viacerých správ, pretože sa do jednej správy nevojde):

ComboFix 10-07-22.01 - xp user 23.07.2010 8:45.4.4 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.3327.2915 [GMT 2:00]
Running from: c:\documents and settings\xp user\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\xp user\Desktop\CFScript.txt
AV: ESET Smart Security 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\xp user\Application Data\avdrn.dat
c:\documents and settings\xp user\Start Menu\Programs\Startup\srvklw32.exe
c:\program files\Search Toolbar
c:\program files\Search Toolbar\SearchToolbarUninstall.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_BYU3LOETZRYI
-------\Legacy_MCHINJDRV
-------\Service_byu3loetzryi


((((((((((((((((((((((((( Files Created from 2010-06-23 to 2010-07-23 )))))))))))))))))))))))))))))))
.

2010-07-22 19:39 . 2010-07-22 19:39 -------- d--h--w- c:\windows\system32\GroupPolicy
2010-07-21 17:12 . 2010-07-23 06:57 565280 ----a-w- c:\windows\system32\drivers\bjlxa.sys
2010-07-21 09:40 . 2010-07-21 09:40 -------- d-----w- c:\documents and settings\xp user\Local Settings\Application Data\ArmA 2 OA DEMO
2010-07-21 07:05 . 2010-06-29 22:13 52224 ----a-w- c:\documents and settings\xp user\Application Data\Mozilla\Firefox\Profiles\waf4tiw4.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll
2010-07-21 07:05 . 2010-06-29 22:13 101376 ----a-w- c:\documents and settings\xp user\Application Data\Mozilla\Firefox\Profiles\waf4tiw4.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll
2010-07-16 07:47 . 2010-07-16 07:47 -------- d-----w- c:\windows\E10DB5DAE57640EAA7FC1CB2A7B283A6.TMP
2010-07-15 18:07 . 2010-07-15 19:25 -------- d-----w- C:\Downloads
2010-07-11 11:02 . 2010-07-11 11:02 -------- d-----w- c:\program files\iPod
2010-07-11 11:02 . 2010-07-11 11:02 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-07-11 10:58 . 2010-07-11 10:59 -------- d-----w- c:\program files\QuickTime
2010-07-11 10:54 . 2010-07-11 10:54 72504 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
2010-07-11 10:52 . 2010-07-11 10:52 -------- d-----w- c:\program files\Safari
2010-07-11 10:51 . 2010-07-11 10:51 71992 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.33.16.0\SetupAdmin.exe
2010-06-23 10:19 . 2001-08-17 09:48 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2010-06-23 10:19 . 2001-08-17 09:48 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2010-06-23 10:19 . 2008-04-13 20:15 10368 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2010-06-23 10:19 . 2008-04-13 20:15 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-23 03:52 . 2009-11-02 20:46 -------- d-----w- c:\program files\trend micro
2010-07-22 14:59 . 2010-07-21 17:12 20 ----a-w- c:\documents and settings\NetworkService\Application Data\hwzypv.dat
2010-07-21 20:02 . 2009-08-29 19:10 -------- d-----w- c:\documents and settings\xp user\Application Data\FileZilla
2010-07-20 19:51 . 2009-09-24 05:20 -------- d-----w- c:\documents and settings\xp user\Application Data\Skype
2010-07-20 17:58 . 2009-09-24 06:06 -------- d-----w- c:\documents and settings\xp user\Application Data\skypePM
2010-07-16 07:47 . 2010-01-08 22:23 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-07-16 07:43 . 2008-08-28 09:22 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-07-15 19:15 . 2010-03-16 12:23 -------- d-----w- c:\documents and settings\xp user\Application Data\Free Download Manager
2010-07-15 18:02 . 2009-08-31 12:01 -------- d-----w- c:\documents and settings\xp user\Application Data\DC++
2010-07-14 22:03 . 2008-08-28 10:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-07-11 11:49 . 2010-02-27 11:47 -------- d-----w- c:\documents and settings\xp user\Application Data\Apple Computer
2010-07-11 11:02 . 2010-02-27 11:45 -------- d-----w- c:\program files\Common Files\Apple
2010-07-11 10:56 . 2009-08-29 19:59 -------- d-----w- c:\program files\Bonjour
2010-07-02 14:32 . 2009-08-28 14:19 -------- d-----w- c:\program files\Opera
2010-06-21 15:09 . 2010-06-21 15:09 -------- d-----w- c:\documents and settings\xp user\Application Data\TS3Client
2010-06-19 13:43 . 2010-06-19 13:43 -------- d-----w- c:\program files\FLV Player X
2010-06-14 14:31 . 2008-08-28 09:07 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-12 18:38 . 2010-06-12 18:38 50354 ----a-w- c:\documents and settings\xp user\Application Data\Facebook\uninstall.exe
2010-06-12 18:38 . 2010-06-12 18:38 -------- d-----w- c:\documents and settings\xp user\Application Data\Facebook
2010-06-09 10:45 . 2010-06-09 10:45 5591040 ----a-w- c:\documents and settings\xp user\Application Data\Facebook\npfbplugin_1_0_3.dll
2010-06-05 15:30 . 2010-05-09 17:11 -------- d-----w- c:\documents and settings\xp user\Application Data\Mumble
2010-05-18 14:35 . 2010-05-18 14:35 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 14:35 . 2010-05-18 14:35 197920 ----a-w- c:\windows\system32\dnssdX.dll
2010-05-18 14:35 . 2010-05-18 14:35 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-05-15 08:50 . 2009-08-29 10:35 214808 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-05-15 08:35 . 2009-08-29 10:36 139920 ----a-w- c:\windows\system32\drivers\pnkbstrk.sys
2010-05-02 10:04 . 2009-06-09 19:33 1860352 ----a-w- c:\windows\system32\win32k.sys
.

((((((((((((((((((((((((((((( SnapShot_2010-03-09_22.05.53 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-06 23:19 . 2007-11-06 23:19 46592 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_11f3ea3a\mfc90kor.dll
+ 2007-11-06 23:19 . 2007-11-06 23:19 47104 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_11f3ea3a\mfc90jpn.dll
+ 2007-11-06 23:19 . 2007-11-06 23:19 59392 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_11f3ea3a\mfc90ita.dll
+ 2007-11-06 23:19 . 2007-11-06 23:19 41984 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_11f3ea3a\mfc90cht.dll
+ 2007-11-06 23:19 . 2007-11-06 23:19 41472 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_11f3ea3a\mfc90chs.dll
+ 2007-11-06 23:19 . 2007-11-06 23:19 60416 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_11f3ea3a\mfc90fra.dll
+ 2007-11-06 23:19 . 2007-11-06 23:19 59392 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_11f3ea3a\mfc90esp.dll
+ 2007-11-06 23:19 . 2007-11-06 23:19 59392 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_11f3ea3a\mfc90esn.dll
+ 2007-11-06 23:19 . 2007-11-06 23:19 54272 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_11f3ea3a\mfc90enu.dll
+ 2007-11-06 23:19 . 2007-11-06 23:19 60928 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_11f3ea3a\mfc90deu.dll
+ 2007-11-06 20:51 . 2007-11-06 20:51 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_a173767a\mfcm90u.dll
+ 2007-11-06 20:51 . 2007-11-06 20:51 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_a173767a\mfcm90.dll
+ 2010-04-08 13:18 . 1999-12-17 07:13 86016 c:\windows\unvise32.exe
+ 2009-11-30 16:02 . 2009-11-30 16:02 72840 c:\windows\system32\xliveinstallhost.exe
+ 2010-03-16 22:19 . 2010-02-04 09:01 74072 c:\windows\system32\XAPOFX1_4.dll
+ 2010-03-16 22:19 . 2010-02-04 09:01 22360 c:\windows\system32\X3DAudio1_7.dll
+ 2008-04-14 12:00 . 2010-04-21 13:28 46080 c:\windows\system32\tzchange.exe
- 2008-04-14 12:00 . 2010-01-23 08:11 46080 c:\windows\system32\tzchange.exe
+ 2010-05-12 12:06 . 2009-05-26 11:40 17272 c:\windows\system32\spmsg.dll
+ 2010-03-16 21:44 . 2008-10-07 05:33 81920 c:\windows\system32\ReinstallBackups\0018\DriverFiles\nvwddi.dll
+ 2010-03-16 21:44 . 2008-10-07 05:33 86016 c:\windows\system32\ReinstallBackups\0018\DriverFiles\nvmctray.dll
+ 2010-03-16 21:44 . 2008-10-21 16:00 32768 c:\windows\system32\ReinstallBackups\0018\DriverFiles\Auxiliary.dll
+ 2010-03-30 22:16 . 2010-03-30 22:16 99176 c:\windows\system32\PresentationHostProxy.dll
+ 2008-04-14 12:00 . 2010-07-23 06:54 68156 c:\windows\system32\perfc009.dat
- 2008-04-14 12:00 . 2010-03-09 21:59 68156 c:\windows\system32\perfc009.dat
+ 2010-03-16 21:44 . 2010-01-12 04:03 61440 c:\windows\system32\OpenCL.dll
+ 2010-01-11 21:17 . 2010-01-11 21:17 81920 c:\windows\system32\nvwddi.dll
- 2008-10-07 05:33 . 2008-10-07 05:33 81920 c:\windows\system32\nvwddi.dll
+ 2009-11-06 23:07 . 2009-11-06 23:07 49488 c:\windows\system32\netfxperf.dll
+ 2009-11-06 23:07 . 2009-11-06 23:07 11600 c:\windows\system32\mui\0409\mscorees.dll
+ 2010-07-11 10:56 . 2010-04-19 18:47 41984 c:\windows\system32\DRVSTORE\usbaapl_3822718F9E2E86C3752D30561ECA5A855A4A3F7D\usbaapl.sys
+ 2010-07-11 10:56 . 2010-04-19 18:29 18432 c:\windows\system32\DRVSTORE\netaapl_3A00C5601D92D37DDCB0AE45518D6B42BE1588E6\netaapl.sys
+ 2010-03-11 16:15 . 2008-04-13 21:15 15104 c:\windows\system32\drivers\usbscan.sys
+ 2010-02-27 11:45 . 2010-04-19 18:47 41984 c:\windows\system32\drivers\usbaapl.sys
+ 2007-04-23 11:54 . 2007-04-23 11:54 98568 c:\windows\system32\drivers\s115obex.sys
+ 2007-04-23 12:54 . 2007-04-23 11:54 12424 c:\windows\system32\drivers\s115cmnt.sys
- 2007-04-23 12:54 . 2007-04-23 12:54 12424 c:\windows\system32\drivers\s115cmnt.sys
- 2007-04-23 12:54 . 2007-04-23 12:54 12424 c:\windows\system32\drivers\s115cm.sys
+ 2007-04-23 12:54 . 2007-04-23 11:54 12424 c:\windows\system32\drivers\s115cm.sys
+ 2010-03-11 16:15 . 2008-04-13 21:15 15104 c:\windows\system32\dllcache\usbscan.sys
+ 2008-04-14 12:00 . 2010-01-13 14:01 86016 c:\windows\system32\dllcache\cabview.dll
+ 2008-04-14 12:00 . 2010-03-05 14:37 65536 c:\windows\system32\dllcache\asycfilt.dll
+ 2008-08-28 09:12 . 2010-07-22 14:59 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-08-28 09:12 . 2010-03-09 07:20 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-08-28 09:12 . 2010-07-22 14:59 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-08-28 09:12 . 2010-03-09 07:20 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2010-07-21 17:12 . 2010-07-22 14:59 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2010-03-09 07:20 . 2010-03-09 07:20 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-04-14 12:00 . 2010-01-13 14:01 86016 c:\windows\system32\cabview.dll
+ 2008-04-14 12:00 . 2010-03-05 14:37 65536 c:\windows\system32\asycfilt.dll
+ 2002-12-05 15:51 . 2010-07-22 19:54 59392 c:\windows\streamhlp.dll
- 2008-07-29 17:16 . 2008-07-29 17:16 32768 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll
+ 2010-04-07 21:48 . 2010-04-07 21:48 32768 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll
+ 2009-11-06 23:07 . 2009-11-06 23:07 13648 c:\windows\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll
+ 2010-03-23 03:31 . 2010-03-23 03:31 30544 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
+ 2009-11-06 23:07 . 2009-11-06 23:07 13648 c:\windows\Microsoft.NET\Framework\SharedReg12.dll
+ 2009-11-06 23:07 . 2009-11-06 23:07 13648 c:\windows\Microsoft.NET\Framework\sbscmp20_perfcounter.dll
+ 2009-11-06 23:07 . 2009-11-06 23:07 13648 c:\windows\Microsoft.NET\Framework\sbscmp20_mscorwks.dll
+ 2009-11-06 23:07 . 2009-11-06 23:07 13648 c:\windows\Microsoft.NET\Framework\sbscmp10.dll
+ 2009-11-06 23:07 . 2009-11-06 23:07 13664 c:\windows\Microsoft.NET\Framework\sbs_wminet_utils.dll
+ 2009-11-06 23:07 . 2009-11-06 23:07 13688 c:\windows\Microsoft.NET\Framework\sbs_system.enterpriseservices.dll
+ 2009-11-06 23:07 . 2009-11-06 23:07 13664 c:\windows\Microsoft.NET\Framework\sbs_system.data.dll
+ 2009-11-06 23:07 . 2009-11-06 23:07 13696 c:\windows\Microsoft.NET\Framework\sbs_system.configuration.install.dll
+ 2009-11-06 23:07 . 2009-11-06 23:07 13656 c:\windows\Microsoft.NET\Framework\sbs_mscorsec.dll
+ 2009-11-06 23:07 . 2009-11-06 23:07 13656 c:\windows\Microsoft.NET\Framework\sbs_mscorrc.dll
+ 2009-11-06 23:07 . 2009-11-06 23:07 13656 c:\windows\Microsoft.NET\Framework\sbs_mscordbi.dll
+ 2009-11-06 23:07 . 2009-11-06 23:07 13672 c:\windows\Microsoft.NET\Framework\sbs_microsoft.jscript.dll
+ 2009-11-06 23:07 . 2009-11-06 23:07 13664 c:\windows\Microsoft.NET\Framework\sbs_diasymreader.dll
+ 2009-11-06 23:07 . 2009-11-06 23:07 86864 c:\windows\Microsoft.NET\Framework\NETFXSBS10.exe
- 2008-08-28 10:57 . 2010-02-10 07:42 35088 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
+ 2008-08-28 10:57 . 2010-07-14 22:03 35088 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
+ 2008-08-28 10:57 . 2010-07-14 22:03 18704 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
- 2008-08-28 10:57 . 2010-02-10 07:42 18704 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
- 2008-08-28 10:57 . 2010-02-10 07:42 20240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
+ 2008-08-28 10:57 . 2010-07-14 22:03 20240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
+ 2010-07-16 07:43 . 2010-07-16 07:43 86016 c:\windows\Installer\{3FAD68D9-1FA1-4871-9ADF-9151D969E943}\ARPPRODUCTICON.exe
+ 2008-10-25 06:18 . 2008-10-25 06:18 72568 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\ONFILTER.DLL
+ 2008-10-25 06:18 . 2008-10-25 06:18 98696 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\ONENOTEM.EXE
+ 2010-03-25 21:30 . 2006-05-16 09:58 24576 c:\windows\Downloaded Program Files\dwusplay.dll
+ 2010-06-23 16:12 . 2010-06-23 16:12 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\ea1b4fbde0e772748c6ac42d627cf684\UIAutomationProvider.ni.dll
+ 2010-06-23 16:15 . 2010-06-23 16:15 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\f46915dfc57bc7e49c5402e9b8f7ec18\System.Windows.Presentation.ni.dll
+ 2010-06-09 12:25 . 2010-06-09 12:25 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\1464c662c302ea6372a885161b983732\System.Web.DynamicData.Design.ni.dll
+ 2010-06-09 12:24 . 2010-06-09 12:24 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\5d535ecadf77ac2d9278a1661beb2855\System.ComponentModel.DataAnnotations.ni.dll
+ 2010-06-23 16:11 . 2010-06-23 16:11 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\18729514178d458aa1225dd068718d4e\PresentationFontCache.ni.exe
+ 2010-06-23 16:11 . 2010-06-23 16:11 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\0375dfa28e2f6ef7e89df9edede4b83d\PresentationCFFRasterizer.ni.dll
+ 2010-06-09 12:25 . 2010-06-09 12:25 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\4a52287444c36c89310856b38ff52fe0\Microsoft.Vsa.ni.dll
- 2009-10-16 05:14 . 2009-10-16 05:14 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
- 2008-08-28 16:26 . 2008-08-28 16:26 32768 c:\windows\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
+ 2010-06-09 08:20 . 2010-06-09 08:20 32768 c:\windows\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
- 2009-10-16 05:14 . 2009-10-16 05:14 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
- 2010-03-06 11:58 . 2010-03-06 11:58 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2010-07-21 09:22 . 2010-07-21 09:22 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
- 2010-03-06 11:58 . 2010-03-06 11:58 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2010-07-21 09:22 . 2010-07-21 09:22 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2010-05-25 20:55 . 2010-01-23 08:11 46080 c:\windows\$NtUninstallKB981793$\tzchange.exe
+ 2010-05-25 20:55 . 2010-04-22 22:21 16896 c:\windows\$NtUninstallKB981793$\spuninst\tzchange.dll
+ 2010-06-09 08:21 . 2008-04-14 12:00 65024 c:\windows\$NtUninstallKB979482$\asycfilt.dll
+ 2010-04-14 11:41 . 2008-04-14 12:00 84480 c:\windows\$NtUninstallKB979309$\cabview.dll
+ 2010-04-14 11:43 . 2009-05-26 09:01 26488 c:\windows\$hf_mig$\KB980232\update\spcustom.dll
+ 2010-04-14 11:43 . 2009-05-26 09:01 17272 c:\windows\$hf_mig$\KB980232\spmsg.dll
+ 2010-06-09 08:24 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB980218\update\spcustom.dll
+ 2010-06-09 08:24 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB980218\spmsg.dll
+ 2010-06-09 08:23 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB980195\update\spcustom.dll
+ 2010-06-09 08:23 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB980195\spmsg.dll
+ 2010-06-09 08:21 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB979482\update\spcustom.dll
+ 2010-06-09 08:21 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB979482\spmsg.dll
+ 2010-06-09 05:46 . 2010-03-05 14:52 65536 c:\windows\$hf_mig$\KB979482\SP3QFE\asycfilt.dll
+ 2010-04-14 11:41 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB979309\update\spcustom.dll
+ 2010-04-14 11:41 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB979309\spmsg.dll
+ 2010-04-14 05:17 . 2010-01-13 13:48 86016 c:\windows\$hf_mig$\KB979309\SP3QFE\cabview.dll
+ 2010-04-14 11:41 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB978601\update\spcustom.dll
+ 2010-04-14 11:41 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB978601\spmsg.dll
+ 2010-05-12 12:06 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB978542\update\spcustom.dll
+ 2010-05-12 12:06 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB978542\spmsg.dll
+ 2010-04-14 11:41 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB978338\update\spcustom.dll
+ 2010-04-14 11:41 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB978338\spmsg.dll
+ 2010-04-14 11:41 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB977816\update\spcustom.dll
+ 2010-04-14 11:41 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB977816\spmsg.dll
+ 2010-03-10 07:37 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB975561\update\spcustom.dll
+ 2010-03-10 07:37 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB975561\spmsg.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 2010-03-11 16:15 . 2001-08-17 19:36 5632 c:\windows\system32\ptpusb.dll
- 2010-01-08 22:24 . 2010-01-08 22:24 5120 c:\windows\Installer\{789289CA-F73A-4A16-A331-54D498CE069F}\Icon789289CA.exe
+ 2010-04-13 18:22 . 2010-04-13 18:22 5120 c:\windows\Installer\{789289CA-F73A-4A16-A331-54D498CE069F}\Icon789289CA.exe
- 2009-10-16 05:15 . 2009-10-16 05:15 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2009-08-14 21:03 . 2009-08-14 21:03 653120 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll
+ 2009-08-14 21:03 . 2009-08-14 21:03 569664 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll
+ 2009-08-14 21:03 . 2009-08-14 21:03 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcm90.dll
+ 2007-11-06 23:19 . 2007-11-06 23:19 161784 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_312cf0e9\atl90.dll
+ 2009-11-30 16:02 . 2009-11-30 16:02 171144 c:\windows\system32\xliveinstall.dll
+ 2010-03-16 22:19 . 2010-02-04 09:01 528216 c:\windows\system32\XAudio2_6.dll
+ 2010-03-16 22:19 . 2010-02-04 09:01 238936 c:\windows\system32\xactengine3_6.dll
+ 2008-04-14 12:00 . 2009-12-24 06:59 177664 c:\windows\system32\wintrust.dll
+ 2010-04-08 13:01 . 2002-03-29 08:13 102400 c:\windows\system32\TrackerNET.dll
+ 2010-04-08 12:33 . 1998-10-30 20:21 231936 c:\windows\system32\SNWValid.dll
+ 2010-03-16 21:44 . 2008-10-21 16:00 131072 c:\windows\system32\ReinstallBackups\0018\DriverFiles\smdll.dll
+ 2010-03-16 21:44 . 2008-10-07 05:33 163908 c:\windows\system32\ReinstallBackups\0018\DriverFiles\nvsvc32.exe
+ 2010-03-16 21:44 . 2008-10-07 05:33 286720 c:\windows\system32\ReinstallBackups\0018\DriverFiles\nvnt4cpl.dll
+ 2010-03-16 21:44 . 2008-10-07 05:33 458752 c:\windows\system32\ReinstallBackups\0018\DriverFiles\nvmccssr.dll
+ 2010-03-16 21:44 . 2008-10-07 05:33 188416 c:\windows\system32\ReinstallBackups\0018\DriverFiles\nvmccss.dll
+ 2010-03-16 21:44 . 2008-10-07 05:33 229376 c:\windows\system32\ReinstallBackups\0018\DriverFiles\nvmccs.dll
+ 2010-03-16 21:44 . 2008-10-07 05:33 122880 c:\windows\system32\ReinstallBackups\0018\DriverFiles\nvcod.dll
+ 2010-03-16 21:44 . 2008-10-07 05:33 475136 c:\windows\system32\ReinstallBackups\0018\DriverFiles\nvapi.dll
+ 2010-03-16 21:44 . 2008-10-21 16:00 614400 c:\windows\system32\ReinstallBackups\0018\DriverFiles\msvcr80.dll
+ 2010-03-16 21:44 . 2008-10-21 16:00 130048 c:\windows\system32\ReinstallBackups\0018\DriverFiles\MadCHook.dll
+ 2010-03-16 21:44 . 2008-11-03 02:00 262144 c:\windows\system32\ReinstallBackups\0018\DriverFiles\HookShield.dll
+ 2010-03-16 21:44 . 2008-11-03 02:22 262144 c:\windows\system32\ReinstallBackups\0018\DriverFiles\HookMAp.dll
+ 2010-03-11 16:15 . 2008-04-14 02:42 159232 c:\windows\system32\ptpusd.dll
+ 2010-03-30 22:10 . 2010-03-30 22:10 295264 c:\windows\system32\PresentationHost.exe
+ 2008-04-14 12:00 . 2010-07-23 06:54 435260 c:\windows\system32\perfh009.dat
- 2008-04-14 12:00 . 2010-03-09 21:59 435260 c:\windows\system32\perfh009.dat
+ 2008-08-28 09:34 . 2009-11-19 20:42 592488 c:\windows\system32\NVUNINST.EXE
+ 2008-08-28 09:35 . 2010-01-12 04:03 592488 c:\windows\system32\nvudisp.exe
+ 2010-01-11 21:17 . 2010-01-11 21:17 154216 c:\windows\system32\nvsvc32.exe
+ 2010-01-11 21:17 . 2010-01-11 21:17 126976 c:\windows\system32\nvrszht.dll
+ 2010-01-11 21:17 . 2010-01-11 21:17 229376 c:\windows\system32\nvrszhc.dll
+ 2010-01-11 21:17 . 2010-01-11 21:17 258048 c:\windows\system32\nvrstr.dll
+ 2010-01-11 21:17 . 2010-01-11 21:17 253952 c:\windows\system32\nvrsth.dll
- 2008-10-07 05:33 . 2008-10-07 05:33 253952 c:\windows\system32\nvrsth.dll
- 2008-10-07 05:33 . 2008-10-07 05:33 253952 c:\windows\system32\nvrssv.dll
+ 2010-01-11 21:17 . 2010-01-11 21:17 253952 c:\windows\system32\nvrssv.dll
+ 2010-01-11 21:17 . 2010-01-11 21:17 258048 c:\windows\system32\nvrssl.dll
- 2008-10-07 05:33 . 2008-10-07 05:33 258048 c:\windows\system32\nvrssl.dll
- 2008-10-07 05:33 . 2008-10-07 05:33 258048 c:\windows\system32\nvrssk.dll
+ 2010-01-11 21:17 . 2010-01-11 21:17 258048 c:\windows\system32\nvrssk.dll
+ 2010-01-11 21:17 . 2010-01-11 21:17 270336 c:\windows\system32\nvrsru.dll
+ 2010-01-11 21:17 . 2010-01-11 21:17 270336 c:\windows\system32\nvrsptb.dll
+ 2010-01-11 21:17 . 2010-01-11 21:17 274432 c:\windows\system32\nvrspt.dll
+ 2010-01-11 21:17 . 2010-01-11 21:17 258048 c:\windows\system32\nvrspl.dll
+ 2010-01-11 21:17 . 2010-01-11 21:17 253952 c:\windows\system32\nvrsno.dll
- 2008-10-07 05:33 . 2008-10-07 05:33 253952 c:\windows\system32\nvrsno.dll
+ 2010-01-11 21:17 . 2010-01-11 21:17 274432 c:\windows\system32\nvrsnl.dll
- 2008-10-07 05:33 . 2008-10-07 05:33 274432 c:\windows\system32\nvrsnl.dll
+ 2010-01-11 21:17 . 2010-01-11 21:17 266240 c:\windows\system32\nvrsko.dll
+ 2010-01-11 21:17 . 2010-01-11 21:17 274432 c:\windows\system32\nvrsja.dll
+ 2010-01-11 21:17 . 2010-01-11 21:17 282624 c:\windows\system32\nvrsit.dll
+ 2010-01-11 21:17 . 2010-01-11 21:17 262144 c:\windows\system32\nvrshu.dll
+ 2010-01-11 21:17 . 2010-01-11 21:17 335872 c:\windows\system32\nvrshe.dll
+ 2010-01-11 21:17 . 2010-01-11 21:17 286720 c:\windows\system32\nvrsfr.dll
- 2008-10-07 05:33 . 2008-10-07 05:33 249856 c:\windows\system32\nvrsfi.dll
+ 2010-01-11 21:17 . 2010-01-11 21:17 249856 c:\windows\system32\nvrsfi.dll
+ 2010-01-11 21:17 . 2010-01-11 21:17 274432 c:\windows\system32\nvrsesm.dll
- 2008-10-07 05:33 . 2008-10-07 05:33 274432 c:\windows\system32\nvrsesm.dll
+ 2010-01-11 21:17 . 2010-01-11 21:17 282624 c:\windows\system32\nvrses.dll
- 2008-10-07 05:33 . 2008-10-07 05:33 282624 c:\windows\system32\nvrses.dll
+ 2010-01-11 21:17 . 2010-01-11 21:17 249856 c:\windows\system32\nvrseng.dll
- 2008-10-07 05:33 . 2008-10-07 05:33 282624 c:\windows\system32\nvrsel.dll
+ 2010-01-11 21:17 . 2010-01-11 21:17 282624 c:\windows\system32\nvrsel.dll
+ 2010-01-11 21:17 . 2010-01-11 21:17 278528 c:\windows\system32\nvrsde.dll
- 2008-10-07 05:33 . 2008-10-07 05:33 278528 c:\windows\system32\nvrsde.dll
- 2008-10-07 05:33 . 2008-10-07 05:33 253952 c:\windows\system32\nvrsda.dll
+ 2010-01-11 21:17 . 2010-01-11 21:17 253952 c:\windows\system32\nvrsda.dll
+ 2010-01-11 21:17 . 2010-01-11 21:17 249856 c:\windows\system32\nvrscs.dll
+ 2010-01-11 21:17 . 2010-01-11 21:17 335872 c:\windows\system32\nvrsar.dll
+ 2010-01-11 21:17 . 2010-01-11 21:17 110696 c:\windows\system32\nvmctray.dll
+ 2010-01-11 21:17 . 2010-01-11 21:17 278120 c:\windows\system32\nvmccs.dll
+ 2010-01-11 21:17 . 2010-01-11 21:17 145000 c:\windows\system32\nvcolor.exe
+ 2008-10-07 05:33 . 2010-01-12 04:03 182888 c:\windows\system32\nvcodins.dll
+ 2008-10-07 05:33 . 2010-01-12 04:03 182888 c:\windows\system32\nvcod.dll
+ 2009-11-06 23:07 . 2009-11-06 23:07 297808 c:\windows\system32\mscoree.dll
+ 2010-04-08 13:01 . 2002-03-27 12:54 217088 c:\windows\system32\libmySQL.dll
- 2008-08-28 09:07 . 2009-06-09 19:30 691712 c:\windows\system32\inetcomm.dll
+ 2008-08-28 09:07 . 2010-01-29 15:01 691712 c:\windows\system32\inetcomm.dll
+ 2009-06-09 19:31 . 2010-02-11 12:02 226880 c:\windows\system32\drivers\tcpip6.sys
+ 2007-04-23 11:54 . 2007-04-23 11:54 100488 c:\windows\system32\drivers\s115mgmt.sys
+ 2009-06-09 19:30 . 2010-02-24 13:11 455680 c:\windows\system32\drivers\mrxsmb.sys
+ 2008-04-14 12:00 . 2009-12-24 06:59 177664 c:\windows\system32\dllcache\wintrust.dll
+ 2009-06-09 19:31 . 2010-02-11 12:02 226880 c:\windows\system32\dllcache\tcpip6.sys
+ 2010-02-10 07:01 . 2010-02-24 13:11 455680 c:\windows\system32\dllcache\mrxsmb.sys
+ 2008-08-28 09:07 . 2010-01-29 15:01 691712 c:\windows\system32\dllcache\inetcomm.dll
- 2008-08-28 09:07 . 2009-06-09 19:30 691712 c:\windows\system32\dllcache\inetcomm.dll
+ 2008-08-28 09:07 . 2010-06-14 14:31 744448 c:\windows\system32\dllcache\helpsvc.exe
- 2008-08-28 09:07 . 2008-04-14 12:00 744448 c:\windows\system32\dllcache\helpsvc.exe
- 2008-04-14 12:00 . 2008-04-14 12:00 285696 c:\windows\system32\dllcache\atmfd.dll
+ 2008-04-14 12:00 . 2010-04-20 05:30 285696 c:\windows\system32\dllcache\atmfd.dll
+ 2008-04-14 12:00 . 2010-02-12 04:33 100864 c:\windows\system32\dllcache\6to4svc.dll
+ 2010-04-13 03:51 . 2010-02-12 10:03 293376 c:\windows\system32\browserchoice.exe
- 2008-04-14 12:00 . 2008-04-14 12:00 285696 c:\windows\system32\atmfd.dll
+ 2008-04-14 12:00 . 2010-04-20 05:30 285696 c:\windows\system32\atmfd.dll
+ 2008-04-14 12:00 . 2010-02-12 04:33 100864 c:\windows\system32\6to4svc.dll
+ 2010-03-30 22:16 . 2010-03-30 22:16 130408 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationHostDLL.dll
+ 2010-04-07 21:48 . 2010-04-07 21:48 970752 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
- 2008-07-29 17:16 . 2008-07-29 17:16 110592 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMdiagnostics.dll
+ 2010-04-07 21:48 . 2010-04-07 21:48 110592 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMdiagnostics.dll
+ 2010-03-23 03:31 . 2010-03-23 03:31 435024 c:\windows\Microsoft.NET\Framework\v2.0.50727\webengine.dll
- 2008-07-25 09:17 . 2008-07-25 09:17 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Security.dll
+ 2010-02-09 10:22 . 2010-02-09 10:22 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Security.dll
+ 2010-04-08 12:32 . 1998-01-23 10:22 304128 c:\windows\IsUninst.exe
+ 2010-07-16 07:47 . 2010-07-16 07:47 228352 c:\windows\Installer\914277.msi
+ 2010-02-24 22:14 . 2010-02-24 22:14 543232 c:\windows\Installer\8d02e3.msp
+ 2010-04-25 14:21 . 2010-04-25 14:21 752128 c:\windows\Installer\251f4d4.msi
+ 2010-04-25 14:21 . 2010-04-25 14:21 847872 c:\windows\Installer\251f46f.msi
+ 2010-07-11 10:52 . 2010-07-11 10:52 807424 c:\windows\Installer\1766e57.msi
+ 2010-04-01 18:41 . 2010-04-01 18:41 700416 c:\windows\Installer\15149c.msi
- 2009-12-20 08:01 . 2009-12-20 08:01 371272 c:\windows\Installer\{D103C4BA-F905-437A-8049-DB24763BBE36}\SkypeIcon.exe
+ 2010-04-01 18:40 . 2010-04-01 18:40 371272 c:\windows\Installer\{D103C4BA-F905-437A-8049-DB24763BBE36}\SkypeIcon.exe
+ 2010-07-11 10:52 . 2010-07-11 10:52 897024 c:\windows\Installer\{AFAC914D-9E83-4A89-8ABE-427521C82CCF}\SafariIco.exe
+ 2008-08-28 10:57 . 2010-07-14 22:03 888080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
- 2008-08-28 10:57 . 2010-02-10 07:42 888080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
- 2008-08-28 10:57 . 2010-02-10 07:42 272648 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
+ 2008-08-28 10:57 . 2010-07-14 22:03 272648 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
- 2008-08-28 10:57 . 2010-02-10 07:42 922384 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
+ 2008-08-28 10:57 . 2010-07-14 22:03 922384 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
- 2008-08-28 10:57 . 2010-02-10 07:42 845584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
+ 2008-08-28 10:57 . 2010-07-14 22:03 845584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
- 2008-08-28 10:57 . 2010-02-10 07:42 217864 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
+ 2008-08-28 10:57 . 2010-07-14 22:03 217864 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
+ 2008-08-28 10:57 . 2010-07-14 22:03 184080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
- 2008-08-28 10:57 . 2010-02-10 07:42 184080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2008-08-28 10:57 . 2010-07-14 22:03 159504 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
- 2008-08-28 10:57 . 2010-02-10 07:42 159504 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
+ 2010-07-11 11:03 . 2010-07-11 11:03 372736 c:\windows\Installer\{7AB3A249-FB81-416B-917A-A2A10E74C503}\iTunesIco.exe
+ 2009-03-06 00:37 . 2009-03-06 00:37 501640 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\SOA.DLL
+ 2009-03-06 02:26 . 2009-03-06 02:26 770464 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\REGFORM.EXE
+ 2008-10-25 05:52 . 2008-10-25 05:52 664968 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\ONBTTNOL.DLL
+ 2008-10-25 05:52 . 2008-10-25 05:52 604056 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\ONBTTNIE.DLL
+ 2008-10-25 07:27 . 2008-10-25 07:27 177040 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\IPOLK.DLL
+ 2008-10-26 04:26 . 2008-10-26 04:26 162680 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\ACCWIZ.DLL
+ 2010-07-16 07:47 . 2010-07-16 07:47 200704 c:\windows\E10DB5DAE57640EAA7FC1CB2A7B283A6.TMP\WiseCustomCalla.dll
+ 2010-02-10 07:01 . 2010-02-24 13:11 455680 c:\windows\Driver Cache\i386\mrxsmb.sys
+ 2010-03-25 21:30 . 2006-05-16 09:58 484272 c:\windows\Downloaded Program Files\isusweb.dll
+ 2010-03-25 21:30 . 2006-05-16 09:58 196608 c:\windows\Downloaded Program Files\dwusplay.exe
+ 2010-06-09 12:23 . 2010-06-09 12:23 321536 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\4d07b1ccecca66f320c1a0971dd614d1\WsatConfig.ni.exe
+ 2010-06-23 16:12 . 2010-06-23 16:12 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\b3a9fac9aea3ad913781fafbdcbb0cae\WindowsFormsIntegration.ni.dll
+ 2010-06-23 16:12 . 2010-06-23 16:12 447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\4131a3627fec69291dbaed236f30dc65\UIAutomationClient.ni.dll
+ 2010-06-09 12:26 . 2010-06-09 12:26 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\747e84d81d1de2041661f0f71b04734a\System.Xml.Linq.ni.dll
+ 2010-06-09 12:25 . 2010-06-09 12:25 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\d51dfbd8d5431eb89181baaa24863e15\System.Web.Routing.ni.dll
+ 2010-06-09 12:25 . 2010-06-09 12:25 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\436dde9611932489da3dc8a1be170843\System.Web.RegularExpressions.ni.dll
+ 2010-06-09 12:25 . 2010-06-09 12:25 859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\e8ef769b3e899e62b26daadee50b97ed\System.Web.Extensions.Design.ni.dll
+ 2010-06-09 12:25 . 2010-06-09 12:25 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\ce3b446b7bee5c47949c994ec89b1649\System.Web.Entity.ni.dll
+ 2010-06-09 12:25 . 2010-06-09 12:25 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\ad04fe1182e55e7c01066b62a4bee6b5\System.Web.Entity.Design.ni.dll
+ 2010-06-09 12:25 . 2010-06-09 12:25 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\20ba0d4d182a1a9c1f54c00d3bc29a68\System.Web.DynamicData.ni.dll
+ 2010-06-09 12:25 . 2010-06-09 12:25 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\c97ecf9250c2f0794262534f27f98b72\System.Web.Abstractions.ni.dll
+ 2010-06-09 12:25 . 2010-06-09 12:25 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\9c56656c88979cf18de6cbcb6587ba8f\System.Transactions.ni.dll
+ 2010-06-09 12:25 . 2010-06-09 12:25 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\5adb0f89d469632511aed9d88cfe05c4\System.ServiceProcess.ni.dll
+ 2010-06-09 12:24 . 2010-06-09 12:24 679936 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\42b2ffb594dbd5652a576a0dce28722c\System.Security.ni.dll
+ 2010-06-09 12:25 . 2010-06-09 12:25 311296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\3231473e2ec4451c8f218930fda80d19\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2010-06-09 12:25 . 2010-06-09 12:25 621056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\f90965b9d9a6a6604c9a66f57c37c026\System.Net.ni.dll
+ 2010-06-09 12:25 . 2010-06-09 12:25 998400 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\16670b6870746e5a8dc4a73a76a90bed\System.Management.ni.dll
+ 2010-06-09 12:25 . 2010-06-09 12:25 330752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\e6bd59fec415e273c173170c6508180a\System.Management.Instrumentation.ni.dll
+ 2010-06-09 12:17 . 2010-06-09 12:17 381440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\e3eb86170cba4c80e6e22ca33c63c218\System.IO.Log.ni.dll
+ 2010-06-09 12:23 . 2010-06-09 12:23 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\cfa48936affc9a5fb89f0bf66cc52a47\System.IdentityModel.Selectors.ni.dll
+ 2010-06-09 12:25 . 2010-06-09 12:25 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\e9edc5cd12ebb513b4a3c53cb4640771\System.EnterpriseServices.Wrapper.dll
+ 2010-06-09 12:25 . 2010-06-09 12:25 627712 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\e9edc5cd12ebb513b4a3c53cb4640771\System.EnterpriseServices.ni.dll
+ 2010-06-09 08:21 . 2010-06-09 08:21 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\aeba6820f20655dec7fe0fe05aaeb818\System.Drawing.Design.ni.dll
+ 2010-06-09 12:25 . 2010-06-09 12:25 455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\9ef70079beca3a9982a3aa76ebc0ddd8\System.DirectoryServices.Protocols.ni.dll
+ 2010-06-09 12:25 . 2010-06-09 12:25 881152 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\277619716d9136216065bea970365c65\System.DirectoryServices.AccountManagement.ni.dll
+ 2010-06-09 12:24 . 2010-06-09 12:24 939008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\90b67e13866b176ae6cbdb23144f724d\System.Data.Services.Client.ni.dll
+ 2010-06-09 12:25 . 2010-06-09 12:25 354816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\131a477d41a8669b15696128b94c2636\System.Data.Services.Design.ni.dll
+ 2010-06-09 12:24 . 2010-06-09 12:24 756736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\d4990681ce373d81a52b231ee4c4afea\System.Data.Entity.Design.ni.dll
+ 2010-06-09 12:24 . 2010-06-09 12:24 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\9e9d66a3a0e16fceead505c25af569eb\System.Data.DataSetExtensions.ni.dll
+ 2010-06-09 12:23 . 2010-06-09 12:23 971264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\631b3eba1ba5bd3c3f027f34011cadeb\System.Configuration.ni.dll
+ 2010-06-09 12:25 . 2010-06-09 12:25 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\39e4f9a276fb12125d8a1444d8b65a84\System.Configuration.Install.ni.dll
+ 2010-06-09 12:24 . 2010-06-09 12:24 633856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\849916c5cb3ff7763d15a3976766c2f6\System.AddIn.ni.dll
+ 2010-06-09 12:23 . 2010-06-09 12:23 366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\f38a426b90e6c526dcb2c435c7380450\SMSvcHost.ni.exe
+ 2010-06-09 12:23 . 2010-06-09 12:23 256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\6cabc7d1700c224e8b41ff2f96a3087c\SMDiagnostics.ni.dll
+ 2010-06-09 12:23 . 2010-06-09 12:23 320512 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\5c8f5ca36498f43980d64820d8186c8a\ServiceModelReg.ni.exe
+ 2010-06-23 16:11 . 2010-06-23 16:11 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\a10c2c7e38291c3ada631ad13e762818\PresentationFramework.Aero.ni.dll
+ 2010-06-23 16:11 . 2010-06-23 16:11 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\7579c76fa81eb309d3170b62467be58d\PresentationFramework.Luna.ni.dll
+ 2010-06-23 16:11 . 2010-06-23 16:11 224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\3bef0992fb684e71dbfab5c0a99316af\PresentationFramework.Classic.ni.dll
+ 2010-06-23 16:11 . 2010-06-23 16:11 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\2f6687d394813d760496f60acf046384\PresentationFramework.Royale.ni.dll
+ 2010-06-09 12:23 . 2010-06-09 12:23 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\7700963610c1af364aa934c3c824b7b4\MSBuild.ni.exe
+ 2010-06-09 12:17 . 2010-06-09 12:17 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\c74d4c69c49992dfb23ba512081dc3de\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2010-06-09 12:24 . 2010-06-09 12:24 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\a6a9f24b1a8984eaafbabb1ee968e359\Microsoft.Build.Utilities.ni.dll
+ 2010-06-09 12:24 . 2010-06-09 12:24 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\2fa81d363cb1496be2427d848a867409\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2010-06-09 12:24 . 2010-06-09 12:24 839680 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\c4c360df9c1024ebc3f0de77f5cf8b1c\Microsoft.Build.Engine.ni.dll
+ 2010-06-09 12:24 . 2010-06-09 12:24 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\c9386dcd89c2518a74115f3bfd861830\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2010-06-09 12:17 . 2010-06-09 12:17 410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\abb62e3ed74c974f0282bc7ea5d3f1c1\ComSvcConfig.ni.exe
+ 2010-06-09 12:23 . 2010-06-09 12:23 842240 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\6d34f00b6a782d15bec70d6cdb00b5e8\AspNetMMCExt.ni.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
- 2009-10-16 05:14 . 2009-10-16 05:14 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
- 2009-10-16 05:14 . 2009-10-16 05:14 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2010-06-09 08:20 . 2010-06-09 08:20 970752 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2010-06-09 08:20 . 2010-06-09 08:20 438272 c:\windows\assembly\GAC_MSIL\System.IdentityModel\3.0.0.0__b77a5c561934e089\System.IdentityModel.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- 2009-10-16 05:14 . 2009-10-16 05:14 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll

Lukas666
Návštěvník
Návštěvník
Příspěvky: 89
Registrován: 02 lis 2009 17:19

Re: Vírusy - trójske kone + log z RSIT

#4 Příspěvek od Lukas666 »

+ 2010-06-23 15:25 . 2010-06-23 15:25 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2010-06-09 08:20 . 2010-06-09 08:20 110592 c:\windows\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0__b77a5c561934e089\SMdiagnostics.dll
- 2008-08-28 16:26 . 2008-08-28 16:26 110592 c:\windows\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0__b77a5c561934e089\SMdiagnostics.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
- 2009-10-16 05:14 . 2009-10-16 05:14 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2010-07-21 09:22 . 2010-07-21 09:22 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
- 2010-03-06 11:58 . 2010-03-06 11:58 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2010-07-21 09:22 . 2010-07-21 09:22 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
- 2010-03-06 11:58 . 2010-03-06 11:58 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
- 2010-03-06 11:58 . 2010-03-06 11:58 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2010-07-21 09:22 . 2010-07-21 09:22 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
- 2010-03-06 11:58 . 2010-03-06 11:58 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2010-07-21 09:22 . 2010-07-21 09:22 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2010-07-21 09:22 . 2010-07-21 09:22 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
- 2010-03-06 11:58 . 2010-03-06 11:58 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2010-07-21 09:22 . 2010-07-21 09:22 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2010-03-06 11:58 . 2010-03-06 11:58 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-07-21 09:22 . 2010-07-21 09:22 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2010-03-06 11:58 . 2010-03-06 11:58 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2010-03-06 11:58 . 2010-03-06 11:58 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-07-21 09:22 . 2010-07-21 09:22 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2010-03-06 11:58 . 2010-03-06 11:58 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-07-21 09:22 . 2010-07-21 09:22 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-07-21 09:22 . 2010-07-21 09:22 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2010-03-06 11:58 . 2010-03-06 11:58 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2010-03-06 11:58 . 2010-03-06 11:58 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-07-21 09:22 . 2010-07-21 09:22 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2010-03-06 11:58 . 2010-03-06 11:58 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-07-21 09:22 . 2010-07-21 09:22 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-07-21 09:22 . 2010-07-21 09:22 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2010-03-06 11:58 . 2010-03-06 11:58 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2010-03-06 11:58 . 2010-03-06 11:58 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2010-07-21 09:22 . 2010-07-21 09:22 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2010-05-25 20:55 . 2009-05-26 09:01 382840 c:\windows\$NtUninstallKB981793$\spuninst\updspapi.dll
+ 2010-05-25 20:55 . 2009-05-26 09:01 231288 c:\windows\$NtUninstallKB981793$\spuninst\spuninst.exe
+ 2010-04-14 11:43 . 2009-05-26 09:01 382840 c:\windows\$NtUninstallKB980232$\spuninst\updspapi.dll
+ 2010-04-14 11:43 . 2009-05-26 09:01 231288 c:\windows\$NtUninstallKB980232$\spuninst\spuninst.exe
+ 2010-04-14 11:43 . 2009-12-04 18:22 455424 c:\windows\$NtUninstallKB980232$\mrxsmb.sys
+ 2010-06-09 08:24 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB980218$\spuninst\updspapi.dll
+ 2010-06-09 08:24 . 2009-05-26 11:40 231288 c:\windows\$NtUninstallKB980218$\spuninst\spuninst.exe
+ 2010-06-09 08:24 . 2008-04-14 12:00 285696 c:\windows\$NtUninstallKB980218$\atmfd.dll
+ 2010-06-09 08:23 . 2008-07-08 13:02 382840 c:\windows\$NtUninstallKB980195$\spuninst\updspapi.dll
+ 2010-06-09 08:23 . 2008-07-08 13:02 231288 c:\windows\$NtUninstallKB980195$\spuninst\spuninst.exe
+ 2010-04-14 11:43 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB979683$\spuninst\updspapi.dll
+ 2010-04-14 11:43 . 2009-05-26 11:40 231288 c:\windows\$NtUninstallKB979683$\spuninst\spuninst.exe
+ 2010-06-09 08:22 . 2009-05-26 09:01 382840 c:\windows\$NtUninstallKB979559$\spuninst\updspapi.dll
+ 2010-06-09 08:22 . 2009-05-26 09:01 231288 c:\windows\$NtUninstallKB979559$\spuninst\spuninst.exe
+ 2010-06-09 08:21 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB979482$\spuninst\updspapi.dll
+ 2010-06-09 08:21 . 2009-05-26 11:40 231288 c:\windows\$NtUninstallKB979482$\spuninst\spuninst.exe
+ 2010-04-14 11:43 . 2007-07-27 21:11 382840 c:\windows\$NtUninstallKB979402_WM9$\spuninst\updspapi.dll
+ 2010-04-14 11:43 . 2007-07-27 21:11 231288 c:\windows\$NtUninstallKB979402_WM9$\spuninst\spuninst.exe
+ 2010-04-14 11:41 . 2008-07-08 13:02 382840 c:\windows\$NtUninstallKB979309$\spuninst\updspapi.dll
+ 2010-04-14 11:41 . 2008-07-08 13:02 231288 c:\windows\$NtUninstallKB979309$\spuninst\spuninst.exe
+ 2010-06-09 08:21 . 2007-07-27 21:11 382840 c:\windows\$NtUninstallKB978695_WM9$\spuninst\updspapi.dll
+ 2010-06-09 08:21 . 2007-07-27 21:11 231288 c:\windows\$NtUninstallKB978695_WM9$\spuninst\spuninst.exe
+ 2010-04-14 11:41 . 2008-04-14 12:00 176640 c:\windows\$NtUninstallKB978601$\wintrust.dll
+ 2010-04-14 11:41 . 2008-07-08 13:02 382840 c:\windows\$NtUninstallKB978601$\spuninst\updspapi.dll
+ 2010-04-14 11:41 . 2008-07-08 13:02 231288 c:\windows\$NtUninstallKB978601$\spuninst\spuninst.exe
+ 2010-05-12 12:06 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB978542$\spuninst\updspapi.dll
+ 2010-05-12 12:06 . 2009-05-26 11:40 231288 c:\windows\$NtUninstallKB978542$\spuninst\spuninst.exe
+ 2010-05-12 12:06 . 2009-06-09 19:30 691712 c:\windows\$NtUninstallKB978542$\inetcomm.dll
+ 2010-04-14 11:41 . 2009-06-09 19:31 225856 c:\windows\$NtUninstallKB978338$\tcpip6.sys
+ 2010-04-14 11:41 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB978338$\spuninst\updspapi.dll
+ 2010-04-14 11:41 . 2009-05-26 11:40 231288 c:\windows\$NtUninstallKB978338$\spuninst\spuninst.exe
+ 2010-04-14 11:41 . 2008-04-14 12:00 100352 c:\windows\$NtUninstallKB978338$\6to4svc.dll
+ 2010-04-14 11:41 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB977816$\spuninst\updspapi.dll
+ 2010-04-14 11:41 . 2009-05-26 11:40 231288 c:\windows\$NtUninstallKB977816$\spuninst\spuninst.exe
+ 2010-06-09 08:20 . 2010-02-22 17:53 382840 c:\windows\$NtUninstallKB975562$\spuninst\updspapi.dll
+ 2010-06-09 08:20 . 2008-07-08 13:02 231288 c:\windows\$NtUninstallKB975562$\spuninst\spuninst.exe
+ 2010-03-10 07:37 . 2009-05-26 16:10 382840 c:\windows\$NtUninstallKB975561$\spuninst\updspapi.dll
+ 2010-03-10 07:37 . 2008-07-08 13:02 231288 c:\windows\$NtUninstallKB975561$\spuninst\spuninst.exe
+ 2010-04-14 11:43 . 2009-05-26 09:01 382840 c:\windows\$hf_mig$\KB980232\update\updspapi.dll
+ 2010-04-14 11:43 . 2009-05-26 09:01 755576 c:\windows\$hf_mig$\KB980232\update\update.exe
+ 2010-04-14 11:43 . 2009-05-26 09:01 231288 c:\windows\$hf_mig$\KB980232\spuninst.exe
+ 2010-04-14 05:20 . 2010-02-24 11:57 457216 c:\windows\$hf_mig$\KB980232\SP3QFE\mrxsmb.sys
+ 2010-06-09 08:24 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB980218\update\updspapi.dll
+ 2010-06-09 08:24 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB980218\update\update.exe
+ 2010-06-09 08:24 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB980218\spuninst.exe
+ 2010-06-09 05:46 . 2010-04-20 05:37 285824 c:\windows\$hf_mig$\KB980218\SP3QFE\atmfd.dll
+ 2010-06-09 08:23 . 2008-07-08 13:02 382840 c:\windows\$hf_mig$\KB980195\update\updspapi.dll
+ 2010-06-09 08:23 . 2008-07-08 13:02 755576 c:\windows\$hf_mig$\KB980195\update\update.exe
+ 2010-06-09 08:23 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB980195\spuninst.exe
+ 2010-06-09 08:21 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB979482\update\updspapi.dll
+ 2010-06-09 08:21 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB979482\update\update.exe
+ 2010-06-09 08:21 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB979482\spuninst.exe
+ 2010-04-14 11:41 . 2008-07-08 13:02 382840 c:\windows\$hf_mig$\KB979309\update\updspapi.dll
+ 2010-04-14 11:41 . 2008-07-08 13:02 755576 c:\windows\$hf_mig$\KB979309\update\update.exe
+ 2010-04-14 11:41 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB979309\spuninst.exe
+ 2010-04-14 11:41 . 2008-07-08 13:02 382840 c:\windows\$hf_mig$\KB978601\update\updspapi.dll
+ 2010-04-14 11:41 . 2008-07-08 13:02 755576 c:\windows\$hf_mig$\KB978601\update\update.exe
+ 2010-04-14 11:41 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB978601\spuninst.exe
+ 2010-04-14 05:16 . 2009-12-24 06:42 178176 c:\windows\$hf_mig$\KB978601\SP3QFE\wintrust.dll
+ 2010-05-12 12:06 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB978542\update\updspapi.dll
+ 2010-05-12 12:06 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB978542\update\update.exe
+ 2010-05-12 12:06 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB978542\spuninst.exe
+ 2010-05-12 10:39 . 2010-01-29 14:53 691712 c:\windows\$hf_mig$\KB978542\SP3QFE\inetcomm.dll
+ 2010-04-14 11:41 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB978338\update\updspapi.dll
+ 2010-04-14 11:41 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB978338\update\update.exe
+ 2010-04-14 11:41 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB978338\spuninst.exe
+ 2010-04-14 05:21 . 2010-02-11 11:36 226880 c:\windows\$hf_mig$\KB978338\SP3QFE\tcpip6.sys
+ 2010-04-14 05:21 . 2010-02-12 04:27 100864 c:\windows\$hf_mig$\KB978338\SP3QFE\6to4svc.dll
+ 2010-04-14 11:41 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB977816\update\updspapi.dll
+ 2010-04-14 11:41 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB977816\update\update.exe
+ 2010-04-14 11:41 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB977816\spuninst.exe
+ 2010-03-10 07:37 . 2009-05-26 16:10 382840 c:\windows\$hf_mig$\KB975561\update\updspapi.dll
+ 2010-03-10 07:37 . 2008-07-08 13:02 755576 c:\windows\$hf_mig$\KB975561\update\update.exe
+ 2010-03-10 07:37 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB975561\spuninst.exe
+ 2007-11-06 23:19 . 2007-11-06 23:19 1162744 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_a173767a\mfc90u.dll
+ 2007-11-06 23:19 . 2007-11-06 23:19 1156600 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_a173767a\mfc90.dll
+ 2009-06-09 19:31 . 2010-04-06 02:52 2462720 c:\windows\system32\WMVCore.dll
- 2008-04-14 12:00 . 2009-07-12 10:21 4874240 c:\windows\system32\wmp.dll
+ 2008-04-14 12:00 . 2010-03-19 16:05 4874240 c:\windows\system32\wmp.dll
+ 2010-02-27 11:45 . 2010-04-19 18:47 3062048 c:\windows\system32\usbaaplrc.dll
+ 2010-04-08 12:33 . 1998-10-30 20:21 1022976 c:\windows\system32\SierraNW.dll
+ 2010-03-16 21:44 . 2008-10-07 05:33 2981888 c:\windows\system32\ReinstallBackups\0018\DriverFiles\nvwssr.dll
+ 2010-03-16 21:44 . 2008-10-07 05:33 2686976 c:\windows\system32\ReinstallBackups\0018\DriverFiles\nvwss.dll
+ 2010-03-16 21:44 . 2008-10-07 05:33 4149248 c:\windows\system32\ReinstallBackups\0018\DriverFiles\nvvitvsr.dll
+ 2010-03-16 21:44 . 2008-10-07 05:33 3764224 c:\windows\system32\ReinstallBackups\0018\DriverFiles\nvvitvs.dll
+ 2010-03-16 21:44 . 2008-10-07 05:33 8826880 c:\windows\system32\ReinstallBackups\0018\DriverFiles\nvoglnt.dll
+ 2010-03-16 21:44 . 2008-10-07 05:33 2854912 c:\windows\system32\ReinstallBackups\0018\DriverFiles\nvmoblsr.dll
+ 2010-03-16 21:44 . 2008-10-07 05:33 1257472 c:\windows\system32\ReinstallBackups\0018\DriverFiles\nvmobls.dll
+ 2010-03-16 21:44 . 2008-10-07 05:33 3457024 c:\windows\system32\ReinstallBackups\0018\DriverFiles\nvgamesr.dll
+ 2010-03-16 21:44 . 2008-10-07 05:33 3444736 c:\windows\system32\ReinstallBackups\0018\DriverFiles\nvgames.dll
+ 2010-03-16 21:44 . 2008-10-07 05:33 5799936 c:\windows\system32\ReinstallBackups\0018\DriverFiles\nvdispsr.dll
+ 2010-03-16 21:44 . 2008-10-07 05:33 3989504 c:\windows\system32\ReinstallBackups\0018\DriverFiles\nvdisps.dll
+ 2010-03-16 21:44 . 2008-10-07 05:33 1368064 c:\windows\system32\ReinstallBackups\0018\DriverFiles\nvcuda.dll
+ 2010-03-16 21:44 . 2008-10-07 05:33 6133856 c:\windows\system32\ReinstallBackups\0018\DriverFiles\nv4_mini.sys
+ 2010-03-16 21:44 . 2008-10-07 05:33 6058112 c:\windows\system32\ReinstallBackups\0018\DriverFiles\nv4_disp.dll
+ 2010-03-16 21:44 . 2008-11-03 02:13 1785856 c:\windows\system32\ReinstallBackups\0018\DriverFiles\msicpl.dll
+ 2010-03-16 21:44 . 2008-10-21 16:00 2323664 c:\windows\system32\ReinstallBackups\0018\DriverFiles\d3dx9_28.dll
+ 2010-03-16 21:44 . 2008-10-21 16:00 2319568 c:\windows\system32\ReinstallBackups\0018\DriverFiles\d3dx9_27.dll
- 2009-06-09 19:33 . 2009-11-27 17:23 1291776 c:\windows\system32\quartz.dll
+ 2009-06-09 19:33 . 2010-02-05 18:29 1291776 c:\windows\system32\quartz.dll
+ 2010-03-16 21:44 . 2010-01-12 04:03 2283526 c:\windows\system32\nvdata.bin
+ 2010-03-16 21:44 . 2010-01-12 04:03 2259560 c:\windows\system32\nvcuvid.dll
+ 2010-03-16 21:44 . 2010-01-12 04:03 4077672 c:\windows\system32\nvcuvenc.dll
+ 2008-10-07 05:33 . 2010-01-12 04:03 4104192 c:\windows\system32\nvcuda.dll
+ 2008-10-07 05:33 . 2010-01-12 04:03 1081344 c:\windows\system32\nvapi.dll
+ 2008-10-07 05:33 . 2010-01-12 04:03 6359168 c:\windows\system32\nv4_disp.dll
+ 2009-06-09 19:32 . 2010-02-16 12:50 2146304 c:\windows\system32\ntoskrnl.exe
+ 2009-02-06 10:30 . 2010-02-16 12:12 2024448 c:\windows\system32\ntkrnlpa.exe
+ 2008-08-28 11:01 . 2010-06-09 10:46 1574192 c:\windows\system32\FNTCACHE.DAT
- 2008-08-28 11:01 . 2009-11-29 08:04 1574192 c:\windows\system32\FNTCACHE.DAT
+ 2010-07-11 10:56 . 2010-04-19 18:47 3062048 c:\windows\system32\DRVSTORE\usbaapl_3822718F9E2E86C3752D30561ECA5A855A4A3F7D\usbaaplrc.dll
+ 2010-07-11 10:56 . 2010-04-19 18:29 1461992 c:\windows\system32\DRVSTORE\netaapl_3A00C5601D92D37DDCB0AE45518D6B42BE1588E6\wdfcoinstaller01009.dll
+ 2009-06-09 19:31 . 2010-04-06 02:52 2462720 c:\windows\system32\dllcache\WMVCore.dll
+ 2008-04-14 12:00 . 2010-03-19 16:05 4874240 c:\windows\system32\dllcache\wmp.dll
- 2008-04-14 12:00 . 2009-07-12 10:21 4874240 c:\windows\system32\dllcache\wmp.dll
+ 2009-06-09 19:33 . 2010-05-02 10:04 1860352 c:\windows\system32\dllcache\win32k.sys
+ 2009-06-09 19:33 . 2010-02-05 18:29 1291776 c:\windows\system32\dllcache\quartz.dll
- 2009-06-09 19:33 . 2009-11-27 17:23 1291776 c:\windows\system32\dllcache\quartz.dll
+ 2009-10-15 21:34 . 2010-02-16 12:52 2190080 c:\windows\system32\dllcache\ntoskrnl.exe
+ 2009-10-15 21:34 . 2010-02-16 12:12 2024448 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2009-08-04 16:47 . 2010-02-16 12:12 2066944 c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2009-10-15 21:34 . 2010-02-16 12:50 2146304 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2008-08-28 09:07 . 2010-01-29 18:31 1315328 c:\windows\system32\dllcache\msoe.dll
- 2008-08-28 09:07 . 2009-07-10 13:27 1315328 c:\windows\system32\dllcache\msoe.dll
- 2008-08-28 09:08 . 2008-04-14 12:00 3558912 c:\windows\system32\dllcache\moviemk.exe
+ 2008-08-28 09:08 . 2009-10-23 15:28 3558912 c:\windows\system32\dllcache\moviemk.exe
+ 2009-11-06 23:06 . 2009-11-06 23:06 1130824 c:\windows\system32\dfshim.dll
+ 2010-04-07 21:48 . 2010-04-07 21:48 5967872 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.dll
- 2008-11-25 02:59 . 2008-11-25 02:59 5242880 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
+ 2010-03-23 03:32 . 2010-03-23 03:32 5242880 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
+ 2010-03-23 03:32 . 2010-03-23 03:32 3182592 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
+ 2009-11-08 22:25 . 2009-11-08 22:25 1935360 c:\windows\Installer\cace5f.msp
+ 2010-04-24 15:08 . 2010-04-24 15:08 9129984 c:\windows\Installer\8d0391.msp
+ 2010-03-24 16:54 . 2010-03-24 16:54 3126272 c:\windows\Installer\8d0379.msp
+ 2010-03-24 16:54 . 2010-03-24 16:54 2516992 c:\windows\Installer\8d0378.msp
+ 2010-04-24 15:07 . 2010-04-24 15:07 4667392 c:\windows\Installer\8d035c.msp
+ 2010-04-24 15:05 . 2010-04-24 15:05 4199424 c:\windows\Installer\8d0345.msp
+ 2010-05-18 21:35 . 2010-05-18 21:35 5023744 c:\windows\Installer\8d032e.msp
+ 2010-04-11 20:17 . 2010-04-11 20:17 2607104 c:\windows\Installer\8d0308.msp
+ 2010-04-11 20:17 . 2010-04-11 20:17 4210688 c:\windows\Installer\8d0307.msp
+ 2010-04-24 15:10 . 2010-04-24 15:10 8486400 c:\windows\Installer\8d02d6.msp
+ 2009-10-16 05:08 . 2009-10-16 05:08 2237952 c:\windows\Installer\539e5c.msp
+ 2010-04-09 13:21 . 2010-04-09 13:21 5025792 c:\windows\Installer\539e45.msp
+ 2010-02-04 16:24 . 2010-02-04 16:24 9122304 c:\windows\Installer\4e20fe.msp
+ 2010-02-21 00:00 . 2010-02-21 00:00 8480768 c:\windows\Installer\4e20e7.msp
+ 2010-02-03 23:59 . 2010-02-03 23:59 5031936 c:\windows\Installer\4e20d0.msp
+ 2010-07-02 14:32 . 2010-07-02 14:32 2647552 c:\windows\Installer\464ad08.msi
+ 2010-05-20 17:57 . 2010-05-20 17:57 4989952 c:\windows\Installer\3c85e20.msp
+ 2010-05-20 17:57 . 2010-05-20 17:57 5907456 c:\windows\Installer\3c85e1f.msp
+ 2010-06-11 09:03 . 2010-06-11 09:03 5021184 c:\windows\Installer\3c85dff.msp
+ 2010-03-16 22:20 . 2010-03-16 22:20 1598464 c:\windows\Installer\1d8cc5.msi
+ 2010-07-11 11:04 . 2010-07-11 11:04 1689600 c:\windows\Installer\1767dec.msi
+ 2010-07-11 11:03 . 2010-07-11 11:03 4820480 c:\windows\Installer\1767de5.msi
+ 2010-07-11 10:59 . 2010-07-11 10:59 9472000 c:\windows\Installer\1767648.msi
+ 2010-07-11 10:56 . 2010-07-11 10:56 3089408 c:\windows\Installer\1766ec7.msi
+ 2010-07-11 10:56 . 2010-07-11 10:56 1984000 c:\windows\Installer\1766e89.msi
+ 2010-07-11 10:52 . 2010-07-11 10:52 3094528 c:\windows\Installer\1766e76.msi
+ 2010-02-20 23:03 . 2010-02-20 23:03 4472832 c:\windows\Installer\1629ec1.msp
+ 2010-02-20 23:02 . 2010-02-20 23:02 4195840 c:\windows\Installer\1629ea4.msp
+ 2010-03-11 21:59 . 2010-03-11 21:59 5031424 c:\windows\Installer\1629e8d.msp
+ 2010-04-01 18:40 . 2010-04-01 18:40 1575936 c:\windows\Installer\151493.msi
- 2008-08-28 10:57 . 2010-02-10 07:42 1172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
+ 2008-08-28 10:57 . 2010-07-14 22:03 1172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
- 2008-08-28 10:57 . 2010-02-10 07:42 1165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2008-08-28 10:57 . 2010-07-14 22:03 1165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2008-08-25 20:50 . 2008-08-25 20:50 2585592 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\VBE6.DLL
+ 2009-03-06 02:00 . 2009-03-06 02:00 6596472 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\ONMAIN.DLL
+ 2008-11-10 08:49 . 2008-11-10 08:49 1165680 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\ONLIBS.DLL
+ 2008-11-24 20:16 . 2008-11-24 20:16 1020776 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\ONENOTE.EXE
+ 2009-03-06 02:26 . 2009-03-06 02:26 5466488 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\IPDESIGN.DLL
+ 2008-11-03 22:40 . 2008-11-03 22:40 1442160 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\INFOPATH.EXE
+ 2009-10-15 21:34 . 2010-02-16 12:52 2190080 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2009-10-15 21:34 . 2010-02-16 12:12 2024448 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2009-08-04 16:47 . 2010-02-16 12:12 2066944 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2009-10-15 21:34 . 2010-02-16 12:50 2146304 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2010-06-23 16:11 . 2010-06-23 16:11 3325440 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\d63164ac4ed5adabc6a1b0fdf07eee05\WindowsBase.ni.dll
+ 2010-06-23 16:12 . 2010-06-23 16:12 1049600 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\d8549ce90b26cdc3071224ab6f020189\UIAutomationClientsideProviders.ni.dll
+ 2010-06-09 08:20 . 2010-06-09 08:20 7949824 c:\windows\assembly\NativeImages_v2.0.50727_32\System\37217abe2c5164e59aba251860f4c79e\System.ni.dll
+ 2010-06-09 08:22 . 2010-06-09 08:22 5450752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\563a54b98adb70fae862974042298348\System.Xml.ni.dll
+ 2010-06-09 12:26 . 2010-06-09 12:26 1356288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\016b75f60a18535c8d6b3e5d861ab559\System.WorkflowServices.ni.dll
+ 2010-06-09 12:26 . 2010-06-09 12:26 1908224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\6dacae37d337004345518976fb57099e\System.Workflow.Runtime.ni.dll
+ 2010-06-09 12:26 . 2010-06-09 12:26 4514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\c7b832bbc5bb11c6c7f128c801ce90d7\System.Workflow.ComponentModel.ni.dll
+ 2010-06-09 12:26 . 2010-06-09 12:26 2992640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\b9ea6ea910293cd6f13f765775867ebd\System.Workflow.Activities.ni.dll
+ 2010-06-09 12:25 . 2010-06-09 12:25 1840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\8ef8d556899a4a10b7f288a80925489f\System.Web.Services.ni.dll
+ 2010-06-09 12:25 . 2010-06-09 12:25 2209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\5dfda43f1991ee6ba345d62b2be4801c\System.Web.Mobile.ni.dll
+ 2010-06-09 12:25 . 2010-06-09 12:25 2403328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\f08b3b8cdf548e3dfe61f342536175eb\System.Web.Extensions.ni.dll
+ 2010-06-09 08:21 . 2010-06-09 08:21 1917952 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\2d6a5dbee4506bf643b853e41668afa3\System.Speech.ni.dll
+ 2010-06-09 12:25 . 2010-06-09 12:25 1706496 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\169fe0ad9d59982a2a6b89779c09885b\System.ServiceModel.Web.ni.dll
+ 2010-06-09 12:17 . 2010-06-09 12:17 2345472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\8b2710a63ecd363315ef16b257588b95\System.Runtime.Serialization.ni.dll
+ 2010-06-23 16:12 . 2010-06-23 16:12 1035264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\af217ef58e5558991f331d482c2bdba6\System.Printing.ni.dll
+ 2010-06-09 12:17 . 2010-06-09 12:17 1070080 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\ad4fb86064d7a1ebcb9ee997e7208ac1\System.IdentityModel.ni.dll
+ 2010-06-09 08:21 . 2010-06-09 08:21 1587200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\f3440ea00eb3c40dc073b2fe03843638\System.Drawing.ni.dll
+ 2010-06-09 12:25 . 2010-06-09 12:25 1116672 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\7deab2494d53763cd83c567e71e0d8e0\System.DirectoryServices.ni.dll
+ 2010-06-09 12:25 . 2010-06-09 12:25 1801216 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\b81efadfee7702624b713c6d86f7e369\System.Deployment.ni.dll
+ 2010-06-09 08:21 . 2010-06-09 08:21 6616576 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\50130ef751b98a4a11bd4ab73af7cab5\System.Data.ni.dll
+ 2010-06-09 12:24 . 2010-06-09 12:24 2510336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\f71abf392c5ca05a4e46a5d1c4c72856\System.Data.SqlXml.ni.dll
+ 2010-06-09 12:24 . 2010-06-09 12:24 1328128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\5e6311aff5ada83d0f854922fa62faf6\System.Data.Services.ni.dll
+ 2010-06-09 08:21 . 2010-06-09 08:21 2516480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\c3ba3367d03779ad6e76c5d4cdfe572a\System.Data.Linq.ni.dll
+ 2010-06-09 12:24 . 2010-06-09 12:24 9924096 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\6abf820d8ec57a0561c3367727d274df\System.Data.Entity.ni.dll
+ 2010-06-09 08:21 . 2010-06-09 08:21 2295296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\e98726349766935ec0e9b980f19a046a\System.Core.ni.dll
+ 2010-06-23 16:12 . 2010-06-23 16:12 2128896 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\57abb757c1f38586390dcc63bf056322\ReachFramework.ni.dll
+ 2010-06-23 16:11 . 2010-06-23 16:11 1657856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\0095ba60255d4addaf5b8ebee697a027\PresentationUI.ni.dll
+ 2010-06-09 08:20 . 2010-06-09 08:20 1451008 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\20ef773b20f6ce721ae60e5c2c2e8f80\PresentationBuildTasks.ni.dll
+ 2010-06-09 12:24 . 2010-06-09 12:24 1712128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\935b855860088a86bb65d37a19f059cc\Microsoft.VisualBasic.ni.dll
+ 2010-06-09 12:17 . 2010-06-09 12:17 1093120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\7a266de493d30eed21cb60ebe300be53\Microsoft.Transactions.Bridge.ni.dll
+ 2010-06-09 12:25 . 2010-06-09 12:25 2332160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\9db8f9f7fe63ca4451bb5316a3ebb009\Microsoft.JScript.ni.dll
+ 2010-06-09 12:24 . 2010-06-09 12:24 1966080 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\c96be82d6cb00367db4e3553272165ef\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2010-06-09 12:24 . 2010-06-09 12:24 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\3815de5b052187b5d9375681a6784255\Microsoft.Build.Tasks.ni.dll
+ 2010-06-09 12:23 . 2010-06-09 12:23 1888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\43fc6723d08e9ce88701c29653efd224\Microsoft.Build.Engine.ni.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 1249280 c:\windows\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 3182592 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- 2009-10-16 05:14 . 2009-10-16 05:14 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2010-06-09 08:20 . 2010-06-09 08:20 5967872 c:\windows\assembly\GAC_MSIL\System.ServiceModel\3.0.0.0__b77a5c561934e089\System.ServiceModel.dll
- 2009-10-16 05:14 . 2009-10-16 05:14 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 5279744 c:\windows\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 5242880 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
- 2009-10-16 05:14 . 2009-10-16 05:14 5242880 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 4210688 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
- 2008-08-28 16:26 . 2008-08-28 16:26 4210688 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
- 2009-10-16 05:15 . 2009-10-16 05:15 4546560 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2010-06-23 15:25 . 2010-06-23 15:25 4546560 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
- 2010-03-06 11:58 . 2010-03-06 11:58 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-07-21 09:22 . 2010-07-21 09:22 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2010-03-06 11:58 . 2010-03-06 11:58 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-07-21 09:22 . 2010-07-21 09:22 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-04-14 11:43 . 2009-12-08 18:20 2145280 c:\windows\$NtUninstallKB979683$\ntoskrnl.exe
+ 2010-04-14 11:43 . 2009-12-08 17:40 2023936 c:\windows\$NtUninstallKB979683$\ntkrpamp.exe
+ 2010-04-14 11:43 . 2009-12-08 17:40 2023936 c:\windows\$NtUninstallKB979683$\ntkrnlpa.exe
+ 2010-04-14 11:43 . 2009-12-08 18:20 2145280 c:\windows\$NtUninstallKB979683$\ntkrnlmp.exe
+ 2010-06-09 08:22 . 2009-08-14 16:49 1859712 c:\windows\$NtUninstallKB979559$\win32k.sys
+ 2010-04-14 11:43 . 2009-07-12 10:21 4874240 c:\windows\$NtUninstallKB979402_WM9$\wmp.dll
+ 2010-06-09 08:21 . 2009-05-20 02:56 2458112 c:\windows\$NtUninstallKB978695_WM9$\wmvcore.dll
+ 2010-05-12 12:06 . 2009-07-10 13:27 1315328 c:\windows\$NtUninstallKB978542$\msoe.dll
+ 2010-06-09 08:20 . 2009-11-27 17:23 1291776 c:\windows\$NtUninstallKB975562$\quartz.dll
+ 2010-03-10 07:37 . 2008-04-14 12:00 3558912 c:\windows\$NtUninstallKB975561$\moviemk.exe
+ 2010-05-12 10:39 . 2010-01-29 14:53 1315328 c:\windows\$hf_mig$\KB978542\SP3QFE\msoe.dll
+ 2010-03-10 06:13 . 2009-10-23 14:53 3558912 c:\windows\$hf_mig$\KB975561\SP3QFE\moviemk.exe
- 2009-08-07 17:51 . 2009-08-07 17:51 13642888 c:\windows\system32\xlivefnt.dll
+ 2009-11-06 08:59 . 2009-11-06 08:59 13642888 c:\windows\system32\xlivefnt.dll
+ 2009-11-06 08:59 . 2009-11-06 08:59 15406728 c:\windows\system32\xlive.dll
+ 2010-03-16 21:44 . 2008-10-07 05:33 13574144 c:\windows\system32\ReinstallBackups\0018\DriverFiles\nvcpl.dll
+ 2008-10-07 05:33 . 2010-01-12 04:03 14458880 c:\windows\system32\nvoglnt.dll
+ 2010-01-11 21:17 . 2010-01-11 21:17 13666408 c:\windows\system32\nvcpl.dll
+ 2010-03-16 21:44 . 2010-01-12 04:03 11632640 c:\windows\system32\nvcompiler.dll
+ 2009-08-28 11:33 . 2010-07-02 19:39 34045896 c:\windows\system32\MRT.exe
+ 2008-10-07 05:33 . 2010-01-12 04:03 10276768 c:\windows\system32\drivers\nv4_mini.sys
+ 2008-10-07 05:33 . 2010-01-12 04:03 10276768 c:\windows\system32\dllcache\nv4_mini.sys
+ 2010-03-30 23:23 . 2010-03-30 23:23 15638528 c:\windows\Installer\cace6c.msp
+ 2010-07-16 07:43 . 2010-07-16 07:43 22232576 c:\windows\Installer\91426a.msi
+ 2010-04-24 15:09 . 2010-04-24 15:09 11750912 c:\windows\Installer\8d03a8.msp
+ 2010-04-11 20:17 . 2010-04-11 20:17 14599680 c:\windows\Installer\8d0317.msp
+ 2010-04-24 15:07 . 2010-04-24 15:07 10118144 c:\windows\Installer\8d02fb.msp
+ 2009-11-20 22:46 . 2009-11-20 22:46 11524608 c:\windows\Installer\4e2115.msp
+ 2010-05-20 17:58 . 2010-05-20 17:58 12114432 c:\windows\Installer\3c85de8.msp
+ 2010-03-22 14:03 . 2010-03-22 14:03 11732992 c:\windows\Installer\1629ed8.msp
+ 2009-04-03 16:46 . 2009-04-03 16:46 17314688 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\MSO.DLL
+ 2009-03-06 00:37 . 2009-03-06 00:37 10222432 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\MSACCESS.EXE
+ 2010-06-09 08:22 . 2010-06-09 08:22 12430848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\2dfe045e4b1577fdea9a2f456db0afc2\System.Windows.Forms.ni.dll
+ 2010-06-09 12:25 . 2010-06-09 12:25 11797504 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\d987cf1de4ba688da92e212a374232c2\System.Web.ni.dll
+ 2010-06-09 12:17 . 2010-06-09 12:17 17403904 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\8b74f2fe3f3632f95ff4ddb8c4839a1e\System.ServiceModel.ni.dll
+ 2010-06-09 08:21 . 2010-06-09 08:21 10683392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\f352c5cb50bee105e4c873ca050f9f46\System.Design.ni.dll
+ 2010-06-23 16:11 . 2010-06-23 16:11 14328320 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\560662ada034afb6ec78a152bd9a47b5\PresentationFramework.ni.dll
+ 2010-06-23 16:11 . 2010-06-23 16:11 12215808 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\9f5dff344ac6ac923b5ade8ba1ab9382\PresentationCore.ni.dll
.
-- Snapshot reset to current date --

Lukas666
Návštěvník
Návštěvník
Příspěvky: 89
Registrován: 02 lis 2009 17:19

Re: Vírusy - trójske kone + log z RSIT

#5 Příspěvek od Lukas666 »

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-01-11 13666408]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-03-19 2029640]
"SNPSTD2"="c:\windows\vsnpstd2.exe" [2004-06-10 286720]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"36X Raid Configurer"="c:\windows\system32\xRaidSetup.exe" [2007-11-19 1970176]
"THGuard"="d:\programy\TrojanHunter 4.2\THGuard.exe" [2005-02-19 1089024]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKLM\~\startupfolder\C:^Documents and Settings^xp user^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
path=c:\documents and settings\xp user\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
backup=c:\windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2007-10-10 17:51 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
2009-08-31 11:06 2356088 ----a-w- c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
2008-11-26 07:23 881664 ----a-w- d:\programy\Ares\Ares.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Update Checker]
2008-12-11 11:45 114688 ----a-w- c:\program files\ASUS\ASUSUpdate\UpdateChecker\UpdateChecker.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cpu Level Up help]
2007-11-30 18:03 881152 ----a-w- c:\program files\ASUS\AI Suite\CpuLevelUpHelp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-04-23 13:51 691656 ----a-w- d:\programy\DAEMON Tools Lite\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 09:44 31072 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HDAudDeck]
2009-01-09 05:49 33570816 ----a-r- c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-06-15 14:33 141624 ----a-w- d:\programy\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 01:42 1695232 ------w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 13:57 153136 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2010-01-11 21:17 13666408 ----a-w- c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2010-01-11 21:17 110696 ----a-w- c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-18 20:16 421888 ----a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RGSC]
2009-09-04 17:51 306088 ----a-w- d:\hry\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Six Engine]
2009-02-10 19:28 5993984 ----a-w- c:\program files\ASUS\EPU-6 Engine\SixEngine.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-03-09 08:02 26100520 ----a-r- c:\program files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Turbo Key]
2009-02-17 15:29 1753600 ----a-w- c:\program files\ASUS\Turbo Key\TurboKey.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TurboV]
2009-02-05 08:51 5384192 ----a-w- c:\program files\ASUS\TurboV\TurboV.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"FLEXnet Licensing Service"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"d:\\Hry\\Gears of War\\Binaries\\WarGame-G4WLive.exe"=
"d:\\Hry\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"d:\\Hry\\Rockstar Games\\Grand Theft Auto IV\\LaunchGTAIV.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\FlashFXP\\FlashFXP.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"d:\\Hry\\Steam\\Steam.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"d:\\Hry\\Grand Theft Auto IV - Episodes From Liberty City\\EFLC.exe"=
"c:\\Program Files\\Ubisoft\\Ubisoft Game Launcher\\UbisoftGameLauncher.exe"=
"d:\\Hry\\Ubisoft\\Tom Clancy's Splinter Cell Conviction\\src\\system\\conviction_game.exe"=
"d:\\Hry\\Ubisoft\\Tom Clancy's Splinter Cell Conviction\\src\\system\\gu.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\Programy\\iTunes\\iTunes.exe"=
"d:\\Hry\\Singularity(TM)\\Binaries\\Singularity.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"d:\\Hry\\ArmA 2 Operation Arrowhead DEMO\\ArmA2OA_Demo.exe"=
"d:\\Hry\\Steam\\steamapps\\deadnight_warrior_sk\\counter-strike\\hl.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"11660:TCP"= 11660:TCP:BitComet 11660 TCP
"11660:UDP"= 11660:UDP:BitComet 11660 UDP

R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [19.3.2009 11:44 107256]
R2 AsSysCtrlService;ASUS System Control Service;c:\program files\ASUS\AsSysCtrlService\1.00.00\AsSysCtrlService.exe [28.8.2008 11:23 86016]
R2 DvmMDES;DeviceVM Meta Data Export Service;c:\asus.sys\config\DVMExportService.exe [26.11.2008 10:36 323584]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [19.3.2009 11:44 731840]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [30.9.2009 7:43 222456]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [28.8.2008 11:22 993280]
S3 s115bus;Sony Ericsson Device 115 driver (WDM);c:\windows\system32\drivers\s115bus.sys [23.4.2007 14:54 83208]
S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;c:\windows\system32\drivers\s115mdfl.sys [23.4.2007 14:54 15112]
S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;c:\windows\system32\drivers\s115mdm.sys [23.4.2007 14:54 108680]
S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s115mgmt.sys [23.4.2007 13:54 100488]
S3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;c:\windows\system32\drivers\s115obex.sys [23.4.2007 13:54 98568]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [28.8.2008 18:29 721904]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - MCHINJDRV
*Deregistered* - bjlxa
*Deregistered* - mchInjDrv
.
Contents of the 'Scheduled Tasks' folder

2010-07-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Download all with Free Download Manager - file://d:\programy\Free Download Manager\dlall.htm
IE: Download selected with Free Download Manager - file://d:\programy\Free Download Manager\dlselected.htm
IE: Download video with Free Download Manager - file://d:\programy\Free Download Manager\dlfvideo.htm
IE: Download with Free Download Manager - file://d:\programy\Free Download Manager\dllink.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: cyber-deployment.com
Trusted Zone: download-soft-package.com
Trusted Zone: download-software-package.com
Trusted Zone: get-key-se10.com
Trusted Zone: is-software-download.com
Trusted Zone: cyber-deployment.com
Trusted Zone: get-key-se10.com
FF - ProfilePath - c:\documents and settings\xp user\Application Data\Mozilla\Firefox\Profiles\waf4tiw4.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.sk
FF - component: c:\documents and settings\xp user\Application Data\Mozilla\Firefox\Profiles\waf4tiw4.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\xp user\Application Data\Mozilla\Firefox\Profiles\waf4tiw4.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll
FF - plugin: c:\documents and settings\xp user\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\xp user\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: d:\programy\iTunes\Mozilla Plugins\npitunes.dll
FF - plugin: d:\programy\Picasa3\npPicasa3.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-ICQ - d:\programy\ICQ7.0\ICQ.exe
MSConfigStartUp-nwiz - nwiz.exe
AddRemove-Half-Life - d:\hry\Half-Life\Uninst.isu
AddRemove-NFS Carbon - d:\hry\NEEDFO~4\Uninstall NFSCSK.exe
AddRemove-NVIDIA Display Control Panel - c:\program files\NVIDIA Corporation\Uninstall\nvuninst.exe
AddRemove-stalker_2215_svk_by_cracken - d:\hry\S.T.A.L.K.E.R. - Shadow of Chernobyl\Uninstal.exe
AddRemove-{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1 - d:\hry\BRS\unins000.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-23 08:57
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\c:\docume~1\XPUSER~1\LOCALS~1\Temp\mc22.tmp"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bjlxa]

.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1645522239-527237240-1801674531-1003\Software\SecuROM\License information*]
"datasecu"=hex:98,96,41,17,0d,11,f0,f2,1b,50,79,f6,70,10,35,fa,0f,a9,01,66,3c,
ae,5f,1f,12,e1,ba,77,3b,c6,5b,61,a8,58,23,9c,8a,17,bc,7a,94,80,4a,37,7c,7a,\
"rkeysecu"=hex:41,b6,5d,01,3e,41,79,ba,28,80,ff,9d,66,52,28,89
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(3124)
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-07-23 09:00:31 - machine was rebooted
ComboFix-quarantined-files.txt 2010-07-23 07:00
ComboFix2.txt 2010-03-10 19:02
ComboFix3.txt 2010-03-09 22:09
ComboFix4.txt 2009-11-02 21:37

Pre-Run: 13 215 125 504 bytes free
Post-Run: 19 adresárov, 14 124 572 672 voľných bajtov

- - End Of File - - 8A23ECF4DF733635B2230FC541FE31A4

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15663
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Vírusy - trójske kone + log z RSIT

#6 Příspěvek od JaRon »

OKi - druhe kolo :) zopakuj akciu 0 novy CFS:

Kód: Vybrat vše

File::
c:\windows\system32\drivers\bjlxa.sys
c:\docume~1\XPUSER~1\LOCALS~1\Temp\mc22.tmp

Driver::
bjlxa
mchInjDrv


FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

Lukas666
Návštěvník
Návštěvník
Příspěvky: 89
Registrován: 02 lis 2009 17:19

Re: Vírusy - trójske kone + log z RSIT

#7 Příspěvek od Lukas666 »

ComboFix 10-07-22.01 - xp user 23.07.2010 9:33.5.4 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.3327.2702 [GMT 2:00]
Running from: c:\documents and settings\xp user\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\xp user\Desktop\CFScript.txt
AV: ESET Smart Security 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}

FILE ::
"c:\docume~1\XPUSER~1\LOCALS~1\Temp\mc22.tmp"
"c:\windows\system32\drivers\bjlxa.sys"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\driVERs\bjlxa.sys

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_BJLXA
-------\Legacy_MCHINJDRV
-------\Service_bjlxa
-------\Service_mchInjDrv


((((((((((((((((((((((((( Files Created from 2010-06-23 to 2010-07-23 )))))))))))))))))))))))))))))))
.

2010-07-22 19:39 . 2010-07-22 19:39 -------- d--h--w- c:\windows\system32\GroupPolicy
2010-07-21 09:40 . 2010-07-21 09:40 -------- d-----w- c:\documents and settings\xp user\Local Settings\Application Data\ArmA 2 OA DEMO
2010-07-21 07:05 . 2010-06-29 22:13 52224 ----a-w- c:\documents and settings\xp user\Application Data\Mozilla\Firefox\Profiles\waf4tiw4.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll
2010-07-21 07:05 . 2010-06-29 22:13 101376 ----a-w- c:\documents and settings\xp user\Application Data\Mozilla\Firefox\Profiles\waf4tiw4.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll
2010-07-16 07:47 . 2010-07-16 07:47 -------- d-----w- c:\windows\E10DB5DAE57640EAA7FC1CB2A7B283A6.TMP
2010-07-15 18:07 . 2010-07-15 19:25 -------- d-----w- C:\Downloads
2010-07-11 11:02 . 2010-07-11 11:02 -------- d-----w- c:\program files\iPod
2010-07-11 11:02 . 2010-07-11 11:02 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-07-11 10:58 . 2010-07-11 10:59 -------- d-----w- c:\program files\QuickTime
2010-07-11 10:54 . 2010-07-11 10:54 72504 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
2010-07-11 10:52 . 2010-07-11 10:52 -------- d-----w- c:\program files\Safari
2010-07-11 10:51 . 2010-07-11 10:51 71992 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.33.16.0\SetupAdmin.exe
2010-06-23 10:19 . 2001-08-17 09:48 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2010-06-23 10:19 . 2001-08-17 09:48 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2010-06-23 10:19 . 2008-04-13 20:15 10368 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2010-06-23 10:19 . 2008-04-13 20:15 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-23 03:52 . 2009-11-02 20:46 -------- d-----w- c:\program files\trend micro
2010-07-22 14:59 . 2010-07-21 17:12 20 ----a-w- c:\documents and settings\NetworkService\Application Data\hwzypv.dat
2010-07-21 20:02 . 2009-08-29 19:10 -------- d-----w- c:\documents and settings\xp user\Application Data\FileZilla
2010-07-20 19:51 . 2009-09-24 05:20 -------- d-----w- c:\documents and settings\xp user\Application Data\Skype
2010-07-20 17:58 . 2009-09-24 06:06 -------- d-----w- c:\documents and settings\xp user\Application Data\skypePM
2010-07-16 07:47 . 2010-01-08 22:23 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-07-16 07:43 . 2008-08-28 09:22 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-07-15 19:15 . 2010-03-16 12:23 -------- d-----w- c:\documents and settings\xp user\Application Data\Free Download Manager
2010-07-15 18:02 . 2009-08-31 12:01 -------- d-----w- c:\documents and settings\xp user\Application Data\DC++
2010-07-14 22:03 . 2008-08-28 10:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-07-11 11:49 . 2010-02-27 11:47 -------- d-----w- c:\documents and settings\xp user\Application Data\Apple Computer
2010-07-11 11:02 . 2010-02-27 11:45 -------- d-----w- c:\program files\Common Files\Apple
2010-07-11 10:56 . 2009-08-29 19:59 -------- d-----w- c:\program files\Bonjour
2010-07-02 14:32 . 2009-08-28 14:19 -------- d-----w- c:\program files\Opera
2010-06-21 15:09 . 2010-06-21 15:09 -------- d-----w- c:\documents and settings\xp user\Application Data\TS3Client
2010-06-19 13:43 . 2010-06-19 13:43 -------- d-----w- c:\program files\FLV Player X
2010-06-14 14:31 . 2008-08-28 09:07 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-12 18:38 . 2010-06-12 18:38 50354 ----a-w- c:\documents and settings\xp user\Application Data\Facebook\uninstall.exe
2010-06-12 18:38 . 2010-06-12 18:38 -------- d-----w- c:\documents and settings\xp user\Application Data\Facebook
2010-06-09 10:45 . 2010-06-09 10:45 5591040 ----a-w- c:\documents and settings\xp user\Application Data\Facebook\npfbplugin_1_0_3.dll
2010-06-05 15:30 . 2010-05-09 17:11 -------- d-----w- c:\documents and settings\xp user\Application Data\Mumble
2010-05-18 14:35 . 2010-05-18 14:35 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 14:35 . 2010-05-18 14:35 197920 ----a-w- c:\windows\system32\dnssdX.dll
2010-05-18 14:35 . 2010-05-18 14:35 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-05-15 08:50 . 2009-08-29 10:35 214808 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-05-15 08:35 . 2009-08-29 10:36 139920 ----a-w- c:\windows\system32\drivers\pnkbstrk.sys
2010-05-02 10:04 . 2009-06-09 19:33 1860352 ----a-w- c:\windows\system32\win32k.sys
.

((((((((((((((((((((((((((((( SnapShot_2010-07-23_06.57.26 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-14 12:00 . 2010-07-23 06:54 68156 c:\windows\system32\perfc009.dat
+ 2008-04-14 12:00 . 2010-07-23 06:58 68156 c:\windows\system32\perfc009.dat
+ 2008-04-14 12:00 . 2010-07-23 06:58 435260 c:\windows\system32\perfh009.dat
- 2008-04-14 12:00 . 2010-07-23 06:54 435260 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-01-11 13666408]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-03-19 2029640]
"SNPSTD2"="c:\windows\vsnpstd2.exe" [2004-06-10 286720]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"36X Raid Configurer"="c:\windows\system32\xRaidSetup.exe" [2007-11-19 1970176]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKLM\~\startupfolder\C:^Documents and Settings^xp user^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
path=c:\documents and settings\xp user\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
backup=c:\windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2007-10-10 17:51 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
2009-08-31 11:06 2356088 ----a-w- c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
2008-11-26 07:23 881664 ----a-w- d:\programy\Ares\Ares.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Update Checker]
2008-12-11 11:45 114688 ----a-w- c:\program files\ASUS\ASUSUpdate\UpdateChecker\UpdateChecker.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cpu Level Up help]
2007-11-30 18:03 881152 ----a-w- c:\program files\ASUS\AI Suite\CpuLevelUpHelp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-04-23 13:51 691656 ----a-w- d:\programy\DAEMON Tools Lite\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 09:44 31072 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HDAudDeck]
2009-01-09 05:49 33570816 ----a-r- c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-06-15 14:33 141624 ----a-w- d:\programy\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 01:42 1695232 ------w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 13:57 153136 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2010-01-11 21:17 13666408 ----a-w- c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2010-01-11 21:17 110696 ----a-w- c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-18 20:16 421888 ----a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RGSC]
2009-09-04 17:51 306088 ----a-w- d:\hry\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Six Engine]
2009-02-10 19:28 5993984 ----a-w- c:\program files\ASUS\EPU-6 Engine\SixEngine.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-03-09 08:02 26100520 ----a-r- c:\program files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Turbo Key]
2009-02-17 15:29 1753600 ----a-w- c:\program files\ASUS\Turbo Key\TurboKey.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TurboV]
2009-02-05 08:51 5384192 ----a-w- c:\program files\ASUS\TurboV\TurboV.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"FLEXnet Licensing Service"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"d:\\Hry\\Gears of War\\Binaries\\WarGame-G4WLive.exe"=
"d:\\Hry\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"d:\\Hry\\Rockstar Games\\Grand Theft Auto IV\\LaunchGTAIV.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\FlashFXP\\FlashFXP.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"d:\\Hry\\Steam\\Steam.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"d:\\Hry\\Grand Theft Auto IV - Episodes From Liberty City\\EFLC.exe"=
"c:\\Program Files\\Ubisoft\\Ubisoft Game Launcher\\UbisoftGameLauncher.exe"=
"d:\\Hry\\Ubisoft\\Tom Clancy's Splinter Cell Conviction\\src\\system\\conviction_game.exe"=
"d:\\Hry\\Ubisoft\\Tom Clancy's Splinter Cell Conviction\\src\\system\\gu.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\Programy\\iTunes\\iTunes.exe"=
"d:\\Hry\\Singularity(TM)\\Binaries\\Singularity.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"d:\\Hry\\ArmA 2 Operation Arrowhead DEMO\\ArmA2OA_Demo.exe"=
"d:\\Hry\\Steam\\steamapps\\deadnight_warrior_sk\\counter-strike\\hl.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"11660:TCP"= 11660:TCP:BitComet 11660 TCP
"11660:UDP"= 11660:UDP:BitComet 11660 UDP

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [28.8.2008 18:29 721904]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [19.3.2009 11:44 107256]
R2 AsSysCtrlService;ASUS System Control Service;c:\program files\ASUS\AsSysCtrlService\1.00.00\AsSysCtrlService.exe [28.8.2008 11:23 86016]
R2 DvmMDES;DeviceVM Meta Data Export Service;c:\asus.sys\config\DVMExportService.exe [26.11.2008 10:36 323584]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [19.3.2009 11:44 731840]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [30.9.2009 7:43 222456]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [28.8.2008 11:22 993280]
S3 s115bus;Sony Ericsson Device 115 driver (WDM);c:\windows\system32\drivers\s115bus.sys [23.4.2007 14:54 83208]
S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;c:\windows\system32\drivers\s115mdfl.sys [23.4.2007 14:54 15112]
S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;c:\windows\system32\drivers\s115mdm.sys [23.4.2007 14:54 108680]
S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s115mgmt.sys [23.4.2007 13:54 100488]
S3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;c:\windows\system32\drivers\s115obex.sys [23.4.2007 13:54 98568]
.
Contents of the 'Scheduled Tasks' folder

2010-07-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Download all with Free Download Manager - file://d:\programy\Free Download Manager\dlall.htm
IE: Download selected with Free Download Manager - file://d:\programy\Free Download Manager\dlselected.htm
IE: Download video with Free Download Manager - file://d:\programy\Free Download Manager\dlfvideo.htm
IE: Download with Free Download Manager - file://d:\programy\Free Download Manager\dllink.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: cyber-deployment.com
Trusted Zone: download-soft-package.com
Trusted Zone: download-software-package.com
Trusted Zone: get-key-se10.com
Trusted Zone: is-software-download.com
Trusted Zone: cyber-deployment.com
Trusted Zone: get-key-se10.com
FF - ProfilePath - c:\documents and settings\xp user\Application Data\Mozilla\Firefox\Profiles\waf4tiw4.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.sk
FF - component: c:\documents and settings\xp user\Application Data\Mozilla\Firefox\Profiles\waf4tiw4.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\xp user\Application Data\Mozilla\Firefox\Profiles\waf4tiw4.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll
FF - plugin: c:\documents and settings\xp user\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\xp user\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: d:\programy\iTunes\Mozilla Plugins\npitunes.dll
FF - plugin: d:\programy\Picasa3\npPicasa3.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-23 09:37
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spof.sys >>UNKNOWN [0x8A8E5938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xb810cf28
\Driver\ACPI -> ACPI.sys @ 0xb7e66cb8
\Driver\atapi -> atapi.sys @ 0xb7d70b40
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: Realtek RTL8139 Family PCI Fast Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0xb7c4fbd4
PacketIndicateHandler -> NDIS.sys @ 0xb7c3da0d
SendHandler -> NDIS.sys @ 0xb7c51b40
user & kernel MBR OK

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1645522239-527237240-1801674531-1003\Software\SecuROM\License information*]
"datasecu"=hex:98,96,41,17,0d,11,f0,f2,1b,50,79,f6,70,10,35,fa,0f,a9,01,66,3c,
ae,5f,1f,12,e1,ba,77,3b,c6,5b,61,a8,58,23,9c,8a,17,bc,7a,94,80,4a,37,7c,7a,\
"rkeysecu"=hex:41,b6,5d,01,3e,41,79,ba,28,80,ff,9d,66,52,28,89
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(2616)
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-07-23 09:39:29 - machine was rebooted
ComboFix-quarantined-files.txt 2010-07-23 07:39
ComboFix2.txt 2010-07-23 07:00
ComboFix3.txt 2010-03-10 19:02
ComboFix4.txt 2010-03-09 22:09
ComboFix5.txt 2010-07-23 07:32

Pre-Run: 14 109 528 064 bytes free
Post-Run: 14 098 120 704 bytes free

- - End Of File - - 9F5AB7925F8DC9B8654C27B671C4EA8F

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15663
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Vírusy - trójske kone + log z RSIT

#8 Příspěvek od JaRon »

OKi - prescanuj PC s http://www.viry.cz/forum/viewtopic.php?f=29&t=101984 a napis ako sa sprava PC :???:
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

Lukas666
Návštěvník
Návštěvník
Příspěvky: 89
Registrován: 02 lis 2009 17:19

Re: Vírusy - trójske kone + log z RSIT

#9 Příspěvek od Lukas666 »

Vyzerá to byť okej.

Ďakujem opať veľmi pekne.

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15663
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Vírusy - trójske kone + log z RSIT

#10 Příspěvek od JaRon »

rado sa stalo :)
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

Odpovědět