Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Malware juzjf.exe

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
VanaFrantisek
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 13 lis 2010 20:35

Re: Malware juzjf.exe

#16 Příspěvek od VanaFrantisek »

mechanika odstraněna a mbr stejné
Po SPTD a Defogger
:arrow:
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.0.6002 Disk: MAXTOR_S rev.4.AA -> Harddisk0\DR0 -> \Device\00000051

device: opened successfully
user: MBR read successfully

Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll storport.sys nvstor32.sys win32k.sys
C:\Windows\system32\DRIVERS\nvstor32.sys NVIDIA Corporation NVIDIA nForce(TM) SATA Driver
1 ntkrnlpa!IofCallDriver[0x82089962] -> \Device\Harddisk0\DR0[0x85F0DAC8]
3 CLASSPNP[0x82FA78B3] -> ntkrnlpa!IofCallDriver[0x82089962] -> [0x8457D2B8]
5 acpi[0x806176BC] -> ntkrnlpa!IofCallDriver[0x82089962] -> \Device\00000051[0x84FB2B88]
kernel: MBR read successfully
user & kernel MBR OK

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Malware juzjf.exe

#17 Příspěvek od vyosek »

Dejte novy log z RSIT a napiste jak se chova PC, ci jsou nejake problemy...
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

VanaFrantisek
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 13 lis 2010 20:35

Re: Malware juzjf.exe

#18 Příspěvek od VanaFrantisek »

Už se chová normálně... :worship: :worship: :worship:
tady se mě to nevleze http://leteckaposta.cz/301879509

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Malware juzjf.exe

#19 Příspěvek od vyosek »

Ja jej sem pro prehlednost vlozim rozdeleny do vice prispevku

Logfile of random's system information tool 1.08 (written by random/random)
Run by Pečimuthovi at 2010-11-14 21:49:00
Microsoft® Windows Vista™ Home Basic Service Pack 2
System drive C: has 66 GB (66%) free of 100 GB
Total RAM: 1919 MB (51% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:49:33, on 14.11.2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18975)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\totalcmd\TOTALCMD.EXE
C:\Windows\system32\conime.exe
C:\Windows\system32\SearchFilterHost.exe
D:\Stažené soubory\RSIT(2).exe
C:\Program Files\trend micro\Pečimuthovi.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatche ... tbid=60446
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://googleure.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.myheritage.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=fbpage&s= ... Terms}&f=4
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: MHURLSearchHook Class - {1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48} - C:\Program Files\Family Toolbar\tbhelper.dll (file missing)
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (file missing)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [MobileConnect] %programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
O23 - Service: Vodafone Mobile Connect Service (VMCService) - Vodafone - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe

--
End of file - 6090 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-26 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-18 1008184]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-26 31016]
"amd_dc_opt"=C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe [2008-07-22 77824]
"MobileConnect"=C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe [2008-11-04 2087424]
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2010-09-07 2838912]
"ZoneAlarm Client"=C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe [2010-09-02 1043968]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-26 2210608]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2010-11-14 19:38:05 ----D---- C:\Users\Pečimuthovi\AppData\Roaming\Malwarebytes
2010-11-14 19:37:52 ----A---- C:\Windows\system32\drivers\mbamswissarmy.sys
2010-11-14 19:37:51 ----D---- C:\ProgramData\Malwarebytes
2010-11-14 19:37:51 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-11-14 19:37:51 ----A---- C:\Windows\system32\drivers\mbam.sys
2010-11-14 18:06:35 ----D---- C:\_OTM
2010-11-14 10:56:53 ----A---- C:\Windows\system32\vsregexp.dll
2010-11-14 10:56:50 ----A---- C:\Windows\system32\zlcommdb.dll
2010-11-14 10:56:50 ----A---- C:\Windows\system32\zlcomm.dll
2010-11-14 10:56:43 ----A---- C:\Windows\system32\vswmi.dll
2010-11-14 10:56:41 ----A---- C:\Windows\system32\zpeng25.dll
2010-11-14 10:56:41 ----A---- C:\Windows\system32\vsxml.dll
2010-11-14 10:56:40 ----A---- C:\Windows\system32\vspubapi.dll
2010-11-14 10:56:40 ----A---- C:\Windows\system32\vsmonapi.dll
2010-11-14 10:56:40 ----A---- C:\Windows\system32\vsdata.dll
2010-11-14 10:56:36 ----D---- C:\Windows\system32\ZoneLabs
2010-11-14 10:56:36 ----A---- C:\Windows\system32\drivers\vsdatant.sys
2010-11-14 10:56:35 ----D---- C:\Program Files\Zone Labs
2010-11-14 10:55:51 ----D---- C:\ProgramData\CheckPoint
2010-11-14 10:55:50 ----D---- C:\Windows\Internet Logs
2010-11-14 10:55:50 ----A---- C:\Windows\system32\vsutil.dll
2010-11-14 10:55:50 ----A---- C:\Windows\system32\vsinit.dll
2010-11-14 10:49:55 ----A---- C:\Windows\system32\drivers\aswSP.sys
2010-11-14 10:49:55 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2010-11-14 10:49:54 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2010-11-14 10:49:54 ----A---- C:\Windows\system32\drivers\aswRdr.sys
2010-11-14 10:49:53 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2010-11-14 10:49:25 ----A---- C:\Windows\system32\aswBoot.exe
2010-11-14 10:49:17 ----D---- C:\ProgramData\Alwil Software
2010-11-14 10:49:17 ----D---- C:\Program Files\Alwil Software
2010-11-14 09:37:21 ----D---- C:\Program Files\trend micro
2010-11-14 09:37:20 ----D---- C:\rsit
2010-11-13 19:26:19 ----RSHD---- C:\RECYCLER
2010-11-08 21:02:11 ----D---- C:\Users\Pečimuthovi\AppData\Roaming\Vodafone
2010-11-08 21:01:40 ----D---- C:\ProgramData\Vodafone
2010-11-08 21:01:34 ----D---- C:\Program Files\Vodafone
2010-11-08 20:48:42 ----A---- C:\Windows\ntbtlog.txt
2010-11-07 10:50:39 ----D---- C:\Windows\system32\vi-VN
2010-11-07 10:50:39 ----D---- C:\Windows\system32\eu-ES
2010-11-07 10:50:39 ----D---- C:\Windows\system32\ca-ES
2010-11-07 10:31:10 ----A---- C:\Windows\system32\NlsLexicons0007.dll
2010-11-07 10:31:06 ----A---- C:\Windows\system32\SLsvc.exe
2010-11-07 10:31:06 ----A---- C:\Windows\system32\SLCExt.dll
2010-11-07 10:31:03 ----A---- C:\Windows\system32\FunctionDiscoveryFolder.dll
2010-11-07 10:31:03 ----A---- C:\Windows\system32\DevicePairingWizard.exe
2010-11-07 10:31:00 ----A---- C:\Windows\system32\NlsLexicons0009.dll
2010-11-07 10:30:57 ----A---- C:\Windows\system32\mssrch.dll
2010-11-07 10:30:55 ----A---- C:\Windows\system32\drivers\spsys.sys
2010-11-07 10:30:54 ----A---- C:\Windows\system32\tquery.dll
2010-11-07 10:30:53 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
2010-11-07 10:30:53 ----A---- C:\Windows\system32\drivers\hdaudbus.sys
2010-11-07 10:30:52 ----A---- C:\Windows\system32\scavenge.dll
2010-11-07 10:30:50 ----A---- C:\Windows\system32\msi.dll
2010-11-07 10:30:49 ----A---- C:\Windows\system32\imapi2fs.dll
2010-11-07 10:30:48 ----A---- C:\Windows\system32\WscEapPr.dll
2010-11-07 10:30:48 ----A---- C:\Windows\system32\wcnwiz2.dll
2010-11-07 10:30:48 ----A---- C:\Windows\system32\sysmain.dll
2010-11-07 10:30:46 ----A---- C:\Windows\system32\icardagt.exe
2010-11-07 10:30:45 ----A---- C:\Windows\system32\EhStorShell.dll
2010-11-07 10:30:43 ----A---- C:\Windows\system32\spreview.exe
2010-11-07 10:30:43 ----A---- C:\Windows\system32\spinstall.exe
2010-11-07 10:30:43 ----A---- C:\Windows\system32\drmv2clt.dll
2010-11-07 10:30:42 ----A---- C:\Windows\system32\spwizui.dll
2010-11-07 10:30:42 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2010-11-07 10:30:41 ----A---- C:\Windows\system32\p2psvc.dll
2010-11-07 10:30:40 ----A---- C:\Windows\system32\SearchIndexer.exe
2010-11-07 10:30:40 ----A---- C:\Windows\system32\mssvp.dll
2010-11-07 10:30:39 ----A---- C:\Windows\system32\mssphtb.dll
2010-11-07 10:30:39 ----A---- C:\Windows\system32\mssph.dll
2010-11-07 10:30:39 ----A---- C:\Windows\system32\imapi2.dll
2010-11-07 10:30:38 ----A---- C:\Windows\system32\sdohlp.dll
2010-11-07 10:30:37 ----A---- C:\Windows\system32\IMJP10K.DLL
2010-11-07 10:30:37 ----A---- C:\Windows\system32\esent.dll
2010-11-07 10:30:36 ----A---- C:\Windows\system32\sperror.dll
2010-11-07 10:30:36 ----A---- C:\Windows\system32\DevicePairing.dll
2010-11-07 10:30:35 ----A---- C:\Windows\system32\wevtsvc.dll
2010-11-07 10:30:35 ----A---- C:\Windows\system32\SLC.dll
2010-11-07 10:30:35 ----A---- C:\Windows\system32\korwbrkr.dll
2010-11-07 10:30:34 ----A---- C:\Windows\system32\msshsq.dll
2010-11-07 10:30:31 ----A---- C:\Windows\system32\msjet40.dll
2010-11-07 10:30:31 ----A---- C:\Windows\system32\MPSSVC.dll
2010-11-07 10:30:30 ----A---- C:\Windows\system32\Query.dll
2010-11-07 10:30:30 ----A---- C:\Windows\system32\qmgr.dll
2010-11-07 10:30:29 ----A---- C:\Windows\system32\P2PGraph.dll
2010-11-07 10:30:29 ----A---- C:\Windows\system32\msexch40.dll
2010-11-07 10:30:29 ----A---- C:\Windows\system32\diagperf.dll
2010-11-07 10:30:28 ----A---- C:\Windows\system32\srchadmin.dll
2010-11-07 10:30:28 ----A---- C:\Windows\system32\ntdll.dll
2010-11-07 10:30:28 ----A---- C:\Windows\system32\IasMigReader.exe
2010-11-07 10:30:27 ----A---- C:\Windows\system32\winload.exe
2010-11-07 10:30:27 ----A---- C:\Windows\system32\mblctr.exe
2010-11-07 10:30:26 ----A---- C:\Windows\system32\uDWM.dll
2010-11-07 10:30:26 ----A---- C:\Windows\system32\mmc.exe
2010-11-07 10:30:26 ----A---- C:\Windows\system32\EncDec.dll
2010-11-07 10:30:25 ----A---- C:\Windows\system32\riched20.dll
2010-11-07 10:30:25 ----A---- C:\Windows\system32\IasMigPlugin.dll
2010-11-07 10:30:25 ----A---- C:\Windows\system32\dfsr.exe
2010-11-07 10:30:24 ----A---- C:\Windows\system32\fdBth.dll
2010-11-07 10:30:23 ----A---- C:\Windows\system32\RacEngn.dll
2010-11-07 10:30:23 ----A---- C:\Windows\system32\kernel32.dll
2010-11-07 10:30:22 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2010-11-07 10:30:22 ----A---- C:\Windows\system32\SearchFilterHost.exe
2010-11-07 10:30:22 ----A---- C:\Windows\system32\milcore.dll
2010-11-07 10:30:22 ----A---- C:\Windows\system32\EhStorAPI.dll
2010-11-07 10:30:21 ----A---- C:\Windows\system32\spoolss.dll
2010-11-07 10:30:21 ----A---- C:\Windows\system32\schedsvc.dll
2010-11-07 10:30:21 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2010-11-07 10:30:21 ----A---- C:\Windows\system32\CertEnroll.dll
2010-11-07 10:30:14 ----A---- C:\Windows\system32\msjtes40.dll
2010-11-07 10:30:13 ----A---- C:\Windows\system32\msvcp60.dll
2010-11-07 10:30:13 ----A---- C:\Windows\system32\gpedit.dll
2010-11-07 10:30:12 ----A---- C:\Windows\system32\WinSAT.exe
2010-11-07 10:30:12 ----A---- C:\Windows\system32\infocardapi.dll
2010-11-07 10:30:12 ----A---- C:\Windows\system32\es.dll
2010-11-07 10:30:10 ----A---- C:\Windows\system32\Magnify.exe
2010-11-07 10:30:09 ----A---- C:\Windows\system32\mstext40.dll
2010-11-07 10:30:09 ----A---- C:\Windows\system32\drivers\ntfs.sys
2010-11-07 10:30:09 ----A---- C:\Windows\system32\advapi32.dll
2010-11-07 10:30:08 ----A---- C:\Windows\system32\WMPhoto.dll
2010-11-07 10:30:08 ----A---- C:\Windows\system32\WebClnt.dll
2010-11-07 10:30:08 ----A---- C:\Windows\system32\msexcl40.dll
2010-11-07 10:30:07 ----A---- C:\Windows\system32\slwmi.dll
2010-11-07 10:30:07 ----A---- C:\Windows\system32\comsvcs.dll
2010-11-07 10:30:06 ----A---- C:\Windows\system32\WindowsAnytimeUpgradeCPL.dll
2010-11-07 10:30:06 ----A---- C:\Windows\system32\msxbde40.dll
2010-11-07 10:30:05 ----A---- C:\Windows\system32\vssapi.dll
2010-11-07 10:30:04 ----A---- C:\Windows\system32\authui.dll
2010-11-07 10:30:03 ----A---- C:\Windows\system32\msrepl40.dll
2010-11-07 10:30:02 ----A---- C:\Windows\system32\propsys.dll
2010-11-07 10:30:02 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2010-11-07 10:30:02 ----A---- C:\Windows\system32\newdev.dll
2010-11-07 10:30:02 ----A---- C:\Windows\system32\iasrecst.dll
2010-11-07 10:30:02 ----A---- C:\Windows\system32\gpsvc.dll
2010-11-07 10:30:01 ----A---- C:\Windows\system32\rpcss.dll
2010-11-07 10:30:01 ----A---- C:\Windows\system32\eudcedit.exe
2010-11-07 10:30:01 ----A---- C:\Windows\system32\crypt32.dll
2010-11-07 10:30:01 ----A---- C:\Windows\explorer.exe
2010-11-07 10:30:00 ----A---- C:\Windows\system32\setupapi.dll
2010-11-07 10:29:59 ----A---- C:\Windows\system32\mspbde40.dll
2010-11-07 10:29:59 ----A---- C:\Windows\system32\d3d9.dll
2010-11-07 10:29:58 ----A---- C:\Windows\system32\msltus40.dll
2010-11-07 10:29:58 ----A---- C:\Windows\system32\davclnt.dll
2010-11-07 10:29:57 ----A---- C:\Windows\system32\shlwapi.dll
2010-11-07 10:29:57 ----A---- C:\Windows\system32\msrd3x40.dll
2010-11-07 10:29:57 ----A---- C:\Windows\system32\msdtctm.dll
2010-11-07 10:29:57 ----A---- C:\Windows\system32\mfc42.dll
2010-11-07 10:29:57 ----A---- C:\Windows\system32\EhStorPwdMgr.dll
2010-11-07 10:29:57 ----A---- C:\Windows\system32\EhStorAuthn.dll
2010-11-07 10:29:56 ----A---- C:\Windows\system32\wevtapi.dll
2010-11-07 10:29:56 ----A---- C:\Windows\system32\photowiz.dll
2010-11-07 10:29:56 ----A---- C:\Windows\system32\nlhtml.dll
2010-11-07 10:29:56 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2010-11-07 10:29:56 ----A---- C:\Windows\system32\browseui.dll
2010-11-07 10:29:55 ----A---- C:\Windows\system32\user32.dll
2010-11-07 10:29:54 ----A---- C:\Windows\system32\samsrv.dll
2010-11-07 10:29:54 ----A---- C:\Windows\system32\ci.dll
2010-11-07 10:29:53 ----A---- C:\Windows\system32\win32spl.dll
2010-11-07 10:29:53 ----A---- C:\Windows\system32\WcnNetsh.dll
2010-11-07 10:29:53 ----A---- C:\Windows\system32\SLCommDlg.dll
2010-11-07 10:29:53 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
2010-11-07 10:29:53 ----A---- C:\Windows\system32\oleaut32.dll
2010-11-07 10:29:53 ----A---- C:\Windows\system32\IKEEXT.DLL
2010-11-07 10:29:52 ----A---- C:\Windows\system32\netshell.dll
2010-11-07 10:29:52 ----A---- C:\Windows\system32\drivers\rdbss.sys
2010-11-07 10:29:52 ----A---- C:\Windows\system32\compcln.exe
2010-11-07 10:29:52 ----A---- C:\Windows\system32\apds.dll
2010-11-07 10:29:51 ----A---- C:\Windows\system32\xmlfilter.dll
2010-11-07 10:29:51 ----A---- C:\Windows\system32\mswstr10.dll
2010-11-07 10:29:51 ----A---- C:\Windows\system32\msctf.dll
2010-11-07 10:29:51 ----A---- C:\Windows\system32\emdmgmt.dll
2010-11-07 10:29:51 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2010-11-07 10:29:51 ----A---- C:\Windows\system32\audiosrv.dll
2010-11-07 10:29:50 ----A---- C:\Windows\system32\VSSVC.exe
2010-11-07 10:29:50 ----A---- C:\Windows\system32\QAGENTRT.DLL
2010-11-07 10:29:50 ----A---- C:\Windows\system32\msvcrt.dll
2010-11-07 10:29:50 ----A---- C:\Windows\system32\gdi32.dll
2010-11-07 10:29:50 ----A---- C:\Windows\system32\drivers\netio.sys
2010-11-07 10:29:49 ----A---- C:\Windows\system32\SLUI.exe
2010-11-07 10:29:49 ----A---- C:\Windows\system32\msrd2x40.dll
2010-11-07 10:29:49 ----A---- C:\Windows\system32\mfc42u.dll
2010-11-07 10:29:49 ----A---- C:\Windows\system32\eapphost.dll
2010-11-07 10:29:48 ----A---- C:\Windows\system32\sqlsrv32.dll
2010-11-07 10:29:48 ----A---- C:\Windows\system32\odbc32.dll
2010-11-07 10:29:48 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
2010-11-07 10:29:47 ----A---- C:\Windows\system32\winresume.exe
2010-11-07 10:29:47 ----A---- C:\Windows\system32\shdocvw.dll
2010-11-07 10:29:47 ----A---- C:\Windows\system32\propdefs.dll
2010-11-07 10:29:47 ----A---- C:\Windows\system32\drivers\usbhub.sys
2010-11-07 10:29:46 ----A---- C:\Windows\system32\wevtutil.exe
2010-11-07 10:29:46 ----A---- C:\Windows\system32\dbgeng.dll
2010-11-07 10:29:45 ----A---- C:\Windows\system32\mssitlb.dll
2010-11-07 10:29:44 ----A---- C:\Windows\system32\WsmSvc.dll
2010-11-07 10:29:44 ----A---- C:\Windows\system32\swprv.dll
2010-11-07 10:29:43 ----A---- C:\Windows\system32\mmcndmgr.dll
2010-11-07 10:29:42 ----A---- C:\Windows\system32\vds.exe
2010-11-07 10:29:42 ----A---- C:\Windows\system32\drvinst.exe
2010-11-07 10:29:42 ----A---- C:\Windows\system32\devmgr.dll
2010-11-07 10:29:41 ----A---- C:\Windows\system32\netlogon.dll
2010-11-07 10:29:41 ----A---- C:\Windows\system32\msscb.dll
2010-11-07 10:29:41 ----A---- C:\Windows\system32\msctfp.dll
2010-11-07 10:29:41 ----A---- C:\Windows\system32\fdBthProxy.dll
2010-11-07 10:29:41 ----A---- C:\Windows\system32\DevicePairingProxy.dll
2010-11-07 10:29:41 ----A---- C:\Windows\system32\BFE.DLL
2010-11-07 10:29:41 ----A---- C:\Windows\system32\adsldpc.dll
2010-11-07 10:29:40 ----A---- C:\Windows\system32\Wldap32.dll
2010-11-07 10:29:40 ----A---- C:\Windows\system32\wcnwiz.dll
2010-11-07 10:29:40 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
2010-11-07 10:29:40 ----A---- C:\Windows\system32\evr.dll
2010-11-07 10:29:39 ----A---- C:\Windows\system32\WMVSDECD.DLL
2010-11-07 10:29:39 ----A---- C:\Windows\system32\WindowsCodecs.dll
2010-11-07 10:29:39 ----A---- C:\Windows\system32\services.exe
2010-11-07 10:29:38 ----A---- C:\Windows\system32\wercon.exe
2010-11-07 10:29:38 ----A---- C:\Windows\system32\wcncsvc.dll
2010-11-07 10:29:38 ----A---- C:\Windows\system32\mimefilt.dll
2010-11-07 10:29:38 ----A---- C:\Windows\system32\drivers\msiscsi.sys
2010-11-07 10:29:38 ----A---- C:\Windows\system32\comdlg32.dll
2010-11-07 10:29:38 ----A---- C:\Windows\system32\adtschema.dll
2010-11-07 10:29:37 ----A---- C:\Windows\system32\taskeng.exe
2010-11-07 10:29:37 ----A---- C:\Windows\system32\rtffilt.dll
2010-11-07 10:29:37 ----A---- C:\Windows\system32\reg.exe
2010-11-07 10:29:37 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2010-11-07 10:29:37 ----A---- C:\Windows\system32\mswdat10.dll
2010-11-07 10:29:37 ----A---- C:\Windows\system32\msjter40.dll
2010-11-07 10:29:37 ----A---- C:\Windows\system32\msdtcprx.dll
2010-11-07 10:29:37 ----A---- C:\Windows\system32\ipsmsnap.dll
2010-11-07 10:29:37 ----A---- C:\Windows\system32\certcli.dll
2010-11-07 10:29:36 ----A---- C:\Windows\system32\WMNetMgr.dll
2010-11-07 10:29:36 ----A---- C:\Windows\system32\w32time.dll
2010-11-07 10:29:36 ----A---- C:\Windows\system32\umpnpmgr.dll
2010-11-07 10:29:36 ----A---- C:\Windows\system32\dnsapi.dll
2010-11-07 10:29:36 ----A---- C:\Windows\system32\certutil.exe
2010-11-07 10:29:35 ----A---- C:\Windows\system32\msshooks.dll
2010-11-07 10:29:35 ----A---- C:\Windows\system32\msscntrs.dll
2010-11-07 10:29:35 ----A---- C:\Windows\system32\IPSECSVC.DLL
2010-11-07 10:29:35 ----A---- C:\Windows\system32\drivers\usbport.sys
2010-11-07 10:29:35 ----A---- C:\Windows\system32\bthserv.dll
2010-11-07 10:29:35 ----A---- C:\Windows\system32\bcrypt.dll
2010-11-07 10:29:34 ----A---- C:\Windows\system32\TsWpfWrp.exe
2010-11-07 10:29:34 ----A---- C:\Windows\system32\rsaenh.dll
2010-11-07 10:29:34 ----A---- C:\Windows\system32\msstrc.dll
2010-11-07 10:29:34 ----A---- C:\Windows\system32\msihnd.dll
2010-11-07 10:29:34 ----A---- C:\Windows\system32\MMDevAPI.dll
2010-11-07 10:29:34 ----A---- C:\Windows\system32\drivers\ndis.sys
2010-11-07 10:29:33 ----A---- C:\Windows\system32\netapi32.dll
2010-11-07 10:29:33 ----A---- C:\Windows\system32\mtxclu.dll
2010-11-07 10:29:33 ----A---- C:\Windows\system32\mscories.dll
2010-11-07 10:29:33 ----A---- C:\Windows\system32\inetpp.dll
2010-11-07 10:29:33 ----A---- C:\Windows\system32\hidserv.dll
2010-11-07 10:29:33 ----A---- C:\Windows\system32\fundisc.dll
2010-11-07 10:29:33 ----A---- C:\Windows\system32\cryptsvc.dll
2010-11-07 10:29:32 ----A---- C:\Windows\system32\wmicmiplugin.dll
2010-11-07 10:29:32 ----A---- C:\Windows\system32\termsrv.dll
2010-11-07 10:29:32 ----A---- C:\Windows\system32\profsvc.dll
2010-11-07 10:29:32 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2010-11-07 10:29:31 ----A---- C:\Windows\system32\wdc.dll
2010-11-07 10:29:31 ----A---- C:\Windows\system32\shsvcs.dll
2010-11-07 10:29:31 ----A---- C:\Windows\system32\msiexec.exe
2010-11-07 10:29:31 ----A---- C:\Windows\system32\imapi.dll
2010-11-07 10:29:31 ----A---- C:\Windows\system32\chsbrkr.dll
2010-11-07 10:29:31 ----A---- C:\Windows\system32\drivers\pci.sys
2010-11-07 10:29:31 ----A---- C:\Windows\system32\drivers\Classpnp.sys
2010-11-07 10:29:30 ----A---- C:\Windows\system32\rasmans.dll
2010-11-07 10:29:30 ----A---- C:\Windows\system32\pnidui.dll
2010-11-07 10:29:30 ----A---- C:\Windows\system32\icardres.dll
2010-11-07 10:29:30 ----A---- C:\Windows\system32\iassdo.dll
2010-11-07 10:29:29 ----A---- C:\Windows\system32\wersvc.dll
2010-11-07 10:29:29 ----A---- C:\Windows\system32\slmgr.vbs
2010-11-07 10:29:29 ----A---- C:\Windows\system32\scrrun.dll
2010-11-07 10:29:29 ----A---- C:\Windows\system32\PSHED.DLL
2010-11-07 10:29:29 ----A---- C:\Windows\system32\pdh.dll
2010-11-07 10:29:29 ----A---- C:\Windows\system32\drivers\termdd.sys
2010-11-07 10:29:29 ----A---- C:\Windows\system32\drivers\Storport.sys
2010-11-07 10:29:29 ----A---- C:\Windows\system32\drivers\crashdmp.sys
2010-11-07 10:29:29 ----A---- C:\Windows\system32\drivers\ataport.sys
2010-11-07 10:29:29 ----A---- C:\Windows\system32\drivers\acpi.sys
2010-11-07 10:29:29 ----A---- C:\Windows\system32\clfs.sys
2010-11-07 10:29:29 ----A---- C:\Windows\system32\autofmt.exe
2010-11-07 10:29:28 ----A---- C:\Windows\system32\pidgenx.dll
2010-11-07 10:29:28 ----A---- C:\Windows\system32\drivers\partmgr.sys
2010-11-07 10:29:28 ----A---- C:\Windows\system32\dhcpcsvc.dll
2010-11-07 10:29:28 ----A---- C:\Windows\system32\CertEnrollUI.dll
2010-11-07 10:29:28 ----A---- C:\Windows\system32\azroles.dll
2010-11-07 10:29:23 ----A---- C:\Windows\system32\winlogon.exe
2010-11-07 10:29:23 ----A---- C:\Windows\system32\SyncCenter.dll
2010-11-07 10:29:23 ----A---- C:\Windows\system32\SLUINotify.dll
2010-11-07 10:29:22 ----A---- C:\Windows\system32\sethc.exe
2010-11-07 10:29:22 ----A---- C:\Windows\system32\ncrypt.dll
2010-11-07 10:29:22 ----A---- C:\Windows\system32\msjetoledb40.dll
2010-11-07 10:29:22 ----A---- C:\Windows\system32\kd1394.dll
2010-11-07 10:29:22 ----A---- C:\Windows\system32\drivers\mup.sys
2010-11-07 10:29:22 ----A---- C:\Windows\system32\comuid.dll
2010-11-07 10:29:22 ----A---- C:\Windows\system32\certmgr.dll
2010-11-07 10:29:21 ----A---- C:\Windows\system32\wisptis.exe
2010-11-07 10:29:21 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2010-11-07 10:29:21 ----A---- C:\Windows\system32\untfs.dll
2010-11-07 10:29:21 ----A---- C:\Windows\system32\spp.dll
2010-11-07 10:29:21 ----A---- C:\Windows\system32\scrobj.dll
2010-11-07 10:29:21 ----A---- C:\Windows\system32\iassam.dll
2010-11-07 10:29:21 ----A---- C:\Windows\system32\dwm.exe
2010-11-07 10:29:21 ----A---- C:\Windows\system32\drivers\disk.sys
2010-11-07 10:29:20 ----A---- C:\Windows\system32\taskcomp.dll
2010-11-07 10:29:20 ----A---- C:\Windows\system32\printui.dll
2010-11-07 10:29:20 ----A---- C:\Windows\system32\iasnap.dll
2010-11-07 10:29:20 ----A---- C:\Windows\system32\drivers\volsnap.sys
2010-11-07 10:29:20 ----A---- C:\Windows\system32\drivers\volmgrx.sys
2010-11-07 10:29:20 ----A---- C:\Windows\system32\drivers\pciidex.sys
2010-11-07 10:29:20 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2010-11-07 10:29:20 ----A---- C:\Windows\system32\drivers\fltMgr.sys
2010-11-07 10:29:20 ----A---- C:\Windows\system32\autochk.exe
2010-11-07 10:29:19 ----A---- C:\Windows\system32\winsrv.dll
2010-11-07 10:29:19 ----A---- C:\Windows\system32\drivers\pciide.sys
2010-11-07 10:29:19 ----A---- C:\Windows\system32\drivers\msrpc.sys
2010-11-07 10:29:19 ----A---- C:\Windows\system32\drivers\ecache.sys
2010-11-07 10:29:19 ----A---- C:\Windows\system32\drivers\Dumpata.sys
2010-11-07 10:29:19 ----A---- C:\Windows\system32\autoconv.exe
2010-11-07 10:29:18 ----A---- C:\Windows\system32\wow32.dll
2010-11-07 10:29:18 ----A---- C:\Windows\system32\userenv.dll
2010-11-07 10:29:18 ----A---- C:\Windows\system32\osk.exe
2010-11-07 10:29:18 ----A---- C:\Windows\system32\onex.dll
2010-11-07 10:29:18 ----A---- C:\Windows\system32\mswsock.dll
2010-11-07 10:29:18 ----A---- C:\Windows\system32\kdcom.dll
2010-11-07 10:29:18 ----A---- C:\Windows\system32\cscript.exe
2010-11-07 10:29:18 ----A---- C:\Windows\system32\basecsp.dll
2010-11-07 10:29:18 ----A---- C:\Windows\system32\audiodg.exe
2010-11-07 10:29:17 ----A---- C:\Windows\system32\WinSCard.dll
2010-11-07 10:29:17 ----A---- C:\Windows\system32\winmm.dll
2010-11-07 10:29:17 ----A---- C:\Windows\system32\RelMon.dll
2010-11-07 10:29:17 ----A---- C:\Windows\system32\rdpencom.dll
2010-11-07 10:29:17 ----A---- C:\Windows\system32\kdusb.dll
2010-11-07 10:29:17 ----A---- C:\Windows\system32\drivers\netbt.sys
2010-11-07 10:29:17 ----A---- C:\Windows\system32\drivers\atapi.sys
2010-11-07 10:29:16 ----A---- C:\Windows\system32\WerFaultSecure.exe
2010-11-07 10:29:16 ----A---- C:\Windows\system32\spcmsg.dll
2010-11-07 10:29:16 ----A---- C:\Windows\system32\offfilt.dll
2010-11-07 10:29:16 ----A---- C:\Windows\system32\msftedit.dll
2010-11-07 10:29:16 ----A---- C:\Windows\system32\dnsrslvr.dll
2010-11-07 10:29:15 ----A---- C:\Windows\system32\WerFault.exe
2010-11-07 10:29:15 ----A---- C:\Windows\system32\Utilman.exe
2010-11-07 10:29:14 ----A---- C:\Windows\system32\wsepno.dll
2010-11-07 10:29:14 ----A---- C:\Windows\system32\stobject.dll
2010-11-07 10:29:14 ----A---- C:\Windows\system32\SndVol.exe
2010-11-07 10:29:14 ----A---- C:\Windows\system32\msnetobj.dll
2010-11-07 10:29:14 ----A---- C:\Windows\system32\mscms.dll
2010-11-07 10:29:14 ----A---- C:\Windows\system32\mfplat.dll
2010-11-07 10:29:14 ----A---- C:\Windows\system32\diskraid.exe
2010-11-07 10:29:14 ----A---- C:\Windows\system32\apphelp.dll
2010-11-07 10:29:14 ----A---- C:\Windows\system32\adsmsext.dll
2010-11-07 10:29:13 ----A---- C:\Windows\system32\wscript.exe
2010-11-07 10:29:13 ----A---- C:\Windows\system32\wiaservc.dll
2010-11-07 10:29:13 ----A---- C:\Windows\system32\ulib.dll
2010-11-07 10:29:13 ----A---- C:\Windows\system32\sysclass.dll
2010-11-07 10:29:13 ----A---- C:\Windows\system32\prnntfy.dll
2010-11-07 10:29:13 ----A---- C:\Windows\system32\odbccp32.dll
2010-11-07 10:29:13 ----A---- C:\Windows\system32\iasdatastore.dll
2010-11-07 10:29:12 ----A---- C:\Windows\system32\wscntfy.dll
2010-11-07 10:29:12 ----A---- C:\Windows\system32\rastapi.dll
2010-11-07 10:29:12 ----A---- C:\Windows\system32\pnpsetup.dll
2010-11-07 10:29:12 ----A---- C:\Windows\system32\IPHLPAPI.DLL
2010-11-07 10:29:12 ----A---- C:\Windows\system32\fdProxy.dll
2010-11-07 10:29:12 ----A---- C:\Windows\system32\dsound.dll
2010-11-07 10:29:12 ----A---- C:\Windows\system32\cryptui.dll
2010-11-07 10:29:11 ----A---- C:\Windows\system32\wlangpui.dll
2010-11-07 10:29:11 ----A---- C:\Windows\system32\ipsecsnp.dll
2010-11-07 10:29:11 ----A---- C:\Windows\system32\iashlpr.dll
2010-11-07 10:29:11 ----A---- C:\Windows\system32\gpapi.dll
2010-11-07 10:29:11 ----A---- C:\Windows\system32\diskpart.exe
2010-11-07 10:29:11 ----A---- C:\Windows\system32\brcpl.dll
2010-11-07 10:29:10 ----A---- C:\Windows\system32\wscsvc.dll
2010-11-07 10:29:10 ----A---- C:\Windows\system32\WMVENCOD.DLL
2010-11-07 10:29:10 ----A---- C:\Windows\system32\vdsdyn.dll
2010-11-07 10:29:10 ----A---- C:\Windows\system32\rasapi32.dll
2010-11-07 10:29:10 ----A---- C:\Windows\system32\ntprint.dll
2010-11-07 10:29:10 ----A---- C:\Windows\system32\logman.exe
2010-11-07 10:29:09 ----A---- C:\Windows\system32\wusa.exe
2010-11-07 10:29:09 ----A---- C:\Windows\system32\regsvc.dll
2010-11-07 10:29:09 ----A---- C:\Windows\system32\mscorier.dll
2010-11-07 10:29:09 ----A---- C:\Windows\system32\iasrad.dll
2010-11-07 10:29:09 ----A---- C:\Windows\system32\findstr.exe
2010-11-07 10:29:08 ----A---- C:\Windows\system32\zipfldr.dll
2010-11-07 10:29:08 ----A---- C:\Windows\system32\wshext.dll
2010-11-07 10:29:07 ----A---- C:\Windows\system32\wpccpl.dll
2010-11-07 10:29:07 ----A---- C:\Windows\system32\netcenter.dll
2010-11-07 10:29:05 ----A---- C:\Windows\system32\wer.dll
2010-11-07 10:29:05 ----A---- C:\Windows\system32\rasdlg.dll
2010-11-07 10:29:05 ----A---- C:\Windows\system32\iassvcs.dll
2010-11-07 10:29:04 ----A---- C:\Windows\system32\wsnmp32.dll
2010-11-07 10:29:04 ----A---- C:\Windows\system32\themecpl.dll
2010-11-07 10:29:04 ----A---- C:\Windows\system32\drivers\usbehci.sys
2010-11-07 10:29:03 ----A---- C:\Windows\system32\uxsms.dll
2010-11-07 10:29:03 ----A---- C:\Windows\system32\mssprxy.dll
2010-11-07 10:29:02 ----A---- C:\Windows\system32\scansetting.dll
2010-11-07 10:29:02 ----A---- C:\Windows\system32\ntmarta.dll
2010-11-07 10:29:02 ----A---- C:\Windows\system32\msutb.dll
2010-11-07 10:29:02 ----A---- C:\Windows\system32\mstlsapi.dll
2010-11-07 10:29:02 ----A---- C:\Windows\system32\iasads.dll
2010-11-07 10:29:02 ----A---- C:\Windows\system32\drivers\HdAudio.sys
2010-11-07 10:29:01 ----A---- C:\Windows\system32\slcc.dll
2010-11-07 10:29:01 ----A---- C:\Windows\system32\powrprof.dll
2010-11-07 10:29:01 ----A---- C:\Windows\system32\mstsc.exe
2010-11-07 10:29:01 ----A---- C:\Windows\system32\drivers\ks.sys
2010-11-07 10:29:00 ----A---- C:\Windows\system32\iasacct.dll
2010-11-07 10:28:56 ----A---- C:\Windows\system32\powercpl.dll
2010-11-07 10:28:56 ----A---- C:\Windows\system32\PerfCenterCPL.dll
2010-11-07 10:28:56 ----A---- C:\Windows\system32\networkmap.dll
2010-11-07 10:28:55 ----A---- C:\Windows\system32\newdev.exe
2010-11-07 10:28:55 ----A---- C:\Windows\system32\connect.dll
2010-11-07 10:28:55 ----A---- C:\Windows\system32\authz.dll
2010-11-07 10:28:54 ----A---- C:\Windows\system32\systemcpl.dll
2010-11-07 10:28:54 ----A---- C:\Windows\system32\sud.dll
2010-11-07 10:28:54 ----A---- C:\Windows\system32\dot3svc.dll
2010-11-07 10:28:53 ----A---- C:\Windows\system32\themeui.dll
2010-11-07 10:28:53 ----A---- C:\Windows\system32\pcaui.dll
2010-11-07 10:28:52 ----A---- C:\Windows\system32\usercpl.dll
2010-11-07 10:28:52 ----A---- C:\Windows\system32\samlib.dll
2010-11-07 10:28:52 ----A---- C:\Windows\system32\mmci.dll
2010-11-07 10:28:52 ----A---- C:\Windows\system32\accessibilitycpl.dll
2010-11-07 10:28:51 ----A---- C:\Windows\system32\wlanpref.dll
2010-11-07 10:28:51 ----A---- C:\Windows\system32\qdvd.dll
2010-11-07 10:28:51 ----A---- C:\Windows\system32\autoplay.dll
2010-11-07 10:28:50 ----A---- C:\Windows\system32\wpcao.dll
2010-11-07 10:28:50 ----A---- C:\Windows\system32\vdsutil.dll
2010-11-07 10:28:50 ----A---- C:\Windows\system32\rpchttp.dll
2010-11-07 10:28:50 ----A---- C:\Windows\system32\regapi.dll
2010-11-07 10:28:50 ----A---- C:\Windows\system32\msinfo32.exe
2010-11-07 10:28:49 ----A---- C:\Windows\system32\tapisrv.dll
2010-11-07 10:28:49 ----A---- C:\Windows\system32\scksp.dll
2010-11-07 10:28:49 ----A---- C:\Windows\system32\mpr.dll
2010-11-07 10:28:49 ----A---- C:\Windows\system32\feclient.dll
2010-11-07 10:28:48 ----A---- C:\Windows\system32\wscisvif.dll
2010-11-07 10:28:48 ----A---- C:\Windows\system32\scesrv.dll
2010-11-07 10:28:48 ----A---- C:\Windows\system32\rekeywiz.exe
2010-11-07 10:28:48 ----A---- C:\Windows\system32\psisdecd.dll
2010-11-07 10:28:48 ----A---- C:\Windows\system32\oleprn.dll
2010-11-07 10:28:48 ----A---- C:\Windows\system32\imm32.dll
2010-11-07 10:28:48 ----A---- C:\Windows\system32\iaspolcy.dll
2010-11-07 10:28:48 ----A---- C:\Windows\system32\Faultrep.dll
2010-11-07 10:28:48 ----A---- C:\Windows\system32\drivers\exfat.sys
2010-11-07 10:28:48 ----A---- C:\Windows\system32\dot3msm.dll
2010-11-07 10:28:48 ----A---- C:\Windows\system32\DeviceEject.exe
2010-11-07 10:28:48 ----A---- C:\Windows\system32\AudioSes.dll
2010-11-07 10:28:47 ----A---- C:\Windows\system32\sdclt.exe
2010-11-07 10:28:47 ----A---- C:\Windows\system32\qedit.dll
2010-11-07 10:28:47 ----A---- C:\Windows\system32\pnpui.dll
2010-11-07 10:28:47 ----A---- C:\Windows\system32\perfdisk.dll
2010-11-07 10:28:47 ----A---- C:\Windows\system32\ncryptui.dll
2010-11-07 10:28:47 ----A---- C:\Windows\system32\dpapimig.exe
2010-11-07 10:28:47 ----A---- C:\Windows\system32\certreq.exe
2010-11-07 10:28:46 ----A---- C:\Windows\system32\TSTheme.exe
2010-11-07 10:28:46 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2010-11-07 10:28:46 ----A---- C:\Windows\system32\scecli.dll
2010-11-07 10:28:46 ----A---- C:\Windows\system32\rasplap.dll
2010-11-07 10:28:46 ----A---- C:\Windows\system32\rasgcw.dll
2010-11-07 10:28:46 ----A---- C:\Windows\system32\hdwwiz.exe
2010-11-07 10:28:46 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2010-11-07 10:28:46 ----A---- C:\Windows\system32\drivers\USBAUDIO.sys
2010-11-07 10:28:45 ----A---- C:\Windows\system32\tcpipcfg.dll
2010-11-07 10:28:45 ----A---- C:\Windows\system32\spwinsat.dll
2010-11-07 10:28:45 ----A---- C:\Windows\system32\PnPUnattend.exe
2010-11-07 10:28:45 ----A---- C:\Windows\system32\cmmon32.exe
2010-11-07 10:28:44 ----A---- C:\Windows\system32\whealogr.dll
2010-11-07 10:28:44 ----A---- C:\Windows\system32\tcpmon.dll
2010-11-07 10:28:44 ----A---- C:\Windows\system32\fdWSD.dll
2010-11-07 10:28:44 ----A---- C:\Windows\system32\drivers\USBCAMD2.sys
2010-11-07 10:28:44 ----A---- C:\Windows\system32\drivers\USBCAMD.sys
2010-11-07 10:28:44 ----A---- C:\Windows\system32\drivers\portcls.sys
2010-11-07 10:28:43 ----A---- C:\Windows\system32\srcore.dll
2010-11-07 10:28:43 ----A---- C:\Windows\system32\SCardSvr.dll
2010-11-07 10:28:43 ----A---- C:\Windows\system32\raschap.dll
2010-11-07 10:28:43 ----A---- C:\Windows\system32\fontext.dll
2010-11-07 10:28:43 ----A---- C:\Windows\system32\conime.exe
2010-11-07 10:28:43 ----A---- C:\Windows\system32\cmdial32.dll
2010-11-07 10:28:42 ----A---- C:\Windows\system32\wiaaut.dll
2010-11-07 10:28:42 ----A---- C:\Windows\system32\MSVidCtl.dll
2010-11-07 10:28:42 ----A---- C:\Windows\system32\drivers\npfs.sys
2010-11-07 10:28:42 ----A---- C:\Windows\system32\drivers\afd.sys
2010-11-07 10:28:41 ----A---- C:\Windows\system32\WMVXENCD.DLL
2010-11-07 10:28:41 ----A---- C:\Windows\system32\wlanui.dll
2010-11-07 10:28:41 ----A---- C:\Windows\system32\shwebsvc.dll
2010-11-07 10:28:41 ----A---- C:\Windows\system32\rasppp.dll
2010-11-07 10:28:41 ----A---- C:\Windows\system32\PnPutil.exe
2010-11-07 10:28:41 ----A---- C:\Windows\system32\dsprop.dll
2010-11-07 10:28:40 ----A---- C:\Windows\system32\oobefldr.dll
2010-11-07 10:28:40 ----A---- C:\Windows\system32\drivers\tdx.sys
2010-11-07 10:28:40 ----A---- C:\Windows\system32\drivers\pacer.sys
2010-11-07 10:28:40 ----A---- C:\Windows\system32\dimsroam.dll
2010-11-07 10:28:39 ----A---- C:\Windows\system32\shsetup.dll
2010-11-07 10:28:39 ----A---- C:\Windows\system32\rasmontr.dll
2010-11-07 10:28:39 ----A---- C:\Windows\system32\mscandui.dll
2010-11-07 10:28:39 ----A---- C:\Windows\system32\modemui.dll
2010-11-07 10:28:38 ----A---- C:\Windows\system32\wmdrmsdk.dll
2010-11-07 10:28:38 ----A---- C:\Windows\system32\chtbrkr.dll
2010-11-07 10:28:38 ----A---- C:\Windows\system32\dataclen.dll
2010-11-07 10:28:37 ----A---- C:\Windows\system32\wlgpclnt.dll
2010-11-07 10:28:37 ----A---- C:\Windows\system32\smss.exe
2010-11-07 10:28:37 ----A---- C:\Windows\system32\rdpwsx.dll
2010-11-07 10:28:37 ----A---- C:\Windows\system32\drivers\fastfat.sys
2010-11-07 10:28:37 ----A---- C:\Windows\system32\credui.dll
2010-11-07 10:28:37 ----A---- C:\Windows\system32\blackbox.dll
2010-11-07 10:28:36 ----A---- C:\Windows\system32\WSDMon.dll
2010-11-07 10:28:36 ----A---- C:\Windows\system32\wmpeffects.dll
2010-11-07 10:28:36 ----A---- C:\Windows\system32\netplwiz.dll
2010-11-07 10:28:36 ----A---- C:\Windows\system32\drivers\rmcast.sys
2010-11-07 10:28:36 ----A---- C:\Windows\system32\certprop.dll
2010-11-07 10:28:35 ----A---- C:\Windows\system32\wpcsvc.dll
2010-11-07 10:28:35 ----A---- C:\Windows\system32\networkexplorer.dll
2010-11-07 10:28:35 ----A---- C:\Windows\system32\msscp.dll
2010-11-07 10:28:35 ----A---- C:\Windows\system32\logagent.exe
2010-11-07 10:28:35 ----A---- C:\Windows\system32\InkEd.dll
2010-11-07 10:28:35 ----A---- C:\Windows\system32\ifmon.dll
2010-11-07 10:28:35 ----A---- C:\Windows\system32\cipher.exe
2010-11-07 10:28:34 ----A---- C:\Windows\system32\wscapi.dll
2010-11-07 10:28:34 ----A---- C:\Windows\system32\thawbrkr.dll
2010-11-07 10:28:34 ----A---- C:\Windows\system32\softkbd.dll
2010-11-07 10:28:34 ----A---- C:\Windows\system32\sendmail.dll
2010-11-07 10:28:34 ----A---- C:\Windows\system32\msimtf.dll
2010-11-07 10:28:34 ----A---- C:\Windows\system32\MediaMetadataHandler.dll
2010-11-07 10:28:34 ----A---- C:\Windows\system32\gpresult.exe
2010-11-07 10:28:34 ----A---- C:\Windows\system32\drivers\watchdog.sys
2010-11-07 10:28:33 ----A---- C:\Windows\system32\olepro32.dll
2010-11-07 10:28:33 ----A---- C:\Windows\system32\msctfui.dll
2010-11-07 10:28:33 ----A---- C:\Windows\system32\drmmgrtn.dll
2010-11-07 10:28:33 ----A---- C:\Windows\system32\drivers\smb.sys
2010-11-07 10:28:33 ----A---- C:\Windows\system32\drivers\hidusb.sys
2010-11-07 10:28:33 ----A---- C:\Windows\system32\dmsynth.dll
2010-11-07 10:28:32 ----A---- C:\Windows\system32\puiapi.dll
2010-11-07 10:28:32 ----A---- C:\Windows\system32\input.dll
2010-11-07 10:28:32 ----A---- C:\Windows\system32\ExplorerFrame.dll
2010-11-07 10:28:32 ----A---- C:\Windows\system32\drivers\udfs.sys
2010-11-07 10:28:32 ----A---- C:\Windows\system32\cdd.dll
2010-11-07 10:28:31 ----A---- C:\Windows\system32\wshbth.dll
2010-11-07 10:28:31 ----A---- C:\Windows\system32\version.dll
2010-11-07 10:28:31 ----A---- C:\Windows\system32\SLLUA.exe
2010-11-07 10:28:31 ----A---- C:\Windows\system32\msisip.dll
2010-11-07 10:28:31 ----A---- C:\Windows\system32\mprapi.dll
2010-11-07 10:28:31 ----A---- C:\Windows\system32\fc.exe
2010-11-07 10:28:30 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll
2010-11-07 10:28:30 ----A---- C:\Windows\system32\msjint40.dll
2010-11-07 10:28:30 ----A---- C:\Windows\system32\MsCtfMonitor.dll
2010-11-07 10:28:30 ----A---- C:\Windows\system32\fdSSDP.dll
2010-11-07 10:28:30 ----A---- C:\Windows\system32\eapp3hst.dll
2010-11-07 10:28:30 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2010-11-07 10:28:30 ----A---- C:\Windows\system32\drivers\ndiswan.sys
2010-11-07 10:28:30 ----A---- C:\Windows\system32\dmusic.dll
2010-11-07 10:28:30 ----A---- C:\Windows\system32\cscapi.dll
2010-11-07 10:28:29 ----A---- C:\Windows\system32\wsdchngr.dll
2010-11-07 10:28:29 ----A---- C:\Windows\system32\SMBHelperClass.dll
2010-11-07 10:28:29 ----A---- C:\Windows\system32\PortableDeviceClassExtension.dll
2010-11-07 10:28:29 ----A---- C:\Windows\system32\l2nacp.dll
2010-11-07 10:28:29 ----A---- C:\Windows\system32\ftp.exe
2010-11-07 10:28:29 ----A---- C:\Windows\system32\cscdll.dll
2010-11-07 10:28:28 ----A---- C:\Windows\system32\Storprop.dll
2010-11-07 10:28:28 ----A---- C:\Windows\system32\rasdial.exe
2010-11-07 10:28:28 ----A---- C:\Windows\system32\rasdiag.dll
2010-11-07 10:28:28 ----A---- C:\Windows\system32\PortableDeviceTypes.dll
2010-11-07 10:28:28 ----A---- C:\Windows\system32\ipconfig.exe
2010-11-07 10:28:28 ----A---- C:\Windows\system32\fdWCN.dll
2010-11-07 10:28:28 ----A---- C:\Windows\system32\eappcfg.dll
2010-11-07 10:28:28 ----A---- C:\Windows\system32\dot3cfg.dll
2010-11-07 10:28:28 ----A---- C:\Windows\system32\bthudtask.exe
2010-11-07 10:28:28 ----A---- C:\Windows\system32\bthci.dll
2010-11-07 10:28:27 ----A---- C:\Windows\system32\tscupgrd.exe
2010-11-07 10:28:27 ----A---- C:\Windows\system32\slcinst.dll
2010-11-07 10:28:27 ----A---- C:\Windows\system32\ocsetup.exe
2010-11-07 10:28:27 ----A---- C:\Windows\system32\nslookup.exe
2010-11-07 10:28:27 ----A---- C:\Windows\system32\networkitemfactory.dll
2010-11-07 10:28:27 ----A---- C:\Windows\system32\CHxReadingStringIME.dll
2010-11-07 10:28:27 ----A---- C:\Windows\system32\eappgnui.dll
2010-11-07 10:28:27 ----A---- C:\Windows\system32\drivers\rassstp.sys
2010-11-07 10:28:27 ----A---- C:\Windows\system32\drivers\hidclass.sys
2010-11-07 10:28:26 ----A---- C:\Windows\system32\mmcico.dll
2010-11-07 10:28:26 ----A---- C:\Windows\system32\hbaapi.dll
2010-11-07 10:28:26 ----A---- C:\Windows\system32\FwRemoteSvr.dll
2010-11-07 10:28:26 ----A---- C:\Windows\system32\fdeploy.dll
2010-11-07 10:28:25 ----A---- C:\Windows\system32\PNPXAssoc.dll
2010-11-07 10:28:25 ----A---- C:\Windows\system32\gpupdate.exe
2010-11-07 10:28:25 ----A---- C:\Windows\system32\drivers\nwifi.sys
2010-11-07 10:28:25 ----A---- C:\Windows\system32\drivers\dfsc.sys
2010-11-07 10:28:25 ----A---- C:\Windows\system32\drivers\cdrom.sys
2010-11-07 10:28:24 ----A---- C:\Windows\system32\csrstub.exe
2010-11-07 10:28:24 ----A---- C:\Windows\system32\cbsra.exe
2010-11-07 10:28:24 ----A---- C:\Windows\system32\bitsigd.dll
2010-11-07 10:28:23 ----A---- C:\Windows\system32\NcdProp.dll
2010-11-07 10:28:23 ----A---- C:\Windows\system32\iscsilog.dll
2010-11-07 10:28:22 ----A---- C:\Windows\system32\vdmdbg.dll
2010-11-07 10:28:22 ----A---- C:\Windows\system32\odbcconf.dll
2010-11-07 10:28:22 ----A---- C:\Windows\system32\drivers\dxg.sys
2010-11-07 10:28:22 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2010-11-07 10:28:21 ----A---- C:\Windows\system32\winrnr.dll
2010-11-07 10:28:21 ----A---- C:\Windows\system32\slwga.dll
2010-11-07 10:28:21 ----A---- C:\Windows\system32\midimap.dll
2010-11-07 10:28:21 ----A---- C:\Windows\system32\inetppui.dll
2010-11-07 10:28:19 ----A---- C:\Windows\system32\drivers\stream.sys
2010-11-07 10:28:19 ----A---- C:\Windows\system32\drivers\RNDISMP.sys
2010-11-07 10:28:18 ----A---- C:\Windows\system32\drivers\usbohci.sys
2010-11-07 10:28:18 ----A---- C:\Windows\system32\drivers\bridge.sys
2010-11-07 10:28:17 ----A---- C:\Windows\system32\msimsg.dll
2010-11-07 10:28:17 ----A---- C:\Windows\system32\f3ahvoas.dll
2010-11-07 10:28:17 ----A---- C:\Windows\system32\drivers\usb8023.sys
2010-11-07 10:28:17 ----A---- C:\Windows\system32\drivers\raspppoe.sys
2010-11-07 10:27:31 ----A---- C:\Windows\system32\SmiEngine.dll
2010-11-07 10:27:16 ----A---- C:\Windows\system32\wdscore.dll
2010-11-07 10:27:16 ----A---- C:\Windows\system32\PkgMgr.exe
2010-11-07 10:26:39 ----A---- C:\Windows\system32\drvstore.dll
2010-11-07 09:59:30 ----A---- C:\Windows\system32\gameux.dll
2010-11-07 09:59:28 ----A---- C:\Windows\system32\Apphlpdm.dll
2010-11-07 09:59:27 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2010-10-31 20:00:02 ----D---- C:\Users\Pečimuthovi\AppData\Roaming\Netscape
2010-10-31 20:00:02 ----D---- C:\Program Files\Photodex Presenter
2010-10-31 19:59:20 ----D---- C:\Program Files\Photodex
2010-10-31 19:57:22 ----D---- C:\Users\Pečimuthovi\AppData\Roaming\Photodex
2010-10-29 23:01:11 ----D---- C:\Program Files\WinClamAVShield
2010-10-27 13:33:12 ----D---- C:\Program Files\Zrychleni Pocitace
2010-10-27 13:32:54 ----D---- C:\Users\Pečimuthovi\AppData\Roaming\OpenCandy
2010-10-26 12:33:54 ----D---- C:\ProgramData\Sony Ericsson
2010-10-26 12:33:12 ----D---- C:\Program Files\Avanquest update
2010-10-26 10:05:54 ----SHD---- C:\found.000
2010-10-25 04:37:04 ----D---- C:\ProgramData\BVRP Software
2010-10-16 23:06:14 ----A---- C:\Windows\system32\mshtml.dll
2010-10-16 23:06:13 ----A---- C:\Windows\system32\ieframe.dll
2010-10-16 23:06:12 ----A---- C:\Windows\system32\wininet.dll
2010-10-16 23:06:12 ----A---- C:\Windows\system32\urlmon.dll
2010-10-16 23:06:12 ----A---- C:\Windows\system32\occache.dll
2010-10-16 23:06:12 ----A---- C:\Windows\system32\mstime.dll
2010-10-16 23:06:12 ----A---- C:\Windows\system32\mshtmled.dll
2010-10-16 23:06:12 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-10-16 23:06:12 ----A---- C:\Windows\system32\msfeeds.dll
2010-10-16 23:06:12 ----A---- C:\Windows\system32\licmgr10.dll
2010-10-16 23:06:12 ----A---- C:\Windows\system32\ieUnatt.exe
2010-10-16 23:06:12 ----A---- C:\Windows\system32\ieui.dll
2010-10-16 23:06:12 ----A---- C:\Windows\system32\iesysprep.dll
2010-10-16 23:06:12 ----A---- C:\Windows\system32\iesetup.dll
2010-10-16 23:06:12 ----A---- C:\Windows\system32\iertutil.dll
2010-10-16 23:06:12 ----A---- C:\Windows\system32\iernonce.dll
2010-10-16 23:06:12 ----A---- C:\Windows\system32\iepeers.dll
2010-10-16 23:06:12 ----A---- C:\Windows\system32\iedkcs32.dll
2010-10-16 23:06:11 ----A---- C:\Windows\system32\msfeedssync.exe
2010-10-16 23:06:11 ----A---- C:\Windows\system32\jsproxy.dll
2010-10-16 23:06:11 ----A---- C:\Windows\system32\ie4uinit.exe
2010-10-16 23:06:07 ----A---- C:\Windows\system32\srvsvc.dll
2010-10-16 23:06:07 ----A---- C:\Windows\system32\drivers\srvnet.sys
2010-10-16 23:06:07 ----A---- C:\Windows\system32\drivers\srv2.sys
2010-10-16 23:06:07 ----A---- C:\Windows\system32\drivers\srv.sys
2010-10-16 23:06:06 ----A---- C:\Windows\system32\netevent.dll
2010-10-16 23:05:56 ----A---- C:\Windows\system32\wmp.dll
2010-10-16 23:05:54 ----A---- C:\Windows\system32\wmploc.DLL
2010-10-16 23:05:45 ----A---- C:\Windows\system32\mfc40u.dll
2010-10-16 23:05:45 ----A---- C:\Windows\system32\mfc40.dll
2010-10-16 23:05:44 ----A---- C:\Windows\system32\win32k.sys
2010-10-16 23:05:43 ----A---- C:\Windows\system32\wmpmde.dll
2010-10-16 23:05:42 ----A---- C:\Windows\system32\t2embed.dll
2010-10-16 23:05:40 ----A---- C:\Windows\system32\ole32.dll
2010-10-16 23:05:38 ----A---- C:\Windows\system32\schannel.dll
2010-10-16 23:03:34 ----A---- C:\Windows\system32\comctl32.dll
2010-10-16 23:01:48 ----D---- C:\Program Files\Common Files\Adobe
2010-10-16 23:01:48 ----D---- C:\Program Files\Adobe

======List of files/folders modified in the last 1 months======

2010-11-14 21:49:22 ----D---- C:\Windows\Temp
2010-11-14 21:30:42 ----D---- C:\Windows\System32
2010-11-14 21:30:42 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-11-14 21:30:41 ----D---- C:\Windows\inf
2010-11-14 21:25:44 ----D---- C:\Windows\system32\drivers
2010-11-14 21:23:52 ----D---- C:\Windows\ModemLogs
2010-11-14 20:48:19 ----SD---- C:\ProgramData\Microsoft
2010-11-14 19:37:51 ----RD---- C:\Program Files
2010-11-14 19:37:51 ----HD---- C:\ProgramData
2010-11-14 18:42:55 ----SHD---- C:\System Volume Information
2010-11-14 18:40:52 ----D---- C:\Windows\system32\drivers\etc
2010-11-14 18:39:48 ----D---- C:\Windows\twain_32
2010-11-14 18:06:58 ----SHD---- C:\Windows\Installer
2010-11-14 11:13:30 ----D---- C:\Windows
2010-11-14 11:13:06 ----SD---- C:\Users\Pečimuthovi\AppData\Roaming\Microsoft
2010-11-14 10:56:38 ----D---- C:\Windows\system32\catroot
2010-11-14 10:49:50 ----HD---- C:\Config.Msi
2010-11-14 10:49:50 ----D---- C:\Windows\winsxs
2010-11-14 10:49:32 ----D---- C:\Program Files\Common Files\microsoft shared
2010-11-13 19:26:19 ----D---- C:\Windows\Prefetch
2010-11-13 19:16:57 ----D---- C:\Windows\system32\catroot2
2010-11-11 16:04:01 ----D---- C:\Users\Pečimuthovi\AppData\Roaming\Skype
2010-11-11 16:00:21 ----D---- C:\Users\Pečimuthovi\AppData\Roaming\skypePM
2010-11-08 12:45:47 ----D---- C:\ProgramData\ESET
2010-11-07 11:20:58 ----D---- C:\Windows\rescache
2010-11-07 11:13:47 ----D---- C:\Windows\Microsoft.NET
2010-11-07 11:13:24 ----RSD---- C:\Windows\assembly
2010-11-07 10:56:41 ----SHD---- C:\Boot
2010-11-07 10:54:35 ----D---- C:\ProgramData\NVIDIA
2010-11-07 10:53:40 ----D---- C:\Windows\system32\drivers\UMDF
2010-11-07 10:50:57 ----D---- C:\Program Files\Windows Sidebar
2010-11-07 10:50:57 ----D---- C:\Program Files\Windows Photo Gallery
2010-11-07 10:50:57 ----D---- C:\Program Files\Windows Media Player
2010-11-07 10:50:57 ----D---- C:\Program Files\Windows Mail
2010-11-07 10:50:57 ----D---- C:\Program Files\Windows Collaboration
2010-11-07 10:50:57 ----D---- C:\Program Files\Windows Calendar
2010-11-07 10:50:57 ----D---- C:\Program Files\Movie Maker
2010-11-07 10:50:57 ----D---- C:\Program Files\Internet Explorer
2010-11-07 10:50:57 ----D---- C:\Program Files\Common Files\System
2010-11-07 10:50:56 ----D---- C:\Windows\servicing
2010-11-07 10:50:56 ----D---- C:\Program Files\Windows Defender
2010-11-07 10:50:55 ----D---- C:\Windows\system32\XPSViewer
2010-11-07 10:50:55 ----D---- C:\Windows\system32\sk-SK
2010-11-07 10:50:55 ----D---- C:\Windows\system32\ru-RU
2010-11-07 10:50:55 ----D---- C:\Windows\system32\oobe
2010-11-07 10:50:55 ----D---- C:\Windows\system32\migration
2010-11-07 10:50:55 ----D---- C:\Windows\system32\lv-LV
2010-11-07 10:50:55 ----D---- C:\Windows\system32\ko-KR
2010-11-07 10:50:55 ----D---- C:\Windows\system32\it-IT
2010-11-07 10:50:55 ----D---- C:\Windows\system32\hr-HR
2010-11-07 10:50:55 ----D---- C:\Windows\system32\fr-FR
2010-11-07 10:50:55 ----D---- C:\Windows\system32\et-EE
2010-11-07 10:50:55 ----D---- C:\Windows\system32\en-US
2010-11-07 10:50:55 ----D---- C:\Windows\system32\el-GR
2010-11-07 10:50:55 ----D---- C:\Windows\system32\de-DE
2010-11-07 10:50:55 ----D---- C:\Windows\system32\da-DK
2010-11-07 10:50:55 ----D---- C:\Windows\system32\AdvancedInstallers
2010-11-07 10:50:55 ----D---- C:\Windows\IME
2010-11-07 10:50:54 ----D---- C:\Windows\system32\sv-SE
2010-11-07 10:50:54 ----D---- C:\Windows\system32\setup
2010-11-07 10:50:54 ----D---- C:\Windows\system32\he-IL
2010-11-07 10:50:54 ----D---- C:\Windows\system32\fi-FI
2010-11-07 10:50:54 ----D---- C:\Windows\system32\cs-CZ
2010-11-07 10:50:54 ----D---- C:\Windows\system32\cs
2010-11-07 10:50:51 ----D---- C:\Windows\system32\SLUI
2010-11-07 10:50:51 ----D---- C:\Windows\system32\pt-PT
2010-11-07 10:50:51 ----D---- C:\Windows\system32\hu-HU
2010-11-07 10:50:50 ----D---- C:\Windows\system32\zh-TW
2010-11-07 10:50:50 ----D---- C:\Windows\system32\zh-CN
2010-11-07 10:50:50 ----D---- C:\Windows\system32\uk-UA
2010-11-07 10:50:50 ----D---- C:\Windows\system32\th-TH
2010-11-07 10:50:50 ----D---- C:\Windows\system32\sr-Latn-CS
2010-11-07 10:50:50 ----D---- C:\Windows\system32\sl-SI
2010-11-07 10:50:50 ----D---- C:\Windows\system32\ro-RO
2010-11-07 10:50:50 ----D---- C:\Windows\system32\pl-PL
2010-11-07 10:50:50 ----D---- C:\Windows\system32\manifeststore
2010-11-07 10:50:50 ----D---- C:\Windows\system32\ja-JP
2010-11-07 10:50:50 ----D---- C:\Windows\system32\es-ES
2010-11-07 10:50:50 ----D---- C:\Windows\system32\drivers\cs-CZ
2010-11-07 10:50:50 ----D---- C:\Windows\system32\bg-BG
2010-11-07 10:50:49 ----D---- C:\Windows\system32\wbem
2010-11-07 10:50:49 ----D---- C:\Windows\system32\tr-TR
2010-11-07 10:50:49 ----D---- C:\Windows\system32\pt-BR
2010-11-07 10:50:49 ----D---- C:\Windows\system32\nl-NL
2010-11-07 10:50:49 ----D---- C:\Windows\system32\nb-NO
2010-11-07 10:50:49 ----D---- C:\Windows\system32\migwiz
2010-11-07 10:50:49 ----D---- C:\Windows\system32\lt-LT
2010-11-07 10:50:49 ----D---- C:\Windows\system32\ar-SA
2010-11-07 10:50:42 ----RSD---- C:\Windows\Fonts
2010-11-07 10:50:42 ----D---- C:\Windows\AppPatch
2010-11-07 10:50:39 ----D---- C:\Windows\system32\Boot
2010-11-07 10:46:28 ----A---- C:\Windows\fonts\GlobalUserInterface.CompositeFont
2010-11-04 14:13:09 ----D---- C:\Users\Pečimuthovi\AppData\Roaming\ICQ
2010-11-02 06:23:40 ----D---- C:\Program Files\ICQ7.1
2010-10-31 20:00:02 ----D---- C:\Users\Pečimuthovi\AppData\Roaming\Mozilla
2010-10-31 08:08:50 ----D---- C:\Program Files\Mozilla Firefox
2010-10-26 12:33:08 ----HD---- C:\Program Files\InstallShield Installation Information
2010-10-26 11:55:46 ----D---- C:\Windows\Minidump
2010-10-26 11:48:54 ----D---- C:\Program Files\Common Files\InstallShield
2010-10-26 11:41:21 ----D---- C:\Windows\system32\Tasks
2010-10-22 11:33:05 ----D---- C:\ProgramData\Electronic Arts
2010-10-22 11:33:05 ----D---- C:\Program Files\Electronic Arts
2010-10-19 11:41:44 ----N---- C:\Windows\system32\MpSigStub.exe
2010-10-16 23:07:01 ----A---- C:\Windows\system32\mrt.exe
2010-10-16 23:01:53 ----D---- C:\ProgramData\Adobe
2010-10-16 23:01:48 ----D---- C:\Program Files\Common Files
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Malware juzjf.exe

#20 Příspěvek od vyosek »

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 nvstor32;nvstor32; C:\Windows\system32\DRIVERS\nvstor32.sys [2007-08-09 110624]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2010-09-07 23376]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2010-09-07 165584]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2010-09-07 46672]
R1 Vsdatant;Zone Alarm Firewall Driver; C:\Windows\system32\DRIVERS\vsdatant.sys [2010-05-15 457304]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2010-09-07 17744]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2010-09-07 50768]
R3 3xHybrid;SAA713x TV Card Service; C:\Windows\system32\DRIVERS\3xHybrid.sys [2007-07-06 906368]
R3 AmdLLD;AMD Low Level Device Driver; C:\Windows\system32\DRIVERS\AmdLLD.sys [2007-06-29 34304]
R3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 236544]
R3 L8042Kbd;Logitech SetPoint Keyboard Driver; C:\Windows\system32\DRIVERS\L8042Kbd.sys [2009-06-17 20240]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvmfdx32.sys [2007-11-18 1040544]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2010-07-10 11008040]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-18 83328]
S3 Dot4;Ovladač MS IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4.sys [2006-11-02 131584]
S3 Dot4Print;Ovladač třídy tiskárny standardu IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2006-11-02 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2006-11-02 36864]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-18 5632]
S3 massfilter;ZTE Mass Storage Filter Driver; C:\Windows\system32\DRIVERS\massfilter.sys [2008-12-08 7680]
S3 mbr;mbr; \??\C:\Users\PEIMUT~1\AppData\Local\Temp\mbr.sys []
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-18 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-18 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-18 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-18 6016]
S3 usbaudio;Ovladač zvuků USB (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-04-11 73216]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-18 35328]
S3 vsdatant7;vsdatant7; C:\Windows\System32\drivers\vsdatant.win7.sys []
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-18 39936]
S3 ZTEusbmdm6k;ZTE Proprietary USB Driver; C:\Windows\system32\DRIVERS\ZTEusbmdm6k.sys [2008-12-08 104960]
S3 ZTEusbnet;ZTE USB-NDIS miniport; C:\Windows\system32\DRIVERS\ZTEusbnet.sys [2008-12-08 110080]
S3 ZTEusbnmea;ZTE NMEA Port; C:\Windows\system32\DRIVERS\ZTEusbnmea.sys [2008-12-08 105344]
S3 ZTEusbser6k;ZTE Diagnostic Port; C:\Windows\system32\DRIVERS\ZTEusbser6k.sys [2008-12-08 104960]
S4 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2008-01-18 21504]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-18 21504]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-07-09 129640]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-18 21504]
R2 ScsiAccess;ScsiAccess; C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe [2010-10-31 181312]
R2 VMCService;Vodafone Mobile Connect Service; C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [2008-11-04 14336]
R2 vsmon;TrueVector Internet Monitor; C:\Windows\System32\ZoneLabs\vsmon.exe [2010-09-02 2435592]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-18 21504]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe [2009-07-20 121360]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-26 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]

-----------------EOF-----------------

A vydrze prosim chvili nez se jim prokousu...
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Malware juzjf.exe

#21 Příspěvek od vyosek »

:arrow: Spustte HJT a provedeme fixnuti polozek
  • HJT najdete zde C:\Program Files\trend micro\Pečimuthovi.exe
  • Otevre se Vam okno, kliknete na Do a system scan only
  • V dalsim okne najdete radky které jsem Vam vypsal nize, vedle nich je ctverecek, do ktereho udelate zatrzitko
  • R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatche ... p=aus&qkw=%s&tbid=60446
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://googleure.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.myheritage.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=fbpage&s= ... Terms}&f=4
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: MHURLSearchHook Class - {1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48} - C:\Program Files\Family Toolbar\tbhelper.dll (file missing)
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (file missing)
  • Kliknete na Fix checked (vlevo dole)
  • HJT se Vas zepta zda opravdu ANO, s tim souhlasite a je hotovo Obrázek
:arrow: MBAM muzete odinstalovat nebo nechat na obcasny sken - v pripade nalezu velmi doporucuji dat sem log na posouzeni, at si neodstrelite neco legitimniho

:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner (viz muj podpis), pri instalaci dejte fajfku pryc u google toolbaru
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za 14 dni

:arrow: A melo by to byt vse :wink:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

VanaFrantisek
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 13 lis 2010 20:35

Re: Malware juzjf.exe

#22 Příspěvek od VanaFrantisek »

:guitar: :guitar: :guitar:
mnohokrát díky... Už jsem posla ejemejku.... až bude nějaká kajda pošlu raději jiný způsobem...takhle vám z toho moc nezbyde... : :hmm: :hmm:

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Malware juzjf.exe

#23 Příspěvek od vyosek »

:arrow: Bohuzel SMS pro nas nejsou vyhodne, ale i tam mockarat za cely tym fora viry.cz za podporu dekuji :worship:

Nemate zac, rad jsem pomohl :) Zase nekdy Obrázek
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

VanaFrantisek
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 13 lis 2010 20:35

Re: Malware juzjf.exe

#24 Příspěvek od VanaFrantisek »


Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Malware juzjf.exe

#25 Příspěvek od vyosek »

Kolega se Vam jiz venuje, takze se mu do toho nebudu motat...
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět