C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Zpráva
Autor
Mirusek
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 14 Pro 2010 15:05

C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen

#1 Příspěvek od Mirusek »

Dobrý den. Mám problém s virem trojský kůň. Jako antivir používám Eset smart security. Při spuštění windowsů (Vista) mi vyskočí tabulka Run dll s textem: chyba při načítání souboru C:/windows/system 32/sshnas.21.dll - uvedený modul nebyl nalezen. Nevíte někdo co s tím aniž bych musel formátovat. Děkuji za odpověď

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen

#2 Příspěvek od vyosek »

Zdravim, pekne odpoledne preji a vitam Vas u nas na foru :welcome:

:arrow: Prectete si prosim pravidla fora

:arrow: Havet to je, ale format nevyzaduje...

:arrow: Jelikoz nevime o Vasem PC nic a z kristalove koule se spatne vesti, navic pri zatazenem pocasi jake ted v okrese Kromeriz panuje, neni nic videt :o

:arrow: Ale dosti legracek, kouknem na to :wink: Kliknete do meho podpisu na RSIT a dejte log z nej - navod Vas povede...
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Mirusek
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 14 Pro 2010 15:05

Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen

#3 Příspěvek od Mirusek »

mám obavy, že se v tom moc nevyznám co jste mi napsal :lol:

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen

#4 Příspěvek od vyosek »

Abychom mohli urcit kde havet presne je, tak potrebuji log z RSIT - navod je zde http://www.viry.cz/forum/viewtopic.php?f=24&t=81939 - udelejte dle nej sken a log mi sem pak vlozte...
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Mirusek
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 14 Pro 2010 15:05

Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen

#5 Příspěvek od Mirusek »

OK

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen

#6 Příspěvek od vyosek »

Po ukonceni skenu se vytvori dva logy - log.txt a info.txt - oba dva my sem vlozte - pripadne budou ulozeny v c:\rsit
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Mirusek
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 14 Pro 2010 15:05

Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen

#7 Příspěvek od Mirusek »

jeste mi to nedobehlo ten listing co mam delat?

Mirusek
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 14 Pro 2010 15:05

Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen

#8 Příspěvek od Mirusek »

jo uz to je
Logfile of random's system information tool 1.08 (written by random/random)
Run by Notebook at 2010-12-14 15:22:26
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 141 GB (59%) free of 238 GB
Total RAM: 3062 MB (59% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:23:28, on 14.12.2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18975)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\pdf24\pdf24.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Users\Notebook\AppData\Local\Seznam.cz\postak.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\QIP\qip.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Users\Notebook\AppData\Local\Seznam.cz\MiniBrowser.exe
C:\Users\Notebook\AppData\Local\Seznam.cz\MiniBrowser.exe
C:\Users\Notebook\Downloads\RSIT.exe
C:\Program Files\trend micro\Notebook.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.atcomet.com/b/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Notebook\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll (file missing)
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.4.4.13.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Notebook\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll (file missing)
O3 - Toolbar: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll (file missing)
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\pdfforge Toolbar\SearchSettings.exe
O4 - HKLM\..\Run: [PDFPrint] C:\Program Files\pdf24\pdf24.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Seznam Postak] "C:\Users\Notebook\AppData\Local\Seznam.cz\postak.exe" -s
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Metropolis] rundll32.exe C:\Windows\system32\sshnas21.dll,GetHandle
O4 - HKCU\..\Run: [JP595IR86O] C:\Users\Notebook\AppData\Local\Temp\Tvt.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Stáhnout odkaz s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: Stáhnout všechna videa s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Stáhnout všechny odkazy s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.4.4.13.dll/206 (file missing)
O9 - Extra button: Nastavení Lištičky ... - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\Users\Notebook\AppData\Local\Seznam.cz\listicka.dll (HKCU)
O9 - Extra 'Tools' menuitem: Nastavení Lištičky ... - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\Users\Notebook\AppData\Local\Seznam.cz\listicka.dll (HKCU)
O9 - Extra button: QIP 2005 - {1EF681F7-A04B-4D6D-9012-A307CCA55610} - C:\Program Files\QIP\qip.exe (HKCU)
O9 - Extra button: Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\Users\Notebook\AppData\Local\Seznam.cz\listicka.dll (HKCU)
O9 - Extra 'Tools' menuitem: Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\Users\Notebook\AppData\Local\Seznam.cz\listicka.dll (HKCU)
O17 - HKLM\System\CCS\Services\Tcpip\..\{28C35D89-1E7F-455A-B8D0-5120ED3C30DA}: NameServer = 192.168.10.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{28C35D89-1E7F-455A-B8D0-5120ED3C30DA}: NameServer = 192.168.10.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{28C35D89-1E7F-455A-B8D0-5120ED3C30DA}: NameServer = 192.168.10.1
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\Windows\system32\AEADISRV.EXE
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: SW Distributed TS Coordinator Service (CoordinatorServiceHost) - Dassault Systemes SolidWorks Corp. - C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Remote Solver for Flow Simulation 2010 - Mentor Graphics Corporation - C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe

--
End of file - 9809 bytes

======Scheduled tasks folder======

C:\Windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
BitComet Helper - C:\Program Files\BitComet\tools\BitCometBHO_1.4.4.13.dll [2010-04-13 662776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class - C:\Users\Notebook\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll [2009-07-14 150768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
pdfforge Toolbar - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-07-10 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
C:\Program Files\pdfforge Toolbar\SearchSettings.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{B922D405-6D13-4A2B-AE89-08A030DA4402} - pdfforge Toolbar - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll []
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2010-03-25 968000]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-05-22 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2008-05-22 166424]
"Persistence"=C:\Windows\system32\igfxpers.exe [2008-05-22 133656]
"QlbCtrl.exe"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2008-06-03 177456]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-03-27 1045800]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2007-02-21 1183744]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2008-03-01 1443072]
"SearchSettings"=C:\Program Files\pdfforge Toolbar\SearchSettings.exe []
"PDFPrint"=C:\Program Files\pdf24\pdf24.exe [2010-03-11 208528]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2010-07-10 149280]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Seznam Postak"=C:\Users\Notebook\AppData\Local\Seznam.cz\postak.exe [2010-10-06 488728]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
"Metropolis"=C:\Windows\system32\sshnas21.dll,GetHandle []
"JP595IR86O"=C:\Users\Notebook\AppData\Local\Temp\Tvt.exe []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2008-02-11 204800]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2010-12-14 15:22:27 ----D---- C:\Program Files\trend micro
2010-12-14 15:22:26 ----D---- C:\rsit
2010-12-14 13:12:35 ----D---- C:\Program Files\MSXML 4.0
2010-12-13 18:47:53 ----D---- C:\Program Files\Common Files\Macrovision Shared
2010-12-13 18:37:56 ----D---- C:\Program Files\Common Files\SolidWorks Shared
2010-12-13 18:37:52 ----D---- C:\Program Files\AGEIA Technologies
2010-12-13 18:37:50 ----D---- C:\ProgramData\SolidWorks
2010-12-13 18:37:50 ----D---- C:\Program Files\SolidWorks Corp
2010-12-13 18:36:35 ----D---- C:\SolidWorks Data
2010-12-13 13:12:39 ----D---- C:\Users\Notebook\AppData\Roaming\BitComet
2010-12-13 13:12:39 ----D---- C:\Downloads
2010-12-13 13:11:42 ----D---- C:\Program Files\BitComet
2010-12-11 17:14:14 ----D---- C:\ProgramData\Macrovision
2010-12-10 13:01:21 ----D---- C:\ProgramData\FLEXnet
2010-12-10 12:56:36 ----A---- C:\Windows\eDrawingOfficeAutomator.INI
2010-12-10 12:36:56 ----D---- C:\Program Files\Microsoft Visual Studio 8
2010-12-10 12:36:12 ----D---- C:\Program Files\MSECache
2010-12-10 12:33:46 ----D---- C:\Program Files\Common Files\Manažer instalací SolidWorks
2010-12-10 12:23:40 ----D---- C:\Program Files\Common Files\InstallShield
2010-12-10 12:13:24 ----D---- C:\Windows\SolidWorks
2010-12-10 12:13:19 ----D---- C:\Users\Notebook\AppData\Roaming\SolidWorks
2010-11-23 18:56:52 ----D---- C:\Users\Notebook\AppData\Roaming\progeSOFT
2010-11-23 18:56:45 ----D---- C:\ProgramData\progeSOFT
2010-11-23 18:52:59 ----A---- C:\Windows\system32\cdintf251.dll
2010-11-23 18:51:28 ----A---- C:\Windows\system32\drivers\eusk3usb.sys
2010-11-23 18:51:21 ----A---- C:\Windows\system32\vbar332.dll
2010-11-15 19:34:51 ----D---- C:\Program Files\Common Files\3DO Shared

======List of files/folders modified in the last 1 months======

2010-12-14 15:22:30 ----D---- C:\Windows\Temp
2010-12-14 15:22:27 ----RD---- C:\Program Files
2010-12-14 14:55:08 ----D---- C:\Windows\System32
2010-12-14 14:55:07 ----D---- C:\Windows\inf
2010-12-14 14:55:07 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-12-14 14:37:06 ----D---- C:\Windows
2010-12-14 13:31:28 ----SHD---- C:\System Volume Information
2010-12-14 13:13:45 ----SHD---- C:\Windows\Installer
2010-12-14 13:13:43 ----D---- C:\Windows\winsxs
2010-12-14 08:16:57 ----D---- C:\Windows\Tasks
2010-12-13 22:32:04 ----D---- C:\Windows\system32\Tasks
2010-12-13 19:10:44 ----D---- C:\Windows\system32\catroot2
2010-12-13 18:57:07 ----D---- C:\Windows\Microsoft.NET
2010-12-13 18:57:02 ----RSD---- C:\Windows\assembly
2010-12-13 18:50:32 ----D---- C:\ProgramData\Microsoft Help
2010-12-13 18:49:27 ----D---- C:\Windows\system32\catroot
2010-12-13 18:47:53 ----D---- C:\Program Files\Common Files
2010-12-13 18:40:02 ----RSD---- C:\Windows\Fonts
2010-12-13 18:37:53 ----D---- C:\Program Files\Common Files\DESIGNER
2010-12-13 18:37:52 ----D---- C:\Program Files\Microsoft Office
2010-12-13 18:37:50 ----HD---- C:\ProgramData
2010-12-13 17:18:19 ----D---- C:\Windows\Logs
2010-12-13 13:11:06 ----D---- C:\Program Files\Mozilla Firefox
2010-12-13 11:57:11 ----D---- C:\Windows\Prefetch
2010-12-11 17:55:27 ----D---- C:\Windows\system32\WDI
2010-12-10 12:54:06 ----SD---- C:\Users\Notebook\AppData\Roaming\Microsoft
2010-12-10 12:37:49 ----SD---- C:\ProgramData\Microsoft
2010-12-10 12:37:18 ----D---- C:\Program Files\Common Files\microsoft shared
2010-11-25 17:41:29 ----D---- C:\Program Files\Internet Explorer
2010-11-25 17:40:39 ----D---- C:\Windows\system32\cs-CZ
2010-11-25 17:36:06 ----D---- C:\Windows\system32\en-US
2010-11-25 17:36:04 ----D---- C:\Program Files\Microsoft.NET
2010-11-23 18:51:28 ----D---- C:\Windows\system32\drivers
2010-11-15 19:36:15 ----D---- C:\Program Files\3DO

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-11-12 691696]
R1 easdrv;easdrv; C:\Windows\system32\DRIVERS\easdrv.sys [2008-03-01 29704]
R1 epfwtdi;epfwtdi; C:\Windows\system32\DRIVERS\epfwtdi.sys [2008-03-01 54280]
R2 eamon;EAMON; C:\Windows\system32\DRIVERS\eamon.sys [2008-03-01 39944]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2008-03-01 71176]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\ADIHdAud.sys [2008-04-24 309248]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2008-11-21 1204128]
R3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-04-11 29696]
R3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\Windows\system32\DRIVERS\e1e6032.sys [2008-01-21 220672]
R3 Epfwndis;Eset Personal Firewall; C:\Windows\system32\DRIVERS\Epfwndis.sys [2008-03-01 30728]
R3 HBtnKey;HBtnKey; C:\Windows\system32\DRIVERS\cpqbttn.sys [2008-04-14 9344]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\Windows\system32\DRIVERS\HpqKbFiltr.sys [2007-06-18 16768]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 2302976]
R3 NETw3v32;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw3v32.sys [2008-01-21 2225664]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2008-03-27 199472]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S3 al06i5e8;al06i5e8; C:\Windows\system32\drivers\al06i5e8.sys []
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2009-04-11 507904]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AEADIFilters;Andrea ADI Filters Service; C:\Windows\system32\AEADISRV.EXE [2007-02-06 69632]
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [2008-08-26 14336]
R2 Application Updater;Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe [2010-01-07 380928]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 ekrn;Eset Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
R2 Remote Solver for Flow Simulation 2010;Remote Solver for Flow Simulation 2010; C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe [2009-09-11 144680]
R3 Com4QLBEx;Com4QLBEx; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
R3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2008-05-01 165192]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service; C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [2009-10-15 87336]
S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2008-03-01 19200]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-12-13 867080]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 SolidWorks Licensing Service;SolidWorks Licensing Service; C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [2010-12-13 79360]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 msvsmon80;Visual Studio 2005 Remote Debugger; C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2005-09-23 2799808]

-----------------EOF-----------------

Mirusek
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 14 Pro 2010 15:05

Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen

#9 Příspěvek od Mirusek »

a jeste info

info.txt logfile of random's system information tool 1.08 2010-12-14 15:23:29

======Uninstall list======

Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\FlashUtil10k_Plugin.exe -maintain plugin
Adobe Reader 9.4.0 - Czech-->MsiExec.exe /I{AC76BA86-7AD7-1029-7B44-A94000000001}
Agere Systems HDA Modem-->C:\Windows\agrsmdel
BitComet 1.21-->C:\Program Files\BitComet\uninst.exe
COSMOSM 2010 (2009/280)-->MsiExec.exe /I{1553E6CA-E99D-4885-A8BE-EF67342B859F}
DAEMON Tools Toolbar-->C:\Program Files\DAEMON Tools Toolbar\uninst.exe
DWGeditor-->MsiExec.exe /X{56DCD20A-E558-4396-AF59-14D15AA737BB}
ESET Smart Security-->MsiExec.exe /I{6ECB944F-D027-4E8A-9906-70E77C005AD5}
Heroes of Might and Magic® III Complete-->C:\Windows\IsUninst.exe -f"C:\Program Files\3DO\Heroes 3 Complete\Heroes of Might and Magic® III.isu" -c"C:\Program Files\Common Files\3DO Shared\3DOUnInst.dll
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
HP Quick Launch Buttons 6.40 F1-->C:\Program Files\InstallShield Installation Information\{34D2AB40-150D-475D-AE32-BD23FB5EE355}\Setup.exe -runfromtemp -l0x0005 -removeonly uninst
Intel(R) Graphics Media Accelerator Driver-->C:\Windows\system32\igxpun.exe -uninstall
Java(TM) 6 Update 16-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216016FF}
K-Lite Mega Codec Pack 6.4.0-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
Microsoft .NET Framework 3.5 Language Pack SP1 - csy-->MsiExec.exe /I{DD73CA82-EA82-38AA-863D-9A24A018DC96}
Microsoft .NET Framework 3.5 SP1 – jazyková sada – CSY-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - csy\setup.exe
Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\Setup.exe /repair /x86 /lcid 1029 /parameterfolder ClientLP
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->MsiExec.exe /X{7036A6F4-5DAD-3908-956D-1752CD7F7E5A}
Microsoft .NET Framework 4 Client Profile-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /parameterfolder Client
Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{3C3901C5-3455-3E0A-A214-0B093A5070A6}
Microsoft Office 2003 Web Components-->MsiExec.exe /I{90120000-00A4-0409-0000-0000000FF1CE}
Microsoft Office Excel MUI (Czech) 2007-->MsiExec.exe /X{90120000-0016-0405-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Czech) 2007-->MsiExec.exe /X{90120000-001A-0405-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Czech) 2007-->MsiExec.exe /X{90120000-0018-0405-0000-0000000FF1CE}
Microsoft Office Proof (Czech) 2007-->MsiExec.exe /X{90120000-001F-0405-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Slovak) 2007-->MsiExec.exe /X{90120000-001F-041B-0000-0000000FF1CE}
Microsoft Office Proofing (Czech) 2007-->MsiExec.exe /X{90120000-002C-0405-0000-0000000FF1CE}
Microsoft Office Shared MUI (Czech) 2007-->MsiExec.exe /X{90120000-006E-0405-0000-0000000FF1CE}
Microsoft Office Standard 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall STANDARD /dll OSETUP.DLL
Microsoft Office Standard 2007-->MsiExec.exe /X{90120000-0012-0000-0000-0000000FF1CE}
Microsoft Office Word MUI (Czech) 2007-->MsiExec.exe /X{90120000-001B-0405-0000-0000000FF1CE}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual Studio 2005 Tools for Applications - ENU-->MsiExec.exe /X{D481EA96-2313-4A7C-98EE-710D1AF884AC}
Microsoft Visual Studio 2005 Tools for Applications - ENU-->MsiExec.exe /X{D481EA96-2313-4A7C-98EE-710D1AF884AC}
Mozilla Firefox (3.5.16)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
PDF24 Creator-->"C:\Program Files\pdf24\unins000.exe"
pdfforge Toolbar v1.1.2-->MsiExec.exe /X{5791B7D3-8B34-4218-9750-6A8E45D0AD32}
PhotoView 360-->MsiExec.exe /I{736D2DAD-3D87-4CAA-8646-83D238AD68E0}
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A8894F19-59C8-38D2-8A75-36C0CCE56A5B} /qb+ REBOOTPROMPT=""
SolidWorks 2010 SP0-->"C:\Windows\SolidWorks\IM_20100-40000-1100-200\sldim\sldIM.exe" /remove "C:\Windows\SolidWorks\IM_20100-40000-1100-200\sldim\sldIM_installed.xml"
SolidWorks 2010 SP0-->MsiExec.exe /X{AF2066F6-7C57-46A1-A306-077EBBFC7B2B}
SolidWorks eDrawings 2010-->MsiExec.exe /I{1959101B-E34C-4266-8915-20F23B5BCF43}
SolidWorks Explorer 2010 SP0-->MsiExec.exe /I{2D8D14CC-5B31-44B9-87FC-BEC3D8AFFD1D}
SolidWorks Flow Simulation 2010 SP0-->MsiExec.exe /I{15041B8B-AC63-41DF-91D2-2118CE39E8D9}
SopCast 3.0.3-->C:\Program Files\SopCast\uninst.exe
SoundMAX-->C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\setup.exe -runfromtemp -l0x0005 -removeonly
Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
WinRAR-->C:\Program Files\WinRAR\uninstall.exe

======Security center information======

AV: ESET Smart Security 3.0
FW: ESET personal firewall
AS: ESET Smart Security 3.0
AS: Windows Defender

======System event log======

Computer Name: Notebook-PC
Event Code: 7036
Message: Stav služby Plug and Play byl změněn na: Spuštěno
Record Number: 61587
Source Name: Service Control Manager
Time Written: 20100425210139.000000-000
Event Type: Informace
User:

Computer Name: Notebook-PC
Event Code: 10029
Message: Model DCOM spustil službu fdPHost s argumenty "" za účelem spuštění serveru:
{145B4335-FE2A-4927-A040-7C35AD3180EF}
Record Number: 61586
Source Name: Microsoft-Windows-DistributedCOM
Time Written: 20100425210136.000000-000
Event Type: Informace
User:

Computer Name: Notebook-PC
Event Code: 10029
Message: Model DCOM spustil službu hpqwmiex s argumenty "" za účelem spuštění serveru:
{F5539356-2F02-40D4-999E-FA61F45FE12E}
Record Number: 61585
Source Name: Microsoft-Windows-DistributedCOM
Time Written: 20100425210136.000000-000
Event Type: Informace
User:

Computer Name: Notebook-PC
Event Code: 10029
Message: Model DCOM spustil službu netman s argumenty "" za účelem spuštění serveru:
{BA126AD1-2166-11D1-B1D0-00805FC1270E}
Record Number: 61584
Source Name: Microsoft-Windows-DistributedCOM
Time Written: 20100425210136.000000-000
Event Type: Informace
User:

Computer Name: Notebook-PC
Event Code: 14204
Message: Služba WMPNetworkSvc byla spuštěna.
Record Number: 61583
Source Name: Microsoft-Windows-WMPNSS-Service
Time Written: 20100425210136.000000-000
Event Type: Informace
User:

=====Application event log=====

Computer Name: 26L2233B1-13
Event Code: 5615
Message: Windows Management Instrumentation Service started sucessfully
Record Number: 5
Source Name: Microsoft-Windows-WMI
Time Written: 20091214081704.000000-000
Event Type: Informace
User:

Computer Name: WIN-Z1YZLTLKKPE
Event Code: 4625
Message: Subsystém EventSystem zabraňuje vytváření duplicitních záznamů v protokolu událostí po dobu 86400 sekund. Tuto dobu lze změnit pomocí hodnoty REG_DWORD s názvem SuppressDuplicateDuration v následujícím klíči registru: HKLM\Software\Microsoft\EventSystem\EventLog.
Record Number: 4
Source Name: Microsoft-Windows-EventSystem
Time Written: 20091214081700.000000-000
Event Type: Informace
User:

Computer Name: WIN-Z1YZLTLKKPE
Event Code: 900
Message: Služba Licencování softwaru se spouští.

Record Number: 3
Source Name: Microsoft-Windows-Security-Licensing-SLC
Time Written: 20091214081659.000000-000
Event Type: Informace
User:

Computer Name: WIN-Z1YZLTLKKPE
Event Code: 1531
Message: Služba Profil uživatele byla úspěšně spuštěna.


Record Number: 2
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20091214081659.000000-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

Computer Name: 26L2233B1-13
Event Code: 2
Message: Klient Certifikační služby byl úspěšně zastaven.
Record Number: 1
Source Name: Microsoft-Windows-CertificateServicesClient
Time Written: 20080121025830.046400-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

=====Security event log=====

Computer Name: Notebook-PC
Event Code: 4672
Message: Novému přihlášení byla přiřazena zvláštní oprávnění.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7

Oprávnění: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
Record Number: 9573
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100306092810.199739-000
Event Type: Úspěch auditu
User:

Computer Name: Notebook-PC
Event Code: 4624
Message: Účet byl úspěšně přihlášen.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: NOTEBOOK-PC$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7

Typ přihlášení: 5

Nové přihlášení:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}

Informace o procesu:
ID procesu: 0x26c
Název procesu: C:\Windows\System32\services.exe

Informace o síti:
Název pracovní stanice:
Adresa zdrojové sítě -
Zdrojový port: -

Podrobné informace o ověření:
Proces přihlášení: Advapi
Balíček ověření: Negotiate
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0

Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.

Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.

Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).

Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.

Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.

Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 9572
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100306092810.199739-000
Event Type: Úspěch auditu
User:

Computer Name: Notebook-PC
Event Code: 4648
Message: Došlo k pokusu o přihlášení pomocí explicitního pověření.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: NOTEBOOK-PC$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}

Účet, jehož pověření bylo použito:
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
GUID přihlášení: {00000000-0000-0000-0000-000000000000}

Cílový server:
Název cílového serveru: localhost
Další informace: localhost

Informace o procesu:
ID procesu: 0x26c
Název procesu: C:\Windows\System32\services.exe

Informace o síti:
Síťová adresa: -
Port: -

Tato událost je generována, pokud se proces pokusí přihlásit k účtu explicitním zadáním pověření tohoto účtu. K tomu nejčastěji dochází v dávkových konfiguracích, například naplánovaných úlohách, nebo při použití příkazu RUNAS.
Record Number: 9571
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100306092810.199739-000
Event Type: Úspěch auditu
User:

Computer Name: Notebook-PC
Event Code: 4672
Message: Novému přihlášení byla přiřazena zvláštní oprávnění.

Předmět:
ID zabezpečení: S-1-5-19
Název účtu: LOCAL SERVICE
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e5

Oprávnění: SeAssignPrimaryTokenPrivilege
SeAuditPrivilege
SeImpersonatePrivilege
Record Number: 9570
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100306092809.950137-000
Event Type: Úspěch auditu
User:

Computer Name: Notebook-PC
Event Code: 4624
Message: Účet byl úspěšně přihlášen.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: NOTEBOOK-PC$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7

Typ přihlášení: 5

Nové přihlášení:
ID zabezpečení: S-1-5-19
Název účtu: LOCAL SERVICE
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e5
GUID přihlášení: {00000000-0000-0000-0000-000000000000}

Informace o procesu:
ID procesu: 0x26c
Název procesu: C:\Windows\System32\services.exe

Informace o síti:
Název pracovní stanice:
Adresa zdrojové sítě -
Zdrojový port: -

Podrobné informace o ověření:
Proces přihlášení: Advapi
Balíček ověření: Negotiate
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0

Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.

Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.

Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).

Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.

Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.

Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 9569
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100306092809.950137-000
Event Type: Úspěch auditu
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%COSMOSM%;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
"PROCESSOR_REVISION"=0f0d
"NUMBER_OF_PROCESSORS"=2
"TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
"DFSTRACINGON"=FALSE
"COSMOSM"=C:\Program Files\SolidWorks Corp\COSMOS M

-----------------EOF-----------------

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen

#10 Příspěvek od vyosek »

:arrow: Tam toho je :arcisit:

:arrow: Spustte HJT a provedeme fixnuti polozek
  • HJT najdete zde C:\Program Files\trend micro\Notebook.exe
  • Otevre se Vam okno, kliknete na Do a system scan only
  • V dalsim okne najdete radky které jsem Vam vypsal nize, vedle nich je ctverecek, do ktereho udelate zatrzitko
  • R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.qip.ru
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.atcomet.com/b/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Notebook\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
    R3 - URLSearchHook: (no name) - - (no file)
    R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll (file missing)
  • Kliknete na Fix checked (vlevo dole)
  • HJT se Vas zepta zda opravdu ANO, s tim souhlasite a je hotovo Obrázek
PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Vložte do PC vsechny USB klice (flash disky, ext.disky apod.)
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Mirusek
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 14 Pro 2010 15:05

Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen

#11 Příspěvek od Mirusek »

staci kdyz volzim flashku?

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen

#12 Příspěvek od vyosek »

Ano, je to z duvodu ze havet muze byt i na ni a PC ji umi smazat...
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Mirusek
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 14 Pro 2010 15:05

Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen

#13 Příspěvek od Mirusek »

tady je log z combofixu

ComboFix 10-12-13.07 - Notebook 14.12.2010 17:16:53.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3062.1559 [GMT 1:00]
Spuštěný z: c:\users\Notebook\Downloads\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Rezidentní štít AV je zapnutý

.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-11-14 do 2010-12-14 )))))))))))))))))))))))))))))))
.

2010-12-14 14:22 . 2010-12-14 16:03 -------- d-----w- c:\program files\trend micro
2010-12-14 14:22 . 2010-12-14 14:23 -------- d-----w- C:\rsit
2010-12-14 12:14 . 2010-11-10 04:33 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{246FAB05-F1CF-4DEF-9AAB-C2F19E95C092}\mpengine.dll
2010-12-14 12:12 . 2010-12-14 12:12 -------- d-----w- c:\program files\MSXML 4.0
2010-12-13 17:47 . 2010-12-13 17:47 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2010-12-13 17:37 . 2010-12-13 17:58 -------- d-----w- c:\program files\Common Files\SolidWorks Shared
2010-12-13 17:37 . 2010-12-13 17:37 -------- d-----w- c:\program files\AGEIA Technologies
2010-12-13 17:37 . 2010-12-13 18:00 -------- d-----w- c:\program files\SolidWorks Corp
2010-12-13 17:37 . 2010-12-13 17:46 -------- d-----w- c:\programdata\SolidWorks
2010-12-13 17:36 . 2010-12-13 17:51 -------- d-----w- C:\SolidWorks Data
2010-12-13 14:53 . 2010-12-13 14:53 -------- d-----w- c:\users\Notebook\AppData\Local\ESET
2010-12-13 12:12 . 2010-12-13 19:01 -------- d-----w- c:\users\Notebook\AppData\Roaming\BitComet
2010-12-13 12:12 . 2010-12-13 15:38 -------- d-----w- C:\Downloads
2010-12-13 12:11 . 2010-12-13 12:11 -------- d-----w- c:\program files\BitComet
2010-12-11 16:14 . 2010-12-11 16:14 -------- d-----w- c:\programdata\Macrovision
2010-12-10 12:01 . 2010-12-11 17:22 -------- d-----w- c:\programdata\FLEXnet
2010-12-10 11:36 . 2010-12-10 11:37 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2010-12-10 11:36 . 2010-12-10 11:36 -------- d-----w- c:\program files\MSECache
2010-12-10 11:33 . 2010-12-13 17:36 -------- d-----w- c:\program files\Common Files\Manažer instalací SolidWorks
2010-12-10 11:23 . 2010-12-10 11:23 -------- d-----w- c:\program files\Common Files\InstallShield
2010-12-10 11:13 . 2010-12-13 17:36 -------- d-----w- c:\windows\SolidWorks
2010-12-10 11:13 . 2010-12-10 12:01 -------- d-----w- c:\users\Notebook\AppData\Roaming\SolidWorks
2010-11-24 13:37 . 2010-10-19 04:27 7680 ----a-w- c:\program files\Internet Explorer\iecompat.dll
2010-11-23 17:56 . 2010-11-23 17:56 -------- d-----w- c:\users\Notebook\AppData\Roaming\progeSOFT
2010-11-23 17:56 . 2010-11-23 17:57 -------- d-----w- c:\programdata\progeSOFT
2010-11-23 17:54 . 2009-04-15 13:59 431616 ----a-w- c:\windows\system32\temp.005
2010-11-23 17:54 . 2009-04-15 13:59 1392671 ----a-w- c:\windows\system32\temp.004
2010-11-23 17:53 . 2009-04-15 13:58 77878 ----a-w- c:\windows\system32\temp.002
2010-11-23 17:53 . 2009-04-15 13:58 69632 ----a-w- c:\windows\system32\temp.003
2010-11-23 17:53 . 2009-04-15 13:58 266293 ----a-w- c:\windows\system32\temp.001
2010-11-23 17:52 . 2009-04-15 13:57 2134016 ----a-w- c:\windows\system32\cdintf251.dll
2010-11-23 17:52 . 2004-08-19 14:39 151552 ----a-w- c:\windows\system32\temp.000
2010-11-23 17:52 . 1999-11-08 12:45 339968 ----a-w- c:\windows\system32\Slide.ocx
2010-11-23 17:52 . 1999-07-21 16:25 274432 ----a-w- c:\windows\system32\DwgThumbnail.ocx
2010-11-23 17:51 . 2009-04-15 13:58 43968 ----a-w- c:\windows\system32\drivers\eusk3usb.sys
2010-11-23 17:51 . 2010-11-23 17:51 1115704 ----a-w- c:\windows\system32\O2CPlayer.OCX
2010-11-23 17:51 . 2001-03-13 14:49 140288 ----a-w- c:\windows\system32\COMDLG32.OCX
2010-11-23 17:51 . 1998-04-24 23:00 368912 ----a-w- c:\windows\system32\vbar332.dll
2010-11-15 18:34 . 2010-11-15 18:36 -------- d-----w- c:\program files\Common Files\3DO Shared

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-12 10:32 . 2010-11-12 10:32 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-10-19 09:41 . 2009-12-31 12:16 222080 ------w- c:\windows\system32\MpSigStub.exe
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;c:\program files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [2009-10-15 87336]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [2010-01-07 380928]
R4 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
R4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2005-09-23 2799808]
R4 Remote Solver for Flow Simulation 2010;Remote Solver for Flow Simulation 2010;c:\program files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe [2009-09-11 144680]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-11-12 691696]
S2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Obsah adresáře 'Naplánované úlohy'
.
.
------- Doplňkový sken -------
.
Trusted Zone: mojebanka.cz\*
Trusted Zone: mojebanka.cz\*
FF - ProfilePath - c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\
FF - prefs.js: browser.search.selectedEngine - QIP Search
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Personas: personas@christopher.beard - %profile%\extensions\personas@christopher.beard
FF - Ext: DAEMON Tools Toolbar: DTToolbar@toolbarnet.com - %profile%\extensions\DTToolbar@toolbarnet.com
FF - Ext: BitComet Video Downloader: {B042753D-F57E-4e8e-A01B-7379A6D4CEFB} - %profile%\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

AddRemove-Agere Systems Soft Modem - c:\windows\agrsmdel



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-14 17:20
Windows 6.0.6002 Service Pack 2 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Celkový čas: 2010-12-14 17:22:21
ComboFix-quarantined-files.txt 2010-12-14 16:22

Před spuštěním: Volných bajtů: 146 717 605 888
Po spuštění: Volných bajtů: 148 062 810 112

- - End Of File - - 9733DB0CDFAA7A4872823710CA6E0C7D

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen

#14 Příspěvek od vyosek »

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Collect::
    C:\Windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
    C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
    
    Folder::
    C:\Program Files\DAEMON Tools Toolbar
    
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{B922D405-6D13-4A2B-AE89-08A030DA4402}"=-
    "{32099AAC-C132-4136-9E9A-4E364A424E17}"=-
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "SunJavaUpdateSched"=-
    "Adobe Reader Speed Launcher"=-
    "Adobe ARM"=-
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
    "Metropolis"=-
    "JP595IR86O"=-
    
    Firefox::
    FF - ProfilePath - c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\
    FF - prefs.js: browser.search.selectedEngine - QIP Search
    FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query=
    FF - Ext: DAEMON Tools Toolbar: DTToolbar@toolbarnet.com - %profile%\extensions\DTToolbar@toolbarnet.com
    
    RegLock::
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Mirusek
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 14 Pro 2010 15:05

Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen

#15 Příspěvek od Mirusek »

ComboFix 10-12-13.07 - Notebook 14.12.2010 17:40:45.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3062.1703 [GMT 1:00]
Spuštěný z: c:\users\Notebook\Downloads\ComboFix.exe
Použité ovládací přepínače :: c:\users\Notebook\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Rezidentní štít AV je zapnutý

.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\DAEMON Tools Toolbar
c:\program files\DAEMON Tools Toolbar\_DTLite.xml
c:\program files\DAEMON Tools Toolbar\DTToolbar.dll
c:\program files\DAEMON Tools Toolbar\Resources\about.ico
c:\program files\DAEMON Tools Toolbar\Resources\AboutWindow.ico
c:\program files\DAEMON Tools Toolbar\Resources\accept.ico
c:\program files\DAEMON Tools Toolbar\Resources\AddRadioStation.ico
c:\program files\DAEMON Tools Toolbar\Resources\as.ico
c:\program files\DAEMON Tools Toolbar\Resources\as.png
c:\program files\DAEMON Tools Toolbar\Resources\astro.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_buy.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_download.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_feedback.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_forum.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_home.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_lite.ico
c:\program files\DAEMON Tools Toolbar\Resources\astroburn_site.ico
c:\program files\DAEMON Tools Toolbar\Resources\astroLite_16.ico
c:\program files\DAEMON Tools Toolbar\Resources\az.ico
c:\program files\DAEMON Tools Toolbar\Resources\b1.png
c:\program files\DAEMON Tools Toolbar\Resources\burn_files.ico
c:\program files\DAEMON Tools Toolbar\Resources\burn_image.ico
c:\program files\DAEMON Tools Toolbar\Resources\burn_imgs.ico
c:\program files\DAEMON Tools Toolbar\Resources\BurnImage.ico
c:\program files\DAEMON Tools Toolbar\Resources\buy.ico
c:\program files\DAEMON Tools Toolbar\Resources\Config.ico
c:\program files\DAEMON Tools Toolbar\Resources\d.ico
c:\program files\DAEMON Tools Toolbar\Resources\d2.ico
c:\program files\DAEMON Tools Toolbar\Resources\daemon.ico
c:\program files\DAEMON Tools Toolbar\Resources\daemon_search.ico
c:\program files\DAEMON Tools Toolbar\Resources\daemon_search_site.ico
c:\program files\DAEMON Tools Toolbar\Resources\dot_disabled.bmp
c:\program files\DAEMON Tools Toolbar\Resources\dot_enabled.bmp
c:\program files\DAEMON Tools Toolbar\Resources\dot_on_over.bmp
c:\program files\DAEMON Tools Toolbar\Resources\download.ico
c:\program files\DAEMON Tools Toolbar\Resources\ds.ico
c:\program files\DAEMON Tools Toolbar\Resources\dsearch.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt-home.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_about.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_buy.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_download.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_faq.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_feedback.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_forum.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_line.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_lite.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_manual.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_pro.ico
c:\program files\DAEMON Tools Toolbar\Resources\DTPro.ico
c:\program files\DAEMON Tools Toolbar\Resources\dtt16.ico
c:\program files\DAEMON Tools Toolbar\Resources\dtt32.ico
c:\program files\DAEMON Tools Toolbar\Resources\Dwnl.ico
c:\program files\DAEMON Tools Toolbar\Resources\emulation.ico
c:\program files\DAEMON Tools Toolbar\Resources\faq.ico
c:\program files\DAEMON Tools Toolbar\Resources\favicon.ico
c:\program files\DAEMON Tools Toolbar\Resources\features.ico
c:\program files\DAEMON Tools Toolbar\Resources\feedback.ico
c:\program files\DAEMON Tools Toolbar\Resources\forum.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrix.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrixCristals.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrixDownload.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrixPlayOnline.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrixTop.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameS.ico
c:\program files\DAEMON Tools Toolbar\Resources\games_search.ico
c:\program files\DAEMON Tools Toolbar\Resources\games_search_SA.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameSA.ico
c:\program files\DAEMON Tools Toolbar\Resources\gct16.ico
c:\program files\DAEMON Tools Toolbar\Resources\gd.ico
c:\program files\DAEMON Tools Toolbar\Resources\genre.xml
c:\program files\DAEMON Tools Toolbar\Resources\globe.ico
c:\program files\DAEMON Tools Toolbar\Resources\GrabImage.ico
c:\program files\DAEMON Tools Toolbar\Resources\hb.bmp
c:\program files\DAEMON Tools Toolbar\Resources\hb.ico
c:\program files\DAEMON Tools Toolbar\Resources\help.ico
c:\program files\DAEMON Tools Toolbar\Resources\hide.ico
c:\program files\DAEMON Tools Toolbar\Resources\home.ico
c:\program files\DAEMON Tools Toolbar\Resources\image_search.ico
c:\program files\DAEMON Tools Toolbar\Resources\image_search_SA.ico
c:\program files\DAEMON Tools Toolbar\Resources\ImageS.ico
c:\program files\DAEMON Tools Toolbar\Resources\ImageSA.ico
c:\program files\DAEMON Tools Toolbar\Resources\ip.ico
c:\program files\DAEMON Tools Toolbar\Resources\lang.xml
c:\program files\DAEMON Tools Toolbar\Resources\lingvo.ico
c:\program files\DAEMON Tools Toolbar\Resources\m.ico
c:\program files\DAEMON Tools Toolbar\Resources\mail.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_disable.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_disable.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\manual.ico
c:\program files\DAEMON Tools Toolbar\Resources\map.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuRadioConfig.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuRadioStation.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuRSCur.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuTr.ico
c:\program files\DAEMON Tools Toolbar\Resources\mount.ico
c:\program files\DAEMON Tools Toolbar\Resources\mount_n_drive.ico
c:\program files\DAEMON Tools Toolbar\Resources\next.bmp
c:\program files\DAEMON Tools Toolbar\Resources\next_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\next_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\next_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\none.bmp
c:\program files\DAEMON Tools Toolbar\Resources\none_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\op.ico
c:\program files\DAEMON Tools Toolbar\Resources\play.bmp
c:\program files\DAEMON Tools Toolbar\Resources\play.ico
c:\program files\DAEMON Tools Toolbar\Resources\play_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\play_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\play_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\pragma.ico
c:\program files\DAEMON Tools Toolbar\Resources\prev.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prev_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prev_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prev_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prod.ico
c:\program files\DAEMON Tools Toolbar\Resources\Radio.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioBg.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioBg.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioBgMask.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDisp.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDisp_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioE.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioG.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioL.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLDotMask.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLeft.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLeftMask.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLM.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioM.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioN.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioR.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioR.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioRM.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioRU.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioW.bmp
c:\program files\DAEMON Tools Toolbar\Resources\rbcheck.ico
c:\program files\DAEMON Tools Toolbar\Resources\rbtxt.ico
c:\program files\DAEMON Tools Toolbar\Resources\refresh.bmp
c:\program files\DAEMON Tools Toolbar\Resources\refresh_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\refresh_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\refresh_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Rss.ico
c:\program files\DAEMON Tools Toolbar\Resources\Rss1.ico
c:\program files\DAEMON Tools Toolbar\Resources\RssA.ico
c:\program files\DAEMON Tools Toolbar\Resources\RssA1.ico
c:\program files\DAEMON Tools Toolbar\Resources\rssClose.ico
c:\program files\DAEMON Tools Toolbar\Resources\rssL.bmp
c:\program files\DAEMON Tools Toolbar\Resources\rssOpen.ico
c:\program files\DAEMON Tools Toolbar\Resources\RssRefresh.ico
c:\program files\DAEMON Tools Toolbar\Resources\s2.ico
c:\program files\DAEMON Tools Toolbar\Resources\show.ico
c:\program files\DAEMON Tools Toolbar\Resources\size.bmp
c:\program files\DAEMON Tools Toolbar\Resources\size_lr.ico
c:\program files\DAEMON Tools Toolbar\Resources\size_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\size_rl.ico
c:\program files\DAEMON Tools Toolbar\Resources\skins.ico
c:\program files\DAEMON Tools Toolbar\Resources\soft24.ico
c:\program files\DAEMON Tools Toolbar\Resources\soft24_SA.ico
c:\program files\DAEMON Tools Toolbar\Resources\spt.ico
c:\program files\DAEMON Tools Toolbar\Resources\stop.bmp
c:\program files\DAEMON Tools Toolbar\Resources\stop.ico
c:\program files\DAEMON Tools Toolbar\Resources\stop_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\stop_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\stop_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\style.ico
c:\program files\DAEMON Tools Toolbar\Resources\SupportRequest.ico
c:\program files\DAEMON Tools Toolbar\Resources\timer.ico
c:\program files\DAEMON Tools Toolbar\Resources\TitleIcon.ico
c:\program files\DAEMON Tools Toolbar\Resources\toolbar.xml
c:\program files\DAEMON Tools Toolbar\Resources\trans.ico
c:\program files\DAEMON Tools Toolbar\Resources\Trash.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_disable.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\u.ico
c:\program files\DAEMON Tools Toolbar\Resources\unmount-all.ico
c:\program files\DAEMON Tools Toolbar\Resources\vol.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol.ico
c:\program files\DAEMON Tools Toolbar\Resources\vol_back.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_dott.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_dott_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_mute.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_mute_check.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\web_resources.ico
c:\program files\DAEMON Tools Toolbar\Resources\web_search.ico
c:\program files\DAEMON Tools Toolbar\Resources\web_search_SA.ico
c:\program files\DAEMON Tools Toolbar\Resources\WebS.ico
c:\program files\DAEMON Tools Toolbar\Resources\WebSa.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi0.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi1.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi10.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi11.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi12.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi13.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi14.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi2.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi3.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi4.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi5.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi6.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi7.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi8.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi9.ico
c:\program files\DAEMON Tools Toolbar\uninst.exe
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.dll
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.xpt
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\about.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\AboutWindow.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\accept.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\AddRadioStation.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\as.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\as.png
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_buy.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_download.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_feedback.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_forum.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_home.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_lite.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astroburn_site.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astroLite_16.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\az.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\b1.png
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\burn_files.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\burn_image.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\burn_imgs.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\BurnImage.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\buy.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Config.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\d.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\d2.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\daemon.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\daemon_search.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\daemon_search_site.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dot_disabled.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dot_enabled.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dot_on_over.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\download.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ds.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dsearch.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt-home.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_about.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_buy.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_download.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_faq.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_feedback.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_forum.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_line.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_lite.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_manual.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_pro.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\DTPro.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dtt16.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dtt32.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Dwnl.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\emulation.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\faq.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\favicon.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\features.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\feedback.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\forum.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrix.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixCristals.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixDownload.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixPlayOnline.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixTop.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameS.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\games_search.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\games_search_SA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameSA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\gct16.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\gd.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\genre.xml
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\globe.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GrabImage.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\hb.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\hb.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\help.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\hide.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\home.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\image_search.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\image_search_SA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ImageS.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ImageSA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ip.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\lang.xml
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\lingvo.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\m.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_disable.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_disable.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\manual.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\map.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuRadioConfig.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuRadioStation.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuRSCur.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuTr.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mount.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mount_n_drive.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\none.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\none_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\op.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\pragma.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prod.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Radio.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioBg.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioBg.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioBgMask.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDisp.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDisp_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioE.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioG.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioL.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLDotMask.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLeft.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLeftMask.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLM.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioM.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioN.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioR.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioR.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioRM.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioRU.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioW.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rbcheck.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rbtxt.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Rss.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Rss1.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RssA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RssA1.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rssClose.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rssL.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rssOpen.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RssRefresh.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\s2.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\show.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size_lr.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size_rl.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\skins.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\soft24.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\soft24_SA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\spt.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\style.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\SupportRequest.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\timer.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\TitleIcon.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\toolbar.xml
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\trans.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_disable.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\u.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\unmount-all.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_back.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_dott.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_dott_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_mute.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_mute_check.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\web_resources.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\web_search.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\web_search_SA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\WebS.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\WebSa.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi0.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi1.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi10.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi11.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi12.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi13.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi14.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi2.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi3.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi4.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi5.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi6.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi7.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi8.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi9.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\chrome.manifest
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\chrome\dttoolbar.jar
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\install.rdf

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-11-14 do 2010-12-14 )))))))))))))))))))))))))))))))
.

2010-12-14 16:45 . 2010-12-14 16:45 -------- d-----w- c:\users\Notebook\AppData\Local\temp
2010-12-14 16:45 . 2010-12-14 16:45 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-12-14 14:22 . 2010-12-14 16:03 -------- d-----w- c:\program files\trend micro
2010-12-14 14:22 . 2010-12-14 14:23 -------- d-----w- C:\rsit
2010-12-14 12:14 . 2010-11-10 04:33 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{246FAB05-F1CF-4DEF-9AAB-C2F19E95C092}\mpengine.dll
2010-12-14 12:12 . 2010-12-14 12:12 -------- d-----w- c:\program files\MSXML 4.0
2010-12-13 17:47 . 2010-12-13 17:47 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2010-12-13 17:37 . 2010-12-13 17:58 -------- d-----w- c:\program files\Common Files\SolidWorks Shared
2010-12-13 17:37 . 2010-12-13 17:37 -------- d-----w- c:\program files\AGEIA Technologies
2010-12-13 17:37 . 2010-12-13 18:00 -------- d-----w- c:\program files\SolidWorks Corp
2010-12-13 17:37 . 2010-12-13 17:46 -------- d-----w- c:\programdata\SolidWorks
2010-12-13 17:36 . 2010-12-13 17:51 -------- d-----w- C:\SolidWorks Data
2010-12-13 14:53 . 2010-12-13 14:53 -------- d-----w- c:\users\Notebook\AppData\Local\ESET
2010-12-13 12:12 . 2010-12-13 19:01 -------- d-----w- c:\users\Notebook\AppData\Roaming\BitComet
2010-12-13 12:12 . 2010-12-13 15:38 -------- d-----w- C:\Downloads
2010-12-13 12:11 . 2010-12-13 12:11 -------- d-----w- c:\program files\BitComet
2010-12-11 16:14 . 2010-12-11 16:14 -------- d-----w- c:\programdata\Macrovision
2010-12-10 12:01 . 2010-12-11 17:22 -------- d-----w- c:\programdata\FLEXnet
2010-12-10 11:36 . 2010-12-10 11:37 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2010-12-10 11:36 . 2010-12-10 11:36 -------- d-----w- c:\program files\MSECache
2010-12-10 11:33 . 2010-12-13 17:36 -------- d-----w- c:\program files\Common Files\Manažer instalací SolidWorks
2010-12-10 11:23 . 2010-12-10 11:23 -------- d-----w- c:\program files\Common Files\InstallShield
2010-12-10 11:13 . 2010-12-13 17:36 -------- d-----w- c:\windows\SolidWorks
2010-12-10 11:13 . 2010-12-10 12:01 -------- d-----w- c:\users\Notebook\AppData\Roaming\SolidWorks
2010-11-24 13:37 . 2010-10-19 04:27 7680 ----a-w- c:\program files\Internet Explorer\iecompat.dll
2010-11-23 17:56 . 2010-11-23 17:56 -------- d-----w- c:\users\Notebook\AppData\Roaming\progeSOFT
2010-11-23 17:56 . 2010-11-23 17:57 -------- d-----w- c:\programdata\progeSOFT
2010-11-23 17:54 . 2009-04-15 13:59 431616 ----a-w- c:\windows\system32\temp.005
2010-11-23 17:54 . 2009-04-15 13:59 1392671 ----a-w- c:\windows\system32\temp.004
2010-11-23 17:53 . 2009-04-15 13:58 77878 ----a-w- c:\windows\system32\temp.002
2010-11-23 17:53 . 2009-04-15 13:58 69632 ----a-w- c:\windows\system32\temp.003
2010-11-23 17:53 . 2009-04-15 13:58 266293 ----a-w- c:\windows\system32\temp.001
2010-11-23 17:52 . 2009-04-15 13:57 2134016 ----a-w- c:\windows\system32\cdintf251.dll
2010-11-23 17:52 . 2004-08-19 14:39 151552 ----a-w- c:\windows\system32\temp.000
2010-11-23 17:52 . 1999-11-08 12:45 339968 ----a-w- c:\windows\system32\Slide.ocx
2010-11-23 17:52 . 1999-07-21 16:25 274432 ----a-w- c:\windows\system32\DwgThumbnail.ocx
2010-11-23 17:51 . 2009-04-15 13:58 43968 ----a-w- c:\windows\system32\drivers\eusk3usb.sys
2010-11-23 17:51 . 2010-11-23 17:51 1115704 ----a-w- c:\windows\system32\O2CPlayer.OCX
2010-11-23 17:51 . 2001-03-13 14:49 140288 ----a-w- c:\windows\system32\COMDLG32.OCX
2010-11-23 17:51 . 1998-04-24 23:00 368912 ----a-w- c:\windows\system32\vbar332.dll
2010-11-15 18:34 . 2010-11-15 18:36 -------- d-----w- c:\program files\Common Files\3DO Shared

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-12 10:32 . 2010-11-12 10:32 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-10-19 09:41 . 2009-12-31 12:16 222080 ------w- c:\windows\system32\MpSigStub.exe
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;c:\program files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [2009-10-15 87336]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [2010-01-07 380928]
R4 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
R4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2005-09-23 2799808]
R4 Remote Solver for Flow Simulation 2010;Remote Solver for Flow Simulation 2010;c:\program files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe [2009-09-11 144680]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-11-12 691696]
S2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
.
------- Doplňkový sken -------
.
Trusted Zone: mojebanka.cz\*
Trusted Zone: mojebanka.cz\*
FF - ProfilePath - c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Personas: personas@christopher.beard - %profile%\extensions\personas@christopher.beard
FF - Ext: BitComet Video Downloader: {B042753D-F57E-4e8e-A01B-7379A6D4CEFB} - %profile%\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

AddRemove-DAEMON Tools Toolbar - c:\program files\DAEMON Tools Toolbar\uninst.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-14 17:45
Windows 6.0.6002 Service Pack 2 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Celkový čas: 2010-12-14 17:46:35
ComboFix-quarantined-files.txt 2010-12-14 16:46
ComboFix2.txt 2010-12-14 16:22

Před spuštěním: Volných bajtů: 148 112 240 640
Po spuštění: Volných bajtů: 148 090 269 696

- - End Of File - - 5C9256E4DFA5961881EFD797BF9F0F05

Odpovědět