Zdravim,
dneska mi byl ukraden ICQ ucet a stale si nejsem jist, jestli byla chyba na moji strane nebo ke kradezi doslo jinak, nez pres muj notebook. Celou dobu jsem mel nainstalovany Norton, ale najednou jsem zjistil , ze ani nejde spustit. Proto jsem ho odinstaloval a udelal log z hijackthis. Premyslim, ze bych to i cely pro jistotu zformatoval (a to jsem formatoval nedavno), ale rad bych vedel, jestli jsem tam mam nejakou mrchu, abych si na to daval vice pozor, protoze ukradeny ICQ ucet, ktery mam 10 let neni nic prijemneho (nejsem sam, v poslednich dnech se to stalo mnoha lidem) a ICQ se tvari jakoby nic...chjo. Predem dekuji za odpovedi.
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:16:47, on 19.1.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16700)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\rundll32.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\O S T A T N I\totalcmd\TOTALCMD.EXE
C:\Program Files\Opera\opera.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\NOTEPAD.EXE
C:\Users\Ha-ns\AppData\Local\Opera\Opera\temporary_downloads\RSIT.exe
C:\Program Files\trend micro\Ha-ns.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Microsoft Web Test Recorder 10.0 Helper - {DDA57003-0068-4ed2-9D32-4D1EC707D94D} - C:\Program Files\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\Ha-ns\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Ha-ns\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O8 - Extra context menu item: Stáhnout pomocí &BitSpiritu - C:\Program Files\BitSpirit\bsurl.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: Device Error Recovery Service (dgdersvc) - Devguru Co., Ltd. - C:\Windows\system32\dgdersvc.exe
O23 - Service: FsUsbExService - Teruten - C:\Windows\system32\FsUsbExService.Exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
--
End of file - 4798 bytes
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2337997463-3138014002-1648050931-1001Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2337997463-3138014002-1648050931-1001UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-01-14 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DDA57003-0068-4ed2-9D32-4D1EC707D94D}]
Microsoft Web Test Recorder 10.0 Helper - C:\Program Files\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll [2010-03-19 61360]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2009-01-30 13605408]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2009-01-30 92704]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2010-02-22 8522272]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\Ha-ns\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-01 136176]
"KiesTrayAgent"= []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2011-01-19 17:16:45 ----D---- C:\rsit
2011-01-19 17:16:45 ----D---- C:\Program Files\trend micro
2011-01-17 16:47:06 ----A---- C:\Windows\system32\pdfcmnnt.dll
2011-01-17 16:47:02 ----A---- C:\Windows\system32\MSMPIDE.DLL
2011-01-17 16:47:01 ----D---- C:\Program Files\PDFCreator
2011-01-14 19:31:34 ----D---- C:\ProgramData\Sun
2011-01-14 19:31:29 ----D---- C:\Program Files\Common Files\Java
2011-01-14 19:30:55 ----A---- C:\Windows\system32\javaws.exe
2011-01-14 19:30:55 ----A---- C:\Windows\system32\javaw.exe
2011-01-14 19:30:55 ----A---- C:\Windows\system32\java.exe
2011-01-14 19:30:55 ----A---- C:\Windows\system32\deployJava1.dll
2011-01-14 19:30:22 ----D---- C:\Program Files\Java
2011-01-13 09:32:36 ----D---- C:\Program Files\Microsoft Games
2011-01-12 20:37:10 ----A---- C:\Windows\system32\odbc32.dll
2011-01-12 20:37:07 ----A---- C:\Windows\system32\mf.dll
2011-01-12 20:37:07 ----A---- C:\Windows\system32\DWrite.dll
2011-01-12 20:37:07 ----A---- C:\Windows\system32\d3d10warp.dll
2011-01-12 20:37:07 ----A---- C:\Windows\system32\d2d1.dll
2011-01-12 20:37:06 ----A---- C:\Windows\system32\XpsPrint.dll
2011-01-12 20:37:06 ----A---- C:\Windows\system32\FntCache.dll
2011-01-12 20:37:05 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2011-01-12 20:37:05 ----A---- C:\Windows\system32\WMVDECOD.DLL
2011-01-12 20:37:05 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-01-12 20:37:05 ----A---- C:\Windows\system32\d3d10_1core.dll
2011-01-12 20:37:05 ----A---- C:\Windows\system32\cdd.dll
2011-01-12 20:37:04 ----A---- C:\Windows\system32\XpsRasterService.dll
2011-01-12 20:37:04 ----A---- C:\Windows\system32\mfreadwrite.dll
2011-01-12 20:37:04 ----A---- C:\Windows\system32\ExplorerFrame.dll
2011-01-12 20:37:04 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2011-01-12 20:37:04 ----A---- C:\Windows\system32\d3d10_1.dll
2011-01-08 10:58:34 ----D---- C:\Temp
2011-01-04 13:06:54 ----D---- C:\Program Files\VirtualDJ5
2011-01-04 13:03:21 ----D---- C:\Program Files\VirtualDJ
2011-01-03 11:18:16 ----D---- C:\Users\Ha-ns\AppData\Roaming\Ashampoo
2011-01-03 11:12:33 ----D---- C:\ProgramData\ashampoo
2011-01-03 11:12:17 ----D---- C:\Program Files\Ashampoo
2011-01-02 23:31:21 ----D---- C:\U C L
2011-01-02 20:36:19 ----A---- C:\Windows\system32\msvcr71.dll
2011-01-02 18:23:11 ----D---- C:\Users\Ha-ns\AppData\Roaming\WinRAR
2011-01-02 18:19:35 ----D---- C:\Users\Ha-ns\AppData\Roaming\BitSpirit
2011-01-02 18:19:18 ----D---- C:\Program Files\Common Files\BitSpirit
2011-01-02 18:19:17 ----D---- C:\Program Files\BitSpirit
2011-01-02 17:57:15 ----D---- C:\Users\Ha-ns\AppData\Roaming\DVDVideoSoftIEHelpers
2011-01-02 17:46:19 ----D---- C:\Program Files\DVDVideoSoft
2011-01-02 17:46:19 ----D---- C:\Program Files\Common Files\DVDVideoSoft
2011-01-02 11:27:57 ----A---- C:\Windows\system32\WdfCoInstaller01005.dll
2011-01-02 11:27:57 ----A---- C:\Windows\system32\drivers\WdfCoInstaller01005.dll
2011-01-02 11:27:57 ----A---- C:\Windows\system32\drivers\ssadwhnt.sys
2011-01-02 11:27:57 ----A---- C:\Windows\system32\drivers\ssadwh.sys
2011-01-02 11:27:56 ----A---- C:\Windows\system32\drivers\ssadmdm.sys
2011-01-02 11:27:56 ----A---- C:\Windows\system32\drivers\ssadmdfl.sys
2011-01-02 11:27:56 ----A---- C:\Windows\system32\drivers\ssadcmnt.sys
2011-01-02 11:27:56 ----A---- C:\Windows\system32\drivers\ssadcm.sys
2011-01-02 11:27:56 ----A---- C:\Windows\system32\drivers\ssadbus.sys
2011-01-02 11:27:56 ----A---- C:\Windows\system32\drivers\ssadadb.sys
2011-01-02 11:26:00 ----A---- C:\Windows\system32\FsUsbExService.Exe
2011-01-02 11:26:00 ----A---- C:\Windows\system32\FsUsbExDisk.Sys
2011-01-02 11:26:00 ----A---- C:\Windows\system32\FsUsbExDevice.Dll
2011-01-02 11:24:15 ----D---- C:\Program Files\PC Connectivity Solution
2011-01-02 11:23:24 ----D---- C:\Users\Ha-ns\AppData\Roaming\Samsung
2011-01-02 11:23:24 ----D---- C:\ProgramData\Samsung
2011-01-02 11:23:24 ----D---- C:\Program Files\MarkAny
2011-01-02 10:36:14 ----D---- C:\Program Files\Samsung
2011-01-02 10:34:11 ----D---- C:\Program Files\Common Files\Samsung
2011-01-02 04:45:41 ----A---- C:\Windows\system32\perf-SQLAgent$SQLEXPRESS-sqlagtctr10.1.2531.0.dll
2011-01-02 04:45:21 ----A---- C:\Windows\system32\perf-MSSQL$SQLEXPRESS-sqlctr10.1.2531.0.dll
2011-01-02 04:43:46 ----D---- C:\Windows\system32\RsFx
2011-01-02 04:35:34 ----D---- C:\Program Files\Microsoft SQL Server
2011-01-02 04:34:55 ----D---- C:\Program Files\Microsoft Sync Framework
2011-01-02 04:34:45 ----D---- C:\Program Files\Microsoft Synchronization Services
2011-01-02 04:34:45 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2011-01-02 04:33:16 ----D---- C:\ProgramData\PreEmptive Solutions
2011-01-02 04:29:58 ----D---- C:\Program Files\Microsoft Silverlight
2011-01-02 04:27:22 ----D---- C:\Program Files\Microsoft ASP.NET
2011-01-02 04:27:16 ----D---- C:\Program Files\IIS
2011-01-02 04:16:19 ----D---- C:\Windows\system32\1033
2011-01-02 04:16:00 ----D---- C:\Windows\symbols
2011-01-02 04:15:28 ----D---- C:\Program Files\Microsoft SDKs
2011-01-02 04:15:28 ----D---- C:\Program Files\Microsoft F#
2011-01-02 04:15:28 ----D---- C:\Program Files\HTML Help Workshop
2011-01-02 04:15:27 ----D---- C:\Program Files\Microsoft Visual Studio 10.0
2011-01-02 04:15:27 ----D---- C:\Program Files\Microsoft Help Viewer
2011-01-02 04:15:27 ----D---- C:\Program Files\Common Files\Merge Modules
2011-01-02 04:10:50 ----D---- C:\Program Files\Microsoft Visual Studio 9.0
2011-01-02 01:23:10 ----A---- C:\Windows\system32\msonpmon.dll
2011-01-02 01:21:19 ----D---- C:\Program Files\Microsoft Works
2011-01-02 01:20:47 ----D---- C:\Program Files\Microsoft Visual Studio
2011-01-02 01:20:47 ----D---- C:\Program Files\Common Files\DESIGNER
2011-01-02 01:20:09 ----D---- C:\Windows\PCHEALTH
2011-01-02 01:20:09 ----D---- C:\Program Files\Microsoft.NET
2011-01-02 01:18:12 ----D---- C:\Program Files\Microsoft Visual Studio 8
2011-01-02 01:16:58 ----D---- C:\Program Files\Microsoft Office
2011-01-02 01:16:57 ----D---- C:\ProgramData\Microsoft Help
2011-01-02 01:04:18 ----RHD---- C:\MSOCache
2011-01-02 00:09:49 ----D---- C:\Windows\system32\appmgmt
2011-01-02 00:01:11 ----D---- C:\D I R E C T
2011-01-01 23:04:31 ----D---- C:\ProgramData\Adobe
2011-01-01 23:04:23 ----D---- C:\Program Files\Common Files\Adobe
2011-01-01 23:04:23 ----D---- C:\Program Files\Adobe
2011-01-01 23:03:14 ----SHD---- C:\Windows\Installer
2011-01-01 22:52:27 ----D---- C:\Users\Ha-ns\AppData\Roaming\Media Player Classic
2011-01-01 22:45:50 ----D---- C:\Program Files\Common Files\EZB Systems
2011-01-01 22:45:49 ----D---- C:\Program Files\UltraISO
2011-01-01 22:45:06 ----D---- C:\Program Files\Combined Community Codec Pack
2011-01-01 22:35:40 ----A---- C:\Windows\system32\XAudio2_5.dll
2011-01-01 22:35:39 ----A---- C:\Windows\system32\xactengine3_5.dll
2011-01-01 22:35:39 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2011-01-01 22:35:38 ----A---- C:\Windows\system32\D3DX9_42.dll
2011-01-01 22:35:38 ----A---- C:\Windows\system32\d3dx11_42.dll
2011-01-01 22:35:38 ----A---- C:\Windows\system32\d3dx10_42.dll
2011-01-01 22:35:38 ----A---- C:\Windows\system32\d3dcsx_42.dll
2011-01-01 22:35:37 ----A---- C:\Windows\system32\D3DX9_41.dll
2011-01-01 22:35:37 ----A---- C:\Windows\system32\d3dx10_41.dll
2011-01-01 22:35:37 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2011-01-01 22:35:36 ----A---- C:\Windows\system32\XAudio2_4.dll
2011-01-01 22:35:36 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2011-01-01 22:35:36 ----A---- C:\Windows\system32\xactengine3_4.dll
2011-01-01 22:35:36 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2011-01-01 22:35:36 ----A---- C:\Windows\system32\d3dx10_40.dll
2011-01-01 22:35:36 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2011-01-01 22:35:35 ----A---- C:\Windows\system32\D3DX9_40.dll
2011-01-01 22:35:34 ----A---- C:\Windows\system32\XAudio2_3.dll
2011-01-01 22:35:34 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2011-01-01 22:35:34 ----A---- C:\Windows\system32\xactengine3_3.dll
2011-01-01 22:35:34 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2011-01-01 22:35:33 ----A---- C:\Windows\system32\XAudio2_2.dll
2011-01-01 22:35:33 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2011-01-01 22:35:33 ----A---- C:\Windows\system32\xactengine3_2.dll
2011-01-01 22:35:32 ----A---- C:\Windows\system32\D3DX9_39.dll
2011-01-01 22:35:32 ----A---- C:\Windows\system32\d3dx10_39.dll
2011-01-01 22:35:32 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2011-01-01 22:35:31 ----A---- C:\Windows\system32\XAudio2_1.dll
2011-01-01 22:35:31 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2011-01-01 22:35:31 ----A---- C:\Windows\system32\xactengine3_1.dll
2011-01-01 22:35:31 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2011-01-01 22:35:30 ----A---- C:\Windows\system32\D3DX9_38.dll
2011-01-01 22:35:30 ----A---- C:\Windows\system32\d3dx10_38.dll
2011-01-01 22:35:30 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2011-01-01 22:35:29 ----A---- C:\Windows\system32\XAudio2_0.dll
2011-01-01 22:35:29 ----A---- C:\Windows\system32\xactengine3_0.dll
2011-01-01 22:35:29 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2011-01-01 22:35:28 ----A---- C:\Windows\system32\xactengine2_10.dll
2011-01-01 22:35:28 ----A---- C:\Windows\system32\D3DX9_37.dll
2011-01-01 22:35:28 ----A---- C:\Windows\system32\d3dx10_37.dll
2011-01-01 22:35:28 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2011-01-01 22:35:26 ----A---- C:\Windows\system32\xactengine2_9.dll
2011-01-01 22:35:26 ----A---- C:\Windows\system32\d3dx9_36.dll
2011-01-01 22:35:26 ----A---- C:\Windows\system32\d3dx10_36.dll
2011-01-01 22:35:26 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2011-01-01 22:35:25 ----A---- C:\Windows\system32\d3dx9_35.dll
2011-01-01 22:35:25 ----A---- C:\Windows\system32\d3dx10_35.dll
2011-01-01 22:35:25 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2011-01-01 22:35:24 ----A---- C:\Windows\system32\xactengine2_8.dll
2011-01-01 22:35:24 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2011-01-01 22:35:24 ----A---- C:\Windows\system32\d3dx10_34.dll
2011-01-01 22:35:24 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2011-01-01 22:35:23 ----A---- C:\Windows\system32\xinput1_3.dll
2011-01-01 22:35:23 ----A---- C:\Windows\system32\d3dx9_34.dll
2011-01-01 22:35:22 ----A---- C:\Windows\system32\xactengine2_7.dll
2011-01-01 22:35:22 ----A---- C:\Windows\system32\d3dx9_33.dll
2011-01-01 22:35:22 ----A---- C:\Windows\system32\d3dx10_33.dll
2011-01-01 22:35:22 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2011-01-01 22:35:21 ----A---- C:\Windows\system32\xactengine2_6.dll
2011-01-01 22:35:20 ----A---- C:\Windows\system32\xactengine2_5.dll
2011-01-01 22:35:20 ----A---- C:\Windows\system32\d3dx10.dll
2011-01-01 22:35:19 ----A---- C:\Windows\system32\xactengine2_4.dll
2011-01-01 22:35:19 ----A---- C:\Windows\system32\x3daudio1_1.dll
2011-01-01 22:35:19 ----A---- C:\Windows\system32\d3dx9_32.dll
2011-01-01 22:35:19 ----A---- C:\Windows\system32\d3dx9_31.dll
2011-01-01 22:35:18 ----A---- C:\Windows\system32\xinput1_2.dll
2011-01-01 22:35:18 ----A---- C:\Windows\system32\xactengine2_3.dll
2011-01-01 22:35:17 ----A---- C:\Windows\system32\xinput1_1.dll
2011-01-01 22:35:17 ----A---- C:\Windows\system32\xactengine2_2.dll
2011-01-01 22:35:17 ----A---- C:\Windows\system32\xactengine2_1.dll
2011-01-01 22:35:07 ----A---- C:\Windows\system32\d3dx9_30.dll
2011-01-01 22:35:06 ----A---- C:\Windows\system32\xactengine2_0.dll
2011-01-01 22:35:06 ----A---- C:\Windows\system32\x3daudio1_0.dll
2011-01-01 22:35:06 ----A---- C:\Windows\system32\d3dx9_29.dll
2011-01-01 22:35:05 ----A---- C:\Windows\system32\d3dx9_28.dll
2011-01-01 22:35:05 ----A---- C:\Windows\system32\d3dx9_27.dll
2011-01-01 22:35:05 ----A---- C:\Windows\system32\d3dx9_26.dll
2011-01-01 22:35:04 ----A---- C:\Windows\system32\d3dx9_25.dll
2011-01-01 22:35:04 ----A---- C:\Windows\system32\d3dx9_24.dll
2011-01-01 22:31:16 ----D---- C:\Program Files\WinRAR
2011-01-01 22:27:18 ----D---- C:\ProgramData\Norton
2011-01-01 22:27:10 ----D---- C:\ProgramData\NortonInstaller
2011-01-01 21:23:18 ----D---- C:\Users\Ha-ns\AppData\Roaming\Macromedia
2011-01-01 21:23:18 ----D---- C:\Users\Ha-ns\AppData\Roaming\Adobe
2011-01-01 21:23:12 ----D---- C:\Windows\system32\Macromed
2011-01-01 18:51:45 ----D---- C:\Program Files\Wireless Console 2
2011-01-01 18:50:36 ----D---- C:\Program Files\ATK Hotkey
2011-01-01 18:49:58 ----D---- C:\Windows\system32\RTCOM
2011-01-01 18:49:41 ----D---- C:\Users\Ha-ns\AppData\Roaming\InstallShield
2011-01-01 18:49:24 ----A---- C:\Windows\system32\WavesLib.dll
2011-01-01 18:49:24 ----A---- C:\Windows\system32\SRSWOW.dll
2011-01-01 18:49:24 ----A---- C:\Windows\system32\SRSTSXT.dll
2011-01-01 18:49:24 ----A---- C:\Windows\system32\SRSTSHD.dll
2011-01-01 18:49:24 ----A---- C:\Windows\system32\SRSHP360.dll
2011-01-01 18:49:23 ----A---- C:\Windows\system32\RtkPgExt.dll
2011-01-01 18:49:23 ----A---- C:\Windows\system32\RtkCoInst.dll
2011-01-01 18:49:23 ----A---- C:\Windows\system32\RtkApoApi.dll
2011-01-01 18:49:23 ----A---- C:\Windows\system32\RtkAPO.dll
2011-01-01 18:49:23 ----A---- C:\Windows\system32\RTEEP32A.dll
2011-01-01 18:49:23 ----A---- C:\Windows\system32\RTEEL32A.dll
2011-01-01 18:49:23 ----A---- C:\Windows\system32\RTEEG32A.dll
2011-01-01 18:49:23 ----A---- C:\Windows\system32\RTEED32A.dll
2011-01-01 18:49:23 ----A---- C:\Windows\system32\RP3DHT32.dll
2011-01-01 18:49:23 ----A---- C:\Windows\system32\RP3DAA32.dll
2011-01-01 18:49:23 ----A---- C:\Windows\system32\drivers\RTKVHDA.sys
2011-01-01 18:49:22 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2011-01-01 18:49:22 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2011-01-01 18:49:22 ----A---- C:\Windows\system32\MaxxAudioAPO.dll
2011-01-01 18:49:22 ----A---- C:\Windows\system32\FMAPO.dll
2011-01-01 18:49:22 ----A---- C:\Windows\system32\DTSVoiceClarityDLL.dll
2011-01-01 18:49:22 ----A---- C:\Windows\system32\DTSS2SpeakerDLL.dll
2011-01-01 18:49:22 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL.dll
2011-01-01 18:49:22 ----A---- C:\Windows\system32\DTSNeoPCDLL.dll
2011-01-01 18:49:22 ----A---- C:\Windows\system32\DTSLimiterDLL.dll
2011-01-01 18:49:21 ----HD---- C:\Program Files\InstallShield Installation Information
2011-01-01 18:49:21 ----D---- C:\Program Files\Realtek
2011-01-01 18:49:21 ----A---- C:\Windows\system32\DTSLFXAPO.dll
2011-01-01 18:49:21 ----A---- C:\Windows\system32\DTSGFXAPO.dll
2011-01-01 18:49:21 ----A---- C:\Windows\system32\DTSGainCompensatorDLL.dll
2011-01-01 18:49:21 ----A---- C:\Windows\system32\DTSBoostDLL.dll
2011-01-01 18:49:21 ----A---- C:\Windows\system32\DTSBassEnhancementDLL.dll
2011-01-01 18:49:21 ----A---- C:\Windows\system32\AERTARen.dll
2011-01-01 18:49:21 ----A---- C:\Windows\system32\AERTACap.dll
2011-01-01 18:49:19 ----HD---- C:\Program Files\Temp
2011-01-01 18:49:19 ----A---- C:\Windows\RtlExUpd.dll
2011-01-01 18:49:15 ----D---- C:\Program Files\Common Files\InstallShield
2011-01-01 18:48:33 ----D---- C:\Users\Ha-ns\AppData\Roaming\GHISLER
2011-01-01 18:48:33 ----A---- C:\Windows\UC.PIF
2011-01-01 18:48:33 ----A---- C:\Windows\RAR.PIF
2011-01-01 18:48:33 ----A---- C:\Windows\PKZIP.PIF
2011-01-01 18:48:33 ----A---- C:\Windows\PKUNZIP.PIF
2011-01-01 18:48:33 ----A---- C:\Windows\NOCLOSE.PIF
2011-01-01 18:48:33 ----A---- C:\Windows\LHA.PIF
2011-01-01 18:48:33 ----A---- C:\Windows\ARJ.PIF
2011-01-01 18:47:59 ----D---- C:\O S T A T N I
2011-01-01 18:44:46 ----D---- C:\Users\Ha-ns\AppData\Roaming\Opera
2011-01-01 18:44:43 ----D---- C:\Program Files\Opera
2011-01-01 18:40:51 ----D---- C:\Windows\system32\Wat
2011-01-01 03:31:37 ----D---- C:\Windows\Panther
2011-01-01 03:31:25 ----RASH---- C:\BOOTSECT.BAK
2011-01-01 03:31:22 ----SHD---- C:\Boot
2010-12-31 19:23:08 ----A---- C:\Windows\system32\msv1_0.dll
2010-12-31 19:21:57 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2010-12-31 19:21:57 ----A---- C:\Windows\system32\PresentationHost.exe
2010-12-31 19:21:57 ----A---- C:\Windows\system32\netfxperf.dll
2010-12-31 19:21:57 ----A---- C:\Windows\system32\mscoree.dll
2010-12-31 19:21:57 ----A---- C:\Windows\system32\dfshim.dll
2010-12-31 19:18:23 ----N---- C:\Windows\system32\MpSigStub.exe
2010-12-31 19:15:41 ----A---- C:\Windows\system32\browserchoice.exe
2010-12-31 19:15:06 ----A---- C:\Windows\system32\drivers\ks.sys
2010-12-31 19:13:58 ----A---- C:\Windows\system32\MRT.exe
2010-12-31 19:13:08 ----A---- C:\Windows\system32\webio.dll
2010-12-31 19:13:07 ----A---- C:\Windows\system32\schannel.dll
2010-12-31 19:13:02 ----A---- C:\Windows\system32\tzres.dll
2010-12-31 19:12:58 ----A---- C:\Windows\system32\oleaut32.dll
2010-12-31 19:12:53 ----A---- C:\Windows\system32\winresume.exe
2010-12-31 19:12:53 ----A---- C:\Windows\system32\winload.exe
2010-12-31 19:12:53 ----A---- C:\Windows\system32\CertEnroll.dll
2010-12-31 19:12:51 ----A---- C:\Windows\system32\consent.exe
2010-12-31 19:12:50 ----A---- C:\Windows\system32\StructuredQuery.dll
2010-12-31 19:12:50 ----A---- C:\Windows\system32\drivers\fvevol.sys
2010-12-31 19:12:45 ----A---- C:\Windows\system32\CPFilters.dll
2010-12-31 19:12:44 ----A---- C:\Windows\system32\psisdecd.dll
2010-12-31 19:12:44 ----A---- C:\Windows\system32\msdri.dll
2010-12-31 19:12:43 ----A---- C:\Windows\system32\mfc40u.dll
2010-12-31 19:12:43 ----A---- C:\Windows\system32\mfc40.dll
2010-12-31 19:12:37 ----A---- C:\Windows\system32\lsasrv.dll
2010-12-31 19:12:37 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2010-12-31 19:12:36 ----A---- C:\Windows\system32\mshtml.dll
2010-12-31 19:12:35 ----A---- C:\Windows\system32\iertutil.dll
2010-12-31 19:12:35 ----A---- C:\Windows\system32\ieframe.dll
2010-12-31 19:12:33 ----A---- C:\Windows\system32\wininet.dll
2010-12-31 19:12:33 ----A---- C:\Windows\system32\urlmon.dll
2010-12-31 19:12:33 ----A---- C:\Windows\system32\mstime.dll
2010-12-31 19:12:33 ----A---- C:\Windows\system32\mshtmled.dll
2010-12-31 19:12:33 ----A---- C:\Windows\system32\msfeedssync.exe
2010-12-31 19:12:33 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-12-31 19:12:33 ----A---- C:\Windows\system32\msfeeds.dll
2010-12-31 19:12:33 ----A---- C:\Windows\system32\licmgr10.dll
2010-12-31 19:12:33 ----A---- C:\Windows\system32\jsproxy.dll
2010-12-31 19:12:33 ----A---- C:\Windows\system32\ieui.dll
2010-12-31 19:12:33 ----A---- C:\Windows\system32\iepeers.dll
2010-12-31 19:12:33 ----A---- C:\Windows\system32\iedkcs32.dll
2010-12-31 19:12:31 ----A---- C:\Windows\system32\shell32.dll
2010-12-31 19:12:30 ----A---- C:\Windows\system32\wmicmiplugin.dll
2010-12-31 19:12:30 ----A---- C:\Windows\system32\taskschd.dll
2010-12-31 19:12:30 ----A---- C:\Windows\system32\taskeng.exe
2010-12-31 19:12:30 ----A---- C:\Windows\system32\taskcomp.dll
2010-12-31 19:12:30 ----A---- C:\Windows\system32\schtasks.exe
2010-12-31 19:12:30 ----A---- C:\Windows\system32\schedsvc.dll
2010-12-31 19:12:29 ----A---- C:\Windows\system32\winlogon.exe
2010-12-31 19:12:29 ----A---- C:\Windows\explorer.exe
2010-12-31 19:12:28 ----A---- C:\Windows\system32\kernel32.dll
2010-12-31 19:12:28 ----A---- C:\Windows\system32\apphelp.dll
2010-12-31 19:12:27 ----A---- C:\Windows\system32\ole32.dll
2010-12-31 19:12:21 ----A---- C:\Windows\system32\wmp.dll
2010-12-31 19:12:20 ----A---- C:\Windows\system32\wmploc.DLL
2010-12-31 19:12:20 ----A---- C:\Windows\system32\spoolsv.exe
2010-12-31 19:12:19 ----A---- C:\Windows\system32\srvsvc.dll
2010-12-31 19:12:19 ----A---- C:\Windows\system32\drivers\srvnet.sys
2010-12-31 19:12:19 ----A---- C:\Windows\system32\drivers\srv2.sys
2010-12-31 19:12:19 ----A---- C:\Windows\system32\drivers\srv.sys
2010-12-31 19:12:18 ----A---- C:\Windows\system32\ntoskrnl.exe
2010-12-31 19:12:18 ----A---- C:\Windows\system32\ntkrnlpa.exe
2010-12-31 19:12:17 ----A---- C:\Windows\system32\vbscript.dll
2010-12-31 19:12:16 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2010-12-31 19:12:16 ----A---- C:\Windows\system32\secproc_ssp.dll
2010-12-31 19:12:16 ----A---- C:\Windows\system32\secproc_isv.dll
2010-12-31 19:12:16 ----A---- C:\Windows\system32\secproc.dll
2010-12-31 19:12:16 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2010-12-31 19:12:16 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2010-12-31 19:12:16 ----A---- C:\Windows\system32\RMActivate_isv.exe
2010-12-31 19:12:16 ----A---- C:\Windows\system32\RMActivate.exe
2010-12-31 19:12:16 ----A---- C:\Windows\system32\inetcomm.dll
2010-12-31 19:12:15 ----A---- C:\Windows\system32\t2embed.dll
2010-12-31 19:12:15 ----A---- C:\Windows\system32\drivers\tcpip.sys
2010-12-31 19:12:14 ----A---- C:\Windows\system32\msasn1.dll
2010-12-31 19:12:13 ----A---- C:\Windows\system32\rtutils.dll
2010-12-31 19:12:12 ----A---- C:\Windows\system32\wmpmde.dll
2010-12-31 19:12:12 ----A---- C:\Windows\system32\comctl32.dll
2010-12-31 19:12:11 ----A---- C:\Windows\system32\ntdll.dll
2010-12-31 19:12:11 ----A---- C:\Windows\system32\jscript.dll
2010-12-31 19:12:10 ----A---- C:\Windows\system32\tsbyuv.dll
2010-12-31 19:12:10 ----A---- C:\Windows\system32\quartz.dll
2010-12-31 19:12:10 ----A---- C:\Windows\system32\msyuv.dll
2010-12-31 19:12:10 ----A---- C:\Windows\system32\msvidc32.dll
2010-12-31 19:12:10 ----A---- C:\Windows\system32\msrle32.dll
2010-12-31 19:12:10 ----A---- C:\Windows\system32\mciavi32.dll
2010-12-31 19:12:10 ----A---- C:\Windows\system32\iyuv_32.dll
2010-12-31 19:12:10 ----A---- C:\Windows\system32\avifil32.dll
2010-12-31 19:12:09 ----A---- C:\Windows\system32\ir32_32.dll
2010-12-31 19:12:09 ----A---- C:\Windows\system32\iccvid.dll
2010-12-31 19:12:09 ----A---- C:\Windows\system32\fontsub.dll
2010-12-31 19:12:09 ----A---- C:\Windows\system32\atmlib.dll
2010-12-31 19:12:09 ----A---- C:\Windows\system32\atmfd.dll
2010-12-31 19:12:08 ----A---- C:\Windows\system32\msxml3.dll
2010-12-31 19:12:07 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2010-12-31 19:12:07 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2010-12-31 19:12:07 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2010-12-31 19:12:07 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2010-12-31 19:12:07 ----A---- C:\Windows\system32\asycfilt.dll
2010-12-31 19:11:35 ----A---- C:\Windows\system32\win32k.sys
2010-12-31 19:01:06 ----D---- C:\ProgramData\NVIDIA
2010-12-31 18:54:05 ----A---- C:\Windows\system32\nvcpluir.dll
2010-12-31 18:54:05 ----A---- C:\Windows\system32\nvcplui.exe
2010-12-31 18:51:14 ----A---- C:\Windows\system32\NVUNINST.EXE
2010-12-31 18:48:07 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-12-31 18:40:42 ----A---- C:\Windows\system32\wintrust.dll
2010-12-31 18:40:41 ----A---- C:\Windows\system32\cabview.dll
2010-12-31 18:39:24 ----D---- C:\Users\Ha-ns\AppData\Roaming\Identities
2010-12-31 18:39:10 ----SD---- C:\Users\Ha-ns\AppData\Roaming\Microsoft
2010-12-31 18:39:10 ----D---- C:\Users\Ha-ns\AppData\Roaming\Media Center Programs
2010-12-31 18:38:51 ----SHD---- C:\Recovery
2010-12-31 18:35:26 ----D---- C:\Windows\SoftwareDistribution
2010-12-31 18:33:19 ----D---- C:\Windows\Prefetch
2010-12-31 18:32:21 ----ASH---- C:\pagefile.sys
2010-12-31 18:32:20 ----SHD---- C:\System Volume Information
2010-12-31 18:32:20 ----ASH---- C:\hiberfil.sys
======List of files/folders modified in the last 1 months======
2011-01-19 17:16:46 ----D---- C:\Windows\Temp
2011-01-19 17:16:45 ----RD---- C:\Program Files
2011-01-19 16:49:49 ----D---- C:\Windows\System32
2011-01-19 16:49:49 ----D---- C:\Windows\inf
2011-01-19 16:47:32 ----D---- C:\Windows\system32\config
2011-01-19 16:43:55 ----D---- C:\Program Files\Common Files
2011-01-19 16:40:40 ----D---- C:\Windows\system32\drivers
2011-01-16 01:58:42 ----D---- C:\Windows\rescache
2011-01-14 19:31:34 ----HD---- C:\ProgramData
2011-01-13 09:32:56 ----D---- C:\Windows\winsxs
2011-01-12 20:36:58 ----D---- C:\Windows\system32\catroot
2011-01-12 20:36:54 ----D---- C:\Windows\system32\catroot2
2011-01-04 13:07:06 ----RSD---- C:\Windows\Fonts
2011-01-04 12:06:49 ----D---- C:\Windows\system32\Tasks
2011-01-04 09:23:17 ----RSD---- C:\Windows\assembly
2011-01-03 09:52:01 ----D---- C:\Windows\Microsoft.NET
2011-01-02 20:36:24 ----D---- C:\Windows\system
2011-01-02 20:28:07 ----D---- C:\Windows\system32\wdi
2011-01-02 20:27:16 ----D---- C:\Program Files\Common Files\microsoft shared
2011-01-02 20:18:09 ----SD---- C:\ProgramData\Microsoft
2011-01-02 20:02:11 ----A---- C:\Windows\win.ini
2011-01-02 14:08:13 ----D---- C:\Windows\system32\drivers\UMDF
2011-01-02 11:28:31 ----D---- C:\Windows\system32\DriverStore
2011-01-02 04:31:16 ----D---- C:\Program Files\MSBuild
2011-01-02 04:16:00 ----D---- C:\Windows
2011-01-02 04:05:22 ----D---- C:\Windows\system32\en-US
2011-01-02 03:35:23 ----D---- C:\Windows\ShellNew
2011-01-02 01:17:40 ----D---- C:\Program Files\Common Files\System
2011-01-01 22:32:15 ----D---- C:\Windows\Logs
2011-01-01 22:30:28 ----D---- C:\Windows\Tasks
2011-01-01 18:39:53 ----D---- C:\Windows\system32\LogFiles
2010-12-31 19:25:06 ----D---- C:\Windows\system32\migration
2010-12-31 19:25:06 ----D---- C:\Windows\ehome
2010-12-31 19:25:06 ----D---- C:\Program Files\Windows Mail
2010-12-31 19:25:06 ----D---- C:\Program Files\Internet Explorer
2010-12-31 19:25:01 ----D---- C:\Windows\system32\Boot
2010-12-31 19:25:01 ----D---- C:\Windows\AppPatch
2010-12-31 19:25:01 ----D---- C:\Program Files\Windows Media Player
2010-12-31 19:14:02 ----D---- C:\Windows\debug
2010-12-31 18:54:00 ----D---- C:\Windows\Help
2010-12-31 18:52:43 ----D---- C:\Windows\system32\CodeIntegrity
2010-12-31 18:47:06 ----D---- C:\Windows\system32\wbem
2010-12-31 18:40:43 ----D---- C:\Windows\system32\restore
2010-12-31 18:39:21 ----SHD---- C:\$Recycle.Bin
2010-12-31 18:39:07 ----RD---- C:\Users
2010-12-31 18:35:08 ----D---- C:\Windows\system32\sysprep
2010-12-31 18:33:15 ----D---- C:\Windows\CSC
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 ISODrive;ISO DVD/CD-ROM Device Driver; \??\C:\Program Files\UltraISO\drivers\ISODrive.sys [2009-02-10 82320]
R3 dgderdrv;dgderdrv; C:\Windows\System32\drivers\dgderdrv.sys [2010-10-25 18120]
R3 FsUsbExDisk;FsUsbExDisk; \??\C:\Windows\system32\FsUsbExDisk.SYS [2010-10-25 36640]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2010-02-22 3022944]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATKACPI.sys [2007-07-31 7680]
R3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-07-14 84992]
R3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2009-07-13 1068032]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver; C:\Windows\System32\Drivers\ssadadb.sys [2010-08-27 30312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 BthEnum;Bluetooth Request Block Driver; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 392704]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 58880]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM); C:\Windows\system32\DRIVERS\ssadbus.sys [2010-08-27 96488]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter); C:\Windows\system32\DRIVERS\ssadmdfl.sys [2010-08-27 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers; C:\Windows\system32\DRIVERS\ssadmdm.sys [2010-08-27 121576]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
S3 VSPerfDrv100;Performance Tools Driver 10.0; \??\C:\Program Files\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\VSPerfDrv100.sys [2009-12-08 48128]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 34944]
S4 RsFx0103;RsFx0103 Driver; C:\Windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 239336]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ASLDRService;ASLDR Service; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [2007-02-05 94208]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 dgdersvc;Device Error Recovery Service; C:\Windows\system32\dgdersvc.exe [2010-10-25 95568]
R2 FsUsbExService;FsUsbExService; C:\Windows\system32\FsUsbExService.Exe [2010-10-25 217088]
R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [2009-03-30 43010392]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-01-30 203296]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-07-10 98840]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-01-01 1343400]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; C:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-23 47128]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS); C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 366936]
S4 SQLBrowser;SQL Server Browser; C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2009-03-30 254808]
-----------------EOF-----------------

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Prosim o kontrolu. Ukraden ICQ ucet.
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
-
- Návštěvník
- Příspěvky: 2
- Registrován: 07 črc 2008 17:48
Re: Prosim o kontrolu. Ukraden ICQ ucet.
Dobrý večer
Spusťte combofix podle tohoto návodu
http://www.bleepingcomputer.com/combofi ... t-combofix


http://www.bleepingcomputer.com/combofi ... t-combofix
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
-
- Návštěvník
- Příspěvky: 2
- Registrován: 07 črc 2008 17:48
Re: Prosim o kontrolu. Ukraden ICQ ucet.
Dobry vecer,
zde je log, dekuji za snahu
ComboFix 11-01-18.04 - Ha-ns 19.01.2011 19:10:28.1.2 - x86
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1033.18.1535.704 [GMT 1:00]
Spuštěný z: c:\users\Ha-ns\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\muzapp.exe
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-12-19 do 2011-01-19 )))))))))))))))))))))))))))))))
.
2011-01-19 18:19 . 2011-01-19 18:19 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-01-19 16:16 . 2011-01-19 16:16 -------- d-----w- C:\rsit
2011-01-19 16:16 . 2011-01-19 16:16 -------- d-----w- c:\program files\trend micro
2011-01-17 15:47 . 1998-06-23 23:00 137000 ----a-w- c:\windows\system32\MSMAPI32.OCX
2011-01-17 15:47 . 2004-03-08 23:00 662288 ----a-w- c:\windows\system32\MSCOMCT2.OCX
2011-01-17 15:47 . 2001-10-28 15:42 116224 ----a-w- c:\windows\system32\pdfcmnnt.dll
2011-01-17 15:47 . 1998-07-05 23:00 23552 ----a-w- c:\windows\system32\MSMPIDE.DLL
2011-01-17 15:47 . 2011-01-17 15:50 -------- d-----w- c:\program files\PDFCreator
2011-01-14 18:31 . 2011-01-14 18:31 -------- d-----w- c:\program files\Common Files\Java
2011-01-14 18:30 . 2011-01-14 18:30 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-01-14 18:30 . 2011-01-14 18:30 -------- d-----w- c:\program files\Java
2011-01-13 08:32 . 2011-01-13 08:32 -------- d-----w- c:\program files\Microsoft Games
2011-01-08 09:58 . 2011-01-08 09:58 -------- d-----w- C:\Temp
2011-01-04 12:03 . 2011-01-04 12:03 -------- d-----w- c:\program files\VirtualDJ
2011-01-03 10:12 . 2011-01-03 10:12 -------- d-----w- c:\programdata\ashampoo
2011-01-03 10:12 . 2011-01-03 10:12 -------- d-----w- c:\program files\Ashampoo
2011-01-02 22:31 . 2011-01-13 09:55 -------- d-----w- C:\U C L
2011-01-02 19:36 . 2004-01-11 23:00 348160 ----a-w- c:\windows\system\msvcr71.dll
2011-01-02 19:36 . 2004-01-11 23:00 348160 ----a-w- c:\windows\system32\msvcr71.dll
2011-01-02 18:53 . 2011-01-02 18:53 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2011-01-02 17:19 . 2011-01-02 17:19 -------- d-----w- c:\program files\Common Files\BitSpirit
2011-01-02 17:19 . 2011-01-02 17:19 -------- d-----w- c:\program files\BitSpirit
2011-01-02 16:46 . 2011-01-02 16:57 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2011-01-02 16:46 . 2011-01-02 16:46 -------- d-----w- c:\program files\DVDVideoSoft
2011-01-02 10:27 . 2010-08-27 04:32 1416680 ----a-w- c:\windows\system32\WdfCoInstaller01005.dll
2011-01-02 10:27 . 2010-08-27 04:32 1416680 ----a-w- c:\windows\system32\drivers\WdfCoInstaller01005.dll
2011-01-02 10:27 . 2010-08-27 04:32 10216 ----a-w- c:\windows\system32\drivers\ssadwhnt.sys
2011-01-02 10:27 . 2010-08-27 04:32 10216 ----a-w- c:\windows\system32\drivers\ssadwh.sys
2011-01-02 10:27 . 2010-08-27 04:32 96488 ----a-w- c:\windows\system32\drivers\ssadbus.sys
2011-01-02 10:27 . 2010-08-27 04:32 30312 ----a-w- c:\windows\system32\drivers\ssadadb.sys
2011-01-02 10:27 . 2010-08-27 04:32 12776 ----a-w- c:\windows\system32\drivers\ssadmdfl.sys
2011-01-02 10:27 . 2010-08-27 04:32 121576 ----a-w- c:\windows\system32\drivers\ssadmdm.sys
2011-01-02 10:27 . 2010-08-27 04:32 10344 ----a-w- c:\windows\system32\drivers\ssadcmnt.sys
2011-01-02 10:27 . 2010-08-27 04:32 10344 ----a-w- c:\windows\system32\drivers\ssadcm.sys
2011-01-02 10:26 . 2010-10-25 09:03 36640 ----a-w- c:\windows\system32\FsUsbExDisk.Sys
2011-01-02 10:26 . 2010-10-25 09:03 217088 ----a-w- c:\windows\system32\FsUsbExService.Exe
2011-01-02 10:26 . 2010-10-25 09:03 110592 ----a-w- c:\windows\system32\FsUsbExDevice.Dll
2011-01-02 10:24 . 2011-01-02 10:24 -------- d-----w- c:\program files\PC Connectivity Solution
2011-01-02 10:23 . 2011-01-02 10:26 -------- d-----w- c:\programdata\Samsung
2011-01-02 10:23 . 2011-01-02 10:23 -------- d-----w- c:\program files\MarkAny
2011-01-02 09:36 . 2011-01-02 10:26 -------- d-----w- c:\program files\Samsung
2011-01-02 09:34 . 2011-01-02 10:23 -------- d-----w- c:\program files\Common Files\Samsung
2011-01-02 03:45 . 2009-07-23 03:08 50200 ----a-w- c:\windows\system32\perf-SQLAgent$SQLEXPRESS-sqlagtctr10.1.2531.0.dll
2011-01-02 03:45 . 2009-07-23 03:08 79896 ----a-w- c:\windows\system32\perf-MSSQL$SQLEXPRESS-sqlctr10.1.2531.0.dll
2011-01-02 03:43 . 2011-01-02 03:43 -------- d-----w- c:\windows\system32\RsFx
2011-01-02 03:35 . 2011-01-02 03:43 -------- d-----w- c:\program files\Microsoft SQL Server
2011-01-02 03:34 . 2011-01-02 03:34 -------- d-----w- c:\program files\Microsoft Sync Framework
2011-01-02 03:34 . 2011-01-02 03:34 -------- d-----w- c:\program files\Microsoft Synchronization Services
2011-01-02 03:34 . 2011-01-02 03:34 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2011-01-02 03:33 . 2011-01-02 03:33 -------- d-----w- c:\programdata\PreEmptive Solutions
2011-01-02 03:29 . 2011-01-07 23:33 -------- d-----w- c:\program files\Microsoft Silverlight
2011-01-02 03:27 . 2011-01-02 03:27 -------- d-----w- c:\program files\Microsoft ASP.NET
2011-01-02 03:27 . 2011-01-02 03:27 -------- d-----w- c:\program files\IIS
2011-01-02 03:25 . 2011-01-02 03:52 2478272 ----a-w- c:\programdata\Microsoft\VisualStudio\10.0\1033\ResourceCache.dll
2011-01-02 03:16 . 2011-01-02 03:42 -------- d-----w- c:\windows\system32\1033
2011-01-02 03:16 . 2011-01-02 03:16 -------- d-----w- c:\windows\symbols
2011-01-02 03:15 . 2011-01-02 03:35 -------- d-----w- c:\program files\Microsoft SDKs
2011-01-02 03:15 . 2011-01-02 03:19 -------- d-----w- c:\program files\Microsoft F#
2011-01-02 03:15 . 2011-01-02 03:17 -------- d-----w- c:\program files\HTML Help Workshop
2011-01-02 03:15 . 2011-01-02 03:33 -------- d-----w- c:\program files\Microsoft Visual Studio 10.0
2011-01-02 03:15 . 2011-01-02 03:19 -------- d-----w- c:\program files\Common Files\Merge Modules
2011-01-02 03:15 . 2011-01-02 03:15 -------- d-----w- c:\program files\Microsoft Help Viewer
2011-01-02 03:10 . 2011-01-02 03:10 -------- d-----w- c:\program files\Microsoft Visual Studio 9.0
2011-01-02 00:23 . 2008-11-10 10:41 32656 ----a-w- c:\windows\system32\msonpmon.dll
2011-01-02 00:23 . 2006-10-26 18:56 33104 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2011-01-02 00:21 . 2011-01-02 19:05 -------- d-----w- c:\program files\Microsoft Works
2011-01-02 00:20 . 2011-01-02 03:41 -------- d-----w- c:\program files\Microsoft.NET
2011-01-02 00:20 . 2011-01-02 00:20 -------- d-----w- c:\windows\PCHEALTH
2011-01-02 00:18 . 2011-01-02 00:18 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2011-01-02 00:16 . 2011-01-13 07:34 -------- d-----w- c:\programdata\Microsoft Help
2011-01-02 00:04 . 2011-01-02 00:04 -------- d-----r- C:\MSOCache
2011-01-01 23:01 . 2011-01-01 23:01 -------- d-----w- C:\D I R E C T
2011-01-01 22:04 . 2011-01-01 22:04 -------- d-----w- c:\program files\Common Files\Adobe
2011-01-01 22:03 . 2011-01-17 13:01 -------- d-sh--w- c:\windows\Installer
2011-01-01 21:45 . 2011-01-01 21:45 -------- d-----w- c:\program files\Common Files\EZB Systems
2011-01-01 21:45 . 2011-01-01 21:45 -------- d-----w- c:\program files\UltraISO
2011-01-01 21:45 . 2011-01-01 21:45 -------- d-----w- c:\program files\Combined Community Codec Pack
2011-01-01 21:27 . 2011-01-19 15:43 -------- d-----w- c:\programdata\Norton
2011-01-01 20:23 . 2011-01-01 20:23 -------- d-----w- c:\windows\system32\Macromed
2011-01-01 17:51 . 2011-01-01 17:51 -------- d-----w- c:\program files\Wireless Console 2
2011-01-01 17:50 . 2011-01-01 17:50 -------- d-----w- c:\program files\ATK Hotkey
2011-01-01 17:48 . 2010-12-17 06:56 545 ----a-w- c:\windows\UC.PIF
2011-01-01 17:48 . 2010-12-17 06:56 545 ----a-w- c:\windows\RAR.PIF
2011-01-01 17:48 . 2010-12-17 06:56 545 ----a-w- c:\windows\PKZIP.PIF
2011-01-01 17:48 . 2010-12-17 06:56 545 ----a-w- c:\windows\PKUNZIP.PIF
2011-01-01 17:48 . 2010-12-17 06:56 545 ----a-w- c:\windows\NOCLOSE.PIF
2011-01-01 17:48 . 2010-12-17 06:56 545 ----a-w- c:\windows\LHA.PIF
2011-01-01 17:48 . 2010-12-17 06:56 545 ----a-w- c:\windows\ARJ.PIF
2011-01-01 17:47 . 2011-01-19 15:49 -------- d-----w- C:\O S T A T N I
2011-01-01 17:44 . 2011-01-01 23:10 -------- d-----w- c:\program files\Opera
2011-01-01 17:40 . 2011-01-01 17:40 -------- d-----w- c:\windows\system32\Wat
2011-01-01 02:31 . 2010-12-31 17:38 -------- d-----w- c:\windows\Panther
2011-01-01 02:31 . 2011-01-01 02:31 -------- d-----w- C:\Boot
2010-12-31 18:23 . 2009-09-10 05:52 257024 ----a-w- c:\windows\system32\msv1_0.dll
2010-12-31 18:21 . 2009-11-25 11:47 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-12-31 18:21 . 2009-11-25 11:47 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-12-31 18:21 . 2009-11-25 11:47 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-12-31 18:21 . 2009-11-25 11:47 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-12-31 18:21 . 2009-11-25 11:47 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-12-31 18:18 . 2010-11-16 11:01 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6ED5E033-806F-4CE2-889E-C8B6011954A5}\mpengine.dll
2010-12-31 18:18 . 2010-10-19 09:41 222080 ------w- c:\windows\system32\MpSigStub.exe
2010-12-31 18:15 . 2010-02-11 07:10 293376 ----a-w- c:\windows\system32\browserchoice.exe
2010-12-31 18:15 . 2010-03-04 03:57 190976 ----a-w- c:\windows\system32\drivers\ks.sys
2010-12-31 18:13 . 2010-10-16 04:36 314368 ----a-w- c:\windows\system32\webio.dll
2010-12-31 18:13 . 2010-08-21 05:36 224256 ----a-w- c:\windows\system32\schannel.dll
2010-12-31 18:13 . 2010-10-27 04:32 2048 ----a-w- c:\windows\system32\tzres.dll
2010-12-31 18:11 . 2010-10-20 03:00 2327552 ----a-w- c:\windows\system32\win32k.sys
2010-12-31 18:01 . 2010-12-31 18:01 -------- d-----w- c:\programdata\NVIDIA
2010-12-31 17:54 . 2009-01-30 08:12 797216 ----a-w- c:\windows\system32\nvcplui.exe
2010-12-31 17:54 . 2009-01-30 08:12 420384 ----a-w- c:\windows\system32\nvcpl.cpl
2010-12-31 17:54 . 2009-01-30 08:12 1108512 ----a-w- c:\windows\system32\nvcpluir.dll
2010-12-31 17:51 . 2009-02-04 04:45 453152 ----a-w- c:\windows\system32\NVUNINST.EXE
2010-12-31 17:47 . 2011-01-19 15:49 -------- d-----w- c:\windows\system32\wbem\Performance
2010-12-31 17:40 . 2009-12-29 06:55 172032 ----a-w- c:\windows\system32\wintrust.dll
2010-12-31 17:40 . 2010-01-09 06:52 132608 ----a-w- c:\windows\system32\cabview.dll
2010-12-31 17:39 . 2011-01-14 19:01 -------- d-----w- c:\users\Ha-ns
2010-12-31 17:38 . 2010-12-31 17:38 -------- d-----w- C:\Recovery
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-02 04:39 . 2010-12-31 18:12 749056 ----a-w- c:\windows\system32\schedsvc.dll
2010-11-02 04:34 . 2010-12-31 18:12 179712 ----a-w- c:\windows\system32\schtasks.exe
2010-10-25 09:09 . 2010-10-25 09:09 974848 ----a-w- c:\windows\system32\cis-2.4.dll
2010-10-25 09:09 . 2010-10-25 09:09 81920 ----a-w- c:\windows\system32\issacapi_bs-2.3.dll
2010-10-25 09:09 . 2010-10-25 09:09 65536 ----a-w- c:\windows\system32\issacapi_pe-2.3.dll
2010-10-25 09:09 . 2010-10-25 09:09 57344 ----a-w- c:\windows\system32\MTXSYNCICON.dll
2010-10-25 09:09 . 2010-10-25 09:09 57344 ----a-w- c:\windows\system32\MK_Lyric.dll
2010-10-25 09:09 . 2010-10-25 09:09 57344 ----a-w- c:\windows\system32\issacapi_se-2.3.dll
2010-10-25 09:09 . 2010-10-25 09:09 569344 ----a-w- c:\windows\system32\muzdecode.ax
2010-10-25 09:09 . 2010-10-25 09:09 491520 ----a-w- c:\windows\system32\muzapp.dll
2010-10-25 09:09 . 2010-10-25 09:09 49152 ----a-w- c:\windows\system32\MaJGUILib.dll
2010-10-25 09:09 . 2010-10-25 09:09 45056 ----a-w- c:\windows\system32\MaXMLProto.dll
2010-10-25 09:09 . 2010-10-25 09:09 45056 ----a-w- c:\windows\system32\MACXMLProto.dll
2010-10-25 09:09 . 2010-10-25 09:09 413696 ----a-w- c:\programdata\Microsoft\Windows\Templates\msvcp60.dll
2010-10-25 09:09 . 2010-10-25 09:09 40960 ----a-w- c:\windows\system32\MTTELECHIP.dll
2010-10-25 09:09 . 2010-10-25 09:09 40960 ----a-w- c:\windows\system32\MAMACExtract.dll
2010-10-25 09:09 . 2010-10-25 09:09 352256 ----a-w- c:\windows\system32\MSLUR71.dll
2010-10-25 09:09 . 2010-10-25 09:09 258048 ----a-w- c:\windows\system32\muzoggsp.ax
2010-10-25 09:09 . 2010-10-25 09:09 245760 ----a-w- c:\windows\system32\MSCLib.dll
2010-10-25 09:09 . 2010-10-25 09:09 24576 ----a-w- c:\windows\system32\MASetupCleaner.exe
2010-10-25 09:09 . 2010-10-25 09:09 243576 ----a-w- c:\windows\system32\MASetupCaller.dll
2010-10-25 09:09 . 2010-10-25 09:09 23040 ----a-w- c:\programdata\Microsoft\Windows\Templates\psapi.dll
2010-10-25 09:09 . 2010-10-25 09:09 200704 ----a-w- c:\windows\system32\muzwmts.dll
2010-10-25 09:09 . 2010-10-25 09:09 155648 ----a-w- c:\windows\system32\MSFLib.dll
2010-10-25 09:09 . 2010-10-25 09:09 135168 ----a-w- c:\windows\system32\muzaf1.dll
2010-10-25 09:09 . 2010-10-25 09:09 131072 ----a-w- c:\windows\system32\muzmpgsp.ax
2010-10-25 09:09 . 2010-10-25 09:09 122880 ----a-w- c:\windows\system32\muzeffect.ax
2010-10-25 09:09 . 2010-10-25 09:09 118784 ----a-w- c:\windows\system32\MaDRM.dll
2010-10-25 09:09 . 2010-10-25 09:09 110592 ----a-w- c:\windows\system32\muzmp4sp.ax
2010-10-25 09:09 . 2010-10-25 09:09 511328 ----a-w- c:\windows\system32\Synchronization2.dll
2010-10-25 09:09 . 2010-10-25 09:09 288608 ----a-w- c:\windows\system32\Microsoft.Synchronization.dll
2010-10-25 09:09 . 2010-10-25 09:09 253280 ----a-w- c:\windows\system32\MetaStore2.dll
2010-10-25 09:07 . 2010-10-25 09:07 95568 ----a-w- c:\windows\system32\dgdersvc.exe
2010-10-25 09:07 . 2010-10-25 09:07 763216 ----a-w- c:\windows\system32\dgderapi.dll
2010-10-25 09:07 . 2010-10-25 09:07 319456 ----a-w- c:\programdata\Microsoft\Windows\Templates\DIFxAPI.dll
2010-10-25 09:07 . 2010-10-25 09:07 18120 ----a-w- c:\windows\system32\drivers\dgderdrv.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\users\Ha-ns\AppData\Local\Google\Update\GoogleUpdate.exe" [2011-01-01 136176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-30 13605408]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-01-30 92704]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-02-22 8522272]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys [2010-08-27 30312]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [2010-08-27 96488]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [2010-08-27 12776]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [2010-08-27 121576]
R3 VSPerfDrv100;Performance Tools Driver 10.0;c:\program files\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\VSPerfDrv100.sys [2009-12-08 48128]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-01-01 1343400]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-23 47128]
R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 239336]
R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 366936]
S2 dgdersvc;Device Error Recovery Service;c:\windows\system32\dgdersvc.exe [2010-10-25 95568]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-10-25 217088]
S3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [2010-10-25 18120]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2010-10-25 36640]
S3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
--- Ostatní služby/ovladače v paměti ---
*NewlyCreated* - FSUSBEXDISK
.
Obsah adresáře 'Naplánované úlohy'
2011-01-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2337997463-3138014002-1648050931-1001Core.job
- c:\users\Ha-ns\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-01 21:30]
2011-01-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2337997463-3138014002-1648050931-1001UA.job
- c:\users\Ha-ns\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-01 21:30]
.
.
------- Doplňkový sken -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Free YouTube to MP3 Converter - c:\users\Ha-ns\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Stáhnout pomocí &BitSpiritu - c:\program files\BitSpirit\bsurl.htm
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKCU-Run-KiesTrayAgent - (no file)
AddRemove-01_Simmental - c:\program files\Samsung\USB Drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - c:\program files\Samsung\USB Drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-07_Schorl - c:\program files\Samsung\USB Drivers\07_Schorl\Uninstall.exe
AddRemove-09_Hsp - c:\program files\Samsung\USB Drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - c:\program files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-12_Symbian_USB_Download_Driver - c:\program files\Samsung\USB Drivers\12_Symbian_USB_Download_Driver\Uninstall.exe
AddRemove-15_Symbian_Samsung_PC_DLC_Driver - c:\program files\Samsung\USB Drivers\15_Symbian_Samsung_PC_DLC_Driver\Uninstall.exe
AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe
AddRemove-24_flashusbdriver - c:\program files\Samsung\USB Drivers\24_flashusbdriver\Uninstall.exe
AddRemove-25_escape - c:\program files\Samsung\USB Drivers\25_escape\Uninstall.exe
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3g2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.3G2"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.3GP"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.3G2"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gpp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.3GP"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aac\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.ADTS"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.adt\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.ADTS"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.adts\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.ADTS"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.AIFF"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.AIFF"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.AIFF"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.ASF"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.ASX"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.AU"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avi\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.AVI"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cda\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.CDA"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m1v\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2t\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.M2TS"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2ts\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.M2TS"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2v\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.m3u"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.M4A"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4v\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MP4"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MIDI"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.midi\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MIDI"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mkv\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="CCCP.WMP.AssocFile.MKV.1"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mod\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mov\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MOV"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MP3"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2v\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MP3"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MP4"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4v\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MP4"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpa\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpe\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpeg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpv2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mts\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.M2TS"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="CCCP.WMP.AssocFile.OGM.1"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmi\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MIDI"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.AU"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ts\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.TTS"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tts\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.TTS"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.WAV"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wax\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.WAX"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.ASF"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.WMA"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.WMD"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wms\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.WMS"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmv\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.WMV"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.ASX"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmz\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.WMZ"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wpl\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.WPL"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wvx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.WVX"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2011-01-19 19:21:58
ComboFix-quarantined-files.txt 2011-01-19 18:21
Před spuštěním: 13 682 995 200 bytes free
Po spuštění: 13 970 403 328 bytes free
- - End Of File - - B1A43B152A6BA6668F458E0EC8EC9B9E
zde je log, dekuji za snahu

ComboFix 11-01-18.04 - Ha-ns 19.01.2011 19:10:28.1.2 - x86
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1033.18.1535.704 [GMT 1:00]
Spuštěný z: c:\users\Ha-ns\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\muzapp.exe
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-12-19 do 2011-01-19 )))))))))))))))))))))))))))))))
.
2011-01-19 18:19 . 2011-01-19 18:19 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-01-19 16:16 . 2011-01-19 16:16 -------- d-----w- C:\rsit
2011-01-19 16:16 . 2011-01-19 16:16 -------- d-----w- c:\program files\trend micro
2011-01-17 15:47 . 1998-06-23 23:00 137000 ----a-w- c:\windows\system32\MSMAPI32.OCX
2011-01-17 15:47 . 2004-03-08 23:00 662288 ----a-w- c:\windows\system32\MSCOMCT2.OCX
2011-01-17 15:47 . 2001-10-28 15:42 116224 ----a-w- c:\windows\system32\pdfcmnnt.dll
2011-01-17 15:47 . 1998-07-05 23:00 23552 ----a-w- c:\windows\system32\MSMPIDE.DLL
2011-01-17 15:47 . 2011-01-17 15:50 -------- d-----w- c:\program files\PDFCreator
2011-01-14 18:31 . 2011-01-14 18:31 -------- d-----w- c:\program files\Common Files\Java
2011-01-14 18:30 . 2011-01-14 18:30 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-01-14 18:30 . 2011-01-14 18:30 -------- d-----w- c:\program files\Java
2011-01-13 08:32 . 2011-01-13 08:32 -------- d-----w- c:\program files\Microsoft Games
2011-01-08 09:58 . 2011-01-08 09:58 -------- d-----w- C:\Temp
2011-01-04 12:03 . 2011-01-04 12:03 -------- d-----w- c:\program files\VirtualDJ
2011-01-03 10:12 . 2011-01-03 10:12 -------- d-----w- c:\programdata\ashampoo
2011-01-03 10:12 . 2011-01-03 10:12 -------- d-----w- c:\program files\Ashampoo
2011-01-02 22:31 . 2011-01-13 09:55 -------- d-----w- C:\U C L
2011-01-02 19:36 . 2004-01-11 23:00 348160 ----a-w- c:\windows\system\msvcr71.dll
2011-01-02 19:36 . 2004-01-11 23:00 348160 ----a-w- c:\windows\system32\msvcr71.dll
2011-01-02 18:53 . 2011-01-02 18:53 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2011-01-02 17:19 . 2011-01-02 17:19 -------- d-----w- c:\program files\Common Files\BitSpirit
2011-01-02 17:19 . 2011-01-02 17:19 -------- d-----w- c:\program files\BitSpirit
2011-01-02 16:46 . 2011-01-02 16:57 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2011-01-02 16:46 . 2011-01-02 16:46 -------- d-----w- c:\program files\DVDVideoSoft
2011-01-02 10:27 . 2010-08-27 04:32 1416680 ----a-w- c:\windows\system32\WdfCoInstaller01005.dll
2011-01-02 10:27 . 2010-08-27 04:32 1416680 ----a-w- c:\windows\system32\drivers\WdfCoInstaller01005.dll
2011-01-02 10:27 . 2010-08-27 04:32 10216 ----a-w- c:\windows\system32\drivers\ssadwhnt.sys
2011-01-02 10:27 . 2010-08-27 04:32 10216 ----a-w- c:\windows\system32\drivers\ssadwh.sys
2011-01-02 10:27 . 2010-08-27 04:32 96488 ----a-w- c:\windows\system32\drivers\ssadbus.sys
2011-01-02 10:27 . 2010-08-27 04:32 30312 ----a-w- c:\windows\system32\drivers\ssadadb.sys
2011-01-02 10:27 . 2010-08-27 04:32 12776 ----a-w- c:\windows\system32\drivers\ssadmdfl.sys
2011-01-02 10:27 . 2010-08-27 04:32 121576 ----a-w- c:\windows\system32\drivers\ssadmdm.sys
2011-01-02 10:27 . 2010-08-27 04:32 10344 ----a-w- c:\windows\system32\drivers\ssadcmnt.sys
2011-01-02 10:27 . 2010-08-27 04:32 10344 ----a-w- c:\windows\system32\drivers\ssadcm.sys
2011-01-02 10:26 . 2010-10-25 09:03 36640 ----a-w- c:\windows\system32\FsUsbExDisk.Sys
2011-01-02 10:26 . 2010-10-25 09:03 217088 ----a-w- c:\windows\system32\FsUsbExService.Exe
2011-01-02 10:26 . 2010-10-25 09:03 110592 ----a-w- c:\windows\system32\FsUsbExDevice.Dll
2011-01-02 10:24 . 2011-01-02 10:24 -------- d-----w- c:\program files\PC Connectivity Solution
2011-01-02 10:23 . 2011-01-02 10:26 -------- d-----w- c:\programdata\Samsung
2011-01-02 10:23 . 2011-01-02 10:23 -------- d-----w- c:\program files\MarkAny
2011-01-02 09:36 . 2011-01-02 10:26 -------- d-----w- c:\program files\Samsung
2011-01-02 09:34 . 2011-01-02 10:23 -------- d-----w- c:\program files\Common Files\Samsung
2011-01-02 03:45 . 2009-07-23 03:08 50200 ----a-w- c:\windows\system32\perf-SQLAgent$SQLEXPRESS-sqlagtctr10.1.2531.0.dll
2011-01-02 03:45 . 2009-07-23 03:08 79896 ----a-w- c:\windows\system32\perf-MSSQL$SQLEXPRESS-sqlctr10.1.2531.0.dll
2011-01-02 03:43 . 2011-01-02 03:43 -------- d-----w- c:\windows\system32\RsFx
2011-01-02 03:35 . 2011-01-02 03:43 -------- d-----w- c:\program files\Microsoft SQL Server
2011-01-02 03:34 . 2011-01-02 03:34 -------- d-----w- c:\program files\Microsoft Sync Framework
2011-01-02 03:34 . 2011-01-02 03:34 -------- d-----w- c:\program files\Microsoft Synchronization Services
2011-01-02 03:34 . 2011-01-02 03:34 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2011-01-02 03:33 . 2011-01-02 03:33 -------- d-----w- c:\programdata\PreEmptive Solutions
2011-01-02 03:29 . 2011-01-07 23:33 -------- d-----w- c:\program files\Microsoft Silverlight
2011-01-02 03:27 . 2011-01-02 03:27 -------- d-----w- c:\program files\Microsoft ASP.NET
2011-01-02 03:27 . 2011-01-02 03:27 -------- d-----w- c:\program files\IIS
2011-01-02 03:25 . 2011-01-02 03:52 2478272 ----a-w- c:\programdata\Microsoft\VisualStudio\10.0\1033\ResourceCache.dll
2011-01-02 03:16 . 2011-01-02 03:42 -------- d-----w- c:\windows\system32\1033
2011-01-02 03:16 . 2011-01-02 03:16 -------- d-----w- c:\windows\symbols
2011-01-02 03:15 . 2011-01-02 03:35 -------- d-----w- c:\program files\Microsoft SDKs
2011-01-02 03:15 . 2011-01-02 03:19 -------- d-----w- c:\program files\Microsoft F#
2011-01-02 03:15 . 2011-01-02 03:17 -------- d-----w- c:\program files\HTML Help Workshop
2011-01-02 03:15 . 2011-01-02 03:33 -------- d-----w- c:\program files\Microsoft Visual Studio 10.0
2011-01-02 03:15 . 2011-01-02 03:19 -------- d-----w- c:\program files\Common Files\Merge Modules
2011-01-02 03:15 . 2011-01-02 03:15 -------- d-----w- c:\program files\Microsoft Help Viewer
2011-01-02 03:10 . 2011-01-02 03:10 -------- d-----w- c:\program files\Microsoft Visual Studio 9.0
2011-01-02 00:23 . 2008-11-10 10:41 32656 ----a-w- c:\windows\system32\msonpmon.dll
2011-01-02 00:23 . 2006-10-26 18:56 33104 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2011-01-02 00:21 . 2011-01-02 19:05 -------- d-----w- c:\program files\Microsoft Works
2011-01-02 00:20 . 2011-01-02 03:41 -------- d-----w- c:\program files\Microsoft.NET
2011-01-02 00:20 . 2011-01-02 00:20 -------- d-----w- c:\windows\PCHEALTH
2011-01-02 00:18 . 2011-01-02 00:18 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2011-01-02 00:16 . 2011-01-13 07:34 -------- d-----w- c:\programdata\Microsoft Help
2011-01-02 00:04 . 2011-01-02 00:04 -------- d-----r- C:\MSOCache
2011-01-01 23:01 . 2011-01-01 23:01 -------- d-----w- C:\D I R E C T
2011-01-01 22:04 . 2011-01-01 22:04 -------- d-----w- c:\program files\Common Files\Adobe
2011-01-01 22:03 . 2011-01-17 13:01 -------- d-sh--w- c:\windows\Installer
2011-01-01 21:45 . 2011-01-01 21:45 -------- d-----w- c:\program files\Common Files\EZB Systems
2011-01-01 21:45 . 2011-01-01 21:45 -------- d-----w- c:\program files\UltraISO
2011-01-01 21:45 . 2011-01-01 21:45 -------- d-----w- c:\program files\Combined Community Codec Pack
2011-01-01 21:27 . 2011-01-19 15:43 -------- d-----w- c:\programdata\Norton
2011-01-01 20:23 . 2011-01-01 20:23 -------- d-----w- c:\windows\system32\Macromed
2011-01-01 17:51 . 2011-01-01 17:51 -------- d-----w- c:\program files\Wireless Console 2
2011-01-01 17:50 . 2011-01-01 17:50 -------- d-----w- c:\program files\ATK Hotkey
2011-01-01 17:48 . 2010-12-17 06:56 545 ----a-w- c:\windows\UC.PIF
2011-01-01 17:48 . 2010-12-17 06:56 545 ----a-w- c:\windows\RAR.PIF
2011-01-01 17:48 . 2010-12-17 06:56 545 ----a-w- c:\windows\PKZIP.PIF
2011-01-01 17:48 . 2010-12-17 06:56 545 ----a-w- c:\windows\PKUNZIP.PIF
2011-01-01 17:48 . 2010-12-17 06:56 545 ----a-w- c:\windows\NOCLOSE.PIF
2011-01-01 17:48 . 2010-12-17 06:56 545 ----a-w- c:\windows\LHA.PIF
2011-01-01 17:48 . 2010-12-17 06:56 545 ----a-w- c:\windows\ARJ.PIF
2011-01-01 17:47 . 2011-01-19 15:49 -------- d-----w- C:\O S T A T N I
2011-01-01 17:44 . 2011-01-01 23:10 -------- d-----w- c:\program files\Opera
2011-01-01 17:40 . 2011-01-01 17:40 -------- d-----w- c:\windows\system32\Wat
2011-01-01 02:31 . 2010-12-31 17:38 -------- d-----w- c:\windows\Panther
2011-01-01 02:31 . 2011-01-01 02:31 -------- d-----w- C:\Boot
2010-12-31 18:23 . 2009-09-10 05:52 257024 ----a-w- c:\windows\system32\msv1_0.dll
2010-12-31 18:21 . 2009-11-25 11:47 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-12-31 18:21 . 2009-11-25 11:47 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-12-31 18:21 . 2009-11-25 11:47 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-12-31 18:21 . 2009-11-25 11:47 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-12-31 18:21 . 2009-11-25 11:47 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-12-31 18:18 . 2010-11-16 11:01 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6ED5E033-806F-4CE2-889E-C8B6011954A5}\mpengine.dll
2010-12-31 18:18 . 2010-10-19 09:41 222080 ------w- c:\windows\system32\MpSigStub.exe
2010-12-31 18:15 . 2010-02-11 07:10 293376 ----a-w- c:\windows\system32\browserchoice.exe
2010-12-31 18:15 . 2010-03-04 03:57 190976 ----a-w- c:\windows\system32\drivers\ks.sys
2010-12-31 18:13 . 2010-10-16 04:36 314368 ----a-w- c:\windows\system32\webio.dll
2010-12-31 18:13 . 2010-08-21 05:36 224256 ----a-w- c:\windows\system32\schannel.dll
2010-12-31 18:13 . 2010-10-27 04:32 2048 ----a-w- c:\windows\system32\tzres.dll
2010-12-31 18:11 . 2010-10-20 03:00 2327552 ----a-w- c:\windows\system32\win32k.sys
2010-12-31 18:01 . 2010-12-31 18:01 -------- d-----w- c:\programdata\NVIDIA
2010-12-31 17:54 . 2009-01-30 08:12 797216 ----a-w- c:\windows\system32\nvcplui.exe
2010-12-31 17:54 . 2009-01-30 08:12 420384 ----a-w- c:\windows\system32\nvcpl.cpl
2010-12-31 17:54 . 2009-01-30 08:12 1108512 ----a-w- c:\windows\system32\nvcpluir.dll
2010-12-31 17:51 . 2009-02-04 04:45 453152 ----a-w- c:\windows\system32\NVUNINST.EXE
2010-12-31 17:47 . 2011-01-19 15:49 -------- d-----w- c:\windows\system32\wbem\Performance
2010-12-31 17:40 . 2009-12-29 06:55 172032 ----a-w- c:\windows\system32\wintrust.dll
2010-12-31 17:40 . 2010-01-09 06:52 132608 ----a-w- c:\windows\system32\cabview.dll
2010-12-31 17:39 . 2011-01-14 19:01 -------- d-----w- c:\users\Ha-ns
2010-12-31 17:38 . 2010-12-31 17:38 -------- d-----w- C:\Recovery
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-02 04:39 . 2010-12-31 18:12 749056 ----a-w- c:\windows\system32\schedsvc.dll
2010-11-02 04:34 . 2010-12-31 18:12 179712 ----a-w- c:\windows\system32\schtasks.exe
2010-10-25 09:09 . 2010-10-25 09:09 974848 ----a-w- c:\windows\system32\cis-2.4.dll
2010-10-25 09:09 . 2010-10-25 09:09 81920 ----a-w- c:\windows\system32\issacapi_bs-2.3.dll
2010-10-25 09:09 . 2010-10-25 09:09 65536 ----a-w- c:\windows\system32\issacapi_pe-2.3.dll
2010-10-25 09:09 . 2010-10-25 09:09 57344 ----a-w- c:\windows\system32\MTXSYNCICON.dll
2010-10-25 09:09 . 2010-10-25 09:09 57344 ----a-w- c:\windows\system32\MK_Lyric.dll
2010-10-25 09:09 . 2010-10-25 09:09 57344 ----a-w- c:\windows\system32\issacapi_se-2.3.dll
2010-10-25 09:09 . 2010-10-25 09:09 569344 ----a-w- c:\windows\system32\muzdecode.ax
2010-10-25 09:09 . 2010-10-25 09:09 491520 ----a-w- c:\windows\system32\muzapp.dll
2010-10-25 09:09 . 2010-10-25 09:09 49152 ----a-w- c:\windows\system32\MaJGUILib.dll
2010-10-25 09:09 . 2010-10-25 09:09 45056 ----a-w- c:\windows\system32\MaXMLProto.dll
2010-10-25 09:09 . 2010-10-25 09:09 45056 ----a-w- c:\windows\system32\MACXMLProto.dll
2010-10-25 09:09 . 2010-10-25 09:09 413696 ----a-w- c:\programdata\Microsoft\Windows\Templates\msvcp60.dll
2010-10-25 09:09 . 2010-10-25 09:09 40960 ----a-w- c:\windows\system32\MTTELECHIP.dll
2010-10-25 09:09 . 2010-10-25 09:09 40960 ----a-w- c:\windows\system32\MAMACExtract.dll
2010-10-25 09:09 . 2010-10-25 09:09 352256 ----a-w- c:\windows\system32\MSLUR71.dll
2010-10-25 09:09 . 2010-10-25 09:09 258048 ----a-w- c:\windows\system32\muzoggsp.ax
2010-10-25 09:09 . 2010-10-25 09:09 245760 ----a-w- c:\windows\system32\MSCLib.dll
2010-10-25 09:09 . 2010-10-25 09:09 24576 ----a-w- c:\windows\system32\MASetupCleaner.exe
2010-10-25 09:09 . 2010-10-25 09:09 243576 ----a-w- c:\windows\system32\MASetupCaller.dll
2010-10-25 09:09 . 2010-10-25 09:09 23040 ----a-w- c:\programdata\Microsoft\Windows\Templates\psapi.dll
2010-10-25 09:09 . 2010-10-25 09:09 200704 ----a-w- c:\windows\system32\muzwmts.dll
2010-10-25 09:09 . 2010-10-25 09:09 155648 ----a-w- c:\windows\system32\MSFLib.dll
2010-10-25 09:09 . 2010-10-25 09:09 135168 ----a-w- c:\windows\system32\muzaf1.dll
2010-10-25 09:09 . 2010-10-25 09:09 131072 ----a-w- c:\windows\system32\muzmpgsp.ax
2010-10-25 09:09 . 2010-10-25 09:09 122880 ----a-w- c:\windows\system32\muzeffect.ax
2010-10-25 09:09 . 2010-10-25 09:09 118784 ----a-w- c:\windows\system32\MaDRM.dll
2010-10-25 09:09 . 2010-10-25 09:09 110592 ----a-w- c:\windows\system32\muzmp4sp.ax
2010-10-25 09:09 . 2010-10-25 09:09 511328 ----a-w- c:\windows\system32\Synchronization2.dll
2010-10-25 09:09 . 2010-10-25 09:09 288608 ----a-w- c:\windows\system32\Microsoft.Synchronization.dll
2010-10-25 09:09 . 2010-10-25 09:09 253280 ----a-w- c:\windows\system32\MetaStore2.dll
2010-10-25 09:07 . 2010-10-25 09:07 95568 ----a-w- c:\windows\system32\dgdersvc.exe
2010-10-25 09:07 . 2010-10-25 09:07 763216 ----a-w- c:\windows\system32\dgderapi.dll
2010-10-25 09:07 . 2010-10-25 09:07 319456 ----a-w- c:\programdata\Microsoft\Windows\Templates\DIFxAPI.dll
2010-10-25 09:07 . 2010-10-25 09:07 18120 ----a-w- c:\windows\system32\drivers\dgderdrv.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\users\Ha-ns\AppData\Local\Google\Update\GoogleUpdate.exe" [2011-01-01 136176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-30 13605408]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-01-30 92704]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-02-22 8522272]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys [2010-08-27 30312]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [2010-08-27 96488]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [2010-08-27 12776]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [2010-08-27 121576]
R3 VSPerfDrv100;Performance Tools Driver 10.0;c:\program files\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\VSPerfDrv100.sys [2009-12-08 48128]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-01-01 1343400]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-23 47128]
R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 239336]
R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 366936]
S2 dgdersvc;Device Error Recovery Service;c:\windows\system32\dgdersvc.exe [2010-10-25 95568]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-10-25 217088]
S3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [2010-10-25 18120]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2010-10-25 36640]
S3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
--- Ostatní služby/ovladače v paměti ---
*NewlyCreated* - FSUSBEXDISK
.
Obsah adresáře 'Naplánované úlohy'
2011-01-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2337997463-3138014002-1648050931-1001Core.job
- c:\users\Ha-ns\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-01 21:30]
2011-01-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2337997463-3138014002-1648050931-1001UA.job
- c:\users\Ha-ns\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-01 21:30]
.
.
------- Doplňkový sken -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Free YouTube to MP3 Converter - c:\users\Ha-ns\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Stáhnout pomocí &BitSpiritu - c:\program files\BitSpirit\bsurl.htm
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKCU-Run-KiesTrayAgent - (no file)
AddRemove-01_Simmental - c:\program files\Samsung\USB Drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - c:\program files\Samsung\USB Drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-07_Schorl - c:\program files\Samsung\USB Drivers\07_Schorl\Uninstall.exe
AddRemove-09_Hsp - c:\program files\Samsung\USB Drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - c:\program files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-12_Symbian_USB_Download_Driver - c:\program files\Samsung\USB Drivers\12_Symbian_USB_Download_Driver\Uninstall.exe
AddRemove-15_Symbian_Samsung_PC_DLC_Driver - c:\program files\Samsung\USB Drivers\15_Symbian_Samsung_PC_DLC_Driver\Uninstall.exe
AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe
AddRemove-24_flashusbdriver - c:\program files\Samsung\USB Drivers\24_flashusbdriver\Uninstall.exe
AddRemove-25_escape - c:\program files\Samsung\USB Drivers\25_escape\Uninstall.exe
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3g2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.3G2"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.3GP"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.3G2"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gpp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.3GP"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aac\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.ADTS"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.adt\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.ADTS"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.adts\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.ADTS"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.AIFF"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.AIFF"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.AIFF"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.ASF"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.ASX"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.AU"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avi\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.AVI"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cda\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.CDA"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m1v\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2t\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.M2TS"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2ts\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.M2TS"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2v\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.m3u"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.M4A"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4v\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MP4"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MIDI"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.midi\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MIDI"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mkv\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="CCCP.WMP.AssocFile.MKV.1"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mod\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mov\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MOV"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MP3"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2v\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MP3"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MP4"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4v\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MP4"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpa\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpe\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpeg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpv2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mts\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.M2TS"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="CCCP.WMP.AssocFile.OGM.1"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmi\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.MIDI"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.AU"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ts\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.TTS"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tts\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.TTS"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.WAV"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wax\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.WAX"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.ASF"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.WMA"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.WMD"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wms\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.WMS"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmv\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.WMV"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.ASX"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmz\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.WMZ"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wpl\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.WPL"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wvx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WMP11.AssocFile.WVX"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2011-01-19 19:21:58
ComboFix-quarantined-files.txt 2011-01-19 18:21
Před spuštěním: 13 682 995 200 bytes free
Po spuštění: 13 970 403 328 bytes free
- - End Of File - - B1A43B152A6BA6668F458E0EC8EC9B9E
Re: Prosim o kontrolu. Ukraden ICQ ucet.

-Nainstalujte,dejte úplný sken
NIC NEMAZAT

-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.