Stránka 2 z 2

Re: facebook vírus

Napsal: 09 lis 2011 16:55
od vyosek
Opakujte postup v nouzovem rezimu (restart PC, mackat F8, zvolit Stav nouze s praci v siti)

Re: facebook vírus

Napsal: 09 lis 2011 18:35
od tomi
No už sa podarilo mi zísakť ten log len som mal problem potom s najdením nejakej sieťe tak som to musel obnoviť.

All processes killed
========== OTL ==========
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\SearchAssistant| /E : value set successfully!
HKU\S-1-5-21-839543870-2764649644-3222184407-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully!
Prefs.js: "http://startsear.ch/?q=" removed from browser.search.defaultengine
Prefs.js: "http://startsear.ch/?q=" removed from browser.search.defaultenginename
Prefs.js: "http://startsear.ch/?q=" removed from browser.search.order.1
Prefs.js: "http://www.google.sk/" removed from browser.startup.homepage
Prefs.js: "http://startsear.ch/?q=" removed from keyword.URL
Prefs.js: 0 removed from network.proxy.type
64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
C:\Users\Tomáš\AppData\Roaming\Mozilla\Firefox\Profiles\oeb9zod4.default\searchplugins\startsear.xml moved successfully.
C:\Program Files (x86)\Mozilla Firefox\searchplugins\fcmdSrch.xml moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000001\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000002\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000003\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000004\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000005\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000006\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000007\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000008\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000009\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000010\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010\ deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes\\gopher|:gopher:// /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\livecall\ deleted successfully.
File Protocol\Handler\livecall - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-help\ deleted successfully.
File Protocol\Handler\ms-help - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msnim\ deleted successfully.
File Protocol\Handler\msnim - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\skype4com\ deleted successfully.
File Protocol\Handler\skype4com - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\skype-ie-addon-data\ deleted successfully.
File Protocol\Handler\skype-ie-addon-data - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlmailhtml\ deleted successfully.
File Protocol\Handler\wlmailhtml - No CLSID value found not found.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
File move failed. F:\autorun.inf scheduled to be moved on reboot.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7cd0b6d8-56f5-11e0-b6fb-00266c91ed1f}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7cd0b6d8-56f5-11e0-b6fb-00266c91ed1f}\ not found.
C:\Users\Tomáš\AppData\Roaming\Eodsdw.exe moved successfully.
C:\Users\Tomáš\AppData\Roaming\51B8.exe moved successfully.
C:\Users\Tomáš\AppData\Roaming\B9AA.exe moved successfully.
C:\Users\Tomáš\AppData\Roaming\5BA6.exe moved successfully.
C:\Users\Tomáš\AppData\Roaming\1D01.exe moved successfully.
C:\Users\Tomáš\AppData\Roaming\lolspplol2.exe moved successfully.
C:\Users\Tomáš\AppData\Roaming\spwin.exe moved successfully.
C:\Users\Tomáš\AppData\Roaming\E965.exe moved successfully.
C:\Users\Tomáš\AppData\Roaming\AE58.exe moved successfully.
C:\Users\Tomáš\AppData\Roaming\20D9.exe moved successfully.
C:\Windows\SysWow64\tmp5618.tmp deleted successfully.
C:\Windows\SysWow64\tmp5619.tmp deleted successfully.
C:\Windows\SysWow64\tmpFF08.tmp deleted successfully.
C:\Windows\SysWow64\tmpFF09.tmp deleted successfully.
C:\Users\Tomáš\AppData\Roaming\338F.tmp deleted successfully.
C:\Users\Tomáš\AppData\Roaming\6A97.tmp deleted successfully.
C:\Users\Tomáš\AppData\Roaming\B349.tmp deleted successfully.
C:\Users\Tomáš\AppData\Roaming\D25A.tmp deleted successfully.
C:\Windows\msdownld.tmp folder deleted successfully.
File C:\Users\Tomáš\AppData\Roaming\Eodsdw.exe not found.
C:\Users\Tomáš\Desktop\RogueKiller.exe moved successfully.
C:\Users\Tomáš\AppData\Roaming\5E18.exe moved successfully.
File C:\Users\Tomáš\AppData\Roaming\51B8.exe not found.
C:\Users\Tomáš\AppData\Roaming\445F.exe moved successfully.
C:\Users\Tomáš\AppData\Roaming\E717.exe moved successfully.
C:\Users\Tomáš\AppData\Roaming\9242.exe moved successfully.
C:\Users\Tomáš\AppData\Roaming\8121.exe moved successfully.
C:\Users\Tomáš\AppData\Roaming\7934.exe moved successfully.
C:\Users\Tomáš\AppData\Roaming\199F.exe moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-839543870-2764649644-3222184407-1000Core.job moved successfully.
C:\Users\Tomáš\AppData\Roaming\5050.exe moved successfully.
C:\Users\Tomáš\AppData\Roaming\EIg7ittkk81k moved successfully.
C:\Users\Tomáš\AppData\Roaming\lif76ttLkH0L moved successfully.
C:\Users\Tomáš\AppData\Roaming\hy8KfJgK7eyf moved successfully.
C:\Users\Tomáš\AppData\Roaming\Jgl67KriI1ti moved successfully.
C:\Users\Tomáš\AppData\Roaming\EfgJhIrJK1fh moved successfully.
Mount Point C:\Windows\system64 removed successfully!
========== REGISTRY ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\swg deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\RGSC deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\msnmsgr deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ICQ deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Google Update deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Bpdsdt not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Eodsdw not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\TaskUpdate v1.3 not found.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\Adobe Reader Speed Launcher deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\NBAgent deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\AdobeCS4ServiceManager deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\Adobe Acrobat Speed Launcher deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\Acrobat Assistant 8.0 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\Adobe_ID0ENQBO deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task deleted successfully.
========== FILES ==========
File\Folder C:\Windows\system32\%APPDATA% not found.
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job moved successfully.
File\Folder C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-839543870-2764649644-3222184407-1000Core.job not found.
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-839543870-2764649644-3222184407-1000UA.job moved successfully.
c:\Users\Tomáš\Downloads\Assassins+Creed+-+Crack.rar deleted successfully.
c:\Users\Tomáš\Downloads\FI57FA12CrackRelo-jan0000.zip deleted successfully.
c:\Users\Tomáš\Downloads\FIFA-11-Crack+Keygen.rar deleted successfully.
c:\Users\Tomáš\Downloads\FIFA-12---RELOADED-CRACK.rar deleted successfully.
c:\Users\Tomáš\Downloads\FIFA-12-Crack-by-SKIDROW.rar deleted successfully.
c:\Users\Tomáš\Downloads\FIFA.12_RELOADED_CracksSite.rar deleted successfully.
c:\Users\Tomáš\Downloads\FIFA.12_RELOADED_CracksSite.rar.part deleted successfully.
c:\Users\Tomáš\Downloads\star-wars-the-force-unleashed-2-2010-p2p-crack-by-muploaders-of-ups.rar deleted successfully.
C:\Users\Tomáš\AppData\Roaming\kakao2 folder moved successfully.
C:\Users\Tomáš\AppData\Roaming\277D.exe moved successfully.
C:\Users\Tomáš\AppData\Roaming\3307.exe moved successfully.
C:\Users\Tomáš\AppData\Roaming\4C1E.exe moved successfully.
C:\Users\Tomáš\AppData\Roaming\5BAE.exe moved successfully.
C:\Users\Tomáš\AppData\Roaming\626F.exe moved successfully.
C:\Users\Tomáš\AppData\Roaming\6873.exe moved successfully.
C:\Users\Tomáš\AppData\Roaming\710A.exe moved successfully.
C:\Users\Tomáš\AppData\Roaming\A1CA.exe moved successfully.
C:\Users\Tomáš\AppData\Roaming\C494.exe moved successfully.
C:\Users\Tomáš\AppData\Roaming\D99F.exe moved successfully.
C:\Users\Tomáš\AppData\Roaming\DB41.exe moved successfully.
C:\Users\Tomáš\AppData\Roaming\FCC5.exe moved successfully.
File/Folder C:\Windows\system32\*.tmp.dll not found.
File/Folder C:\Windows\system32\SET*.tmp not found.
File/Folder C:\Windows\*.tmp not found.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 41620 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

User: Tomárysis2

User: Tomáš
->Temp folder emptied: 2283342547 bytes
->Temporary Internet Files folder emptied: 71564412 bytes
->Java cache emptied: 1116992 bytes
->FireFox cache emptied: 87818366 bytes
->Flash cache emptied: 128009 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 855388757 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 51879564 bytes
RecycleBin emptied: 1092586035 bytes

Total Files Cleaned = 4 238,00 mb


[EMPTYFLASH]

User: All Users

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Public

User: Tomárysis2

User: Tomáš
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0,00 mb


OTL by OldTimer - Version 3.2.31.0 log created on 11092011_180003

Files\Folders moved on Reboot...
File\Folder F:\autorun.inf not found!
C:\Users\Tomáš\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\Tomáš\AppData\Local\Temp\{E9C1E1AC-C9B2-4c85-94DE-9C1518918D12}.tlb moved successfully.
File move failed. C:\Windows\temp\italc_client.log scheduled to be moved on reboot.
C:\Windows\temp\{E9C1E1AC-C9B2-4c85-94DE-9C1518918D02}.tlb moved successfully.
C:\Windows\temp\{E9C1E1AC-C9B2-4c85-94DE-9C1518918D12}.tlb moved successfully.

Registry entries deleted on Reboot...

Re: facebook vírus

Napsal: 09 lis 2011 18:37
od vyosek
OK, ona asi i havet jebala do nastaveni :?:

PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix

Re: facebook vírus

Napsal: 09 lis 2011 21:04
od tomi
Takťe takto:

ComboFix 11-11-09.01 - Tomáš . 11. 2011 20:38:59.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.421.1051.18.4091.2614 [GMT 1:00]
Running from: c:\users\TomßÜ\Desktop\ComboFix.exe
AV: ESET Smart Security 4.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET Personal firewall *Disabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 4.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Tomáš\AppData\Roaming\199F.exe
c:\users\Tomáš\AppData\Roaming\1D01.exe
c:\users\Tomáš\AppData\Roaming\20D9.exe
c:\users\Tomáš\AppData\Roaming\3307.exe
c:\users\Tomáš\AppData\Roaming\445F.exe
c:\users\Tomáš\AppData\Roaming\4C1E.exe
c:\users\Tomáš\AppData\Roaming\5050.exe
c:\users\Tomáš\AppData\Roaming\51B8.exe
c:\users\Tomáš\AppData\Roaming\5BA6.exe
c:\users\Tomáš\AppData\Roaming\5BAE.exe
c:\users\Tomáš\AppData\Roaming\5E18.exe
c:\users\Tomáš\AppData\Roaming\626F.exe
c:\users\Tomáš\AppData\Roaming\6873.exe
c:\users\Tomáš\AppData\Roaming\7934.exe
c:\users\Tomáš\AppData\Roaming\8121.exe
c:\users\Tomáš\AppData\Roaming\9242.exe
c:\users\Tomáš\AppData\Roaming\AE58.exe
c:\users\Tomáš\AppData\Roaming\B9AA.exe
c:\users\Tomáš\AppData\Roaming\D99F.exe
c:\users\Tomáš\AppData\Roaming\DB41.exe
c:\users\Tomáš\AppData\Roaming\E717.exe
c:\users\Tomáš\AppData\Roaming\E965.exe
c:\users\Tomáš\AppData\Roaming\Eodsdw.exe
c:\users\Tomáš\AppData\Roaming\FCC5.exe
c:\users\Tomáš\AppData\Roaming\lolspplol2.exe
c:\users\Tomáš\AppData\Roaming\spwin.exe
c:\windows\assembly\tmp\U
c:\windows\assembly\tmp\U\000000c0.@
c:\windows\assembly\tmp\U\000000cb.@
c:\windows\assembly\tmp\U\000000cf.@
c:\windows\assembly\tmp\U\80000000.@
c:\windows\assembly\tmp\U\800000c0.@
c:\windows\assembly\tmp\U\800000cb.@
c:\windows\assembly\tmp\U\800000cf.@
c:\windows\PFRO.log
c:\windows\system32\consrv.dll
.
.
((((((((((((((((((((((((( Files Created from 2011-10-09 to 2011-11-09 )))))))))))))))))))))))))))))))
.
.
2011-11-09 19:47 . 2011-11-09 19:47 69000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6B319FE3-96BB-4772-9A68-34DAF9B184F2}\offreg.dll
2011-11-09 19:43 . 2011-11-09 19:43 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-11-09 17:08 . 2011-11-09 17:08 -------- d-----w- c:\users\Tomáš\AppData\Local\Diagnostics
2011-11-09 17:00 . 2011-11-09 17:00 -------- d-----w- C:\_OTL
2011-11-08 20:59 . 2011-11-08 21:33 512 ----a-w- C:\PhysicalMBR.bin
2011-11-07 20:39 . 2011-11-07 20:39 -------- d-----w- c:\program files\trend micro
2011-11-07 20:39 . 2011-11-07 20:39 -------- d-----w- C:\rsit
2011-11-06 08:30 . 2011-11-09 17:26 -------- d-----w- c:\users\Tomáš\AppData\Roaming\kakao2
2011-11-05 16:13 . 2011-11-05 16:13 -------- d-----w- c:\users\Tomáš\Application Data
2011-10-29 14:03 . 2011-10-29 14:03 -------- d-sh--w- c:\windows\system32\%APPDATA%
2011-10-27 12:54 . 2011-10-27 12:54 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-10-27 12:42 . 2011-10-27 12:42 -------- d-----w- c:\windows\system32\Macromed
2011-10-26 19:54 . 2011-10-26 19:55 -------- d-----w- c:\users\Tomáš\AppData\Roaming\GetRightToGo
2011-10-26 18:51 . 2006-07-24 14:05 5632 ----a-w- c:\windows\SysWow64\drivers\StarOpen.sys
2011-10-26 18:47 . 2011-10-26 18:52 -------- d-----w- c:\windows\SysWow64\Samsung_USB_Drivers
2011-10-26 18:42 . 2011-10-26 18:47 -------- d-----w- c:\program files (x86)\SAMSUNG
2011-10-22 11:43 . 2011-10-25 19:13 -------- d-----w- c:\program files\MAXON
2011-10-21 17:43 . 2011-10-25 19:59 -------- d-----w- c:\users\Tomáš\AppData\Roaming\MAXON
2011-10-17 17:32 . 2011-10-17 17:32 358150 ----a-w- c:\users\Tomáš\AppData\Roaming\C494.exe
2011-10-16 07:51 . 2011-10-16 07:51 -------- d-----w- c:\users\Tomáš\AppData\Roaming\ESET
2011-10-16 07:51 . 2011-10-16 07:51 -------- d-----w- c:\users\Tomáš\AppData\Local\ESET
2011-10-16 07:41 . 2011-10-16 07:41 -------- d-----w- c:\program files\ESET
2011-10-16 07:39 . 2011-10-16 07:39 358150 ----a-w- c:\users\Tomáš\AppData\Roaming\277D.exe
2011-10-12 17:21 . 2011-10-12 17:21 -------- d-----w- c:\users\Tomáš\Start Menu
2011-10-12 17:21 . 2011-10-12 17:21 358150 ----a-w- c:\users\Tomáš\AppData\Roaming\A1CA.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-17 17:32 . 2011-10-17 17:32 358150 ----a-w- c:\users\Tomáš\AppData\Roaming\C494.exe
2011-10-17 17:32 . 2011-10-17 17:32 358150 ----a-w- c:\users\Tomáš\AppData\Roaming\C494.exe
2011-10-16 07:39 . 2011-10-16 07:39 358150 ----a-w- c:\users\Tomáš\AppData\Roaming\277D.exe
2011-10-16 07:39 . 2011-10-16 07:39 358150 ----a-w- c:\users\Tomáš\AppData\Roaming\277D.exe
2011-10-12 17:21 . 2011-10-12 17:21 358150 ----a-w- c:\users\Tomáš\AppData\Roaming\A1CA.exe
2011-10-12 17:21 . 2011-10-12 17:21 358150 ----a-w- c:\users\Tomáš\AppData\Roaming\A1CA.exe
2011-10-07 12:30 . 2011-10-07 12:30 4679 ----a-w- c:\users\Tomáš\AppData\Roaming\710A.exe
2011-10-07 12:30 . 2011-10-07 12:30 4679 ----a-w- c:\users\Tomáš\AppData\Roaming\710A.exe
2011-09-23 19:17 . 2011-04-23 12:42 466520 ----a-w- c:\windows\system32\wrap_oal.dll
2011-09-23 19:17 . 2011-04-23 12:42 122968 ----a-w- c:\windows\system32\OpenAL32.dll
2011-09-23 19:17 . 2011-04-23 12:42 445016 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2011-09-23 19:17 . 2011-04-23 12:42 109144 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2011-09-13 00:26 . 2011-09-28 13:09 9049936 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6B319FE3-96BB-4772-9A68-34DAF9B184F2}\mpengine.dll
2011-08-21 09:06 . 2011-08-21 09:06 33344 ----a-w- c:\windows\system32\drivers\hamachi.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Tomáš\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Tomáš\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Tomáš\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Tomáš\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="d:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-03-25 39408]
"RGSC"="d:\program files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe" [2008-11-14 305064]
"msnmsgr"="c:\program files (x86)\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
"ICQ"="d:\program files\ICQ7.4\ICQ.exe" [2011-03-25 119608]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-21 35760]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"NBAgent"="c:\program files (x86)\Nero\Nero BackItUp & Burn\Nero BackItUp\NBAgent.exe" [2010-03-09 1086760]
"Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-11-11 288088]
"ITSecMng"="c:\program files (x86)\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2009-07-22 83336]
"ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-10-06 1294136]
"TWebCamera"="c:\program files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2010-02-24 2454840]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-03-08 336384]
"AdobeCS4ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"Adobe Acrobat Speed Launcher"="d:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232]
"Acrobat Assistant 8.0"="d:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-11 640376]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
"GLDStart"="d:\program files (x86)\GLDirect\gldirect.exe" [2004-07-20 241664]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"TOSHIBA Online Product Information"="c:\program files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe" [2010-03-03 4581280]
.
c:\users\Tomáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Tomáš\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-5-25 24176560]
hamachi.lnk - d:\program files\Hamachi\hamachi.exe [2011-8-21 624416]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2010-2-24 2721120]
Network Server.lnk - c:\program files (x86)\WIBUKEY\Server\WkSvMgr.exe [2011-5-22 3768320]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
TRDCReminder.lnk - c:\program files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe [2009-9-1 481184]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-25 136176]
R3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2008-08-15 284016]
R3 AODDriver4.0;AODDriver4.0;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011-04-24 1038088]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-25 136176]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUStor.sys [x]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x]
R3 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe [2010-02-11 124368]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-03-08 365568]
S2 AMD Reservation Manager;AMD Reservation Manager;c:\program files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe [2010-06-17 194496]
S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2010-01-28 249200]
S2 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-10 46448]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [2011-01-12 810144]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [x]
S2 icas;iTALC Client;d:\program files\iTALC\ica.exe [2011-01-06 814094]
S2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\SysWOW64\nlssrv32.exe [2011-02-21 66560]
S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2010-03-17 258928]
S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [x]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [x]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 CnxtHdmiAudService;Conexant UAA HDMI Function Driver for High Definition Audio Service;c:\windows\system32\drivers\CHDMI64.sys [x]
S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [x]
S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x]
S3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512]
S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-05 137560]
S3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2010-02-23 835952]
.
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7cd0b6d8-56f5-11e0-b6fb-00266c91ed1f}]
\shell\AutoRun\command - F:\setup.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-25 21:14]
.
2011-11-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-25 21:14]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Tomáš\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Tomáš\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Tomáš\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Tomáš\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2010-02-05 709976]
"Toshiba TEMPRO"="c:\program files (x86)\Toshiba TEMPRO\TemproTray.exe" [2010-02-11 1050072]
"SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2009-11-19 307768]
"cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2010-03-10 520760]
"TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376]
"Toshiba Registration"="c:\program files\Toshiba\Registration\ToshibaReminder.exe" [2010-04-19 136136]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-01-12 2918656]
"combofix"="c:\combofix\CF14007.3XE" [2009-07-14 344576]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.facebook.com
mStart Page = hxxp://startsear.ch
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Append Link Target to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xportovať do programu Microsoft Excel - d:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: Sothink SWF Catcher - c:\program files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
IE: {{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - d:\program files\ICQ7.4\ICQ.exe
TCP: Interfaces\{D790733C-180E-4CE7-B707-22C62435B11A}: NameServer = 192.168.1.1
FF - ProfilePath - c:\users\Tomáš\AppData\Roaming\Mozilla\Firefox\Profiles\oeb9zod4.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.sk/
FF - prefs.js: keyword.URL - hxxp://startsear.ch/?q=
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Toolbar-Locked - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
HKLM-Run-TosReelTimeMonitor - c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
HKLM-Run-TosNC - c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe
HKLM-Run-TPwrMain - c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE
HKLM-Run-HSON - c:\program files (x86)\TOSHIBA\TBS\HSON.exe
HKLM-Run-SmoothView - c:\program files (x86)\Toshiba\SmoothView\SmoothView.exe
HKLM-Run-00TCrdMain - c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe
HKLM-Run-Teco - c:\program files (x86)\TOSHIBA\TECO\Teco.exe
HKLM-Run-TosWaitSrv - c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe
HKLM-Run-SmartFaceVWatcher - c:\program files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe
AddRemove-PSPad editor_is1 - d:\program file\PSPad editor\Uninst\unins000.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-839543870-2764649644-3222184407-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:15,d2,65,0e,2b,3b,a5,a8,ac,df,82,68,5d,ad,d3,e3,de,2e,3a,ea,76,09,03,
16,34,c4,6b,32,ed,c5,b8,a2,66,57,e9,af,44,ab,47,8f,1e,45,f6,50,10,95,b2,e7,\
"??"=hex:21,c6,db,3b,34,31,ed,4e,5e,c3,42,6e,e5,bd,e9,fb
.
[HKEY_USERS\S-1-5-21-839543870-2764649644-3222184407-1000\Software\SecuROM\License information*]
"datasecu"=hex:7a,ac,ad,76,a1,43,54,f2,b0,2e,5c,39,dc,dd,92,04,18,74,d4,a9,f9,
da,9a,c2,26,d2,83,62,5c,3a,6d,24,98,d8,59,08,58,d9,06,ef,8c,9e,a0,5d,76,c6,\
"rkeysecu"=hex:24,f3,78,c1,4a,ae,f6,72,f4,bd,e5,98,ef,c5,21,28
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\program files (x86)\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
c:\program files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
c:\program files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
.
**************************************************************************
.
Completion time: 2011-11-09 21:02:40 - machine was rebooted
ComboFix-quarantined-files.txt 2011-11-09 20:02
.
Pre-Run: 12 560 781 312 bytes free
Post-Run: 12 601 819 136 bytes free
.
- - End Of File - - 1F5AAD36CA1C3114BFDFCB01BF6D389A

Re: facebook vírus

Napsal: 10 lis 2011 21:09
od vyosek
:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    Collect::
    c:\users\Tomáš\AppData\Roaming\C494.exe
    c:\users\Tomáš\AppData\Roaming\277D.exe
    c:\users\Tomáš\AppData\Roaming\A1CA.exe
    c:\users\Tomáš\AppData\Roaming\C494.exe
    c:\users\Tomáš\AppData\Roaming\C494.exe
    c:\users\Tomáš\AppData\Roaming\277D.exe
    c:\users\Tomáš\AppData\Roaming\277D.exe
    c:\users\Tomáš\AppData\Roaming\A1CA.exe
    c:\users\Tomáš\AppData\Roaming\A1CA.exe
    c:\users\Tomáš\AppData\Roaming\710A.exe
    c:\users\Tomáš\AppData\Roaming\710A.exe
    
    Folder::
    c:\users\Tomáš\AppData\Roaming\kakao2
    c:\windows\system32\%APPDATA%
    C:\Users\Tomáš\AppData\Roaming\EIg7ittkk81k
    C:\Users\Tomáš\AppData\Roaming\lif76ttLkH0L
    C:\Users\Tomáš\AppData\Roaming\hy8KfJgK7eyf
    C:\Users\Tomáš\AppData\Roaming\Jgl67KriI1ti
    C:\Users\Tomáš\AppData\Roaming\EfgJhIrJK1fh
    
    File::
    C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-839543870-2764649644-3222184407-1000Core.job
    C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-839543870-2764649644-3222184407-1000UA.job
    c:\Users\Tomáš\Downloads\Assassins+Creed+-+Crack.rar
    c:\Users\Tomáš\Downloads\FI57FA12CrackRelo-jan0000.zip
    c:\Users\Tomáš\Downloads\FIFA-11-Crack+Keygen.rar
    c:\Users\Tomáš\Downloads\FIFA-12---RELOADED-CRACK.rar
    c:\Users\Tomáš\Downloads\FIFA-12-Crack-by-SKIDROW.rar
    c:\Users\Tomáš\Downloads\FIFA.12_RELOADED_CracksSite.rar
    c:\Users\Tomáš\Downloads\FIFA.12_RELOADED_CracksSite.rar.part
    c:\Users\Tomáš\Downloads\star-wars-the-force-unleashed-2-2010-p2p-crack-by-muploaders-of-ups.rar
    
    Registry::
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "DAEMON Tools Lite"=-
    "swg"=-
    "RGSC"=-
    "msnmsgr"=-
    "ICQ"=-
    "Google Update"=-
    "Bpdsdt"=-
    "Eodsdw"=-
    "TaskUpdate v1.3"=-
    [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
    "Adobe Reader Speed Launcher"=-
    "Adobe ARM"=-
    "NBAgent"=-
    "AdobeCS4ServiceManager"=-
    "Adobe Acrobat Speed Launcher"=-
    ""=-
    "Acrobat Assistant 8.0"=-
    "Adobe_ID0ENQBO"=-
    "QuickTime Task"=-
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7cd0b6d8-56f5-11e0-b6fb-00266c91ed1f}]
    
    Driver::
    gupdate
    gupdatem
    
    DDS::
    uLocal Page = c:\windows\system32\blank.htm
    uStart Page = hxxp://www.facebook.com
    mStart Page = hxxp://startsear.ch
    
    Firefox::
    FF - ProfilePath - c:\users\Tomáš\AppData\Roaming\Mozilla\Firefox\Profiles\oeb9zod4.default\
    FF - prefs.js: keyword.URL - hxxp://startsear.ch/?q=
    
    RegNull::
    [HKEY_USERS\S-1-5-21-839543870-2764649644-3222184407-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
    [HKEY_USERS\S-1-5-21-839543870-2764649644-3222184407-1000\Software\SecuROM\License information*]
    
    RegLock::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    [HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    
    Reboot::
    
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci

Re: facebook vírus

Napsal: 17 lis 2011 19:33
od tomi
Takže tak:

ComboFix 11-11-17.03 - Tomáš . 11. 2011 18:56:54.2.2 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.421.1051.18.4091.2660 [GMT 1:00]
Running from: c:\combofix\ComboFix.exe
Command switches used :: c:\users\TomßÜ\Desktop\CFScript.TXT
AV: ESET Smart Security 4.2 *Disabled/Outdated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET Personal firewall *Disabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 4.2 *Disabled/Outdated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Tomáš\AppData\Roaming\61BE.exe
c:\users\Tomáš\AppData\Roaming\85D1.exe
c:\users\Tomáš\AppData\Roaming\92CD.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-10-17 to 2011-11-17 )))))))))))))))))))))))))))))))
.
.
2011-11-17 18:07 . 2011-11-17 18:07 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-11-17 17:29 . 2011-11-17 17:29 69000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6B319FE3-96BB-4772-9A68-34DAF9B184F2}\offreg.dll
2011-11-17 08:04 . 2011-11-17 08:04 0 ----a-w- c:\users\Tomáš\AppData\Roaming\6FB4.tmp
2011-11-17 08:04 . 2011-11-17 08:04 200704 ----a-w- c:\users\Tomáš\AppData\Roaming\Eodsdw.exe
2011-11-16 13:15 . 2011-11-17 08:04 -------- d-----w- c:\users\Tomáš\AppData\Roaming\kakao3
2011-11-15 08:36 . 2011-11-15 08:36 -------- d-----w- c:\programdata\Conexant
2011-11-15 08:36 . 2011-11-15 08:36 -------- d-----w- c:\users\Tomáš\AppData\Local\Conexant
2011-11-14 18:48 . 2011-11-14 18:48 -------- d-----w- c:\users\Tomáš\AppData\Local\Floorball League
2011-11-14 09:15 . 2011-11-14 09:42 -------- d-----w- c:\program files (x86)\Prodigium Game Studios
2011-11-12 13:04 . 2011-11-13 09:45 -------- d-----w- c:\programdata\boost_interprocess
2011-11-12 12:49 . 2011-11-14 06:14 -------- d-----w- c:\program files\Common Files\Autodesk Shared
2011-11-09 20:02 . 2011-11-09 20:02 -------- d-----w- c:\users\Tomárysis2\AppData
2011-11-09 17:08 . 2011-11-14 09:45 -------- d-----w- c:\users\Tomáš\AppData\Local\Diagnostics
2011-11-09 17:00 . 2011-11-09 17:00 -------- d-----w- C:\_OTL
2011-11-08 20:59 . 2011-11-08 21:33 512 ----a-w- C:\PhysicalMBR.bin
2011-11-07 20:39 . 2011-11-07 20:39 -------- d-----w- c:\program files\trend micro
2011-11-07 20:39 . 2011-11-07 20:39 -------- d-----w- C:\rsit
2011-11-06 08:30 . 2011-11-09 17:26 -------- d-----w- c:\users\Tomáš\AppData\Roaming\kakao2
2011-11-05 16:13 . 2011-11-05 16:13 -------- d-----w- c:\users\Tomáš\Application Data
2011-10-29 14:03 . 2011-10-29 14:03 -------- d-sh--w- c:\windows\system32\%APPDATA%
2011-10-27 12:54 . 2011-10-27 12:54 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-10-27 12:42 . 2011-10-27 12:42 -------- d-----w- c:\windows\system32\Macromed
2011-10-26 19:54 . 2011-10-26 19:55 -------- d-----w- c:\users\Tomáš\AppData\Roaming\GetRightToGo
2011-10-26 18:51 . 2006-07-24 14:05 5632 ----a-w- c:\windows\SysWow64\drivers\StarOpen.sys
2011-10-26 18:47 . 2011-10-26 18:52 -------- d-----w- c:\windows\SysWow64\Samsung_USB_Drivers
2011-10-26 18:42 . 2011-10-26 18:47 -------- d-----w- c:\program files (x86)\SAMSUNG
2011-10-22 11:43 . 2011-10-25 19:13 -------- d-----w- c:\program files\MAXON
2011-10-21 17:43 . 2011-10-25 19:59 -------- d-----w- c:\users\Tomáš\AppData\Roaming\MAXON
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-17 08:04 . 2011-11-17 08:04 0 ----a-w- c:\users\Tomáš\AppData\Roaming\6FB4.tmp
2011-11-17 08:04 . 2011-11-17 08:04 0 ----a-w- c:\users\Tomáš\AppData\Roaming\6FB4.tmp
2011-11-17 08:04 . 2011-11-17 08:04 200704 ----a-w- c:\users\Tomáš\AppData\Roaming\Eodsdw.exe
2011-11-17 08:04 . 2011-11-17 08:04 200704 ----a-w- c:\users\Tomáš\AppData\Roaming\Eodsdw.exe
2011-11-14 18:51 . 2011-04-23 12:42 122904 ----a-w- c:\windows\system32\OpenAL32.dll
2011-11-14 18:51 . 2011-04-23 12:42 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2011-10-17 17:32 . 2011-10-17 17:32 358150 ----a-w- c:\users\Tomáš\AppData\Roaming\C494.exe
2011-10-17 17:32 . 2011-10-17 17:32 358150 ----a-w- c:\users\Tomáš\AppData\Roaming\C494.exe
2011-10-16 07:39 . 2011-10-16 07:39 358150 ----a-w- c:\users\Tomáš\AppData\Roaming\277D.exe
2011-10-16 07:39 . 2011-10-16 07:39 358150 ----a-w- c:\users\Tomáš\AppData\Roaming\277D.exe
2011-10-12 17:21 . 2011-10-12 17:21 358150 ----a-w- c:\users\Tomáš\AppData\Roaming\A1CA.exe
2011-10-12 17:21 . 2011-10-12 17:21 358150 ----a-w- c:\users\Tomáš\AppData\Roaming\A1CA.exe
2011-10-07 12:30 . 2011-10-07 12:30 4679 ----a-w- c:\users\Tomáš\AppData\Roaming\710A.exe
2011-10-07 12:30 . 2011-10-07 12:30 4679 ----a-w- c:\users\Tomáš\AppData\Roaming\710A.exe
2011-09-23 19:17 . 2011-04-23 12:42 466520 ----a-w- c:\windows\system32\wrap_oal.dll
2011-09-23 19:17 . 2011-04-23 12:42 445016 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2011-09-13 00:26 . 2011-09-28 13:09 9049936 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6B319FE3-96BB-4772-9A68-34DAF9B184F2}\mpengine.dll
2011-08-21 09:06 . 2011-08-21 09:06 33344 ----a-w- c:\windows\system32\drivers\hamachi.sys
.
.
((((((((((((((((((((((((((((( SnapShot@2011-11-09_19.58.54 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-03-18 15:47 . 2010-03-18 15:47 17760 c:\windows\SysWOW64\aspnet_counters.dll
+ 2010-04-15 04:49 . 2011-11-17 17:28 58852 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
- 2009-07-14 05:10 . 2011-11-09 17:29 44372 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-11-17 17:28 44372 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2011-03-25 21:39 . 2011-11-17 17:28 13316 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-839543870-2764649644-3222184407-1000_UserData.bin
- 2011-03-25 15:36 . 2011-11-09 19:44 98304 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-03-25 15:36 . 2011-11-17 17:26 98304 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-03-18 16:23 . 2010-03-18 16:23 20832 c:\windows\system32\aspnet_counters.dll
+ 2009-07-14 04:46 . 2011-11-15 17:45 80352 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
- 2009-07-14 04:46 . 2011-10-25 18:43 80352 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
- 2011-03-25 19:09 . 2011-11-09 19:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-03-25 19:09 . 2011-11-17 17:29 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-03-25 19:09 . 2011-11-09 19:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-03-25 19:09 . 2011-11-17 17:29 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-03-18 15:47 . 2010-03-18 15:47 97624 c:\windows\Microsoft.NET\Framework64\v4.0.30319\XamlBuildTask.dll
+ 2010-03-18 16:23 . 2010-03-18 16:23 15696 c:\windows\Microsoft.NET\Framework64\v4.0.30319\webengine.dll
+ 2010-03-18 16:23 . 2010-03-18 16:23 81224 c:\windows\Microsoft.NET\Framework64\v4.0.30319\TLBREF.DLL
+ 2010-03-18 15:47 . 2010-03-18 15:47 29544 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Xaml.Hosting.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 70040 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Windows.Forms.DataVisualization.Design.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 24928 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Web.Routing.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 81272 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Web.RegularExpressions.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 33144 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Web.DynamicData.Design.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 93576 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Web.DataVisualization.Design.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 24944 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Web.Abstractions.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 28024 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.ServiceModel.WasHosting.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 12168 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.ServiceModel.ServiceMoniker40.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 95592 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Runtime.Caching.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 86888 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Drawing.Design.dll
+ 2010-03-18 19:58 . 2010-03-18 19:58 96088 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\SetupUtility.exe
+ 2010-03-18 20:16 . 2010-03-18 20:16 78152 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\Setup.exe
+ 2010-03-18 20:16 . 2010-03-18 20:16 18776 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\3082\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 14168 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\3076\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 18776 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\2070\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 14168 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\2052\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 17752 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\1055\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 17752 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\1053\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 18264 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\1049\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 18264 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\1046\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 18264 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\1045\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 17752 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\1044\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 19288 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\1043\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 15192 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\1042\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 15704 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\1041\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 18264 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\1040\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 18776 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\1038\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 16728 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\1037\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 18776 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\1036\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 18264 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\1035\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 17240 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\1033\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 19288 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\1032\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 18776 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\1031\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 18264 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\1030\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 18264 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\1029\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 14168 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\1028\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 17240 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\1025\SetupResources.dll
+ 2010-03-18 16:23 . 2010-03-18 16:23 20840 c:\windows\Microsoft.NET\Framework64\v4.0.30319\ServiceMonikerSupport.dll
+ 2010-03-18 16:23 . 2010-03-18 16:23 16208 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsn.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 21880 c:\windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.Workflow.Compiler.exe
+ 2010-03-18 15:47 . 2010-03-18 15:47 40304 c:\windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.VisualC.STLCLR.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 38784 c:\windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.Data.Entity.Build.Tasks.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 67968 c:\windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.Build.Conversion.v4.0.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 84296 c:\windows\Microsoft.NET\Framework64\v4.0.30319\EdmGen.exe
+ 2010-03-18 15:47 . 2010-03-18 15:47 60248 c:\windows\Microsoft.NET\Framework64\v4.0.30319\DataSvcUtil.exe
+ 2010-03-18 16:23 . 2010-03-18 16:23 40784 c:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_wp.exe
+ 2010-03-18 16:23 . 2010-03-18 16:23 44376 c:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
+ 2010-03-18 16:23 . 2010-03-18 16:23 36696 c:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_regiis.exe
+ 2010-03-18 16:23 . 2010-03-18 16:23 19296 c:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_regbrowsers.exe
+ 2010-03-18 16:23 . 2010-03-18 16:23 78160 c:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll
+ 2010-03-18 16:23 . 2010-03-18 16:23 36184 c:\windows\Microsoft.NET\Framework64\v4.0.30319\Aspnet_perf.dll
+ 2010-03-18 16:23 . 2010-03-18 16:23 15704 c:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_isapi.dll
+ 2010-03-18 16:23 . 2010-03-18 16:23 29528 c:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_filter.dll
+ 2010-03-18 16:23 . 2010-03-18 16:23 29536 c:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe
+ 2010-03-18 16:23 . 2010-03-18 16:23 11608 c:\windows\Microsoft.NET\Framework64\v4.0.30319\1033\FileTrackerUI.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 97624 c:\windows\Microsoft.NET\Framework\v4.0.30319\XamlBuildTask.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 14160 c:\windows\Microsoft.NET\Framework\v4.0.30319\webengine.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 69960 c:\windows\Microsoft.NET\Framework\v4.0.30319\TLBREF.DLL
+ 2010-03-18 15:47 . 2010-03-18 15:47 29544 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Xaml.Hosting.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 70040 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Windows.Forms.DataVisualization.Design.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 24928 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Web.Routing.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 81272 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Web.RegularExpressions.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 33144 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Web.DynamicData.Design.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 93576 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Web.DataVisualization.Design.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 24944 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Web.Abstractions.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 28024 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.ServiceModel.WasHosting.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 12168 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.ServiceModel.ServiceMoniker40.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 95592 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Caching.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 86888 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Drawing.Design.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 17256 c:\windows\Microsoft.NET\Framework\v4.0.30319\ServiceMonikerSupport.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 15184 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsn.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 96592 c:\windows\Microsoft.NET\Framework\v4.0.30319\MmcAspExt.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 21880 c:\windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.Workflow.Compiler.exe
+ 2010-03-18 15:47 . 2010-03-18 15:47 40304 c:\windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.VisualC.STLCLR.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 38784 c:\windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.Data.Entity.Build.Tasks.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 67968 c:\windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.Build.Conversion.v4.0.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 84296 c:\windows\Microsoft.NET\Framework\v4.0.30319\EdmGen.exe
+ 2010-03-18 15:47 . 2010-03-18 15:47 60248 c:\windows\Microsoft.NET\Framework\v4.0.30319\DataSvcUtil.exe
+ 2010-03-18 15:47 . 2010-03-18 15:47 32592 c:\windows\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe
+ 2010-03-18 15:47 . 2010-03-18 15:47 35160 c:\windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
+ 2010-03-18 15:47 . 2010-03-18 15:47 30040 c:\windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe
+ 2010-03-18 15:47 . 2010-03-18 15:47 19808 c:\windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regbrowsers.exe
+ 2010-03-18 15:47 . 2010-03-18 15:47 78160 c:\windows\Microsoft.NET\Framework\v4.0.30319\aspnet_rc.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 30040 c:\windows\Microsoft.NET\Framework\v4.0.30319\Aspnet_perf.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 14168 c:\windows\Microsoft.NET\Framework\v4.0.30319\aspnet_isapi.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 24408 c:\windows\Microsoft.NET\Framework\v4.0.30319\aspnet_filter.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 30048 c:\windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
+ 2010-03-18 15:47 . 2010-03-18 15:47 11608 c:\windows\Microsoft.NET\Framework\v4.0.30319\1033\FileTrackerUI.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 97624 c:\windows\Microsoft.NET\assembly\GAC_MSIL\XamlBuildTask\v4.0_4.0.0.0__31bf3856ad364e35\XamlBuildTask.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 29544 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xaml.Hosting\v4.0_4.0.0.0__31bf3856ad364e35\System.Xaml.Hosting.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 70040 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms.DataVisualization.Design\v4.0_4.0.0.0__31bf3856ad364e35\System.Windows.Forms.DataVisualization.Design.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 24928 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Routing\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Routing.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 81272 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.RegularExpressions\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 33144 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.DynamicData.Design\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.DynamicData.Design.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 93576 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.DataVisualization.Design\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.DataVisualization.Design.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 24944 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Abstractions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Abstractions.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 28024 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.WasHosting\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 12168 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.ServiceMoniker40\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.ServiceMoniker40.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 95592 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Caching\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Caching.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 86888 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing.Design\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 21880 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Workflow.Compiler\v4.0_4.0.0.0__31bf3856ad364e35\Microsoft.Workflow.Compiler.exe
+ 2011-11-12 12:39 . 2011-11-12 12:39 40304 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualC.STLCLR\v4.0_2.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.STLCLR.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 67968 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Conversion.v4.0\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Conversion.v4.0.dll
+ 2011-11-14 10:43 . 2011-11-14 10:43 70656 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Xaml.Hosting\201431794661c80c6dfc73979b31026f\System.Xaml.Hosting.ni.dll
+ 2011-11-14 10:43 . 2011-11-14 10:43 26112 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Routing\fc86f1d651f8705ca903ab8e54f2c15f\System.Web.Routing.ni.dll
+ 2011-11-14 10:43 . 2011-11-14 10:43 53760 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.DynamicD#\f346a9369903d4c8724c8e2a6ce01c49\System.Web.DynamicData.Design.ni.dll
+ 2011-11-14 10:43 . 2011-11-14 10:43 26112 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Abstract#\4dee9fa394659d2471f4f0fb75c85ec3\System.Web.Abstractions.ni.dll
+ 2011-11-14 10:43 . 2011-11-14 10:43 13824 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\726216d2d6041331c6dab737947d450d\System.ServiceModel.ServiceMoniker40.ni.dll
+ 2011-11-14 10:42 . 2011-11-14 10:42 46592 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Workflow.#\1ab2b522466c1afa6e3810573672e79f\Microsoft.Workflow.Compiler.ni.exe
+ 2011-11-14 10:40 . 2011-11-14 10:40 54784 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xaml.Hosting\70c840dc13aae2e1323b13d7b27030ae\System.Xaml.Hosting.ni.dll
+ 2011-11-14 10:40 . 2011-11-14 10:40 24064 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Routing\9484262c4f1cfaace92aa9d1fee76025\System.Web.Routing.ni.dll
+ 2011-11-14 10:40 . 2011-11-14 10:40 46592 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.DynamicD#\569a7210fae634e8827a1bd805922540\System.Web.DynamicData.Design.ni.dll
+ 2011-11-14 10:40 . 2011-11-14 10:40 24576 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Abstract#\0d2eb147f2b4b13af1141810688e2d5f\System.Web.Abstractions.ni.dll
+ 2011-11-14 10:40 . 2011-11-14 10:40 12288 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\2ac3fd2abc9bb5eab553ef8e44ca77ca\System.ServiceModel.ServiceMoniker40.ni.dll
+ 2011-11-14 10:39 . 2011-11-14 10:39 37376 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Workflow.#\6a8da5dd61b1fcfed27f84047a3e2bad\Microsoft.Workflow.Compiler.ni.exe
+ 2011-11-14 10:41 . 2011-11-14 10:41 90624 c:\windows\assembly\NativeImages_v2.0.50727_64\stdole\327e4351187b26a668e82c2cb898bd5c\stdole.ni.dll
- 2011-11-09 19:44 . 2011-11-09 19:44 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-11-17 17:26 . 2011-11-17 17:26 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-11-17 17:26 . 2011-11-17 17:26 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-11-09 19:44 . 2011-11-09 19:44 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-03-26 09:31 . 2011-11-17 17:25 224734 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S4.bin
+ 2011-03-26 17:51 . 2011-11-14 10:53 319324 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2009-07-14 02:36 . 2011-11-17 16:03 651648 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2011-11-17 16:03 120580 c:\windows\system32\perfc009.dat
- 2009-07-14 05:38 . 2011-11-09 17:26 262144 c:\windows\system32\config\systemprofile\ntuser.dat
+ 2009-07-14 05:38 . 2011-11-14 06:14 262144 c:\windows\system32\config\systemprofile\ntuser.dat
+ 2011-11-09 17:27 . 2011-11-17 17:26 131072 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2011-11-09 17:27 . 2011-11-09 19:44 131072 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-11-17 17:26 114688 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2011-11-09 19:44 114688 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 05:01 . 2011-11-17 17:25 390976 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2011-11-09 19:44 390976 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2011-11-09 17:02 . 2011-11-17 17:25 390976 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-839543870-2764649644-3222184407-1000-8192.dat
- 2011-11-09 17:02 . 2011-11-09 19:44 390976 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-839543870-2764649644-3222184407-1000-8192.dat
+ 2010-03-18 15:47 . 2010-03-18 15:47 142672 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WsatConfig.exe
+ 2010-03-18 15:47 . 2010-03-18 15:47 587624 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationBuildTasks.dll
+ 2010-03-18 16:23 . 2010-03-18 16:23 717136 c:\windows\Microsoft.NET\Framework64\v4.0.30319\webengine4.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 431984 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.WorkflowServices.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 511344 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Workflow.Runtime.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 826208 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Web.Mobile.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 321912 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Web.Extensions.Design.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 137568 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Web.Entity.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 132464 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Web.Entity.Design.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 237928 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Web.DynamicData.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 316272 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.ServiceModel.Web.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 170872 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.ServiceModel.Activation.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 683368 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Data.Services.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 178040 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Data.Services.Design.dll
+ 2010-03-18 16:23 . 2010-03-18 16:23 512368 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Data.OracleClient.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 804720 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Data.Entity.Design.dll
+ 2009-08-31 10:44 . 2009-08-31 10:44 144416 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\sqmapi.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 295248 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\SetupUi.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 807256 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\SetupEngine.dll
+ 2010-03-19 00:29 . 2010-03-19 00:29 872448 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\netfx_extended_x64.msi
+ 2010-03-18 16:23 . 2010-03-18 16:23 222544 c:\windows\Microsoft.NET\Framework64\v4.0.30319\peverify.dll
+ 2010-03-18 16:23 . 2010-03-18 16:23 132432 c:\windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe
+ 2010-03-18 16:23 . 2010-03-18 16:23 108880 c:\windows\Microsoft.NET\Framework64\v4.0.30319\MmcAspExt.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 220024 c:\windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.Build.Utilities.v4.0.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 107376 c:\windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.Build.Framework.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 714600 c:\windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.Build.Engine.dll
+ 2010-03-18 16:23 . 2010-03-18 16:23 351560 c:\windows\Microsoft.NET\Framework64\v4.0.30319\ilasm.exe
+ 2010-03-18 16:23 . 2010-03-18 16:23 221016 c:\windows\Microsoft.NET\Framework64\v4.0.30319\FileTracker.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 163672 c:\windows\Microsoft.NET\Framework64\v4.0.30319\ComSvcConfig.exe
+ 2010-03-18 16:23 . 2010-03-18 16:23 155984 c:\windows\Microsoft.NET\Framework64\v4.0.30319\clretwrc.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 498520 c:\windows\Microsoft.NET\Framework64\v4.0.30319\AspNetMMCExt.dll
+ 2010-03-18 16:23 . 2010-03-18 16:23 102232 c:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_regsql.exe
+ 2010-03-18 15:47 . 2010-03-18 15:47 142672 c:\windows\Microsoft.NET\Framework\v4.0.30319\WsatConfig.exe
+ 2010-03-18 15:47 . 2010-03-18 15:47 587624 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationBuildTasks.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 492368 c:\windows\Microsoft.NET\Framework\v4.0.30319\webengine4.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 431984 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.WorkflowServices.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 511344 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Workflow.Runtime.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 826208 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Web.Mobile.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 321912 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Web.Extensions.Design.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 137568 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Web.Entity.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 132464 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Web.Entity.Design.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 237928 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Web.DynamicData.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 316272 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.ServiceModel.Web.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 170872 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.ServiceModel.Activation.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 683368 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Data.Services.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 178040 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Data.Services.Design.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 495984 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Data.OracleClient.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 804720 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Data.Entity.Design.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 181584 c:\windows\Microsoft.NET\Framework\v4.0.30319\peverify.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 132944 c:\windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
+ 2010-03-18 15:47 . 2010-03-18 15:47 220024 c:\windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.Build.Utilities.v4.0.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 107376 c:\windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.Build.Framework.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 714600 c:\windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.Build.Engine.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 294728 c:\windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe
+ 2010-03-18 15:47 . 2010-03-18 15:47 173400 c:\windows\Microsoft.NET\Framework\v4.0.30319\FileTracker.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 163672 c:\windows\Microsoft.NET\Framework\v4.0.30319\ComSvcConfig.exe
+ 2010-03-18 15:47 . 2010-03-18 15:47 155472 c:\windows\Microsoft.NET\Framework\v4.0.30319\clretwrc.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 498520 c:\windows\Microsoft.NET\Framework\v4.0.30319\AspNetMMCExt.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 102744 c:\windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regsql.exe
+ 2011-11-12 12:39 . 2011-11-12 12:39 431984 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.WorkflowServices\v4.0_4.0.0.0__31bf3856ad364e35\System.WorkflowServices.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 511344 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Workflow.Runtime\v4.0_4.0.0.0__31bf3856ad364e35\System.Workflow.Runtime.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 826208 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Mobile\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 321912 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions.Design\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.Design.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 137568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Entity\v4.0_4.0.0.0__b77a5c561934e089\System.Web.Entity.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 132464 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Entity.Design\v4.0_4.0.0.0__b77a5c561934e089\System.Web.Entity.Design.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 237928 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.DynamicData\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.DynamicData.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 316272 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Web\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Web.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 170872 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Activation\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Activation.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 683368 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 178040 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services.Design\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.Design.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 804720 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity.Design\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Entity.Design.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 587624 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationBuildTasks\v4.0_4.0.0.0__31bf3856ad364e35\PresentationBuildTasks.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 220024 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Utilities.v4.0\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.v4.0.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 107376 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Framework\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 714600 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Engine\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 498520 c:\windows\Microsoft.NET\assembly\GAC_MSIL\AspNetMMCExt\v4.0_4.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 512368 c:\windows\Microsoft.NET\assembly\GAC_64\System.Data.OracleClient\v4.0_4.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 495984 c:\windows\Microsoft.NET\assembly\GAC_32\System.Data.OracleClient\v4.0_4.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2010-03-19 00:29 . 2010-03-19 00:29 872448 c:\windows\Installer\8a04d5.msi
+ 2009-07-12 11:16 . 2009-07-12 11:16 223232 c:\windows\Installer\8a04cf.msi
+ 2011-11-14 10:44 . 2011-11-14 10:44 527360 c:\windows\assembly\NativeImages_v4.0.30319_64\XamlBuildTask\f143ae2f8d285b159779b98fa614c310\XamlBuildTask.ni.dll
+ 2011-11-14 10:42 . 2011-11-14 10:42 448512 c:\windows\assembly\NativeImages_v4.0.30319_64\WsatConfig\1331bbcd0aaa52b60aaee1a01bec8053\WsatConfig.ni.exe
+ 2011-11-14 10:43 . 2011-11-14 10:43 240128 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Form#\94e2d169b99240d78484f0fef3884d43\System.Windows.Forms.DataVisualization.Design.ni.dll
+ 2011-11-14 10:43 . 2011-11-14 10:43 306176 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.RegularE#\f763c25e2c5c2234848cc22010970bfe\System.Web.RegularExpressions.ni.dll
+ 2011-11-14 10:43 . 2011-11-14 10:43 442368 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Entity\11a095c200079a6cf52d06b510cc8db2\System.Web.Entity.ni.dll
+ 2011-11-14 10:43 . 2011-11-14 10:43 360960 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Entity.D#\499093c175fa44cabf14de0e4258167b\System.Web.Entity.Design.ni.dll
+ 2011-11-14 10:43 . 2011-11-14 10:43 950784 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.DynamicD#\5c1f1ddf6e2bdb1c7bee06c2c3f8072c\System.Web.DynamicData.ni.dll
+ 2011-11-14 10:43 . 2011-11-14 10:43 323584 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.DataVisu#\c8afc9329f2a3b3fb8f42cbfa9654683\System.Web.DataVisualization.Design.ni.dll
+ 2011-11-14 10:43 . 2011-11-14 10:43 560640 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\03001f33f9d43c8256f0a4ea0d177df1\System.ServiceModel.Activation.ni.dll
+ 2011-11-14 10:42 . 2011-11-14 10:42 983552 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Remo#\fe0ab1bba3dcedd5e2ac47e859be078e\System.Runtime.Remoting.ni.dll
+ 2011-11-14 10:42 . 2011-11-14 10:42 306688 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Cach#\8cdb82aee5518b5d6e8d9521fe155575\System.Runtime.Caching.ni.dll
+ 2011-11-14 10:43 . 2011-11-14 10:43 284672 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Drawing.Desi#\67515d0d33aac17df9e39042e0427d9a\System.Drawing.Design.ni.dll
+ 2011-11-14 10:43 . 2011-11-14 10:43 646656 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Service#\202eda9671411062f280fe188fefbef0\System.Data.Services.Design.ni.dll
+ 2011-11-14 10:41 . 2011-11-14 10:41 357888 c:\windows\assembly\NativeImages_v4.0.30319_64\MSBuild\9fb02cb09727f99161b87b83e38e3cda\MSBuild.ni.exe
+ 2011-11-14 10:42 . 2011-11-14 10:42 417280 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\bcc8e35d753ffccf339770189e254c1c\Microsoft.VisualBasic.Compatibility.Data.ni.dll
+ 2011-11-14 10:42 . 2011-11-14 10:42 833024 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Build.Uti#\bb9c327bca111ed498ffbdfc3da50df7\Microsoft.Build.Utilities.v4.0.ni.dll
+ 2011-11-14 10:41 . 2011-11-14 10:41 350720 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Build.Fra#\e3a540b5a90eadb3b1d8717d3f48ac82\Microsoft.Build.Framework.ni.dll
+ 2011-11-14 10:41 . 2011-11-14 10:41 634880 c:\windows\assembly\NativeImages_v4.0.30319_64\ComSvcConfig\277ba7e739dd2581171f908cbbe0294c\ComSvcConfig.ni.exe
+ 2011-11-14 10:41 . 2011-11-14 10:41 985600 c:\windows\assembly\NativeImages_v4.0.30319_64\AspNetMMCExt\e6714c10925019a0d1b861b815e23061\AspNetMMCExt.ni.dll
+ 2011-11-14 10:40 . 2011-11-14 10:40 399360 c:\windows\assembly\NativeImages_v4.0.30319_32\XamlBuildTask\4daf91c66e01c3dd92b239feacaa8245\XamlBuildTask.ni.dll
+ 2011-11-14 10:39 . 2011-11-14 10:39 353792 c:\windows\assembly\NativeImages_v4.0.30319_32\WsatConfig\3c0d21e75c9a48aba6fba3ddff0fcf39\WsatConfig.ni.exe
+ 2011-11-14 10:40 . 2011-11-14 10:40 192512 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Form#\4cb0c81cca997d9fbecda9a1824f2fdb\System.Windows.Forms.DataVisualization.Design.ni.dll
+ 2011-11-14 10:40 . 2011-11-14 10:40 218624 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.RegularE#\770e21411a66352a12b5d3f1e47e972e\System.Web.RegularExpressions.ni.dll
+ 2011-11-14 10:40 . 2011-11-14 10:40 858112 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Extensio#\2e2096834f67f11a362be1e5c0da4d54\System.Web.Extensions.Design.ni.dll
+ 2011-11-14 10:40 . 2011-11-14 10:40 332288 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Entity\0d511c8f1da06cc18f2da9b593042841\System.Web.Entity.ni.dll
+ 2011-11-14 10:40 . 2011-11-14 10:40 296448 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Entity.D#\c69974f79eb0c96357fbf031df6d8ed0\System.Web.Entity.Design.ni.dll
+ 2011-11-14 10:40 . 2011-11-14 10:40 705536 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.DynamicD#\a1d43a413800a3fa024cba9161c34c44\System.Web.DynamicData.ni.dll
+ 2011-11-14 10:40 . 2011-11-14 10:40 256512 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.DataVisu#\8fbe244f1f9ad9ce887c125bae44a50b\System.Web.DataVisualization.Design.ni.dll
+ 2011-11-14 10:40 . 2011-11-14 10:40 421888 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\9e32918462a2d0c786fbf21a873cc358\System.ServiceModel.Activation.ni.dll
+ 2011-11-14 10:40 . 2011-11-14 10:40 767488 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\dc1f0dbf1d3ba856eccec90b62b55d79\System.Runtime.Remoting.ni.dll
+ 2011-11-14 10:40 . 2011-11-14 10:40 239616 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Cach#\565496636c549f7f72fff7db554685b6\System.Runtime.Caching.ni.dll
+ 2011-11-12 12:41 . 2011-11-12 12:41 223744 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Drawing.Desi#\8f9993d3eb4cd33d1452155f79b23d65\System.Drawing.Design.ni.dll
+ 2011-11-14 10:40 . 2011-11-14 10:40 499712 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Service#\ec884cc78d6c5bb67bc2c819b1f00ee5\System.Data.Services.Design.ni.dll
+ 2011-11-14 10:39 . 2011-11-14 10:39 273920 c:\windows\assembly\NativeImages_v4.0.30319_32\MSBuild\aa25092606e5e9826db7a7bd0adb9b2b\MSBuild.ni.exe
+ 2011-11-14 10:39 . 2011-11-14 10:39 629248 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Build.Uti#\b384b96460ad28697e8990e56b0234d8\Microsoft.Build.Utilities.v4.0.ni.dll
+ 2011-11-14 10:39 . 2011-11-14 10:39 257536 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Build.Fra#\11ef4be6ee227fce3725d6df534297a4\Microsoft.Build.Framework.ni.dll
+ 2011-11-14 10:39 . 2011-11-14 10:39 135680 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Build.Con#\837fa037ca302e7432ea9913ae453e70\Microsoft.Build.Conversion.v4.0.ni.dll
+ 2011-11-14 10:39 . 2011-11-14 10:39 471040 c:\windows\assembly\NativeImages_v4.0.30319_32\ComSvcConfig\51819c709096229ee187a7feee395d9f\ComSvcConfig.ni.exe
+ 2011-11-14 10:39 . 2011-11-14 10:39 842752 c:\windows\assembly\NativeImages_v4.0.30319_32\AspNetMMCExt\03bf63d8ea6622a32b9a3fc6851801a9\AspNetMMCExt.ni.dll
+ 2011-11-14 10:41 . 2011-11-14 10:41 107520 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft-Windows-H#\91766d4eec3608b7ef0771e2a27aa2c4\Microsoft-Windows-HomeGroupDiagnostic.NetListMgr.Interop.ni.dll
+ 2011-11-14 10:41 . 2011-11-14 10:41 126976 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiActivScp\d2b9c24ece4568e6d050cd44628ec2f6\ehiActivScp.ni.dll
+ 2009-07-14 04:45 . 2011-11-12 15:11 3798234 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
- 2009-07-14 04:45 . 2011-05-27 15:17 3798234 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2011-03-25 21:35 . 2011-11-17 17:25 3506144 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2010-03-18 15:47 . 2010-03-18 15:47 1587064 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Workflow.ComponentModel.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 1070960 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Workflow.Activities.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 1836904 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Web.Extensions.dll
+ 2010-03-18 16:23 . 2010-03-18 16:23 5145936 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Web.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 1697144 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Web.DataVisualization.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 5078360 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Design.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 1064816 c:\windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.Build.Tasks.v4.0.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 1327968 c:\windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.Build.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 1587064 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Workflow.ComponentModel.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 1070960 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Workflow.Activities.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 1836904 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Web.Extensions.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 5174608 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Web.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 1697144 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Web.DataVisualization.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 5078360 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Design.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 1064816 c:\windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.Build.Tasks.v4.0.dll
+ 2010-03-18 15:47 . 2010-03-18 15:47 1327968 c:\windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.Build.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 1587064 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Workflow.ComponentModel\v4.0_4.0.0.0__31bf3856ad364e35\System.Workflow.ComponentModel.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 1070960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Workflow.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.Workflow.Activities.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 1836904 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 1697144 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.DataVisualization.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 5078360 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Design\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 1327968 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 1064816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Tasks.v4.0\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.v4.0.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 5145936 c:\windows\Microsoft.NET\assembly\GAC_64\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2011-11-12 12:39 . 2011-11-12 12:39 5174608 c:\windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2009-07-11 19:46 . 2009-07-11 19:46 3136512 c:\windows\Installer\8a04c8.msi
+ 2011-11-14 10:44 . 2011-11-14 10:44 1564160 c:\windows\assembly\NativeImages_v4.0.30319_64\System.WorkflowServ#\789e6c024a821d83621bef3fb6c49967\System.WorkflowServices.ni.dll
+ 2011-11-14 10:44 . 2011-11-14 10:44 2758144 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Workflow.Run#\8f4da8b2f0959948003bf4b504caee25\System.Workflow.Runtime.ni.dll
+ 2011-11-14 10:44 . 2011-11-14 10:44 5749760 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Workflow.Com#\af580e724e9caead714dff8bc08508d8\System.Workflow.ComponentModel.ni.dll
+ 2011-11-14 10:43 . 2011-11-14 10:43 3664384 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Workflow.Act#\fa6bd29ac18116e49a81b4f16b804a4f\System.Workflow.Activities.ni.dll
+ 2011-11-14 10:42 . 2011-11-14 10:42 2268160 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Services\6cd002594b56953e9c210581e7f3f3cd\System.Web.Services.ni.dll
+ 2011-11-14 10:43 . 2011-11-14 10:43 2925568 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Mobile\bd7620d27c9492d58488c32d99768083\System.Web.Mobile.ni.dll
+ 2011-11-14 10:43 . 2011-11-14 10:43 1083392 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Extensio#\d9e5bfd269c03b3d023d48ec3975fc9c\System.Web.Extensions.Design.ni.dll
+ 2011-11-14 10:43 . 2011-11-14 10:43 3732480 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Extensio#\626bd92f3332be2f23cf2fc2c39133e1\System.Web.Extensions.ni.dll
+ 2011-11-14 10:43 . 2011-11-14 10:43 5501952 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.DataVisu#\a344d19794ec874b827e9331e587d555\System.Web.DataVisualization.ni.dll
+ 2011-11-14 10:43 . 2011-11-14 10:43 1426944 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\43f892698b9de4d752c13cc2d91ff16d\System.ServiceModel.Web.ni.dll
+ 2011-11-14 10:43 . 2011-11-14 10:43 2636800 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Services\84226b67f4623bd3b0dde9aa00c5c88d\System.Data.Services.ni.dll
+ 2011-11-14 10:43 . 2011-11-14 10:43 1481728 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.OracleC#\850abdea1c65b88ba24a77f0191caea8\System.Data.OracleClient.ni.dll
+ 2011-11-14 10:43 . 2011-11-14 10:43 1694720 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Entity.#\4e95b694037430c97b5987e4c18ef1c1\System.Data.Entity.Design.ni.dll
+ 2011-11-14 10:42 . 2011-11-14 10:42 1861632 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationBuildTa#\af8ec2588657e48d0b61ef1b79055e00\PresentationBuildTasks.ni.dll
+ 2011-11-14 10:42 . 2011-11-14 10:42 1821696 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\8fe251848367c36401ce92e83a3f7f61\Microsoft.VisualBasic.Compatibility.ni.dll
+ 2011-11-14 10:42 . 2011-11-14 10:42 5853184 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Build\055d4ad3cccc507fe82e90951a562783\Microsoft.Build.ni.dll
+ 2011-11-14 10:43 . 2011-11-14 10:43 3726848 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Build.Tas#\525b26d5bcdfd73ea71b1c273f992ee7\Microsoft.Build.Tasks.v4.0.ni.dll
+ 2011-11-14 10:42 . 2011-11-14 10:42 2490880 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Build.Eng#\2a8e444347d30c9c040129e2ee65372a\Microsoft.Build.Engine.ni.dll
+ 2011-11-14 10:40 . 2011-11-14 10:40 1203712 c:\windows\assembly\NativeImages_v4.0.30319_32\System.WorkflowServ#\ad9facc364268611cc4ca65f77caeddd\System.WorkflowServices.ni.dll
+ 2011-11-14 10:40 . 2011-11-14 10:40 1956352 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Workflow.Run#\be049b8fe1bf23daab7e76159a7e00dd\System.Workflow.Runtime.ni.dll
+ 2011-11-14 10:40 . 2011-11-14 10:40 4428800 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Workflow.Com#\467bcaca5f4d2914922f62772ea4ea7d\System.Workflow.ComponentModel.ni.dll
+ 2011-11-14 10:40 . 2011-11-14 10:40 2839552 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Workflow.Act#\544e73a3f3f2daea050f03e4c94e9a6d\System.Workflow.Activities.ni.dll
+ 2011-11-14 10:40 . 2011-11-14 10:40 1864704 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Services\149f2dcb9c9706e592d1980a945850c2\System.Web.Services.ni.dll
+ 2011-11-14 10:40 . 2011-11-14 10:40 2324992 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Mobile\c7b1290bb35d3e3c53d20e5928c9fa73\System.Web.Mobile.ni.dll
+ 2011-11-14 10:40 . 2011-11-14 10:40 3078144 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Extensio#\0f643b7bd4525c3165733f6988bdbfe2\System.Web.Extensions.ni.dll
+ 2011-11-14 10:40 . 2011-11-14 10:40 4429312 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.DataVisu#\9df99ed350ef0a43fbcc1b9e586f1c7f\System.Web.DataVisualization.ni.dll
+ 2011-11-14 10:40 . 2011-11-14 10:40 1046528 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\51c60db370e050d9cdcac17060aaac53\System.ServiceModel.Web.ni.dll
+ 2011-11-14 10:40 . 2011-11-14 10:40 2008576 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Services\62f067f8572551df931b3ee6493383d7\System.Data.Services.ni.dll
+ 2011-11-14 10:40 . 2011-11-14 10:40 1183744 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.OracleC#\db33744fb49e77c7233adb50f07fe62a\System.Data.OracleClient.ni.dll
+ 2011-11-14 10:40 . 2011-11-14 10:40 1398272 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Entity.#\7bab044e648dfea461b73dc898150539\System.Data.Entity.Design.ni.dll
+ 2011-11-14 10:39 . 2011-11-14 10:39 1467904 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationBuildTa#\d0e67f49781c157069bc3298454354bd\PresentationBuildTasks.ni.dll
+ 2011-11-14 10:39 . 2011-11-14 10:39 1135104 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\6f82f181d36fcd0e1fd5f09a22e0b8db\Microsoft.VisualBasic.Compatibility.ni.dll
+ 2011-11-14 10:39 . 2011-11-14 10:39 4226560 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Build\3bfb841477d28ca866b91211f50199bb\Microsoft.Build.ni.dll
+ 2011-11-14 10:39 . 2011-11-14 10:39 2850816 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Build.Tas#\8973265600edd2135ecf5e369a087dfb\Microsoft.Build.Tasks.v4.0.ni.dll
+ 2011-11-14 10:39 . 2011-11-14 10:39 1914368 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Build.Eng#\7cfd4a64a95807ee7cb6ae50cfabd93c\Microsoft.Build.Engine.ni.dll
+ 2011-11-14 10:41 . 2011-11-14 10:41 2184192 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiVidCtl\ae155ce3d320566c76599ec972efbdad\ehiVidCtl.ni.dll
+ 2009-07-14 02:34 . 2011-11-17 14:10 10223616 c:\windows\system32\SMI\Store\Machine\schema.dat
- 2009-07-14 02:34 . 2011-11-09 17:41 10223616 c:\windows\system32\SMI\Store\Machine\schema.dat
+ 2011-11-14 10:42 . 2011-11-14 10:42 15503360 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web\7e5af1fdbcffeab8daffc7633f9c337a\System.Web.ni.dll
+ 2011-11-14 10:42 . 2011-11-14 10:42 13076480 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Design\a6cf47e2ac5fdeb5fdb8d3e5630c9d93\System.Design.ni.dll
+ 2011-11-14 10:40 . 2011-11-14 10:40 11912704 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web\a70842538614699d690561ef5f43598b\System.Web.ni.dll
+ 2011-11-12 12:41 . 2011-11-12 12:41 10847744 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Design\95a46d4775428acf5dd84f12aaa9f06f\System.Design.ni.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Tomáš\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Tomáš\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Tomáš\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Tomáš\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="d:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
"RGSC"="d:\program files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe" [2008-11-14 305064]
"msnmsgr"="c:\program files (x86)\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
"ICQ"="d:\program files\ICQ7.4\ICQ.exe" [2011-03-25 119608]
"Eodsdw"="c:\users\Tomáš\AppData\Roaming\Eodsdw.exe" [2011-11-17 200704]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-21 35760]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"NBAgent"="c:\program files (x86)\Nero\Nero BackItUp & Burn\Nero BackItUp\NBAgent.exe" [2010-03-09 1086760]
"Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-11-11 288088]
"ITSecMng"="c:\program files (x86)\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2009-07-22 83336]
"ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-10-06 1294136]
"TWebCamera"="c:\program files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2010-02-24 2454840]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-03-08 336384]
"AdobeCS4ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"Adobe Acrobat Speed Launcher"="d:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232]
"Acrobat Assistant 8.0"="d:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-11 640376]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
"GLDStart"="d:\program files (x86)\GLDirect\gldirect.exe" [2004-07-20 241664]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"TOSHIBA Online Product Information"="c:\program files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe" [2010-03-03 4581280]
.
c:\users\Tomáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Tomáš\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-5-25 24176560]
hamachi.lnk - d:\program files\Hamachi\hamachi.exe [2011-8-21 624416]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2010-2-24 2721120]
Network Server.lnk - c:\program files (x86)\WIBUKEY\Server\WkSvMgr.exe [2011-5-22 3768320]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
TRDCReminder.lnk - c:\program files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe [2009-9-1 481184]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2008-08-15 284016]
R3 AODDriver4.0;AODDriver4.0;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011-04-24 1038088]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUStor.sys [x]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x]
R3 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe [2010-02-11 124368]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-03-08 365568]
S2 AMD Reservation Manager;AMD Reservation Manager;c:\program files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe [2010-06-17 194496]
S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2010-01-28 249200]
S2 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-10 46448]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [2011-01-12 810144]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [x]
S2 icas;iTALC Client;d:\program files\iTALC\ica.exe [2011-01-06 814094]
S2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\SysWOW64\nlssrv32.exe [2011-02-21 66560]
S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2010-03-17 258928]
S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [x]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [x]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 CnxtHdmiAudService;Conexant UAA HDMI Function Driver for High Definition Audio Service;c:\windows\system32\drivers\CHDMI64.sys [x]
S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [x]
S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x]
S3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512]
S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-05 137560]
S3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2010-02-23 835952]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Tomáš\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Tomáš\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Tomáš\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Tomáš\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2010-02-05 709976]
"TosReelTimeMonitor"="c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe" [BU]
"TosNC"="c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe" [BU]
"Toshiba TEMPRO"="c:\program files (x86)\Toshiba TEMPRO\TemproTray.exe" [2010-02-11 1050072]
"SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2009-11-19 307768]
"cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2010-03-10 520760]
"TPwrMain"="c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE" [BU]
"HSON"="c:\program files (x86)\TOSHIBA\TBS\HSON.exe" [BU]
"SmoothView"="c:\program files (x86)\Toshiba\SmoothView\SmoothView.exe" [BU]
"00TCrdMain"="c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe" [BU]
"Teco"="c:\program files (x86)\TOSHIBA\TECO\Teco.exe" [BU]
"TosWaitSrv"="c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe" [BU]
"TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376]
"SmartFaceVWatcher"="c:\program files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe" [BU]
"Toshiba Registration"="c:\program files\Toshiba\Registration\ToshibaReminder.exe" [2010-04-19 136136]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-01-12 2918656]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://facebook.com/
mStart Page = hxxp://startsear.ch
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Append Link Target to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xportovať do programu Microsoft Excel - d:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: Sothink SWF Catcher - c:\program files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
IE: {{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - d:\program files\ICQ7.4\ICQ.exe
TCP: DhcpNameServer = 192.168.10.1
TCP: Interfaces\{D790733C-180E-4CE7-B707-22C62435B11A}: NameServer = 192.168.1.1
FF - ProfilePath - c:\users\Tomáš\AppData\Roaming\Mozilla\Firefox\Profiles\oeb9zod4.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.sk/
FF - prefs.js: keyword.URL - hxxp://startsear.ch/?q=
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-839543870-2764649644-3222184407-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:15,d2,65,0e,2b,3b,a5,a8,ac,df,82,68,5d,ad,d3,e3,de,2e,3a,ea,76,09,03,
16,34,c4,6b,32,ed,c5,b8,a2,66,57,e9,af,44,ab,47,8f,1e,45,f6,50,10,95,b2,e7,\
"??"=hex:21,c6,db,3b,34,31,ed,4e,5e,c3,42,6e,e5,bd,e9,fb
.
[HKEY_USERS\S-1-5-21-839543870-2764649644-3222184407-1000\Software\SecuROM\License information*]
"datasecu"=hex:7a,ac,ad,76,a1,43,54,f2,b0,2e,5c,39,dc,dd,92,04,18,74,d4,a9,f9,
da,9a,c2,26,d2,83,62,5c,3a,6d,24,98,d8,59,08,58,d9,06,ef,8c,9e,a0,5d,76,c6,\
"rkeysecu"=hex:24,f3,78,c1,4a,ae,f6,72,f4,bd,e5,98,ef,c5,21,28
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-11-17 19:29:26
ComboFix-quarantined-files.txt 2011-11-17 18:29
ComboFix2.txt 2011-11-09 20:02
.
Pre-Run: 43 744 694 272 bytes free
Post-Run: 43 698 479 104 bytes free
.
- - End Of File - - DC16B0635D5C457C0796D54B7AD62CCC

Re: facebook vírus

Napsal: 17 lis 2011 20:06
od vyosek
:arrow: A jeje, zase diakritika :?:

:arrow: Presunte ComboFix primo na disk c:\

:arrow: Na disku C:\ vytvorte znovu skript a aplikujte jej

Re: facebook vírus

Napsal: 23 lis 2011 20:50
od tomi
tu to je:


ComboFix 11-11-23.01 - Tomáš . 11. 2011 20:11:39.3.2 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.421.1051.18.4091.2726 [GMT 1:00]
Running from: C:\ComboFix.exe
Command switches used :: C:\CFScript.TXT
AV: ESET Smart Security 4.2 *Disabled/Outdated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET Personal firewall *Disabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 4.2 *Disabled/Outdated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
FILE ::
"c:\users\Tomáš\Downloads\Assassins+Creed+-+Crack.rar"
"c:\users\Tomáš\Downloads\FI57FA12CrackRelo-jan0000.zip"
"c:\users\Tomáš\Downloads\FIFA-11-Crack+Keygen.rar"
"c:\users\Tomáš\Downloads\FIFA-12---RELOADED-CRACK.rar"
"c:\users\Tomáš\Downloads\FIFA-12-Crack-by-SKIDROW.rar"
"c:\users\Tomáš\Downloads\FIFA.12_RELOADED_CracksSite.rar"
"c:\users\Tomáš\Downloads\FIFA.12_RELOADED_CracksSite.rar.part"
"c:\users\Tomáš\Downloads\star-wars-the-force-unleashed-2-2010-p2p-crack-by-muploaders-of-ups.rar"
"c:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-839543870-2764649644-3222184407-1000Core.job"
"c:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-839543870-2764649644-3222184407-1000UA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Tomáš\AppData\Roaming\1DFC.exe
c:\users\Tomáš\AppData\Roaming\31CB.tmp
c:\users\Tomáš\AppData\Roaming\5705.exe
c:\users\Tomáš\AppData\Roaming\7179.exe
c:\users\Tomáš\AppData\Roaming\7243.exe
c:\users\Tomáš\AppData\Roaming\7FEA.tmp
c:\users\Tomáš\AppData\Roaming\AE09.exe
c:\users\Tomáš\AppData\Roaming\F4B.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-10-23 to 2011-11-23 )))))))))))))))))))))))))))))))
.
.
2011-11-23 19:26 . 2011-11-23 19:26 69000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6B319FE3-96BB-4772-9A68-34DAF9B184F2}\offreg.dll
2011-11-23 19:22 . 2011-11-23 19:22 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-11-23 18:43 . 2011-11-23 18:43 131584 ----a-w- c:\users\Tomáš\AppData\Roaming\Eodsdw.exe
2011-11-23 13:21 . 2011-11-23 13:21 137536 ----a-w- c:\users\Tomáš\AppData\Roaming\4642.exe
2011-11-22 17:35 . 2011-11-23 13:21 -------- d-----w- c:\users\Tomáš\AppData\Roaming\kakao4
2011-11-22 17:35 . 2011-11-22 17:35 137536 ----a-w- c:\users\Tomáš\AppData\Roaming\58D8.exe
2011-11-20 09:03 . 2011-11-20 09:03 0 ----a-w- c:\users\Tomáš\AppData\Roaming\5215.tmp
2011-11-17 08:04 . 2011-11-17 08:04 0 ----a-w- c:\users\Tomáš\AppData\Roaming\6FB4.tmp
2011-11-16 13:15 . 2011-11-21 13:27 -------- d-----w- c:\users\Tomáš\AppData\Roaming\kakao3
2011-11-15 08:36 . 2011-11-15 08:36 -------- d-----w- c:\programdata\Conexant
2011-11-15 08:36 . 2011-11-15 08:36 -------- d-----w- c:\users\Tomáš\AppData\Local\Conexant
2011-11-14 18:48 . 2011-11-14 18:48 -------- d-----w- c:\users\Tomáš\AppData\Local\Floorball League
2011-11-14 09:15 . 2011-11-14 09:42 -------- d-----w- c:\program files (x86)\Prodigium Game Studios
2011-11-12 13:04 . 2011-11-13 09:45 -------- d-----w- c:\programdata\boost_interprocess
2011-11-12 12:49 . 2011-11-14 06:14 -------- d-----w- c:\program files\Common Files\Autodesk Shared
2011-11-09 20:02 . 2011-11-09 20:02 -------- d-----w- c:\users\Tomárysis2\AppData
2011-11-09 17:08 . 2011-11-14 09:45 -------- d-----w- c:\users\Tomáš\AppData\Local\Diagnostics
2011-11-09 17:00 . 2011-11-09 17:00 -------- d-----w- C:\_OTL
2011-11-08 20:59 . 2011-11-08 21:33 512 ----a-w- C:\PhysicalMBR.bin
2011-11-07 20:39 . 2011-11-07 20:39 -------- d-----w- c:\program files\trend micro
2011-11-07 20:39 . 2011-11-07 20:39 -------- d-----w- C:\rsit
2011-11-06 08:30 . 2011-11-09 17:26 -------- d-----w- c:\users\Tomáš\AppData\Roaming\kakao2
2011-11-05 16:13 . 2011-11-05 16:13 -------- d-----w- c:\users\Tomáš\Application Data
2011-10-29 14:03 . 2011-10-29 14:03 -------- d-sh--w- c:\windows\system32\%APPDATA%
2011-10-27 12:54 . 2011-10-27 12:54 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-10-27 12:42 . 2011-10-27 12:42 -------- d-----w- c:\windows\system32\Macromed
2011-10-26 19:54 . 2011-10-26 19:55 -------- d-----w- c:\users\Tomáš\AppData\Roaming\GetRightToGo
2011-10-26 18:51 . 2006-07-24 14:05 5632 ----a-w- c:\windows\SysWow64\drivers\StarOpen.sys
2011-10-26 18:47 . 2011-10-26 18:52 -------- d-----w- c:\windows\SysWow64\Samsung_USB_Drivers
2011-10-26 18:42 . 2011-10-26 18:47 -------- d-----w- c:\program files (x86)\SAMSUNG
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-23 18:43 . 2011-11-23 18:43 131584 ----a-w- c:\users\Tomáš\AppData\Roaming\Eodsdw.exe
2011-11-23 18:43 . 2011-11-23 18:43 131584 ----a-w- c:\users\Tomáš\AppData\Roaming\Eodsdw.exe
2011-11-23 13:21 . 2011-11-23 13:21 137536 ----a-w- c:\users\Tomáš\AppData\Roaming\4642.exe
2011-11-23 13:21 . 2011-11-23 13:21 137536 ----a-w- c:\users\Tomáš\AppData\Roaming\4642.exe
2011-11-22 17:35 . 2011-11-22 17:35 137536 ----a-w- c:\users\Tomáš\AppData\Roaming\58D8.exe
2011-11-22 17:35 . 2011-11-22 17:35 137536 ----a-w- c:\users\Tomáš\AppData\Roaming\58D8.exe
2011-11-20 09:03 . 2011-11-20 09:03 0 ----a-w- c:\users\Tomáš\AppData\Roaming\5215.tmp
2011-11-20 09:03 . 2011-11-20 09:03 0 ----a-w- c:\users\Tomáš\AppData\Roaming\5215.tmp
2011-11-17 08:04 . 2011-11-17 08:04 0 ----a-w- c:\users\Tomáš\AppData\Roaming\6FB4.tmp
2011-11-17 08:04 . 2011-11-17 08:04 0 ----a-w- c:\users\Tomáš\AppData\Roaming\6FB4.tmp
2011-11-14 18:51 . 2011-04-23 12:42 122904 ----a-w- c:\windows\system32\OpenAL32.dll
2011-11-14 18:51 . 2011-04-23 12:42 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2011-10-17 17:32 . 2011-10-17 17:32 358150 ------w- c:\users\Tomáš\AppData\Roaming\C494.exe
2011-10-17 17:32 . 2011-10-17 17:32 358150 ------w- c:\users\Tomáš\AppData\Roaming\C494.exe
2011-10-16 07:39 . 2011-10-16 07:39 358150 ------w- c:\users\Tomáš\AppData\Roaming\277D.exe
2011-10-16 07:39 . 2011-10-16 07:39 358150 ------w- c:\users\Tomáš\AppData\Roaming\277D.exe
2011-10-12 17:21 . 2011-10-12 17:21 358150 ------w- c:\users\Tomáš\AppData\Roaming\A1CA.exe
2011-10-12 17:21 . 2011-10-12 17:21 358150 ------w- c:\users\Tomáš\AppData\Roaming\A1CA.exe
2011-10-07 12:30 . 2011-10-07 12:30 4679 ------w- c:\users\Tomáš\AppData\Roaming\710A.exe
2011-10-07 12:30 . 2011-10-07 12:30 4679 ------w- c:\users\Tomáš\AppData\Roaming\710A.exe
2011-09-23 19:17 . 2011-04-23 12:42 466520 ----a-w- c:\windows\system32\wrap_oal.dll
2011-09-23 19:17 . 2011-04-23 12:42 445016 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2011-09-13 00:26 . 2011-09-28 13:09 9049936 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6B319FE3-96BB-4772-9A68-34DAF9B184F2}\mpengine.dll
.
.
((((((((((((((((((((((((((((( SnapShot_2011-11-17_18.09.13 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-04-15 04:49 . 2011-11-23 19:26 59682 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-11-23 19:26 44380 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2011-03-25 21:39 . 2011-11-23 19:26 14130 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-839543870-2764649644-3222184407-1000_UserData.bin
+ 2011-03-25 15:36 . 2011-11-23 19:24 98304 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-03-25 15:36 . 2011-11-17 17:26 98304 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-03-25 19:09 . 2011-11-23 19:01 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-03-25 19:09 . 2011-11-17 17:29 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-03-25 19:09 . 2011-11-17 17:29 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-03-25 19:09 . 2011-11-23 19:01 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-11-23 19:24 . 2011-11-23 19:24 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-11-17 17:26 . 2011-11-17 17:26 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-11-17 17:26 . 2011-11-17 17:26 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-11-23 19:24 . 2011-11-23 19:24 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-03-26 17:51 . 2011-11-20 18:25 319524 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin
- 2009-07-14 02:36 . 2011-11-17 16:03 651648 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2011-11-23 15:13 651648 c:\windows\system32\perfh009.dat
- 2009-07-14 02:36 . 2011-11-17 16:03 120580 c:\windows\system32\perfc009.dat
+ 2009-07-14 02:36 . 2011-11-23 15:13 120580 c:\windows\system32\perfc009.dat
- 2009-07-14 05:12 . 2011-06-28 10:18 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-07-14 05:12 . 2011-11-20 12:52 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2011-11-09 17:27 . 2011-11-17 17:26 131072 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2011-11-09 17:27 . 2011-11-23 19:24 131072 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-11-17 17:26 114688 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-11-23 19:24 114688 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 05:01 . 2011-11-23 19:23 390976 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2011-11-17 17:25 390976 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2011-11-09 17:02 . 2011-11-21 21:07 390976 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-839543870-2764649644-3222184407-1000-8192.dat
- 2011-11-09 17:02 . 2011-11-17 17:25 390976 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-839543870-2764649644-3222184407-1000-8192.dat
- 2011-03-25 21:35 . 2011-11-17 17:25 3506144 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2011-03-25 21:35 . 2011-11-23 19:23 3506144 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2009-07-14 02:34 . 2011-11-23 18:55 10223616 c:\windows\system32\SMI\Store\Machine\schema.dat
- 2009-07-14 02:34 . 2011-11-17 14:10 10223616 c:\windows\system32\SMI\Store\Machine\schema.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Tomáš\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Tomáš\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Tomáš\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Tomáš\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-11-11 288088]
"ITSecMng"="c:\program files (x86)\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2009-07-22 83336]
"ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-10-06 1294136]
"TWebCamera"="c:\program files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2010-02-24 2454840]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-03-08 336384]
"GLDStart"="d:\program files (x86)\GLDirect\gldirect.exe" [2004-07-20 241664]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"TOSHIBA Online Product Information"="c:\program files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe" [2010-03-03 4581280]
.
c:\users\Tomáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Tomáš\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-5-25 24176560]
hamachi.lnk - d:\program files\Hamachi\hamachi.exe [2011-8-21 624416]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2010-2-24 2721120]
Network Server.lnk - c:\program files (x86)\WIBUKEY\Server\WkSvMgr.exe [2011-5-22 3768320]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
TRDCReminder.lnk - c:\program files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe [2009-9-1 481184]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2008-08-15 284016]
R3 AODDriver4.0;AODDriver4.0;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011-04-24 1038088]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUStor.sys [x]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x]
R3 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe [2010-02-11 124368]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-03-08 365568]
S2 AMD Reservation Manager;AMD Reservation Manager;c:\program files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe [2010-06-17 194496]
S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2010-01-28 249200]
S2 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-10 46448]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [2011-01-12 810144]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [x]
S2 icas;iTALC Client;d:\program files\iTALC\ica.exe [2011-01-06 814094]
S2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\SysWOW64\nlssrv32.exe [2011-02-21 66560]
S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2010-03-17 258928]
S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [x]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [x]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 CnxtHdmiAudService;Conexant UAA HDMI Function Driver for High Definition Audio Service;c:\windows\system32\drivers\CHDMI64.sys [x]
S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [x]
S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x]
S3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512]
S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-05 137560]
S3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2010-02-23 835952]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Tomáš\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Tomáš\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Tomáš\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Tomáš\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2010-02-05 709976]
"TosReelTimeMonitor"="c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe" [BU]
"TosNC"="c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe" [BU]
"Toshiba TEMPRO"="c:\program files (x86)\Toshiba TEMPRO\TemproTray.exe" [2010-02-11 1050072]
"SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2009-11-19 307768]
"cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2010-03-10 520760]
"TPwrMain"="c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE" [BU]
"HSON"="c:\program files (x86)\TOSHIBA\TBS\HSON.exe" [BU]
"SmoothView"="c:\program files (x86)\Toshiba\SmoothView\SmoothView.exe" [BU]
"00TCrdMain"="c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe" [BU]
"Teco"="c:\program files (x86)\TOSHIBA\TECO\Teco.exe" [BU]
"TosWaitSrv"="c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe" [BU]
"TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376]
"SmartFaceVWatcher"="c:\program files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe" [BU]
"Toshiba Registration"="c:\program files\Toshiba\Registration\ToshibaReminder.exe" [2010-04-19 136136]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-01-12 2918656]
.
------- Supplementary Scan -------
.
uLocal Page = %SystemRoot%\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Append Link Target to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xportovať do programu Microsoft Excel - d:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: Sothink SWF Catcher - c:\program files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
IE: {{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - d:\program files\ICQ7.4\ICQ.exe
TCP: DhcpNameServer = 192.168.10.1
TCP: Interfaces\{D790733C-180E-4CE7-B707-22C62435B11A}: NameServer = 192.168.1.1
FF - ProfilePath - c:\users\Tomáš\AppData\Roaming\Mozilla\Firefox\Profiles\oeb9zod4.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.sk/
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
c:\program files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\program files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
.
**************************************************************************
.
Completion time: 2011-11-23 20:46:29 - machine was rebooted
ComboFix-quarantined-files.txt 2011-11-23 19:46
ComboFix2.txt 2011-11-17 18:29
ComboFix3.txt 2011-11-09 20:02
.
Pre-Run: 37 410 254 848 bytes free
Post-Run: 37 285 408 768 bytes free
.
- - End Of File - - 0EB22DE9B27D3B0716AA4EF216D07886

Re: facebook vírus

Napsal: 23 lis 2011 21:45
od vyosek
:arrow: Stahnete OTM (viz muj podpis)
  • Pokud pouzivate Win Vista ci W7, kliknete na OTM pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do leveho okna Paste Instructions for Items to be Moved (pod zlutou caru) vlozte obsah, ktery mate nize
  • Kód: Vybrat vše

    :files
    c:\users\Tomáš\AppData\Roaming\*.exe
    c:\users\Tomáš\AppData\Roaming\*.tmp
    c:\windows\system32\%APPDATA%
    c:\users\Tomáš\AppData\Roaming\kakao4
    %windir%\system32\*.tmp.dll /s
    %windir%\system32\SET*.tmp /s
    %windir%\*.tmp
    
    :commands
    [RESETHOSTS]
    [EMPTYTEMP]
    [EMPTYFLASH]
  • Kliknete na cervene tlacitko MoveIt!
  • Budete vyzvani na restart, dejte Yes, log pote najdete C:\_OTM\MovedFiles, obsah sem vlozte

Re: facebook vírus

Napsal: 24 lis 2011 19:00
od tomi
All processes killed
========== FILES ==========
c:\users\Tomáš\AppData\Roaming\277D.exe moved successfully.
c:\users\Tomáš\AppData\Roaming\4642.exe moved successfully.
c:\users\Tomáš\AppData\Roaming\58D8.exe moved successfully.
c:\users\Tomáš\AppData\Roaming\710A.exe moved successfully.
c:\users\Tomáš\AppData\Roaming\A1CA.exe moved successfully.
c:\users\Tomáš\AppData\Roaming\C494.exe moved successfully.
c:\users\Tomáš\AppData\Roaming\Eodsdw.exe moved successfully.
c:\users\Tomáš\AppData\Roaming\5215.tmp moved successfully.
c:\users\Tomáš\AppData\Roaming\6FB4.tmp moved successfully.
File/Folder c:\windows\system32\%APPDATA% not found.
c:\users\Tomáš\AppData\Roaming\kakao4 folder moved successfully.
File/Folder C:\Windows\system32\*.tmp.dll not found.
File/Folder C:\Windows\system32\SET*.tmp not found.
File/Folder C:\Windows\*.tmp not found.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 38784 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

User: Tomárysis2
->Temp folder emptied: 0 bytes

User: Tomáš
->Temp folder emptied: 962247 bytes
->Temporary Internet Files folder emptied: 16752598 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 57415863 bytes
->Google Chrome cache emptied: 358904763 bytes
->Flash cache emptied: 56285 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 3238112 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 3118 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 2346204 bytes
RecycleBin emptied: 109988 bytes

Total Files Cleaned = 419,00 mb


[EMPTYFLASH]

User: All Users

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Public

User: Tomárysis2

User: Tomáš
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0,00 mb


OTM by OldTimer - Version 3.1.19.0 log created on 11242011_185442

Files moved on Reboot...
C:\Users\Tomáš\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File move failed. C:\Windows\temp\italc_client.log scheduled to be moved on reboot.

Registry entries deleted on Reboot...

Re: facebook vírus

Napsal: 24 lis 2011 19:04
od vyosek
Spustte nyni ComboFix - bez skriptu - a dejte z nej log

Re: facebook vírus

Napsal: 24 lis 2011 19:21
od tomi
ComboFix 11-11-24.01 - Tomáš . 11. 2011 19:13:58.4.2 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.421.1051.18.4091.2651 [GMT 1:00]
Running from: c:\users\Tomáš\Desktop\ComboFix.exe
AV: ESET Smart Security 4.2 *Disabled/Outdated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET Personal firewall *Disabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 4.2 *Disabled/Outdated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2011-10-24 to 2011-11-24 )))))))))))))))))))))))))))))))
.
.
2011-11-24 18:18 . 2011-11-24 18:18 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-11-24 17:58 . 2011-11-24 17:58 69000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6B319FE3-96BB-4772-9A68-34DAF9B184F2}\offreg.dll
2011-11-24 17:54 . 2011-11-24 17:54 -------- d-----w- C:\_OTM
2011-11-24 15:08 . 2011-11-24 15:08 -------- d-----w- c:\users\Tomáš\Turbo Squid Tentacles
2011-11-16 13:15 . 2011-11-21 13:27 -------- d-----w- c:\users\Tomáš\AppData\Roaming\kakao3
2011-11-15 08:36 . 2011-11-15 08:36 -------- d-----w- c:\programdata\Conexant
2011-11-15 08:36 . 2011-11-15 08:36 -------- d-----w- c:\users\Tomáš\AppData\Local\Conexant
2011-11-14 09:15 . 2011-11-14 09:42 -------- d-----w- c:\program files (x86)\Prodigium Game Studios
2011-11-12 13:04 . 2011-11-13 09:45 -------- d-----w- c:\programdata\boost_interprocess
2011-11-12 12:49 . 2011-11-14 06:14 -------- d-----w- c:\program files\Common Files\Autodesk Shared
2011-11-09 20:02 . 2011-11-09 20:02 -------- d-----w- c:\users\Tomárysis2\AppData
2011-11-09 17:08 . 2011-11-14 09:45 -------- d-----w- c:\users\Tomáš\AppData\Local\Diagnostics
2011-11-09 17:00 . 2011-11-09 17:00 -------- d-----w- C:\_OTL
2011-11-08 20:59 . 2011-11-08 21:33 512 ----a-w- C:\PhysicalMBR.bin
2011-11-07 20:39 . 2011-11-07 20:39 -------- d-----w- c:\program files\trend micro
2011-11-07 20:39 . 2011-11-07 20:39 -------- d-----w- C:\rsit
2011-11-06 08:30 . 2011-11-09 17:26 -------- d-----w- c:\users\Tomáš\AppData\Roaming\kakao2
2011-11-05 16:13 . 2011-11-05 16:13 -------- d-----w- c:\users\Tomáš\Application Data
2011-10-29 14:03 . 2011-10-29 14:03 -------- d-sh--w- c:\windows\system32\%APPDATA%
2011-10-27 12:54 . 2011-10-27 12:54 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-10-27 12:42 . 2011-10-27 12:42 -------- d-----w- c:\windows\system32\Macromed
2011-10-26 19:54 . 2011-10-26 19:55 -------- d-----w- c:\users\Tomáš\AppData\Roaming\GetRightToGo
2011-10-26 18:51 . 2006-07-24 14:05 5632 ----a-w- c:\windows\SysWow64\drivers\StarOpen.sys
2011-10-26 18:47 . 2011-10-26 18:52 -------- d-----w- c:\windows\SysWow64\Samsung_USB_Drivers
2011-10-26 18:42 . 2011-10-26 18:47 -------- d-----w- c:\program files (x86)\SAMSUNG
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-14 18:51 . 2011-04-23 12:42 122904 ----a-w- c:\windows\system32\OpenAL32.dll
2011-11-14 18:51 . 2011-04-23 12:42 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2011-09-23 19:17 . 2011-04-23 12:42 466520 ----a-w- c:\windows\system32\wrap_oal.dll
2011-09-23 19:17 . 2011-04-23 12:42 445016 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2011-09-13 00:26 . 2011-09-28 13:09 9049936 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6B319FE3-96BB-4772-9A68-34DAF9B184F2}\mpengine.dll
.
.
((((((((((((((((((((((((((((( SnapShot_2011-11-17_18.09.13 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-04-15 04:49 . 2011-11-24 13:30 59748 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-11-24 17:58 44380 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2011-03-25 21:39 . 2011-11-24 17:58 14138 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-839543870-2764649644-3222184407-1000_UserData.bin
- 2011-03-25 15:36 . 2011-11-17 17:26 98304 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-03-25 15:36 . 2011-11-24 17:56 98304 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-11-24 17:56 . 2011-11-24 17:56 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2011-03-25 19:09 . 2011-11-24 18:01 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-03-25 19:09 . 2011-11-17 17:29 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-03-25 19:09 . 2011-11-24 18:01 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2011-03-25 19:09 . 2011-11-17 17:29 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2011-11-17 17:26 . 2011-11-17 17:26 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-11-24 17:56 . 2011-11-24 17:56 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-11-17 17:26 . 2011-11-17 17:26 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-11-24 17:56 . 2011-11-24 17:56 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-03-26 17:51 . 2011-11-24 17:15 319532 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2009-07-14 02:36 . 2011-11-23 15:13 651648 c:\windows\system32\perfh009.dat
- 2009-07-14 02:36 . 2011-11-17 16:03 651648 c:\windows\system32\perfh009.dat
- 2009-07-14 02:36 . 2011-11-17 16:03 120580 c:\windows\system32\perfc009.dat
+ 2009-07-14 02:36 . 2011-11-23 15:13 120580 c:\windows\system32\perfc009.dat
+ 2009-07-14 05:12 . 2011-11-20 12:52 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2009-07-14 05:12 . 2011-06-28 10:18 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-07-14 04:54 . 2011-11-24 17:56 114688 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2011-11-17 17:26 114688 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 05:01 . 2011-11-24 17:55 390976 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2011-11-17 17:25 390976 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2011-11-09 17:02 . 2011-11-17 17:25 390976 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-839543870-2764649644-3222184407-1000-8192.dat
+ 2011-11-09 17:02 . 2011-11-21 21:07 390976 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-839543870-2764649644-3222184407-1000-8192.dat
- 2011-03-25 21:35 . 2011-11-17 17:25 3506144 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2011-03-25 21:35 . 2011-11-24 17:55 3506144 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2009-07-14 02:34 . 2011-11-17 14:10 10223616 c:\windows\system32\SMI\Store\Machine\schema.dat
+ 2009-07-14 02:34 . 2011-11-24 13:40 10223616 c:\windows\system32\SMI\Store\Machine\schema.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Tomáš\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Tomáš\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Tomáš\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Tomáš\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-11-11 288088]
"ITSecMng"="c:\program files (x86)\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2009-07-22 83336]
"ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-10-06 1294136]
"TWebCamera"="c:\program files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2010-02-24 2454840]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-03-08 336384]
"GLDStart"="d:\program files (x86)\GLDirect\gldirect.exe" [2004-07-20 241664]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"TOSHIBA Online Product Information"="c:\program files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe" [2010-03-03 4581280]
.
c:\users\Tomáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Tomáš\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-5-25 24176560]
hamachi.lnk - d:\program files\Hamachi\hamachi.exe [2011-8-21 624416]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2010-2-24 2721120]
Network Server.lnk - c:\program files (x86)\WIBUKEY\Server\WkSvMgr.exe [2011-5-22 3768320]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
TRDCReminder.lnk - c:\program files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe [2009-9-1 481184]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2008-08-15 284016]
R3 AODDriver4.0;AODDriver4.0;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011-04-24 1038088]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUStor.sys [x]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x]
R3 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe [2010-02-11 124368]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-03-08 365568]
S2 AMD Reservation Manager;AMD Reservation Manager;c:\program files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe [2010-06-17 194496]
S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2010-01-28 249200]
S2 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-10 46448]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [2011-01-12 810144]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [x]
S2 icas;iTALC Client;d:\program files\iTALC\ica.exe [2011-01-06 814094]
S2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\SysWOW64\nlssrv32.exe [2011-02-21 66560]
S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2010-03-17 258928]
S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [x]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [x]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 CnxtHdmiAudService;Conexant UAA HDMI Function Driver for High Definition Audio Service;c:\windows\system32\drivers\CHDMI64.sys [x]
S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [x]
S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x]
S3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512]
S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-05 137560]
S3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2010-02-23 835952]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Tomáš\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Tomáš\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Tomáš\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Tomáš\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2010-02-05 709976]
"TosReelTimeMonitor"="c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe" [BU]
"TosNC"="c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe" [BU]
"Toshiba TEMPRO"="c:\program files (x86)\Toshiba TEMPRO\TemproTray.exe" [2010-02-11 1050072]
"SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2009-11-19 307768]
"cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2010-03-10 520760]
"TPwrMain"="c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE" [BU]
"HSON"="c:\program files (x86)\TOSHIBA\TBS\HSON.exe" [BU]
"SmoothView"="c:\program files (x86)\Toshiba\SmoothView\SmoothView.exe" [BU]
"00TCrdMain"="c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe" [BU]
"Teco"="c:\program files (x86)\TOSHIBA\TECO\Teco.exe" [BU]
"TosWaitSrv"="c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe" [BU]
"TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376]
"SmartFaceVWatcher"="c:\program files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe" [BU]
"Toshiba Registration"="c:\program files\Toshiba\Registration\ToshibaReminder.exe" [2010-04-19 136136]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-01-12 2918656]
.
------- Supplementary Scan -------
.
uLocal Page = %SystemRoot%\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Append Link Target to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xportovať do programu Microsoft Excel - d:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: Sothink SWF Catcher - c:\program files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
IE: {{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - d:\program files\ICQ7.4\ICQ.exe
TCP: DhcpNameServer = 192.168.10.1
TCP: Interfaces\{D790733C-180E-4CE7-B707-22C62435B11A}: NameServer = 192.168.1.1
FF - ProfilePath - c:\users\Tomáš\AppData\Roaming\Mozilla\Firefox\Profiles\oeb9zod4.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.sk/
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
Completion time: 2011-11-24 19:20:08
ComboFix-quarantined-files.txt 2011-11-24 18:20
ComboFix2.txt 2011-11-23 19:46
ComboFix3.txt 2011-11-17 18:29
ComboFix4.txt 2011-11-09 20:02
.
Pre-Run: 200 185 647 104 bytes free
Post-Run: 200 127 430 656 bytes free
.
- - End Of File - - EF5F6D6A0AC5C1AF889791B4CC48D8F2

Re: facebook vírus

Napsal: 24 lis 2011 19:28
od vyosek
Fajn, jak se chova PC :???:

Re: facebook vírus

Napsal: 24 lis 2011 19:33
od tomi
No zatial ide čisto ... žiadny náznak chovania sa ako vtedy ... žeby mi to zamrzlo a robilo si to čo chcelo :) len som ešte nezapínal ICQ ... tam to robilo v poslednej dobe tie blbosti

Re: facebook vírus

Napsal: 24 lis 2011 20:33
od vyosek
:arrow: Odinstalujte Combofix
  • Prejmenujte ComboFix na Uninstall
  • Spustte jej
  • Tohle smaze Combofix a jeho slozky
:arrow: T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner (viz muj podpis)
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: Napiste co PC