Stránka 1 z 3

pravděpodobně neznámý TSR.BOOT virus

Napsal: 28 kvě 2010 17:16
od koprkuba
Ahoj, NOD 32 mi dnes vyhodil virus TSR.BOOT tenhle virus mam nahraný na všech oddílech disku v Boot Sectoru. Nemám žádné zkušenosti s ničením havěti, tak mi prosím řekněte co sem mam postnout :-)
Díky moc

Edit:
P.S. dokonce je i na Boot Sektorech mechanik, vč. virtuální

Re: pravděpodobně neznámý TSR.BOOT virus

Napsal: 28 kvě 2010 17:24
od riffman
zdravim

stahnete a ulozte nejlepe na plochu ComboFix

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano:

Obrázek

dale muze dojit k varovani ohledne rezidentniho stitu vaseho antiviru a upozorneni na nenainstalovanou konzoli pro zotaveni; tu zatim neinstalujte.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, deaktivujte jeho rezidentni stit, protoze dochazi pri skenu a vymazu pripadneho malware k nezadoucim kolizim Combofixu s rezidentem antispyware


po restartu aplikace vytvori log, ulozeny na C:/Combofix.txt (pri opakovanem pouziti jsou logy oznaceny Combofix2.txt atd.), jeho obsah vlozte sem

Re: pravděpodobně neznámý TSR.BOOT virus

Napsal: 28 kvě 2010 17:33
od koprkuba
Zapomněl jsem ještě uvést, že mám Win7 x64. Napadlo mne to až když mi ComboFix zahlásil, že pracuje pouze na 32-bit systémech. Mohu použít nějaký jiný program?

Re: pravděpodobně neznámý TSR.BOOT virus

Napsal: 28 kvě 2010 17:37
od riffman
stahni si OTL

po stazeni klikni na tlacitko Prohledat, nech to makat, az to dobehne, vysype to log, jeho obsah sem :)

Re: pravděpodobně neznámý TSR.BOOT virus

Napsal: 28 kvě 2010 17:43
od koprkuba
part: 01 / 03

OTL logfile created on: 28.5.2010 18:37:39 - Run 1
OTL by OldTimer - Version 3.2.5.0 Folder = D:\Download
64bit- An unknown product (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

4,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 48,00% Memory free
8,00 Gb Paging File | 6,00 Gb Available in Paging File | 74,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 165,92 Gb Total Space | 121,31 Gb Free Space | 73,12% Space Free | Partition Type: NTFS
Drive D: | 299,75 Gb Total Space | 143,34 Gb Free Space | 47,82% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 1,92 Gb Total Space | 1,92 Gb Free Space | 100,00% Space Free | Partition Type: FAT32
I: Drive not present or media not loaded

Computer Name: KOPR-PC
Current User Name: Kopr
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010.05.28 18:37:22 | 000,571,904 | ---- | M] (OldTimer Tools) -- D:\Download\OTL.exe
PRC - [2010.05.13 22:07:57 | 000,395,048 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe
PRC - [2010.05.08 18:25:34 | 001,238,352 | ---- | M] (Valve Corporation) -- D:\Games\Steam\Steam.exe
PRC - [2010.05.03 00:25:21 | 000,075,064 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2010.05.01 01:05:02 | 000,202,256 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
PRC - [2010.05.01 00:32:47 | 003,581,680 | ---- | M] (Stardock) -- C:\Program Files (x86)\Stardock\ObjectDock\ObjectDock.exe
PRC - [2010.04.30 22:34:41 | 000,136,176 | ---- | M] (Google Inc.) -- C:\Users\Kopr\AppData\Local\Google\Update\1.2.183.23\GoogleCrashHandler.exe
PRC - [2010.04.30 20:42:06 | 002,480,048 | ---- | M] (Acronis) -- C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
PRC - [2010.04.26 19:13:25 | 000,531,440 | ---- | M] (Google Inc.) -- C:\Users\Kopr\AppData\Local\Google\Chrome\Application\chrome.exe
PRC - [2010.04.21 16:17:38 | 005,559,248 | ---- | M] (QIP) -- C:\Program Files\QIP 2010\qip.exe
PRC - [2010.04.16 08:33:40 | 000,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010.04.07 21:07:24 | 000,810,120 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
PRC - [2010.04.03 16:59:00 | 000,240,232 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2009.11.26 17:45:54 | 000,361,976 | ---- | M] (Acronis) -- C:\Program Files (x86)\Common Files\Acronis\Plán2\schedhlp.exe
PRC - [2009.11.26 17:44:46 | 005,129,128 | ---- | M] (Acronis) -- C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
PRC - [2009.10.09 19:12:16 | 000,741,376 | ---- | M] () -- C:\Program Files (x86)\Marvell\raid\tray\MarvellTray.exe
PRC - [2009.10.05 20:01:30 | 000,151,552 | ---- | M] () -- C:\Program Files (x86)\Marvell\raid\svc\mvraidsvc.exe
PRC - [2009.09.25 16:59:18 | 000,106,496 | ---- | M] (NEC Electronics Corporation) -- C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
PRC - [2009.08.04 17:29:54 | 000,219,360 | ---- | M] (DeviceVM, Inc.) -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe
PRC - [2009.08.04 17:29:52 | 000,346,320 | ---- | M] (DeviceVM, Inc.) -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe
PRC - [2009.04.09 02:38:52 | 000,024,635 | ---- | M] (Apache Software Foundation) -- C:\Program Files (x86)\Marvell\raid\Apache2\bin\httpd.exe
PRC - [2008.11.14 14:35:28 | 001,453,992 | R--- | M] (Take-Two Interactive Software, Inc.) -- D:\Games\GTA IV\Rockstar Games Social Club\1_0_0_0\RGSC.exe
PRC - [2007.09.25 10:10:50 | 002,007,088 | ---- | M] (FlashGet.com) -- C:\Program Files (x86)\FlashGet\flashget.exe


========== Modules (SafeList) ==========

MOD - [2010.05.28 18:37:22 | 000,571,904 | ---- | M] (OldTimer Tools) -- D:\Download\OTL.exe
MOD - [2009.07.14 03:15:07 | 000,486,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\comdlg32.dll
MOD - [2009.07.14 03:14:10 | 000,095,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msscript.ocx
MOD - [2009.07.14 03:03:50 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2010.05.18 01:47:43 | 001,255,736 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\SysNative\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV:64bit: - [2010.04.07 21:10:42 | 000,042,336 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe -- (EhttpSrv)
SRV:64bit: - [2010.04.07 21:07:24 | 000,810,120 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe -- (ekrn)
SRV:64bit: - [2009.09.26 04:28:30 | 004,924,336 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV:64bit: - [2009.07.14 03:41:59 | 000,229,888 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wwansvc.dll -- (WwanSvc)
SRV:64bit: - [2009.07.14 03:41:56 | 000,202,240 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wbiosrvc.dll -- (WbioSrvc)
SRV:64bit: - [2009.07.14 03:41:56 | 000,195,072 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\umrdp.dll -- (UmRdpService)
SRV:64bit: - [2009.07.14 03:41:56 | 000,163,840 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\umpo.dll -- (Power)
SRV:64bit: - [2009.07.14 03:41:55 | 000,044,544 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\themeservice.dll -- (Themes)
SRV:64bit: - [2009.07.14 03:41:54 | 000,065,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\sppuinotify.dll -- (sppuinotify)
SRV:64bit: - [2009.07.14 03:41:54 | 000,029,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\sensrsvc.dll -- (SensrSvc)
SRV:64bit: - [2009.07.14 03:41:54 | 000,017,920 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\StorSvc.dll -- (StorSvc)
SRV:64bit: - [2009.07.14 03:41:53 | 001,361,920 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\PeerDistSvc.dll -- (PeerDistSvc)
SRV:64bit: - [2009.07.14 03:41:53 | 000,327,168 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\pnrpsvc.dll -- (PNRPsvc)
SRV:64bit: - [2009.07.14 03:41:53 | 000,327,168 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\pnrpsvc.dll -- (p2pimsvc)
SRV:64bit: - [2009.07.14 03:41:53 | 000,187,904 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\provsvc.dll -- (HomeGroupProvider)
SRV:64bit: - [2009.07.14 03:41:53 | 000,067,072 | ---- | M] (Microsoft Corporation) [Unknown | Running] -- C:\Windows\SysNative\RpcEpMap.dll -- (RpcEptMapper)
SRV:64bit: - [2009.07.14 03:41:53 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\pnrpauto.dll -- (PNRPAutoReg)
SRV:64bit: - [2009.07.14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009.07.14 03:41:18 | 000,231,936 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ListSvc.dll -- (HomeGroupListener)
SRV:64bit: - [2009.07.14 03:40:54 | 001,127,936 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\FntCache.dll -- (FontCache)
SRV:64bit: - [2009.07.14 03:40:28 | 000,314,368 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dhcpcore.dll -- (Dhcp)
SRV:64bit: - [2009.07.14 03:40:28 | 000,291,328 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\defragsvc.dll -- (defragsvc)
SRV:64bit: - [2009.07.14 03:40:24 | 000,689,152 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\cscsvc.dll -- (CscService)
SRV:64bit: - [2009.07.14 03:40:13 | 000,083,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\bthserv.dll -- (bthserv)
SRV:64bit: - [2009.07.14 03:40:10 | 000,100,864 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\SysNative\bdesvc.dll -- (BDESVC)
SRV:64bit: - [2009.07.14 03:40:05 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AxInstSv.dll -- (AxInstSV)
SRV:64bit: - [2009.07.14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV:64bit: - [2009.07.14 03:40:01 | 000,032,256 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appidsvc.dll -- (AppIDSvc)
SRV:64bit: - [2009.07.14 03:39:51 | 001,503,744 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wbengine.exe -- (wbengine)
SRV:64bit: - [2009.07.14 03:39:28 | 003,524,608 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\sppsvc.exe -- (sppsvc)
SRV:64bit: - [2009.07.14 03:39:11 | 000,689,152 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\FXSSVC.exe -- (Fax)
SRV - [2010.05.13 22:07:57 | 000,395,048 | ---- | M] (Valve Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2010.05.03 00:25:21 | 000,075,064 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2010.04.30 20:42:06 | 002,480,048 | ---- | M] (Acronis) [Auto | Running] -- C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe -- (afcdpsrv)
SRV - [2010.04.16 08:33:40 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2010.04.03 16:59:00 | 000,240,232 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2010.03.22 09:17:24 | 000,276,584 | ---- | M] (NVIDIA) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe -- (nTuneService)
SRV - [2010.02.19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009.12.23 23:34:20 | 000,370,688 | ---- | M] (StarWind Software) [Auto | Stopped] -- C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE)
SRV - [2009.11.26 17:47:06 | 000,894,480 | ---- | M] (Acronis) [Auto | Running] -- C:\Program Files (x86)\Common Files\Acronis\Plán2\schedul2.exe -- (AcrSch2Svc)
SRV - [2009.11.06 13:24:54 | 000,282,728 | ---- | M] (NVIDIA) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\System Update\UpdateCenterService.exe -- (UpdateCenterService)
SRV - [2009.10.29 10:22:50 | 030,603,640 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
SRV - [2009.10.05 20:01:30 | 000,151,552 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Marvell\raid\svc\mvraidsvc.exe -- (Marvell RAID)
SRV - [2009.08.04 17:29:54 | 000,219,360 | ---- | M] (DeviceVM, Inc.) [Auto | Running] -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe -- (BCUService)
SRV - [2009.07.14 05:20:14 | 000,000,000 | ---D | M] [On_Demand | Stopped] -- C:\Windows\Vss -- (VSS)
SRV - [2009.07.14 05:20:14 | 000,000,000 | ---D | M] [Unknown | Stopped] -- C:\Windows\SysWOW64\Msdtc -- (MSDTC) Služba DTC (Distributed Transaction Coordinator)
SRV - [2009.07.14 03:16:12 | 000,165,376 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\provsvc.dll -- (HomeGroupProvider)
SRV - [2009.07.14 03:15:11 | 000,253,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\dhcpcore.dll -- (Dhcp)
SRV - [2009.07.13 22:30:11 | 000,061,056 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysWOW64\wbem\vds.mof -- (vds)
SRV - [2009.06.10 22:39:58 | 000,089,920 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_64)
SRV - [2009.04.09 02:38:52 | 000,024,635 | ---- | M] (Apache Software Foundation) [Auto | Running] -- C:\Program Files (x86)\Marvell\raid\Apache2\bin\httpd.exe -- (MRUWebService)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2010.04.30 22:26:30 | 000,834,544 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2010.04.30 20:42:07 | 000,251,488 | ---- | M] (Acronis) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\afcdp.sys -- (afcdp)
DRV:64bit: - [2010.04.30 20:42:05 | 001,477,728 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\tdrpm258.sys -- (tdrpman258) Acronis Try&Decide and Restore Points filter (build 258)
DRV:64bit: - [2010.04.30 20:42:04 | 000,943,712 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\timntr.sys -- (timounter)
DRV:64bit: - [2010.04.30 20:42:00 | 000,257,120 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\snapman.sys -- (snapman)
DRV:64bit: - [2010.04.07 21:08:30 | 000,050,600 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\epfwwfp.sys -- (epfwwfp)
DRV:64bit: - [2010.04.07 21:08:28 | 000,033,608 | ---- | M] (ESET) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\epfwndis.sys -- (Epfwndis)
DRV:64bit: - [2010.04.07 21:08:26 | 000,169,592 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\epfw.sys -- (epfw)
DRV:64bit: - [2010.04.07 21:07:10 | 000,139,704 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ehdrv.sys -- (ehdrv)
DRV:64bit: - [2010.04.07 21:03:52 | 000,163,888 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\eamonm.sys -- (eamonm)
DRV:64bit: - [2009.12.11 12:29:27 | 000,153,160 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ksecpkg.sys -- (KSecPkg)
DRV:64bit: - [2009.10.10 00:55:56 | 000,022,568 | ---- | M] (Marvell Semiconductor Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mv91cons.sys -- (mv91cons)
DRV:64bit: - [2009.09.26 08:20:38 | 000,223,448 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\fvevol.sys -- (fvevol)
DRV:64bit: - [2009.09.25 16:58:32 | 000,178,688 | ---- | M] (NEC Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV:64bit: - [2009.09.25 16:58:24 | 000,073,728 | ---- | M] (NEC Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub)
DRV:64bit: - [2009.09.15 14:59:30 | 000,042,088 | ---- | M] (NVIDIA Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvoclk64.sys -- (nvoclk64)
DRV:64bit: - [2009.08.20 18:05:06 | 000,239,616 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009.08.13 10:10:42 | 000,112,240 | ---- | M] (JMicron Technology Corp.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\jraid.sys -- (JRAID)
DRV:64bit: - [2009.07.14 03:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009.07.14 03:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:48:04 | 000,014,416 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\hwpolicy.sys -- (hwpolicy)
DRV:64bit: - [2009.07.14 03:47:49 | 000,055,376 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fsdepends.sys -- (FsDepends)
DRV:64bit: - [2009.07.14 03:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009.07.14 03:45:56 | 000,022,096 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wimmount.sys -- (WIMMount)
DRV:64bit: - [2009.07.14 03:45:55 | 000,217,680 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vhdmp.sys -- (vhdmp)
DRV:64bit: - [2009.07.14 03:45:55 | 000,200,272 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmbus.sys -- (vmbus)
DRV:64bit: - [2009.07.14 03:45:55 | 000,046,672 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\vmstorfl.sys -- (storflt)
DRV:64bit: - [2009.07.14 03:45:55 | 000,036,432 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\vdrvroot.sys -- (vdrvroot)
DRV:64bit: - [2009.07.14 03:45:55 | 000,034,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\storvsc.sys -- (storvsc)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.07.14 03:45:46 | 000,214,096 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\rdyboost.sys -- (rdyboost)
DRV:64bit: - [2009.07.14 03:45:45 | 000,050,768 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pcw.sys -- (pcw)
DRV:64bit: - [2009.07.14 03:43:14 | 000,460,504 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\cng.sys -- (CNG)
DRV:64bit: - [2009.07.14 02:17:46 | 000,024,064 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rdpbus.sys -- (rdpbus)
DRV:64bit: - [2009.07.14 02:16:35 | 000,008,192 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\RDPREFMP.sys -- (RDPREFMP)
DRV:64bit: - [2009.07.14 02:10:24 | 000,060,416 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\agilevpn.sys -- (RasAgileVpn) WAN Miniport (IKEv2)
DRV:64bit: - [2009.07.14 02:09:26 | 000,012,800 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\wfplwf.sys -- (WfpLwf)
DRV:64bit: - [2009.07.14 02:08:13 | 000,035,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ndiscap.sys -- (NdisCap)
DRV:64bit: - [2009.07.14 02:07:21 | 000,024,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vwifibus.sys -- (vwifibus)
DRV:64bit: - [2009.07.14 02:07:13 | 000,227,840 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\1394ohci.sys -- (1394ohci)
DRV:64bit: - [2009.07.14 02:07:00 | 000,350,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HdAudio.sys -- (HdAudAddService)
DRV:64bit: - [2009.07.14 02:06:52 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\umpass.sys -- (UmPass)
DRV:64bit: - [2009.07.14 02:06:24 | 000,008,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mshidkmdf.sys -- (mshidkmdf)
DRV:64bit: - [2009.07.14 02:05:37 | 000,112,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WUDFPf.sys -- (WudfPf)
DRV:64bit: - [2009.07.14 02:02:08 | 000,015,360 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\MTConfig.sys -- (MTConfig)
DRV:64bit: - [2009.07.14 02:00:34 | 000,038,912 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CompositeBus.sys -- (CompositeBus)
DRV:64bit: - [2009.07.14 02:00:13 | 000,006,656 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\beep.sys -- (Beep)
DRV:64bit: - [2009.07.14 01:52:39 | 000,061,440 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\appid.sys -- (AppID)
DRV:64bit: - [2009.07.14 01:50:17 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | Unknown | Stopped] -- C:\Windows\SysNative\drivers\scfilter.sys -- (scfilter)
DRV:64bit: - [2009.07.14 01:42:58 | 000,006,656 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vms3cap.sys -- (s3cap)
DRV:64bit: - [2009.07.14 01:42:44 | 000,021,760 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VMBusHID.sys -- (VMBusHID)
DRV:64bit: - [2009.07.14 01:37:18 | 000,040,448 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\discache.sys -- (discache)
DRV:64bit: - [2009.07.14 01:31:06 | 000,026,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidbatt.sys -- (HidBatt)
DRV:64bit: - [2009.07.14 01:31:03 | 000,017,664 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CmBatt.sys -- (CmBatt)
DRV:64bit: - [2009.07.14 01:27:17 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpipmi.sys -- (AcpiPmi)
DRV:64bit: - [2009.07.14 01:24:27 | 000,514,048 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\csc.sys -- (CSC)
DRV:64bit: - [2009.07.14 01:19:25 | 000,060,928 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdppm.sys -- (AmdPPM)
DRV:64bit: - [2009.07.09 03:00:00 | 000,055,280 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV - [2010.05.28 15:57:20 | 000,030,528 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\GVTDrv64.sys -- (GVTDrv64)
DRV - [2010.05.28 15:57:05 | 000,025,640 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\gdrv.sys -- (gdrv)
DRV - [2010.05.08 18:37:05 | 000,025,640 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\etdrv.sys -- (etdrv)
DRV - [2010.04.30 19:56:42 | 000,000,000 | ---D | M] [Kernel | System | Running] -- C:\Windows\CSC -- (CSC)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2009.07.14 03:16:02 | 000,014,336 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\Windows\SysWOW64\netbios.dll -- (NetBIOS)
DRV - [2009.06.10 23:28:14 | 000,001,088 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\wbem\mpsdrv.mof -- (mpsdrv)
DRV - [2009.06.10 23:15:18 | 000,003,066 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysWOW64\wbem\tcpip.mof -- (Tcpip)
DRV - [2009.02.23 00:21:54 | 000,014,904 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Program Files (x86)\GIGABYTE\ET6\amd64\AODDriver.sys -- (AODDriver)
DRV - [2007.02.07 20:27:46 | 000,014,104 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | Boot | Running] -- C:\Windows\SysWOW64\speedfan.sys -- (speedfan)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = CF 98 4C FB 52 FB CA 01 [binary data]
IE - HKCU\..\URLSearchHook: {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll (DeviceVM, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com"
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.3
FF - prefs.js..extensions.enabledItems: {01A8CA0A-4C96-465b-A49B-65C46FAD54F9}:6.0
FF - prefs.js..extensions.enabledItems: firebug@software.joehewitt.com:1.5.4
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.8
FF - prefs.js..extensions.enabledItems: firecookie@janodvarko.cz:1.0.2

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010.05.01 01:05:16 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}: C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2010.05.28 09:23:06 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010.05.18 10:25:20 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010.05.28 09:23:08 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2010.04.30 22:41:56 | 000,000,000 | ---D | M]

[2010.04.30 22:34:20 | 000,000,000 | ---D | M] -- C:\Users\Kopr\AppData\Roaming\Mozilla\Extensions
[2010.05.23 13:44:35 | 000,000,000 | ---D | M] -- C:\Users\Kopr\AppData\Roaming\Mozilla\Firefox\Profiles\zsjjuv80.default\extensions
[2010.05.04 21:03:50 | 000,000,000 | ---D | M] (Web Developer) -- C:\Users\Kopr\AppData\Roaming\Mozilla\Firefox\Profiles\zsjjuv80.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2010.05.11 16:17:37 | 000,000,000 | ---D | M] -- C:\Users\Kopr\AppData\Roaming\Mozilla\Firefox\Profiles\zsjjuv80.default\extensions\firebug@software.joehewitt.com
[2010.05.04 21:03:50 | 000,000,000 | ---D | M] -- C:\Users\Kopr\AppData\Roaming\Mozilla\Firefox\Profiles\zsjjuv80.default\extensions\firecookie@janodvarko.cz
[2010.05.01 01:03:56 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2010.05.01 00:11:46 | 000,000,000 | ---D | M] (Skype extension for Firefox) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010.05.01 01:03:56 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010.03.27 18:06:04 | 000,067,032 | ---- | M] (Adobe Systems, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npContribute.dll
[2010.05.01 01:03:52 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
[2010.04.01 18:51:34 | 000,000,638 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2010.04.01 18:51:34 | 000,001,687 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\mall-cz.xml
[2010.04.01 18:51:34 | 000,001,367 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\seznam-cz.xml
[2010.04.01 18:51:34 | 000,000,654 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2010.04.01 18:51:34 | 000,001,179 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\wikipedia-cz.xml

O1 HOSTS File: ([2010.05.28 15:38:58 | 000,001,482 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 serial.alcohol-soft.com
O1 - Hosts: 127.0.0.1 http://www.alcohol-soft.com
O1 - Hosts: 127.0.0.1 images.alcohol-soft.com
O1 - Hosts: 127.0.0.1 trial.alcohol-soft.com
O1 - Hosts: 127.0.0.1 alcohol-soft.com
O2:64bit: - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O2 - BHO: (FGCatchUrl) - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files (x86)\FlashGet\jccatch.dll (http://www.flashget.com)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (FlashGetBHO) - {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - C:\Users\Kopr\AppData\Roaming\FlashGetBHO\FlashGetBHO3.dll (Trend Media Group)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (FlashGet GetFlash Class) - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files (x86)\FlashGet\getflash.dll (http://www.flashget.com)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Služba Acronis Scheduler2] C:\Program Files (x86)\Common Files\Acronis\Plán2\schedhlp.exe (Acronis)
O4:64bit: - HKLM..\Run: [TNOD UP] C:\Program Files (x86)\TNod User & Password Finder\TNODUP.exe (Tukero[X]Team)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [BCSSync] C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [BCU] C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)
O4 - HKLM..\Run: [EasyTuneVI] C:\Program Files (x86)\GIGABYTE\ET6\ETcall.exe ()
O4 - HKLM..\Run: [Flashget] C:\Program Files (x86)\FlashGet\FlashGet.exe (FlashGet.com)
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe ()
O4 - HKLM..\Run: [MRUTray] C:\Program Files (x86)\Marvell\raid\tray\MarvellTray.exe ()
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (NEC Electronics Corporation)
O4 - HKLM..\Run: [ScanRegistry] File not found
O4 - HKLM..\Run: [StillImageMonitor] File not found
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [Infium] C:\Program Files\QIP 2010\qip.exe (QIP)
O4 - HKCU..\Run: [RGSC] D:\Games\GTA IV\Rockstar Games Social Club\RGSCLauncher.exe (Take-Two Interactive Software, Inc.)
O4 - HKCU..\Run: [Steam] D:\Games\Steam\Steam.exe (Valve Corporation)
O4 - Startup: C:\Users\Kopr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Stardock ObjectDock.lnk = C:\Program Files (x86)\Stardock\ObjectDock\ObjectDock.exe (Stardock)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: &Download All with FlashGet - C:\Program Files (x86)\FlashGet\JC_ALL.HTM ()
O8:64bit: - Extra context menu item: &Download with FlashGet - C:\Program Files (x86)\FlashGet\JC_LINK.HTM ()
O8:64bit: - Extra context menu item: Download all by FlashGet3 - C:\Users\Kopr\AppData\Roaming\FlashGetBHO\GetAllUrl.htm ()
O8:64bit: - Extra context menu item: Download by FlashGet3 - C:\Users\Kopr\AppData\Roaming\FlashGetBHO\GetUrl.htm ()
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8:64bit: - Extra context menu item: Se&nd to OneNote - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files (x86)\FlashGet\JC_ALL.HTM ()
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files (x86)\FlashGet\JC_LINK.HTM ()
O8 - Extra context menu item: Download all by FlashGet3 - C:\Users\Kopr\AppData\Roaming\FlashGetBHO\GetAllUrl.htm ()
O8 - Extra context menu item: Download by FlashGet3 - C:\Users\Kopr\AppData\Roaming\FlashGetBHO\GetUrl.htm ()
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files (x86)\FlashGet\flashget.exe (FlashGet.com)
O9 - Extra 'Tools' menuitem : FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files (x86)\FlashGet\flashget.exe (FlashGet.com)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: kuaiche.com ([software] http in Trusted sites)
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Trusted sites)
O15 - HKCU\..Trusted Ranges: Range1 ([https] in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 8.8.8.8 8.8.4.4
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O28:64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{c951c9a9-5496-11df-883c-6cf049030424}\Shell - "" = AutoRun
O33 - MountPoints2\{c951c9a9-5496-11df-883c-6cf049030424}\Shell\AutoRun\command - "" = F:\WD SmartWare.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (auto_reactivate \\?\Volume{4cf8e547-54a1-11df-9e8e-806e6f6e6963}\bootwiz\asrm.bin) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010.05.28 18:31:26 | 000,000,000 | ---D | C] -- C:\32788R22FWJFW
[2010.05.28 18:04:51 | 000,455,680 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\deployJava1.dll
[2010.05.28 18:04:51 | 000,182,784 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\javaws.exe
[2010.05.28 18:04:51 | 000,165,888 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\javaw.exe
[2010.05.28 18:04:51 | 000,165,888 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\java.exe
[2010.05.28 18:03:22 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2010.05.28 09:36:55 | 000,000,000 | ---D | C] -- C:\ProgramData\ALM
[2010.05.28 09:28:51 | 000,000,000 | ---D | C] -- C:\Users\Kopr\Adobe Flash Builder 4
[2010.05.28 09:15:08 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2010.05.23 21:53:35 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Roaming\PSpad
[2010.05.23 21:53:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PSPad editor
[2010.05.23 13:47:56 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Roaming\FileZilla
[2010.05.23 13:47:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FileZilla FTP Client
[2010.05.22 18:58:14 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2010.05.21 23:26:26 | 000,000,000 | ---D | C] -- C:\Users\Kopr\Documents\My Albums
[2010.05.21 23:25:12 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Roaming\JAlbum
[2010.05.21 23:25:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Jalbum
[2010.05.21 11:07:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Synchronization Services
[2010.05.21 11:07:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2010.05.21 11:06:49 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2010.05.21 11:06:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
[2010.05.21 11:06:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Sync Framework
[2010.05.21 11:06:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
[2010.05.21 11:05:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 8
[2010.05.21 11:04:56 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2010.05.21 11:04:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Analysis Services
[2010.05.21 11:04:14 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Local\Microsoft Help
[2010.05.21 11:04:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
[2010.05.21 11:04:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2010.05.21 11:03:37 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2010.05.18 10:24:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2010.05.18 02:29:28 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2010.05.18 02:29:27 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2010.05.18 02:29:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2010.05.18 01:47:45 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Wat
[2010.05.18 01:47:45 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Wat
[2010.05.18 00:17:44 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Roaming\PACE Anti-Piracy
[2010.05.18 00:17:44 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Local\PACE Anti-Piracy
[2010.05.18 00:17:44 | 000,000,000 | ---D | C] -- C:\ProgramData\PACE Anti-Piracy
[2010.05.18 00:17:43 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Roaming\NVIDIA
[2010.05.18 00:17:41 | 000,000,000 | ---D | C] -- C:\Users\Kopr\Documents\Adobe
[2010.05.17 12:40:35 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Local\MediaMonkey
[2010.05.17 12:40:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MediaMonkey
[2010.05.17 11:09:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mp3tag
[2010.05.16 14:31:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\directx
[2010.05.16 14:30:27 | 000,000,000 | ---D | C] -- C:\VideoCAM Express V2
[2010.05.16 14:27:31 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Local\PackageAware
[2010.05.15 13:55:29 | 000,000,000 | ---D | C] -- C:\Users\Kopr\.netbeans-derby
[2010.05.10 23:02:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Core Services
[2010.05.10 03:00:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0

Re: pravděpodobně neznámý TSR.BOOT virus

Napsal: 28 kvě 2010 17:45
od koprkuba
Part: 02/03

[2010.05.08 20:25:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WinSCP
[2010.05.08 20:18:59 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Roaming\PDF Writer
[2010.05.08 20:18:59 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Local\PDF Writer
[2010.05.08 20:18:59 | 000,000,000 | ---D | C] -- C:\ProgramData\PDF Writer
[2010.05.08 20:17:53 | 000,227,840 | ---- | C] (Bullzip) -- C:\Windows\SysWow64\bzFlRdr.dll
[2010.05.08 20:17:53 | 000,135,168 | ---- | C] (Bullzip) -- C:\Windows\SysWow64\bzpdfc.dll
[2010.05.08 20:17:53 | 000,103,424 | ---- | C] (Bullzip) -- C:\Windows\SysWow64\bzDCT.dll
[2010.05.08 20:17:53 | 000,008,192 | ---- | C] (bioPDF) -- C:\Windows\SysWow64\BioPdf.PdfWriter.Lib.dll
[2010.05.08 20:17:53 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Bullzip
[2010.05.08 20:17:50 | 000,212,480 | ---- | C] (Bullzip) -- C:\Windows\SysNative\bzpdf.dll
[2010.05.08 20:17:47 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\comdlg32.OCX
[2010.05.08 20:17:46 | 000,000,000 | ---D | C] -- C:\Program Files\Bullzip
[2010.05.08 18:37:08 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Roaming\Sparx Systems
[2010.05.08 18:36:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sparx Systems
[2010.05.08 18:36:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2010.05.05 18:34:09 | 000,000,000 | ---D | C] -- C:\a
[2010.05.04 23:28:29 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Roaming\Subversion
[2010.05.04 23:24:07 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Local\NVIDIA Corporation
[2010.05.04 22:56:15 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Roaming\dvdcss
[2010.05.04 22:55:58 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Roaming\vlc
[2010.05.04 22:48:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CollabNet Subversion Client
[2010.05.04 22:29:54 | 000,000,000 | ---D | C] -- C:\Users\Kopr\.netbeans
[2010.05.04 22:29:52 | 000,000,000 | ---D | C] -- C:\Users\Kopr\.netbeans-registration
[2010.05.04 22:29:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apache Software Foundation
[2010.05.04 22:29:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\sges-v3
[2010.05.04 22:23:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NetBeans 6.8
[2010.05.04 22:12:40 | 000,000,000 | ---D | C] -- C:\Users\Kopr\.nbi
[2010.05.04 15:59:44 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Roaming\Adobe Mini Bridge CS5
[2010.05.04 15:59:43 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2010.05.04 15:58:35 | 000,000,000 | ---D | C] -- C:\ProgramData\regid.1986-12.com.adobe
[2010.05.04 15:31:15 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Adobe
[2010.05.04 15:25:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe Media Player
[2010.05.04 15:25:35 | 000,055,280 | ---- | C] (Sonic Solutions) -- C:\Windows\SysNative\drivers\PxHlpa64.sys
[2010.05.04 15:25:35 | 000,010,224 | ---- | C] (Sonic Solutions) -- C:\Windows\SysNative\drivers\cdralw2k.sys
[2010.05.04 15:25:35 | 000,010,224 | ---- | C] (Sonic Solutions) -- C:\Windows\SysNative\drivers\cdr4_xp.sys
[2010.05.04 15:25:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Sonic Shared
[2010.05.04 15:25:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PX Storage Engine
[2010.05.04 15:25:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\My Company Name
[2010.05.04 15:23:48 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2010.05.04 00:24:52 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Roaming\Apple Computer
[2010.05.04 00:24:52 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Local\Apple Computer
[2010.05.04 00:24:35 | 000,126,312 | ---- | C] (GEAR Software Inc.) -- C:\Windows\SysNative\GEARAspi64.dll
[2010.05.04 00:24:35 | 000,107,368 | ---- | C] (GEAR Software Inc.) -- C:\Windows\SysWow64\GEARAspi.dll
[2010.05.04 00:24:35 | 000,034,152 | ---- | C] (GEAR Software Inc.) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2010.05.04 00:24:35 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\DRVSTORE
[2010.05.04 00:24:14 | 000,000,000 | ---D | C] -- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2010.05.04 00:23:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2010.05.04 00:23:38 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Local\Apple
[2010.05.04 00:23:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update
[2010.05.04 00:23:26 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2010.05.04 00:23:17 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2010.05.04 00:23:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bonjour
[2010.05.04 00:23:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2010.05.04 00:23:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Apple
[2010.05.03 00:27:33 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Local\PunkBuster
[2010.05.03 00:27:31 | 000,000,000 | ---D | C] -- C:\Users\Kopr\Documents\BFBC2
[2010.05.03 00:25:13 | 000,517,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_5.dll
[2010.05.03 00:25:13 | 000,515,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_5.dll
[2010.05.03 00:25:12 | 005,554,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dcsx_42.dll
[2010.05.03 00:25:12 | 005,501,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dcsx_42.dll
[2010.05.03 00:25:12 | 002,582,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_42.dll
[2010.05.03 00:25:12 | 001,974,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_42.dll
[2010.05.03 00:25:12 | 000,523,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_42.dll
[2010.05.03 00:25:12 | 000,285,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx11_42.dll
[2010.05.03 00:25:12 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_5.dll
[2010.05.03 00:25:12 | 000,235,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx11_42.dll
[2010.05.03 00:25:12 | 000,176,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_5.dll
[2010.05.03 00:25:11 | 005,425,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_41.dll
[2010.05.03 00:25:11 | 004,178,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_41.dll
[2010.05.03 00:25:11 | 002,475,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_42.dll
[2010.05.03 00:25:11 | 002,430,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_41.dll
[2010.05.03 00:25:11 | 001,846,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_41.dll
[2010.05.03 00:25:11 | 000,521,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_4.dll
[2010.05.03 00:25:11 | 000,520,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_41.dll
[2010.05.03 00:25:11 | 000,517,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_4.dll
[2010.05.03 00:25:11 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_41.dll
[2010.05.03 00:25:11 | 000,073,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_3.dll
[2010.05.03 00:25:11 | 000,069,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_3.dll
[2010.05.03 00:25:10 | 002,605,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_40.dll
[2010.05.03 00:25:10 | 002,036,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_40.dll
[2010.05.03 00:25:10 | 000,519,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_40.dll
[2010.05.03 00:25:10 | 000,452,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_40.dll
[2010.05.03 00:25:10 | 000,235,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_4.dll
[2010.05.03 00:25:10 | 000,174,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_4.dll
[2010.05.03 00:25:10 | 000,024,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_6.dll
[2010.05.03 00:25:10 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_6.dll
[2010.05.03 00:25:09 | 005,631,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_40.dll
[2010.05.03 00:25:09 | 004,379,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_40.dll
[2010.05.03 00:25:08 | 000,513,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_2.dll
[2010.05.03 00:25:08 | 000,509,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_2.dll
[2010.05.03 00:25:08 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_2.dll
[2010.05.03 00:25:08 | 000,177,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_2.dll
[2010.05.03 00:25:08 | 000,072,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_1.dll
[2010.05.03 00:25:08 | 000,068,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_1.dll
[2010.05.02 23:50:19 | 000,000,000 | ---D | C] -- C:\Users\Kopr\Documents\Prototype
[2010.05.02 23:47:48 | 000,518,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_3.dll
[2010.05.02 23:47:48 | 000,514,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_3.dll
[2010.05.02 23:47:48 | 000,235,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_3.dll
[2010.05.02 23:47:48 | 000,175,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_3.dll
[2010.05.02 23:47:48 | 000,074,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_2.dll
[2010.05.02 23:47:48 | 000,070,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_2.dll
[2010.05.02 23:47:48 | 000,025,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_5.dll
[2010.05.02 23:47:48 | 000,023,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_5.dll
[2010.05.02 23:47:47 | 001,942,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_39.dll
[2010.05.02 23:47:47 | 001,493,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_39.dll
[2010.05.02 23:47:47 | 000,540,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_39.dll
[2010.05.02 23:47:47 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_39.dll
[2010.05.02 23:47:46 | 004,992,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_39.dll
[2010.05.02 23:47:46 | 003,851,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_39.dll
[2010.05.02 22:56:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Steam
[2010.05.02 22:54:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SpeedFan
[2010.05.01 07:32:32 | 000,294,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\browserchoice.exe
[2010.05.01 04:06:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Symantec
[2010.05.01 04:06:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton
[2010.05.01 04:06:14 | 000,000,000 | ---D | C] -- C:\ProgramData\NortonInstaller
[2010.05.01 03:06:08 | 000,612,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2010.05.01 03:06:08 | 000,427,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\vbscript.dll
[2010.05.01 03:06:04 | 014,629,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmp.dll
[2010.05.01 03:06:01 | 011,406,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmp.dll
[2010.05.01 03:06:00 | 001,975,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CertEnroll.dll
[2010.05.01 03:06:00 | 001,320,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CertEnroll.dll
[2010.05.01 03:05:58 | 012,625,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmploc.DLL
[2010.05.01 03:05:58 | 012,625,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmploc.DLL
[2010.05.01 03:05:39 | 000,422,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_isv.dll
[2010.05.01 03:05:39 | 000,365,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_isv.dll
[2010.05.01 03:05:38 | 000,424,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc.dll
[2010.05.01 03:05:38 | 000,369,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc.dll
[2010.05.01 03:05:38 | 000,357,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_isv.exe
[2010.05.01 03:05:38 | 000,356,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate.exe
[2010.05.01 03:05:38 | 000,324,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_isv.exe
[2010.05.01 03:05:38 | 000,320,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate.exe
[2010.05.01 03:05:38 | 000,306,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_ssp.exe
[2010.05.01 03:05:38 | 000,305,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_ssp_isv.exe
[2010.05.01 03:05:38 | 000,280,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_ssp.exe
[2010.05.01 03:05:38 | 000,277,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_ssp_isv.exe
[2010.05.01 03:05:38 | 000,121,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_ssp_isv.dll
[2010.05.01 03:05:38 | 000,121,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_ssp.dll
[2010.05.01 03:05:38 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_ssp_isv.dll
[2010.05.01 03:05:38 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_ssp.dll
[2010.05.01 03:05:37 | 000,366,080 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysNative\atmfd.dll
[2010.05.01 03:05:37 | 000,148,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\t2embed.dll
[2010.05.01 03:05:37 | 000,100,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fontsub.dll
[2010.05.01 03:05:36 | 002,870,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\explorer.exe
[2010.05.01 03:05:36 | 002,614,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\explorer.exe
[2010.05.01 03:05:36 | 000,293,888 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\atmfd.dll
[2010.05.01 03:05:36 | 000,108,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\t2embed.dll
[2010.05.01 03:05:36 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fontsub.dll
[2010.05.01 03:05:35 | 000,389,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winlogon.exe
[2010.05.01 03:05:34 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll
[2010.05.01 03:05:34 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe
[2010.05.01 03:05:33 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll
[2010.05.01 03:05:33 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe
[2010.05.01 03:05:33 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll
[2010.05.01 03:05:32 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe
[2010.05.01 03:05:24 | 001,026,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstime.dll
[2010.05.01 03:05:23 | 001,192,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wininet.dll
[2010.05.01 03:05:23 | 000,606,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstime.dll
[2010.05.01 03:05:23 | 000,445,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iedkcs32.dll
[2010.05.01 03:05:22 | 000,977,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wininet.dll
[2010.05.01 03:05:22 | 000,381,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iedkcs32.dll
[2010.05.01 03:05:22 | 000,082,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedsbs.dll
[2010.05.01 03:05:22 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedsbs.dll
[2010.05.01 03:05:14 | 000,223,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\fvevol.sys
[2010.05.01 03:05:09 | 001,572,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\quartz.dll
[2010.05.01 03:05:08 | 001,328,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\quartz.dll
[2010.05.01 03:05:08 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\avifil32.dll
[2010.05.01 03:05:08 | 000,084,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mciavi32.dll
[2010.05.01 03:05:08 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iyuv_32.dll
[2010.05.01 03:05:08 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msvidc32.dll
[2010.05.01 03:05:08 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msyuv.dll
[2010.05.01 03:05:08 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrle32.dll
[2010.05.01 03:05:08 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tsbyuv.dll
[2010.05.01 03:05:05 | 005,509,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2010.05.01 03:05:03 | 003,954,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2010.05.01 03:05:03 | 003,899,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2010.05.01 03:05:00 | 000,852,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2010.05.01 03:04:59 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2010.05.01 03:04:54 | 001,446,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2010.05.01 03:04:54 | 000,153,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\ksecpkg.sys
[2010.05.01 03:04:33 | 000,960,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CPFilters.dll
[2010.05.01 03:04:33 | 000,641,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CPFilters.dll
[2010.05.01 03:04:33 | 000,552,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdri.dll
[2010.05.01 03:04:33 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSNP.ax
[2010.05.01 03:04:32 | 000,613,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\psisdecd.dll
[2010.05.01 03:04:32 | 000,465,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\psisdecd.dll
[2010.05.01 03:04:32 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSNP.ax
[2010.05.01 03:04:28 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msasn1.dll
[2010.05.01 03:00:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FlashGet
[2010.05.01 02:58:37 | 000,000,000 | RH-D | C] -- C:\Users\Kopr\AppData\Roaming\SecuROM
[2010.05.01 02:33:00 | 001,892,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_42.dll
[2010.05.01 02:33:00 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_42.dll
[2010.05.01 02:22:59 | 000,000,000 | ---D | C] -- C:\Users\Kopr\Documents\Rockstar Games
[2010.05.01 02:16:11 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Local\Rockstar Games
[2010.05.01 02:15:16 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\microsoft
[2010.05.01 01:54:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SystemRequirementsLab
[2010.05.01 01:54:43 | 000,000,000 | ---D | C] -- C:\Users\Kopr\SystemRequirementsLab
[2010.05.01 01:09:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe
[2010.05.01 01:09:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe
[2010.05.01 01:09:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2010.05.01 01:09:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe AIR
[2010.05.01 01:09:35 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Roaming\Macromedia
[2010.05.01 01:09:35 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Roaming\Adobe
[2010.05.01 01:09:17 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Local\Adobe
[2010.05.01 01:06:25 | 000,000,000 | ---D | C] -- C:\ProgramData\NOS
[2010.05.01 01:06:05 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Adobe
[2010.05.01 01:05:14 | 000,185,920 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\rmoc3260.dll
[2010.05.01 01:05:12 | 000,006,656 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5016.dll
[2010.05.01 01:05:12 | 000,005,632 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5032.dll
[2010.05.01 01:05:11 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Macromed
[2010.05.01 01:05:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\xing shared
[2010.05.01 01:05:03 | 000,499,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcp71.dll
[2010.05.01 01:05:03 | 000,348,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcr71.dll
[2010.05.01 01:05:03 | 000,278,528 | ---- | C] (Real Networks, Inc) -- C:\Windows\SysWow64\pncrt.dll
[2010.05.01 01:05:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Real
[2010.05.01 01:05:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Real
[2010.05.01 01:05:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Real
[2010.05.01 01:04:19 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Roaming\Real
[2010.05.01 01:04:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2010.05.01 01:04:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2010.05.01 01:03:56 | 000,411,368 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\deployJava1.dll
[2010.05.01 01:03:56 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe
[2010.05.01 01:03:56 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaw.exe
[2010.05.01 01:03:55 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\java.exe
[2010.05.01 01:03:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2010.05.01 01:01:58 | 000,178,800 | ---- | C] (Sony DADC Austria AG.) -- C:\Windows\SysWow64\CmdLineExt_x64.dll
[2010.05.01 01:01:36 | 000,068,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_0.dll
[2010.05.01 01:01:36 | 000,065,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_0.dll
[2010.05.01 01:01:35 | 004,991,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_38.dll
[2010.05.01 01:01:35 | 003,850,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_38.dll
[2010.05.01 01:01:35 | 001,941,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_38.dll
[2010.05.01 01:01:35 | 001,491,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_38.dll
[2010.05.01 01:01:35 | 000,540,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_38.dll
[2010.05.01 01:01:35 | 000,511,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_1.dll
[2010.05.01 01:01:35 | 000,507,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_1.dll
[2010.05.01 01:01:35 | 000,489,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_0.dll
[2010.05.01 01:01:35 | 000,479,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_0.dll
[2010.05.01 01:01:35 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_38.dll
[2010.05.01 01:01:35 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_1.dll
[2010.05.01 01:01:35 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_0.dll
[2010.05.01 01:01:35 | 000,177,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_1.dll
[2010.05.01 01:01:35 | 000,177,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_0.dll
[2010.05.01 01:01:35 | 000,028,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_4.dll
[2010.05.01 01:01:35 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_4.dll
[2010.05.01 01:01:34 | 004,910,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_37.dll
[2010.05.01 01:01:34 | 002,006,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_36.dll
[2010.05.01 01:01:34 | 001,860,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_37.dll
[2010.05.01 01:01:34 | 001,374,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_36.dll
[2010.05.01 01:01:34 | 000,529,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_37.dll
[2010.05.01 01:01:34 | 000,508,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_36.dll
[2010.05.01 01:01:34 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_36.dll
[2010.05.01 01:01:34 | 000,411,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_10.dll
[2010.05.01 01:01:34 | 000,267,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_10.dll
[2010.05.01 01:01:34 | 000,028,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_3.dll
[2010.05.01 01:01:34 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_3.dll
[2010.05.01 01:01:33 | 005,081,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_36.dll
[2010.05.01 01:01:33 | 005,073,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_35.dll
[2010.05.01 01:01:33 | 003,734,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_36.dll
[2010.05.01 01:01:33 | 003,727,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_35.dll
[2010.05.01 01:01:33 | 001,985,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_35.dll
[2010.05.01 01:01:33 | 001,358,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_35.dll
[2010.05.01 01:01:33 | 000,508,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_35.dll
[2010.05.01 01:01:33 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_35.dll
[2010.05.01 01:01:33 | 000,411,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_9.dll
[2010.05.01 01:01:33 | 000,267,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_9.dll
[2010.05.01 01:01:32 | 004,496,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_34.dll
[2010.05.01 01:01:32 | 003,497,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_34.dll
[2010.05.01 01:01:32 | 001,401,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_34.dll
[2010.05.01 01:01:32 | 001,124,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_34.dll
[2010.05.01 01:01:32 | 000,506,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_34.dll
[2010.05.01 01:01:32 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_34.dll
[2010.05.01 01:01:32 | 000,409,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_8.dll
[2010.05.01 01:01:32 | 000,403,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_7.dll
[2010.05.01 01:01:32 | 000,266,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_8.dll
[2010.05.01 01:01:32 | 000,261,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_7.dll
[2010.05.01 01:01:32 | 000,107,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xinput1_3.dll
[2010.05.01 01:01:32 | 000,021,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_2.dll
[2010.05.01 01:01:32 | 000,017,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_2.dll
[2010.05.01 01:01:31 | 004,494,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_33.dll
[2010.05.01 01:01:31 | 003,495,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_33.dll
[2010.05.01 01:01:31 | 001,400,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_33.dll
[2010.05.01 01:01:31 | 001,123,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_33.dll
[2010.05.01 01:01:31 | 000,506,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_33.dll
[2010.05.01 01:01:31 | 000,469,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10.dll
[2010.05.01 01:01:31 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_33.dll
[2010.05.01 01:01:31 | 000,440,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10.dll
[2010.05.01 01:01:31 | 000,393,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_6.dll
[2010.05.01 01:01:31 | 000,390,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_5.dll
[2010.05.01 01:01:31 | 000,255,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_6.dll
[2010.05.01 01:01:31 | 000,251,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_5.dll
[2010.05.01 01:01:30 | 004,398,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_32.dll
[2010.05.01 01:01:30 | 003,977,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_31.dll
[2010.05.01 01:01:30 | 003,426,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_32.dll
[2010.05.01 01:01:30 | 002,414,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_31.dll
[2010.05.01 01:01:30 | 000,364,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_4.dll
[2010.05.01 01:01:30 | 000,363,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_3.dll
[2010.05.01 01:01:30 | 000,354,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_2.dll
[2010.05.01 01:01:30 | 000,237,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_4.dll
[2010.05.01 01:01:30 | 000,236,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_3.dll
[2010.05.01 01:01:30 | 000,230,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_2.dll
[2010.05.01 01:01:30 | 000,083,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xinput1_2.dll
[2010.05.01 01:01:30 | 000,062,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xinput1_2.dll
[2010.05.01 01:01:30 | 000,017,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\x3daudio1_1.dll
[2010.05.01 01:01:30 | 000,015,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\x3daudio1_1.dll
[2010.05.01 01:01:29 | 000,352,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_1.dll
[2010.05.01 01:01:29 | 000,229,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_1.dll
[2010.05.01 01:01:29 | 000,083,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xinput1_1.dll
[2010.05.01 01:01:29 | 000,062,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xinput1_1.dll
[2010.05.01 01:01:27 | 003,927,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_30.dll
[2010.05.01 01:01:27 | 003,830,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_29.dll
[2010.05.01 01:01:27 | 003,815,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_28.dll
[2010.05.01 01:01:27 | 002,388,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_30.dll
[2010.05.01 01:01:27 | 002,332,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_29.dll
[2010.05.01 01:01:27 | 002,323,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_28.dll
[2010.05.01 01:01:27 | 000,355,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_0.dll
[2010.05.01 01:01:27 | 000,230,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_0.dll
[2010.05.01 01:01:27 | 000,016,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\x3daudio1_0.dll
[2010.05.01 01:01:27 | 000,014,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\x3daudio1_0.dll
[2010.05.01 01:01:26 | 003,823,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_25.dll
[2010.05.01 01:01:26 | 003,807,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_27.dll
[2010.05.01 01:01:26 | 003,767,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_26.dll
[2010.05.01 01:01:26 | 003,544,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_24.dll
[2010.05.01 01:01:26 | 002,337,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_25.dll
[2010.05.01 01:01:26 | 002,319,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_27.dll
[2010.05.01 01:01:26 | 002,297,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_26.dll
[2010.05.01 01:01:26 | 002,222,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_24.dll
[2010.05.01 01:01:16 | 003,786,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_37.dll
[2010.05.01 01:01:16 | 001,420,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_37.dll
[2010.05.01 01:01:16 | 000,462,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_37.dll
[2010.05.01 01:01:16 | 000,081,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xinput1_3.dll
[2010.05.01 01:01:02 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\xlive
[2010.05.01 01:01:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
[2010.05.01 00:32:59 | 000,000,000 | ---D | C] -- C:\Users\Kopr\Documents\Stardock
[2010.05.01 00:31:02 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Local\Stardock
[2010.05.01 00:29:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Stardock
[2010.05.01 00:29:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Stardock
[2010.05.01 00:12:13 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Roaming\skypePM
[2010.05.01 00:11:49 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Roaming\Skype
[2010.05.01 00:11:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2010.05.01 00:11:38 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype
[2010.05.01 00:11:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
[2010.05.01 00:00:04 | 000,000,000 | ---D | C] -- C:\Program Files\QIP 2010
[2010.04.30 23:54:19 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2010.04.30 23:53:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NVIDIA Corporation
[2010.04.30 23:53:45 | 000,000,000 | ---D | C] -- C:\Program Files\NVIDIA Corporation
[2010.04.30 23:51:55 | 004,503,144 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvwgf2um.dll
[2010.04.30 23:51:55 | 000,930,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dpinst.exe
[2010.04.30 23:51:55 | 000,064,616 | ---- | C] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
[2010.04.30 23:51:55 | 000,056,424 | ---- | C] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
[2010.04.30 23:51:55 | 000,011,240 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\drivers\nvBridge.kmd
[2010.04.30 23:51:53 | 021,005,928 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglv64.dll
[2010.04.30 23:51:53 | 015,227,496 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglv32.dll
[2010.04.30 23:51:53 | 003,215,464 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvencodemft.dll
[2010.04.30 23:51:53 | 002,907,752 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvencodemft.dll
[2010.04.30 23:51:53 | 000,384,616 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdecodemft.dll
[2010.04.30 23:51:53 | 000,316,008 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvdecodemft.dll
[2010.04.30 23:51:52 | 011,906,664 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvd3dumx.dll
[2010.04.30 23:51:52 | 009,386,600 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvd3dum.dll
[2010.04.30 23:51:52 | 002,893,416 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvenc.dll
[2010.04.30 23:51:52 | 002,646,632 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvenc.dll
[2010.04.30 23:51:52 | 002,106,472 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvid.dll
[2010.04.30 23:51:52 | 002,009,704 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvid.dll
[2010.04.30 23:51:51 | 016,061,032 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcompiler.dll
[2010.04.30 23:51:51 | 011,647,592 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcompiler.dll
[2010.04.30 23:51:51 | 005,444,200 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuda.dll
[2010.04.30 23:51:51 | 004,029,544 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuda.dll
[2010.04.30 23:51:51 | 001,592,936 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvapi64.dll
[2010.04.30 23:51:51 | 001,296,488 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvapi.dll
[2010.04.30 23:51:51 | 000,254,056 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcod1914.dll
[2010.04.30 23:51:51 | 000,254,056 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcod.dll
[2010.04.30 23:45:48 | 002,719,144 | ---- | C] (Acronis) -- C:\Windows\SysNative\auto_reactivate.exe
[2010.04.30 23:45:27 | 000,000,000 | RHSD | C] -- C:\bootwiz
[2010.04.30 23:03:27 | 003,692,384 | ---- | C] (Acronis) -- C:\Windows\SysNative\AutoPartNt.exe
[2010.04.30 22:51:13 | 000,000,000 | ---D | C] -- C:\Users\Kopr\Documents\Zálohy
[2010.04.30 22:48:48 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Roaming\Acronis
[2010.04.30 22:46:08 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Local\ElevatedDiagnostics
[2010.04.30 22:44:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TNod User & Password Finder
[2010.04.30 22:42:24 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Roaming\ESET
[2010.04.30 22:42:24 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Local\ESET
[2010.04.30 22:41:55 | 000,000,000 | ---D | C] -- C:\ProgramData\ESET
[2010.04.30 22:41:55 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2010.04.30 22:38:31 | 000,000,000 | ---D | C] -- C:\Users\Kopr\Documents\Downloads
[2010.04.30 22:34:41 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Local\Google
[2010.04.30 22:34:16 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Roaming\Mozilla
[2010.04.30 22:34:16 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Local\Mozilla
[2010.04.30 22:32:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2010.04.30 22:28:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Alcohol Soft
[2010.04.30 22:28:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Acronis
[2010.04.30 22:19:51 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Roaming\FlashGet
[2010.04.30 22:19:51 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Roaming\BITS
[2010.04.30 22:19:50 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Roaming\FlashGetBHO
[2010.04.30 22:19:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FlashGet 3
[2010.04.30 22:18:17 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Local\GHISLER
[2010.04.30 22:14:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Total Commander
[2010.04.30 22:14:53 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Roaming\GHISLER
[2010.04.30 22:13:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VideoLAN
[2010.04.30 22:07:02 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Roaming\WinRAR
[2010.04.30 22:06:20 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2010.04.30 21:35:14 | 000,025,640 | ---- | C] (Windows (R) Server 2003 DDK provider) -- C:\Windows\etdrv.sys
[2010.04.30 20:55:13 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[2010.04.30 20:42:07 | 000,251,488 | ---- | C] (Acronis) -- C:\Windows\SysNative\drivers\afcdp.sys
[2010.04.30 20:42:05 | 001,477,728 | ---- | C] (Acronis) -- C:\Windows\SysNative\drivers\tdrpm258.sys
[2010.04.30 20:42:04 | 000,943,712 | ---- | C] (Acronis) -- C:\Windows\SysNative\drivers\timntr.sys
[2010.04.30 20:42:00 | 000,257,120 | ---- | C] (Acronis) -- C:\Windows\SysNative\drivers\snapman.sys
[2010.04.30 20:41:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Acronis
[2010.04.30 20:41:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Acronis
[2010.04.30 20:39:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GIGABYTE
[2010.04.30 20:39:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD
[2010.04.30 20:22:47 | 000,025,640 | ---- | C] (Windows (R) Server 2003 DDK provider) -- C:\Windows\gdrv.sys
[2010.04.30 20:21:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NEC Electronics
[2010.04.30 20:21:17 | 001,970,176 | R--- | C] (Gigabyte Technology Corp.) -- C:\Windows\SysWow64\xRaidSetup.exe
[2010.04.30 20:21:17 | 000,151,552 | R--- | C] (JMicron Technology Corp.) -- C:\Windows\SysWow64\xRaidAPI.dll
[2010.04.30 20:21:14 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2010.04.30 20:21:11 | 000,112,240 | ---- | C] (JMicron Technology Corp.) -- C:\Windows\SysNative\drivers\jraid.sys
[2010.04.30 20:21:10 | 000,000,000 | ---D | C] -- C:\Windows\RaidTool
[2010.04.30 20:20:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Marvell
[2010.04.30 20:19:27 | 000,097,792 | ---- | C] (Realtek Semiconductor Corporation) -- C:\Windows\SysNative\RTNUninst64.dll
[2010.04.30 20:19:16 | 000,239,616 | ---- | C] (Realtek ) -- C:\Windows\SysNative\drivers\Rt64win7.sys
[2010.04.30 20:17:42 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\RTCOM
[2010.04.30 20:17:42 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek
[2010.04.30 20:17:32 | 000,513,536 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSX64.dll
[2010.04.30 20:17:32 | 000,211,376 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSH64.dll
[2010.04.30 20:17:32 | 000,193,536 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSHP64.dll
[2010.04.30 20:17:32 | 000,150,528 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSWOW64.dll
[2010.04.30 20:17:31 | 000,436,768 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkApi64.dll
[2010.04.30 20:17:31 | 000,332,320 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtlCPAPI64.dll
[2010.04.30 20:17:31 | 000,149,536 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkCfg64.dll
[2010.04.30 20:17:30 | 001,671,200 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkAPO64.dll
[2010.04.30 20:17:30 | 001,483,296 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtPgEx64.dll
[2010.04.30 20:17:30 | 001,178,656 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RTCOM64.dll
[2010.04.30 20:17:29 | 000,611,872 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RTSnMg64.cpl
[2010.04.30 20:17:29 | 000,363,008 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEP64A.dll
[2010.04.30 20:17:29 | 000,304,640 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DHT64.dll
[2010.04.30 20:17:29 | 000,304,640 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DAA64.dll
[2010.04.30 20:17:29 | 000,198,656 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEED64A.dll
[2010.04.30 20:17:29 | 000,095,744 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEL64A.dll
[2010.04.30 20:17:29 | 000,073,216 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEG64A.dll
[2010.04.30 20:17:29 | 000,064,032 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RCoInst64.dll
[2010.04.30 20:17:27 | 000,320,512 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPO20.dll
[2010.04.30 20:17:26 | 000,307,200 | ---- | C] (Fortemedia Corporation) -- C:\Windows\SysNative\FMAPO64.dll
[2010.04.30 20:17:26 | 000,166,400 | ---- | C] (Andrea Electronics Corporation) -- C:\Windows\SysNative\AERTAC64.dll
[2010.04.30 20:17:26 | 000,108,032 | ---- | C] (Andrea Electronics Corporation) -- C:\Windows\SysNative\AERTAR64.dll
[2010.04.30 20:17:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Realtek
[2010.04.30 20:17:25 | 000,831,488 | R--- | C] (Realtek Semiconductor Corp.) -- C:\Windows\RtlExUpd.dll
[2010.04.30 20:17:25 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\Temp
[2010.04.30 20:17:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InstallShield
[2010.04.30 20:14:50 | 000,053,248 | R--- | C] (Windows XP Bundled build C-Centric Single User) -- C:\Windows\SysWow64\CSVer.dll
[2010.04.30 20:14:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Intel
[2010.04.30 20:14:44 | 000,000,000 | ---D | C] -- C:\Intel
[2010.04.30 20:14:27 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\InstallShield Installation Information
[2010.04.30 20:14:27 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\DeviceVM
[2010.04.30 20:12:54 | 000,220,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wintrust.dll
[2010.04.30 20:12:54 | 000,172,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wintrust.dll
[2010.04.30 20:12:54 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cabview.dll
[2010.04.30 20:12:54 | 000,132,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cabview.dll
[2010.04.30 20:12:54 | 000,000,000 | R--D | C] -- C:\Users\Kopr\Searches
[2010.04.30 20:12:48 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Roaming\Identities
[2010.04.30 20:12:46 | 000,000,000 | R--D | C] -- C:\Users\Kopr\Contacts
[2010.04.30 20:12:45 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Local\VirtualStore
[2010.04.30 20:12:39 | 000,000,000 | --SD | C] -- C:\Users\Kopr\AppData\Roaming\Microsoft
[2010.04.30 20:12:39 | 000,000,000 | R--D | C] -- C:\Users\Kopr\Videos
[2010.04.30 20:12:39 | 000,000,000 | R--D | C] -- C:\Users\Kopr\Saved Games
[2010.04.30 20:12:39 | 000,000,000 | R--D | C] -- C:\Users\Kopr\Pictures
[2010.04.30 20:12:39 | 000,000,000 | R--D | C] -- C:\Users\Kopr\Music
[2010.04.30 20:12:39 | 000,000,000 | R--D | C] -- C:\Users\Kopr\Links
[2010.04.30 20:12:39 | 000,000,000 | R--D | C] -- C:\Users\Kopr\Favorites
[2010.04.30 20:12:39 | 000,000,000 | R--D | C] -- C:\Users\Kopr\Downloads
[2010.04.30 20:12:39 | 000,000,000 | R--D | C] -- C:\Users\Kopr\Dokumenty
[2010.04.30 20:12:39 | 000,000,000 | R--D | C] -- C:\Users\Kopr\Desktop
[2010.04.30 20:12:39 | 000,000,000 | -HSD | C] -- C:\Users\Kopr\AppData\Local\Temporary Internet Files
[2010.04.30 20:12:39 | 000,000,000 | -HSD | C] -- C:\Users\Kopr\Šablony
[2010.04.30 20:12:39 | 000,000,000 | -HSD | C] -- C:\Users\Kopr\Soubory cookie
[2010.04.30 20:12:39 | 000,000,000 | -HSD | C] -- C:\Users\Kopr\SendTo
[2010.04.30 20:12:39 | 000,000,000 | -HSD | C] -- C:\Users\Kopr\Poslední
[2010.04.30 20:12:39 | 000,000,000 | -HSD | C] -- C:\Users\Kopr\Okolní tiskárny
[2010.04.30 20:12:39 | 000,000,000 | -HSD | C] -- C:\Users\Kopr\Okolní síť
[2010.04.30 20:12:39 | 000,000,000 | -HSD | C] -- C:\Users\Kopr\Documents\Obrázky
[2010.04.30 20:12:39 | 000,000,000 | -HSD | C] -- C:\Users\Kopr\Nabídka Start
[2010.04.30 20:12:39 | 000,000,000 | -HSD | C] -- C:\Users\Kopr\Local Settings
[2010.04.30 20:12:39 | 000,000,000 | -HSD | C] -- C:\Users\Kopr\Documents\Hudba
[2010.04.30 20:12:39 | 000,000,000 | -HSD | C] -- C:\Users\Kopr\AppData\Local\History
[2010.04.30 20:12:39 | 000,000,000 | -HSD | C] -- C:\Users\Kopr\Documents\Filmy
[2010.04.30 20:12:39 | 000,000,000 | -HSD | C] -- C:\Users\Kopr\Dokumenty
[2010.04.30 20:12:39 | 000,000,000 | -HSD | C] -- C:\Users\Kopr\Data aplikací
[2010.04.30 20:12:39 | 000,000,000 | -HSD | C] -- C:\Users\Kopr\AppData\Local\Data aplikací
[2010.04.30 20:12:39 | 000,000,000 | -H-D | C] -- C:\Users\Kopr\AppData
[2010.04.30 20:12:39 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Local\Temp
[2010.04.30 20:12:39 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Local\Microsoft
[2010.04.30 20:12:39 | 000,000,000 | ---D | C] -- C:\Users\Kopr\AppData\Roaming\Media Center Programs
[2010.04.30 20:12:29 | 000,000,000 | -HSD | C] -- C:\ProgramData\Šablony
[2010.04.30 20:12:29 | 000,000,000 | -HSD | C] -- C:\Recovery
[2010.04.30 20:12:29 | 000,000,000 | -HSD | C] -- C:\ProgramData\Plocha
[2010.04.30 20:12:29 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Obrázky
[2010.04.30 20:12:29 | 000,000,000 | -HSD | C] -- C:\ProgramData\Oblíbené položky
[2010.04.30 20:12:29 | 000,000,000 | -HSD | C] -- C:\ProgramData\Nabídka Start
[2010.04.30 20:12:29 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Hudba
[2010.04.30 20:12:29 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Filmy
[2010.04.30 20:12:29 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumenty
[2010.04.30 20:12:29 | 000,000,000 | -HSD | C] -- C:\ProgramData\Data aplikací
[2010.04.30 19:58:52 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2010.04.30 19:56:28 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2010.04.30 19:56:08 | 000,000,000 | -HSD | C] -- C:\System Volume Information

Re: pravděpodobně neznámý TSR.BOOT virus

Napsal: 28 kvě 2010 17:45
od koprkuba
Part: 03/03

========== Files - Modified Within 30 Days ==========

[2010.05.28 18:39:38 | 003,145,728 | -HS- | M] () -- C:\Users\Kopr\NTUSER.DAT
[2010.05.28 18:39:10 | 000,000,958 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3057483691-2723968932-3762023798-1001UA.job
[2010.05.28 18:04:41 | 000,455,680 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\deployJava1.dll
[2010.05.28 18:04:41 | 000,182,784 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\javaws.exe
[2010.05.28 18:04:41 | 000,165,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\javaw.exe
[2010.05.28 18:04:41 | 000,165,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\java.exe
[2010.05.28 17:38:23 | 000,000,132 | ---- | M] () -- C:\Users\Kopr\AppData\Roaming\Adobe Formát PNG CS5 – předvolby
[2010.05.28 16:03:38 | 000,014,992 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010.05.28 16:03:38 | 000,014,992 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010.05.28 15:57:20 | 000,030,528 | ---- | M] () -- C:\Windows\GVTDrv64.sys
[2010.05.28 15:57:20 | 000,000,004 | ---- | M] () -- C:\Windows\SysWow64\GVTunner.ref
[2010.05.28 15:57:05 | 000,025,640 | ---- | M] (Windows (R) Server 2003 DDK provider) -- C:\Windows\gdrv.sys
[2010.05.28 15:56:37 | 000,000,008 | ---- | M] () -- C:\Windows\mvraidver.dat
[2010.05.28 15:56:31 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010.05.28 15:56:28 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010.05.28 15:56:26 | 3217,678,336 | -HS- | M] () -- C:\hiberfil.sys
[2010.05.28 15:46:58 | 002,929,639 | -H-- | M] () -- C:\Users\Kopr\AppData\Local\IconCache.db
[2010.05.28 15:43:57 | 000,001,189 | ---- | M] () -- C:\Users\Kopr\Documents\ax_files.xml
[2010.05.28 14:15:06 | 001,445,734 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2010.05.28 14:15:06 | 000,622,422 | ---- | M] () -- C:\Windows\SysNative\perfh005.dat
[2010.05.28 14:15:06 | 000,606,992 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2010.05.28 14:15:06 | 000,118,604 | ---- | M] () -- C:\Windows\SysNative\perfc005.dat
[2010.05.28 14:15:06 | 000,103,370 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2010.05.27 22:39:00 | 000,000,906 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3057483691-2723968932-3762023798-1001Core.job
[2010.05.27 21:29:24 | 000,004,544 | ---- | M] () -- C:\Windows\za_mv_raid.ev
[2010.05.27 21:29:24 | 000,000,096 | ---- | M] () -- C:\Windows\za_mv_seqnum.ev
[2010.05.24 20:30:23 | 004,981,376 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2010.05.23 19:05:00 | 000,000,132 | ---- | M] () -- C:\Users\Kopr\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2010.05.23 13:23:34 | 000,025,698 | ---- | M] () -- C:\Users\Kopr\Desktop\WMM dok.docx
[2010.05.23 13:23:25 | 000,298,926 | ---- | M] () -- C:\Users\Kopr\Desktop\WMM-tabulka.pdf
[2010.05.22 22:26:05 | 000,001,456 | ---- | M] () -- C:\Users\Kopr\AppData\Local\Adobe Save for Web 12.0 Prefs
[2010.05.22 19:57:52 | 000,110,680 | ---- | M] () -- C:\Users\Kopr\AppData\Local\GDIPFONTCACHEV1.DAT
[2010.05.22 16:53:27 | 000,000,162 | -H-- | M] () -- C:\Users\Kopr\Desktop\~$MM dok.docx
[2010.05.22 02:06:27 | 000,000,424 | ---- | M] () -- C:\Users\Kopr\.jalbum-ftp-accounts.xml
[2010.05.22 00:11:26 | 000,000,919 | ---- | M] () -- C:\Users\Kopr\.jalbum-defaults.jap
[2010.05.21 23:37:21 | 000,000,137 | ---- | M] () -- C:\Users\Kopr\.jalbum-recent-projects.properties
[2010.05.21 11:04:52 | 000,000,478 | ---- | M] () -- C:\Windows\win.ini
[2010.05.16 14:30:27 | 000,000,045 | ---- | M] () -- C:\Windows\lifeview.ini
[2010.05.08 20:40:04 | 000,000,600 | ---- | M] () -- C:\Users\Kopr\AppData\Roaming\winscp.rnd
[2010.05.08 20:17:55 | 000,002,100 | ---- | M] () -- C:\Windows\SysWow64\BioPdf.PdfWriter.Lib.tlb
[2010.05.08 18:37:05 | 000,025,640 | ---- | M] (Windows (R) Server 2003 DDK provider) -- C:\Windows\etdrv.sys
[2010.05.04 22:25:47 | 000,000,000 | ---- | M] () -- C:\Users\Kopr\.javafx_eula_accepted
[2010.05.03 14:21:57 | 000,215,128 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2010.05.03 14:21:57 | 000,215,128 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2010.05.03 00:25:21 | 000,075,064 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2010.05.03 00:25:20 | 002,434,856 | ---- | M] () -- C:\Windows\SysWow64\pbsvc_bc2.exe
[2010.05.02 22:54:24 | 000,000,045 | ---- | M] () -- C:\Windows\SysWow64\initdebug.nfo
[2010.05.01 01:50:04 | 000,000,292 | ---- | M] () -- C:\Windows\SysWow64\secustat.dat
[2010.05.01 01:05:14 | 000,185,920 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\rmoc3260.dll
[2010.05.01 01:05:12 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5016.dll
[2010.05.01 01:05:12 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5032.dll
[2010.05.01 01:05:03 | 000,499,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcp71.dll
[2010.05.01 01:05:03 | 000,348,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcr71.dll
[2010.05.01 01:05:03 | 000,278,528 | ---- | M] (Real Networks, Inc) -- C:\Windows\SysWow64\pncrt.dll
[2010.05.01 01:03:51 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe
[2010.05.01 01:03:51 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaw.exe
[2010.05.01 01:03:50 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\deployJava1.dll
[2010.05.01 01:03:50 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\java.exe
[2010.05.01 01:01:58 | 000,178,800 | ---- | M] (Sony DADC Austria AG.) -- C:\Windows\SysWow64\CmdLineExt_x64.dll
[2010.05.01 00:33:30 | 000,002,066 | ---- | M] () -- C:\Users\Kopr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Stardock ObjectDock.lnk
[2010.05.01 00:12:13 | 000,000,056 | -H-- | M] () -- C:\ProgramData\ezsidmv.dat
[2010.04.30 23:45:48 | 002,719,144 | ---- | M] (Acronis) -- C:\Windows\SysNative\auto_reactivate.exe
[2010.04.30 23:05:11 | 000,001,024 | ---- | M] () -- C:\Windows\SysNative\AutoPartNt.let
[2010.04.30 23:03:27 | 003,692,384 | ---- | M] (Acronis) -- C:\Windows\SysNative\AutoPartNt.exe
[2010.04.30 22:26:30 | 000,834,544 | ---- | M] () -- C:\Windows\SysNative\drivers\sptd.sys
[2010.04.30 22:21:54 | 000,000,598 | ---- | M] () -- C:\Windows\SysWow64\secushr.dat
[2010.04.30 22:21:43 | 000,000,025 | ---- | M] () -- C:\Windows\libem.INI
[2010.04.30 20:42:07 | 000,251,488 | ---- | M] (Acronis) -- C:\Windows\SysNative\drivers\afcdp.sys
[2010.04.30 20:42:05 | 001,477,728 | ---- | M] (Acronis) -- C:\Windows\SysNative\drivers\tdrpm258.sys
[2010.04.30 20:42:04 | 000,943,712 | ---- | M] (Acronis) -- C:\Windows\SysNative\drivers\timntr.sys
[2010.04.30 20:42:00 | 000,257,120 | ---- | M] (Acronis) -- C:\Windows\SysNative\drivers\snapman.sys
[2010.04.30 20:38:07 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2010.04.30 20:22:47 | 000,000,010 | ---- | M] () -- C:\Windows\GSetup.ini
[2010.04.30 20:20:48 | 000,050,360 | ---- | M] () -- C:\Windows\php.ini
[2010.04.30 20:15:34 | 000,524,288 | -HS- | M] () -- C:\Users\Kopr\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
[2010.04.30 20:15:34 | 000,524,288 | -HS- | M] () -- C:\Users\Kopr\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
[2010.04.30 20:15:34 | 000,065,536 | -HS- | M] () -- C:\Users\Kopr\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
[2010.04.30 20:12:39 | 000,000,020 | -HS- | M] () -- C:\Users\Kopr\ntuser.ini
[2010.04.30 19:59:32 | 000,068,224 | ---- | M] () -- C:\Windows\SysWow64\license.rtf
[2010.04.30 19:59:32 | 000,068,224 | ---- | M] () -- C:\Windows\SysNative\license.rtf

========== Files Created - No Company Name ==========

[2010.05.28 16:44:24 | 000,000,132 | ---- | C] () -- C:\Users\Kopr\AppData\Roaming\Adobe Formát PNG CS5 – předvolby
[2010.05.23 13:23:24 | 000,298,926 | ---- | C] () -- C:\Users\Kopr\Desktop\WMM-tabulka.pdf
[2010.05.22 19:57:13 | 000,001,456 | ---- | C] () -- C:\Users\Kopr\AppData\Local\Adobe Save for Web 12.0 Prefs
[2010.05.22 16:53:27 | 000,000,162 | -H-- | C] () -- C:\Users\Kopr\Desktop\~$MM dok.docx
[2010.05.22 10:01:17 | 000,025,698 | ---- | C] () -- C:\Users\Kopr\Desktop\WMM dok.docx
[2010.05.21 23:37:21 | 000,000,137 | ---- | C] () -- C:\Users\Kopr\.jalbum-recent-projects.properties
[2010.05.21 23:26:03 | 000,000,424 | ---- | C] () -- C:\Users\Kopr\.jalbum-ftp-accounts.xml
[2010.05.21 23:26:02 | 000,000,919 | ---- | C] () -- C:\Users\Kopr\.jalbum-defaults.jap
[2010.05.21 22:27:25 | 000,000,132 | ---- | C] () -- C:\Users\Kopr\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2010.05.16 14:30:27 | 000,000,045 | ---- | C] () -- C:\Windows\lifeview.ini
[2010.05.12 01:55:34 | 3217,678,336 | -HS- | C] () -- C:\hiberfil.sys
[2010.05.08 20:25:44 | 000,000,600 | ---- | C] () -- C:\Users\Kopr\AppData\Roaming\winscp.rnd
[2010.05.08 20:17:55 | 000,002,100 | ---- | C] () -- C:\Windows\SysWow64\BioPdf.PdfWriter.Lib.tlb
[2010.05.04 22:25:47 | 000,000,000 | ---- | C] () -- C:\Users\Kopr\.javafx_eula_accepted
[2010.05.03 00:27:37 | 000,215,128 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2010.05.03 00:25:22 | 000,215,128 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2010.05.03 00:25:21 | 000,075,064 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2010.05.03 00:25:20 | 002,434,856 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_bc2.exe
[2010.05.02 22:54:23 | 000,000,045 | ---- | C] () -- C:\Windows\SysWow64\initdebug.nfo
[2010.05.01 01:50:04 | 000,000,292 | ---- | C] () -- C:\Windows\SysWow64\secustat.dat
[2010.05.01 00:32:59 | 000,002,066 | ---- | C] () -- C:\Users\Kopr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Stardock ObjectDock.lnk
[2010.05.01 00:12:13 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010.04.30 23:51:55 | 000,009,832 | ---- | C] () -- C:\Windows\SysNative\nvinfo.pb
[2010.04.30 23:03:27 | 000,001,024 | ---- | C] () -- C:\Windows\SysNative\AutoPartNt.let
[2010.04.30 22:34:43 | 000,000,958 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3057483691-2723968932-3762023798-1001UA.job
[2010.04.30 22:34:42 | 000,000,906 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3057483691-2723968932-3762023798-1001Core.job
[2010.04.30 22:31:46 | 000,001,189 | ---- | C] () -- C:\Users\Kopr\Documents\ax_files.xml
[2010.04.30 22:28:25 | 000,004,544 | ---- | C] () -- C:\Windows\za_mv_raid.ev
[2010.04.30 22:28:25 | 000,000,096 | ---- | C] () -- C:\Windows\za_mv_seqnum.ev
[2010.04.30 22:28:22 | 000,000,008 | ---- | C] () -- C:\Windows\mvraidver.dat
[2010.04.30 22:26:30 | 000,834,544 | ---- | C] () -- C:\Windows\SysNative\drivers\sptd.sys
[2010.04.30 22:21:54 | 000,000,598 | ---- | C] () -- C:\Windows\SysWow64\secushr.dat
[2010.04.30 22:21:43 | 000,000,025 | ---- | C] () -- C:\Windows\libem.INI
[2010.04.30 22:14:53 | 000,000,545 | ---- | C] () -- C:\Windows\UC.PIF
[2010.04.30 22:14:53 | 000,000,545 | ---- | C] () -- C:\Windows\RAR.PIF
[2010.04.30 22:14:53 | 000,000,545 | ---- | C] () -- C:\Windows\PKZIP.PIF
[2010.04.30 22:14:53 | 000,000,545 | ---- | C] () -- C:\Windows\PKUNZIP.PIF
[2010.04.30 22:14:53 | 000,000,545 | ---- | C] () -- C:\Windows\NOCLOSE.PIF
[2010.04.30 22:14:53 | 000,000,545 | ---- | C] () -- C:\Windows\LHA.PIF
[2010.04.30 22:14:53 | 000,000,545 | ---- | C] () -- C:\Windows\ARJ.PIF
[2010.04.30 20:39:33 | 000,030,528 | ---- | C] () -- C:\Windows\GVTDrv64.sys
[2010.04.30 20:39:33 | 000,000,004 | ---- | C] () -- C:\Windows\SysWow64\GVTunner.ref
[2010.04.30 20:38:07 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2010.04.30 20:19:27 | 000,067,584 | ---- | C] () -- C:\Windows\SysNative\RtNicProp64.dll
[2010.04.30 20:13:51 | 000,000,010 | ---- | C] () -- C:\Windows\GSetup.ini
[2010.04.30 20:12:39 | 003,145,728 | -HS- | C] () -- C:\Users\Kopr\NTUSER.DAT
[2010.04.30 20:12:39 | 000,524,288 | -HS- | C] () -- C:\Users\Kopr\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
[2010.04.30 20:12:39 | 000,524,288 | -HS- | C] () -- C:\Users\Kopr\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
[2010.04.30 20:12:39 | 000,262,144 | -HS- | C] () -- C:\Users\Kopr\ntuser.dat.LOG1
[2010.04.30 20:12:39 | 000,065,536 | -HS- | C] () -- C:\Users\Kopr\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
[2010.04.30 20:12:39 | 000,000,020 | -HS- | C] () -- C:\Users\Kopr\ntuser.ini
[2010.04.30 20:12:39 | 000,000,000 | -HS- | C] () -- C:\Users\Kopr\ntuser.dat.LOG2
[2010.04.02 17:17:34 | 000,179,091 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2009.09.30 19:18:26 | 000,050,360 | ---- | C] () -- C:\Windows\php.ini
[2009.09.29 23:16:26 | 000,000,127 | ---- | C] () -- C:\Windows\zraidtray.ini
[2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009.07.13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2002.08.13 12:01:26 | 000,014,385 | ---- | C] () -- C:\Windows\TW561a.ini

========== Alternate Data Streams ==========

@Alternate Data Stream - 1134 bytes -> C:\Users\Kopr\AppData\Local\TpbWMaN8N:ZHIYWuGjXwqHIQUV
@Alternate Data Stream - 1104 bytes -> C:\Users\Kopr\AppData\Local\Temp:HoLSx9hCoGES1oOkn6VtnbwgEsN
< End of report >

Re: pravděpodobně neznámý TSR.BOOT virus

Napsal: 28 kvě 2010 17:53
od koprkuba
Pokud by jste potřebovali tak ještě ten Extras.txt:

OTL Extras logfile created on: 28.5.2010 18:37:39 - Run 1
OTL by OldTimer - Version 3.2.5.0 Folder = D:\Download
64bit- An unknown product (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

4,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 48,00% Memory free
8,00 Gb Paging File | 6,00 Gb Available in Paging File | 74,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 165,92 Gb Total Space | 121,31 Gb Free Space | 73,12% Space Free | Partition Type: NTFS
Drive D: | 299,75 Gb Total Space | 143,34 Gb Free Space | 47,82% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 1,92 Gb Total Space | 1,92 Gb Free Space | 100,00% Space Free | Partition Type: FAT32
I: Drive not present or media not loaded

Computer Name: KOPR-PC
Current User Name: Kopr
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- C:\Users\Kopr\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)
.txt [@ = txtfile] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [Bridge] -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [MediaMonkey.1Play] -- "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" "%1" (Ventis Media Inc.)
Directory [MediaMonkey.2PlayNext] -- "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" /NEXT "%1" (Ventis Media Inc.)
Directory [MediaMonkey.3Enqueue] -- "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" /ADD "%1" (Ventis Media Inc.)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [Bridge] -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [MediaMonkey.1Play] -- "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" "%1" (Ventis Media Inc.)
Directory [MediaMonkey.2PlayNext] -- "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" /NEXT "%1" (Ventis Media Inc.)
Directory [MediaMonkey.3Enqueue] -- "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" /ADD "%1" (Ventis Media Inc.)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\FlashGet 3\FlashGet3.exe" = C:\Program Files (x86)\FlashGet 3\FlashGet3.exe:*:Enabled:Flashget3 -- (Trend Media Corporation Limited)
"C:\Program Files (x86)\FlashGet 3\FlashGet3.exe" = C:\Program Files (x86)\FlashGet 3\FlashGet3.exe:*:Enabled:Flashget3 -- (Trend Media Corporation Limited)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{20140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010 (Beta)
"{20140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010 (Beta)
"{20140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010 (Beta)
"{26A24AE4-039D-4CA4-87B4-2F86416020FF}" = Java(TM) 6 Update 20 (64-bit)
"{404BB1FF-A84F-432F-B77B-301E88E8D1C7}" = Apple Mobile Device Support
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{64A3A4F4-B792-11D6-A78A-00B0D0160200}" = Java(TM) SE Development Kit 6 Update 20 (64-bit)
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{9574DA73-7591-4063-8E24-01EA5972312B}" = ESET Smart Security
"{96D5EB02-DE18-4DCD-A713-929B4461CA8D}" = iTunes
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{C19D4D8F-4433-4F6D-9F0C-79589FD0B973}" = Bonjour
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"Bullzip PDF Printer_is1" = Bullzip PDF Printer 7.1.0.1181
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"TNod" = TNod User & Password Finder
"WinRAR archiver" = WinRAR

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{024521CF-C07E-4F8E-8481-0D75695E03AF}" = PxMergeModule
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{08B3869E-D282-424C-9AFC-870E04A4BA14}" = Rockstar Games Social Club
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{1BBD8D70-721A-41AD-AC8F-7308A0C8FA92}" = Adobe Creative Suite 5 Master Collection
"{20140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010 (Beta)
"{20140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010 (Beta)
"{20140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010 (Beta)
"{20140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010 (Beta)
"{20140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010 (Beta)
"{20140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010 (Beta)
"{20140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010 (Beta)
"{20140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 (Beta)
"{20140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010 (Beta)
"{20140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010 (Beta)
"{20140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010 (Beta)
"{20140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010 (Beta)
"{20140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010 (Beta)
"{20140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010 (Beta)
"{20140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010 (Beta)
"{20140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010 (Beta)
"{20140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010 (Beta)
"{20140000-011A-0000-0000-0000000FF1CE}" = Microsoft Office Send-a-Smile
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 20
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{32A3A4F4-B792-11D6-A78A-00B0D0160200}" = Java(TM) SE Development Kit 6 Update 20
"{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = Gigabyte Raid Configurer
"{457D7505-D665-4F95-91C3-ECB8C56E9ACA}" = Easy Tune 6 B09.0908.1
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{579BA58C-F33D-4970-9953-B94B43768AC3}" = Grand Theft Auto IV
"{5B363E1D-8C36-4458-BAE4-D5081999E094}" = Browser Configuration Utility
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{65A92AAA-3D05-4C94-9F70-731C05E60C16}" = NVIDIA System Update
"{67ED38A3-4882-448B-B44D-3428AB00D7D5}" = Acronis True Image Home
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6E9EF98E-259E-416D-B5F8-0ABDB99942CE}" = Adobe Flash Player 10 ActiveX
"{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA Performance
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows Vista and Later
"{8FB1B528-E260-451E-9B55-E9152F94B80B}" = Microsoft Games for Windows - LIVE Redistributable
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{9322A850-9091-4D0E-B252-3E82EDA3D94A}" = Prototype(TM)
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.2
"{BC41C09D-FAA9-4346-9FE6-1E0017BC551A}" = Adobe Flash Player 10 Plugin
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{CC98E8B3-FAAA-4D09-A813-A44C9FA1A3EE}" = Enterprise Architect 7.5
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D7BF9739-8A68-4335-BBEE-37752AD9E86B}" = NEC Electronics USB 3.0 Host Controller Driver
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E9CFBE78-ED91-4FCF-9E6F-210E477E527D}" = NVIDIA System Monitor
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F186D52C-BBD6-4C7D-80FA-28D0662D7ABD}" = Jalbum
"{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0
"{F8131A35-47FD-27AD-116D-0E79AF5DE5EE}" = Acrobat.com
"{F97E3841-CA9D-4964-9D64-26066241D26F}" = Microsoft Games for Windows - LIVE
"Adobe AIR" = Adobe AIR
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"CollabNet Subversion Client" = CollabNet Subversion Client 1.5.5
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"FileZilla Client" = FileZilla Client 3.3.2.1
"FlashGet" = FlashGet 1.9.6.1073
"FlashGet 3.3" = FlashGet 3.3
"Fraps" = Fraps (remove only)
"GPL Ghostscript Lite_is1" = GPL Ghostscript Lite 8.70
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"IETester" = IETester v0.4.3 (remove only)
"InstallShield_{457D7505-D665-4F95-91C3-ECB8C56E9ACA}" = Easy Tune 6 B09.0908.1
"InstallShield_{65A92AAA-3D05-4C94-9F70-731C05E60C16}" = NVIDIA System Update
"InstallShield_{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA Performance
"InstallShield_{9322A850-9091-4D0E-B252-3E82EDA3D94A}" = Prototype(TM)
"InstallShield_{D7BF9739-8A68-4335-BBEE-37752AD9E86B}" = NEC Electronics USB 3.0 Host Controller Driver
"InstallShield_{E9CFBE78-ED91-4FCF-9E6F-210E477E527D}" = NVIDIA System Monitor
"MediaMonkey_is1" = MediaMonkey 3.2
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"mv61xxMRU" = Marvell MRU V4
"nbi-glassfish-mod-sun-3.0.0.74.2" = Sun GlassFish Enterprise Server v3
"nbi-nb-base-6.8.0.0.0" = NetBeans IDE 6.8
"nbi-tomcat-6.0.20.0.0" = Apache Tomcat 6.0.20
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"ObjectDock Plus" = ObjectDock Plus
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"PSPad editor_is1" = PSPad editor
"PunkBusterSvc" = PunkBuster Services
"RealPlayer 12.0" = RealPlayer
"SpeedFan" = SpeedFan (remove only)
"Steam App 220" = Half-Life 2
"Steam App 240" = Counter-Strike: Source
"Steam App 24960" = Battlefield: Bad Company 2
"Steam App 400" = Portal
"SystemRequirementsLab" = System Requirements Lab
"Totalcmd" = Total Commander (Remove or Repair)
"VLC media player" = VLC media player 1.0.5
"winscp3_is1" = WinSCP 4.2.7

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"Qip 2010 packverze: 3341 s IRC protokolem" = Qip 2010 pack verze: 3341 s IRC protokolem
"Sloppy" = Sloppy
"TextComponentDemo" = TextComponentDemo

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 28.5.2010 7:01:13 | Computer Name = Kopr-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 7020

Error - 28.5.2010 7:01:14 | Computer Name = Kopr-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 28.5.2010 7:01:14 | Computer Name = Kopr-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 8019

Error - 28.5.2010 7:01:14 | Computer Name = Kopr-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 8019

Error - 28.5.2010 7:01:15 | Computer Name = Kopr-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 28.5.2010 7:01:15 | Computer Name = Kopr-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 9017

Error - 28.5.2010 7:01:15 | Computer Name = Kopr-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 9017

Error - 28.5.2010 7:01:16 | Computer Name = Kopr-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 28.5.2010 7:01:16 | Computer Name = Kopr-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 10016

Error - 28.5.2010 7:01:16 | Computer Name = Kopr-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 10016

[ System Events ]
Error - 26.5.2010 3:34:59 | Computer Name = Kopr-PC | Source = Service Control Manager | ID = 7016
Description = Služba NVIDIA Stereoscopic 3D Driver Service ohlásila neplatný současný
stav 0.

Error - 26.5.2010 11:37:51 | Computer Name = Kopr-PC | Source = Microsoft-Windows-HAL | ID = 12
Description = Firmware platformy při předchozím přechodu systémového napájení poškodil
paměť. Zkontrolujte dostupnost aktualizovaného firmwaru pro váš systém.

Error - 26.5.2010 21:00:12 | Computer Name = Kopr-PC | Source = Service Control Manager | ID = 7011
Description = Při čekání na odezvu transakce služby Schedule bylo dosaženo časového
limitu (30000 ms).

Error - 27.5.2010 11:02:45 | Computer Name = Kopr-PC | Source = Service Control Manager | ID = 7016
Description = Služba NVIDIA Stereoscopic 3D Driver Service ohlásila neplatný současný
stav 0.

Error - 27.5.2010 18:51:43 | Computer Name = Kopr-PC | Source = Microsoft-Windows-HAL | ID = 12
Description = Firmware platformy při předchozím přechodu systémového napájení poškodil
paměť. Zkontrolujte dostupnost aktualizovaného firmwaru pro váš systém.

Error - 28.5.2010 4:00:17 | Computer Name = Kopr-PC | Source = Schannel | ID = 36888
Description = Byla vygenerována následující výstraha o závažné chybě: 10. Stav interní
chyby: 10

Error - 28.5.2010 8:51:45 | Computer Name = Kopr-PC | Source = Schannel | ID = 36888
Description = Byla vygenerována následující výstraha o závažné chybě: 10. Stav interní
chyby: 10

Error - 28.5.2010 9:47:46 | Computer Name = Kopr-PC | Source = Service Control Manager | ID = 7016
Description = Služba NVIDIA Stereoscopic 3D Driver Service ohlásila neplatný současný
stav 0.

Error - 28.5.2010 10:25:58 | Computer Name = Kopr-PC | Source = Schannel | ID = 36888
Description = Byla vygenerována následující výstraha o závažné chybě: 10. Stav interní
chyby: 10

Error - 28.5.2010 10:34:23 | Computer Name = Kopr-PC | Source = Schannel | ID = 36888
Description = Byla vygenerována následující výstraha o závažné chybě: 10. Stav interní
chyby: 10


< End of report >

Re: pravděpodobně neznámý TSR.BOOT virus

Napsal: 28 kvě 2010 18:41
od riffman
nevim, zdali to bude fungovat...na 64bitech toho zas az tak moc nejede...
1:-Stiahni na plochu UsbFix-pripoj USB-kluce-mp3.kameru,mobil,vsetko co pouzivas cez USB
-spust>>zvol Jazyk E-[enter]
-stlac 2-[enter]>po skane log vloz sem

Re: pravděpodobně neznámý TSR.BOOT virus

Napsal: 28 kvě 2010 19:06
od koprkuba
UsbFixLog:


############################## | UsbFix V6.059 |

User : Kopr (Administrators) # KOPR-PC
Update on 01/12/2009 by Chiquitine29, C_XX & Chimay8
Start at: 19:54:01 | 28.5.2010
Website : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com

Intel(R) Core(TM) i5 CPU 750 @ 2.67GHz
Microsoft Windows 7 Professional (6.1.7600 64-bit) #
Internet Explorer 8.0.7600.16385
Windows Firewall Status : Disabled

C:\ -> Local Fixed Disk # 165,92 Go (120,98 Go free) [System] # NTFS
D:\ -> Local Fixed Disk # 299,75 Go (143,34 Go free) [Data] # NTFS
E:\ -> CD-ROM Disc
F:\ -> CD-ROM Disc # 644,12 Mo (0 Mo free) [WD SmartWare] # UDF
G:\ -> CD-ROM Disc
H:\ -> Removable Disk # 1,92 Go (1,92 Go free) [KOPRUSB] # FAT32
I:\ -> Local Fixed Disk # 930,86 Go (456,3 Go free) [Kopr's OneTera] # NTFS

############################## | Active processes |

C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe 1704
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 1760
C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe 1784
C:\Program Files (x86)\Bonjour\mDNSResponder.exe 1828
C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe 1864
C:\Program Files (x86)\Marvell\raid\Apache2\bin\httpd.exe 2164
C:\Windows\SysWOW64\PnkBstrA.exe 2392
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe 2452
C:\Program Files (x86)\Marvell\raid\Apache2\bin\httpd.exe 2496
C:\Program Files (x86)\Marvell\raid\svc\mvraidsvc.exe 2060
C:\Windows\SysWOW64\runonce.exe 3212

################## | Files # Infected Folders |

Not deleted ! C:\Windows\System32\regedit.exe
Not deleted ! F:\autorun.inf

################## | Spyware.OnlineGames |


################## | Registry # Infected Keys |


################## | Registry # Mountpoints2 |

Deleted ! HKCU\...\Explorer\MountPoints2\{c951c9a9-5496-11df-883c-6cf049030424}\Shell\AutoRun\Command

################## | Listing of the present files |

[?|?|?] C:\hiberfil.sys
[?|?|?] C:\pagefile.sys
[28.05.2010 19:54|--a------|2097] C:\UsbFix.txt
[18.06.2009 23:12|--a------|88] F:\autorun.inf
[13.10.2009 18:49|--a------|3684128] F:\Unlock.exe
[14.10.2009 23:28|--a------|3271968] F:\WD SmartWare.exe
[18.06.2009 19:06|--a------|695] F:\What is this.html

################## | Vaccination |

# C:\autorun.inf -> Folder created by UsbFix.
# D:\autorun.inf -> Folder created by UsbFix.
# I:\autorun.inf -> Folder created by UsbFix.

################## | Cracks / Keygens / Serials |

"C:\Program Files\Java\jdk1.6.0_20\bin\serialver.exe"
28.05.2010 18:03 |Size 33792 |Crc32 9744f5c4 |Md5 629a53935957c83b8a1a27362bbb59aa

"C:\Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\bin\TestPlainTextSerializer.exe"
27.03.2010 14:32 |Size 9728 |Crc32 8b373e14 |Md5 a74f9d18f0622bf31839705de86771de

"C:\Program Files (x86)\Java\jdk1.6.0_20\bin\serialver.exe"
04.05.2010 22:20 |Size 27648 |Crc32 e0fcda8b |Md5 ec4c3b01b726b36e3258b020cb16f920

"D:\Download\Software\AdobeMasterCZ\keygen\adobe_keygen_mc_cs5.exe"
30.04.2010 18:30 |Size 74752 |Crc32 d2cd1346 |Md5 3d74cfb293a6e20e00540e9f032d0c63

"I:\Games\Dragon Age Origins\Dragon Age patch, DLC, manual\patch DAO1.01\crack\daorigins.exe"
06.11.2009 01:00 |Size 9921768 |Crc32 64494b5c |Md5 cc97ec810c480b3352e361a9905c497f

"I:\Games\Fallout 3 CZ\Crack\FalloutLauncher.exe"
05.11.2008 00:27 |Size 18552088 |Crc32 5c0691f9 |Md5 9bde0f461f037126db1b820ced98a8f2

"I:\Games\Far Cry (CZ)\FarCry\Crack\FarCry.exe"
15.03.2004 18:00 |Size 32768 |Crc32 17452e46 |Md5 0a861c42d3c9fa5c01d477240e9c010d

"I:\Games\Live For Speed\LFSZ\LFS_S2X_KeyGen.exe"
22.08.2007 22:31 |Size 53248 |Crc32 c06515f8 |Md5 ac36a9d7f13a3d332408594dffed571d

"I:\Games\motoGP\moto GP\Crack\Launcher.exe"
23.10.2008 23:33 |Size 32249208 |Crc32 7d171a61 |Md5 0ec9abce8ce43cca68e6d865309fe557

"I:\Games\NeedForSpeed Undercover\Crack\nfs.exe"
18.11.2008 22:47 |Size 46601680 |Crc32 d4fcf521 |Md5 1fb7e83476dd53c94a91cef0223020c1

"I:\Games\NeedForSpeed Undercover\Crack\rld-nfsk.exe"
17.11.2008 20:58 |Size 8192 |Crc32 720dd1d0 |Md5 15fb2b770b39dcc1fd45479d7c4aef4d

"I:\Games\Red Alert 3\Crack\rld-ra3k.exe"
27.10.2008 21:09 |Size 8192 |Crc32 b91683d6 |Md5 58dcccb946605891f9d063f1e0cc16ea

"I:\Games\Wolfenstein (2009)\¬eçtina+Patch+Crack\WolfensteinLiteServer_1_1_PatchSetup.exe"
19.08.2009 13:11 |Size 31405080 |Crc32 96aa4ccd |Md5 c036efd49d5708e73ae29332737dc0af

"I:\Games\Wolfenstein (2009)\¬eçtina+Patch+Crack\Wolfenstein_1_1_PatchSetup.exe"
19.08.2009 12:57 |Size 33756536 |Crc32 a4f1375e |Md5 1e5c5a69c1bc14f628ce8d9bbb1e59e7

"I:\Games\Wolfenstein (2009)\¬eçtina+Patch+Crack\Crack v1.1\Wolf2.exe"
19.08.2009 02:51 |Size 10459787 |Crc32 d558ab82 |Md5 4b4d89bea87cf0466917bd759d96ea53

"I:\Games\Wolfenstein (2009)\¬eçtina+Patch+Crack\¬eçtina\WolfensteinBetaCz.exe"
28.08.2009 16:12 |Size 264688 |Crc32 cb084252 |Md5 e51040caa1e5e6042ac137c887790fd2

"I:\Games\HoMaM V\HEROES OF MIGHT AND MAGIC - 5 COLLECTORS EDITION CZ\Crack 1.41.rar"
-> contain : H5_Game.exe

"I:\Games\HoMaM V\HEROES OF MIGHT AND MAGIC - 5 COLLECTORS EDITION CZ\Crack 1.41.rar"
-> contain : H5_MapEditor.exe

"I:\Games\HoMaM V\HEROES OF MIGHT AND MAGIC - 5 COLLECTORS EDITION CZ\Crack 1.5.rar"
-> contain : H5_Game.exe

"I:\Games\HoMaM V\HEROES OF MIGHT AND MAGIC - 5 COLLECTORS EDITION CZ\Crack 1.5.rar"
-> contain : H5_MapEditor.exe

"I:\Games\Live For Speed\LFS_S2_ALPHA_Z_CRACK.rar"
-> contain : unlocker.exe


################## | Upload |

Please send the file : C:\Users\Kopr\Desktop\UsbFix_Upload_Me_Kopr-PC.zip : http://chiquitine.changelog.fr/Sample/Upload.php
Thank you for your contribution .

################## | ! End of report # UsbFix V6.059 ! |

Re: pravděpodobně neznámý TSR.BOOT virus

Napsal: 28 kvě 2010 19:24
od riffman
co se tyce tech cracku, to asi nema smysl komentovat, ze... :?:

C:\Windows\System32\regedit.exe otestujte na VIRUSTOTALu

(navod prosty: po nacteni stranky kliknete na tlacitko Prochazet, najdete cestu k vyse zminenemu souboru a kliknete na tlacitko Odeslat soubor, ignorujte pripadne hlasky, ze soubor byl jiz testovan a provedte sken znova; dejte skenerum nejakych deset minut; vysledek sem vlozte at uz zkopirovanim textu, nebo pripadne vlozenim odkazu po ukonceni skenu)

Re: pravděpodobně neznámý TSR.BOOT virus

Napsal: 28 kvě 2010 20:26
od koprkuba
Odkaz:

Kód: Vybrat vše

http://www.virustotal.com/cs/analisis/f318c94a46dbca88eefc3e28be51d27e5f91029dc062f56faaa995f0b5f8e518-1275074420
Antivirus;Verze;Poslední aktualizace;Výsledek
a-squared;4.5.0.50;2010.05.10;-
AhnLab-V3;2010.05.28.01;2010.05.28;-
AntiVir;8.2.1.242;2010.05.28;-
Antiy-AVL;2.0.3.7;2010.05.26;-
Authentium;5.2.0.5;2010.05.28;-
Avast;4.8.1351.0;2010.05.28;-
Avast5;5.0.332.0;2010.05.28;-
AVG;9.0.0.787;2010.05.28;-
BitDefender;7.2;2010.05.28;-
CAT-QuickHeal;10.00;2010.05.28;-
ClamAV;0.96.0.3-git;2010.05.28;-
Comodo;4942;2010.05.25;-
DrWeb;5.0.2.03300;2010.05.28;-
eSafe;7.0.17.0;2010.05.27;-
eTrust-Vet;35.2.7516;2010.05.28;-
F-Prot;4.6.0.103;2010.05.28;-
F-Secure;9.0.15370.0;2010.05.28;-
Fortinet;4.1.133.0;2010.05.28;-
GData;21;2010.05.28;-
Ikarus;T3.1.1.84.0;2010.05.28;-
Jiangmin;13.0.900;2010.05.28;-
Kaspersky;7.0.0.125;2010.05.28;-
McAfee;5.400.0.1158;2010.05.28;-
McAfee-GW-Edition;2010.1;2010.05.28;-
Microsoft;1.5802;2010.05.28;-
NOD32;5154;2010.05.28;-
Norman;6.04.12;2010.05.27;-
nProtect;2010-05-28.01;2010.05.28;-
Panda;10.0.2.7;2010.05.28;-
PCTools;7.0.3.5;2010.05.28;-
Rising;22.49.04.04;2010.05.28;-
Sophos;4.53.0;2010.05.28;-
Sunbelt;6370;2010.05.28;-
Symantec;20101.1.0.89;2010.05.28;-
TheHacker;6.5.2.0.288;2010.05.27;-
TrendMicro;9.120.0.1004;2010.05.28;-
TrendMicro-HouseCall;9.120.0.1004;2010.05.28;-
VBA32;3.12.12.5;2010.05.28;-
ViRobot;2010.5.20.2326;2010.05.28;-
VirusBuster;5.0.27.0;2010.05.28;-

Rozšiřující informace
File&nbsp;size: 398336 bytes
MD5&nbsp;&nbsp;&nbsp;: 8a4883f5e7ac37444f23279239553878
SHA1&nbsp;&nbsp;: 682214961228453c389854e81e6786df92bbfa67
SHA256: f318c94a46dbca88eefc3e28be51d27e5f91029dc062f56faaa995f0b5f8e518
PEInfo: PE Structure information<br> <br> ( base data )<br> entrypointaddress.: 0x19B0<br> timedatestamp.....: 0x4A5BC072 (Tue Jul 14 01:17:06 2009)<br> machinetype.......: 0x14C (Intel I386)<br> <br> ( 4 sections )<br> name viradd virsiz rawdsiz ntrpy md5<br> .text 0x1000 0x1B47C 0x1B600 6.43 eabe943e53e560d889b47c9fbd06af2d<br>.data 0x1D000 0x412F0 0x40800 0.01 6c9314800e405d40445be8a2676a1c27<br>.rsrc 0x5F000 0x3488 0x3600 4.28 4d2849c874343ddce5fd395c51a996ad<br>.reloc 0x63000 0x1A80 0x1C00 6.67 f84fb1a807f4c68dbec71b9e69c89866<br> <br> ( 16 imports )<br> <br>> aclui.dll: -<br>> advapi32.dll: RegSetValueExW, RegCreateKeyW, RegEnumValueW, RegDeleteValueW, RegOpenKeyW, RegEnumKeyW, RegQueryInfoKeyW, RegDeleteKeyW, RegCreateKeyExW, RegRenameKey, GetSecurityDescriptorControl, RegQueryValueExW, AdjustTokenPrivileges, LookupPrivilegeValueW, OpenProcessToken, RegSetKeySecurity, GetSecurityInfo, RegConnectRegistryW, RegRestoreKeyW, RegSaveKeyW, RegFlushKey, RegSetValueW, RegOpenKeyExW, RegUnLoadKeyW, RegLoadKeyW, MapGenericMask, GetNamedSecurityInfoW, SetSecurityDescriptorGroup, GetSecurityDescriptorGroup, SetSecurityDescriptorOwner, GetSecurityDescriptorOwner, SetSecurityDescriptorSacl, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, SetNamedSecurityInfoW, SetSecurityInfo, GetSecurityDescriptorSacl, GetSecurityDescriptorDacl, GetSidSubAuthority, GetSidSubAuthorityCount, LookupAccountSidW, GetInheritanceSourceW, InitializeAcl, IsValidSecurityDescriptor, RegSetValueExA, RegCloseKey<br>> authz.dll: AuthzInitializeResourceManager, AuthzInitializeContextFromSid, AuthzAccessCheck, AuthzFreeContext, AuthzFreeResourceManager<br>> clb.dll: ClbAddData, ClbSetColumnWidths<br>> comctl32.dll: -, -, -, -, InitCommonControlsEx, -, CreateStatusWindowW, ImageList_SetBkColor, ImageList_Create, ImageList_ReplaceIcon, -, -, -, ImageList_Destroy<br>> comdlg32.dll: GetSaveFileNameW, GetOpenFileNameW, PrintDlgExW<br>> gdi32.dll: GetTextExtentPoint32W, SetAbortProc, StartDocW, StartPage, SetViewportOrgEx, EndPage, EndDoc, AbortDoc, DeleteDC, CreateBitmap, CreatePatternBrush, PatBlt, ExcludeClipRect, SelectClipRgn, DeleteObject, SetBkColor, SetTextColor, GetTextMetricsW, SelectObject, CreateFontIndirectW, GetDeviceCaps, ExtTextOutW, GetStockObject<br>> kernel32.dll: LoadLibraryExA, InterlockedCompareExchange, GetProcAddress, DelayLoadFailureHook, MulDiv, LoadLibraryW, FreeLibrary, FileTimeToLocalFileTime, FileTimeToSystemTime, GetDateFormatW, GetTimeFormatW, MultiByteToWideChar, GetFileSize, SetFilePointer, GetLastError, OutputDebugStringW, ReadFile, CreateFileW, RegOpenKeyExA, RegQueryValueExA, ExpandEnvironmentStringsA, UnhandledExceptionFilter, TerminateProcess, GetSystemTimeAsFileTime, GetCurrentProcessId, GetCurrentThreadId, GetTickCount, QueryPerformanceCounter, GetModuleHandleA, SetUnhandledExceptionFilter, GetStartupInfoA, Sleep, InterlockedExchange, lstrcmpW, GetCurrentProcess, CloseHandle, HeapSetInformation, GetThreadLocale, GetModuleHandleW, RegisterApplicationRestart, ExitProcess, WideCharToMultiByte, WriteFile, DeleteFileW, GetCommandLineW, GetLongPathNameW, GetProcessHeap, FormatMessageW, GetWindowsDirectoryW, lstrcmpiW, LocalFree, LocalAlloc, GetComputerNameW, lstrlenW, LocalReAlloc, GlobalAlloc, GlobalLock, GlobalUnlock, SearchPathW, LoadLibraryA<br>> msvcrt.dll: _controlfp, _terminate@@YAXXZ, __set_app_type, __p__fmode, __p__commode, __setusermatherr, _amsg_exit, _initterm, _acmdln, exit, _ismbblead, _XcptFilter, _exit, _vsnwprintf, memcpy, atoi, memset, iswctype, wcschr, wcsncmp, wcsrchr, _wcsnicmp, _resetstkoflw, iswprint, _purecall, __getmainargs, _cexit, _except_handler4_common, memmove<br>> ntdll.dll: RtlInitUnicodeString, RtlIoDecodeMemIoResource, RtlCmDecodeMemIoResource, RtlFreeUnicodeString, RtlCreateUnicodeString, RtlAllocateHeap, RtlFreeHeap<br>> ole32.dll: CoCreateInstance, ReleaseStgMedium, CoInitializeEx, CoUninitialize<br>> shell32.dll: SHGetStockIconInfo, DragQueryFileW, DragFinish, ShellAboutW<br>> shlwapi.dll: StrChrIW, StrChrW, StrRChrW, -, StrToIntW, StrStrIW, -<br>> ulib.dll: _NewBuf@DSTRING@@UAEEK@Z, __1OBJECT@@UAE@XZ, _Compare@OBJECT@@UBEJPBV1@@Z, __0OBJECT@@IAE@XZ, __0DSTRING@@QAE@XZ, _Initialize@WSTRING@@QAEEPBV1@KK@Z, _Strcat@WSTRING@@QAEEPBV1@@Z, _Initialize@WSTRING@@QAEEPBGK@Z, __1DSTRING@@UAE@XZ, _SPrintfAppend@DSTRING@@UAAEPBGZZ, _Initialize@ARRAY@@QAEEKK@Z, __0ARRAY@@QAE@XZ, _Resize@DSTRING@@UAEEK@Z, _SPrintf@DSTRING@@UAAEPBGZZ<br>> user32.dll: EnableWindow, DialogBoxParamW, DrawMenuBar, InsertMenuItemW, DeleteMenu, GetKeyState, GetMenu, GetMenuItemInfoW, EndDeferWindowPos, DeferWindowPos, BeginDeferWindowPos, IsIconic, DestroyIcon, LoadImageW, GetSysColor, SetCursor, ShowCursor, ShowWindow, SetWindowPlacement, CreateWindowExW, GetProcessDefaultLayout, LoadStringW, GetMessageW, ScreenToClient, SetCursorPos, DispatchMessageW, ClientToScreen, GetDesktopWindow, LoadIconW, PostMessageW, SetMenuDefaultItem, InsertMenuW, GetMenuItemID, CheckMenuItem, UpdateWindow, RegisterClassExW, CheckDlgButton, DestroyWindow, CreateDialogParamW, DrawAnimatedRects, IntersectRect, GetClientRect, SetWindowTextW, GetMessagePos, CharNextW, TranslateMessage, TranslateAcceleratorW, LoadAcceleratorsW, SetForegroundWindow, GetLastActivePopup, BringWindowToTop, FindWindowW, GetWindow, IsDialogMessageW, PeekMessageW, CharUpperBuffW, CharUpperW, IsCharAlphaNumericW, SetWindowPos, MapWindowPoints, MoveWindow, GetSystemMetrics, GetWindowRect, GetDlgItem, SendDlgItemMessageW, SetDlgItemTextW, SetWindowLongW, DefWindowProcW, ReleaseDC, GetDC, SetScrollInfo, DestroyCaret, ReleaseCapture, KillTimer, SetCaretPos, ScrollWindowEx, InvalidateRect, CloseClipboard, SetClipboardData, EmptyClipboard, OpenClipboard, GetWindowPlacement, PostQuitMessage, GetDlgItemInt, SetMenuItemInfoW, GetWindowTextLengthW, CallWindowProcW, IsDlgButtonChecked, GetDlgItemTextW, GetClipboardData, EndDialog, GetWindowLongW, GetParent, GetWindowTextW, SendMessageW, CheckRadioButton, RegisterClipboardFormatW, LoadCursorW, ModifyMenuW, RegisterClassW, SetCapture, SetTimer, BeginPaint, EndPaint, SetFocus, LoadMenuW, GetSubMenu, EnableMenuItem, IsClipboardFormatAvailable, TrackPopupMenuEx, DestroyMenu, HideCaret, MessageBeep, CharLowerW, CreateCaret, ShowCaret<br>> uxtheme.dll: SetWindowTheme<br> <br> ( 0 exports )<br>
TrID&nbsp;&nbsp;: File type identification<br>Windows Screen Saver (39.4%)<br>Win32 Executable Generic (25.6%)<br>Win32 Dynamic Link Library (generic) (22.8%)<br>Generic Win/DOS Executable (6.0%)<br>DOS Executable Generic (6.0%)
ThreatExpert: <a href="http://www.threatexpert.com/report.aspx ... 9239553878" target="_blank">http://www.threatexpert.com/report.aspx ... 9553878</a>
ssdeep: 3072:apjBFy11Aw6Zyhurk2ilx3hLvgiuRMoiFeYOlZvGgiKzZISqQ:AhuhuIpRL5uO1FeYOlZvGgiKF1
sigcheck: publisher....: Microsoft Corporation<br>copyright....: (c) Microsoft Corporation. All rights reserved.<br>product......: Microsoft_ Windows_ Operating System<br>description..: Registry Editor<br>original name: REGEDIT.EXE<br>internal name: REGEDIT<br>file version.: 6.1.7600.16385 (win7_rtm.090713-1255)<br>comments.....: n/a<br>signers......: -<br>signing date.: -<br>verified.....: Unsigned<br>
PEiD&nbsp;&nbsp;: -
RDS&nbsp;&nbsp;&nbsp;: NSRL Reference Data Set<br>-

Co se tyče těch cracků, tak to opravdu nemá smysl: Hru si stáhnu a když se mi líbí tak si ji koupím. Něco jako plnohodnotné demo ;-)

Re: pravděpodobně neznámý TSR.BOOT virus

Napsal: 28 kvě 2010 20:50
od riffman
zeptam se hloupe - testoval jste opravdu C:\Windows\System32\regedit.exe? netestoval jste C:\Windows\regedit.exe?
Co se tyče těch cracků, tak to opravdu nemá smysl: Hru si stáhnu a když se mi líbí tak si ji koupím. Něco jako plnohodnotné demo ;)
cracky, keygeny a podobne bordely jsou velmi castym zdrojem infekce

Re: pravděpodobně neznámý TSR.BOOT virus

Napsal: 28 kvě 2010 21:17
od koprkuba
Opravdu C:/Windows/System32/regedit.exe
Pro jistotu jsem to spustil znovu a stále výsledek 0/41

ano opravdu bývají zdrojem infekce, ale mám osvědčenou metodu jak toto riziko minimalizovat.

Re: pravděpodobně neznámý TSR.BOOT virus

Napsal: 28 kvě 2010 21:21
od riffman
ja vam to rozmlouvat nebudu

http://www.viry.cz/forum/viewtopic.php?f=29&t=58179

stahnout, nainstalovat, spustit, nechat probehnout sken a pak dle navodu vlozit ten spravny kus logu