Stránka 1 z 2

prosím o kontrolu logu / otváranie stránok

Napsal: 14 črc 2010 11:55
od SSemteXX
No takže pred pár dňami som si všimol jeden odkaz na stránke, proste neviem ako nikdy som to neurobil ale bola to reklama na jeden blog, no práveže to bolo len napísané, že "Click here to visit my blog!" ja som tam klikol a načítala sa mi prázdna stránka a odvtedy asi každý deň 5-6 krát pri zapnutí Firefox-u mi naskočí nejaká podivná stránka. Ešte v živote som takúto chybu neurobil, som dosť skúsený na to aby som vedel obísť hociaký problém, ale toto neviem ako sa mohlo stať. Používam Aviru a Firewall Sygate, oba som mal zapnuté no Avira po skončení testu nenašla nič, skúsil som Eset Online Scanner a ten našiel 3 infiltrácie, aj to bolo cracky hier. Z histórii som si skopíroval tú stránku ktorá sa mi otvára, dúfam, že aspoň niečo pomôže.
http://cellulitous.com/?xurl=http://hyt ... button.y=0

btw. prikladám log, dúfam, že mi viete pomôcť. Ďakujem

Logfile of random's system information tool 1.08 (written by random/random)
Run by Marian at 2010-07-14 12:48:53
Microsoft Windows XP Professional Service Pack 3
System drive C: has 12 GB (15%) free of 76 GB
Total RAM: 2047 MB (55% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:50:00, on 14. 7. 2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 SP3 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\PixArt\PAC7302\Monitor.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\PROGRA~1\TRUETR~1\TrueTransparency.exe
C:\PROGRA~1\ViStart\ViStart.exe
C:\PROGRA~1\ViGlance\ViGlance.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\PROGRA~1\ViSplore\ViSplore.exe
C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Marian\Desktop\RSIT.exe
C:\Program Files\trend micro\Marian.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live bejelentkezési segítség - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\PAC7302\Monitor.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [vilaunch] C:\WINDOWS\system32\vilaunch.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [TrueTransparency] "C:\PROGRA~1\TRUETR~1\TrueTransparency.exe"
O4 - HKCU\..\Run: [ViStart] C:\PROGRA~1\ViStart\ViStart.exe
O4 - HKCU\..\Run: [ViGlance] C:\PROGRA~1\ViGlance\ViGlance.exe
O4 - HKUS\S-1-5-18\..\Run: [JDK5SWFMZY] C:\WINDOWS\TEMP\Smr.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [JDK5SWFMZY] C:\WINDOWS\TEMP\Smr.exe (User 'Default user')
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftup ... 8516750203
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 8516739375
O17 - HKLM\System\CCS\Services\Tcpip\..\{16E39F2B-0996-4D5E-A3D6-5F83CA2E0C43}: NameServer = 195.168.69.136 195.168.69.139
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: Sony Ericsson OMSI download service (OMSI download service) - Unknown owner - C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe

--
End of file - 7958 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\At1.job
C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
C:\WINDOWS\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2007-11-06 322880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live bejelentkezési segítség - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-04-12 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-04-12 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2007-11-06 542016]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"PAC7302_Monitor"=C:\WINDOWS\PixArt\PAC7302\Monitor.exe [2006-11-03 319488]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-05-04 102400]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2010-06-08 19552872]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2010-03-02 282792]
"vilaunch"=C:\WINDOWS\system32\vilaunch.exe [2009-09-09 146412]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-04-04 36272]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-03-24 952768]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-05-07 1277440]
"TrueTransparency"=C:\PROGRA~1\TRUETR~1\TrueTransparency.exe [2009-10-15 356352]
"ViStart"=C:\PROGRA~1\ViStart\ViStart.exe [2009-11-20 798720]
"ViGlance"=C:\PROGRA~1\ViGlance\ViGlance.exe [2009-11-07 438272]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-03-24 952768]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-04-04 36272]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe [2007-09-20 202024]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2010-06-03 1144104]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DrvIcon]
C:\Program Files\Vista Drive Icon\DrvIcon.exe [2008-04-13 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-10-14 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [2007-08-22 80896]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2007-09-20 1836328]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [2007-03-01 153136]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Octoshape Streaming Services]
C:\Documents and Settings\Marian\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe [2009-01-08 70936]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlayBar]
C:\Program Files\Playbar\playbar.exe rejtett []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmcService]
C:\PROGRA~1\Sygate\SPF\smc.exe [2004-10-15 2577632]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe [2009-09-24 434176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2007-10-14 214360]

C:\Documents and Settings\Marian\Start Menu\Programs\Startup
Stardock ObjectDock.lnk - C:\Program Files\Stardock\ObjectDock\ObjectDock.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2010-05-05 159744]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 239496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2009-01-30 133632]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\HLSW\hlsw.exe"="C:\Program Files\HLSW\hlsw.exe:*:Enabled:HLSW Application"
"C:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe"="C:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe:*:Enabled:CoD2MP_s"
"C:\Program Files\mIRC\mirc.exe"="C:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\SopCast\SopCast.exe"="C:\Program Files\SopCast\SopCast.exe:*:Enabled:SopCast Main Application"
"C:\Program Files\SopCast\adv\SopAdver.exe"="C:\Program Files\SopCast\adv\SopAdver.exe:*:Enabled:SopCast Adver"
"C:\Program Files\Valve\Steam\Steam.exe"="C:\Program Files\Valve\Steam\Steam.exe:*:Enabled:Steam"
"C:\Program Files\VirtualDJ\virtualdj_trial.exe"="C:\Program Files\VirtualDJ\virtualdj_trial.exe:*:Enabled:VirtualDJ"
"C:\Program Files\KONAMI\Pro Evolution Soccer 2010\pes2010.exe"="C:\Program Files\KONAMI\Pro Evolution Soccer 2010\pes2010.exe:*:Enabled:Pro Evolution Soccer 2010"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\WINDOWS\system32\usmt\migwiz.exe"="C:\WINDOWS\system32\usmt\migwiz.exe:*:Enabled:Files and Settings Transfer Wizard"
"C:\Program Files\Ubisoft\Tom Clancy's Splinter Cell Conviction\src\system\conviction_game.exe"="C:\Program Files\Ubisoft\Tom Clancy's Splinter Cell Conviction\src\system\conviction_game.exe:*:Enabled:conviction_game"
"C:\Program Files\Electronic Arts\Battlefield Bad Company 2\BFBC2Updater.exe"="C:\Program Files\Electronic Arts\Battlefield Bad Company 2\BFBC2Updater.exe:*:Enabled:Battlefield: Bad Company™ 2"
"C:\Documents and Settings\Marian\Desktop\RatioMaster.NET.exe"="C:\Documents and Settings\Marian\Desktop\RatioMaster.NET.exe:*:Enabled:RatioMaster.NET"
"C:\Documents and Settings\Marian\My Documents\Prgr\RatioMaster.NET.exe"="C:\Documents and Settings\Marian\My Documents\Prgr\RatioMaster.NET.exe:*:Enabled:RatioMaster.NET"
"C:\Program Files\Eidos\Batman Arkham Asylum\Binaries\ShippingPC-BmGame.exe"="C:\Program Files\Eidos\Batman Arkham Asylum\Binaries\ShippingPC-BmGame.exe:*:Enabled:BmGame"
"C:\Documents and Settings\Marian\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe"="C:\Documents and Settings\Marian\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe:*:Enabled:Main program for Octoshape client"
"C:\Program Files\PESEdit\2010 FIFA World Cup Patch\pes2010.exe"="C:\Program Files\PESEdit\2010 FIFA World Cup Patch\pes2010.exe:*:Enabled:Pro Evolution Soccer 2010"
"C:\Program Files\Valve\Steam\SteamApps\ssementexx\ricochet\hl.exe"="C:\Program Files\Valve\Steam\SteamApps\ssementexx\ricochet\hl.exe:*:Enabled:Ricochet"
"C:\Program Files\Codemasters\Colin McRae DiRT 2\dirt2_game.exe"="C:\Program Files\Codemasters\Colin McRae DiRT 2\dirt2_game.exe:*:Enabled:DiRT2 Executable"
"C:\Program Files\Valve\Steam\SteamApps\common\trackmania nations forever\TmForever.exe"="C:\Program Files\Valve\Steam\SteamApps\common\trackmania nations forever\TmForever.exe:*:Enabled:TrackMania Nations Forever"
"C:\Program Files\Valve\Steam\SteamApps\common\trackmania nations forever\TmForeverLauncher.exe"="C:\Program Files\Valve\Steam\SteamApps\common\trackmania nations forever\TmForeverLauncher.exe:*:Enabled:TrackMania Nations Forever"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\TeamViewer\Version5\TeamViewer.exe"="C:\Program Files\TeamViewer\Version5\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application"
"C:\Program Files\Valve\Steam\SteamApps\ssementexx\counter-strike\hl.exe"="C:\Program Files\Valve\Steam\SteamApps\ssementexx\counter-strike\hl.exe:*:Enabled:Counter-Strike"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

======File associations======

.scr - open - C:\WINDOWS\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 months======

2010-07-12 21:00:45 ----A---- C:\WINDOWS\system32\sshnas21.dll
2010-07-12 20:39:59 ----D---- C:\Program Files\Valve
2010-07-12 16:21:36 ----D---- C:\Documents and Settings\All Users\Application Data\Trymedia
2010-07-11 19:27:08 ----D---- C:\Program Files\KONAMI
2010-07-11 19:27:07 ----D---- C:\Documents and Settings\All Users\Application Data\KONAMI
2010-07-11 17:55:58 ----N---- C:\WINDOWS\system32\spmsg.dll
2010-07-11 17:55:08 ----HDC---- C:\WINDOWS\$NtUninstallwmp11$
2010-07-11 17:08:54 ----D---- C:\Documents and Settings\Marian\Application Data\vlc
2010-07-10 15:56:44 ----D---- C:\Program Files\PCSX2 0.9.7
2010-07-08 19:27:57 ----A---- C:\WINDOWS\system32\javaws.exe
2010-07-08 19:27:57 ----A---- C:\WINDOWS\system32\javaw.exe
2010-07-08 19:27:57 ----A---- C:\WINDOWS\system32\java.exe
2010-07-08 19:27:57 ----A---- C:\WINDOWS\system32\deployJava1.dll
2010-07-08 16:05:42 ----D---- C:\Documents and Settings\Marian\Application Data\ViSplore
2010-07-08 16:05:41 ----D---- C:\Documents and Settings\Marian\Application Data\ViStart
2010-07-08 16:05:41 ----D---- C:\Documents and Settings\Marian\Application Data\ViGlance
2010-07-08 16:05:35 ----D---- C:\WINDOWS\system32\VIRepair
2010-07-08 16:02:59 ----D---- C:\Program Files\ViSplore
2010-07-08 16:02:59 ----D---- C:\Program Files\TrueTransparency
2010-07-08 16:02:59 ----A---- C:\WINDOWS\system32\viwc.exe
2010-07-08 16:02:59 ----A---- C:\WINDOWS\system32\vilaunch.exe
2010-07-08 16:02:56 ----D---- C:\Program Files\WinFlip
2010-07-08 16:02:56 ----D---- C:\Program Files\ViStart
2010-07-08 16:02:56 ----D---- C:\Program Files\Vista Rainbar
2010-07-08 16:02:56 ----D---- C:\Program Files\ViGlance
2010-07-08 16:02:55 ----D---- C:\Program Files\Vista Drive Icon
2010-07-08 16:00:25 ----D---- C:\WINDOWS\system32\VITrans
2010-07-08 16:00:25 ----D---- C:\VTPFiles
2010-07-08 16:00:25 ----A---- C:\WINDOWS\system32\Uharc.exe
2010-07-08 16:00:25 ----A---- C:\WINDOWS\system32\reico.exe
2010-07-08 16:00:25 ----A---- C:\WINDOWS\system32\moveex.exe
2010-07-08 16:00:25 ----A---- C:\WINDOWS\system32\modifype.exe
2010-07-08 16:00:24 ----A---- C:\WINDOWS\system32\pskill.exe
2010-07-08 15:59:49 ----A---- C:\WINDOWS\system32\scrnrdr.exe
2010-07-07 20:34:23 ----HDC---- C:\WINDOWS\$NtUninstallKB979559$
2010-07-07 20:31:07 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2010-07-07 20:27:56 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2010-07-07 20:27:50 ----HDC---- C:\WINDOWS\$NtUninstallKB980195$
2010-07-07 20:24:43 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2010-07-07 20:23:41 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$
2010-07-07 20:23:35 ----HDC---- C:\WINDOWS\$NtUninstallKB981793$
2010-07-07 20:23:30 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2010-07-07 20:19:50 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-07-07 20:19:41 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2010-07-07 20:19:35 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-07-07 20:19:30 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-07-07 20:19:20 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2010-07-07 20:19:16 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-07-07 20:18:53 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2010-07-07 20:18:46 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-07-07 20:18:42 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-07-07 20:18:36 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-07-07 20:18:29 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-07-07 20:18:22 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-07-07 20:18:18 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-07-07 20:18:13 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-07-07 20:18:01 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2010-07-07 20:17:56 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-07-07 20:17:51 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2010-07-07 20:17:46 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2010-07-07 20:17:39 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2010-07-07 20:17:34 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2010-07-07 20:17:29 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2010-07-07 20:17:23 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2010-07-07 20:17:20 ----D---- C:\Program Files\MSXML 4.0
2010-07-07 20:17:10 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2010-07-07 20:17:07 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2010-07-07 20:17:03 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2010-07-07 20:16:58 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2010-07-07 20:16:54 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2010-07-07 20:16:50 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2010-07-07 20:16:46 ----D---- C:\WINDOWS\ie8updates
2010-07-07 20:16:40 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2010-07-07 20:16:36 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2010-07-07 20:16:30 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2010-07-07 20:16:21 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2010-07-07 20:16:14 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2010-07-07 20:16:03 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2010-07-07 20:15:52 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2010-07-07 20:15:46 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
2010-07-07 20:15:28 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2010-07-07 20:15:21 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2010-07-07 20:15:12 ----HDC---- C:\WINDOWS\$NtUninstallKB961503$
2010-07-07 20:14:58 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2010-07-07 20:14:46 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2010-07-07 20:14:25 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2010-07-07 20:13:50 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2010-07-07 20:13:27 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2010-07-07 20:11:39 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2010-07-07 20:11:35 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2010-07-07 20:11:13 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2010-07-07 20:11:08 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2010-07-07 20:11:03 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2010-07-07 20:10:58 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
2010-07-07 20:10:53 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2010-07-07 20:10:48 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2010-07-07 20:10:43 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2010-07-07 20:10:38 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2010-07-07 20:10:34 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2010-07-07 20:10:30 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2010-07-07 20:10:24 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
2010-07-07 20:10:07 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2010-07-07 20:10:01 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2010-07-07 20:09:56 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2010-07-07 20:09:51 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2010-07-07 20:09:43 ----HDC---- C:\WINDOWS\$NtUninstallKB950760$
2010-07-07 20:06:49 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2010-07-07 19:39:43 ----N---- C:\WINDOWS\system32\browserchoice.exe
2010-07-07 19:03:36 ----N---- C:\WINDOWS\system32\xpsp4res.dll
2010-07-07 17:33:17 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2010-07-07 17:33:17 ----A---- C:\WINDOWS\system32\wucltui.dll.mui
2010-07-07 17:33:17 ----A---- C:\WINDOWS\system32\wuaueng.dll.mui
2010-07-07 17:33:17 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
2010-07-05 13:42:02 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2010-07-05 13:40:51 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2010-07-05 13:40:33 ----D---- C:\6c15930dff31220c866b2810ba
2010-07-05 13:40:28 ----D---- C:\WINDOWS\system32\LogFiles
2010-07-05 13:40:28 ----D---- C:\WINDOWS\system32\drivers\UMDF
2010-07-05 13:40:23 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2010-07-05 13:40:11 ----D---- C:\1132aea08f7be422c351
2010-07-05 13:35:27 ----A---- C:\WINDOWS\system32\antiwpa.dll107EC54
2010-07-05 13:31:22 ----A---- C:\WINDOWS\system32\LegitCheckControl.dll
2010-07-05 13:26:51 ----D---- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2010-07-05 13:23:45 ----D---- C:\Program Files\VistaExperience.org
2010-07-05 13:21:19 ----A---- C:\WINDOWS\system32\lcid.exe
2010-07-05 13:14:00 ----D---- C:\Program Files\Alky for Applications
2010-07-03 16:04:46 ----D---- C:\Program Files\AnvSoft
2010-06-30 20:33:32 ----A---- C:\WINDOWS\system32\wmpns.dll
2010-06-30 20:30:52 ----D---- C:\WINDOWS\Prefetch
2010-06-30 20:27:06 ----HDC---- C:\WINDOWS\$NtUninstallKB938759$
2010-06-30 20:22:48 ----A---- C:\WINDOWS\system32\msxml6r.dll
2010-06-30 20:22:38 ----N---- C:\WINDOWS\system32\drivers\irbus.sys
2010-06-30 20:22:38 ----N---- C:\WINDOWS\system32\comsdupd.exe
2010-06-30 20:22:37 ----N---- C:\WINDOWS\system32\smtpapi.dll
2010-06-30 20:22:37 ----N---- C:\WINDOWS\system32\rwnh.dll
2010-06-30 20:22:33 ----N---- C:\WINDOWS\system32\credssp.dll
2010-06-30 20:22:33 ----N---- C:\WINDOWS\system32\bitsprx4.dll
2010-06-30 20:22:33 ----N---- C:\WINDOWS\system32\azroles.dll
2010-06-30 20:22:33 ----N---- C:\WINDOWS\system32\ativtmxx.dll
2010-06-30 20:22:33 ----N---- C:\WINDOWS\system32\ati3d1ag.dll
2010-06-30 20:22:33 ----N---- C:\WINDOWS\system32\ati2dvaa.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\eapsvc.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\eapqec.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\eappprxy.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\eapphost.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\eappgnui.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\eappcfg.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\eapp3hst.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\eapolqec.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\dot3ui.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\dot3svc.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\dot3msm.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\dot3dlg.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\dot3cfg.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\dot3api.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\dimsroam.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\dimsntfy.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\dhcpqec.dll
2010-06-30 20:22:31 ----N---- C:\WINDOWS\system32\ieencode.dll
2010-06-30 20:22:31 ----N---- C:\WINDOWS\system32\hsfcisp2.dll
2010-06-30 20:22:30 ----N---- C:\WINDOWS\system32\mdmxsdk.dll
2010-06-30 20:22:30 ----N---- C:\WINDOWS\system32\l2gpstore.dll
2010-06-30 20:22:30 ----N---- C:\WINDOWS\system32\kmsvc.dll
2010-06-30 20:22:29 ----N---- C:\WINDOWS\system32\onex.dll
2010-06-30 20:22:29 ----N---- C:\WINDOWS\system32\nv4_disp.dll
2010-06-30 20:22:29 ----N---- C:\WINDOWS\system32\napstat.exe
2010-06-30 20:22:29 ----N---- C:\WINDOWS\system32\napmontr.dll
2010-06-30 20:22:29 ----N---- C:\WINDOWS\system32\napipsec.dll
2010-06-30 20:22:29 ----N---- C:\WINDOWS\system32\mtxparhd.dll
2010-06-30 20:22:29 ----N---- C:\WINDOWS\system32\msshavmsg.dll
2010-06-30 20:22:29 ----N---- C:\WINDOWS\system32\mssha.dll
2010-06-30 20:22:28 ----N---- C:\WINDOWS\system32\slserv.exe
2010-06-30 20:22:28 ----N---- C:\WINDOWS\system32\slrundll.exe
2010-06-30 20:22:28 ----N---- C:\WINDOWS\system32\slgen.dll
2010-06-30 20:22:28 ----N---- C:\WINDOWS\system32\slextspk.dll
2010-06-30 20:22:28 ----N---- C:\WINDOWS\system32\slcoinst.dll
2010-06-30 20:22:28 ----N---- C:\WINDOWS\system32\setupn.exe
2010-06-30 20:22:28 ----N---- C:\WINDOWS\system32\s3gnb.dll
2010-06-30 20:22:28 ----N---- C:\WINDOWS\system32\rasqec.dll
2010-06-30 20:22:28 ----N---- C:\WINDOWS\system32\qutil.dll
2010-06-30 20:22:28 ----N---- C:\WINDOWS\system32\qcliprov.dll
2010-06-30 20:22:28 ----N---- C:\WINDOWS\system32\qagentrt.dll
2010-06-30 20:22:28 ----N---- C:\WINDOWS\system32\qagent.dll
2010-06-30 20:22:27 ----N---- C:\WINDOWS\system32\tzchange.exe
2010-06-30 20:22:27 ----N---- C:\WINDOWS\system32\tspkg.dll
2010-06-30 20:22:24 ----N---- C:\WINDOWS\slrundll.exe
2010-06-30 20:22:23 ----D---- C:\WINDOWS\system32\scripting
2010-06-30 20:22:22 ----D---- C:\WINDOWS\system32\bits
2010-06-30 20:19:19 ----D---- C:\WINDOWS\ServicePackFiles
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\ati1tuxx.sys
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\ati1ttxx.sys
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\ati1snxx.sys
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\ati1rvxx.sys
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\ati1raxx.sys
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\ati1pdxx.sys
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\ati1mdxx.sys
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\ati1btxx.sys
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\amdagp.sys
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\alim1541.sys
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\agpcpq.sys
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\agp440.sys
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\adv11nt5.dll
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\adv09nt5.dll
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\adv08nt5.dll
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\adv07nt5.dll
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\adv05nt5.dll
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\adv02nt5.dll
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\adv01nt5.dll
2010-06-30 20:15:45 ----N---- C:\WINDOWS\system32\drivers\atv04nt5.dll
2010-06-30 20:15:45 ----N---- C:\WINDOWS\system32\drivers\atv02nt5.dll
2010-06-30 20:15:45 ----N---- C:\WINDOWS\system32\drivers\atv01nt5.dll
2010-06-30 20:15:45 ----N---- C:\WINDOWS\system32\drivers\atinxsxx.sys
2010-06-30 20:15:45 ----N---- C:\WINDOWS\system32\drivers\atinxbxx.sys
2010-06-30 20:15:45 ----N---- C:\WINDOWS\system32\drivers\atintuxx.sys
2010-06-30 20:15:45 ----N---- C:\WINDOWS\system32\drivers\atinttxx.sys
2010-06-30 20:15:45 ----N---- C:\WINDOWS\system32\drivers\atinsnxx.sys
2010-06-30 20:15:45 ----N---- C:\WINDOWS\system32\drivers\atinrvxx.sys
2010-06-30 20:15:45 ----N---- C:\WINDOWS\system32\drivers\atinraxx.sys
2010-06-30 20:15:45 ----N---- C:\WINDOWS\system32\drivers\atinpdxx.sys
2010-06-30 20:15:45 ----N---- C:\WINDOWS\system32\drivers\atinmdxx.sys
2010-06-30 20:15:45 ----N---- C:\WINDOWS\system32\drivers\atinbtxx.sys
2010-06-30 20:15:45 ----N---- C:\WINDOWS\system32\drivers\ati2mtaa.sys
2010-06-30 20:15:45 ----N---- C:\WINDOWS\system32\drivers\ati1xsxx.sys
2010-06-30 20:15:45 ----N---- C:\WINDOWS\system32\drivers\ati1xbxx.sys
2010-06-30 20:15:44 ----N---- C:\WINDOWS\system32\drivers\ch7xxnt5.dll
2010-06-30 20:15:44 ----N---- C:\WINDOWS\system32\drivers\bthusb.sys
2010-06-30 20:15:44 ----N---- C:\WINDOWS\system32\drivers\bthprint.sys
2010-06-30 20:15:44 ----N---- C:\WINDOWS\system32\drivers\bthport.sys
2010-06-30 20:15:44 ----N---- C:\WINDOWS\system32\drivers\bthpan.sys
2010-06-30 20:15:44 ----N---- C:\WINDOWS\system32\drivers\bthmodem.sys
2010-06-30 20:15:44 ----N---- C:\WINDOWS\system32\drivers\bthenum.sys
2010-06-30 20:15:44 ----N---- C:\WINDOWS\system32\drivers\atv10nt5.dll
2010-06-30 20:15:44 ----N---- C:\WINDOWS\system32\drivers\atv06nt5.dll
2010-06-30 20:15:43 ----N---- C:\WINDOWS\system32\drivers\hidbth.sys
2010-06-30 20:15:43 ----N---- C:\WINDOWS\system32\drivers\gagp30kx.sys
2010-06-30 20:15:42 ----N---- C:\WINDOWS\system32\drivers\mdmxsdk.sys
2010-06-30 20:15:42 ----N---- C:\WINDOWS\system32\drivers\hsfdpsp2.sys
2010-06-30 20:15:42 ----N---- C:\WINDOWS\system32\drivers\hsfcxts2.sys
2010-06-30 20:15:42 ----N---- C:\WINDOWS\system32\drivers\hsfbs2s2.sys
2010-06-30 20:15:42 ----N---- C:\WINDOWS\system32\drivers\hidir.sys
2010-06-30 20:15:41 ----N---- C:\WINDOWS\system32\drivers\rfcomm.sys
2010-06-30 20:15:41 ----N---- C:\WINDOWS\system32\drivers\recagent.sys
2010-06-30 20:15:41 ----N---- C:\WINDOWS\system32\drivers\nv4_mini.sys
2010-06-30 20:15:41 ----N---- C:\WINDOWS\system32\drivers\ntmtlfax.sys
2010-06-30 20:15:41 ----N---- C:\WINDOWS\system32\drivers\mutohpen.sys
2010-06-30 20:15:41 ----N---- C:\WINDOWS\system32\drivers\mtxparhm.sys
2010-06-30 20:15:41 ----N---- C:\WINDOWS\system32\drivers\mtlstrm.sys
2010-06-30 20:15:41 ----N---- C:\WINDOWS\system32\drivers\mtlmnt5.sys
2010-06-30 20:15:40 ----N---- C:\WINDOWS\system32\drivers\slnthal.sys
2010-06-30 20:15:40 ----N---- C:\WINDOWS\system32\drivers\slntamr.sys
2010-06-30 20:15:40 ----N---- C:\WINDOWS\system32\drivers\slnt7554.sys
2010-06-30 20:15:40 ----N---- C:\WINDOWS\system32\drivers\sisagp.sys
2010-06-30 20:15:40 ----N---- C:\WINDOWS\system32\drivers\siint5.dll
2010-06-30 20:15:40 ----N---- C:\WINDOWS\system32\drivers\sffp_mmc.sys
2010-06-30 20:15:40 ----N---- C:\WINDOWS\system32\drivers\s3gnbm.sys
2010-06-30 20:15:40 ----N---- C:\WINDOWS\system32\drivers\rndismpx.sys
2010-06-30 20:15:39 ----N---- C:\WINDOWS\system32\drivers\usb8023x.sys
2010-06-30 20:15:39 ----N---- C:\WINDOWS\system32\drivers\uagp35.sys
2010-06-30 20:15:39 ----N---- C:\WINDOWS\system32\drivers\smbali.sys
2010-06-30 20:15:39 ----N---- C:\WINDOWS\system32\drivers\slwdmsup.sys
2010-06-30 20:15:38 ----N---- C:\WINDOWS\system32\drivers\watv10nt.sys
2010-06-30 20:15:38 ----N---- C:\WINDOWS\system32\drivers\watv06nt.sys
2010-06-30 20:15:38 ----N---- C:\WINDOWS\system32\drivers\wadv11nt.sys
2010-06-30 20:15:38 ----N---- C:\WINDOWS\system32\drivers\wadv09nt.sys
2010-06-30 20:15:38 ----N---- C:\WINDOWS\system32\drivers\wadv08nt.sys
2010-06-30 20:15:38 ----N---- C:\WINDOWS\system32\drivers\wadv07nt.sys
2010-06-30 20:15:38 ----N---- C:\WINDOWS\system32\drivers\wacompen.sys
2010-06-30 20:15:38 ----N---- C:\WINDOWS\system32\drivers\viaagp.sys
2010-06-30 20:15:38 ----N---- C:\WINDOWS\system32\drivers\vchnt5.dll
2010-06-30 20:15:38 ----N---- C:\WINDOWS\system32\drivers\usbvideo.sys
2010-06-30 20:13:05 ----A---- C:\WINDOWS\003321_.tmp
2010-06-30 20:10:09 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2010-06-30 18:51:03 ----D---- C:\Program Files\Ubisoft
2010-06-30 18:23:08 ----D---- C:\WINDOWS\WBEM
2010-06-30 18:20:37 ----HDC---- C:\WINDOWS\ie8
2010-06-30 18:18:40 ----HDC---- C:\WINDOWS\$NtUninstallKB932823-v3$
2010-06-30 17:38:05 ----D---- C:\Program Files\trend micro
2010-06-30 17:38:04 ----D---- C:\rsit
2010-06-30 13:33:13 ----A---- C:\WINDOWS\system32\unins000.exe
2010-06-30 13:33:13 ----A---- C:\WINDOWS\system32\camcodec.dll
2010-06-30 13:32:00 ----D---- C:\Program Files\CamStudio
2010-06-30 12:57:46 ----D---- C:\Program Files\Desktop Activity Recorder
2010-06-28 16:46:52 ----D---- C:\Program Files\Oxin's Style!
2010-06-27 15:24:53 ----A---- C:\WINDOWS\system32\drivers\wg6n.sys
2010-06-27 15:24:52 ----A---- C:\WINDOWS\system32\drivers\wg5n.sys
2010-06-27 15:24:52 ----A---- C:\WINDOWS\system32\drivers\wg4n.sys
2010-06-27 15:24:52 ----A---- C:\WINDOWS\system32\drivers\wg3n.sys
2010-06-27 15:24:51 ----A---- C:\WINDOWS\system32\drivers\wpsdrvnt.sys
2010-06-27 15:24:51 ----A---- C:\WINDOWS\system32\drivers\Teefer.sys
2010-06-27 15:24:49 ----A---- C:\WINDOWS\system32\SSSensor.dll
2010-06-27 15:24:46 ----D---- C:\Program Files\Sygate
2010-06-27 15:12:42 ----HDC---- C:\WINDOWS\$NtUninstallKB894391$
2010-06-26 14:55:44 ----D---- C:\Program Files\City Interactive
2010-06-24 17:31:44 ----D---- C:\Documents and Settings\All Users\Application Data\TrackMania
2010-06-24 14:45:27 ----D---- C:\Program Files\NVIDIA Corporation
2010-06-23 19:17:23 ----D---- C:\Documents and Settings\Marian\Application Data\Avira
2010-06-23 19:08:06 ----A---- C:\WINDOWS\system32\drivers\ssmdrv.sys
2010-06-23 19:08:01 ----A---- C:\WINDOWS\system32\drivers\avipbb.sys
2010-06-23 19:08:01 ----A---- C:\WINDOWS\system32\drivers\avgntmgr.sys
2010-06-23 19:08:01 ----A---- C:\WINDOWS\system32\drivers\avgntflt.sys
2010-06-23 19:08:01 ----A---- C:\WINDOWS\system32\drivers\avgntdd.sys
2010-06-23 19:07:59 ----D---- C:\Program Files\Avira
2010-06-23 19:07:59 ----D---- C:\Documents and Settings\All Users\Application Data\Avira
2010-06-23 18:40:14 ----D---- C:\Program Files\ESET
2010-06-23 13:59:45 ----D---- C:\Documents and Settings\Marian\Application Data\FUEL
2010-06-23 12:25:28 ----A---- C:\WINDOWS\ModemLog_Communications cable between two computers.txt
2010-06-22 21:19:02 ----D---- C:\Documents and Settings\All Users\Application Data\Codemasters
2010-06-22 19:59:04 ----D---- C:\Program Files\Codemasters
2010-06-22 19:49:28 ----A---- C:\WINDOWS\vncutil.exe
2010-06-22 19:49:23 ----A---- C:\WINDOWS\system32\RtkCoInstXP.dll
2010-06-22 19:49:23 ----A---- C:\WINDOWS\RtkAudioService.exe
2010-06-22 19:49:20 ----A---- C:\WINDOWS\system32\drivers\Monfilt.sys
2010-06-22 19:49:15 ----A---- C:\WINDOWS\system32\drivers\Ambfilt.sys
2010-06-22 17:29:01 ----A---- C:\WINDOWS\system32\wrap_oal.dll
2010-06-22 17:29:01 ----A---- C:\WINDOWS\system32\OpenAL32.dll
2010-06-22 17:05:43 ----A---- C:\WINDOWS\system32\XAudio2_7.dll
2010-06-22 17:05:43 ----A---- C:\WINDOWS\system32\XAPOFX1_5.dll
2010-06-22 17:05:42 ----A---- C:\WINDOWS\system32\xactengine3_7.dll
2010-06-22 17:05:42 ----A---- C:\WINDOWS\system32\D3DCompiler_43.dll
2010-06-22 17:05:41 ----A---- C:\WINDOWS\system32\d3dx11_43.dll
2010-06-22 17:05:41 ----A---- C:\WINDOWS\system32\d3dcsx_43.dll
2010-06-22 17:05:38 ----A---- C:\WINDOWS\system32\d3dx10_43.dll
2010-06-22 17:05:34 ----A---- C:\WINDOWS\system32\D3DX9_43.dll
2010-06-22 17:04:44 ----HD---- C:\WINDOWS\msdownld.tmp
2010-06-19 14:25:50 ----D---- C:\Program Files\Activision
2010-06-16 15:35:52 ----D---- C:\Documents and Settings\Marian\Application Data\bizarre creations
2010-06-15 20:41:32 ----D---- C:\Documents and Settings\Marian\Application Data\Octoshape

======List of files/folders modified in the last 1 months======

2010-07-14 11:37:18 ----D---- C:\WINDOWS\Temp
2010-07-14 11:37:17 ----D---- C:\WINDOWS\system32\CatRoot2
2010-07-13 23:46:28 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-07-13 21:35:23 ----D---- C:\WINDOWS\system32
2010-07-13 21:33:25 ----D---- C:\WINDOWS
2010-07-13 21:27:27 ----D---- C:\WINDOWS\system32\config
2010-07-13 16:54:52 ----D---- C:\Documents and Settings\Marian\Application Data\uTorrent
2010-07-13 15:14:38 ----D---- C:\Program Files\Playbar
2010-07-13 14:31:33 ----RD---- C:\Program Files
2010-07-13 14:28:08 ----SHD---- C:\System Volume Information
2010-07-13 14:26:38 ----D---- C:\WINDOWS\system32\NtmsData
2010-07-13 14:11:32 ----D---- C:\WINDOWS\Registration
2010-07-13 00:03:48 ----D---- C:\Documents and Settings\Marian\Application Data\mIRC
2010-07-12 23:12:32 ----D---- C:\Program Files\mIRC
2010-07-12 21:01:02 ----SD---- C:\WINDOWS\Tasks
2010-07-12 20:41:36 ----SHD---- C:\WINDOWS\Installer
2010-07-12 15:46:08 ----D---- C:\WINDOWS\Minidump
2010-07-12 15:38:39 ----D---- C:\WINDOWS\system32\DirectX
2010-07-11 17:56:06 ----D---- C:\WINDOWS\system32\CatRoot
2010-07-11 17:55:59 ----HD---- C:\WINDOWS\inf
2010-07-11 17:55:31 ----A---- C:\WINDOWS\win.ini
2010-07-11 17:55:23 ----D---- C:\Program Files\Windows Media Connect 2
2010-07-11 17:55:21 ----D---- C:\Program Files\Windows Media Player
2010-07-11 17:55:18 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-07-11 17:55:18 ----D---- C:\WINDOWS\Help
2010-07-11 17:54:24 ----D---- C:\WINDOWS\system32\drivers
2010-07-11 01:24:37 ----D---- C:\Documents and Settings\Marian\Application Data\HLSW
2010-07-10 15:56:58 ----D---- C:\WINDOWS\WinSxS
2010-07-09 12:52:14 ----RSD---- C:\WINDOWS\Fonts
2010-07-08 22:06:20 ----D---- C:\Program Files\CCleaner
2010-07-08 19:32:41 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2010-07-08 19:27:55 ----D---- C:\Program Files\Java
2010-07-08 18:35:31 ----D---- C:\WINDOWS\Microsoft.NET
2010-07-08 18:35:24 ----RSD---- C:\WINDOWS\assembly
2010-07-08 16:05:13 ----D---- C:\WINDOWS\system32\Restore
2010-07-08 16:05:12 ----D---- C:\Program Files\Outlook Express
2010-07-08 16:05:12 ----D---- C:\Program Files\Internet Explorer
2010-07-08 16:02:55 ----D---- C:\WINDOWS\Cursors
2010-07-08 16:02:53 ----D---- C:\WINDOWS\Media
2010-07-08 15:54:14 ----HD---- C:\Program Files\InstallShield Installation Information
2010-07-08 15:53:18 ----D---- C:\Program Files\Styler
2010-07-08 15:49:58 ----D---- C:\Documents and Settings\Marian\Application Data\IconTweaker
2010-07-08 15:49:58 ----D---- C:\Documents and Settings\All Users\Application Data\IconTweaker
2010-07-08 13:51:35 ----D---- C:\Documents and Settings\Marian\Application Data\Skype
2010-07-08 13:38:38 ----D---- C:\WINDOWS\Debug
2010-07-08 11:50:16 ----D---- C:\Program Files\TeamViewer
2010-07-08 10:08:15 ----D---- C:\Documents and Settings\Marian\Application Data\skypePM
2010-07-08 09:44:10 ----D---- C:\Documents and Settings\Marian\Application Data\Adobe
2010-07-07 20:43:50 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-07-07 20:39:24 ----D---- C:\Program Files\Microsoft Silverlight
2010-07-07 20:39:23 ----D---- C:\WINDOWS\system32\wbem
2010-07-07 20:39:23 ----D---- C:\WINDOWS\AppPatch
2010-07-07 20:34:23 ----HD---- C:\WINDOWS\$hf_mig$
2010-07-07 20:18:54 ----D---- C:\Program Files\Movie Maker
2010-07-07 20:10:32 ----D---- C:\Program Files\Messenger
2010-07-07 20:08:32 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-07-07 19:46:57 ----SD---- C:\Documents and Settings\Marian\Application Data\Microsoft
2010-07-07 19:46:56 ----D---- C:\Documents and Settings\Marian\Application Data\Ventrilo
2010-07-07 17:33:34 ----D---- C:\WINDOWS\SoftwareDistribution
2010-07-07 17:32:36 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-07-06 11:27:17 ----A---- C:\WINDOWS\DUMP67a3.tmp
2010-07-05 13:27:27 ----D---- C:\Program Files\Windows Sidebar
2010-07-04 20:44:03 ----D---- C:\Documents and Settings\Marian\Application Data\dvdcss
2010-07-02 20:37:15 ----D---- C:\Program Files\Mozilla Firefox
2010-06-30 22:46:07 ----D---- C:\Program Files\Online Services
2010-06-30 22:25:34 ----D---- C:\WINDOWS\system32\Side 9 Screensaver dir
2010-06-30 22:23:29 ----D---- C:\WINDOWS\Network Diagnostic
2010-06-30 20:30:03 ----D---- C:\WINDOWS\system32\Setup
2010-06-30 20:26:50 ----D---- C:\WINDOWS\security
2010-06-30 20:22:37 ----D---- C:\WINDOWS\system32\inetsrv
2010-06-30 20:22:36 ----D---- C:\WINDOWS\ime
2010-06-30 20:22:24 ----D---- C:\WINDOWS\system32\usmt
2010-06-30 20:22:24 ----D---- C:\WINDOWS\system32\en-us
2010-06-30 20:22:23 ----D---- C:\WINDOWS\l2schemas
2010-06-30 20:22:22 ----D---- C:\WINDOWS\PeerNet
2010-06-30 20:19:03 ----D---- C:\WINDOWS\system32\npp
2010-06-30 20:19:03 ----D---- C:\WINDOWS\mui
2010-06-30 20:19:00 ----D---- C:\WINDOWS\msagent
2010-06-30 20:18:56 ----D---- C:\WINDOWS\srchasst
2010-06-30 20:18:54 ----D---- C:\Program Files\NetMeeting
2010-06-30 20:18:50 ----D---- C:\WINDOWS\system32\Com
2010-06-30 20:18:43 ----D---- C:\Program Files\Windows NT
2010-06-30 20:18:34 ----D---- C:\Program Files\Common Files\System
2010-06-30 20:17:45 ----D---- C:\WINDOWS\system32\oobe
2010-06-30 20:17:43 ----D---- C:\WINDOWS\system
2010-06-30 20:13:01 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-06-30 20:10:07 ----D---- C:\WINDOWS\ehome
2010-06-30 18:11:56 ----D---- C:\WINDOWS\pss
2010-06-30 13:26:33 ----A---- C:\WINDOWS\NeroDigital.ini
2010-06-27 15:24:32 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-06-24 14:45:52 ----D---- C:\Program Files\AGEIA Technologies
2010-06-24 12:29:16 ----D---- C:\WINDOWS\system32\drivers\etc
2010-06-23 20:52:00 ----ASH---- C:\boot.ini
2010-06-23 18:42:03 ----D---- C:\Documents and Settings\Marian\Application Data\HPAppData
2010-06-23 12:25:36 ----D---- C:\WINDOWS\system32\ias
2010-06-22 19:49:59 ----D---- C:\WINDOWS\system32\RTCOM
2010-06-19 12:28:56 ----D---- C:\Program Files\Electronic Arts
2010-06-18 16:27:30 ----D---- C:\Program Files\Messenger Plus! Live
2010-06-15 15:31:02 ----D---- C:\Program Files\TeamSpeak 3 Client

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2010-04-27 45648]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-04-26 691696]
R0 Teefer;Teefer for NT; C:\WINDOWS\SYSTEM32\Drivers\Teefer.sys [2004-10-15 60496]
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2010-03-01 124784]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 36352]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
R1 wpsdrvnt;wpsdrvnt; \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys []
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2010-02-16 60936]
R2 rspndr;Link-Layer Topology Discovery Responder; C:\WINDOWS\system32\DRIVERS\rspndr.sys [2007-02-18 62336]
R2 wg3n;SyGate for NT, wg3n; C:\WINDOWS\SYSTEM32\Drivers\wg3n.sys [2004-10-15 14568]
R2 wg4n;SyGate for NT, wg4n; C:\WINDOWS\SYSTEM32\Drivers\wg4n.sys [2004-10-15 14568]
R2 wg5n;SyGate for NT, wg5n; C:\WINDOWS\SYSTEM32\Drivers\wg5n.sys [2004-10-15 14568]
R2 wg6n;SyGate for NT, wg6n; C:\WINDOWS\SYSTEM32\Drivers\wg6n.sys [2004-10-15 14568]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2010-05-05 4807680]
R3 GEARAspiWDM;GEARAspiWDM; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2006-09-19 15664]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2007-02-18 138752]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2010-06-08 6056040]
R3 PAC7302;CANYON USB PC CAMERA; C:\WINDOWS\system32\DRIVERS\PAC7302.SYS [2007-11-08 458752]
R3 Ps2;PS2; C:\WINDOWS\system32\DRIVERS\PS2.sys [2010-05-27 19072]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2001-08-23 5888]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2008-01-03 105856]
R3 seehcri;Sony Ericsson seehcri Device Driver; C:\WINDOWS\system32\DRIVERS\seehcri.sys [2008-01-09 27632]
R3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-14 60032]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S3 agavpc70;agavpc70; C:\WINDOWS\system32\drivers\agavpc70.sys []
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2009-11-18 1691480]
S3 AtiHdmiService;ATI Function Driver for HDMI Service; C:\WINDOWS\system32\drivers\AtiHdmi.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 cpuz132;cpuz132; \??\C:\DOCUME~1\Marian\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys []
S3 GMSIPCI;GMSIPCI; \??\D:\INSTALL\GMSIPCI.SYS []
S3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2007-10-30 49920]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2007-10-30 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2007-10-30 21568]
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2009-11-18 1395800]
S3 MSICPL;MSICPL; \??\D:\install4\MSICPL.sys []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 NTACCESS;NTACCESS; \??\D:\NTACCESS.sys []
S3 s117bus;Sony Ericsson Device 117 driver (WDM); C:\WINDOWS\system32\DRIVERS\s117bus.sys [2007-06-25 82984]
S3 s117mdfl;Sony Ericsson Device 117 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s117mdfl.sys [2007-06-25 14888]
S3 s117mdm;Sony Ericsson Device 117 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s117mdm.sys [2007-06-25 108456]
S3 s117mgmt;Sony Ericsson Device 117 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s117mgmt.sys [2007-06-25 100264]
S3 s117nd5;Sony Ericsson Device 117 USB Ethernet Emulation SEMC117 (NDIS); C:\WINDOWS\system32\DRIVERS\s117nd5.sys [2007-06-25 22952]
S3 s117obex;Sony Ericsson Device 117 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s117obex.sys [2007-06-25 98344]
S3 s117unic;Sony Ericsson Device 117 USB Ethernet Emulation SEMC117 (WDM); C:\WINDOWS\system32\DRIVERS\s117unic.sys [2007-06-25 98856]
S3 SetupNTGLM7X;SetupNTGLM7X; \??\D:\NTGLM7X.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 vsdatant;vsdatant; C:\WINDOWS\system32\drivers\vsdatant.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2010-04-01 267432]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2010-02-24 135336]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2010-05-05 602112]
R2 hpqddsvc;HP CUE DeviceDiscovery Service; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-04-12 153376]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2007-09-20 853288]
R2 OMSI download service;Sony Ericsson OMSI download service; C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]
R2 SmcService;Sygate Personal Firewall; C:\Program Files\Sygate\SPF\smc.exe [2004-10-15 2577632]
R2 SSHNAS;SSHNAS; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-05-04 651720]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2007-09-20 382248]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2009-01-30 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: prosím o kontrolu logu / otváranie stránok

Napsal: 14 črc 2010 16:34
od vyosek
Zdravim a pekne odpoledne preji :)

:arrow: Vy jste se dal na chov konicku trojskych :D Uz se Vam tam male stadecko rysuje :?:

:arrow: Stahnete OTM (viz muj podpis)
  • Pokud pouzivate Win Vista ci W7, kliknete na OTM pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do leveho okna Paste Instructions for Items to be Moved (pod zlutou caru) vlozte obsah, ktery mate nize
  • Kód: Vybrat vše

    :reg
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "vilaunch"=-
    "SunJavaUpdateSched"=-
    "Adobe Reader Speed Launcher"=-
    "KernelFaultCheck"=-
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    [HKUS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run]
    "JDK5SWFMZY"=-
    [HKUS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "JDK5SWFMZY"=-
    [HKCU\Software\Microsoft\Internet Explorer\Main]
    "Start Page"="http://www.seznam.cz/"
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "DAEMON Tools Lite"=-
    
    :files
    C:\WINDOWS\system32\*.tmp.dll /s
    C:\WINDOWS\system32\SET*.tmp /s
    C:\WINDOWS\*.tmp /s
    C:\WINDOWS\TEMP\
    C:\WINDOWS\system32\vilaunch.exe
    
    :commands
    [EMPTYTEMP]
    [EMPTYFLASH]
    [CLEARALLRESTOREPOINTS]
  • Kliknete na cervene tlacitko MoveIt!
  • Sem pote dejte obsah okna Results (pod zelenou carou)
  • Pokud budete vyzvani na restart, dejte Yes, log pote najdete C:\_OTM\MovedFiles

Re: prosím o kontrolu logu / otváranie stránok

Napsal: 14 črc 2010 17:33
od SSemteXX
Všetko som urobil podľa Vás, nech sa páči log po restarte.

All processes killed
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\vilaunch deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe Reader Speed Launcher deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched\ deleted successfully.
Registry key Invalid\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run not found.
Registry key Invalid\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run not found.
HKCU\Software\Microsoft\Internet Explorer\Main\\"Start Page"|"http://www.seznam.cz/" /E : value set successfully!
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite deleted successfully.
========== FILES ==========
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
C:\WINDOWS\system32\SET1489.tmp moved successfully.
C:\WINDOWS\system32\SET1495.tmp moved successfully.
C:\WINDOWS\system32\SET39.tmp moved successfully.
C:\WINDOWS\system32\SET4C.tmp moved successfully.
C:\WINDOWS\system32\SET4F.tmp moved successfully.
C:\WINDOWS\system32\SET51.tmp moved successfully.
C:\WINDOWS\system32\SET54.tmp moved successfully.
C:\WINDOWS\system32\SET56.tmp moved successfully.
C:\WINDOWS\system32\SET64.tmp moved successfully.
C:\WINDOWS\system32\SET89.tmp moved successfully.
C:\WINDOWS\003321_.tmp moved successfully.
C:\WINDOWS\DUMP465f.tmp moved successfully.
C:\WINDOWS\DUMP46ad.tmp moved successfully.
C:\WINDOWS\DUMP6496.tmp moved successfully.
C:\WINDOWS\DUMP67a3.tmp moved successfully.
C:\WINDOWS\msdownld.tmp folder moved successfully.
C:\WINDOWS\SET3.tmp moved successfully.
C:\WINDOWS\SET4.tmp moved successfully.
C:\WINDOWS\SET8.tmp moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1B5.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP866.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP946.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPA75.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPCC.tmp folder moved successfully.
C:\WINDOWS\Installer\MSI223.tmp moved successfully.
C:\WINDOWS\Installer\MSI226.tmp moved successfully.
C:\WINDOWS\Installer\MSI27A.tmp moved successfully.
C:\WINDOWS\Installer\MSI27C.tmp moved successfully.
C:\WINDOWS\Installer\MSI39.tmp moved successfully.
C:\WINDOWS\system32\CONFIG.TMP moved successfully.
C:\WINDOWS\Temp\nsi11AF.tmp folder moved successfully.
C:\WINDOWS\twain_32\hpqgnds2.tmp moved successfully.
Folder move failed. C:\WINDOWS\Temp scheduled to be moved on reboot.
C:\WINDOWS\system32\vilaunch.exe moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Marian
->Temp folder emptied: 3472732 bytes
->Temporary Internet Files folder emptied: 853044 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 122045459 bytes
->Flash cache emptied: 6981 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 77582 bytes
->Flash cache emptied: 405 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 186339 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 81824402 bytes

Total Files Cleaned = 199,00 mb


Restore points cleared and new OTM Restore Point set!

OTM by OldTimer - Version 3.1.14.0 log created on 07142010_182443

Files moved on Reboot...
Folder move failed. C:\WINDOWS\Temp scheduled to be moved on reboot.
C:\Documents and Settings\Marian\Local Settings\Temporary Internet Files\Content.IE5\KAS0805Q\MsgrConfig[1].asmx moved successfully.
C:\Documents and Settings\Marian\Local Settings\Temporary Internet Files\Content.IE5\72PBTE11\MsgrConfig[1].asmx moved successfully.
C:\WINDOWS\temp\Perflib_Perfdata_f08.dat moved successfully.

Registry entries deleted on Reboot...

Re: prosím o kontrolu logu / otváranie stránok

Napsal: 14 črc 2010 18:06
od SSemteXX
Sorry, že píšem zase, ale teraz mám zase taký čudný problém. Zapol som PC, skopíroval sem log a robil som si veci atď. A o nejakých 20min na to, si zapnem mozillu a zapne sa mi a zrazu hneď vypne, to isté aj pri IE 8, čím to je?
Skúsim RR pc, keď ti nepôjde tak sa spolieham na Vás.

Re: prosím o kontrolu logu / otváranie stránok

Napsal: 14 črc 2010 18:15
od vyosek
:arrow: Stahnete Malwarebytes' Anti-Malware (zkracene MBAM) (viz muj podpis)
  • Provedte aktualizaci - treti zalozka
  • Provedte uplny sken - nic nemazte :!:
  • MBAM miva obcas falesne detekce, proto vlozte log do prispevku a pockejte na posouzeni

Re: prosím o kontrolu logu / otváranie stránok

Napsal: 14 črc 2010 18:53
od SSemteXX
Ok, dal som update stiahlo databázu novú a teraz skenuje, ale ten scan bude robiť strašne dlho, však ono to ide súbor po súbore, no nič. Potom sem dám log.

Re: prosím o kontrolu logu / otváranie stránok

Napsal: 14 črc 2010 19:04
od vyosek
Jo jde, ale zas dusledne kontroluje a uvidime zda tam neni havet :wink:

Re: prosím o kontrolu logu / otváranie stránok

Napsal: 14 črc 2010 21:54
od SSemteXX
Nech sa páči, tu je log, veci ktoré našlo som dal odstrániť, teraz fičí všetko bez problémov.

Ešte niečo? :)

Malwarebytes' Anti-Malware 1.46
http://www.malwarebytes.org

Database version: 4313

Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512

14. 7. 2010 22:52:31
mbam-log-2010-07-14 (22-52-31).txt

Scan type: Full scan (C:\|)
Objects scanned: 228977
Time elapsed: 2 hour(s), 49 minute(s), 56 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SSHNAS (Trojan.Renos) -> No action taken.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> No action taken.
C:\WINDOWS\Tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job (Trojan.Downloader) -> No action taken.

Re: prosím o kontrolu logu / otváranie stránok

Napsal: 15 črc 2010 04:57
od vyosek
:arrow: Log z MBAM ale ukazuje ze nic nebylo provedeno, pokud jste to smazal, az pak, tak OK :)

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC
:arrow: Stahnete Ccleaner (viz muj podpis), pri instalaci dejte fajfku pryc u yahoo toolbaru
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za 14 dni

:arrow: Novy log ze RSITu

Re: prosím o kontrolu logu / otváranie stránok

Napsal: 15 črc 2010 09:38
od SSemteXX
Nech sa páči tu je log, všetko som urobil podľa Vás, použil som obidve softy a reštartol som PC, až na to, Že CCleaner už používam odjakživa a testujem PC každý 2í deň s tým CCleaner, takže to neni problém :) Som prišiel na to, že ten "wscntfy.exe" je nejaký vír, no ja ho neustále mám medzi procesmi. :/
Aha, no už som ho vypol, som prišiel na to, že ten program slúźi na to, aby mi dole nahadzoval chyby keď nemám zapnutý firewall/antivír atď.

Dobre, takže urobil som nasledovnú vec, stiahol som si program "SpyHunter", samozrejme cracknutý, našlo mi asi 87 infekcií, všetky som odstránil, bol to rôzny malware zo stránok, proste nejaký Addblock, Gator atď. Všetky sú odstránené. Po reštarte mi beží PC ako má, bez problémov, zatiaľ som nemal žiadny problem, dal som sem nový log, dúfam, že už je OK :happy:

Logfile of random's system information tool 1.08 (written by random/random)
Run by Marian at 2010-07-15 11:46:09
Microsoft Windows XP Professional Service Pack 3
System drive C: has 13 GB (17%) free of 76 GB
Total RAM: 2047 MB (65% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:46:20, on 15. 7. 2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 SP3 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\PixArt\PAC7302\Monitor.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Marian\Desktop\RSIT.exe
C:\Program Files\trend micro\Marian.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live bejelentkezési segítség - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\PAC7302\Monitor.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TrueTransparency] "C:\PROGRA~1\TRUETR~1\TrueTransparency.exe"
O4 - HKCU\..\Run: [ViStart] C:\PROGRA~1\ViStart\ViStart.exe
O4 - HKCU\..\Run: [ViGlance] C:\PROGRA~1\ViGlance\ViGlance.exe
O4 - HKUS\S-1-5-18\..\Run: [JDK5SWFMZY] C:\WINDOWS\TEMP\Smr.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [JDK5SWFMZY] C:\WINDOWS\TEMP\Smr.exe (User 'Default user')
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftup ... 8516750203
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 8516739375
O17 - HKLM\System\CCS\Services\Tcpip\..\{16E39F2B-0996-4D5E-A3D6-5F83CA2E0C43}: NameServer = 195.168.69.136 195.168.69.139
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: Sony Ericsson OMSI download service (OMSI download service) - Unknown owner - C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: SpyHunter 4 Service - Enigma Software Group USA, LLC. - C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE

--
End of file - 7349 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\At1.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2007-11-06 322880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live bejelentkezési segítség - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-04-12 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-04-12 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2007-11-06 542016]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"PAC7302_Monitor"=C:\WINDOWS\PixArt\PAC7302\Monitor.exe [2006-11-03 319488]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-05-04 102400]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2010-06-08 19552872]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2010-03-02 282792]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-03-24 952768]
"SpyHunter Security Suite"=C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe [2010-06-28 3021720]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"TrueTransparency"=C:\PROGRA~1\TRUETR~1\TrueTransparency.exe [2010-07-15 356352]
"ViStart"=C:\PROGRA~1\ViStart\ViStart.exe [2010-07-15 798720]
"ViGlance"=C:\PROGRA~1\ViGlance\ViGlance.exe [2010-07-15 438272]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-03-24 952768]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe [2007-09-20 202024]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DrvIcon]
C:\Program Files\Vista Drive Icon\DrvIcon.exe [2008-04-13 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-10-14 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [2007-08-22 80896]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2007-09-20 1836328]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [2007-03-01 153136]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Octoshape Streaming Services]
C:\Documents and Settings\Marian\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe [2009-01-08 70936]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlayBar]
C:\Program Files\Playbar\playbar.exe rejtett []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmcService]
C:\PROGRA~1\Sygate\SPF\smc.exe [2004-10-15 2577632]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe [2009-09-24 434176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2007-10-14 214360]

C:\Documents and Settings\Marian\Start Menu\Programs\Startup
Stardock ObjectDock.lnk - C:\Program Files\Stardock\ObjectDock\ObjectDock.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2010-05-05 159744]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 239496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2009-01-30 133632]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\HLSW\hlsw.exe"="C:\Program Files\HLSW\hlsw.exe:*:Enabled:HLSW Application"
"C:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe"="C:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe:*:Enabled:CoD2MP_s"
"C:\Program Files\mIRC\mirc.exe"="C:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\SopCast\SopCast.exe"="C:\Program Files\SopCast\SopCast.exe:*:Enabled:SopCast Main Application"
"C:\Program Files\SopCast\adv\SopAdver.exe"="C:\Program Files\SopCast\adv\SopAdver.exe:*:Enabled:SopCast Adver"
"C:\Program Files\Valve\Steam\Steam.exe"="C:\Program Files\Valve\Steam\Steam.exe:*:Enabled:Steam"
"C:\Program Files\VirtualDJ\virtualdj_trial.exe"="C:\Program Files\VirtualDJ\virtualdj_trial.exe:*:Enabled:VirtualDJ"
"C:\Program Files\KONAMI\Pro Evolution Soccer 2010\pes2010.exe"="C:\Program Files\KONAMI\Pro Evolution Soccer 2010\pes2010.exe:*:Enabled:Pro Evolution Soccer 2010"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\WINDOWS\system32\usmt\migwiz.exe"="C:\WINDOWS\system32\usmt\migwiz.exe:*:Enabled:Files and Settings Transfer Wizard"
"C:\Program Files\Ubisoft\Tom Clancy's Splinter Cell Conviction\src\system\conviction_game.exe"="C:\Program Files\Ubisoft\Tom Clancy's Splinter Cell Conviction\src\system\conviction_game.exe:*:Enabled:conviction_game"
"C:\Program Files\Electronic Arts\Battlefield Bad Company 2\BFBC2Updater.exe"="C:\Program Files\Electronic Arts\Battlefield Bad Company 2\BFBC2Updater.exe:*:Enabled:Battlefield: Bad Company™ 2"
"C:\Documents and Settings\Marian\Desktop\RatioMaster.NET.exe"="C:\Documents and Settings\Marian\Desktop\RatioMaster.NET.exe:*:Enabled:RatioMaster.NET"
"C:\Documents and Settings\Marian\My Documents\Prgr\RatioMaster.NET.exe"="C:\Documents and Settings\Marian\My Documents\Prgr\RatioMaster.NET.exe:*:Enabled:RatioMaster.NET"
"C:\Program Files\Eidos\Batman Arkham Asylum\Binaries\ShippingPC-BmGame.exe"="C:\Program Files\Eidos\Batman Arkham Asylum\Binaries\ShippingPC-BmGame.exe:*:Enabled:BmGame"
"C:\Documents and Settings\Marian\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe"="C:\Documents and Settings\Marian\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe:*:Enabled:Main program for Octoshape client"
"C:\Program Files\PESEdit\2010 FIFA World Cup Patch\pes2010.exe"="C:\Program Files\PESEdit\2010 FIFA World Cup Patch\pes2010.exe:*:Enabled:Pro Evolution Soccer 2010"
"C:\Program Files\Valve\Steam\SteamApps\ssementexx\ricochet\hl.exe"="C:\Program Files\Valve\Steam\SteamApps\ssementexx\ricochet\hl.exe:*:Enabled:Ricochet"
"C:\Program Files\Codemasters\Colin McRae DiRT 2\dirt2_game.exe"="C:\Program Files\Codemasters\Colin McRae DiRT 2\dirt2_game.exe:*:Enabled:DiRT2 Executable"
"C:\Program Files\Valve\Steam\SteamApps\common\trackmania nations forever\TmForever.exe"="C:\Program Files\Valve\Steam\SteamApps\common\trackmania nations forever\TmForever.exe:*:Enabled:TrackMania Nations Forever"
"C:\Program Files\Valve\Steam\SteamApps\common\trackmania nations forever\TmForeverLauncher.exe"="C:\Program Files\Valve\Steam\SteamApps\common\trackmania nations forever\TmForeverLauncher.exe:*:Enabled:TrackMania Nations Forever"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\TeamViewer\Version5\TeamViewer.exe"="C:\Program Files\TeamViewer\Version5\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application"
"C:\Program Files\Valve\Steam\SteamApps\ssementexx\counter-strike\hl.exe"="C:\Program Files\Valve\Steam\SteamApps\ssementexx\counter-strike\hl.exe:*:Enabled:Counter-Strike"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

======File associations======

.scr - open - C:\WINDOWS\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 months======

2010-07-15 11:42:34 ----A---- C:\WINDOWS\system32\drivers\wpsdrvnt.sys
2010-07-15 11:42:34 ----A---- C:\WINDOWS\system32\drivers\Teefer.sys
2010-07-15 11:42:33 ----A---- C:\WINDOWS\system32\drivers\PAC7302.SYS
2010-07-15 10:45:51 ----D---- C:\sh4ldr
2010-07-15 10:45:51 ----D---- C:\Program Files\Enigma Software Group
2010-07-15 10:45:38 ----D---- C:\WINDOWS\4FC9DA9DF608454E8191D7EFFDCC5726.TMP
2010-07-15 10:35:26 ----D---- C:\rsit
2010-07-15 00:26:46 ----D---- C:\Program Files\Anti Trojan Elite
2010-07-14 19:17:16 ----D---- C:\Documents and Settings\Marian\Application Data\Malwarebytes
2010-07-14 19:17:09 ----A---- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2010-07-14 19:17:07 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-07-14 19:17:07 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2010-07-14 19:17:07 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2010-07-12 20:39:59 ----D---- C:\Program Files\Valve
2010-07-12 16:21:36 ----D---- C:\Documents and Settings\All Users\Application Data\Trymedia
2010-07-11 19:27:08 ----D---- C:\Program Files\KONAMI
2010-07-11 19:27:07 ----D---- C:\Documents and Settings\All Users\Application Data\KONAMI
2010-07-11 17:55:58 ----N---- C:\WINDOWS\system32\spmsg.dll
2010-07-11 17:55:08 ----HDC---- C:\WINDOWS\$NtUninstallwmp11$
2010-07-11 17:08:54 ----D---- C:\Documents and Settings\Marian\Application Data\vlc
2010-07-08 19:27:57 ----A---- C:\WINDOWS\system32\javaws.exe
2010-07-08 19:27:57 ----A---- C:\WINDOWS\system32\javaw.exe
2010-07-08 19:27:57 ----A---- C:\WINDOWS\system32\java.exe
2010-07-08 19:27:57 ----A---- C:\WINDOWS\system32\deployJava1.dll
2010-07-08 16:05:42 ----D---- C:\Documents and Settings\Marian\Application Data\ViSplore
2010-07-08 16:05:41 ----D---- C:\Documents and Settings\Marian\Application Data\ViStart
2010-07-08 16:05:41 ----D---- C:\Documents and Settings\Marian\Application Data\ViGlance
2010-07-08 16:05:35 ----D---- C:\WINDOWS\system32\VIRepair
2010-07-08 16:02:59 ----D---- C:\Program Files\ViSplore
2010-07-08 16:02:59 ----D---- C:\Program Files\TrueTransparency
2010-07-08 16:02:59 ----A---- C:\WINDOWS\system32\viwc.exe
2010-07-08 16:02:56 ----D---- C:\Program Files\WinFlip
2010-07-08 16:02:56 ----D---- C:\Program Files\ViStart
2010-07-08 16:02:56 ----D---- C:\Program Files\ViGlance
2010-07-08 16:02:55 ----D---- C:\Program Files\Vista Drive Icon
2010-07-08 16:00:25 ----D---- C:\WINDOWS\system32\VITrans
2010-07-08 16:00:25 ----D---- C:\VTPFiles
2010-07-08 16:00:25 ----A---- C:\WINDOWS\system32\Uharc.exe
2010-07-08 16:00:25 ----A---- C:\WINDOWS\system32\reico.exe
2010-07-08 16:00:25 ----A---- C:\WINDOWS\system32\modifype.exe
2010-07-08 16:00:24 ----A---- C:\WINDOWS\system32\pskill.exe
2010-07-08 15:59:49 ----A---- C:\WINDOWS\system32\scrnrdr.exe
2010-07-07 20:34:23 ----HDC---- C:\WINDOWS\$NtUninstallKB979559$
2010-07-07 20:31:07 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2010-07-07 20:27:56 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2010-07-07 20:27:50 ----HDC---- C:\WINDOWS\$NtUninstallKB980195$
2010-07-07 20:24:43 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2010-07-07 20:23:41 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$
2010-07-07 20:23:35 ----HDC---- C:\WINDOWS\$NtUninstallKB981793$
2010-07-07 20:23:30 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2010-07-07 20:19:50 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-07-07 20:19:41 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2010-07-07 20:19:35 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-07-07 20:19:30 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-07-07 20:19:20 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2010-07-07 20:19:16 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-07-07 20:18:53 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2010-07-07 20:18:46 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-07-07 20:18:42 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-07-07 20:18:36 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-07-07 20:18:29 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-07-07 20:18:22 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-07-07 20:18:18 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-07-07 20:18:13 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-07-07 20:18:01 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2010-07-07 20:17:56 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-07-07 20:17:51 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2010-07-07 20:17:46 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2010-07-07 20:17:39 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2010-07-07 20:17:34 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2010-07-07 20:17:29 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2010-07-07 20:17:23 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2010-07-07 20:17:20 ----D---- C:\Program Files\MSXML 4.0
2010-07-07 20:17:10 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2010-07-07 20:17:07 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2010-07-07 20:17:03 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2010-07-07 20:16:58 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2010-07-07 20:16:54 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2010-07-07 20:16:50 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2010-07-07 20:16:46 ----D---- C:\WINDOWS\ie8updates
2010-07-07 20:16:40 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2010-07-07 20:16:36 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2010-07-07 20:16:30 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2010-07-07 20:16:21 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2010-07-07 20:16:14 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2010-07-07 20:16:03 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2010-07-07 20:15:52 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2010-07-07 20:15:46 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
2010-07-07 20:15:28 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2010-07-07 20:15:21 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2010-07-07 20:15:12 ----HDC---- C:\WINDOWS\$NtUninstallKB961503$
2010-07-07 20:14:58 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2010-07-07 20:14:46 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2010-07-07 20:14:25 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2010-07-07 20:13:50 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2010-07-07 20:13:27 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2010-07-07 20:11:39 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2010-07-07 20:11:35 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2010-07-07 20:11:13 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2010-07-07 20:11:08 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2010-07-07 20:11:03 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2010-07-07 20:10:58 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
2010-07-07 20:10:53 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2010-07-07 20:10:48 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2010-07-07 20:10:43 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2010-07-07 20:10:38 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2010-07-07 20:10:34 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2010-07-07 20:10:30 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2010-07-07 20:10:24 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
2010-07-07 20:10:07 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2010-07-07 20:10:01 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2010-07-07 20:09:56 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2010-07-07 20:09:51 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2010-07-07 20:09:43 ----HDC---- C:\WINDOWS\$NtUninstallKB950760$
2010-07-07 20:06:49 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2010-07-07 19:39:43 ----N---- C:\WINDOWS\system32\browserchoice.exe
2010-07-07 19:03:36 ----N---- C:\WINDOWS\system32\xpsp4res.dll
2010-07-07 17:33:17 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2010-07-07 17:33:17 ----A---- C:\WINDOWS\system32\wucltui.dll.mui
2010-07-07 17:33:17 ----A---- C:\WINDOWS\system32\wuaueng.dll.mui
2010-07-07 17:33:17 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
2010-07-05 13:42:02 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2010-07-05 13:40:51 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2010-07-05 13:40:33 ----D---- C:\6c15930dff31220c866b2810ba
2010-07-05 13:40:28 ----D---- C:\WINDOWS\system32\LogFiles
2010-07-05 13:40:28 ----D---- C:\WINDOWS\system32\drivers\UMDF
2010-07-05 13:40:23 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2010-07-05 13:40:11 ----D---- C:\1132aea08f7be422c351
2010-07-05 13:35:27 ----A---- C:\WINDOWS\system32\antiwpa.dll107EC54
2010-07-05 13:31:22 ----A---- C:\WINDOWS\system32\LegitCheckControl.dll
2010-07-05 13:26:51 ----D---- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2010-07-05 13:21:19 ----A---- C:\WINDOWS\system32\lcid.exe
2010-07-03 16:04:46 ----D---- C:\Program Files\AnvSoft
2010-06-30 20:33:32 ----A---- C:\WINDOWS\system32\wmpns.dll
2010-06-30 20:30:52 ----D---- C:\WINDOWS\Prefetch
2010-06-30 20:27:06 ----HDC---- C:\WINDOWS\$NtUninstallKB938759$
2010-06-30 20:22:48 ----A---- C:\WINDOWS\system32\msxml6r.dll
2010-06-30 20:22:38 ----N---- C:\WINDOWS\system32\drivers\irbus.sys
2010-06-30 20:22:38 ----N---- C:\WINDOWS\system32\comsdupd.exe
2010-06-30 20:22:37 ----N---- C:\WINDOWS\system32\smtpapi.dll
2010-06-30 20:22:37 ----N---- C:\WINDOWS\system32\rwnh.dll
2010-06-30 20:22:33 ----N---- C:\WINDOWS\system32\credssp.dll
2010-06-30 20:22:33 ----N---- C:\WINDOWS\system32\bitsprx4.dll
2010-06-30 20:22:33 ----N---- C:\WINDOWS\system32\azroles.dll
2010-06-30 20:22:33 ----N---- C:\WINDOWS\system32\ativtmxx.dll
2010-06-30 20:22:33 ----N---- C:\WINDOWS\system32\ati3d1ag.dll
2010-06-30 20:22:33 ----N---- C:\WINDOWS\system32\ati2dvaa.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\eapsvc.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\eapqec.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\eappprxy.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\eapphost.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\eappgnui.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\eappcfg.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\eapp3hst.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\eapolqec.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\dot3ui.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\dot3svc.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\dot3msm.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\dot3dlg.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\dot3cfg.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\dot3api.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\dimsroam.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\dimsntfy.dll
2010-06-30 20:22:32 ----N---- C:\WINDOWS\system32\dhcpqec.dll
2010-06-30 20:22:31 ----N---- C:\WINDOWS\system32\ieencode.dll
2010-06-30 20:22:31 ----N---- C:\WINDOWS\system32\hsfcisp2.dll
2010-06-30 20:22:30 ----N---- C:\WINDOWS\system32\mdmxsdk.dll
2010-06-30 20:22:30 ----N---- C:\WINDOWS\system32\l2gpstore.dll
2010-06-30 20:22:30 ----N---- C:\WINDOWS\system32\kmsvc.dll
2010-06-30 20:22:29 ----N---- C:\WINDOWS\system32\onex.dll
2010-06-30 20:22:29 ----N---- C:\WINDOWS\system32\nv4_disp.dll
2010-06-30 20:22:29 ----N---- C:\WINDOWS\system32\napstat.exe
2010-06-30 20:22:29 ----N---- C:\WINDOWS\system32\napmontr.dll
2010-06-30 20:22:29 ----N---- C:\WINDOWS\system32\napipsec.dll
2010-06-30 20:22:29 ----N---- C:\WINDOWS\system32\mtxparhd.dll
2010-06-30 20:22:29 ----N---- C:\WINDOWS\system32\msshavmsg.dll
2010-06-30 20:22:29 ----N---- C:\WINDOWS\system32\mssha.dll
2010-06-30 20:22:28 ----N---- C:\WINDOWS\system32\slserv.exe
2010-06-30 20:22:28 ----N---- C:\WINDOWS\system32\slrundll.exe
2010-06-30 20:22:28 ----N---- C:\WINDOWS\system32\slgen.dll
2010-06-30 20:22:28 ----N---- C:\WINDOWS\system32\slextspk.dll
2010-06-30 20:22:28 ----N---- C:\WINDOWS\system32\slcoinst.dll
2010-06-30 20:22:28 ----N---- C:\WINDOWS\system32\setupn.exe
2010-06-30 20:22:28 ----N---- C:\WINDOWS\system32\s3gnb.dll
2010-06-30 20:22:28 ----N---- C:\WINDOWS\system32\rasqec.dll
2010-06-30 20:22:28 ----N---- C:\WINDOWS\system32\qutil.dll
2010-06-30 20:22:28 ----N---- C:\WINDOWS\system32\qcliprov.dll
2010-06-30 20:22:28 ----N---- C:\WINDOWS\system32\qagentrt.dll
2010-06-30 20:22:28 ----N---- C:\WINDOWS\system32\qagent.dll
2010-06-30 20:22:27 ----N---- C:\WINDOWS\system32\tzchange.exe
2010-06-30 20:22:27 ----N---- C:\WINDOWS\system32\tspkg.dll
2010-06-30 20:22:24 ----N---- C:\WINDOWS\slrundll.exe
2010-06-30 20:22:23 ----D---- C:\WINDOWS\system32\scripting
2010-06-30 20:22:22 ----D---- C:\WINDOWS\system32\bits
2010-06-30 20:19:19 ----D---- C:\WINDOWS\ServicePackFiles
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\ati1tuxx.sys
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\ati1ttxx.sys
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\ati1snxx.sys
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\ati1rvxx.sys
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\ati1raxx.sys
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\ati1pdxx.sys
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\ati1mdxx.sys
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\ati1btxx.sys
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\amdagp.sys
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\alim1541.sys
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\agpcpq.sys
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\agp440.sys
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\adv11nt5.dll
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\adv09nt5.dll
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\adv08nt5.dll
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\adv07nt5.dll
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\adv05nt5.dll
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\adv02nt5.dll
2010-06-30 20:15:46 ----N---- C:\WINDOWS\system32\drivers\adv01nt5.dll
2010-06-30 20:15:45 ----N---- C:\WINDOWS\system32\drivers\atv04nt5.dll
2010-06-30 20:15:45 ----N---- C:\WINDOWS\system32\drivers\atv02nt5.dll
2010-06-30 20:15:45 ----N---- C:\WINDOWS\system32\drivers\atv01nt5.dll
2010-06-30 20:15:45 ----N---- C:\WINDOWS\system32\drivers\atinxsxx.sys
2010-06-30 20:15:45 ----N---- C:\WINDOWS\system32\drivers\atinxbxx.sys
2010-06-30 20:15:45 ----N---- C:\WINDOWS\system32\drivers\atintuxx.sys
2010-06-30 20:15:45 ----N---- C:\WINDOWS\system32\drivers\atinttxx.sys
2010-06-30 20:15:45 ----N---- C:\WINDOWS\system32\drivers\atinsnxx.sys
2010-06-30 20:15:45 ----N---- C:\WINDOWS\system32\drivers\atinrvxx.sys
2010-06-30 20:15:45 ----N---- C:\WINDOWS\system32\drivers\atinraxx.sys
2010-06-30 20:15:45 ----N---- C:\WINDOWS\system32\drivers\atinpdxx.sys
2010-06-30 20:15:45 ----N---- C:\WINDOWS\system32\drivers\atinmdxx.sys
2010-06-30 20:15:45 ----N---- C:\WINDOWS\system32\drivers\atinbtxx.sys
2010-06-30 20:15:45 ----N---- C:\WINDOWS\system32\drivers\ati2mtaa.sys
2010-06-30 20:15:45 ----N---- C:\WINDOWS\system32\drivers\ati1xsxx.sys
2010-06-30 20:15:45 ----N---- C:\WINDOWS\system32\drivers\ati1xbxx.sys
2010-06-30 20:15:44 ----N---- C:\WINDOWS\system32\drivers\ch7xxnt5.dll
2010-06-30 20:15:44 ----N---- C:\WINDOWS\system32\drivers\bthusb.sys
2010-06-30 20:15:44 ----N---- C:\WINDOWS\system32\drivers\bthprint.sys
2010-06-30 20:15:44 ----N---- C:\WINDOWS\system32\drivers\bthport.sys
2010-06-30 20:15:44 ----N---- C:\WINDOWS\system32\drivers\bthpan.sys
2010-06-30 20:15:44 ----N---- C:\WINDOWS\system32\drivers\bthmodem.sys
2010-06-30 20:15:44 ----N---- C:\WINDOWS\system32\drivers\bthenum.sys
2010-06-30 20:15:44 ----N---- C:\WINDOWS\system32\drivers\atv10nt5.dll
2010-06-30 20:15:44 ----N---- C:\WINDOWS\system32\drivers\atv06nt5.dll
2010-06-30 20:15:43 ----N---- C:\WINDOWS\system32\drivers\hidbth.sys
2010-06-30 20:15:43 ----N---- C:\WINDOWS\system32\drivers\gagp30kx.sys
2010-06-30 20:15:42 ----N---- C:\WINDOWS\system32\drivers\mdmxsdk.sys
2010-06-30 20:15:42 ----N---- C:\WINDOWS\system32\drivers\hsfdpsp2.sys
2010-06-30 20:15:42 ----N---- C:\WINDOWS\system32\drivers\hsfcxts2.sys
2010-06-30 20:15:42 ----N---- C:\WINDOWS\system32\drivers\hsfbs2s2.sys
2010-06-30 20:15:42 ----N---- C:\WINDOWS\system32\drivers\hidir.sys
2010-06-30 20:15:41 ----N---- C:\WINDOWS\system32\drivers\rfcomm.sys
2010-06-30 20:15:41 ----N---- C:\WINDOWS\system32\drivers\recagent.sys
2010-06-30 20:15:41 ----N---- C:\WINDOWS\system32\drivers\nv4_mini.sys
2010-06-30 20:15:41 ----N---- C:\WINDOWS\system32\drivers\ntmtlfax.sys
2010-06-30 20:15:41 ----N---- C:\WINDOWS\system32\drivers\mutohpen.sys
2010-06-30 20:15:41 ----N---- C:\WINDOWS\system32\drivers\mtxparhm.sys
2010-06-30 20:15:41 ----N---- C:\WINDOWS\system32\drivers\mtlstrm.sys
2010-06-30 20:15:41 ----N---- C:\WINDOWS\system32\drivers\mtlmnt5.sys
2010-06-30 20:15:40 ----N---- C:\WINDOWS\system32\drivers\slnthal.sys
2010-06-30 20:15:40 ----N---- C:\WINDOWS\system32\drivers\slntamr.sys
2010-06-30 20:15:40 ----N---- C:\WINDOWS\system32\drivers\slnt7554.sys
2010-06-30 20:15:40 ----N---- C:\WINDOWS\system32\drivers\sisagp.sys
2010-06-30 20:15:40 ----N---- C:\WINDOWS\system32\drivers\siint5.dll
2010-06-30 20:15:40 ----N---- C:\WINDOWS\system32\drivers\sffp_mmc.sys
2010-06-30 20:15:40 ----N---- C:\WINDOWS\system32\drivers\s3gnbm.sys
2010-06-30 20:15:40 ----N---- C:\WINDOWS\system32\drivers\rndismpx.sys
2010-06-30 20:15:39 ----N---- C:\WINDOWS\system32\drivers\usb8023x.sys
2010-06-30 20:15:39 ----N---- C:\WINDOWS\system32\drivers\uagp35.sys
2010-06-30 20:15:39 ----N---- C:\WINDOWS\system32\drivers\smbali.sys
2010-06-30 20:15:39 ----N---- C:\WINDOWS\system32\drivers\slwdmsup.sys
2010-06-30 20:15:38 ----N---- C:\WINDOWS\system32\drivers\watv10nt.sys
2010-06-30 20:15:38 ----N---- C:\WINDOWS\system32\drivers\watv06nt.sys
2010-06-30 20:15:38 ----N---- C:\WINDOWS\system32\drivers\wadv11nt.sys
2010-06-30 20:15:38 ----N---- C:\WINDOWS\system32\drivers\wadv09nt.sys
2010-06-30 20:15:38 ----N---- C:\WINDOWS\system32\drivers\wadv08nt.sys
2010-06-30 20:15:38 ----N---- C:\WINDOWS\system32\drivers\wadv07nt.sys
2010-06-30 20:15:38 ----N---- C:\WINDOWS\system32\drivers\wacompen.sys
2010-06-30 20:15:38 ----N---- C:\WINDOWS\system32\drivers\viaagp.sys
2010-06-30 20:15:38 ----N---- C:\WINDOWS\system32\drivers\vchnt5.dll
2010-06-30 20:15:38 ----N---- C:\WINDOWS\system32\drivers\usbvideo.sys
2010-06-30 20:10:09 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2010-06-30 18:23:08 ----D---- C:\WINDOWS\WBEM
2010-06-30 18:20:37 ----HDC---- C:\WINDOWS\ie8
2010-06-30 18:18:40 ----HDC---- C:\WINDOWS\$NtUninstallKB932823-v3$
2010-06-30 17:38:05 ----D---- C:\Program Files\trend micro
2010-06-30 12:57:46 ----D---- C:\Program Files\Desktop Activity Recorder
2010-06-27 15:24:53 ----A---- C:\WINDOWS\system32\drivers\wg6n.sys
2010-06-27 15:24:52 ----A---- C:\WINDOWS\system32\drivers\wg5n.sys
2010-06-27 15:24:52 ----A---- C:\WINDOWS\system32\drivers\wg4n.sys
2010-06-27 15:24:52 ----A---- C:\WINDOWS\system32\drivers\wg3n.sys
2010-06-27 15:24:49 ----A---- C:\WINDOWS\system32\SSSensor.dll
2010-06-27 15:24:46 ----D---- C:\Program Files\Sygate
2010-06-27 15:12:42 ----HDC---- C:\WINDOWS\$NtUninstallKB894391$
2010-06-26 14:55:44 ----D---- C:\Program Files\City Interactive
2010-06-24 17:31:44 ----D---- C:\Documents and Settings\All Users\Application Data\TrackMania
2010-06-24 14:45:27 ----D---- C:\Program Files\NVIDIA Corporation
2010-06-23 19:17:23 ----D---- C:\Documents and Settings\Marian\Application Data\Avira
2010-06-23 19:08:06 ----A---- C:\WINDOWS\system32\drivers\ssmdrv.sys
2010-06-23 19:08:01 ----A---- C:\WINDOWS\system32\drivers\avipbb.sys
2010-06-23 19:08:01 ----A---- C:\WINDOWS\system32\drivers\avgntmgr.sys
2010-06-23 19:08:01 ----A---- C:\WINDOWS\system32\drivers\avgntflt.sys
2010-06-23 19:08:01 ----A---- C:\WINDOWS\system32\drivers\avgntdd.sys
2010-06-23 19:07:59 ----D---- C:\Program Files\Avira
2010-06-23 19:07:59 ----D---- C:\Documents and Settings\All Users\Application Data\Avira
2010-06-23 18:40:14 ----D---- C:\Program Files\ESET
2010-06-23 13:59:45 ----D---- C:\Documents and Settings\Marian\Application Data\FUEL
2010-06-23 12:25:28 ----A---- C:\WINDOWS\ModemLog_Communications cable between two computers.txt
2010-06-22 21:19:02 ----D---- C:\Documents and Settings\All Users\Application Data\Codemasters
2010-06-22 19:59:04 ----D---- C:\Program Files\Codemasters
2010-06-22 19:49:28 ----A---- C:\WINDOWS\vncutil.exe
2010-06-22 19:49:23 ----A---- C:\WINDOWS\system32\RtkCoInstXP.dll
2010-06-22 19:49:23 ----A---- C:\WINDOWS\RtkAudioService.exe
2010-06-22 19:49:20 ----A---- C:\WINDOWS\system32\drivers\Monfilt.sys
2010-06-22 19:49:15 ----A---- C:\WINDOWS\system32\drivers\Ambfilt.sys
2010-06-22 17:29:01 ----A---- C:\WINDOWS\system32\wrap_oal.dll
2010-06-22 17:29:01 ----A---- C:\WINDOWS\system32\OpenAL32.dll
2010-06-22 17:05:43 ----A---- C:\WINDOWS\system32\XAudio2_7.dll
2010-06-22 17:05:43 ----A---- C:\WINDOWS\system32\XAPOFX1_5.dll
2010-06-22 17:05:42 ----A---- C:\WINDOWS\system32\xactengine3_7.dll
2010-06-22 17:05:42 ----A---- C:\WINDOWS\system32\D3DCompiler_43.dll
2010-06-22 17:05:41 ----A---- C:\WINDOWS\system32\d3dx11_43.dll
2010-06-22 17:05:41 ----A---- C:\WINDOWS\system32\d3dcsx_43.dll
2010-06-22 17:05:38 ----A---- C:\WINDOWS\system32\d3dx10_43.dll
2010-06-22 17:05:34 ----A---- C:\WINDOWS\system32\D3DX9_43.dll
2010-06-19 14:25:50 ----D---- C:\Program Files\Activision
2010-06-16 15:35:52 ----D---- C:\Documents and Settings\Marian\Application Data\bizarre creations

======List of files/folders modified in the last 1 months======

2010-07-15 11:44:12 ----D---- C:\WINDOWS\Temp
2010-07-15 11:43:49 ----D---- C:\WINDOWS\system32\CatRoot2
2010-07-15 11:43:43 ----D---- C:\WINDOWS
2010-07-15 11:42:34 ----D---- C:\WINDOWS\system32\drivers
2010-07-15 11:35:55 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-07-15 11:27:28 ----D---- C:\Documents and Settings\Marian\Application Data\uTorrent
2010-07-15 10:45:59 ----SHD---- C:\WINDOWS\Installer
2010-07-15 10:45:51 ----RD---- C:\Program Files
2010-07-15 10:45:36 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-07-15 10:34:31 ----D---- C:\Program Files\TeamViewer
2010-07-15 10:32:45 ----D---- C:\WINDOWS\system32
2010-07-15 10:22:45 ----HD---- C:\WINDOWS\inf
2010-07-15 10:19:16 ----D---- C:\WINDOWS\system32\config
2010-07-15 00:59:55 ----D---- C:\WINDOWS\WinSxS
2010-07-15 00:20:45 ----D---- C:\Documents and Settings\Marian\Application Data\mIRC
2010-07-14 23:51:13 ----D---- C:\Documents and Settings\Marian\Application Data\HLSW
2010-07-14 23:12:37 ----D---- C:\Program Files\mIRC
2010-07-14 22:53:46 ----SD---- C:\WINDOWS\Tasks
2010-07-14 18:45:42 ----D---- C:\WINDOWS\system32\NtmsData
2010-07-14 18:45:11 ----SHD---- C:\System Volume Information
2010-07-14 18:44:47 ----D---- C:\WINDOWS\Registration
2010-07-14 18:44:42 ----D---- C:\Program Files\Playbar
2010-07-14 18:25:06 ----D---- C:\WINDOWS\twain_32
2010-07-12 15:46:08 ----D---- C:\WINDOWS\Minidump
2010-07-12 15:38:39 ----D---- C:\WINDOWS\system32\DirectX
2010-07-11 17:56:06 ----D---- C:\WINDOWS\system32\CatRoot
2010-07-11 17:55:31 ----A---- C:\WINDOWS\win.ini
2010-07-11 17:55:23 ----D---- C:\Program Files\Windows Media Connect 2
2010-07-11 17:55:21 ----D---- C:\Program Files\Windows Media Player
2010-07-11 17:55:18 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-07-11 17:55:18 ----D---- C:\WINDOWS\Help
2010-07-09 12:52:14 ----RSD---- C:\WINDOWS\Fonts
2010-07-08 22:06:20 ----D---- C:\Program Files\CCleaner
2010-07-08 19:32:41 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2010-07-08 19:27:55 ----D---- C:\Program Files\Java
2010-07-08 18:35:31 ----D---- C:\WINDOWS\Microsoft.NET
2010-07-08 18:35:24 ----RSD---- C:\WINDOWS\assembly
2010-07-08 16:05:13 ----D---- C:\WINDOWS\system32\Restore
2010-07-08 16:05:12 ----D---- C:\Program Files\Outlook Express
2010-07-08 16:05:12 ----D---- C:\Program Files\Internet Explorer
2010-07-08 16:02:55 ----D---- C:\WINDOWS\Cursors
2010-07-08 16:02:53 ----D---- C:\WINDOWS\Media
2010-07-08 15:54:14 ----HD---- C:\Program Files\InstallShield Installation Information
2010-07-08 15:53:18 ----D---- C:\Program Files\Styler
2010-07-08 15:49:58 ----D---- C:\Documents and Settings\Marian\Application Data\IconTweaker
2010-07-08 15:49:58 ----D---- C:\Documents and Settings\All Users\Application Data\IconTweaker
2010-07-08 13:51:35 ----D---- C:\Documents and Settings\Marian\Application Data\Skype
2010-07-08 13:38:38 ----D---- C:\WINDOWS\Debug
2010-07-08 10:08:15 ----D---- C:\Documents and Settings\Marian\Application Data\skypePM
2010-07-08 09:44:10 ----D---- C:\Documents and Settings\Marian\Application Data\Adobe
2010-07-07 20:43:50 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-07-07 20:39:24 ----D---- C:\Program Files\Microsoft Silverlight
2010-07-07 20:39:23 ----D---- C:\WINDOWS\system32\wbem
2010-07-07 20:39:23 ----D---- C:\WINDOWS\AppPatch
2010-07-07 20:34:23 ----HD---- C:\WINDOWS\$hf_mig$
2010-07-07 20:18:54 ----D---- C:\Program Files\Movie Maker
2010-07-07 20:10:32 ----D---- C:\Program Files\Messenger
2010-07-07 20:08:32 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-07-07 19:46:57 ----SD---- C:\Documents and Settings\Marian\Application Data\Microsoft
2010-07-07 19:46:56 ----D---- C:\Documents and Settings\Marian\Application Data\Ventrilo
2010-07-07 17:33:34 ----D---- C:\WINDOWS\SoftwareDistribution
2010-07-07 17:32:36 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-07-04 20:44:03 ----D---- C:\Documents and Settings\Marian\Application Data\dvdcss
2010-07-02 20:37:15 ----D---- C:\Program Files\Mozilla Firefox
2010-06-30 22:46:07 ----D---- C:\Program Files\Online Services
2010-06-30 22:25:34 ----D---- C:\WINDOWS\system32\Side 9 Screensaver dir
2010-06-30 22:23:29 ----D---- C:\WINDOWS\Network Diagnostic
2010-06-30 20:30:03 ----D---- C:\WINDOWS\system32\Setup
2010-06-30 20:26:50 ----D---- C:\WINDOWS\security
2010-06-30 20:22:37 ----D---- C:\WINDOWS\system32\inetsrv
2010-06-30 20:22:36 ----D---- C:\WINDOWS\ime
2010-06-30 20:22:24 ----D---- C:\WINDOWS\system32\usmt
2010-06-30 20:22:24 ----D---- C:\WINDOWS\system32\en-us
2010-06-30 20:22:23 ----D---- C:\WINDOWS\l2schemas
2010-06-30 20:22:22 ----D---- C:\WINDOWS\PeerNet
2010-06-30 20:19:03 ----D---- C:\WINDOWS\system32\npp
2010-06-30 20:19:03 ----D---- C:\WINDOWS\mui
2010-06-30 20:19:00 ----D---- C:\WINDOWS\msagent
2010-06-30 20:18:56 ----D---- C:\WINDOWS\srchasst
2010-06-30 20:18:54 ----D---- C:\Program Files\NetMeeting
2010-06-30 20:18:50 ----D---- C:\WINDOWS\system32\Com
2010-06-30 20:18:43 ----D---- C:\Program Files\Windows NT
2010-06-30 20:18:34 ----D---- C:\Program Files\Common Files\System
2010-06-30 20:17:45 ----D---- C:\WINDOWS\system32\oobe
2010-06-30 20:17:43 ----D---- C:\WINDOWS\system
2010-06-30 20:13:01 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-06-30 20:10:07 ----D---- C:\WINDOWS\ehome
2010-06-30 18:11:56 ----D---- C:\WINDOWS\pss
2010-06-30 13:26:33 ----A---- C:\WINDOWS\NeroDigital.ini
2010-06-24 14:45:52 ----D---- C:\Program Files\AGEIA Technologies
2010-06-24 12:29:16 ----D---- C:\WINDOWS\system32\drivers\etc
2010-06-23 20:52:00 ----ASH---- C:\boot.ini
2010-06-23 18:42:03 ----D---- C:\Documents and Settings\Marian\Application Data\HPAppData
2010-06-23 12:25:36 ----D---- C:\WINDOWS\system32\ias
2010-06-22 19:49:59 ----D---- C:\WINDOWS\system32\RTCOM
2010-06-18 16:27:30 ----D---- C:\Program Files\Messenger Plus! Live

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2010-04-27 45648]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-04-26 691696]
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2010-03-01 124784]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 36352]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2010-02-16 60936]
R2 rspndr;Link-Layer Topology Discovery Responder; C:\WINDOWS\system32\DRIVERS\rspndr.sys [2007-02-18 62336]
R2 wg3n;SyGate for NT, wg3n; C:\WINDOWS\SYSTEM32\Drivers\wg3n.sys [2004-10-15 14568]
R2 wg4n;SyGate for NT, wg4n; C:\WINDOWS\SYSTEM32\Drivers\wg4n.sys [2004-10-15 14568]
R2 wg5n;SyGate for NT, wg5n; C:\WINDOWS\SYSTEM32\Drivers\wg5n.sys [2004-10-15 14568]
R2 wg6n;SyGate for NT, wg6n; C:\WINDOWS\SYSTEM32\Drivers\wg6n.sys [2004-10-15 14568]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2010-05-05 4807680]
R3 GEARAspiWDM;GEARAspiWDM; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2006-09-19 15664]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2007-02-18 138752]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2010-06-08 6056040]
R3 Ps2;PS2; C:\WINDOWS\system32\DRIVERS\PS2.sys [2010-05-27 19072]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2001-08-23 5888]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2008-01-03 105856]
R3 seehcri;Sony Ericsson seehcri Device Driver; C:\WINDOWS\system32\DRIVERS\seehcri.sys [2008-01-09 27632]
R3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-14 60032]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S0 Teefer;Teefer for NT; C:\WINDOWS\SYSTEM32\Drivers\Teefer.sys [2010-07-15 60496]
S1 wpsdrvnt;wpsdrvnt; \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys []
S2 ATE_PROCMON;ATE_PROCMON; \??\C:\Program Files\Anti Trojan Elite\ATEPMon.sys []
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2009-11-18 1691480]
S3 AtiHdmiService;ATI Function Driver for HDMI Service; C:\WINDOWS\system32\drivers\AtiHdmi.sys []
S3 az29wwl7;az29wwl7; C:\WINDOWS\system32\drivers\az29wwl7.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 cpuz132;cpuz132; \??\C:\DOCUME~1\Marian\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys []
S3 GMSIPCI;GMSIPCI; \??\D:\INSTALL\GMSIPCI.SYS []
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2007-10-30 49920]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2007-10-30 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2007-10-30 21568]
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2009-11-18 1395800]
S3 MSICPL;MSICPL; \??\D:\install4\MSICPL.sys []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 NTACCESS;NTACCESS; \??\D:\NTACCESS.sys []
S3 PAC7302;CANYON USB PC CAMERA; C:\WINDOWS\system32\DRIVERS\PAC7302.SYS [2010-07-15 458752]
S3 s117bus;Sony Ericsson Device 117 driver (WDM); C:\WINDOWS\system32\DRIVERS\s117bus.sys [2007-06-25 82984]
S3 s117mdfl;Sony Ericsson Device 117 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s117mdfl.sys [2007-06-25 14888]
S3 s117mdm;Sony Ericsson Device 117 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s117mdm.sys [2007-06-25 108456]
S3 s117mgmt;Sony Ericsson Device 117 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s117mgmt.sys [2007-06-25 100264]
S3 s117nd5;Sony Ericsson Device 117 USB Ethernet Emulation SEMC117 (NDIS); C:\WINDOWS\system32\DRIVERS\s117nd5.sys [2007-06-25 22952]
S3 s117obex;Sony Ericsson Device 117 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s117obex.sys [2007-06-25 98344]
S3 s117unic;Sony Ericsson Device 117 USB Ethernet Emulation SEMC117 (WDM); C:\WINDOWS\system32\DRIVERS\s117unic.sys [2007-06-25 98856]
S3 SetupNTGLM7X;SetupNTGLM7X; \??\D:\NTGLM7X.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 vsdatant;vsdatant; C:\WINDOWS\system32\drivers\vsdatant.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2010-04-01 267432]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2010-02-24 135336]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2010-05-05 602112]
R2 hpqddsvc;HP CUE DeviceDiscovery Service; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-04-12 153376]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2007-09-20 853288]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 OMSI download service;Sony Ericsson OMSI download service; C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 SpyHunter 4 Service;SpyHunter 4 Service; C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE [2010-05-18 327064]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 SmcService;Sygate Personal Firewall; C:\Program Files\Sygate\SPF\smc.exe [2004-10-15 2577632]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-05-04 651720]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2007-09-20 382248]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2009-01-30 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: prosím o kontrolu logu / otváranie stránok

Napsal: 15 črc 2010 19:40
od vyosek
Nevim co je na tom samozrejmeho pouzivat cracky a uz vubec ne na antivirove/spywareove programy :?: Takhle tu budete brzy s problemy znovu :!:

Takze cracknuty SpyHunter odinstalovat, navic nepatri mezi ty lepsi programy, a nahradit free resenim Udelejte kontrolu jednim z nich a log mile rad uvidim. A jeste tedy poprosim o log z toho SpyHuntera, kdyz jste ho uz pouzil, i kdyz cracknuty :o

Re: prosím o kontrolu logu / otváranie stránok

Napsal: 15 črc 2010 19:51
od SSemteXX
Vedel som, že budete po mne chcieť log no žiadny log po skončení skenovania nenašiel, nikde, prehľadal som celé menu nič ako save log alebo niečo, ani mi ho nikde neuložilo, ale môžem Vás uistiť, že Spyhunter som odinštaloval a nemám zatiaľ žiadne problémy.

Stiahol som si SAS, akurát sťahuje aktualizácie, dám preveriť PC a potom sem dám ten log :)

Re: prosím o kontrolu logu / otváranie stránok

Napsal: 15 črc 2010 20:03
od vyosek
Ok, pockam na log ze SAS...

Re: prosím o kontrolu logu / otváranie stránok

Napsal: 15 črc 2010 20:42
od SSemteXX
Do prilohy som dal screen z plochy, hodilo mi tam nejaký čudný prehliadávač, načo to tam je? Je to možné, že je to spôsobené vírusom?
Nech sa páči, log zo SAS :

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 07/15/2010 at 09:33 PM

Application Version : 4.40.1002

Core Rules Database Version : 5206
Trace Rules Database Version: 3018

Scan type : Complete Scan
Total Scan Time : 00:39:06

Memory items scanned : 686
Memory threats detected : 0
Registry items scanned : 7704
Registry threats detected : 14
File items scanned : 23040
File threats detected : 0

Trojan.Agent/Gen-SSHNAS
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SSHNAS
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SSHNAS#NextInstance
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SSHNAS\0000
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SSHNAS\0000#Service
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SSHNAS\0000#Legacy
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SSHNAS\0000#ConfigFlags
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SSHNAS\0000#Class
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SSHNAS\0000#ClassGUID
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SSHNAS\0000#DeviceDesc

Malware.Trace
HKU\.DEFAULT\SOFTWARE\XML
HKU\S-1-5-18\SOFTWARE\XML

Disabled.SecurityCenterOption
HKLM\SOFTWARE\MICROSOFT\SECURITY CENTER#ANTIVIRUSDISABLENOTIFY
HKLM\SOFTWARE\MICROSOFT\SECURITY CENTER#FIREWALLDISABLENOTIFY
HKLM\SOFTWARE\MICROSOFT\SECURITY CENTER#UPDATESDISABLENOTIFY

Re: prosím o kontrolu logu / otváranie stránok

Napsal: 15 črc 2010 20:48
od vyosek
:arrow: Vse smazte, preci jen se tam objevil stary znamy sshnas :?:

:arrow: Stahnete OTM (viz muj podpis)
  • Pokud pouzivate Win Vista ci W7, kliknete na OTM pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do leveho okna Paste Instructions for Items to be Moved (pod zlutou caru) vlozte obsah, ktery mate nize
  • Kód: Vybrat vše

    :services
    SSHNAS
    
    :files
    C:\WINDOWS\tasks\At*.job
    %windir%\msa.exe
    %windir%\system32\sshnas.dll
    %windir%\system32\sshnas21.dll
    %windir%\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
    %windir%\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
    
    :commands
    [EMPTYTEMP]
    [EMPTYFLASH]
    [CLEARALLRESTOREPOINTS]
  • Kliknete na cervene tlacitko MoveIt!
  • Sem pote dejte obsah okna Results (pod zelenou carou)
  • Pokud budete vyzvani na restart, dejte Yes, log pote najdete C:\_OTM\MovedFiles