Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Win32/Mebroot.K trojský kůň

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
davem
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 25 bře 2010 08:26

Win32/Mebroot.K trojský kůň

#1 Příspěvek od davem »

Zdravim,

NOD 32 mi začal hlásit: MBR sektor 1. fyzického disku - Win32/Mebroot.K trojský kůň. Prosím o pomoc :)

Log:


Logfile of random's system information tool 1.08 (written by random/random)
Run by Jan at 2010-08-16 18:00:48
Microsoft® Windows Vista™ Ultimate Service Pack 1
System drive C: has 24 GB (26%) free of 90 GB
Total RAM: 3582 MB (43% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:01, on 2010-08-16
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\epson\Creativity Suite\Event Manager\EEventManager.exe
C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe
C:\Program Files\CyberLink\Shared Files\brs.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Java\jre6\launch4j-tmp\frd.exe
C:\Program Files\epson\Creativity Suite\Copy Utility\ECOPY.EXE
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Jan\Desktop\RSIT.exe
C:\Program Files\trend micro\Jan.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60341
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=60341
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe"
O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe"
O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: FreeRapid 0.83u1.lnk = C:\Users\Jan\Desktop\FreeRapid-0.83u1\frd.exe
O8 - Extra context menu item: &Stáhnout FlashGetem - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: &Stáhnout všechny FlashGetem - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O16 - DPF: {A3E21079-7F41-4125-9EBB-FD44CFCC0AC1} (WLCTSCControl Class) - https://www.mesh.com/0.9.4014.28/TSWeb.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe

--
End of file - 8113 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Ad-Aware Update (Weekly).job
C:\Windows\tasks\User_Feed_Synchronization-{13C540E2-2E69-4923-A003-E4D3D7B77E21}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}]
FGCatchUrl - C:\Program Files\FlashGet\jccatch.dll [2007-08-06 94308]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2008-09-13 308856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-07-13 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F156768E-81EF-470C-9057-481BA8380DBA}]
FlashGet GetFlash Class - C:\Program Files\FlashGet\getflash.dll [2007-05-18 163840]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvSvc"=C:\Windows\system32\nvsvc.dll [2007-12-11 86016]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2007-12-11 8530464]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2007-12-11 81920]
"NBKeyScan"=C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2008-06-08 2221352]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-02-13 4915200]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"EEventManager"=C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe [2006-10-12 102400]
"Ad-Watch"=C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe [2010-03-07 524632]
"RemoteControl8"=C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe [2008-10-17 91432]
"PDVD8LanguageShortcut"=C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe [2007-12-14 50472]
"BDRegion"=C:\Program Files\Cyberlink\Shared Files\brs.exe [2009-01-20 75048]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2010-07-02 2202704]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-05-21 1233920]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [2008-06-24 1840424]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-12-10 216520]
"TomTomHOME.exe"=C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe [2010-06-24 247144]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2009-04-13 2387968]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Flashget]
C:\Program Files\FlashGet\flashget.exe [2007-09-25 2007088]

C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
FreeRapid 0.83u1.lnk - C:\Users\Jan\Desktop\FreeRapid-0.83u1\frd.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSEXESVC]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PSEXESVC]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======List of files/folders created in the last 1 months======

2010-08-16 18:00:48 ----D---- C:\rsit
2010-08-16 18:00:48 ----D---- C:\Program Files\trend micro

======List of files/folders modified in the last 1 months======

2010-08-16 18:01:00 ----D---- C:\Windows\Prefetch
2010-08-16 18:00:51 ----D---- C:\Windows\temp
2010-08-16 18:00:48 ----RD---- C:\Program Files
2010-08-16 17:40:27 ----D---- C:\Downloads
2010-08-16 17:21:47 ----D---- C:\ProgramData\DVD Shrink
2010-08-16 16:48:45 ----SHD---- C:\System Volume Information
2010-08-16 13:41:08 ----A---- C:\Windows\NeroDigital.ini
2010-08-16 09:49:47 ----D---- C:\Windows\System32
2010-08-16 09:49:46 ----D---- C:\Windows\inf
2010-08-16 09:49:46 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-08-11 13:00:15 ----SHD---- C:\Windows\Installer
2010-08-11 13:00:04 ----D---- C:\Windows\system32\drivers
2010-08-06 13:13:17 ----D---- C:\Windows\system32\FxsTmp
2010-08-05 21:26:38 ----D---- C:\Windows\system32\catroot2
2010-08-02 06:41:37 ----D---- C:\Program Files\AIMP2
2010-07-25 08:42:06 ----D---- C:\Program Files\Mozilla Firefox

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 fvevol;BitLocker Drive Encryption Filter Driver; C:\Windows\System32\DRIVERS\fvevol.sys [2008-05-21 145464]
R0 Lbd;Lbd; C:\Windows\system32\DRIVERS\Lbd.sys [2009-05-04 64160]
R0 Pnp680r;Silicon Image SiI 0680 Medley Raid Controller; C:\Windows\system32\DRIVERS\pnp680r.sys [2007-07-19 110120]
R0 PxHelp20;PxHelp20; C:\Windows\system32\DRIVERS\PxHelp20.sys [2008-09-06 20016]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2009-01-01 717296]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-04-28 114984]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};Power Control [2009/04/25 13:23:15]; \??\C:\Program Files\CyberLink\PowerDVD8\000.fcl [2009-01-20 87536]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-06-24 136120]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2010-04-28 96896]
R3 Afc;PPdus ASPI Shell; C:\Windows\system32\drivers\Afc.sys [2005-02-23 11776]
R3 BENDER;Pinnacle AV/DV2 Capture; C:\Windows\system32\drivers\bender.sys [2006-12-04 203264]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-02-14 2061528]
R3 MarvinBus;Pinnacle Marvin Bus; C:\Windows\system32\DRIVERS\MarvinBus.sys [2005-09-23 171520]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2007-12-11 8238688]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2008-01-25 106496]
R3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-05-21 35328]
S3 61883;61883 Unit Device; C:\Windows\system32\DRIVERS\61883.sys [2008-05-21 45696]
S3 a2vytu1q;a2vytu1q; C:\Windows\system32\drivers\a2vytu1q.sys []
S3 Avc;Zařízení AVC; C:\Windows\system32\DRIVERS\avc.sys [2008-05-21 40448]
S3 CrystalSysInfo;CrystalSysInfo; \??\C:\Program Files\MediaCoder\SysInfo.sys [2007-09-25 15152]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-05-21 5632]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2009-06-10 16608]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 mbr;mbr; \??\C:\Users\Jan\AppData\Local\Temp\mbr.sys []
S3 MSDV;Microsoft DV Camera and VCR; C:\Windows\system32\DRIVERS\msdv.sys [2008-05-21 52608]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-05-21 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-05-21 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-05-21 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-05-21 6016]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-05-21 39936]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-05-21 83328]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-05-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-05-21 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2010-07-02 810144]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2010-03-07 1029456]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2009-04-13 73728]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2008-06-08 877864]
R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\Windows\system32\IoctlSvc.exe [2006-12-19 81920]
R2 TomTomHOMEService;TomTomHOMEService; C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe [2010-06-24 92008]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2008-06-24 537896]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2008-09-06 72704]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2010-07-02 33584]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2008-08-24 654848]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

-----------------EOF-----------------

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Win32/Mebroot.K trojský kůň

#2 Příspěvek od Caroprd111 »

Zdravím :)


Obrázek Stáhněte a uložte http://download.bleepingcomputer.com/sUBs/ComboFix.exe na plochu.
  • Vypněte všechny rezidentní bezpečnostní programy - firewally, antiviry, antispywary
  • Vložte do PC všechny flash disky, které používáte.
  • Spusťte aplikaci pod účtem s oprávněním Administrátora (Správce), ihned po startu se zobrazí stránka s licenčními podmínkami, pokračujte stisknutím tlačítka "Ano".
  • Dále postupujte dle pokynů, během scanu nespouštějte jiné aplikace a neklikejte do zobrazujícího se okna :!:
  • Scan by měl trvat okolo 5 - 10 minut, po dokončení Combofix zobrazí log C:\ComboFix.txt , který sem vložte.
  • Během skenování může být počítač restartován.
Obrázek

davem
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 25 bře 2010 08:26

Re: Win32/Mebroot.K trojský kůň

#3 Příspěvek od davem »

diky za odpoved...

zde je log:


ComboFix 10-08-15.04 - Jan 2010-08-16 19:59:54.3.4 - x86
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1250.1.1029.18.3582.2137 [GMT 2:00]
Spuštěný z: c:\users\Jan\Desktop\ComboFix.exe
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Rezidentní štít AV je zapnutý

.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system\Color

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-07-16 do 2010-08-16 )))))))))))))))))))))))))))))))
.

2010-08-16 18:05 . 2010-08-16 18:07 -------- d-----w- c:\users\Jan\AppData\Local\temp
2010-08-16 18:05 . 2010-08-16 18:05 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-08-16 16:00 . 2010-08-16 16:01 -------- d-----w- C:\rsit
2010-08-16 16:00 . 2010-08-16 16:01 -------- d-----w- c:\program files\trend micro

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-16 18:03 . 2007-01-08 21:15 598652 ----a-w- c:\windows\system32\perfh005.dat
2010-08-16 18:03 . 2007-01-08 21:15 114808 ----a-w- c:\windows\system32\perfc005.dat
2010-08-16 16:27 . 2008-09-11 17:20 -------- d-----w- c:\program files\AIMP2
2010-08-16 15:21 . 2008-08-24 11:56 -------- d-----w- c:\programdata\DVD Shrink
2010-07-13 16:53 . 2010-07-13 16:53 -------- d-----w- c:\users\Jan\AppData\Roaming\VitySoft
2010-07-13 16:52 . 2010-07-13 16:52 -------- d-----w- c:\program files\Common Files\Java
2010-07-13 16:51 . 2010-07-13 16:52 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-13 16:51 . 2010-07-13 16:51 -------- d-----w- c:\program files\Java
2010-07-13 15:51 . 2008-08-24 11:57 -------- d-----w- c:\users\Jan\AppData\Roaming\Vso
2010-06-24 07:04 . 2010-06-24 07:04 136120 ----a-w- c:\windows\system32\drivers\eamonm.sys
2008-05-21 08:47 . 2008-05-21 08:17 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-05-21 1233920]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-10 216520]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2010-06-24 247144]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-04-13 2387968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-12-11 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-11 8530464]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-12-11 81920]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 2221352]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"RtHDVCpl"="RtHDVCpl.exe" [2008-02-13 4915200]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"EEventManager"="c:\program files\EPSON\Creativity Suite\Event Manager\EEventManager.exe" [2006-10-12 102400]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2010-03-07 524632]
"RemoteControl8"="c:\program files\CyberLink\PowerDVD8\PDVD8Serv.exe" [2008-10-17 91432]
"PDVD8LanguageShortcut"="c:\program files\CyberLink\PowerDVD8\Language\Language.exe" [2007-12-14 50472]
"BDRegion"="c:\program files\Cyberlink\Shared Files\brs.exe" [2009-01-20 75048]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-07-02 2202704]

c:\users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
FreeRapid 0.83u1.lnk - c:\users\Jan\Desktop\FreeRapid-0.83u1\frd.exe [2010-7-13 35840]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"wave3"=audpci40.dll
"midi3"=audpci40.dll
"mixer3"=audpci40.dll
"aux3"=audpci40.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Flashget]
2007-09-25 08:10 2007088 ----a-w- c:\program files\FlashGet\flashget.exe

R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2009-01-01 717296]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-05-04 64160]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-04-28 114984]
S2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};Power Control [2009/04/25 13:23];c:\program files\CyberLink\PowerDVD8\000.fcl [2009-01-20 17:56 87536]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-06-24 136120]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2010-07-02 810144]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [2010-04-28 96896]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-03-07 1029456]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2010-06-24 92008]
S3 BENDER;Pinnacle AV/DV2 Capture;c:\windows\system32\drivers\bender.sys [2006-12-04 203264]


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-04-13 14:08 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'

2010-08-16 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 09:32]

2010-08-16 c:\windows\Tasks\User_Feed_Synchronization-{13C540E2-2E69-4923-A003-E4D3D7B77E21}.job
- c:\windows\system32\msfeedssync.exe [2008-05-21 08:41]
.
.
------- Doplňkový sken -------
.
uInternet Settings,ProxyOverride = *.local
IE: &Stáhnout FlashGetem - c:\program files\FlashGet\jc_link.htm
IE: &Stáhnout všechny FlashGetem - c:\program files\FlashGet\jc_all.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: {A3E21079-7F41-4125-9EBB-FD44CFCC0AC1} - hxxps://www.mesh.com/0.9.4014.28/TSWeb.cab
FF - ProfilePath - c:\users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\mg9yarla.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - plugin: c:\adobe\QuickTime\Plugins\npqtplugin.dll
FF - plugin: c:\adobe\QuickTime\Plugins\npqtplugin2.dll
FF - plugin: c:\adobe\QuickTime\Plugins\npqtplugin3.dll
FF - plugin: c:\adobe\QuickTime\Plugins\npqtplugin4.dll
FF - plugin: c:\adobe\QuickTime\Plugins\npqtplugin5.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-16 20:08
Windows 6.0.6001 Service Pack 1 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD8\000.fcl"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:41,11,bf,76,f2,6a,a9,2d,5c,87,78,84,dc,7f,bc,e9,70,b6,1a,f6,ff,
56,4f,63,8d,16,48,5c,54,1d,93,47,1b,30,1a,bd,03,2f,a4,09,19,11,2b,ed,c9,ee,\
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'Explorer.exe'(3296)
c:\program files\ArcSoft\PhotoImpression 5\share\pihook.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\IoctlSvc.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\conime.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\rundll32.exe
c:\windows\RtHDVCpl.exe
c:\program files\Java\jre6\launch4j-tmp\frd.exe
c:\program files\Common Files\Nero\Lib\NMIndexingService.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Celkový čas: 2010-08-16 20:13:31 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-08-16 18:13

Před spuštěním: Volných bajtů: 25.601.712.128
Po spuštění: Volných bajtů: 26.127.618.048

- - End Of File - - E5D0E70245EE9CE96A9E94EC619CFA01

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Win32/Mebroot.K trojský kůň

#4 Příspěvek od Caroprd111 »

Obrázek Doporučuji odinstalovat Ad-Aware.


Obrázek Odinstalujte všechny emulátory virtuálních mechanik.

Obrázek Stáhněte SPTD http://www.duplexsecure.com/en/downloads
  • Vyberte verzi podle svého operačního systému (64 & 32b). Uložte na plochu a spusťte.
  • zvolte možnost Uninstall a restartujte PC.

Obrázek Stáhněte a spusťte http://www.jpshortstuff.247fixes.com/Defogger.exe
  • Klikněte na "Disable" a restartujte PC.

Obrázek Stáhněte MBR na plochu http://www2.gmer.net/mbr/mbr.exe

Obrázek Start > Spustit (Win + R)
  • Vyskočí okénko, zkopírujte do něj:

Kód: Vybrat vše

"%userprofile%\plocha\mbr" -t
  • Klikněte na OK
  • Vytvoří se log s názvem mbr.log, vložte ho sem.


Obrázek Dejte log z Gmer http://www.viry.cz/forum/viewtopic.php?f=29&t=62878
Obrázek

davem
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 25 bře 2010 08:26

Re: Win32/Mebroot.K trojský kůň

#5 Příspěvek od davem »

Daemona jsem odinstaloval

v SPTD jsem nemel osvicenu volbu Uninstall, takze to vypada ze tam neni

Defogger probehl.

MBR:


Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
kernel: MBR read successfully
user & kernel MBR OK

davem
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 25 bře 2010 08:26

Re: Win32/Mebroot.K trojský kůň

#6 Příspěvek od davem »

gmer maly:


GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-08-16 21:25:37
Windows 6.0.6001 Service Pack 1
Running: gmer.exe; Driver: C:\Users\Jan\AppData\Local\Temp\uwldypog.sys


---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Společnost Microsoft)

---- EOF - GMER 1.0.15 ----

Pripada me moc maly :)

Velky:


GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-08-16 21:39:51
Windows 6.0.6001 Service Pack 1
Running: gmer.exe; Driver: C:\Users\Jan\AppData\Local\Temp\uwldypog.sys


---- System - GMER 1.0.15 ----

INT 0x01 \??\C:\Users\Jan\AppData\Local\Temp\mbr.sys A04522A4

---- Kernel code sections - GMER 1.0.15 ----

.text C:\Windows\system32\DRIVERS\nvlddmkm.sys section is writeable [0x8F20A340, 0x39DB57, 0xE8000020]
.text C:\Program Files\CyberLink\PowerDVD8\000.fcl section is writeable [0xA0410000, 0x2892, 0xE8000020]
.vmp2 C:\Program Files\CyberLink\PowerDVD8\000.fcl entry point in ".vmp2" section [0xA0433050]
? C:\Users\Jan\AppData\Local\Temp\mbr.sys Systém nemůže nalézt uvedený soubor. !

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1620] kernel32.dll!SetUnhandledExceptionFilter 76656E2D 4 Bytes [C2, 04, 00, 00]

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\Windows\system32\SearchProtocolHost.exe[3816] @ C:\Windows\system32\ole32.dll [USER32.dll!DialogBoxParamW] [6D4BDB6B] C:\Windows\AppPatch\AcSpecfc.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Windows\system32\SearchProtocolHost.exe[3816] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!DialogBoxParamW] [6D4BDB6B] C:\Windows\AppPatch\AcSpecfc.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Windows\system32\SearchProtocolHost.exe[3816] @ C:\Windows\system32\SHELL32.dll [USER32.dll!DialogBoxParamW] [6D4BDB6B] C:\Windows\AppPatch\AcSpecfc.DLL (Windows Compatibility DLL/Microsoft Corporation)

---- Devices - GMER 1.0.15 ----

AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume6 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Společnost Microsoft)

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x33 0x7E 0x03 0x25 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xA0 0x1F 0x78 0x0B ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x6F 0x4B 0xE5 0xFC ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x33 0x7E 0x03 0x25 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xA0 0x1F 0x78 0x0B ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x6F 0x4B 0xE5 0xFC ...
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0x2E 0xE8 0xE1 0x00 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x6A 0x9C 0xD6 0x61 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0xFF 0x7C 0x85 0xE0 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x3E 0x1E 0x9E 0xE0 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xF5 0x1D 0x4D 0x73 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0xB0 0x18 0xED 0xA7 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0xFB 0xA7 0x78 0xE6 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version
Reg HKLM\SOFTWARE\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version@Version 0x41 0x11 0xBF 0x76 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d 0x01 0x3A 0x48 0xFC ...
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3 0xF6 0x0F 0x4E 0x58 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b 0x3D 0xCE 0xEA 0x26 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6 0xE3 0x0E 0x66 0xD5 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2 0x05 0x73 0x21 0xDD ...

---- EOF - GMER 1.0.15 ----

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Win32/Mebroot.K trojský kůň

#7 Příspěvek od Caroprd111 »

Jak se chová PC :???:
Obrázek

davem
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 25 bře 2010 08:26

Re: Win32/Mebroot.K trojský kůň

#8 Příspěvek od davem »

nod stale po startu pc hlasi stejnou hlasku ohledne Win32/Mebroot.K trojský kůň.. nemuze to delat i jiny disk? nemam v GMERu zkontrolovat pro jistotu vsechny? ted sem nechaval pouze C.

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Win32/Mebroot.K trojský kůň

#9 Příspěvek od Caroprd111 »

Obrázek

davem
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 25 bře 2010 08:26

Re: Win32/Mebroot.K trojský kůň

#10 Příspěvek od davem »

Uz to vypada OK

Obrázek

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Win32/Mebroot.K trojský kůň

#11 Příspěvek od Caroprd111 »

Obrázek Doporučuji odinstalovat Ad-Aware.


Obrázek Odinstalujte ComboFix přes:
Start >> Spustit, zkopírujte do okénka:

ComboFix /Uninstall

stiskněte Enter



Obrázek Stáhněte T-Cleaner http://sweb.cz/Marinus/T-Cleaner.exe
  • Spusťte, pro potvrzení volby mačkejte klávesu A, Enter
  • Po použití program vymažte. Pozor, antiviry ho mohou falešně označit za vir.

Obrázek Stáhněte TFC http://oldtimer.geekstogo.com/TFC.exe
  • Spusťte.
  • Klikněte na "Start". Potvrďte hlášku kliknutím na "Ok" (Bude následovat restart)

Obrázek Stáhněte OTC http://oldtimer.geekstogo.com/OTC.exe
  • Spusťte.
  • Klikněte na "CleanUp!". Potvrďte hlášky kliknutím na "Yes" (Bude následovat restart)


Obrázek Stáhněte Ccleaner http://viry.cz/forum/viewtopic.php?t=7478
  • Nainstalujte a v průběhu instalace odškrtněte, že chcete instalovat yahoo toolbar.

    Obrázek Záložka Čistič
  • Dejte analyzovat, po dokončení dejte Spustit Ccleaner.

    Obrázek Záložka Registry
  • Klikněte na Hledej problémy, po dokončení klikněte na Opravit problémy, zálohu dělat nemusíte, potom dejte Opravit všechny problémy.
    Obrázek OK Obrázek Zavřít

Obrázek Doinstalujte SP2 http://www.viry.cz/forum/viewtopic.php?f=46&t=86100


Obrázek V logu nevidím firewall, doinstalujte :!: Přehled: http://www.viry.cz/forum/viewtopic.php?f=41&t=6523


Obrázek Dejte nový log z RSIT.
Obrázek

davem
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 25 bře 2010 08:26

Re: Win32/Mebroot.K trojský kůň

#12 Příspěvek od davem »

Vse hotovo, zde je log:

Logfile of random's system information tool 1.08 (written by random/random)
Run by Jan at 2010-08-18 20:55:50
Microsoft® Windows Vista™ Ultimate Service Pack 2
System drive C: has 25 GB (28%) free of 90 GB
Total RAM: 3582 MB (73% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:56:01, on 18.8.2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\epson\Creativity Suite\Event Manager\EEventManager.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe
C:\Program Files\CyberLink\Shared Files\brs.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Jan\Desktop\RSIT.exe
C:\Program Files\trend micro\Jan.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60341
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=60341
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe"
O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe"
O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: FreeRapid 0.83u1.lnk = C:\Users\Jan\Desktop\FreeRapid-0.83u1\frd.exe
O8 - Extra context menu item: &Stáhnout FlashGetem - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: &Stáhnout všechny FlashGetem - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O16 - DPF: {A3E21079-7F41-4125-9EBB-FD44CFCC0AC1} (WLCTSCControl Class) - https://www.mesh.com/0.9.4014.28/TSWeb.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe

--
End of file - 7852 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Ad-Aware Update (Weekly).job
C:\Windows\tasks\User_Feed_Synchronization-{13C540E2-2E69-4923-A003-E4D3D7B77E21}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}]
FGCatchUrl - C:\Program Files\FlashGet\jccatch.dll [2007-08-06 94308]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2008-09-13 308856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-07-13 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F156768E-81EF-470C-9057-481BA8380DBA}]
FlashGet GetFlash Class - C:\Program Files\FlashGet\getflash.dll [2007-05-18 163840]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvSvc"=C:\Windows\system32\nvsvc.dll [2007-12-11 86016]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2007-12-11 8530464]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2007-12-11 81920]
"NBKeyScan"=C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2008-06-08 2221352]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-02-13 4915200]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"EEventManager"=C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe [2006-10-12 102400]
"RemoteControl8"=C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe [2008-10-17 91432]
"PDVD8LanguageShortcut"=C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe [2007-12-14 50472]
"BDRegion"=C:\Program Files\Cyberlink\Shared Files\brs.exe [2009-01-20 75048]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2010-07-02 2202704]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-10 1233920]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [2008-06-24 1840424]
"TomTomHOME.exe"=C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe [2010-06-24 247144]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2009-04-13 2387968]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Flashget]
C:\Program Files\FlashGet\flashget.exe [2007-09-25 2007088]

C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
FreeRapid 0.83u1.lnk - C:\Users\Jan\Desktop\FreeRapid-0.83u1\frd.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"BindDirectlyToPropertySetStorage"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======List of files/folders created in the last 1 months======

2010-08-18 20:50:16 ----A---- C:\Windows\system32\drivers\SbFwIm.sys
2010-08-18 20:50:01 ----D---- C:\Program Files\Sunbelt Software
2010-08-18 20:48:39 ----D---- C:\Windows\Internet Logs
2010-08-18 20:40:53 ----D---- C:\rsit
2010-08-18 20:32:18 ----A---- C:\Windows\system32\drivers\tcpipreg.sys
2010-08-18 20:32:18 ----A---- C:\Windows\system32\drivers\tcpip.sys
2010-08-18 20:32:18 ----A---- C:\Windows\system32\drivers\netio.sys
2010-08-18 20:31:25 ----D---- C:\ProgramData\CheckPoint
2010-08-18 20:23:34 ----ASH---- C:\hiberfil.sys
2010-08-18 20:20:12 ----D---- C:\Windows\system32\eu-ES
2010-08-18 20:20:12 ----D---- C:\Windows\system32\ca-ES
2010-08-18 20:20:09 ----D---- C:\Windows\system32\vi-VN
2010-08-18 20:19:14 ----A---- C:\Windows\ntbtlog.txt
2010-08-18 19:53:14 ----D---- C:\Windows\system32\SPReview
2010-08-18 19:41:45 ----A---- C:\Windows\system32\scavenge.dll
2010-08-18 19:41:38 ----A---- C:\Windows\system32\compcln.exe
2010-08-18 19:36:37 ----A---- C:\Windows\system32\secur32.dll
2010-08-18 19:36:37 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2010-08-18 19:36:37 ----A---- C:\Windows\system32\secproc_ssp.dll
2010-08-18 19:36:37 ----A---- C:\Windows\system32\secproc_isv.dll
2010-08-18 19:36:37 ----A---- C:\Windows\system32\secproc.dll
2010-08-18 19:36:37 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2010-08-18 19:36:37 ----A---- C:\Windows\system32\SearchIndexer.exe
2010-08-18 19:36:37 ----A---- C:\Windows\system32\SearchFilterHost.exe
2010-08-18 19:36:37 ----A---- C:\Windows\system32\sdohlp.dll
2010-08-18 19:36:37 ----A---- C:\Windows\system32\sdclt.exe
2010-08-18 19:36:36 ----A---- C:\Windows\system32\scrrun.dll
2010-08-18 19:36:36 ----A---- C:\Windows\system32\samlib.dll
2010-08-18 19:36:36 ----A---- C:\Windows\system32\rwinsta.exe
2010-08-18 19:36:36 ----A---- C:\Windows\system32\rtutils.dll
2010-08-18 19:36:36 ----A---- C:\Windows\system32\rtffilt.dll
2010-08-18 19:36:36 ----A---- C:\Windows\system32\rsaenh.dll
2010-08-18 19:36:36 ----A---- C:\Windows\system32\rrinstaller.exe
2010-08-18 19:36:36 ----A---- C:\Windows\system32\rpchttp.dll
2010-08-18 19:36:36 ----A---- C:\Windows\system32\rpcss.dll
2010-08-18 19:36:36 ----A---- C:\Windows\system32\rpcrt4.dll
2010-08-18 19:36:36 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2010-08-18 19:36:36 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2010-08-18 19:36:36 ----A---- C:\Windows\system32\RMActivate_isv.exe
2010-08-18 19:36:36 ----A---- C:\Windows\system32\RMActivate.exe
2010-08-18 19:36:36 ----A---- C:\Windows\system32\riched20.dll
2010-08-18 19:36:36 ----A---- C:\Windows\system32\drivers\RNDISMP.sys
2010-08-18 19:36:36 ----A---- C:\Windows\system32\drivers\rmcast.sys
2010-08-18 19:36:35 ----A---- C:\Windows\system32\SCardSvr.dll
2010-08-18 19:36:35 ----A---- C:\Windows\system32\scansetting.dll
2010-08-18 19:36:35 ----A---- C:\Windows\system32\samsrv.dll
2010-08-18 19:36:34 ----A---- C:\Windows\system32\schedsvc.dll
2010-08-18 19:36:34 ----A---- C:\Windows\system32\schannel.dll
2010-08-18 19:36:34 ----A---- C:\Windows\system32\scrptadm.dll
2010-08-18 19:36:34 ----A---- C:\Windows\system32\scrobj.dll
2010-08-18 19:36:34 ----A---- C:\Windows\system32\scksp.dll
2010-08-18 19:36:34 ----A---- C:\Windows\system32\scesrv.dll
2010-08-18 19:36:34 ----A---- C:\Windows\system32\scecli.dll
2010-08-18 19:36:32 ----A---- C:\Windows\system32\PnPutil.exe
2010-08-18 19:36:32 ----A---- C:\Windows\system32\perfdisk.dll
2010-08-18 19:36:32 ----A---- C:\Windows\system32\PerfCenterCPL.dll
2010-08-18 19:36:32 ----A---- C:\Windows\system32\pdh.dll
2010-08-18 19:36:32 ----A---- C:\Windows\system32\pcaui.dll
2010-08-18 19:36:32 ----A---- C:\Windows\system32\p2psvc.dll
2010-08-18 19:36:32 ----A---- C:\Windows\system32\P2PGraph.dll
2010-08-18 19:36:32 ----A---- C:\Windows\system32\drivers\pciidex.sys
2010-08-18 19:36:32 ----A---- C:\Windows\system32\drivers\pciide.sys
2010-08-18 19:36:32 ----A---- C:\Windows\system32\drivers\pci.sys
2010-08-18 19:36:32 ----A---- C:\Windows\system32\drivers\partmgr.sys
2010-08-18 19:36:32 ----A---- C:\Windows\system32\drivers\pacer.sys
2010-08-18 19:36:31 ----A---- C:\Windows\system32\powercpl.dll
2010-08-18 19:36:31 ----A---- C:\Windows\system32\PortableDeviceTypes.dll
2010-08-18 19:36:31 ----A---- C:\Windows\system32\PortableDeviceClassExtension.dll
2010-08-18 19:36:31 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2010-08-18 19:36:31 ----A---- C:\Windows\system32\PNPXAssoc.dll
2010-08-18 19:36:31 ----A---- C:\Windows\system32\PnPUnattend.exe
2010-08-18 19:36:31 ----A---- C:\Windows\system32\pnpui.dll
2010-08-18 19:36:31 ----A---- C:\Windows\system32\pnpsetup.dll
2010-08-18 19:36:31 ----A---- C:\Windows\system32\pnidui.dll
2010-08-18 19:36:31 ----A---- C:\Windows\system32\pmcsnap.dll
2010-08-18 19:36:31 ----A---- C:\Windows\system32\PkgMgr.exe
2010-08-18 19:36:31 ----A---- C:\Windows\system32\pidgenx.dll
2010-08-18 19:36:31 ----A---- C:\Windows\system32\photowiz.dll
2010-08-18 19:36:31 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
2010-08-18 19:36:31 ----A---- C:\Windows\system32\nslookup.exe
2010-08-18 19:36:31 ----A---- C:\Windows\system32\drivers\portcls.sys
2010-08-18 19:36:31 ----A---- C:\Windows\system32\drivers\npfs.sys
2010-08-18 19:36:30 ----A---- C:\Windows\system32\ntkrnlpa.exe
2010-08-18 19:36:30 ----A---- C:\Windows\system32\ntdll.dll
2010-08-18 19:36:30 ----A---- C:\Windows\system32\NlsLexicons0009.dll
2010-08-18 19:36:30 ----A---- C:\Windows\system32\drivers\ntfs.sys
2010-08-18 19:36:29 ----A---- C:\Windows\system32\osk.exe
2010-08-18 19:36:29 ----A---- C:\Windows\system32\oobefldr.dll
2010-08-18 19:36:29 ----A---- C:\Windows\system32\onex.dll
2010-08-18 19:36:29 ----A---- C:\Windows\system32\olepro32.dll
2010-08-18 19:36:29 ----A---- C:\Windows\system32\oleprn.dll
2010-08-18 19:36:29 ----A---- C:\Windows\system32\oleaut32.dll
2010-08-18 19:36:29 ----A---- C:\Windows\system32\ole32.dll
2010-08-18 19:36:29 ----A---- C:\Windows\system32\offfilt.dll
2010-08-18 19:36:29 ----A---- C:\Windows\system32\odbccp32.dll
2010-08-18 19:36:29 ----A---- C:\Windows\system32\odbcconf.dll
2010-08-18 19:36:29 ----A---- C:\Windows\system32\odbc32.dll
2010-08-18 19:36:29 ----A---- C:\Windows\system32\ocsetup.exe
2010-08-18 19:36:29 ----A---- C:\Windows\system32\occache.dll
2010-08-18 19:36:29 ----A---- C:\Windows\system32\ntprint.dll
2010-08-18 19:36:29 ----A---- C:\Windows\system32\ntoskrnl.exe
2010-08-18 19:36:29 ----A---- C:\Windows\system32\ntmarta.dll
2010-08-18 19:36:29 ----A---- C:\Windows\system32\NlsLexicons0007.dll
2010-08-18 19:36:29 ----A---- C:\Windows\system32\nlhtml.dll
2010-08-18 19:36:29 ----A---- C:\Windows\system32\drivers\ohci1394.sys
2010-08-18 19:36:29 ----A---- C:\Windows\system32\drivers\nwifi.sys
2010-08-18 19:36:28 ----A---- C:\Windows\system32\reset.exe
2010-08-18 19:36:28 ----A---- C:\Windows\system32\RelMon.dll
2010-08-18 19:36:28 ----A---- C:\Windows\system32\rekeywiz.exe
2010-08-18 19:36:28 ----A---- C:\Windows\system32\regsvc.dll
2010-08-18 19:36:28 ----A---- C:\Windows\system32\rastls.dll
2010-08-18 19:36:28 ----A---- C:\Windows\system32\rastapi.dll
2010-08-18 19:36:28 ----A---- C:\Windows\system32\rasppp.dll
2010-08-18 19:36:28 ----A---- C:\Windows\system32\rasplap.dll
2010-08-18 19:36:28 ----A---- C:\Windows\system32\rasmontr.dll
2010-08-18 19:36:28 ----A---- C:\Windows\system32\rasmans.dll
2010-08-18 19:36:28 ----A---- C:\Windows\system32\raschap.dll
2010-08-18 19:36:28 ----A---- C:\Windows\system32\rasgcw.dll
2010-08-18 19:36:28 ----A---- C:\Windows\system32\rasdlg.dll
2010-08-18 19:36:28 ----A---- C:\Windows\system32\rasdial.exe
2010-08-18 19:36:28 ----A---- C:\Windows\system32\rasdiag.dll
2010-08-18 19:36:28 ----A---- C:\Windows\system32\rasapi32.dll
2010-08-18 19:36:28 ----A---- C:\Windows\system32\RacEngn.dll
2010-08-18 19:36:28 ----A---- C:\Windows\system32\query.exe
2010-08-18 19:36:28 ----A---- C:\Windows\system32\Query.dll
2010-08-18 19:36:28 ----A---- C:\Windows\system32\quartz.dll
2010-08-18 19:36:28 ----A---- C:\Windows\system32\qprocess.exe
2010-08-18 19:36:28 ----A---- C:\Windows\system32\qmgr.dll
2010-08-18 19:36:28 ----A---- C:\Windows\system32\qedit.dll
2010-08-18 19:36:28 ----A---- C:\Windows\system32\drivers\rassstp.sys
2010-08-18 19:36:28 ----A---- C:\Windows\system32\drivers\raspppoe.sys
2010-08-18 19:36:27 ----A---- C:\Windows\system32\regapi.dll
2010-08-18 19:36:27 ----A---- C:\Windows\system32\reg.exe
2010-08-18 19:36:27 ----A---- C:\Windows\system32\rdpwsx.dll
2010-08-18 19:36:27 ----A---- C:\Windows\system32\rdpendp.dll
2010-08-18 19:36:27 ----A---- C:\Windows\system32\rdpencom.dll
2010-08-18 19:36:27 ----A---- C:\Windows\system32\rdpclip.exe
2010-08-18 19:36:27 ----A---- C:\Windows\system32\prnntfy.dll
2010-08-18 19:36:27 ----A---- C:\Windows\system32\printui.dll
2010-08-18 19:36:27 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
2010-08-18 19:36:27 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll
2010-08-18 19:36:27 ----A---- C:\Windows\system32\PrintBrmUi.exe
2010-08-18 19:36:27 ----A---- C:\Windows\system32\PresentationSettings.exe
2010-08-18 19:36:27 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
2010-08-18 19:36:27 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2010-08-18 19:36:27 ----A---- C:\Windows\system32\PresentationHost.exe
2010-08-18 19:36:27 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2010-08-18 19:36:27 ----A---- C:\Windows\system32\powrprof.dll
2010-08-18 19:36:27 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2010-08-18 19:36:27 ----A---- C:\Windows\system32\drivers\rdpdr.sys
2010-08-18 19:36:27 ----A---- C:\Windows\system32\drivers\rdbss.sys
2010-08-18 19:36:24 ----A---- C:\Windows\system32\puiapi.dll
2010-08-18 19:36:23 ----A---- C:\Windows\system32\qdvd.dll
2010-08-18 19:36:23 ----A---- C:\Windows\system32\qappsrv.exe
2010-08-18 19:36:23 ----A---- C:\Windows\system32\QAGENTRT.DLL
2010-08-18 19:36:23 ----A---- C:\Windows\system32\propsys.dll
2010-08-18 19:36:23 ----A---- C:\Windows\system32\propdefs.dll
2010-08-18 19:36:23 ----A---- C:\Windows\system32\profsvc.dll
2010-08-18 19:36:22 ----A---- C:\Windows\system32\psisdecd.dll
2010-08-18 19:36:22 ----A---- C:\Windows\system32\PSHED.DLL
2010-08-18 19:36:15 ----A---- C:\Windows\system32\sendmail.dll
2010-08-18 19:36:13 ----A---- C:\Windows\system32\shlwapi.dll
2010-08-18 19:36:13 ----A---- C:\Windows\system32\shell32.dll
2010-08-18 19:36:13 ----A---- C:\Windows\system32\shdocvw.dll
2010-08-18 19:36:13 ----A---- C:\Windows\system32\shadow.exe
2010-08-18 19:36:13 ----A---- C:\Windows\system32\setupapi.dll
2010-08-18 19:36:13 ----A---- C:\Windows\system32\sethc.exe
2010-08-18 19:36:13 ----A---- C:\Windows\system32\services.exe
2010-08-18 19:36:01 ----A---- C:\Windows\system32\EhStorAPI.dll
2010-08-18 19:36:01 ----A---- C:\Windows\system32\eapphost.dll
2010-08-18 19:36:01 ----A---- C:\Windows\system32\eappgnui.dll
2010-08-18 19:36:01 ----A---- C:\Windows\system32\eappcfg.dll
2010-08-18 19:36:01 ----A---- C:\Windows\system32\eapp3hst.dll
2010-08-18 19:36:01 ----A---- C:\Windows\system32\drivers\ecache.sys
2010-08-18 19:36:01 ----A---- C:\Windows\system32\drivers\Dumpata.sys
2010-08-18 19:36:00 ----A---- C:\Windows\system32\f3ahvoas.dll
2010-08-18 19:36:00 ----A---- C:\Windows\system32\extmgr.dll
2010-08-18 19:36:00 ----A---- C:\Windows\system32\ExplorerFrame.dll
2010-08-18 19:36:00 ----A---- C:\Windows\system32\evr.dll
2010-08-18 19:36:00 ----A---- C:\Windows\system32\eudcedit.exe
2010-08-18 19:36:00 ----A---- C:\Windows\system32\esent.dll
2010-08-18 19:36:00 ----A---- C:\Windows\system32\es.dll
2010-08-18 19:36:00 ----A---- C:\Windows\system32\EncDec.dll
2010-08-18 19:36:00 ----A---- C:\Windows\system32\emdmgmt.dll
2010-08-18 19:36:00 ----A---- C:\Windows\system32\EhStorShell.dll
2010-08-18 19:36:00 ----A---- C:\Windows\system32\EhStorPwdMgr.dll
2010-08-18 19:36:00 ----A---- C:\Windows\system32\EhStorAuthn.dll
2010-08-18 19:36:00 ----A---- C:\Windows\system32\dxmasf.dll
2010-08-18 19:36:00 ----A---- C:\Windows\system32\dwm.exe
2010-08-18 19:36:00 ----A---- C:\Windows\system32\dsprop.dll
2010-08-18 19:36:00 ----A---- C:\Windows\system32\dsound.dll
2010-08-18 19:36:00 ----A---- C:\Windows\system32\drivers\exfat.sys
2010-08-18 19:36:00 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2010-08-18 19:36:00 ----A---- C:\Windows\system32\drivers\dxg.sys
2010-08-18 19:36:00 ----A---- C:\Windows\explorer.exe
2010-08-18 19:35:59 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2010-08-18 19:35:59 ----A---- C:\Windows\system32\drivers\disk.sys
2010-08-18 19:35:59 ----A---- C:\Windows\system32\drivers\dfsc.sys
2010-08-18 19:35:59 ----A---- C:\Windows\system32\diskraid.exe
2010-08-18 19:35:59 ----A---- C:\Windows\system32\diskpart.exe
2010-08-18 19:35:59 ----A---- C:\Windows\system32\dimsroam.dll
2010-08-18 19:35:59 ----A---- C:\Windows\system32\diagperf.dll
2010-08-18 19:35:59 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2010-08-18 19:35:59 ----A---- C:\Windows\system32\dfsr.exe
2010-08-18 19:35:59 ----A---- C:\Windows\system32\dfshim.dll
2010-08-18 19:35:59 ----A---- C:\Windows\system32\devmgr.dll
2010-08-18 19:35:58 ----A---- C:\Windows\system32\drvstore.dll
2010-08-18 19:35:58 ----A---- C:\Windows\system32\drvinst.exe
2010-08-18 19:35:58 ----A---- C:\Windows\system32\drmv2clt.dll
2010-08-18 19:35:58 ----A---- C:\Windows\system32\drmmgrtn.dll
2010-08-18 19:35:58 ----A---- C:\Windows\system32\dpapimig.exe
2010-08-18 19:35:58 ----A---- C:\Windows\system32\dot3svc.dll
2010-08-18 19:35:58 ----A---- C:\Windows\system32\dot3msm.dll
2010-08-18 19:35:58 ----A---- C:\Windows\system32\dot3cfg.dll
2010-08-18 19:35:58 ----A---- C:\Windows\system32\dnsapi.dll
2010-08-18 19:35:58 ----A---- C:\Windows\system32\dmusic.dll
2010-08-18 19:35:58 ----A---- C:\Windows\system32\dmsynth.dll
2010-08-18 19:35:58 ----A---- C:\Windows\system32\dhcpcsvc.dll
2010-08-18 19:35:57 ----A---- C:\Windows\system32\iasdatastore.dll
2010-08-18 19:35:57 ----A---- C:\Windows\system32\iasads.dll
2010-08-18 19:35:57 ----A---- C:\Windows\system32\iasacct.dll
2010-08-18 19:35:57 ----A---- C:\Windows\system32\hbaapi.dll
2010-08-18 19:35:57 ----A---- C:\Windows\system32\gpupdate.exe
2010-08-18 19:35:57 ----A---- C:\Windows\system32\gpsvc.dll
2010-08-18 19:35:57 ----A---- C:\Windows\system32\gpscript.exe
2010-08-18 19:35:57 ----A---- C:\Windows\system32\gpscript.dll
2010-08-18 19:35:57 ----A---- C:\Windows\system32\gpresult.exe
2010-08-18 19:35:57 ----A---- C:\Windows\system32\gpprnext.dll
2010-08-18 19:35:57 ----A---- C:\Windows\system32\drivers\hdaudbus.sys
2010-08-18 19:35:57 ----A---- C:\Windows\system32\dnsrslvr.dll
2010-08-18 19:35:56 ----A---- C:\Windows\system32\iasnap.dll
2010-08-18 19:35:56 ----A---- C:\Windows\system32\IasMigReader.exe
2010-08-18 19:35:56 ----A---- C:\Windows\system32\IasMigPlugin.dll
2010-08-18 19:35:56 ----A---- C:\Windows\system32\iashlpr.dll
2010-08-18 19:35:56 ----A---- C:\Windows\system32\hidserv.dll
2010-08-18 19:35:56 ----A---- C:\Windows\system32\hdwwiz.exe
2010-08-18 19:35:56 ----A---- C:\Windows\system32\drivers\http.sys
2010-08-18 19:35:56 ----A---- C:\Windows\system32\drivers\hidusb.sys
2010-08-18 19:35:56 ----A---- C:\Windows\system32\drivers\hidclass.sys
2010-08-18 19:35:55 ----A---- C:\Windows\system32\gpedit.dll
2010-08-18 19:35:55 ----A---- C:\Windows\system32\gpapi.dll
2010-08-18 19:35:55 ----A---- C:\Windows\system32\gdi32.dll
2010-08-18 19:35:55 ----A---- C:\Windows\system32\fundisc.dll
2010-08-18 19:35:55 ----A---- C:\Windows\system32\fontext.dll
2010-08-18 19:35:55 ----A---- C:\Windows\system32\findstr.exe
2010-08-18 19:35:55 ----A---- C:\Windows\system32\feclient.dll
2010-08-18 19:35:55 ----A---- C:\Windows\system32\fdWSD.dll
2010-08-18 19:35:55 ----A---- C:\Windows\system32\fdWCN.dll
2010-08-18 19:35:55 ----A---- C:\Windows\system32\fdSSDP.dll
2010-08-18 19:35:55 ----A---- C:\Windows\system32\fdProxy.dll
2010-08-18 19:35:55 ----A---- C:\Windows\system32\fdeploy.dll
2010-08-18 19:35:55 ----A---- C:\Windows\system32\fdBthProxy.dll
2010-08-18 19:35:55 ----A---- C:\Windows\system32\fdBth.dll
2010-08-18 19:35:55 ----A---- C:\Windows\system32\fc.exe
2010-08-18 19:35:55 ----A---- C:\Windows\system32\Faultrep.dll
2010-08-18 19:35:55 ----A---- C:\Windows\system32\drivers\fltMgr.sys
2010-08-18 19:35:55 ----A---- C:\Windows\system32\drivers\fastfat.sys
2010-08-18 19:35:54 ----A---- C:\Windows\system32\gameux.dll
2010-08-18 19:35:54 ----A---- C:\Windows\system32\FwRemoteSvr.dll
2010-08-18 19:35:54 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2010-08-18 19:35:54 ----A---- C:\Windows\system32\fveui.dll
2010-08-18 19:35:54 ----A---- C:\Windows\system32\fvecpl.dll
2010-08-18 19:35:54 ----A---- C:\Windows\system32\fveapi.dll
2010-08-18 19:35:54 ----A---- C:\Windows\system32\FunctionDiscoveryFolder.dll
2010-08-18 19:35:54 ----A---- C:\Windows\system32\ftp.exe
2010-08-18 19:35:54 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2010-08-18 19:35:54 ----A---- C:\Windows\system32\drivers\fvevol.sys
2010-08-18 19:35:54 ----A---- C:\Windows\system32\drivers\ataport.sys
2010-08-18 19:35:54 ----A---- C:\Windows\system32\AuxiliaryDisplayServices.dll
2010-08-18 19:35:54 ----A---- C:\Windows\system32\AuxiliaryDisplayDriverLib.dll
2010-08-18 19:35:54 ----A---- C:\Windows\system32\AuxiliaryDisplayCpl.dll
2010-08-18 19:35:54 ----A---- C:\Windows\system32\autoplay.dll
2010-08-18 19:35:54 ----A---- C:\Windows\system32\autochk.exe
2010-08-18 19:35:54 ----A---- C:\Windows\system32\autofmt.exe
2010-08-18 19:35:54 ----A---- C:\Windows\system32\autoconv.exe
2010-08-18 19:35:54 ----A---- C:\Windows\system32\authz.dll
2010-08-18 19:35:54 ----A---- C:\Windows\system32\authui.dll
2010-08-18 19:35:54 ----A---- C:\Windows\system32\audiosrv.dll
2010-08-18 19:35:54 ----A---- C:\Windows\system32\AudioSes.dll
2010-08-18 19:35:54 ----A---- C:\Windows\system32\audiodg.exe
2010-08-18 19:35:54 ----A---- C:\Windows\system32\atmlib.dll
2010-08-18 19:35:54 ----A---- C:\Windows\system32\atmfd.dll
2010-08-18 19:35:53 ----A---- C:\Windows\system32\drivers\bridge.sys
2010-08-18 19:35:53 ----A---- C:\Windows\system32\drivers\atapi.sys
2010-08-18 19:35:53 ----A---- C:\Windows\system32\drivers\acpi.sys
2010-08-18 19:35:53 ----A---- C:\Windows\system32\bthci.dll
2010-08-18 19:35:53 ----A---- C:\Windows\system32\browseui.dll
2010-08-18 19:35:53 ----A---- C:\Windows\system32\brcplsiw.dll
2010-08-18 19:35:53 ----A---- C:\Windows\system32\brcpl.dll
2010-08-18 19:35:53 ----A---- C:\Windows\system32\blackbox.dll
2010-08-18 19:35:53 ----A---- C:\Windows\system32\bitsigd.dll
2010-08-18 19:35:53 ----A---- C:\Windows\system32\BFE.DLL
2010-08-18 19:35:53 ----A---- C:\Windows\system32\bcrypt.dll
2010-08-18 19:35:53 ----A---- C:\Windows\system32\basecsp.dll
2010-08-18 19:35:53 ----A---- C:\Windows\system32\azroles.dll
2010-08-18 19:35:52 ----A---- C:\Windows\system32\Apphlpdm.dll
2010-08-18 19:35:52 ----A---- C:\Windows\system32\apphelp.dll
2010-08-18 19:35:52 ----A---- C:\Windows\system32\accessibilitycpl.dll
2010-08-18 19:35:52 ----A---- C:\Windows\system32\aaclient.dll
2010-08-18 19:35:51 ----A---- C:\Windows\system32\drivers\crashdmp.sys
2010-08-18 19:35:51 ----A---- C:\Windows\system32\drivers\afd.sys
2010-08-18 19:35:51 ----A---- C:\Windows\system32\crypt32.dll
2010-08-18 19:35:51 ----A---- C:\Windows\system32\credui.dll
2010-08-18 19:35:51 ----A---- C:\Windows\system32\connect.dll
2010-08-18 19:35:51 ----A---- C:\Windows\system32\conime.exe
2010-08-18 19:35:51 ----A---- C:\Windows\system32\comuid.dll
2010-08-18 19:35:51 ----A---- C:\Windows\system32\comsvcs.dll
2010-08-18 19:35:51 ----A---- C:\Windows\system32\appmgmts.dll
2010-08-18 19:35:51 ----A---- C:\Windows\system32\apds.dll
2010-08-18 19:35:51 ----A---- C:\Windows\system32\advapi32.dll
2010-08-18 19:35:51 ----A---- C:\Windows\system32\adtschema.dll
2010-08-18 19:35:51 ----A---- C:\Windows\system32\adsmsext.dll
2010-08-18 19:35:51 ----A---- C:\Windows\system32\adsldpc.dll
2010-08-18 19:35:50 ----A---- C:\Windows\system32\dbgeng.dll
2010-08-18 19:35:50 ----A---- C:\Windows\system32\davclnt.dll
2010-08-18 19:35:50 ----A---- C:\Windows\system32\d3d9.dll
2010-08-18 19:35:50 ----A---- C:\Windows\system32\comdlg32.dll
2010-08-18 19:35:50 ----A---- C:\Windows\system32\cmmon32.exe
2010-08-18 19:35:50 ----A---- C:\Windows\system32\cmdial32.dll
2010-08-18 19:35:49 ----A---- C:\Windows\system32\drivers\csc.sys
2010-08-18 19:35:49 ----A---- C:\Windows\system32\drivers\cdrom.sys
2010-08-18 19:35:49 ----A---- C:\Windows\system32\DevicePairingWizard.exe
2010-08-18 19:35:49 ----A---- C:\Windows\system32\DevicePairingProxy.dll
2010-08-18 19:35:49 ----A---- C:\Windows\system32\DevicePairing.dll
2010-08-18 19:35:49 ----A---- C:\Windows\system32\DeviceEject.exe
2010-08-18 19:35:49 ----A---- C:\Windows\system32\dataclen.dll
2010-08-18 19:35:49 ----A---- C:\Windows\system32\csrstub.exe
2010-08-18 19:35:49 ----A---- C:\Windows\system32\cscui.dll
2010-08-18 19:35:49 ----A---- C:\Windows\system32\cscsvc.dll
2010-08-18 19:35:49 ----A---- C:\Windows\system32\cscript.exe
2010-08-18 19:35:49 ----A---- C:\Windows\system32\cscobj.dll
2010-08-18 19:35:49 ----A---- C:\Windows\system32\CscMig.dll
2010-08-18 19:35:49 ----A---- C:\Windows\system32\cscdll.dll
2010-08-18 19:35:49 ----A---- C:\Windows\system32\cscapi.dll
2010-08-18 19:35:49 ----A---- C:\Windows\system32\cryptui.dll
2010-08-18 19:35:49 ----A---- C:\Windows\system32\cryptsvc.dll
2010-08-18 19:35:49 ----A---- C:\Windows\system32\certmgr.dll
2010-08-18 19:35:49 ----A---- C:\Windows\system32\CertEnrollUI.dll
2010-08-18 19:35:49 ----A---- C:\Windows\system32\CertEnroll.dll
2010-08-18 19:35:49 ----A---- C:\Windows\system32\certcli.dll
2010-08-18 19:35:49 ----A---- C:\Windows\system32\cdd.dll
2010-08-18 19:35:48 ----A---- C:\Windows\system32\CHxReadingStringIME.dll
2010-08-18 19:35:48 ----A---- C:\Windows\system32\chtbrkr.dll
2010-08-18 19:35:48 ----A---- C:\Windows\system32\chsbrkr.dll
2010-08-18 19:35:48 ----A---- C:\Windows\system32\chglogon.exe
2010-08-18 19:35:48 ----A---- C:\Windows\system32\drivers\Classpnp.sys
2010-08-18 19:35:48 ----A---- C:\Windows\system32\clfs.sys
2010-08-18 19:35:48 ----A---- C:\Windows\system32\cipher.exe
2010-08-18 19:35:48 ----A---- C:\Windows\system32\ci.dll
2010-08-18 19:35:48 ----A---- C:\Windows\system32\certreq.exe
2010-08-18 19:35:48 ----A---- C:\Windows\system32\certprop.dll
2010-08-18 19:35:48 ----A---- C:\Windows\system32\cbsra.exe
2010-08-18 19:35:48 ----A---- C:\Windows\system32\bthudtask.exe
2010-08-18 19:35:48 ----A---- C:\Windows\system32\bthserv.dll
2010-08-18 19:35:47 ----A---- C:\Windows\system32\msihnd.dll
2010-08-18 19:35:47 ----A---- C:\Windows\system32\msiexec.exe
2010-08-18 19:35:47 ----A---- C:\Windows\system32\msi.dll
2010-08-18 19:35:47 ----A---- C:\Windows\system32\mshtmled.dll
2010-08-18 19:35:47 ----A---- C:\Windows\system32\mshtml.dll
2010-08-18 19:35:47 ----A---- C:\Windows\system32\msftedit.dll
2010-08-18 19:35:47 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-08-18 19:35:47 ----A---- C:\Windows\system32\msfeeds.dll
2010-08-18 19:35:47 ----A---- C:\Windows\system32\msexch40.dll
2010-08-18 19:35:47 ----A---- C:\Windows\system32\msexcl40.dll
2010-08-18 19:35:47 ----A---- C:\Windows\system32\msdtctm.dll
2010-08-18 19:35:47 ----A---- C:\Windows\system32\msdtcprx.dll
2010-08-18 19:35:47 ----A---- C:\Windows\system32\msdrm.dll
2010-08-18 19:35:47 ----A---- C:\Windows\system32\msctfui.dll
2010-08-18 19:35:47 ----A---- C:\Windows\system32\msctfp.dll
2010-08-18 19:35:47 ----A---- C:\Windows\system32\MsCtfMonitor.dll
2010-08-18 19:35:47 ----A---- C:\Windows\system32\msctf.dll
2010-08-18 19:35:47 ----A---- C:\Windows\system32\chgusr.exe
2010-08-18 19:35:47 ----A---- C:\Windows\system32\chgport.exe
2010-08-18 19:35:47 ----A---- C:\Windows\system32\change.exe
2010-08-18 19:35:47 ----A---- C:\Windows\system32\certutil.exe
2010-08-18 19:35:46 ----A---- C:\Windows\system32\msimsg.dll
2010-08-18 19:35:46 ----A---- C:\Windows\system32\MPSSVC.dll
2010-08-18 19:35:46 ----A---- C:\Windows\system32\mprapi.dll
2010-08-18 19:35:46 ----A---- C:\Windows\system32\mpr.dll
2010-08-18 19:35:45 ----A---- C:\Windows\system32\mscories.dll
2010-08-18 19:35:45 ----A---- C:\Windows\system32\mscorier.dll
2010-08-18 19:35:45 ----A---- C:\Windows\system32\mscoree.dll
2010-08-18 19:35:45 ----A---- C:\Windows\system32\mscms.dll
2010-08-18 19:35:45 ----A---- C:\Windows\system32\mscandui.dll
2010-08-18 19:35:45 ----A---- C:\Windows\system32\modemui.dll
2010-08-18 19:35:45 ----A---- C:\Windows\system32\MMDevAPI.dll
2010-08-18 19:35:45 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2010-08-18 19:35:45 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2010-08-18 19:35:45 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2010-08-18 19:35:44 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2010-08-18 19:35:41 ----A---- C:\Windows\system32\NetProjW.dll
2010-08-18 19:35:41 ----A---- C:\Windows\system32\netplwiz.dll
2010-08-18 19:35:41 ----A---- C:\Windows\system32\netlogon.dll
2010-08-18 19:35:41 ----A---- C:\Windows\system32\netiohlp.dll
2010-08-18 19:35:41 ----A---- C:\Windows\system32\netcenter.dll
2010-08-18 19:35:41 ----A---- C:\Windows\system32\netapi32.dll
2010-08-18 19:35:41 ----A---- C:\Windows\system32\ncryptui.dll
2010-08-18 19:35:41 ----A---- C:\Windows\system32\ncrypt.dll
2010-08-18 19:35:41 ----A---- C:\Windows\system32\mtxclu.dll
2010-08-18 19:35:41 ----A---- C:\Windows\system32\drivers\netbt.sys
2010-08-18 19:35:41 ----A---- C:\Windows\system32\drivers\ndiswan.sys
2010-08-18 19:35:41 ----A---- C:\Windows\system32\drivers\ndis.sys
2010-08-18 19:35:41 ----A---- C:\Windows\system32\drivers\mup.sys
2010-08-18 19:35:40 ----A---- C:\Windows\system32\NcdProp.dll
2010-08-18 19:35:40 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2010-08-18 19:35:40 ----A---- C:\Windows\system32\msxml6.dll
2010-08-18 19:35:40 ----A---- C:\Windows\system32\msxml3.dll
2010-08-18 19:35:39 ----A---- C:\Windows\system32\newdev.exe
2010-08-18 19:35:39 ----A---- C:\Windows\system32\newdev.dll
2010-08-18 19:35:39 ----A---- C:\Windows\system32\networkmap.dll
2010-08-18 19:35:39 ----A---- C:\Windows\system32\networkexplorer.dll
2010-08-18 19:35:39 ----A---- C:\Windows\system32\netshell.dll
2010-08-18 19:35:38 ----A---- C:\Windows\system32\networkitemfactory.dll
2010-08-18 19:35:38 ----A---- C:\Windows\system32\msscntrs.dll
2010-08-18 19:35:38 ----A---- C:\Windows\system32\msscb.dll
2010-08-18 19:35:38 ----A---- C:\Windows\system32\msrepl40.dll
2010-08-18 19:35:38 ----A---- C:\Windows\system32\msrd3x40.dll
2010-08-18 19:35:38 ----A---- C:\Windows\system32\msrd2x40.dll
2010-08-18 19:35:38 ----A---- C:\Windows\system32\msrating.dll
2010-08-18 19:35:38 ----A---- C:\Windows\system32\mspbde40.dll
2010-08-18 19:35:38 ----A---- C:\Windows\system32\msnetobj.dll
2010-08-18 19:35:38 ----A---- C:\Windows\system32\MSMPEG2VDEC.DLL
2010-08-18 19:35:38 ----A---- C:\Windows\system32\msltus40.dll
2010-08-18 19:35:38 ----A---- C:\Windows\system32\msjtes40.dll
2010-08-18 19:35:38 ----A---- C:\Windows\system32\msjter40.dll
2010-08-18 19:35:38 ----A---- C:\Windows\system32\msjint40.dll
2010-08-18 19:35:38 ----A---- C:\Windows\system32\msjetoledb40.dll
2010-08-18 19:35:38 ----A---- C:\Windows\system32\msinfo32.exe
2010-08-18 19:35:38 ----A---- C:\Windows\system32\msimtf.dll
2010-08-18 19:35:38 ----A---- C:\Windows\system32\drivers\msrpc.sys
2010-08-18 19:35:38 ----A---- C:\Windows\system32\drivers\msiscsi.sys
2010-08-18 19:35:37 ----A---- C:\Windows\system32\msxbde40.dll
2010-08-18 19:35:37 ----A---- C:\Windows\system32\mswstr10.dll
2010-08-18 19:35:37 ----A---- C:\Windows\system32\mswsock.dll
2010-08-18 19:35:37 ----A---- C:\Windows\system32\mswdat10.dll
2010-08-18 19:35:37 ----A---- C:\Windows\system32\MSVidCtl.dll
2010-08-18 19:35:37 ----A---- C:\Windows\system32\msvcrt.dll
2010-08-18 19:35:37 ----A---- C:\Windows\system32\msvcp60.dll
2010-08-18 19:35:37 ----A---- C:\Windows\system32\msv1_0.dll
2010-08-18 19:35:37 ----A---- C:\Windows\system32\msutb.dll
2010-08-18 19:35:37 ----A---- C:\Windows\system32\mstscax.dll
2010-08-18 19:35:37 ----A---- C:\Windows\system32\mstsc.exe
2010-08-18 19:35:37 ----A---- C:\Windows\system32\mstlsapi.dll
2010-08-18 19:35:37 ----A---- C:\Windows\system32\mstime.dll
2010-08-18 19:35:37 ----A---- C:\Windows\system32\mstext40.dll
2010-08-18 19:35:37 ----A---- C:\Windows\system32\mssvp.dll
2010-08-18 19:35:37 ----A---- C:\Windows\system32\msstrc.dll
2010-08-18 19:35:37 ----A---- C:\Windows\system32\mssrch.dll
2010-08-18 19:35:37 ----A---- C:\Windows\system32\mssprxy.dll
2010-08-18 19:35:37 ----A---- C:\Windows\system32\mssphtb.dll
2010-08-18 19:35:37 ----A---- C:\Windows\system32\mssph.dll
2010-08-18 19:35:37 ----A---- C:\Windows\system32\mssitlb.dll
2010-08-18 19:35:37 ----A---- C:\Windows\system32\msshsq.dll
2010-08-18 19:35:37 ----A---- C:\Windows\system32\msshooks.dll
2010-08-18 19:35:37 ----A---- C:\Windows\system32\msscp.dll
2010-08-18 19:35:37 ----A---- C:\Windows\system32\msjet40.dll
2010-08-18 19:35:37 ----A---- C:\Windows\system32\msisip.dll
2010-08-18 19:35:37 ----A---- C:\Windows\system32\InkEd.dll
2010-08-18 19:35:37 ----A---- C:\Windows\system32\inetcomm.dll
2010-08-18 19:35:36 ----A---- C:\Windows\system32\infocardapi.dll
2010-08-18 19:35:36 ----A---- C:\Windows\system32\inetppui.dll
2010-08-18 19:35:36 ----A---- C:\Windows\system32\inetpp.dll
2010-08-18 19:35:36 ----A---- C:\Windows\system32\imm32.dll
2010-08-18 19:35:35 ----A---- C:\Windows\system32\jsproxy.dll
2010-08-18 19:35:35 ----A---- C:\Windows\system32\jscript.dll
2010-08-18 19:35:35 ----A---- C:\Windows\system32\iscsilog.dll
2010-08-18 19:35:35 ----A---- C:\Windows\system32\ipsmsnap.dll
2010-08-18 19:35:35 ----A---- C:\Windows\system32\IPSECSVC.DLL
2010-08-18 19:35:35 ----A---- C:\Windows\system32\ipsecsnp.dll
2010-08-18 19:35:35 ----A---- C:\Windows\system32\iphlpsvc.dll
2010-08-18 19:35:35 ----A---- C:\Windows\system32\IPHLPAPI.DLL
2010-08-18 19:35:35 ----A---- C:\Windows\system32\ipconfig.exe
2010-08-18 19:35:35 ----A---- C:\Windows\system32\input.dll
2010-08-18 19:35:34 ----A---- C:\Windows\system32\IMJP10K.DLL
2010-08-18 19:35:34 ----A---- C:\Windows\system32\imapi2fs.dll
2010-08-18 19:35:34 ----A---- C:\Windows\system32\imapi2.dll
2010-08-18 19:35:34 ----A---- C:\Windows\system32\imapi.dll
2010-08-18 19:35:34 ----A---- C:\Windows\system32\IKEEXT.DLL
2010-08-18 19:35:34 ----A---- C:\Windows\system32\ifmon.dll
2010-08-18 19:35:34 ----A---- C:\Windows\system32\iertutil.dll
2010-08-18 19:35:34 ----A---- C:\Windows\system32\iepeers.dll
2010-08-18 19:35:34 ----A---- C:\Windows\system32\ieframe.dll
2010-08-18 19:35:34 ----A---- C:\Windows\system32\iedkcs32.dll
2010-08-18 19:35:34 ----A---- C:\Windows\system32\ieapfltr.dll
2010-08-18 19:35:34 ----A---- C:\Windows\system32\ieaksie.dll
2010-08-18 19:35:34 ----A---- C:\Windows\system32\icardres.dll
2010-08-18 19:35:34 ----A---- C:\Windows\system32\icardagt.exe
2010-08-18 19:35:34 ----A---- C:\Windows\system32\iassvcs.dll
2010-08-18 19:35:34 ----A---- C:\Windows\system32\iassdo.dll
2010-08-18 19:35:34 ----A---- C:\Windows\system32\iassam.dll
2010-08-18 19:35:34 ----A---- C:\Windows\system32\iasrecst.dll
2010-08-18 19:35:34 ----A---- C:\Windows\system32\iasrad.dll
2010-08-18 19:35:34 ----A---- C:\Windows\system32\iaspolcy.dll
2010-08-18 19:35:33 ----A---- C:\Windows\system32\mfps.dll
2010-08-18 19:35:33 ----A---- C:\Windows\system32\mfpmp.exe
2010-08-18 19:35:33 ----A---- C:\Windows\system32\mfplat.dll
2010-08-18 19:35:33 ----A---- C:\Windows\system32\mferror.dll
2010-08-18 19:35:33 ----A---- C:\Windows\system32\mfc42u.dll
2010-08-18 19:35:33 ----A---- C:\Windows\system32\mfc42.dll
2010-08-18 19:35:33 ----A---- C:\Windows\system32\mf.dll
2010-08-18 19:35:32 ----A---- C:\Windows\system32\mimefilt.dll
2010-08-18 19:35:32 ----A---- C:\Windows\system32\milcore.dll
2010-08-18 19:35:31 ----A---- C:\Windows\system32\mmcndmgr.dll
2010-08-18 19:35:31 ----A---- C:\Windows\system32\mmcico.dll
2010-08-18 19:35:31 ----A---- C:\Windows\system32\mmci.dll
2010-08-18 19:35:31 ----A---- C:\Windows\system32\mmc.exe
2010-08-18 19:35:31 ----A---- C:\Windows\system32\midimap.dll
2010-08-18 19:35:31 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2010-08-18 19:35:31 ----A---- C:\Windows\system32\drivers\ks.sys
2010-08-18 19:35:30 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2010-08-18 19:35:30 ----A---- C:\Windows\system32\mblctr.exe
2010-08-18 19:35:30 ----A---- C:\Windows\system32\l2nacp.dll
2010-08-18 19:35:30 ----A---- C:\Windows\system32\korwbrkr.dll
2010-08-18 19:35:30 ----A---- C:\Windows\system32\kernel32.dll
2010-08-18 19:35:30 ----A---- C:\Windows\system32\kerberos.dll
2010-08-18 19:35:30 ----A---- C:\Windows\system32\kdusb.dll
2010-08-18 19:35:30 ----A---- C:\Windows\system32\kdcom.dll
2010-08-18 19:35:30 ----A---- C:\Windows\system32\kd1394.dll
2010-08-18 19:35:30 ----A---- C:\Windows\system32\drivers\kbdhid.sys
2010-08-18 19:35:29 ----A---- C:\Windows\system32\shsetup.dll
2010-08-18 19:35:29 ----A---- C:\Windows\system32\MediaMetadataHandler.dll
2010-08-18 19:35:29 ----A---- C:\Windows\system32\mcmde.dll
2010-08-18 19:35:29 ----A---- C:\Windows\system32\Magnify.exe
2010-08-18 19:35:29 ----A---- C:\Windows\system32\lsasrv.dll
2010-08-18 19:35:29 ----A---- C:\Windows\system32\logoff.exe
2010-08-18 19:35:29 ----A---- C:\Windows\system32\logman.exe
2010-08-18 19:35:29 ----A---- C:\Windows\system32\logagent.exe
2010-08-18 19:35:29 ----A---- C:\Windows\system32\localspl.dll
2010-08-18 19:35:28 ----A---- C:\Windows\system32\WindowsCodecs.dll
2010-08-18 19:35:28 ----A---- C:\Windows\system32\wercon.exe
2010-08-18 19:35:28 ----A---- C:\Windows\system32\wer.dll
2010-08-18 19:35:28 ----A---- C:\Windows\system32\webcheck.dll
2010-08-18 19:35:28 ----A---- C:\Windows\system32\WebClnt.dll
2010-08-18 19:35:28 ----A---- C:\Windows\system32\wdscore.dll
2010-08-18 19:35:28 ----A---- C:\Windows\system32\wdc.dll
2010-08-18 19:35:27 ----A---- C:\Windows\system32\wininet.dll
2010-08-18 19:35:27 ----A---- C:\Windows\system32\winhttp.dll
2010-08-18 19:35:27 ----A---- C:\Windows\system32\WindowsUltimateExtrasCPL.dll
2010-08-18 19:35:27 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2010-08-18 19:35:27 ----A---- C:\Windows\system32\win32spl.dll
2010-08-18 19:35:27 ----A---- C:\Windows\system32\win32k.sys
2010-08-18 19:35:27 ----A---- C:\Windows\system32\wiaservc.dll
2010-08-18 19:35:27 ----A---- C:\Windows\system32\wiaaut.dll
2010-08-18 19:35:27 ----A---- C:\Windows\system32\whealogr.dll
2010-08-18 19:35:27 ----A---- C:\Windows\system32\WFS.exe
2010-08-18 19:35:27 ----A---- C:\Windows\system32\wevtutil.exe
2010-08-18 19:35:27 ----A---- C:\Windows\system32\wevtsvc.dll
2010-08-18 19:35:27 ----A---- C:\Windows\system32\wevtapi.dll
2010-08-18 19:35:27 ----A---- C:\Windows\system32\wersvc.dll
2010-08-18 19:35:27 ----A---- C:\Windows\system32\WerFaultSecure.exe
2010-08-18 19:35:27 ----A---- C:\Windows\system32\WerFault.exe
2010-08-18 19:35:27 ----A---- C:\Windows\system32\version.dll
2010-08-18 19:35:27 ----A---- C:\Windows\system32\vdsutil.dll
2010-08-18 19:35:27 ----A---- C:\Windows\system32\vdsdyn.dll
2010-08-18 19:35:27 ----A---- C:\Windows\system32\vds.exe
2010-08-18 19:35:27 ----A---- C:\Windows\system32\vdmdbg.dll
2010-08-18 19:35:27 ----A---- C:\Windows\system32\vbscript.dll
2010-08-18 19:35:27 ----A---- C:\Windows\system32\user32.dll
2010-08-18 19:35:27 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
2010-08-18 19:35:26 ----A---- C:\Windows\system32\wcnwiz2.dll
2010-08-18 19:35:26 ----A---- C:\Windows\system32\wcnwiz.dll
2010-08-18 19:35:26 ----A---- C:\Windows\system32\WcnNetsh.dll
2010-08-18 19:35:26 ----A---- C:\Windows\system32\wcncsvc.dll
2010-08-18 19:35:26 ----A---- C:\Windows\system32\wbengine.exe
2010-08-18 19:35:26 ----A---- C:\Windows\system32\uxsms.dll
2010-08-18 19:35:26 ----A---- C:\Windows\system32\Utilman.exe
2010-08-18 19:35:26 ----A---- C:\Windows\system32\usp10.dll
2010-08-18 19:35:26 ----A---- C:\Windows\system32\userenv.dll
2010-08-18 19:35:26 ----A---- C:\Windows\system32\usercpl.dll
2010-08-18 19:35:26 ----A---- C:\Windows\system32\drivers\watchdog.sys
2010-08-18 19:35:26 ----A---- C:\Windows\system32\drivers\usbport.sys
2010-08-18 19:35:25 ----A---- C:\Windows\system32\w32time.dll
2010-08-18 19:35:25 ----A---- C:\Windows\system32\VSSVC.exe
2010-08-18 19:35:25 ----A---- C:\Windows\system32\drivers\volsnap.sys
2010-08-18 19:35:25 ----A---- C:\Windows\system32\drivers\volmgrx.sys
2010-08-18 19:35:24 ----A---- C:\Windows\system32\wscisvif.dll
2010-08-18 19:35:24 ----A---- C:\Windows\system32\WscEapPr.dll
2010-08-18 19:35:24 ----A---- C:\Windows\system32\wscapi.dll
2010-08-18 19:35:24 ----A---- C:\Windows\system32\vssapi.dll
2010-08-18 19:35:23 ----A---- C:\Windows\system32\wsdchngr.dll
2010-08-18 19:35:22 ----A---- C:\Windows\system32\WSDMon.dll
2010-08-18 19:35:22 ----A---- C:\Windows\system32\WSDApi.dll
2010-08-18 19:35:22 ----A---- C:\Windows\system32\wscript.exe
2010-08-18 19:35:22 ----A---- C:\Windows\system32\wscntfy.dll
2010-08-18 19:35:20 ----A---- C:\Windows\system32\wscsvc.dll
2010-08-18 19:35:20 ----A---- C:\Windows\system32\WMVXENCD.DLL
2010-08-18 19:35:20 ----A---- C:\Windows\system32\WMVSDECD.DLL
2010-08-18 19:35:19 ----A---- C:\Windows\system32\wow32.dll
2010-08-18 19:35:19 ----A---- C:\Windows\system32\WMVENCOD.DLL
2010-08-18 19:35:18 ----A---- C:\Windows\system32\WMVCORE.DLL
2010-08-18 19:35:17 ----A---- C:\Windows\system32\wpccpl.dll
2010-08-18 19:35:16 ----A---- C:\Windows\system32\wusa.exe
2010-08-18 19:35:16 ----A---- C:\Windows\system32\wpcsvc.dll
2010-08-18 19:35:16 ----A---- C:\Windows\system32\wpcao.dll
2010-08-18 19:35:14 ----A---- C:\Windows\system32\xmlfilter.dll
2010-08-18 19:35:13 ----A---- C:\Windows\system32\wshext.dll
2010-08-18 19:35:13 ----A---- C:\Windows\system32\wshbth.dll
2010-08-18 19:35:13 ----A---- C:\Windows\system32\wsepno.dll
2010-08-18 19:35:09 ----A---- C:\Windows\system32\wsnmp32.dll
2010-08-18 19:35:09 ----A---- C:\Windows\system32\WsmSvc.dll
2010-08-18 19:35:09 ----A---- C:\Windows\system32\wlanpref.dll
2010-08-18 19:35:09 ----A---- C:\Windows\system32\wlanmsm.dll
2010-08-18 19:35:08 ----A---- C:\Windows\system32\wlanui.dll
2010-08-18 19:35:08 ----A---- C:\Windows\system32\wlansvc.dll
2010-08-18 19:35:08 ----A---- C:\Windows\system32\wlanhlp.dll
2010-08-18 19:35:08 ----A---- C:\Windows\system32\wlangpui.dll
2010-08-18 19:35:08 ----A---- C:\Windows\system32\wisptis.exe
2010-08-18 19:35:07 ----A---- C:\Windows\system32\wlgpclnt.dll
2010-08-18 19:35:07 ----A---- C:\Windows\system32\Wldap32.dll
2010-08-18 19:35:05 ----A---- C:\Windows\system32\winrnr.dll
2010-08-18 19:35:05 ----A---- C:\Windows\system32\winresume.exe
2010-08-18 19:35:04 ----A---- C:\Windows\system32\WinSCard.dll
2010-08-18 19:35:00 ----A---- C:\Windows\system32\WinSAT.exe
2010-08-18 19:34:57 ----A---- C:\Windows\system32\wmpmde.dll
2010-08-18 19:34:57 ----A---- C:\Windows\system32\WMPhoto.dll
2010-08-18 19:34:57 ----A---- C:\Windows\system32\wmpeffects.dll
2010-08-18 19:34:57 ----A---- C:\Windows\system32\WMNetMgr.dll
2010-08-18 19:34:57 ----A---- C:\Windows\system32\winsrv.dll
2010-08-18 19:34:57 ----A---- C:\Windows\system32\winmm.dll
2010-08-18 19:34:57 ----A---- C:\Windows\system32\winlogon.exe
2010-08-18 19:34:57 ----A---- C:\Windows\system32\winload.exe
2010-08-18 19:34:56 ----A---- C:\Windows\system32\wmploc.DLL
2010-08-18 19:34:56 ----A---- C:\Windows\system32\wmp.dll
2010-08-18 19:34:55 ----A---- C:\Windows\system32\wmicmiplugin.dll
2010-08-18 19:34:55 ----A---- C:\Windows\system32\wmdrmsdk.dll
2010-08-18 19:34:55 ----A---- C:\Windows\system32\sud.dll
2010-08-18 19:34:55 ----A---- C:\Windows\system32\Storprop.dll
2010-08-18 19:34:55 ----A---- C:\Windows\system32\stobject.dll
2010-08-18 19:34:55 ----A---- C:\Windows\system32\drivers\stream.sys
2010-08-18 19:34:55 ----A---- C:\Windows\system32\drivers\Storport.sys
2010-08-18 19:34:53 ----A---- C:\Windows\system32\srvsvc.dll
2010-08-18 19:34:53 ----A---- C:\Windows\system32\srchadmin.dll
2010-08-18 19:34:53 ----A---- C:\Windows\system32\srcore.dll
2010-08-18 19:34:53 ----A---- C:\Windows\system32\drivers\srvnet.sys
2010-08-18 19:34:53 ----A---- C:\Windows\system32\drivers\srv2.sys
2010-08-18 19:34:53 ----A---- C:\Windows\system32\drivers\srv.sys
2010-08-18 19:34:52 ----A---- C:\Windows\system32\sysmain.dll
2010-08-18 19:34:52 ----A---- C:\Windows\system32\sysclass.dll
2010-08-18 19:34:52 ----A---- C:\Windows\system32\SyncCenter.dll
2010-08-18 19:34:52 ----A---- C:\Windows\system32\swprv.dll
2010-08-18 19:34:52 ----A---- C:\Windows\system32\smss.exe
2010-08-18 19:34:52 ----A---- C:\Windows\system32\SmiEngine.dll
2010-08-18 19:34:52 ----A---- C:\Windows\system32\SMBHelperClass.dll
2010-08-18 19:34:52 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2010-08-18 19:34:52 ----A---- C:\Windows\system32\slwmi.dll
2010-08-18 19:34:52 ----A---- C:\Windows\system32\slcc.dll
2010-08-18 19:34:52 ----A---- C:\Windows\system32\SLC.dll
2010-08-18 19:34:52 ----A---- C:\Windows\system32\shwebsvc.dll
2010-08-18 19:34:52 ----A---- C:\Windows\system32\shsvcs.dll
2010-08-18 19:34:52 ----A---- C:\Windows\system32\drivers\smb.sys
2010-08-18 19:34:51 ----A---- C:\Windows\system32\sqlsrv32.dll
2010-08-18 19:34:51 ----A---- C:\Windows\system32\spwmp.dll
2010-08-18 19:34:51 ----A---- C:\Windows\system32\spwizui.dll
2010-08-18 19:34:51 ----A---- C:\Windows\system32\spwinsat.dll
2010-08-18 19:34:51 ----A---- C:\Windows\system32\spreview.exe
2010-08-18 19:34:51 ----A---- C:\Windows\system32\spp.dll
2010-08-18 19:34:51 ----A---- C:\Windows\system32\spoolsv.exe
2010-08-18 19:34:51 ----A---- C:\Windows\system32\spoolss.dll
2010-08-18 19:34:51 ----A---- C:\Windows\system32\spinstall.exe
2010-08-18 19:34:51 ----A---- C:\Windows\system32\sperror.dll
2010-08-18 19:34:51 ----A---- C:\Windows\system32\spcmsg.dll
2010-08-18 19:34:51 ----A---- C:\Windows\system32\softkbd.dll
2010-08-18 19:34:51 ----A---- C:\Windows\system32\SnippingTool.exe
2010-08-18 19:34:51 ----A---- C:\Windows\system32\SndVol.exe
2010-08-18 19:34:51 ----A---- C:\Windows\system32\slwga.dll
2010-08-18 19:34:51 ----A---- C:\Windows\system32\SLUINotify.dll
2010-08-18 19:34:51 ----A---- C:\Windows\system32\SLUI.exe
2010-08-18 19:34:51 ----A---- C:\Windows\system32\SLsvc.exe
2010-08-18 19:34:51 ----A---- C:\Windows\system32\slmgr.vbs
2010-08-18 19:34:51 ----A---- C:\Windows\system32\SLLUA.exe
2010-08-18 19:34:51 ----A---- C:\Windows\system32\SLCommDlg.dll
2010-08-18 19:34:51 ----A---- C:\Windows\system32\slcinst.dll
2010-08-18 19:34:51 ----A---- C:\Windows\system32\SLCExt.dll
2010-08-18 19:34:51 ----A---- C:\Windows\system32\drivers\spsys.sys
2010-08-18 19:34:50 ----A---- C:\Windows\system32\zipfldr.dll
2010-08-18 19:34:50 ----A---- C:\Windows\system32\urlmon.dll
2010-08-18 19:34:50 ----A---- C:\Windows\system32\untfs.dll
2010-08-18 19:34:50 ----A---- C:\Windows\system32\TsWpfWrp.exe
2010-08-18 19:34:50 ----A---- C:\Windows\system32\TSTheme.exe
2010-08-18 19:34:50 ----A---- C:\Windows\system32\tskill.exe
2010-08-18 19:34:50 ----A---- C:\Windows\system32\tsgqec.dll
2010-08-18 19:34:50 ----A---- C:\Windows\system32\tsdiscon.exe
2010-08-18 19:34:50 ----A---- C:\Windows\system32\tscupgrd.exe
2010-08-18 19:34:50 ----A---- C:\Windows\system32\drivers\usbhub.sys
2010-08-18 19:34:50 ----A---- C:\Windows\system32\drivers\usbehci.sys
2010-08-18 19:34:50 ----A---- C:\Windows\system32\drivers\USBCAMD2.sys
2010-08-18 19:34:50 ----A---- C:\Windows\system32\drivers\USBCAMD.sys
2010-08-18 19:34:50 ----A---- C:\Windows\system32\drivers\usb8023.sys
2010-08-18 19:34:50 ----A---- C:\Windows\system32\drivers\udfs.sys
2010-08-18 19:34:49 ----A---- C:\Windows\system32\umrdp.dll
2010-08-18 19:34:49 ----A---- C:\Windows\system32\umpnpmgr.dll
2010-08-18 19:34:49 ----A---- C:\Windows\system32\ulib.dll
2010-08-18 19:34:49 ----A---- C:\Windows\system32\uDWM.dll
2010-08-18 19:34:49 ----A---- C:\Windows\system32\systemcpl.dll
2010-08-18 19:34:48 ----A---- C:\Windows\system32\tscon.exe
2010-08-18 19:34:48 ----A---- C:\Windows\system32\tscfgwmi.dll
2010-08-18 19:34:48 ----A---- C:\Windows\system32\tsbyuv.dll
2010-08-18 19:34:48 ----A---- C:\Windows\system32\tquery.dll
2010-08-18 19:34:48 ----A---- C:\Windows\system32\themeui.dll
2010-08-18 19:34:48 ----A---- C:\Windows\system32\themecpl.dll
2010-08-18 19:34:48 ----A---- C:\Windows\system32\thawbrkr.dll
2010-08-18 19:34:48 ----A---- C:\Windows\system32\termsrv.dll
2010-08-18 19:34:48 ----A---- C:\Windows\system32\tcpmon.dll
2010-08-18 19:34:48 ----A---- C:\Windows\system32\tcpipcfg.dll
2010-08-18 19:34:48 ----A---- C:\Windows\system32\taskeng.exe
2010-08-18 19:34:48 ----A---- C:\Windows\system32\taskcomp.dll
2010-08-18 19:34:48 ----A---- C:\Windows\system32\tapisrv.dll
2010-08-18 19:34:48 ----A---- C:\Windows\system32\drivers\termdd.sys
2010-08-18 19:34:48 ----A---- C:\Windows\system32\drivers\tdx.sys
2010-08-18 19:29:27 ----D---- C:\Windows\system32\EventProviders
2010-08-18 19:29:24 ----D---- C:\39158658e89b5e6e0173
2010-08-18 18:57:51 ----D---- C:\Program Files\CCleaner
2010-08-16 20:13:33 ----D---- C:\Windows\temp
2010-08-16 20:07:20 ----D---- C:\$RECYCLE.BIN
2010-08-16 18:00:48 ----D---- C:\Program Files\trend micro

davem
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 25 bře 2010 08:26

Re: Win32/Mebroot.K trojský kůň

#13 Příspěvek od davem »

======List of files/folders modified in the last 1 months======

2010-08-18 20:54:28 ----D---- C:\Windows\Prefetch
2010-08-18 20:53:42 ----D---- C:\Windows
2010-08-18 20:50:46 ----SHD---- C:\Windows\Installer
2010-08-18 20:50:23 ----D---- C:\Windows\system32\catroot2
2010-08-18 20:50:23 ----D---- C:\Windows\system32\catroot
2010-08-18 20:50:22 ----D---- C:\Windows\inf
2010-08-18 20:50:16 ----D---- C:\Windows\system32\drivers
2010-08-18 20:50:15 ----D---- C:\Windows\System32
2010-08-18 20:50:01 ----RD---- C:\Program Files
2010-08-18 20:49:53 ----SHD---- C:\System Volume Information
2010-08-18 20:48:48 ----D---- C:\ProgramData
2010-08-18 20:42:52 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-08-18 20:32:30 ----D---- C:\Windows\winsxs
2010-08-18 20:32:13 ----D---- C:\Windows\SoftwareDistribution
2010-08-18 20:30:50 ----RSD---- C:\Windows\assembly
2010-08-18 20:30:50 ----D---- C:\Windows\Microsoft.NET
2010-08-18 20:27:48 ----SHD---- C:\Boot
2010-08-18 20:21:20 ----D---- C:\Program Files\Windows Mail
2010-08-18 20:21:20 ----D---- C:\Program Files\Windows Calendar
2010-08-18 20:21:20 ----D---- C:\Program Files\Movie Maker
2010-08-18 20:21:19 ----D---- C:\Program Files\Windows Sidebar
2010-08-18 20:21:19 ----D---- C:\Program Files\Windows Media Player
2010-08-18 20:21:19 ----D---- C:\Program Files\Internet Explorer
2010-08-18 20:21:18 ----D---- C:\Program Files\Windows Journal
2010-08-18 20:21:18 ----D---- C:\Program Files\Windows Collaboration
2010-08-18 20:21:17 ----D---- C:\Program Files\Windows Photo Gallery
2010-08-18 20:21:17 ----D---- C:\Program Files\Common Files\System
2010-08-18 20:21:15 ----D---- C:\Windows\servicing
2010-08-18 20:21:15 ----D---- C:\Windows\ehome
2010-08-18 20:21:15 ----D---- C:\Program Files\Windows Defender
2010-08-18 20:21:06 ----D---- C:\Windows\IME
2010-08-18 20:21:05 ----D---- C:\Windows\system32\lv-LV
2010-08-18 20:21:05 ----D---- C:\Windows\PolicyDefinitions
2010-08-18 20:21:04 ----D---- C:\Windows\system32\XPSViewer
2010-08-18 20:21:04 ----D---- C:\Windows\system32\sk-SK
2010-08-18 20:21:04 ----D---- C:\Windows\system32\ko-KR
2010-08-18 20:21:04 ----D---- C:\Windows\system32\it-IT
2010-08-18 20:21:04 ----D---- C:\Windows\system32\hr-HR
2010-08-18 20:21:04 ----D---- C:\Windows\system32\et-EE
2010-08-18 20:21:04 ----D---- C:\Windows\system32\en-US
2010-08-18 20:21:04 ----D---- C:\Windows\system32\el-GR
2010-08-18 20:21:04 ----D---- C:\Windows\system32\de-DE
2010-08-18 20:21:04 ----D---- C:\Windows\system32\da-DK
2010-08-18 20:21:03 ----D---- C:\Windows\system32\oobe
2010-08-18 20:21:03 ----D---- C:\Windows\system32\migration
2010-08-18 20:21:02 ----D---- C:\Windows\system32\AdvancedInstallers
2010-08-18 20:21:01 ----D---- C:\Windows\system32\sv-SE
2010-08-18 20:21:01 ----D---- C:\Windows\system32\setup
2010-08-18 20:21:01 ----D---- C:\Windows\system32\ru-RU
2010-08-18 20:21:01 ----D---- C:\Windows\system32\he-IL
2010-08-18 20:21:01 ----D---- C:\Windows\system32\fr-FR
2010-08-18 20:21:01 ----D---- C:\Windows\system32\fi-FI
2010-08-18 20:21:01 ----D---- C:\Windows\system32\cs
2010-08-18 20:21:00 ----D---- C:\Windows\system32\cs-CZ
2010-08-18 20:20:58 ----D---- C:\Windows\system32\SLUI
2010-08-18 20:20:58 ----D---- C:\Windows\system32\pt-PT
2010-08-18 20:20:58 ----D---- C:\Windows\system32\hu-HU
2010-08-18 20:20:57 ----D---- C:\Windows\system32\zh-TW
2010-08-18 20:20:57 ----D---- C:\Windows\system32\zh-CN
2010-08-18 20:20:57 ----D---- C:\Windows\system32\uk-UA
2010-08-18 20:20:57 ----D---- C:\Windows\system32\sr-Latn-CS
2010-08-18 20:20:57 ----D---- C:\Windows\system32\sl-SI
2010-08-18 20:20:57 ----D---- C:\Windows\system32\pl-PL
2010-08-18 20:20:57 ----D---- C:\Windows\system32\manifeststore
2010-08-18 20:20:57 ----D---- C:\Windows\system32\ja-JP
2010-08-18 20:20:57 ----D---- C:\Windows\system32\es-ES
2010-08-18 20:20:56 ----D---- C:\Windows\system32\th-TH
2010-08-18 20:20:56 ----D---- C:\Windows\system32\ro-RO
2010-08-18 20:20:56 ----D---- C:\Windows\system32\drivers\UMDF
2010-08-18 20:20:56 ----D---- C:\Windows\system32\drivers\cs-CZ
2010-08-18 20:20:56 ----D---- C:\Windows\system32\bg-BG
2010-08-18 20:20:55 ----D---- C:\Windows\system32\tr-TR
2010-08-18 20:20:54 ----D---- C:\Windows\system32\wbem
2010-08-18 20:20:54 ----D---- C:\Windows\system32\nl-NL
2010-08-18 20:20:54 ----D---- C:\Windows\system32\nb-NO
2010-08-18 20:20:53 ----D---- C:\Windows\system32\pt-BR
2010-08-18 20:20:53 ----D---- C:\Windows\system32\migwiz
2010-08-18 20:20:53 ----D---- C:\Windows\system32\lt-LT
2010-08-18 20:20:53 ----D---- C:\Windows\system32\ar-SA
2010-08-18 20:20:18 ----RSD---- C:\Windows\Fonts
2010-08-18 20:20:17 ----D---- C:\Windows\AppPatch
2010-08-18 20:20:09 ----D---- C:\Windows\system32\Boot
2010-08-18 20:19:42 ----D---- C:\Windows\Minidump
2010-08-18 19:58:08 ----D---- C:\Windows\system32\RTCOM
2010-08-18 19:50:26 ----A---- C:\Windows\fonts\GlobalUserInterface.CompositeFont
2010-08-18 18:58:32 ----D---- C:\Windows\Debug
2010-08-17 20:32:32 ----D---- C:\Downloads
2010-08-17 19:04:53 ----A---- C:\Windows\NeroDigital.ini
2010-08-16 21:09:19 ----D---- C:\ProgramData\Lavasoft
2010-08-16 21:09:19 ----D---- C:\Program Files\Lavasoft
2010-08-16 21:09:06 ----DC---- C:\Windows\system32\DRVSTORE
2010-08-16 20:07:27 ----A---- C:\Windows\system.ini
2010-08-16 20:07:15 ----D---- C:\Windows\system32\drivers\etc
2010-08-16 20:05:04 ----D---- C:\Windows\system
2010-08-16 20:02:50 ----D---- C:\Program Files\Common Files
2010-08-16 18:27:18 ----D---- C:\Program Files\AIMP2
2010-08-16 17:21:47 ----D---- C:\ProgramData\DVD Shrink
2010-08-06 13:13:17 ----D---- C:\Windows\system32\FxsTmp
2010-07-25 08:42:06 ----D---- C:\Program Files\Mozilla Firefox

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 fvevol;BitLocker Drive Encryption Filter Driver; C:\Windows\System32\DRIVERS\fvevol.sys [2009-04-10 143848]
R0 Pnp680r;Silicon Image SiI 0680 Medley Raid Controller; C:\Windows\system32\DRIVERS\pnp680r.sys [2007-07-19 110120]
R0 PxHelp20;PxHelp20; C:\Windows\system32\DRIVERS\PxHelp20.sys [2008-09-06 20016]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2009-01-01 717296]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-04-28 114984]
R1 SbFw;SbFw; C:\Windows\system32\drivers\SbFw.sys [2008-10-31 270888]
R1 sbhips;Sunbelt HIPS Driver; C:\Windows\system32\drivers\sbhips.sys [2008-06-21 66600]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};Power Control [2009/04/25 13:23:15]; \??\C:\Program Files\CyberLink\PowerDVD8\000.fcl [2009-01-20 87536]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-06-24 136120]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2010-04-28 96896]
R3 Afc;PPdus ASPI Shell; C:\Windows\system32\drivers\Afc.sys [2005-02-23 11776]
R3 BENDER;Pinnacle AV/DV2 Capture; C:\Windows\system32\drivers\bender.sys [2006-12-04 203264]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-02-14 2061528]
R3 MarvinBus;Pinnacle Marvin Bus; C:\Windows\system32\DRIVERS\MarvinBus.sys [2005-09-23 171520]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2007-12-11 8238688]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2008-01-25 106496]
R3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport; C:\Windows\system32\DRIVERS\sbfwim.sys [2008-06-21 65576]
S0 Lbd;Lbd; C:\Windows\system32\DRIVERS\Lbd.sys []
S3 61883;61883 Unit Device; C:\Windows\system32\DRIVERS\61883.sys [2008-05-21 45696]
S3 Avc;Zařízení AVC; C:\Windows\system32\DRIVERS\avc.sys [2008-05-21 40448]
S3 azpvcygo;azpvcygo; C:\Windows\system32\drivers\azpvcygo.sys []
S3 CrystalSysInfo;CrystalSysInfo; \??\C:\Program Files\MediaCoder\SysInfo.sys [2007-09-25 15152]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-05-21 5632]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2009-06-10 16608]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSDV;Microsoft DV Camera and VCR; C:\Windows\system32\DRIVERS\msdv.sys [2008-05-21 52608]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-05-21 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-05-21 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-05-21 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-05-21 6016]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-05-21 35328]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-05-21 39936]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-05-21 83328]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-05-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-05-21 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2010-07-02 810144]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2009-04-13 73728]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2008-06-08 877864]
R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\Windows\system32\IoctlSvc.exe [2006-12-19 81920]
R2 SbPF.Launcher;SbPF.Launcher; C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe [2008-10-31 95528]
R2 SPF4;Sunbelt Personal Firewall 4; C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe [2008-10-31 1365288]
R2 TomTomHOMEService;TomTomHOMEService; C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe [2010-06-24 92008]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2008-06-24 537896]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2008-09-06 72704]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2010-07-02 33584]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2008-08-24 654848]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

-----------------EOF-----------------

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Win32/Mebroot.K trojský kůň

#14 Příspěvek od Caroprd111 »

Obrázek Doporučuji aktualizovat Adobe Reader http://www.stahuj.centrum.cz/podnikani_ ... batreader/


Jinak je log v pořádku. :)
Obrázek

davem
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 25 bře 2010 08:26

Re: Win32/Mebroot.K trojský kůň

#15 Příspěvek od davem »

Mnohokrate dekuji:) omlouvam se za zpozdenou reakci...trutnov fest no :) Jeste jednou dekuji.

Odpovědět