Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

MBR rootkit

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Sentello
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 12 led 2010 15:12

MBR rootkit

#1 Příspěvek od Sentello »

Zdravím,
Mám v PC MBR rootkit ;)
Bylo nebylo vše začačlo stažením jednoho patche, nebyl to patch ale vir. Smazal mě během zlomku všechny oddíly na disku (NTFS, EXT3) a flashdisk připojený k PC. Několik dnů jsem si hrál s obnovou disku – nakonec se to podařilo, ale vir se uhnízdil v MBR. K tomuto zjištění dospěl ComboFix který jsem spustil hned po obnově.

Analyzoval jsem vir u VT:

Kód: Vybrat vše

 http://www.virustotal.com/file-scan/report.html?id=30e9c5e1f9f91d94c21af51c12d01f558c563fa099bf93d6a366a5af65ac76e1-1290520370 
Odvážným vir rád zašlu – je bezpečný dokud se nestiskne Storno, co dělá Ano nevím :D

BTW: Antivir ESET Smart Security 4.2 nedetekoval nic! Norton Internet Security 2011 také nic.
OS: Windows XP SP3


Log z RSIT: http://leteckaposta.cz/601324406

Za všechny příspěvky předem děkuji. :all_coholic:

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: MBR rootkit

#2 Příspěvek od vyosek »

Zdravim a pekny vecer preji :)

:arrow: Ten RSIT je az po aplikovani Combofixu, ze? ComboFix jste aplikoval na doporuceni nekoho kdo jej v jeho pouzivani vyskolen, ci jste to i Vy sam a umite si jeho log vylustit :???:

:arrow: Nebezpeci CFka
  • Je urcen primarne pro radce - jeho svevolnym pouzitim ztracite narok na podporu
  • Maze stopy po haveti, takze v logu z RSIT neni nic videt
  • Jeho log je treba dolustit, jelikoz neumi smazat vse - to ovsem tezko zvladnete pokud k tomu nejste vyskolen
  • CF muze mit bug = sunda Vam system, pokud nevite kam co uklada, jak co obnovit, mate system v kytkam a ceka Vas reinstal
  • CF taky bohuzel prozatim nekontroluje nektere dulezite knihovny (napr. hal.dll) - ty treba mazou nektere typy haveti (napr. angela) - smaze Vam po restartu hal.dll = nenajede Vam system a jste o radek vyse = reinstal
:arrow: Ten patch - nebyl to spise nejaky crack :o

Vzhledem k tomu, ze pouzivate nelegalni SW Obrázek se nedivim, ze jste navstevnikem naseho fora :?:
Dle pravidel fora (viz zde a a zde bod c.3 ) se vsak nelegalnim SW nezabyvame, jelikoz nelegalni programy jsou vetsinou zdrojem haveti. Navic tim porusujete i autorska prava Obrázek, pachate trestny cin a ten jako takovy nebude nasim forem podporovan. Uvedomte si, ze jste na bezpecnostnim foru - podpora warezu (zvlaste bezpecnostnich programu) by byla zcela proti logice fora :!:
Obstarejte si proto legalni ochranu Vaseho PC (antivir+firewall), pote sem vlozte novy log z RSITu a CKScanneru - viz nize.

Osobne Vam doporucuji kombinaci Avast+ZoneAlarm. Prehled antiviru mate ZDE a firewallu TADY.

:arrow: Log z RSITu - viz muj podpis
:arrow: Stahnete na plochu CKScanner
  • Spustte a kliknete na Search for files
  • Po dokonceni skenu kliknete na Save List to File a nasledne OK
  • Na plose se Vam vytvori log s nazvem ckfiles.txt, jeho obsah mi sem vlozte
:arrow: Oba logy vlozte sem - v pripade ze budou mit hodne znaku, jej rozdelte do vice prispevku
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Sentello
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 12 led 2010 15:12

Re: MBR rootkit

#3 Příspěvek od Sentello »

Dobrý večer,
Ano nemám vše legálně :D
RSIT jsem pustil až po ComboFixu, combofix mě doporučil IT odborník, prý dokáže detekovat havěť a odmazat ji.

CKScanner
CKScanner - Additional Security Risks - These are not necessarily bad
c:\documents and settings\sentello\desktop\wepcrack-ubuntu\dependencies
c:\documents and settings\sentello\desktop\wepcrack-ubuntu\gwepcrackgui.exe
c:\documents and settings\sentello\desktop\wepcrack-ubuntu\gwepcrackgui.exe.mdb
c:\documents and settings\sentello\desktop\wepcrack-ubuntu\oui.txt
c:\documents and settings\sentello\desktop\wepcrack-ubuntu\readme
c:\documents and settings\sentello\desktop\wepcrack-ubuntu\release_notes0.8.1
c:\documents and settings\sentello\desktop\wepcrack-ubuntu\ssid.txt
c:\documents and settings\sentello\desktop\wepcrack-ubuntu\unbuffer.exe
c:\documents and settings\sentello\desktop\wepcrack-ubuntu\unbuffer.exe.mdb
c:\documents and settings\sentello\desktop\wepcrack-ubuntu\wepcrack
c:\documents and settings\sentello\desktop\wepcrack-ubuntu\wepcrack-debug
c:\documents and settings\sentello\desktop\wepcrack-ubuntu\wepcrack.dll
c:\documents and settings\sentello\desktop\wepcrack-ubuntu\wepcrack.dll.mdb
c:\documents and settings\sentello\desktop\wepcrack-ubuntu\wepcrack.pc
c:\documents and settings\sentello\desktop\wepcrack-ubuntu\wepcrackgtk.dll
c:\documents and settings\sentello\desktop\wepcrack-ubuntu\wepcrackgtk.dll.mdb
c:\documents and settings\sentello\desktop\wepcrack-ubuntu\wepcrackgtk.pc
c:\documents and settings\sentello\desktop\wepcrack-ubuntu\wepcrackinterfaces.dll
c:\documents and settings\sentello\desktop\wepcrack-ubuntu\wepcrackinterfaces.dll.mdb
c:\documents and settings\sentello\desktop\wepcrack-ubuntu\wepcrackinterfaces.pc
c:\documents and settings\sentello\desktop\wepcrack-ubuntu\locale\de\lc_messages\i8n1.mo
c:\documents and settings\sentello\desktop\wepcrack-ubuntu\locale\es\lc_messages\i8n1.mo
c:\documents and settings\sentello\desktop\wepcrack-ubuntu\locale\it\lc_messages\i8n1.mo
c:\documents and settings\sentello\desktop\wepcrack-ubuntu\wordlists\password.lst
scanner sequence 3.ZZ.11
----- EOF -----

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: MBR rootkit

#4 Příspěvek od vyosek »

:arrow: Tak tomu IT bych jednu placnul - ano umi detekovat a mazat, ale i pekne sundat system. Navic log je treba dolustit :!: CF opravdu neni hracka na bezne pouzivani :?:

:arrow: Takze odinstalujte nelegalni ESS, dejte free Avast ci Aviru, vlozte novy log z RSIT a nasledne i log z Combofixu
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Sentello
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 12 led 2010 15:12

Re: MBR rootkit

#5 Příspěvek od Sentello »

RIST
Logfile of random's system information tool 1.08 (written by random/random)
Run by Sentello at 2010-11-29 20:28:39
Microsoft Windows XP Professional Service Pack 3
System drive C: has 10 GB (47%) free of 20 GB
Total RAM: 1471 MB (54% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:28:41, on 29.11.2010 г.
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\VTtrayp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HDDlife for Notebooks\HDDlife for Notebooks.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\OpenVPN Technologies\OpenVPN Client\core\capiws.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\QIP\qip.exe
C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
D:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\AIMP2\AIMP2.exe
C:\Program Files\Last.fm\LastFM.exe
C:\Documents and Settings\Sentello\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Sentello\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Sentello\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Sentello\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Sentello\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Sentello\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Sentello\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Sentello\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Sentello\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Sentello\Desktop\RSIT.exe
C:\Program Files\trend micro\Sentello.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: HDDlife.lnk = C:\Program Files\HDDlife for Notebooks\HDDlife for Notebooks.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Zdroje informaci - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 9955803046
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 0039463265
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: OpenVPN Access Client (OpenVPNAccessClient) - Unknown owner - C:\Program Files\OpenVPN Technologies\OpenVPN Client\core\capiws.exe

--
End of file - 5832 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\1-Click Maintenance.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-682003330-1417001333-1003Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-682003330-1417001333-1003UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-11-17 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-11-17 79648]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"=C:\WINDOWS\system32\VTTimer.exe [2005-03-08 53248]
"VTTrayp"=C:\WINDOWS\system32\VTtrayp.exe [2005-09-14 167936]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2005-08-17 90112]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2005-07-08 729178]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2010-08-12 2215064]
"TrueImageMonitor.exe"=C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [2010-03-27 5107232]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"=C:\Program Files\Microsoft ActiveSync\Wcescomm.exe [2006-11-13 1289000]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ose"=3
"JavaQuickStarterService"=2
"JUPOERXJVJY"=3
"afcdpsrv"=2
"AcrSch2Svc"=2

C:\Documents and Settings\Sentello\Start Menu\Programs\Startup
HDDlife.lnk - C:\Program Files\HDDlife for Notebooks\HDDlife for Notebooks.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"D:\Program Files\uTorrent\uTorrent.exe"="D:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\ArcSoft\TotalMedia 3\TotalMedia.exe"="C:\Program Files\ArcSoft\TotalMedia 3\TotalMedia.exe:LocalSubNet:Enabled:ArcSoft TotalMedia 3"
"D:\Program Files\Nonoh.net\Nonoh\nonoh.exe"="D:\Program Files\Nonoh.net\Nonoh\nonoh.exe:*:Enabled:Nonoh"
"D:\Program Files\Skype\Phone\Skype.exe"="D:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"

======List of files/folders created in the last 1 months======

2010-11-29 19:41:55 ----D---- C:\Program Files\trend micro
2010-11-29 19:41:54 ----D---- C:\rsit
2010-11-28 19:33:48 ----D---- C:\Documents and Settings\Sentello\Application Data\Mozilla
2010-11-28 19:33:45 ----D---- C:\Documents and Settings\Sentello\Application Data\OpenVPN Technologies
2010-11-28 19:30:45 ----D---- C:\Program Files\OpenVPN Technologies
2010-11-28 19:25:07 ----D---- C:\WINDOWS\system32\XPSViewer
2010-11-28 19:25:03 ----D---- C:\Program Files\MSBuild
2010-11-28 19:24:53 ----D---- C:\Program Files\Reference Assemblies
2010-11-28 19:23:53 ----N---- C:\WINDOWS\system32\prntvpt.dll
2010-11-28 19:23:52 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2010-11-28 19:23:52 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2010-11-28 19:23:06 ----RSD---- C:\WINDOWS\assembly
2010-11-28 19:22:41 ----D---- C:\WINDOWS\Microsoft.NET
2010-11-28 16:47:32 ----ASH---- C:\pagefile.sys
2010-11-27 16:32:12 ----D---- C:\Program Files\HDDlife for Notebooks
2010-11-27 16:16:20 ----D---- C:\Documents and Settings\Sentello\Application Data\Nonoh
2010-11-27 15:18:31 ----D---- C:\Documents and Settings\Sentello\Application Data\BinarySense
2010-11-25 01:16:47 ----ASH---- C:\hiberfil.sys
2010-11-24 22:24:18 ----SHD---- C:\RECYCLER
2010-11-24 22:18:44 ----D---- C:\WINDOWS\temp
2010-11-24 19:00:49 ----D---- C:\Documents and Settings\Sentello\Application Data\TuneUpMedia
2010-11-24 13:54:25 ----D---- C:\Documents and Settings\Sentello\Application Data\Acronis
2010-11-24 13:53:45 ----D---- C:\Documents and Settings\All Users\Application Data\TuneUpMedia
2010-11-24 13:38:48 ----A---- C:\WINDOWS\system32\GEARAspi.dll
2010-11-24 13:38:48 ----A---- C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
2010-11-24 13:29:12 ----D---- C:\Documents and Settings\All Users\Application Data\Acronis
2010-11-24 13:23:57 ----A---- C:\WINDOWS\system32\drivers\afcdp.sys
2010-11-24 13:22:59 ----A---- C:\WINDOWS\system32\drivers\snapman.sys
2010-11-24 13:22:02 ----D---- C:\Program Files\Common Files\Acronis
2010-11-24 13:22:00 ----D---- C:\Program Files\Acronis
2010-11-24 02:38:57 ----D---- C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
2010-11-23 20:15:09 ----A---- C:\WINDOWS\NIRCMD.exe
2010-11-23 20:15:09 ----A---- C:\WINDOWS\MBR.exe
2010-11-23 20:15:08 ----A---- C:\WINDOWS\zip.exe
2010-11-23 20:15:08 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-11-23 20:15:08 ----A---- C:\WINDOWS\SWSC.exe
2010-11-23 20:15:08 ----A---- C:\WINDOWS\SWREG.exe
2010-11-23 20:15:08 ----A---- C:\WINDOWS\sed.exe
2010-11-23 20:15:08 ----A---- C:\WINDOWS\PEV.exe
2010-11-23 20:15:08 ----A---- C:\WINDOWS\grep.exe
2010-11-23 20:13:17 ----D---- C:\WINDOWS\ERDNT
2010-11-23 20:12:15 ----D---- C:\WINDOWS\pss
2010-11-23 07:57:05 ----D---- C:\WINDOWS\system32\NtmsData
2010-11-22 11:51:35 ----D---- C:\WINDOWS\SxsCaPendDel
2010-11-22 10:38:07 ----A---- C:\WINDOWS\system32\drivers\tdrpm258.sys
2010-11-22 10:38:03 ----A---- C:\WINDOWS\system32\drivers\timntr.sys
2010-11-21 23:06:16 ----D---- C:\WINDOWS\Minidump
2010-11-20 23:04:21 ----HD---- C:\WINDOWS\PIF
2010-11-20 15:41:57 ----D---- C:\Documents and Settings\Sentello\Application Data\vlc
2010-11-20 15:41:15 ----D---- C:\Program Files\VideoLAN
2010-11-20 14:56:07 ----A---- C:\WINDOWS\IsUninst.exe
2010-11-19 12:27:22 ----A---- C:\WINDOWS\ModemLog_HUAWEI Mobile Connect - 3G Modem #3.txt
2010-11-18 19:01:08 ----D---- C:\WINDOWS\system32\appmgmt
2010-11-18 17:16:51 ----D---- C:\Program Files\My Mobile
2010-11-17 21:05:38 ----A---- C:\WINDOWS\system32\drivers\MSTEE.sys
2010-11-17 21:05:36 ----A---- C:\WINDOWS\system32\drivers\MPE.sys
2010-11-17 21:05:31 ----A---- C:\WINDOWS\system32\drivers\NdisIP.sys
2010-11-17 21:05:29 ----A---- C:\WINDOWS\system32\drivers\StreamIP.sys
2010-11-17 21:05:26 ----A---- C:\WINDOWS\system32\drivers\SLIP.sys
2010-11-17 21:05:23 ----A---- C:\WINDOWS\system32\drivers\WSTCODEC.SYS
2010-11-17 21:05:17 ----A---- C:\WINDOWS\system32\drivers\NABTSFEC.sys
2010-11-17 21:05:13 ----A---- C:\WINDOWS\system32\drivers\CCDECODE.sys
2010-11-17 21:05:08 ----D---- C:\Documents and Settings\Sentello\Application Data\ArcSoft
2010-11-17 21:05:01 ----A---- C:\WINDOWS\system32\drivers\afc.sys
2010-11-17 21:04:48 ----D---- C:\Program Files\Common Files\ArcSoft
2010-11-17 21:04:44 ----A---- C:\WINDOWS\system32\PsisDecd.dll
2010-11-17 21:04:43 ----A---- C:\WINDOWS\system32\vfwwdm32.dll
2010-11-17 21:04:43 ----A---- C:\WINDOWS\system32\drivers\BdaSup.sys
2010-11-17 21:01:55 ----RA---- C:\WINDOWS\system32\msvcp71.dll
2010-11-17 21:01:55 ----D---- C:\Program Files\ArcSoft
2010-11-17 21:01:55 ----A---- C:\WINDOWS\system32\unicows.dll
2010-11-17 21:01:55 ----A---- C:\WINDOWS\system32\msvcr71.dll
2010-11-17 21:01:55 ----A---- C:\WINDOWS\PCDLIB32.DLL
2010-11-17 20:52:02 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-11-17 20:52:02 ----A---- C:\WINDOWS\system32\smsprops.dll
2010-11-17 20:52:02 ----A---- C:\WINDOWS\system32\drivers\smsbda.sys
2010-11-17 20:52:01 ----D---- C:\Program Files\Smitbda
2010-11-17 20:22:17 ----D---- C:\Program Files\StrongDC++
2010-11-17 19:55:55 ----D---- C:\Documents and Settings\Sentello\Application Data\VitySoft
2010-11-17 19:55:35 ----D---- C:\Documents and Settings\All Users\Application Data\Sun
2010-11-17 19:55:32 ----D---- C:\Program Files\Common Files\Java
2010-11-17 19:55:07 ----A---- C:\WINDOWS\system32\javaws.exe
2010-11-17 19:55:07 ----A---- C:\WINDOWS\system32\javaw.exe
2010-11-17 19:55:07 ----A---- C:\WINDOWS\system32\java.exe
2010-11-17 19:55:07 ----A---- C:\WINDOWS\system32\deployJava1.dll
2010-11-17 19:54:47 ----D---- C:\Program Files\Java
2010-11-17 19:53:20 ----D---- C:\Documents and Settings\Sentello\Application Data\Sun
2010-11-17 12:48:23 ----D---- C:\Documents and Settings\Sentello\Application Data\URSoft
2010-11-17 12:48:20 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2010-11-17 12:48:11 ----D---- C:\Program Files\Your Uninstaller 2010
2010-11-17 12:47:32 ----A---- C:\WINDOWS\system32\unrar.dll
2010-11-17 02:43:01 ----HDC---- C:\WINDOWS\$NtUninstallKB2345886$
2010-11-17 02:42:56 ----HDC---- C:\WINDOWS\$NtUninstallKB2141007$
2010-11-17 02:42:50 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2010-11-17 02:42:37 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2010-11-17 02:36:13 ----A---- C:\WINDOWS\system32\MRT.exe
2010-11-17 02:36:04 ----HDC---- C:\WINDOWS\$NtUninstallKB2360937$
2010-11-17 02:35:59 ----HDC---- C:\WINDOWS\$NtUninstallKB2279986$
2010-11-17 02:35:53 ----HDC---- C:\WINDOWS\$NtUninstallKB981957$
2010-11-17 02:35:48 ----HDC---- C:\WINDOWS\$NtUninstallKB982132$
2010-11-17 02:35:41 ----HDC---- C:\WINDOWS\$NtUninstallKB2387149$
2010-11-17 02:35:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2378111_WM9$
2010-11-17 02:35:30 ----HDC---- C:\WINDOWS\$NtUninstallKB2296011$
2010-11-17 02:35:24 ----HDC---- C:\WINDOWS\$NtUninstallKB979687$
2010-11-17 02:35:18 ----HDC---- C:\WINDOWS\$NtUninstallKB975558_WM8$
2010-11-17 02:35:13 ----HDC---- C:\WINDOWS\$NtUninstallKB2158563$
2010-11-17 02:35:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2347290$
2010-11-17 02:35:03 ----HDC---- C:\WINDOWS\$NtUninstallKB2121546$
2010-11-17 02:34:58 ----HDC---- C:\WINDOWS\$NtUninstallKB981322$
2010-11-17 02:34:53 ----HDC---- C:\WINDOWS\$NtUninstallKB2259922$
2010-11-17 02:34:48 ----HDC---- C:\WINDOWS\$NtUninstallKB980436$
2010-11-17 02:34:39 ----HDC---- C:\WINDOWS\$NtUninstallKB981852$
2010-11-17 02:34:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2079403$
2010-11-17 02:34:26 ----HDC---- C:\WINDOWS\$NtUninstallKB981997$
2010-11-17 02:34:21 ----HDC---- C:\WINDOWS\$NtUninstallKB982214$
2010-11-17 02:34:16 ----HDC---- C:\WINDOWS\$NtUninstallKB982665$
2010-11-17 02:34:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2115168$
2010-11-17 02:34:02 ----HDC---- C:\WINDOWS\$NtUninstallKB2286198$
2010-11-17 02:33:56 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$
2010-11-17 02:33:51 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2010-11-17 02:33:45 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2010-11-17 02:33:40 ----HDC---- C:\WINDOWS\$NtUninstallKB980195$
2010-11-17 02:33:35 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2010-11-17 02:33:30 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2010-11-17 02:33:25 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-11-17 02:33:20 ----HDC---- C:\WINDOWS\$NtUninstallKB981349$
2010-11-17 02:33:14 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-11-17 02:33:09 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-11-17 02:33:04 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2010-11-17 02:32:59 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-11-17 02:32:54 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-11-17 02:32:48 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-11-17 02:32:37 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-11-17 02:32:23 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-11-17 02:32:13 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-11-17 02:32:08 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-11-17 02:32:02 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2010-11-17 02:31:54 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-11-17 02:31:47 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2010-11-17 02:31:40 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2010-11-17 02:31:31 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2010-11-17 02:31:26 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2010-11-17 02:31:19 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2010-11-17 02:31:13 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2010-11-17 02:31:09 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2010-11-17 02:31:04 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2010-11-17 02:30:59 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2010-11-17 02:30:54 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2010-11-17 02:30:49 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2010-11-17 02:30:45 ----HDC---- C:\WINDOWS\$NtUninstallKB971961$
2010-11-17 02:30:39 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2010-11-17 02:30:34 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2010-11-17 02:30:29 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2010-11-17 02:30:24 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2010-11-17 02:30:19 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2010-11-17 02:30:13 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2010-11-17 02:30:07 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2010-11-17 02:30:00 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
2010-11-17 02:29:55 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2010-11-17 02:29:49 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2010-11-17 02:29:43 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2010-11-17 02:29:36 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2010-11-17 02:29:17 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2010-11-17 02:29:09 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2010-11-17 02:28:57 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2010-11-17 02:28:49 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2010-11-17 02:28:42 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2010-11-17 02:28:36 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
2010-11-17 02:28:31 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2010-11-17 02:28:23 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2010-11-17 02:28:17 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2010-11-17 02:28:12 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2010-11-17 02:28:07 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2010-11-17 02:28:00 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2010-11-17 02:27:51 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2010-11-17 02:27:45 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2010-11-17 02:27:38 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2010-11-17 02:27:28 ----HDC---- C:\WINDOWS\$NtUninstallKB950760$
2010-11-17 02:17:55 ----A---- C:\WINDOWS\system32\xpsp4res.dll
2010-11-17 02:16:18 ----N---- C:\WINDOWS\system32\drivers\bthport.sys
2010-11-17 02:14:07 ----D---- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2010-11-17 02:13:21 ----D---- C:\WINDOWS\system32\PreInstall
2010-11-17 02:13:20 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2010-11-17 02:13:19 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2010-11-17 02:13:19 ----HD---- C:\WINDOWS\$hf_mig$
2010-11-17 02:13:16 ----N---- C:\WINDOWS\system32\spmsg.dll
2010-11-17 02:07:53 ----A---- C:\WINDOWS\system32\wups2.dll
2010-11-17 02:07:53 ----A---- C:\WINDOWS\system32\wucltui.dll.mui
2010-11-17 02:07:53 ----A---- C:\WINDOWS\system32\wuaueng.dll.mui
2010-11-17 02:07:52 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2010-11-17 02:07:52 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
2010-11-16 17:27:59 ----D---- C:\Program Files\Microsoft Works
2010-11-16 15:20:47 ----A---- C:\WINDOWS\ModemLog_HUAWEI Mobile Connect - 3G Modem #2.txt
2010-11-15 23:29:22 ----D---- C:\Documents and Settings\Sentello\Application Data\uTorrent
2010-11-15 21:51:28 ----D---- C:\Program Files\Last.fm
2010-11-15 21:44:22 ----D---- C:\Program Files\Microsoft ActiveSync
2010-11-15 21:35:32 ----A---- C:\WINDOWS\ModemLog_HUAWEI Mobile Connect - 3G Modem.txt
2010-11-15 21:32:47 ----D---- C:\Documents and Settings\Sentello\Application Data\Telefonica Moviles
2010-11-15 21:32:42 ----A---- C:\WINDOWS\system32\XAudio2_7.dll
2010-11-15 21:32:42 ----A---- C:\WINDOWS\system32\XAPOFX1_5.dll
2010-11-15 21:32:41 ----A---- C:\WINDOWS\system32\xactengine3_7.dll
2010-11-15 21:32:40 ----A---- C:\WINDOWS\system32\d3dcsx_43.dll
2010-11-15 21:32:40 ----A---- C:\WINDOWS\system32\D3DCompiler_43.dll
2010-11-15 21:32:39 ----A---- C:\WINDOWS\system32\D3DX9_43.dll
2010-11-15 21:32:39 ----A---- C:\WINDOWS\system32\d3dx11_43.dll
2010-11-15 21:32:39 ----A---- C:\WINDOWS\system32\d3dx10_43.dll
2010-11-15 21:32:38 ----A---- C:\WINDOWS\system32\XAudio2_6.dll
2010-11-15 21:32:38 ----A---- C:\WINDOWS\system32\XAPOFX1_4.dll
2010-11-15 21:32:38 ----A---- C:\WINDOWS\system32\xactengine3_6.dll
2010-11-15 21:32:36 ----A---- C:\WINDOWS\system32\X3DAudio1_7.dll
2010-11-15 21:32:35 ----A---- C:\WINDOWS\system32\XAudio2_5.dll
2010-11-15 21:32:35 ----A---- C:\WINDOWS\system32\xactengine3_5.dll
2010-11-15 21:32:33 ----A---- C:\WINDOWS\system32\D3DCompiler_42.dll
2010-11-15 21:32:32 ----A---- C:\WINDOWS\system32\d3dcsx_42.dll
2010-11-15 21:32:31 ----A---- C:\WINDOWS\system32\d3dx11_42.dll
2010-11-15 21:32:30 ----A---- C:\WINDOWS\system32\D3DX9_42.dll
2010-11-15 21:32:30 ----A---- C:\WINDOWS\system32\d3dx10_42.dll
2010-11-15 21:32:29 ----A---- C:\WINDOWS\system32\d3dx10_41.dll
2010-11-15 21:32:29 ----A---- C:\WINDOWS\system32\D3DCompiler_41.dll
2010-11-15 21:32:28 ----A---- C:\WINDOWS\system32\D3DX9_41.dll
2010-11-15 21:32:27 ----A---- C:\WINDOWS\system32\XAudio2_4.dll

Sentello
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 12 led 2010 15:12

Re: MBR rootkit

#6 Příspěvek od Sentello »

2010-11-15 21:32:27 ----A---- C:\WINDOWS\system32\XAPOFX1_3.dll
2010-11-15 21:32:26 ----A---- C:\WINDOWS\system32\xactengine3_4.dll
2010-11-15 21:32:25 ----A---- C:\WINDOWS\system32\X3DAudio1_6.dll
2010-11-15 21:32:24 ----A---- C:\WINDOWS\system32\d3dx10_40.dll
2010-11-15 21:32:24 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll
2010-11-15 21:32:23 ----A---- C:\WINDOWS\system32\D3DX9_40.dll
2010-11-15 21:32:20 ----A---- C:\WINDOWS\system32\XAudio2_3.dll
2010-11-15 21:32:20 ----A---- C:\WINDOWS\system32\XAPOFX1_2.dll
2010-11-15 21:32:19 ----A---- C:\WINDOWS\system32\xactengine3_3.dll
2010-11-15 21:32:19 ----A---- C:\WINDOWS\system32\X3DAudio1_5.dll
2010-11-15 21:32:17 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2010-11-15 21:32:17 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2010-11-15 21:32:17 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
2010-11-15 21:32:16 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2010-11-15 21:32:16 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2010-11-15 21:32:15 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
2010-11-15 21:32:15 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
2010-11-15 21:32:15 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2010-11-15 21:32:14 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
2010-11-15 21:32:14 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
2010-11-15 21:32:13 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
2010-11-15 21:32:13 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
2010-11-15 21:32:12 ----A---- C:\WINDOWS\system32\XAudio2_0.dll
2010-11-15 21:32:12 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
2010-11-15 21:32:10 ----A---- C:\WINDOWS\system32\xactengine3_0.dll
2010-11-15 21:32:10 ----A---- C:\WINDOWS\system32\X3DAudio1_3.dll
2010-11-15 21:32:08 ----A---- C:\WINDOWS\system32\d3dx10_37.dll
2010-11-15 21:32:08 ----A---- C:\WINDOWS\system32\D3DCompiler_37.dll
2010-11-15 21:32:07 ----A---- C:\WINDOWS\system32\D3DX9_37.dll
2010-11-15 21:32:06 ----A---- C:\WINDOWS\system32\xactengine2_10.dll
2010-11-15 21:32:04 ----A---- C:\WINDOWS\system32\d3dx9_36.dll
2010-11-15 21:32:04 ----A---- C:\WINDOWS\system32\d3dx10_36.dll
2010-11-15 21:32:04 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll
2010-11-15 21:32:03 ----A---- C:\WINDOWS\system32\xactengine2_9.dll
2010-11-15 21:32:02 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
2010-11-15 21:32:02 ----A---- C:\WINDOWS\system32\d3dx10_35.dll
2010-11-15 21:32:02 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll
2010-11-15 21:32:01 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
2010-11-15 21:32:01 ----A---- C:\WINDOWS\system32\X3DAudio1_2.dll
2010-11-15 21:32:00 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2010-11-15 21:32:00 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2010-11-15 21:32:00 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2010-11-15 21:31:59 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2010-11-15 21:31:58 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
2010-11-15 21:31:57 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2010-11-15 21:31:57 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2010-11-15 21:31:55 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2010-11-15 21:31:54 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2010-11-15 21:31:54 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
2010-11-15 21:31:53 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
2010-11-15 21:31:52 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2010-11-15 21:31:52 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
2010-11-15 21:31:52 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2010-11-15 21:31:52 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2010-11-15 21:31:51 ----A---- C:\WINDOWS\system32\xinput1_2.dll
2010-11-15 21:31:51 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2010-11-15 21:31:51 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2010-11-15 21:31:50 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2010-11-15 21:31:50 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2010-11-15 21:31:49 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2010-11-15 21:31:49 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2010-11-15 21:31:49 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2010-11-15 21:31:48 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2010-11-15 21:31:47 ----A---- C:\WINDOWS\system32\xinput9_1_0.dll
2010-11-15 21:31:46 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2010-11-15 21:31:45 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2010-11-15 21:31:43 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2010-11-15 21:31:43 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2010-11-15 21:31:36 ----A---- C:\WINDOWS\system32\drivers\ewusbnet.sys
2010-11-15 21:31:36 ----A---- C:\WINDOWS\system32\drivers\ewusbmdm.sys
2010-11-15 21:31:36 ----A---- C:\WINDOWS\system32\drivers\ewusbdev.sys
2010-11-15 21:31:36 ----A---- C:\WINDOWS\system32\drivers\ewdcsc.sys
2010-11-15 21:30:21 ----D---- C:\Program Files\O2
2010-11-15 17:56:04 ----A---- C:\WINDOWS\imsins.BAK
2010-11-15 16:53:55 ----D---- C:\Documents and Settings\Sentello\Application Data\Macromedia
2010-11-15 16:53:55 ----D---- C:\Documents and Settings\Sentello\Application Data\Adobe
2010-11-15 16:07:42 ----D---- C:\Documents and Settings\Sentello\Application Data\AIMP
2010-11-15 16:07:34 ----D---- C:\Program Files\AIMP2
2010-11-15 16:04:53 ----D---- C:\Documents and Settings\Sentello\Application Data\Skype
2010-11-15 15:33:36 ----A---- C:\WINDOWS\system32\uxtuneup.dll
2010-11-15 15:33:25 ----D---- C:\Program Files\TuneUp Utilities 2007
2010-11-15 15:33:25 ----D---- C:\Documents and Settings\Sentello\Application Data\TuneUp Software
2010-11-15 15:33:05 ----D---- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2010-11-15 15:33:03 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-11-15 15:27:13 ----D---- C:\Program Files\The KMPlayer
2010-11-15 14:33:10 ----D---- C:\WINDOWS\Logs
2010-11-15 14:31:37 ----A---- C:\WINDOWS\system32\kbdbph.dll
2010-11-15 14:26:59 ----D---- C:\Documents and Settings\Sentello\Application Data\ESET
2010-11-15 14:25:37 ----D---- C:\Program Files\ESET
2010-11-15 14:25:37 ----D---- C:\Documents and Settings\All Users\Application Data\ESET
2010-11-14 22:41:29 ----D---- C:\Documents and Settings\Sentello\Application Data\Foxit
2010-11-14 22:41:19 ----D---- C:\Program Files\Foxit Software
2010-11-14 22:40:06 ----D---- C:\Program Files\MSECache
2010-11-14 22:39:49 ----D---- C:\Documents and Settings\Sentello\Application Data\WinRAR
2010-11-14 22:39:10 ----D---- C:\Program Files\WinRAR
2010-11-14 22:38:30 ----A---- C:\WINDOWS\ODBC.INI
2010-11-14 22:38:26 ----A---- C:\WINDOWS\system32\mdimon.dll
2010-11-14 22:37:55 ----D---- C:\Program Files\Common Files\DESIGNER
2010-11-14 22:37:38 ----D---- C:\WINDOWS\SHELLNEW
2010-11-14 22:37:37 ----D---- C:\Program Files\Microsoft Office
2010-11-14 22:35:00 ----D---- C:\Program Files\DAEMON Tools
2010-11-14 22:35:00 ----A---- C:\WINDOWS\system32\drivers\dtscsi.sys
2010-11-14 22:32:48 ----A---- C:\WINDOWS\system32\drivers\sptd9341.sys
2010-11-14 22:32:48 ----A---- C:\WINDOWS\system32\drivers\sptd.sys
2010-11-14 20:22:36 ----A---- C:\WINDOWS\system32\drivers\usbprint.sys
2010-11-14 20:22:22 ----A---- C:\WINDOWS\system32\drivers\usbscan.sys
2010-11-14 20:12:09 ----D---- C:\Program Files\Common Files\CANON
2010-11-14 20:09:18 ----HD---- C:\Documents and Settings\All Users\Application Data\CanonBJ
2010-11-14 20:09:08 ----A---- C:\WINDOWS\system32\CNMLM9C.DLL
2010-11-14 20:09:07 ----D---- C:\Documents and Settings\Sentello\Application Data\Radmin
2010-11-14 20:09:05 ----HD---- C:\WINDOWS\system32\CanonIJ Uninstaller Information
2010-11-14 20:08:54 ----A---- C:\WINDOWS\system32\CNC630O.DLL
2010-11-14 20:08:54 ----A---- C:\WINDOWS\system32\CNC630L.DLL
2010-11-14 20:08:54 ----A---- C:\WINDOWS\system32\CNC630I.DLL
2010-11-14 20:08:53 ----A---- C:\WINDOWS\system32\CNC630C.DLL
2010-11-14 20:08:43 ----HD---- C:\Program Files\CanonBJ
2010-11-14 20:07:10 ----D---- C:\Program Files\Canon
2010-11-14 20:02:09 ----A---- C:\WINDOWS\system32\drivers\USBSTOR.SYS
2010-11-14 19:11:05 ----D---- C:\Documents and Settings\Sentello\Application Data\GHISLER
2010-11-14 19:02:07 ----A---- C:\WINDOWS\system32\h323log.txt
2010-11-14 18:59:37 ----A---- C:\WINDOWS\system32\wpa.bak
2010-11-14 18:58:37 ----A---- C:\WINDOWS\system32\drivers\audstub.sys
2010-11-14 18:58:23 ----A---- C:\WINDOWS\system32\hidserv.dll
2010-11-14 18:57:55 ----A---- C:\WINDOWS\system32\drivers\redbook.sys
2010-11-14 18:57:04 ----A---- C:\WINDOWS\system32\drivers\fetnd5.sys
2010-11-14 18:56:59 ----A---- C:\WINDOWS\system32\usbui.dll
2010-11-14 18:56:50 ----A---- C:\WINDOWS\system32\drivers\UAGP35.SYS
2010-11-14 18:56:40 ----A---- C:\WINDOWS\system32\drivers\compbatt.sys
2010-11-14 18:56:39 ----A---- C:\WINDOWS\system32\drivers\CmBatt.sys
2010-11-14 18:56:39 ----A---- C:\WINDOWS\system32\drivers\battc.sys
2010-11-14 18:55:33 ----SHD---- C:\WINDOWS\Installer
2010-11-14 18:55:33 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-11-14 18:55:32 ----D---- C:\Program Files\Common Files\ODBC
2010-11-14 18:55:32 ----A---- C:\WINDOWS\ODBCINST.INI
2010-11-14 18:55:29 ----D---- C:\Program Files\Common Files\SpeechEngines
2010-11-14 18:55:28 ----RD---- C:\Program Files
2010-11-14 18:55:28 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-11-14 18:55:28 ----D---- C:\Program Files\Common Files
2010-11-14 18:55:25 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2010-11-14 18:55:25 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2010-11-14 18:55:25 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2010-11-14 18:55:24 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2010-11-14 18:55:24 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2010-11-14 18:55:24 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2010-11-14 18:55:24 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2010-11-14 18:55:24 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2010-11-14 18:55:24 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2010-11-14 18:55:23 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2010-11-14 18:55:23 ----RA---- C:\WINDOWS\system32\kbdur.dll
2010-11-14 18:55:23 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2010-11-14 18:55:23 ----RA---- C:\WINDOWS\system32\kbdru.dll
2010-11-14 18:55:23 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2010-11-14 18:55:23 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2010-11-14 18:55:22 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2010-11-14 18:55:22 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2010-11-14 18:55:22 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2010-11-14 18:55:22 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2010-11-14 18:55:22 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2010-11-14 18:55:22 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2010-11-14 18:55:22 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2010-11-14 18:55:20 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2010-11-14 18:55:20 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2010-11-14 18:55:20 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2010-11-14 18:55:20 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2010-11-14 18:55:20 ----RA---- C:\WINDOWS\system32\kbdest.dll
2010-11-14 18:55:19 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2010-11-14 18:55:19 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2010-11-14 18:55:19 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2010-11-14 18:55:19 ----RA---- C:\WINDOWS\system32\kbdro.dll
2010-11-14 18:55:19 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2010-11-14 18:55:19 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2010-11-14 18:55:19 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2010-11-14 18:55:19 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2010-11-14 18:55:19 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
2010-11-14 18:55:19 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
2010-11-14 18:55:19 ----RA---- C:\WINDOWS\system32\kbdcz.dll
2010-11-14 18:55:19 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2010-11-14 18:55:19 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2010-11-14 18:55:16 ----A---- C:\WINDOWS\system32\spxcoins.dll
2010-11-14 18:55:16 ----A---- C:\WINDOWS\system32\irclass.dll
2010-11-14 18:55:16 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2010-11-14 18:55:16 ----A---- C:\WINDOWS\system32\dgsetup.dll
2010-11-14 18:55:16 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2010-11-14 18:55:14 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2010-11-14 18:55:14 ----A---- C:\WINDOWS\TASKMAN.EXE
2010-11-14 18:55:13 ----A---- C:\WINDOWS\system32\drivers\irenum.sys
2010-11-14 18:55:13 ----A---- C:\WINDOWS\system32\batt.dll
2010-11-14 18:55:13 ----A---- C:\WINDOWS\NOTEPAD.EXE
2010-11-14 18:55:12 ----A---- C:\WINDOWS\system32\storprop.dll
2010-11-14 18:55:01 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
2010-11-14 18:54:57 ----RA---- C:\WINDOWS\SET8.tmp
2010-11-14 18:54:54 ----RA---- C:\WINDOWS\SET4.tmp
2010-11-14 18:54:53 ----RA---- C:\WINDOWS\SET3.tmp
2010-11-14 18:54:46 ----D---- C:\WINDOWS\system32\CatRoot2
2010-11-14 18:54:46 ----D---- C:\WINDOWS\system32\CatRoot
2010-11-14 18:54:40 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2010-11-14 18:54:14 ----D---- C:\Documents and Settings
2010-11-14 18:54:13 ----SHD---- C:\System Volume Information
2010-11-14 18:53:37 ----H---- C:\boot.ini
2010-11-14 18:52:41 ----A---- C:\WINDOWS\system32\SynTPFcs.dll
2010-11-14 18:52:41 ----A---- C:\WINDOWS\system32\SynTPCo2.dll
2010-11-14 18:52:41 ----A---- C:\WINDOWS\system32\SynTPAPI.dll
2010-11-14 18:52:41 ----A---- C:\WINDOWS\system32\SynCtrl.dll
2010-11-14 18:52:41 ----A---- C:\WINDOWS\system32\SynCOM.dll
2010-11-14 18:52:41 ----A---- C:\WINDOWS\system32\drivers\SynTP.sys
2010-11-14 18:52:40 ----D---- C:\Program Files\Synaptics
2010-11-14 18:52:25 ----A---- C:\WINDOWS\system32\drivers\MODEMCSA.sys
2010-11-14 18:52:24 ----A---- C:\WINDOWS\system32\csamsp.dll
2010-11-14 18:52:23 ----A---- C:\WINDOWS\system32\SLMOHServ.dll
2010-11-14 18:52:23 ----A---- C:\WINDOWS\system32\slmh.exe
2010-11-14 18:52:23 ----A---- C:\WINDOWS\system32\SLLights.dll
2010-11-14 18:52:23 ----A---- C:\WINDOWS\system32\minirec.exe
2010-11-14 18:52:23 ----A---- C:\WINDOWS\system32\drivers\winddx.sys
2010-11-14 18:52:23 ----A---- C:\WINDOWS\system32\amr_cpl.dll
2010-11-14 18:52:23 ----A---- C:\WINDOWS\SmCfg.exe
2010-11-14 18:52:17 ----D---- C:\WINDOWS\system32\drivers\SLDRV
2010-11-14 18:52:11 ----D---- C:\WINDOWS\Modio
2010-11-14 18:52:01 ----A---- C:\WINDOWS\system32\drivers\splitter.sys
2010-11-14 18:51:59 ----A---- C:\WINDOWS\system32\drivers\wdmaud.sys
2010-11-14 18:51:57 ----A---- C:\WINDOWS\system32\drivers\DMusic.sys
2010-11-14 18:51:55 ----A---- C:\WINDOWS\system32\drivers\swmidi.sys
2010-11-14 18:51:53 ----A---- C:\WINDOWS\system32\drivers\aec.sys
2010-11-14 18:51:52 ----A---- C:\WINDOWS\system32\drivers\kmixer.sys
2010-11-14 18:51:50 ----A---- C:\WINDOWS\system32\drivers\drmkaud.sys
2010-11-14 18:51:48 ----A---- C:\WINDOWS\system32\drivers\sysaudio.sys
2010-11-14 18:51:47 ----A---- C:\WINDOWS\system32\drivers\MSKSSRV.sys
2010-11-14 18:51:44 ----A---- C:\WINDOWS\system32\drivers\MSPQM.sys
2010-11-14 18:51:42 ----A---- C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2010-11-14 18:51:29 ----A---- C:\WINDOWS\system32\ksuser.dll
2010-11-14 18:51:29 ----A---- C:\WINDOWS\system32\drivers\portcls.sys
2010-11-14 18:51:29 ----A---- C:\WINDOWS\system32\drivers\drmk.sys
2010-11-14 18:51:20 ----D---- C:\Program Files\Realtek AC97
2010-11-14 18:51:17 ----A---- C:\WINDOWS\system32\RTLCPAPI.dll
2010-11-14 18:51:17 ----A---- C:\WINDOWS\system32\drivers\ALCXWDM.SYS
2010-11-14 18:51:17 ----A---- C:\WINDOWS\system32\ChCfg.exe
2010-11-14 18:51:17 ----A---- C:\WINDOWS\SOUNDMAN.EXE
2010-11-14 18:51:16 ----A---- C:\WINDOWS\system32\RTLCPL.EXE
2010-11-14 18:51:15 ----A---- C:\WINDOWS\alcupd.exe
2010-11-14 18:51:15 ----A---- C:\WINDOWS\alcrmv.exe
2010-11-14 18:50:36 ----D---- C:\Program Files\S3
2010-11-14 18:50:15 ----HD---- C:\Program Files\InstallShield Installation Information
2010-11-14 18:49:55 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-11-14 18:49:49 ----D---- C:\Program Files\VIA
2010-11-14 18:49:43 ----D---- C:\Program Files\Common Files\InstallShield
2010-11-14 18:49:36 ----A---- C:\WINDOWS\system32\VTTrayp.exe
2010-11-14 18:49:36 ----A---- C:\WINDOWS\system32\drivers\ar5211.sys
2010-11-14 18:49:35 ----A---- C:\WINDOWS\system32\VTTimer.exe
2010-11-14 18:49:35 ----A---- C:\WINDOWS\system32\VTovrlay.dll
2010-11-14 18:49:35 ----A---- C:\WINDOWS\system32\VTInfo2.dll
2010-11-14 18:49:35 ----A---- C:\WINDOWS\system32\vticd.dll
2010-11-14 18:49:35 ----A---- C:\WINDOWS\system32\drivers\vtmini.sys
2010-11-14 18:49:34 ----A---- C:\WINDOWS\system32\VTGamma2.dll
2010-11-14 18:49:34 ----A---- C:\WINDOWS\system32\VTDisply.dll
2010-11-14 18:49:34 ----A---- C:\WINDOWS\system32\vtdisp.dll
2010-11-14 18:49:33 ----A---- C:\WINDOWS\system32\VTCfg3d.dll
2010-11-14 18:49:33 ----A---- C:\WINDOWS\system32\VModes.exe
2010-11-14 18:49:32 ----A---- C:\WINDOWS\system32\slmdmsr.exe
2010-11-14 18:49:32 ----A---- C:\WINDOWS\system32\slmdmsp.dll
2010-11-14 18:49:32 ----A---- C:\WINDOWS\system32\slmdmgx.dll
2010-11-14 18:49:32 ----A---- C:\WINDOWS\system32\slmdmco.dll
2010-11-14 18:49:28 ----A---- C:\WINDOWS\system32\vuins32.dll
2010-11-14 18:49:28 ----A---- C:\WINDOWS\system32\drivers\fetnd5bv.sys
2010-11-14 18:49:02 ----D---- C:\fsc.tmp
2010-11-14 18:49:01 ----A---- C:\FSC-DeskUpdate.txt
2010-11-14 18:47:23 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-11-14 18:47:23 ----RSD---- C:\WINDOWS\Fonts
2010-11-14 18:47:23 ----RD---- C:\WINDOWS\Web
2010-11-14 18:47:23 ----HD---- C:\WINDOWS\inf
2010-11-14 18:47:23 ----D---- C:\WINDOWS\WinSxS
2010-11-14 18:47:23 ----D---- C:\WINDOWS\twain_32
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system32\wins
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system32\wbem
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system32\usmt
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system32\spool
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system32\ShellExt
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system32\Setup
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system32\scripting
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system32\ras
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system32\oobe
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system32\npp
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system32\mui
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system32\inetsrv
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system32\IME
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system32\icsxml
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system32\ias
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system32\export
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system32\en
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system32\drivers\etc
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system32\drivers\disdn
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system32\drivers
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system32\dhcp
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system32\config
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system32\3com_dmi
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system32\3076
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system32\2052
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system32\1054
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system32\1042
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system32\1041
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system32\1037
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system32\1033
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system32\1031
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system32\1028
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system32\1025
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system32
2010-11-14 18:47:23 ----D---- C:\WINDOWS\system
2010-11-14 18:47:23 ----D---- C:\WINDOWS\security
2010-11-14 18:47:23 ----D---- C:\WINDOWS\Resources
2010-11-14 18:47:23 ----D---- C:\WINDOWS\repair
2010-11-14 18:47:23 ----D---- C:\WINDOWS\Provisioning
2010-11-14 18:47:23 ----D---- C:\WINDOWS\PeerNet
2010-11-14 18:47:23 ----D---- C:\WINDOWS\pchealth
2010-11-14 18:47:23 ----D---- C:\WINDOWS\Network Diagnostic
2010-11-14 18:47:23 ----D---- C:\WINDOWS\mui
2010-11-14 18:47:23 ----D---- C:\WINDOWS\msapps
2010-11-14 18:47:23 ----D---- C:\WINDOWS\msagent
2010-11-14 18:47:23 ----D---- C:\WINDOWS\Media
2010-11-14 18:47:23 ----D---- C:\WINDOWS\L2Schemas
2010-11-14 18:47:23 ----D---- C:\WINDOWS\java
2010-11-14 18:47:23 ----D---- C:\WINDOWS\ime
2010-11-14 18:47:23 ----D---- C:\WINDOWS\Help
2010-11-14 18:47:23 ----D---- C:\WINDOWS\ehome
2010-11-14 18:47:23 ----D---- C:\WINDOWS\Driver Cache
2010-11-14 18:47:23 ----D---- C:\WINDOWS\Debug
2010-11-14 18:47:23 ----D---- C:\WINDOWS\Cursors
2010-11-14 18:47:23 ----D---- C:\WINDOWS\Connection Wizard
2010-11-14 18:47:23 ----D---- C:\WINDOWS\Config
2010-11-14 18:47:23 ----D---- C:\WINDOWS\AppPatch
2010-11-14 18:47:23 ----D---- C:\WINDOWS\addins
2010-11-14 18:47:23 ----D---- C:\WINDOWS
2010-11-14 18:17:13 ----D---- C:\Documents and Settings\Sentello\Application Data\Identities
2010-11-14 18:17:02 ----ASH---- C:\Documents and Settings\Sentello\Application Data\desktop.ini
2010-11-14 18:17:01 ----SD---- C:\Documents and Settings\Sentello\Application Data\Microsoft
2010-11-14 18:16:13 ----D---- C:\WINDOWS\SoftwareDistribution
2010-11-14 18:16:12 ----D---- C:\WINDOWS\Prefetch
2010-11-14 18:16:11 ----SD---- C:\WINDOWS\system32\Microsoft
2010-11-14 18:16:11 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-11-14 18:12:40 ----D---- C:\WINDOWS\system32\xircom
2010-11-14 18:12:40 ----D---- C:\Program Files\xerox
2010-11-14 18:12:40 ----D---- C:\Program Files\microsoft frontpage
2010-11-14 18:12:14 ----RASH---- C:\MSDOS.SYS
2010-11-14 18:12:14 ----RASH---- C:\IO.SYS
2010-11-14 18:12:14 ----A---- C:\WINDOWS\control.ini
2010-11-14 18:12:14 ----A---- C:\CONFIG.SYS
2010-11-14 18:11:58 ----A---- C:\WINDOWS\OEWABLog.txt
2010-11-14 18:11:52 ----A---- C:\WINDOWS\system32\mapi32.dll
2010-11-14 18:10:54 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-11-14 18:10:54 ----RD---- C:\WINDOWS\Offline Web Pages
2010-11-14 18:10:54 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2010-11-14 18:10:47 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2010-11-14 18:10:19 ----D---- C:\WINDOWS\system32\DirectX
2010-11-14 18:10:14 ----A---- C:\WINDOWS\system32\atrace.dll
2010-11-14 18:10:11 ----A---- C:\WINDOWS\system32\desktop.ini
2010-11-14 18:10:11 ----A---- C:\WINDOWS\desktop.ini
2010-11-14 18:10:05 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2010-11-14 18:10:04 ----A---- C:\WINDOWS\system32\acctres.dll
2010-11-14 18:10:03 ----D---- C:\Program Files\Common Files\Services
2010-11-14 18:10:01 ----SD---- C:\WINDOWS\Tasks
2010-11-14 18:10:01 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2010-11-14 18:10:00 ----D---- C:\Program Files\Common Files\MSSoap
2010-11-14 18:09:56 ----D---- C:\WINDOWS\srchasst
2010-11-14 18:09:55 ----D---- C:\WINDOWS\system32\Macromed
2010-11-14 18:09:53 ----A---- C:\WINDOWS\system32\wuweb.dll
2010-11-14 18:09:53 ----A---- C:\WINDOWS\system32\wucltui.dll
2010-11-14 18:09:53 ----A---- C:\WINDOWS\system32\wuauserv.dll
2010-11-14 18:09:53 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2010-11-14 18:09:52 ----A---- C:\WINDOWS\system32\wups.dll
2010-11-14 18:09:52 ----A---- C:\WINDOWS\system32\wuaueng.dll
2010-11-14 18:09:52 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2010-11-14 18:09:52 ----A---- C:\WINDOWS\system32\wuauclt.exe
2010-11-14 18:09:52 ----A---- C:\WINDOWS\system32\wuapi.dll
2010-11-14 18:09:52 ----A---- C:\WINDOWS\system32\bitsprx4.dll
2010-11-14 18:09:52 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2010-11-14 18:09:52 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2010-11-14 18:09:51 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2010-11-14 18:09:51 ----A---- C:\WINDOWS\system32\qmgr.dll
2010-11-14 18:09:48 ----D---- C:\Program Files\Movie Maker
2010-11-14 18:09:32 ----A---- C:\WINDOWS\system32\safrslv.dll
2010-11-14 18:09:32 ----A---- C:\WINDOWS\system32\safrdm.dll
2010-11-14 18:09:32 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2010-11-14 18:09:32 ----A---- C:\WINDOWS\system32\racpldlg.dll
2010-11-14 18:09:29 ----A---- C:\WINDOWS\system32\fltMc.exe
2010-11-14 18:09:29 ----A---- C:\WINDOWS\system32\fltlib.dll
2010-11-14 18:09:29 ----A---- C:\WINDOWS\system32\drivers\fltMgr.sys
2010-11-14 18:09:28 ----D---- C:\WINDOWS\system32\Restore
2010-11-14 18:09:28 ----A---- C:\WINDOWS\system32\srsvc.dll
2010-11-14 18:09:28 ----A---- C:\WINDOWS\system32\srrstr.dll
2010-11-14 18:09:28 ----A---- C:\WINDOWS\system32\srclient.dll
2010-11-14 18:09:28 ----A---- C:\WINDOWS\system32\drivers\sr.sys
2010-11-14 18:09:27 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2010-11-14 18:09:27 ----A---- C:\WINDOWS\system32\msconf.dll
2010-11-14 18:09:27 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2010-11-14 18:09:27 ----A---- C:\WINDOWS\system32\mnmdd.dll
2010-11-14 18:09:27 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2010-11-14 18:09:27 ----A---- C:\WINDOWS\system32\ils.dll
2010-11-14 18:09:24 ----D---- C:\Program Files\NetMeeting
2010-11-14 18:09:24 ----A---- C:\WINDOWS\system32\msoert2.dll
2010-11-14 18:09:24 ----A---- C:\WINDOWS\system32\msoeacct.dll
2010-11-14 18:09:23 ----A---- C:\WINDOWS\system32\inetres.dll
2010-11-14 18:09:23 ----A---- C:\WINDOWS\system32\inetcomm.dll
2010-11-14 18:09:21 ----D---- C:\Program Files\Outlook Express
2010-11-14 18:09:21 ----A---- C:\WINDOWS\system32\schedsvc.dll
2010-11-14 18:09:21 ----A---- C:\WINDOWS\system32\mstinit.exe
2010-11-14 18:09:21 ----A---- C:\WINDOWS\system32\mstask.dll
2010-11-14 18:09:21 ----A---- C:\WINDOWS\system32\isign32.dll
2010-11-14 18:09:21 ----A---- C:\WINDOWS\system32\inetcfg.dll
2010-11-14 18:09:21 ----A---- C:\WINDOWS\system32\icwphbk.dll
2010-11-14 18:09:21 ----A---- C:\WINDOWS\system32\icwdial.dll
2010-11-14 18:09:16 ----D---- C:\Program Files\Common Files\System
2010-11-14 18:09:10 ----D---- C:\Program Files\Internet Explorer
2010-11-14 18:08:23 ----A---- C:\WINDOWS\vbaddin.ini
2010-11-14 18:08:23 ----A---- C:\WINDOWS\vb.ini
2010-11-14 18:08:16 ----D---- C:\WINDOWS\Registration
2010-11-14 18:08:06 ----D---- C:\Program Files\Online Services
2010-11-14 18:08:05 ----D---- C:\Program Files\Windows Media Player
2010-11-14 18:07:55 ----D---- C:\Program Files\Messenger
2010-11-14 18:07:51 ----D---- C:\Program Files\MSN Gaming Zone
2010-11-14 18:07:51 ----A---- C:\WINDOWS\system32\write.exe
2010-11-14 18:07:43 ----A---- C:\WINDOWS\system32\sndvol32.exe
2010-11-14 18:07:43 ----A---- C:\WINDOWS\system32\hticons.dll
2010-11-14 18:07:43 ----A---- C:\WINDOWS\system32\avwav.dll
2010-11-14 18:07:43 ----A---- C:\WINDOWS\system32\avtapi.dll
2010-11-14 18:07:43 ----A---- C:\WINDOWS\system32\avmeter.dll
2010-11-14 18:07:42 ----A---- C:\WINDOWS\system32\winchat.exe
2010-11-14 18:07:36 ----A---- C:\WINDOWS\system32\sol.exe
2010-11-14 18:07:36 ----A---- C:\WINDOWS\system32\getuname.dll
2010-11-14 18:07:36 ----A---- C:\WINDOWS\system32\charmap.exe
2010-11-14 18:07:36 ----A---- C:\WINDOWS\system32\calc.exe
2010-11-14 18:07:35 ----A---- C:\WINDOWS\system32\winmine.exe
2010-11-14 18:07:35 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2010-11-14 18:07:35 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2010-11-14 18:07:35 ----A---- C:\WINDOWS\system32\tslabels.ini
2010-11-14 18:07:35 ----A---- C:\WINDOWS\system32\tskill.exe
2010-11-14 18:07:35 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2010-11-14 18:07:35 ----A---- C:\WINDOWS\system32\tscon.exe
2010-11-14 18:07:35 ----A---- C:\WINDOWS\system32\reset.exe
2010-11-14 18:07:35 ----A---- C:\WINDOWS\system32\mshearts.exe
2010-11-14 18:07:35 ----A---- C:\WINDOWS\system32\freecell.exe
2010-11-14 18:07:34 ----A---- C:\WINDOWS\system32\shadow.exe
2010-11-14 18:07:34 ----A---- C:\WINDOWS\system32\rwinsta.exe
2010-11-14 18:07:34 ----A---- C:\WINDOWS\system32\regini.exe
2010-11-14 18:07:34 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2010-11-14 18:07:34 ----A---- C:\WINDOWS\system32\qwinsta.exe
2010-11-14 18:07:34 ----A---- C:\WINDOWS\system32\qappsrv.exe
2010-11-14 18:07:34 ----A---- C:\WINDOWS\system32\msg.exe
2010-11-14 18:07:34 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2010-11-14 18:07:34 ----A---- C:\WINDOWS\system32\logoff.exe
2010-11-14 18:07:34 ----A---- C:\WINDOWS\system32\cdmodem.dll
2010-11-14 18:07:28 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2010-11-14 18:07:19 ----D---- C:\Program Files\MSN
2010-11-14 18:07:18 ----A---- C:\WINDOWS\system32\accwiz.exe
2010-11-14 18:07:17 ----D---- C:\Program Files\Windows NT
2010-11-14 18:07:17 ----A---- C:\WINDOWS\system32\sndrec32.exe
2010-11-14 18:07:17 ----A---- C:\WINDOWS\system32\mspaint.exe
2010-11-14 18:07:17 ----A---- C:\WINDOWS\system32\mplay32.exe
2010-11-14 18:07:17 ----A---- C:\WINDOWS\system32\hypertrm.dll
2010-11-14 18:07:16 ----D---- C:\WINDOWS\system32\en-US
2010-11-14 18:07:16 ----A---- C:\WINDOWS\system32\spider.exe
2010-11-14 18:07:16 ----A---- C:\WINDOWS\system32\clipbrd.exe
2010-11-14 18:07:15 ----A---- C:\WINDOWS\system32\tsgqec.dll
2010-11-14 18:07:15 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2010-11-14 18:07:15 ----A---- C:\WINDOWS\system32\rhttpaa.dll
2010-11-14 18:07:15 ----A---- C:\WINDOWS\system32\drivers\tdtcp.sys
2010-11-14 18:07:15 ----A---- C:\WINDOWS\system32\drivers\tdpipe.sys
2010-11-14 18:07:15 ----A---- C:\WINDOWS\system32\drivers\rdpwd.sys
2010-11-14 18:07:15 ----A---- C:\WINDOWS\system32\aaclient.dll
2010-11-14 18:07:14 ----A---- C:\WINDOWS\system32\remotepg.dll
2010-11-14 18:07:14 ----A---- C:\WINDOWS\system32\rdshost.exe
2010-11-14 18:07:14 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2010-11-14 18:07:14 ----A---- C:\WINDOWS\system32\mstscax.dll
2010-11-14 18:07:14 ----A---- C:\WINDOWS\system32\mstsc.exe
2010-11-14 18:07:13 ----A---- C:\WINDOWS\system32\termsrv.dll
2010-11-14 18:07:13 ----A---- C:\WINDOWS\system32\sessmgr.exe
2010-11-14 18:07:13 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2010-11-14 18:07:13 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2010-11-14 18:07:13 ----A---- C:\WINDOWS\system32\rdpclip.exe
2010-11-14 18:07:13 ----A---- C:\WINDOWS\system32\rdchost.dll
2010-11-14 18:07:13 ----A---- C:\WINDOWS\system32\qprocess.exe
2010-11-14 18:07:13 ----A---- C:\WINDOWS\system32\icaapi.dll
2010-11-14 18:07:13 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2010-11-14 18:07:12 ----D---- C:\WINDOWS\system32\MsDtc
2010-11-14 18:07:12 ----A---- C:\WINDOWS\system32\xolehlp.dll
2010-11-14 18:07:12 ----A---- C:\WINDOWS\system32\mtxoci.dll
2010-11-14 18:07:12 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2010-11-14 18:07:12 ----A---- C:\WINDOWS\system32\msdtctm.dll
2010-11-14 18:07:12 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2010-11-14 18:07:12 ----A---- C:\WINDOWS\system32\msdtclog.dll
2010-11-14 18:07:12 ----A---- C:\WINDOWS\system32\msdtc.exe
2010-11-14 18:07:11 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2010-11-14 18:07:11 ----A---- C:\WINDOWS\system32\mtxex.dll
2010-11-14 18:07:11 ----A---- C:\WINDOWS\system32\mtxdm.dll
2010-11-14 18:07:11 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2010-11-14 18:07:10 ----D---- C:\WINDOWS\system32\Com
2010-11-14 18:07:10 ----A---- C:\WINDOWS\system32\stclient.dll
2010-11-14 18:07:10 ----A---- C:\WINDOWS\system32\comrepl.dll
2010-11-14 18:07:10 ----A---- C:\WINDOWS\system32\comaddin.dll
2010-11-14 18:07:10 ----A---- C:\WINDOWS\system32\colbact.dll
2010-11-14 18:07:10 ----A---- C:\WINDOWS\system32\clbcatex.dll
2010-11-14 18:07:10 ----A---- C:\WINDOWS\system32\catsrvps.dll
2010-11-14 18:07:09 ----A---- C:\WINDOWS\system32\comuid.dll
2010-11-14 18:07:09 ----A---- C:\WINDOWS\system32\comsvcs.dll
2010-11-14 18:07:09 ----A---- C:\WINDOWS\system32\comsnap.dll
2010-11-14 18:07:09 ----A---- C:\WINDOWS\system32\catsrvut.dll
2010-11-14 18:07:09 ----A---- C:\WINDOWS\system32\catsrv.dll
2010-11-14 18:07:08 ----A---- C:\WINDOWS\system32\clbcatq.dll
2010-11-14 18:07:03 ----A---- C:\WINDOWS\system32\servdeps.dll
2010-11-14 18:07:03 ----A---- C:\WINDOWS\system32\mmfutil.dll
2010-11-14 18:07:03 ----A---- C:\WINDOWS\system32\licwmi.dll
2010-11-14 18:07:03 ----A---- C:\WINDOWS\system32\cmprops.dll
2010-11-14 18:06:57 ----A---- C:\WINDOWS\system32\drivers\termdd.sys
2010-11-14 18:06:57 ----A---- C:\WINDOWS\system32\drivers\rdpdr.sys

======List of files/folders modified in the last 1 months======

2010-11-28 11:47:40 ----A---- C:\WINDOWS\win.ini
2010-11-27 15:40:38 ----A---- C:\WINDOWS\system.ini
2010-11-14 18:11:40 ----ASH---- C:\WINDOWS\fonts\desktop.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 RecAgent;RecAgent; C:\WINDOWS\system32\DRIVERS\SLDRV\RecAgent.sys [2005-05-10 14680]
R0 snapman;Acronis Snapshots Manager; C:\WINDOWS\system32\DRIVERS\snapman.sys [2010-11-24 166272]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-11-14 664064]
R0 tdrpman258;Acronis Try&Decide and Restore Points filter (build 258); C:\WINDOWS\system32\DRIVERS\tdrpm258.sys [2010-11-24 911680]
R0 timounter;Acronis Backup Archive Explorer; C:\WINDOWS\system32\DRIVERS\timntr.sys [2010-11-24 581984]
R0 uagp35;Microsoft AGPv3.5 Filter; C:\WINDOWS\system32\DRIVERS\uagp35.sys [2008-04-14 44672]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2010-07-29 115008]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2010-08-03 55256]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 36352]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 tidnet;TID NDIS Protocol Driver; C:\WINDOWS\system32\DRIVERS\tidnet.sys [2009-09-15 19200]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2010-08-04 140752]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2010-07-29 134512]
R3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2006-11-10 18688]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-08-19 3644800]
R3 dtscsi;dtscsi; C:\WINDOWS\System32\Drivers\dtscsi.sys [2010-11-14 223128]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2010-07-29 32608]
R3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2010-06-25 47104]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2008-04-17 15464]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys [2009-12-15 102528]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-04-14 12160]
R3 Mtlmnt5;Mtlmnt5; C:\WINDOWS\system32\DRIVERS\SLDRV\Mtlmnt5.sys [2005-05-10 237616]
R3 Slntamr;SmartLink AMR_PCI Driver; C:\WINDOWS\system32\DRIVERS\SLDRV\slntamr.sys [2005-05-10 698848]
R3 SlWdmSup;SlWdmSup; C:\WINDOWS\system32\DRIVERS\SLDRV\SlWdmSup.sys [2005-05-10 13248]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2005-07-08 190560]
R3 tapoas;TAP-Win32 Adapter OAS; C:\WINDOWS\system32\DRIVERS\tapoas.sys [2010-08-03 26112]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 viagfx;viagfx; C:\WINDOWS\system32\DRIVERS\vtmini.sys [2005-09-29 238464]
S3 afcdp;afcdp; C:\WINDOWS\system32\DRIVERS\afcdp.sys [2010-11-24 160704]
S3 AR5211;Atheros Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\ar5211.sys [2005-05-05 463168]
S3 catchme;catchme; \??\C:\DOCUME~1\Sentello\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 FETND5BV;VIA Rhine-Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2010-06-25 47104]
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader; C:\WINDOWS\system32\DRIVERS\ewdcsc.sys [2009-12-15 24448]
S3 hwusbdev;Huawei DataCard USB PNP Device; C:\WINDOWS\system32\DRIVERS\ewusbdev.sys [2009-12-15 100736]
S3 MPE;BDA MPE Filter; C:\WINDOWS\system32\DRIVERS\MPE.sys [2008-04-14 15232]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 Mtlstrm;Mtlstrm; C:\WINDOWS\system32\DRIVERS\SLDRV\Mtlstrm.sys [2005-06-21 1464912]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 NSNDIS5;NSNDIS5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\NSNDIS5.SYS []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 SlNtHal;SlNtHal; C:\WINDOWS\system32\DRIVERS\SLDRV\Slnthal.sys [2005-05-10 101328]
S3 smsbda;DVB-T TV Stick; C:\WINDOWS\system32\drivers\smsbda.sys [2009-12-03 52128]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2010-08-12 810144]
R2 OpenVPNAccessClient;OpenVPN Access Client; C:\Program Files\OpenVPN Technologies\OpenVPN Client\core\capiws.exe [2010-08-12 24064]
R2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2010-08-12 33584]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S4 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [2010-03-27 751464]
S4 afcdpsrv;Acronis Nonstop Backup service; C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe [2010-11-24 2480048]
S4 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-11-17 153376]
S4 JUPOERXJVJY;JUPOERXJVJY; C:\DOCUME~1\Sentello\LOCALS~1\Temp\JUPOERXJVJY.exe []
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: MBR rootkit

#7 Příspěvek od vyosek »

Delate si ze me legraci - ja psal odstranit nelegalni ESS :!: Ne jen jeho crack :?:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Sentello
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 12 led 2010 15:12

Re: MBR rootkit

#8 Příspěvek od Sentello »

Dobrá mmt

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: MBR rootkit

#9 Příspěvek od vyosek »

Pokud nehodlate respektovat me pokyny, tak tam budete mit bordel porad a cim dele tim lepe se zazere a bude to horsi a horsi...

:arrow: RSIT dejte ne leteckou postu a i ten log z CF
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Sentello
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 12 led 2010 15:12

Re: MBR rootkit

#10 Příspěvek od Sentello »

RIST: http://leteckaposta.cz/401553380
za mmt bude i CF

Sentello
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 12 led 2010 15:12

Re: MBR rootkit

#11 Příspěvek od Sentello »

CF zde:
http://leteckaposta.cz/139468730

MBR infekci to hlásí :(

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: MBR rootkit

#12 Příspěvek od vyosek »

Ja sem pro prehlednost CF vlozim a dejte mi chvili nez vytvorim skript

ComboFix 10-11-29.02 - Sentello 11.2010 ă. 21:13:55.4.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.1459.1154 [GMT 1:00]
Running from: c:\documents and settings\Sentello\Desktop\ComboFix.exe
AV: avast! Antivirus *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2010-10-28 to 2010-11-29 )))))))))))))))))))))))))))))))
.

2010-11-29 18:41 . 2010-11-29 18:42 -------- d-----w- C:\rsit

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-23 19:54 . 2008-04-14 12:00 361600 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-09-18 11:23 . 2008-04-14 12:00 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2008-04-14 12:00 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2008-04-14 12:00 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2008-04-14 12:00 953856 ----a-w- c:\windows\system32\mfc40u.dll
2010-09-01 11:51 . 2008-04-14 12:00 285824 ----a-w- c:\windows\system32\atmfd.dll
.

------- Sigcheck -------

[-] 2010-11-23 . CBEEBEB899E31EF52B962CB31FC8CA5C . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys
[-] 2010-11-14 . 68F06FE0021B01E670AF37B8C5964FDF . 361344 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB951748$\tcpip.sys
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2005-03-08 53248]
"VTTrayp"="VTtrayp.exe" [2005-09-14 167936]
"SoundMan"="SOUNDMAN.EXE" [2005-08-17 90112]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-07-08 729178]
"TNOD UP"="c:\program files\TNod User & Password Finder\TNODUP.exe" [2010-04-01 1811968]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2010-03-27 5107232]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2010-03-27 362232]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2010-09-07 2838912]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Sentello\Start Menu\Programs\Startup\
HDDlife.lnk - c:\program files\HDDlife for Notebooks\HDDlife for Notebooks.exe [2006-12-8 1125888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ose"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
"JUPOERXJVJY"=3 (0x3)
"afcdpsrv"=2 (0x2)
"AcrSch2Svc"=2 (0x2)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Google Update"="c:\documents and settings\Sentello\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"CanonSolutionMenu"=c:\program files\Canon\SolutionMenu\CNSLMAIN.exe /logon
"CanonMyPrinter"=c:\program files\Canon\MyPrinter\BJMyPrt.exe /logon
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"d:\\Program Files\\uTorrent\\uTorrent.exe"=
"d:\\Program Files\\Nonoh.net\\Nonoh\\nonoh.exe"=
"d:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [14.11.2010 ă. 22:32 664064]
R0 tdrpman258;Acronis Try&Decide and Restore Points filter (build 258);c:\windows\system32\drivers\tdrpm258.sys [22.11.2010 ă. 10:38 911680]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [29.11.2010 ă. 20:59 165584]
R1 tidnet;TID NDIS Protocol Driver;c:\windows\system32\drivers\tidnet.sys [15.9.2009 ă. 10:51 19200]
R2 afcdpsrv;Acronis Nonstop Backup service;c:\program files\Common Files\Acronis\CDP\afcdpsrv.exe [24.11.2010 ă. 13:23 2480048]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [29.11.2010 ă. 20:59 17744]
R3 afcdp;afcdp;c:\windows\system32\drivers\afcdp.sys [24.11.2010 ă. 13:23 160704]
R3 tapoas;TAP-Win32 Adapter OAS;c:\windows\system32\drivers\tapoas.sys [03.8.2010 ă. 16:25 26112]
S2 OpenVPNAccessClient;OpenVPN Access Client;c:\program files\OpenVPN Technologies\OpenVPN Client\core\capiws.exe [12.8.2010 ă. 17:45 24064]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader;c:\windows\system32\drivers\ewdcsc.sys [15.11.2010 ă. 21:31 24448]
S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\drivers\ewusbdev.sys [15.11.2010 ă. 21:31 100736]
S3 smsbda;DVB-T TV Stick;c:\windows\system32\drivers\smsbda.sys [17.11.2010 ă. 20:52 52128]
S4 JUPOERXJVJY;JUPOERXJVJY;c:\docume~1\Sentello\LOCALS~1\Temp\JUPOERXJVJY.exe --> c:\docume~1\Sentello\LOCALS~1\Temp\JUPOERXJVJY.exe [?]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2010-11-15 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2007-04-26 20:51]

2010-11-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-682003330-1417001333-1003Core.job
- c:\documents and settings\Sentello\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-11-15 15:52]

2010-11-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-682003330-1417001333-1003UA.job
- c:\documents and settings\Sentello\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-11-15 15:52]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://google.cz/
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-11-29 21:18
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: FUJITSU_MHV2080AT rev.000000A0 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3

device: opened successfully
user: MBR read successfully

Disk trace:
called modules: ntoskrnl.exe catchme.sys >>UNKNOWN [0x8985C0E8]<<
c:\docume~1\Sentello\LOCALS~1\Temp\catchme.sys
_asm { MOV EAX, 0x8985c008; XCHG [ESP], EAX; PUSH EAX; PUSH 0x898aaeb4; RET ; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; }
1 nt!IofCallDriver[0x804E37D5] -> \Device\Harddisk0\DR0[0x897CFAB8]
\Driver\Disk[0x897CAA08] -> IRP_MJ_CREATE -> 0x8985C0E8
kernel: MBR read successfully
_asm { CALL 0x115; }
detected disk devices:
detected hooks:
\Driver\Disk -> 0x8985c0e8
user & kernel MBR OK
Warning: possible MBR rootkit infection !

**************************************************************************
.
Completion time: 2010-11-29 21:21:18
ComboFix-quarantined-files.txt 2010-11-29 20:21

Pre-Run: 10 021 969 920 bytes free
Post-Run: 10 058 977 280 bytes free

- - End Of File - - 74A1F17F747BBA2F404E67D902F268A4
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: MBR rootkit

#13 Příspěvek od vyosek »

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    MBR::
    
    FCopy::
    c:\windows\system32\dllcache\tcpip.sys | c:\windows\system32\drivers\tcpip.sys
    
    Folder::
    c:\program files\TNod User & Password Finder\
    
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "TNOD UP"=-
    
    Collect::
    c:\docume~1\Sentello\LOCALS~1\Temp\JUPOERXJVJY.exe
    
    Driver::
    JUPOERXJVJY
    
    File::
    c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-682003330-1417001333-1003Core.job
    c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-682003330-1417001333-1003UA.job
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Sentello
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 12 led 2010 15:12

Re: MBR rootkit

#14 Příspěvek od Sentello »

děkuji, udělal jsem přesně vše podle návodu:
Tady je LOG:
ComboFix 10-11-29.02 - Sentello 11.2010 г. 21:52:33.4.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.1459.1151 [GMT 1:00]
Running from: c:\documents and settings\Sentello\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Sentello\Desktop\CFScript.txt
AV: avast! Antivirus *On-access scanning enabled* (Outdated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-682003330-1417001333-1003Core.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-682003330-1417001333-1003UA.job"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\TNod User & Password Finder\
c:\program files\TNod User & Password Finder\\CREDITOS.txt
c:\program files\TNod User & Password Finder\\LEEME.txt
c:\program files\TNod User & Password Finder\\tnodicons.icl
c:\program files\TNod User & Password Finder\\TNODUP.exe
c:\program files\TNod User & Password Finder\\uninst-tnod.exe
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-682003330-1417001333-1003Core.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-682003330-1417001333-1003UA.job

.
--------------- FCopy ---------------

c:\windows\system32\dllcache\tcpip.sys --> c:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_JUPOERXJVJY
-------\Service_JUPOERXJVJY


((((((((((((((((((((((((( Files Created from 2010-10-28 to 2010-11-29 )))))))))))))))))))))))))))))))
.

2010-11-29 18:41 . 2010-11-29 18:42 -------- d-----w- C:\rsit

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-18 11:23 . 2008-04-14 12:00 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2008-04-14 12:00 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2008-04-14 12:00 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2008-04-14 12:00 953856 ----a-w- c:\windows\system32\mfc40u.dll
2010-09-01 11:51 . 2008-04-14 12:00 285824 ----a-w- c:\windows\system32\atmfd.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2005-03-08 53248]
"VTTrayp"="VTtrayp.exe" [2005-09-14 167936]
"SoundMan"="SOUNDMAN.EXE" [2005-08-17 90112]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-07-08 729178]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2010-03-27 5107232]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2010-03-27 362232]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2010-09-07 2838912]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Sentello\Start Menu\Programs\Startup\
HDDlife.lnk - c:\program files\HDDlife for Notebooks\HDDlife for Notebooks.exe [2006-12-8 1125888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ose"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
"JUPOERXJVJY"=3 (0x3)
"afcdpsrv"=2 (0x2)
"AcrSch2Svc"=2 (0x2)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Google Update"="c:\documents and settings\Sentello\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"CanonSolutionMenu"=c:\program files\Canon\SolutionMenu\CNSLMAIN.exe /logon
"CanonMyPrinter"=c:\program files\Canon\MyPrinter\BJMyPrt.exe /logon
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"d:\\Program Files\\uTorrent\\uTorrent.exe"=
"d:\\Program Files\\Nonoh.net\\Nonoh\\nonoh.exe"=
"d:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [14.11.2010 г. 22:32 664064]
R0 tdrpman258;Acronis Try&Decide and Restore Points filter (build 258);c:\windows\system32\drivers\tdrpm258.sys [22.11.2010 г. 10:38 911680]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [29.11.2010 г. 21:41 165584]
R1 tidnet;TID NDIS Protocol Driver;c:\windows\system32\drivers\tidnet.sys [15.9.2009 г. 10:51 19200]
R2 afcdpsrv;Acronis Nonstop Backup service;c:\program files\Common Files\Acronis\CDP\afcdpsrv.exe [24.11.2010 г. 13:23 2480048]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [29.11.2010 г. 21:41 17744]
R2 OpenVPNAccessClient;OpenVPN Access Client;c:\program files\OpenVPN Technologies\OpenVPN Client\core\capiws.exe [12.8.2010 г. 17:45 24064]
R3 afcdp;afcdp;c:\windows\system32\drivers\afcdp.sys [24.11.2010 г. 13:23 160704]
R3 tapoas;TAP-Win32 Adapter OAS;c:\windows\system32\drivers\tapoas.sys [03.8.2010 г. 16:25 26112]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader;c:\windows\system32\drivers\ewdcsc.sys [15.11.2010 г. 21:31 24448]
S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\drivers\ewusbdev.sys [15.11.2010 г. 21:31 100736]
S3 smsbda;DVB-T TV Stick;c:\windows\system32\drivers\smsbda.sys [17.11.2010 г. 20:52 52128]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2010-11-15 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2007-04-26 20:51]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://google.cz/
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -

AddRemove-TNod - c:\program files\TNod User & Password Finder\uninst-TNod.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-11-29 22:02
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: FUJITSU_MHV2080AT rev.000000A0 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3

device: opened successfully
user: MBR read successfully

Disk trace:
called modules: ntoskrnl.exe >>UNKNOWN [0x89895688]<<
_asm { MOV EAX, 0x898955a8; XCHG [ESP], EAX; PUSH EAX; PUSH 0x898980d4; RET ; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; }
1 nt!IofCallDriver[0x804E37D5] -> \Device\Harddisk0\DR0[0x897B8AB8]
\Driver\Disk[0x897E1A08] -> IRP_MJ_CREATE -> 0x89895688
kernel: MBR read successfully
_asm { CALL 0x115; }
detected disk devices:
detected hooks:
\Driver\Disk -> 0x89895688
user & kernel MBR OK
Warning: possible MBR rootkit infection !

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1088)
c:\windows\system32\adsldpc.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\system32\VTTimer.exe
c:\windows\system32\VTtrayp.exe
c:\windows\SOUNDMAN.EXE
c:\program files\Microsoft ActiveSync\Wcescomm.exe
c:\progra~1\MICROS~3\rapimgr.exe
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\windows\system32\wscntfy.exe
c:\documents and settings\Sentello\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
c:\documents and settings\Sentello\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
c:\documents and settings\Sentello\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
c:\documents and settings\Sentello\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
c:\documents and settings\Sentello\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
c:\documents and settings\Sentello\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
c:\documents and settings\Sentello\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
c:\documents and settings\Sentello\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
.
**************************************************************************
.
Completion time: 2010-11-29 22:05:15 - machine was rebooted
ComboFix-quarantined-files.txt 2010-11-29 21:04

Pre-Run: 10 012 495 872 bytes free
Post-Run: 9 996 316 672 bytes free

- - End Of File - - 7DFAB0F0EDDDAB6BF7ED7C66AC534AAD
MBR infection to opět detekovalo :(

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: MBR rootkit

#15 Příspěvek od vyosek »

:arrow: Havet je asi hodne hluboko, vypada to ze bude potreba rucni opravy :o jeste to zkusime takhle...

:arrow: Stahnete SPTD http://www.duplexsecure.com/en/downloads
  • Vyberte z uvedene stranky verzi dle sveho operacniho systemu (32(x86)bit ci 64(x64)bit)
  • Ulozte na plochu a spustte
  • Zvolte moznost Uninstall a restartujte PC - pokud nepujde kliknout (tlacitko bude sede), krok preskocte
:arrow: Stahnete Defogger http://www.jpshortstuff.247fixes.com/Defogger.exe
  • Ulozte na plochu a spustte
  • Kliknete na Disable a restartujte PC - pokud nepujde kliknout (tlacitko bude sede), krok preskocte
:arrow: Stahnete MBR na plochu http://www2.gmer.net/mbr/mbr.exe ale nespoustejte

:arrow: Kliknete na Start a pote Spustit, pripadne pouzijte klavesou zkratku Win+R
  • Vyskoci na Vas okenko, do ktereho zkopirujte text nize
  • Kód: Vybrat vše

    "%userprofile%\Desktop\mbr" -t
  • Kliknete na OK
  • Na plose se Vam vytvori log s nazvem mbr.txt, jeho obsah mi sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět