Stránka 1 z 2

dlho bez antiviru, vela haveti, kontrola logu prosim

Napsal: 05 bře 2011 19:19
od Fony
mohli by ste mi prosim poradit co by som mal robit v pripade ze mi ani avira neodstrani nejaky z virusov, 2 dni dozadu mi zacal z nicoho nic po nainstalovani Nokia Ovi padat system pre kriticke chyby v systeme > preinstalil som windows > nainstaloval som si AVG antivir (nasiel cca 50 - 60 infiltracii ale niektorych sa nevedel zbavit) > odinstaloval som AVG a nahodil som aviru ktora mi vraj dost haveti zmazala ale system hlavne ked sa ide do programov (v crackoch patchoch a keymakeroch toho bolo najviac) tak tam vsetko reaguje nejako pomaly

toto mi tak v skratke dnes nasla avira
Obrázek
Obrázek

+LOG
Logfile of random's system information tool 1.08 (written by random/random)
Run by fony at 2011-03-05 19:16:39
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 39 GB (78%) free of 50 GB
Total RAM: 1023 MB (36% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:17:03, on 5.3.2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Adobe\Reader 9.0\Reader\AcroRd32.exe
C:\Program Files\Avira\AntiVir Desktop\avscan.exe
C:\Documents and Settings\fony\Desktop\RSIT.exe
C:\Program Files\trend micro\fony.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: PandoraTV Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{345230CF-B3FA-4590-AC96-0F0460749CF6}: NameServer = 10.125.254.254
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 4341 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
C:\WINDOWS\tasks\WGASetup.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
PandoraTV Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-09-28 1400712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{D4027C7F-154A-4066-A1AD-4243D8127440} - PandoraTV Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-09-28 1400712]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-10-07 13574144]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-10-07 86016]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2008-10-09 17021440]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2008-06-19 57344]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-01-31 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2011-01-10 281768]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Valve\hl.exe"="C:\Program Files\Valve\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe

======List of files/folders created in the last 1 months======

2011-03-05 19:16:42 ----D---- C:\Program Files\trend micro
2011-03-05 19:16:39 ----D---- C:\rsit
2011-03-05 18:18:42 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$
2011-03-05 18:18:34 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2011-03-05 18:18:25 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2011-03-05 18:18:14 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2011-03-05 18:18:04 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2011-03-05 18:17:49 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2011-03-05 18:17:40 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2011-03-05 18:17:30 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2011-03-05 18:17:16 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2011-03-05 18:17:03 ----HDC---- C:\WINDOWS\$NtUninstallKB935448$
2011-03-05 18:16:55 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2011-03-05 18:16:46 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2011-03-05 18:16:39 ----HDC---- C:\WINDOWS\$NtUninstallKB980195$
2011-03-05 18:16:31 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2011-03-05 18:16:22 ----HDC---- C:\WINDOWS\$NtUninstallKB981350$
2011-03-05 18:16:12 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2011-03-05 18:16:07 ----D---- C:\WINDOWS\system32\KB905474
2011-03-05 18:15:51 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2011-03-05 18:15:42 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2011-03-05 18:15:33 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$
2011-03-05 18:15:24 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2011-03-05 18:15:16 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2011-03-05 18:15:08 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2011-03-05 18:14:59 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2011-03-05 18:14:50 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2011-03-05 18:14:41 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2011-03-05 18:14:32 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2011-03-05 18:14:23 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2011-03-05 18:13:59 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2011-03-05 18:13:44 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2011-03-05 18:13:36 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2011-03-05 18:13:27 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2011-03-05 18:13:18 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2011-03-05 18:13:10 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2011-03-05 18:13:01 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2011-03-05 18:12:51 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9L$
2011-03-05 18:12:40 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2011-03-05 18:12:29 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2011-03-05 18:12:20 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2011-03-05 18:12:05 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2011-03-05 18:11:56 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2011-03-05 18:11:46 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2011-03-05 18:10:26 ----A---- C:\WINDOWS\system32\MRT.exe
2011-03-05 18:10:16 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2011-03-05 18:10:05 ----HDC---- C:\WINDOWS\$NtUninstallKB981793$
2011-03-05 18:09:59 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2011-03-05 18:09:50 ----HDC---- C:\WINDOWS\$NtUninstallKB979559$
2011-03-05 18:09:41 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2011-03-05 18:09:31 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2011-03-05 18:09:18 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2011-03-05 18:09:09 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2011-03-05 18:08:56 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2011-03-05 18:08:39 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2011-03-05 18:08:31 ----HDC---- C:\WINDOWS\$NtUninstallKB971961$
2011-03-05 18:08:22 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2011-03-05 18:08:13 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2011-03-05 18:08:05 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2011-03-05 18:07:58 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2011-03-05 18:07:51 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2011-03-05 18:07:44 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2011-03-05 18:07:34 ----D---- C:\WINDOWS\ServicePackFiles
2011-03-05 18:07:32 ----HDC---- C:\WINDOWS\$NtUninstallKB958470$
2011-03-05 18:07:23 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2011-03-05 18:07:15 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2011-03-05 18:07:06 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2011-03-05 18:06:53 ----HDC---- C:\WINDOWS\$NtUninstallKB971032$
2011-03-05 18:06:41 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2011-03-05 18:06:30 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2011-03-05 18:06:18 ----HDC---- C:\WINDOWS\$NtUninstallKB979402_WM9L$
2011-03-05 18:06:08 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2011-03-05 18:05:35 ----HDC---- C:\WINDOWS\$NtUninstallKB982381$
2011-03-05 18:05:19 ----HDC---- C:\WINDOWS\$NtUninstallKB944338-v2$
2011-03-05 18:05:11 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2011-03-05 18:05:04 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2011-03-05 18:04:52 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2011-03-05 17:48:38 ----D---- C:\WINDOWS\system32\NtmsData
2011-03-05 17:47:54 ----D---- C:\Documents and Settings\fony\Application Data\Avira
2011-03-05 17:44:37 ----A---- C:\WINDOWS\system32\drivers\ssmdrv.sys
2011-03-05 17:44:36 ----D---- C:\Program Files\Avira
2011-03-05 17:44:36 ----D---- C:\Documents and Settings\All Users\Application Data\Avira
2011-03-05 17:44:36 ----A---- C:\WINDOWS\system32\drivers\avipbb.sys
2011-03-05 17:44:36 ----A---- C:\WINDOWS\system32\drivers\avgntmgr.sys
2011-03-05 17:44:36 ----A---- C:\WINDOWS\system32\drivers\avgntflt.sys
2011-03-05 17:44:36 ----A---- C:\WINDOWS\system32\drivers\avgntdd.sys
2011-03-05 17:39:35 ----D---- C:\WINDOWS\system32\CatRoot_bak
2011-03-05 17:24:26 ----N---- C:\WINDOWS\system32\drivers\bthport.sys
2011-03-05 16:57:37 ----N---- C:\WINDOWS\system32\tzchange.exe
2011-03-05 16:54:21 ----A---- C:\WINDOWS\system32\xpsp3res.dll
2011-03-05 16:52:58 ----D---- C:\Documents and Settings\fony\Application Data\uniblue
2011-03-05 16:52:19 ----D---- C:\Program Files\Uniblue
2011-03-05 16:51:26 ----D---- C:\WINDOWS\system32\PreInstall
2011-03-05 16:51:24 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2011-03-05 16:51:24 ----HD---- C:\WINDOWS\$hf_mig$
2011-03-05 16:50:21 ----D---- C:\WINDOWS\system32\en-US
2011-03-05 16:50:15 ----D---- C:\Program Files\Reference Assemblies
2011-03-05 16:49:18 ----D---- C:\WINDOWS\assembly
2011-03-05 16:49:02 ----D---- C:\WINDOWS\Microsoft.NET
2011-03-05 16:47:44 ----HDC---- C:\WINDOWS\$NtUninstallWIC$
2011-03-05 16:47:27 ----RHD---- C:\AHCache
2011-03-05 16:45:01 ----N---- C:\WINDOWS\system32\spmsg.dll
2011-03-05 16:44:50 ----HDC---- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
2011-03-05 16:43:50 ----HDC---- C:\Documents and Settings\All Users\Application Data\{51019853-129C-4EDE-9030-D5FD7BBD9AD0}
2011-03-05 16:40:37 ----N---- C:\WINDOWS\system32\browserchoice.exe
2011-03-05 15:48:09 ----A---- C:\WINDOWS\system32\msonpmon.dll
2011-03-05 15:46:18 ----D---- C:\Program Files\Microsoft Works
2011-03-05 15:46:06 ----D---- C:\Program Files\MSBuild
2011-03-05 15:45:48 ----D---- C:\Program Files\Microsoft Visual Studio
2011-03-05 15:45:48 ----D---- C:\Program Files\Common Files\DESIGNER
2011-03-05 15:42:02 ----D---- C:\WINDOWS\SHELLNEW
2011-03-05 15:41:22 ----D---- C:\Program Files\Microsoft Office
2011-03-05 15:41:20 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2011-03-05 15:40:59 ----RHD---- C:\MSOCache
2011-03-05 15:27:48 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2011-03-05 14:16:17 ----D---- C:\Program Files\Valve
2011-03-05 13:09:08 ----D---- C:\Program Files\MediaInfo
2011-03-05 12:51:49 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2011-03-05 12:51:29 ----D---- C:\Program Files\Common Files\Adobe
2011-03-05 12:51:28 ----D---- C:\Program Files\Adobe
2011-03-05 12:49:16 ----D---- C:\Documents and Settings\fony\Application Data\WinRAR
2011-03-05 12:31:28 ----D---- C:\Program Files\AIMP2
2011-03-05 12:29:59 ----D---- C:\Program Files\Ask.com
2011-03-05 11:55:20 ----SHD---- C:\RECYCLER
2011-03-05 11:54:35 ----D---- C:\Program Files\The KMPlayer
2011-03-05 11:54:20 ----D---- C:\Documents and Settings\fony\Application Data\ESTsoft
2011-03-05 11:54:14 ----D---- C:\Documents and Settings\All Users\Application Data\ESTsoft
2011-03-05 11:54:07 ----D---- C:\Program Files\ESTsoft
2011-03-05 11:53:32 ----D---- C:\Program Files\WinRAR
2011-03-05 11:44:18 ----D---- C:\Documents and Settings\fony\Application Data\Macromedia
2011-03-05 11:44:18 ----D---- C:\Documents and Settings\fony\Application Data\Adobe
2011-03-05 11:43:37 ----D---- C:\Documents and Settings\fony\Application Data\Mozilla
2011-03-05 11:43:25 ----D---- C:\Program Files\Mozilla Firefox
2011-03-05 10:55:33 ----A---- C:\WINDOWS\system32\h323log.txt
2011-03-05 10:53:59 ----A---- C:\WINDOWS\system32\drivers\audstub.sys
2011-03-05 10:53:18 ----A---- C:\WINDOWS\system32\drivers\redbook.sys
2011-03-05 10:52:37 ----A---- C:\WINDOWS\system32\usbui.dll
2011-03-05 10:51:42 ----A---- C:\WINDOWS\imsins.BAK
2011-03-05 10:51:40 ----SHD---- C:\WINDOWS\Installer
2011-03-05 10:51:40 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-03-05 10:51:39 ----D---- C:\Program Files\Common Files\ODBC
2011-03-05 10:51:39 ----A---- C:\WINDOWS\ODBCINST.INI
2011-03-05 10:51:36 ----RD---- C:\Program Files
2011-03-05 10:51:36 ----D---- C:\Program Files\Common Files\SpeechEngines
2011-03-05 10:51:36 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-03-05 10:51:36 ----D---- C:\Program Files\Common Files
2011-03-05 10:51:33 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2011-03-05 10:51:33 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2011-03-05 10:51:33 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2011-03-05 10:51:32 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2011-03-05 10:51:32 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2011-03-05 10:51:32 ----RA---- C:\WINDOWS\system32\kbdur.dll
2011-03-05 10:51:32 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2011-03-05 10:51:32 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2011-03-05 10:51:32 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2011-03-05 10:51:32 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2011-03-05 10:51:32 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2011-03-05 10:51:32 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2011-03-05 10:51:31 ----RA---- C:\WINDOWS\system32\kbdru.dll
2011-03-05 10:51:31 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2011-03-05 10:51:31 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2011-03-05 10:51:30 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2011-03-05 10:51:30 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2011-03-05 10:51:30 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2011-03-05 10:51:30 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2011-03-05 10:51:30 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2011-03-05 10:51:30 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2011-03-05 10:51:30 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2011-03-05 10:51:29 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2011-03-05 10:51:29 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2011-03-05 10:51:29 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2011-03-05 10:51:29 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2011-03-05 10:51:28 ----RA---- C:\WINDOWS\system32\kbdest.dll
2011-03-05 10:51:27 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2011-03-05 10:51:27 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2011-03-05 10:51:27 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2011-03-05 10:51:27 ----RA---- C:\WINDOWS\system32\kbdro.dll
2011-03-05 10:51:27 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2011-03-05 10:51:27 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2011-03-05 10:51:27 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2011-03-05 10:51:27 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2011-03-05 10:51:27 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
2011-03-05 10:51:27 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
2011-03-05 10:51:27 ----RA---- C:\WINDOWS\system32\kbdcz.dll
2011-03-05 10:51:27 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2011-03-05 10:51:27 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2011-03-05 10:51:25 ----A---- C:\WINDOWS\system32\spxcoins.dll
2011-03-05 10:51:25 ----A---- C:\WINDOWS\system32\irclass.dll
2011-03-05 10:51:25 ----A---- C:\WINDOWS\system32\dgsetup.dll
2011-03-05 10:51:25 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2011-03-05 10:51:24 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2011-03-05 10:51:23 ----A---- C:\WINDOWS\TASKMAN.EXE
2011-03-05 10:51:22 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2011-03-05 10:51:22 ----A---- C:\WINDOWS\system32\drivers\irenum.sys
2011-03-05 10:51:22 ----A---- C:\WINDOWS\system32\batt.dll
2011-03-05 10:51:22 ----A---- C:\WINDOWS\NOTEPAD.EXE
2011-03-05 10:51:21 ----A---- C:\WINDOWS\system32\storprop.dll
2011-03-05 10:51:14 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
2011-03-05 10:51:10 ----RA---- C:\WINDOWS\SET8.tmp
2011-03-05 10:51:08 ----RA---- C:\WINDOWS\SET4.tmp
2011-03-05 10:51:07 ----RA---- C:\WINDOWS\SET3.tmp
2011-03-05 10:51:02 ----D---- C:\WINDOWS\system32\CatRoot2
2011-03-05 10:51:02 ----D---- C:\WINDOWS\system32\CatRoot
2011-03-05 10:50:56 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2011-03-05 10:50:39 ----A---- C:\WINDOWS\setuplog.txt
2011-03-05 10:50:37 ----SHD---- C:\System Volume Information
2011-03-05 10:50:37 ----D---- C:\Documents and Settings
2011-03-05 10:49:47 ----SH---- C:\boot.ini
2011-03-05 10:43:28 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-03-05 10:43:28 ----RSD---- C:\WINDOWS\Fonts
2011-03-05 10:43:28 ----RD---- C:\WINDOWS\Web
2011-03-05 10:43:28 ----HD---- C:\WINDOWS\inf
2011-03-05 10:43:28 ----D---- C:\WINDOWS\WinSxS
2011-03-05 10:43:28 ----D---- C:\WINDOWS\twain_32
2011-03-05 10:43:28 ----D---- C:\WINDOWS\Temp
2011-03-05 10:43:28 ----D---- C:\WINDOWS\system32\wins
2011-03-05 10:43:28 ----D---- C:\WINDOWS\system32\wbem
2011-03-05 10:43:28 ----D---- C:\WINDOWS\system32\usmt
2011-03-05 10:43:28 ----D---- C:\WINDOWS\system32\spool
2011-03-05 10:43:28 ----D---- C:\WINDOWS\system32\ShellExt
2011-03-05 10:43:28 ----D---- C:\WINDOWS\system32\Setup
2011-03-05 10:43:28 ----D---- C:\WINDOWS\system32\ras
2011-03-05 10:43:28 ----D---- C:\WINDOWS\system32\oobe
2011-03-05 10:43:28 ----D---- C:\WINDOWS\system32\npp
2011-03-05 10:43:28 ----D---- C:\WINDOWS\system32\mui
2011-03-05 10:43:28 ----D---- C:\WINDOWS\system32\inetsrv
2011-03-05 10:43:28 ----D---- C:\WINDOWS\system32\IME
2011-03-05 10:43:28 ----D---- C:\WINDOWS\system32\icsxml
2011-03-05 10:43:28 ----D---- C:\WINDOWS\system32\ias
2011-03-05 10:43:28 ----D---- C:\WINDOWS\system32\export
2011-03-05 10:43:28 ----D---- C:\WINDOWS\system32\drivers\etc
2011-03-05 10:43:28 ----D---- C:\WINDOWS\system32\drivers\disdn
2011-03-05 10:43:28 ----D---- C:\WINDOWS\system32\drivers
2011-03-05 10:43:28 ----D---- C:\WINDOWS\system32\dhcp
2011-03-05 10:43:28 ----D---- C:\WINDOWS\system32\config
2011-03-05 10:43:28 ----D---- C:\WINDOWS\system32\3com_dmi
2011-03-05 10:43:28 ----D---- C:\WINDOWS\system32\3076
2011-03-05 10:43:28 ----D---- C:\WINDOWS\system32\2052
2011-03-05 10:43:28 ----D---- C:\WINDOWS\system32\1054
2011-03-05 10:43:28 ----D---- C:\WINDOWS\system32\1042
2011-03-05 10:43:28 ----D---- C:\WINDOWS\system32\1041
2011-03-05 10:43:28 ----D---- C:\WINDOWS\system32\1037
2011-03-05 10:43:28 ----D---- C:\WINDOWS\system32\1033
2011-03-05 10:43:28 ----D---- C:\WINDOWS\system32\1031
2011-03-05 10:43:28 ----D---- C:\WINDOWS\system32\1028
2011-03-05 10:43:28 ----D---- C:\WINDOWS\system32\1025
2011-03-05 10:43:28 ----D---- C:\WINDOWS\system32
2011-03-05 10:43:28 ----D---- C:\WINDOWS\system
2011-03-05 10:43:28 ----D---- C:\WINDOWS\security
2011-03-05 10:43:28 ----D---- C:\WINDOWS\Resources
2011-03-05 10:43:28 ----D---- C:\WINDOWS\repair
2011-03-05 10:43:28 ----D---- C:\WINDOWS\Provisioning
2011-03-05 10:43:28 ----D---- C:\WINDOWS\pchealth
2011-03-05 10:43:28 ----D---- C:\WINDOWS\PeerNet
2011-03-05 10:43:28 ----D---- C:\WINDOWS\mui
2011-03-05 10:43:28 ----D---- C:\WINDOWS\msapps
2011-03-05 10:43:28 ----D---- C:\WINDOWS\msagent
2011-03-05 10:43:28 ----D---- C:\WINDOWS\Media
2011-03-05 10:43:28 ----D---- C:\WINDOWS\java
2011-03-05 10:43:28 ----D---- C:\WINDOWS\ime
2011-03-05 10:43:28 ----D---- C:\WINDOWS\Help
2011-03-05 10:43:28 ----D---- C:\WINDOWS\ehome
2011-03-05 10:43:28 ----D---- C:\WINDOWS\Driver Cache
2011-03-05 10:43:28 ----D---- C:\WINDOWS\Debug
2011-03-05 10:43:28 ----D---- C:\WINDOWS\Cursors
2011-03-05 10:43:28 ----D---- C:\WINDOWS\Connection Wizard
2011-03-05 10:43:28 ----D---- C:\WINDOWS\Config
2011-03-05 10:43:28 ----D---- C:\WINDOWS\AppPatch
2011-03-05 10:43:28 ----D---- C:\WINDOWS\addins
2011-03-05 10:43:28 ----D---- C:\WINDOWS
2011-03-05 10:43:28 ----ASH---- C:\pagefile.sys
2011-03-05 10:29:23 ----A---- C:\WINDOWS\system32\WMErrSKY.dll
2011-03-05 10:29:22 ----D---- C:\WINDOWS\system32\1051
2011-03-05 10:25:05 ----D---- C:\Program Files\AVG
2011-03-05 10:22:35 ----D---- C:\WINDOWS\system32\Lang
2011-03-05 10:21:33 ----A---- C:\WINDOWS\system32\drivers\splitter.sys
2011-03-05 10:21:31 ----A---- C:\WINDOWS\system32\drivers\wdmaud.sys
2011-03-05 10:21:30 ----A---- C:\WINDOWS\system32\drivers\DMusic.sys
2011-03-05 10:21:26 ----A---- C:\WINDOWS\system32\drivers\swmidi.sys
2011-03-05 10:21:25 ----A---- C:\WINDOWS\system32\drivers\aec.sys
2011-03-05 10:21:24 ----A---- C:\WINDOWS\system32\drivers\kmixer.sys
2011-03-05 10:21:23 ----A---- C:\WINDOWS\system32\drivers\drmkaud.sys
2011-03-05 10:21:22 ----A---- C:\WINDOWS\system32\drivers\sysaudio.sys
2011-03-05 10:21:21 ----A---- C:\WINDOWS\system32\drivers\MSKSSRV.sys
2011-03-05 10:21:19 ----A---- C:\WINDOWS\system32\drivers\MSPQM.sys
2011-03-05 10:21:17 ----A---- C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2011-03-05 10:21:14 ----D---- C:\WINDOWS\system32\RTCOM
2011-03-05 10:21:13 ----A---- C:\WINDOWS\system32\ksuser.dll
2011-03-05 10:21:12 ----A---- C:\WINDOWS\system32\drivers\drmk.sys
2011-03-05 10:20:45 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2011-03-05 10:20:44 ----HDC---- C:\WINDOWS\$NtUninstallKB888111WXPSP2$
2011-03-05 10:20:41 ----A---- C:\WINDOWS\system32\drivers\RtkHDAud.sys
2011-03-05 10:20:41 ----A---- C:\WINDOWS\SOUNDMAN.EXE
2011-03-05 10:20:41 ----A---- C:\WINDOWS\SkyTel.exe
2011-03-05 10:20:41 ----A---- C:\WINDOWS\RtlUpd.exe
2011-03-05 10:20:41 ----A---- C:\WINDOWS\RTLCPL.EXE
2011-03-05 10:20:40 ----A---- C:\WINDOWS\RTHDCPL.EXE
2011-03-05 10:20:39 ----A---- C:\WINDOWS\system32\drivers\Monfilt.sys
2011-03-05 10:20:39 ----A---- C:\WINDOWS\system32\drivers\Ambfilt.sys
2011-03-05 10:20:39 ----A---- C:\WINDOWS\MicCal.exe
2011-03-05 10:20:39 ----A---- C:\WINDOWS\ALCWZRD.EXE
2011-03-05 10:20:39 ----A---- C:\WINDOWS\ALCMTR.EXE
2011-03-05 10:20:35 ----A---- C:\WINDOWS\RtlExUpd.dll
2011-03-05 10:20:35 ----A---- C:\WINDOWS\HideWin.exe
2011-03-05 10:18:06 ----D---- C:\WINDOWS\system32\ReinstallBackups
2011-03-05 10:18:05 ----D---- C:\Program Files\Intel
2011-03-05 10:15:52 ----D---- C:\WINDOWS\nview
2011-03-05 10:15:52 ----A---- C:\WINDOWS\system32\nvudisp.exe
2011-03-05 10:15:42 ----A---- C:\WINDOWS\system32\NVUNINST.EXE
2011-03-05 10:15:30 ----D---- C:\NVIDIA
2011-03-05 10:14:39 ----A---- C:\WINDOWS\system32\drivers\Rtenicxp.sys
2011-03-05 10:14:38 ----HD---- C:\Program Files\InstallShield Installation Information
2011-03-05 10:14:38 ----D---- C:\WINDOWS\OPTIONS
2011-03-05 10:14:38 ----D---- C:\Program Files\Realtek
2011-03-05 10:14:30 ----D---- C:\Program Files\Common Files\InstallShield
2011-03-05 10:12:09 ----D---- C:\Documents and Settings\fony\Application Data\Identities
2011-03-05 10:12:08 ----HD---- C:\Program Files\Uninstall Information
2011-03-05 10:12:03 ----SD---- C:\Documents and Settings\fony\Application Data\Microsoft
2011-03-05 10:12:03 ----ASH---- C:\Documents and Settings\fony\Application Data\desktop.ini
2011-03-05 10:03:11 ----D---- C:\WINDOWS\SoftwareDistribution
2011-03-05 10:03:11 ----D---- C:\WINDOWS\Prefetch
2011-03-05 10:03:10 ----SD---- C:\WINDOWS\system32\Microsoft
2011-03-05 10:03:10 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-03-05 10:00:33 ----D---- C:\WINDOWS\system32\xircom
2011-03-05 10:00:33 ----D---- C:\Program Files\xerox
2011-03-05 10:00:33 ----D---- C:\Program Files\microsoft frontpage
2011-03-05 10:00:18 ----RASH---- C:\MSDOS.SYS
2011-03-05 10:00:18 ----RASH---- C:\IO.SYS
2011-03-05 10:00:18 ----A---- C:\WINDOWS\control.ini
2011-03-05 10:00:18 ----A---- C:\CONFIG.SYS
2011-03-05 10:00:18 ----A---- C:\AUTOEXEC.BAT
2011-03-05 10:00:05 ----A---- C:\WINDOWS\OEWABLog.txt
2011-03-05 10:00:02 ----A---- C:\WINDOWS\system32\mapi32.dll
2011-03-05 09:59:27 ----RD---- C:\WINDOWS\Offline Web Pages
2011-03-05 09:59:26 ----SD---- C:\WINDOWS\Downloaded Program Files
2011-03-05 09:59:26 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2011-03-05 09:59:22 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2011-03-05 09:59:19 ----HD---- C:\Program Files\WindowsUpdate
2011-03-05 09:59:03 ----D---- C:\WINDOWS\system32\DirectX
2011-03-05 09:58:45 ----A---- C:\WINDOWS\system32\atrace.dll
2011-03-05 09:58:43 ----A---- C:\WINDOWS\system32\desktop.ini
2011-03-05 09:58:43 ----A---- C:\WINDOWS\desktop.ini
2011-03-05 09:58:37 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2011-03-05 09:58:36 ----D---- C:\Program Files\Common Files\Services
2011-03-05 09:58:36 ----A---- C:\WINDOWS\system32\acctres.dll
2011-03-05 09:58:33 ----SD---- C:\WINDOWS\Tasks
2011-03-05 09:58:33 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2011-03-05 09:58:32 ----D---- C:\Program Files\Common Files\MSSoap
2011-03-05 09:58:29 ----D---- C:\WINDOWS\srchasst
2011-03-05 09:58:28 ----D---- C:\WINDOWS\system32\Macromed
2011-03-05 09:58:25 ----A---- C:\WINDOWS\system32\wuweb.dll
2011-03-05 09:58:25 ----A---- C:\WINDOWS\system32\wups.dll
2011-03-05 09:58:25 ----A---- C:\WINDOWS\system32\wucltui.dll
2011-03-05 09:58:25 ----A---- C:\WINDOWS\system32\wuauserv.dll
2011-03-05 09:58:25 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2011-03-05 09:58:25 ----A---- C:\WINDOWS\system32\wuaueng.dll
2011-03-05 09:58:25 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2011-03-05 09:58:25 ----A---- C:\WINDOWS\system32\wuauclt.exe
2011-03-05 09:58:25 ----A---- C:\WINDOWS\system32\wuapi.dll
2011-03-05 09:58:24 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2011-03-05 09:58:24 ----A---- C:\WINDOWS\system32\qmgr.dll
2011-03-05 09:58:24 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2011-03-05 09:58:24 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2011-03-05 09:58:21 ----D---- C:\Program Files\Movie Maker
2011-03-05 09:58:17 ----A---- C:\WINDOWS\system32\safrslv.dll
2011-03-05 09:58:17 ----A---- C:\WINDOWS\system32\safrdm.dll
2011-03-05 09:58:17 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2011-03-05 09:58:17 ----A---- C:\WINDOWS\system32\racpldlg.dll
2011-03-05 09:58:14 ----A---- C:\WINDOWS\system32\fltMc.exe
2011-03-05 09:58:14 ----A---- C:\WINDOWS\system32\fltlib.dll
2011-03-05 09:58:14 ----A---- C:\WINDOWS\system32\drivers\fltMgr.sys
2011-03-05 09:58:13 ----D---- C:\WINDOWS\system32\Restore
2011-03-05 09:58:13 ----A---- C:\WINDOWS\system32\srsvc.dll
2011-03-05 09:58:13 ----A---- C:\WINDOWS\system32\srrstr.dll
2011-03-05 09:58:13 ----A---- C:\WINDOWS\system32\srclient.dll
2011-03-05 09:58:13 ----A---- C:\WINDOWS\system32\drivers\sr.sys
2011-03-05 09:58:12 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2011-03-05 09:58:12 ----A---- C:\WINDOWS\system32\msconf.dll
2011-03-05 09:58:12 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2011-03-05 09:58:12 ----A---- C:\WINDOWS\system32\mnmdd.dll
2011-03-05 09:58:12 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2011-03-05 09:58:12 ----A---- C:\WINDOWS\system32\ils.dll
2011-03-05 09:58:09 ----D---- C:\Program Files\NetMeeting
2011-03-05 09:58:09 ----A---- C:\WINDOWS\system32\msoert2.dll
2011-03-05 09:58:09 ----A---- C:\WINDOWS\system32\msoeacct.dll
2011-03-05 09:58:08 ----A---- C:\WINDOWS\system32\inetres.dll
2011-03-05 09:58:08 ----A---- C:\WINDOWS\system32\inetcomm.dll
2011-03-05 09:58:06 ----D---- C:\Program Files\Outlook Express
2011-03-05 09:58:06 ----A---- C:\WINDOWS\system32\schedsvc.dll
2011-03-05 09:58:06 ----A---- C:\WINDOWS\system32\mstinit.exe
2011-03-05 09:58:06 ----A---- C:\WINDOWS\system32\mstask.dll
2011-03-05 09:58:05 ----A---- C:\WINDOWS\system32\isign32.dll
2011-03-05 09:58:05 ----A---- C:\WINDOWS\system32\inetcfg.dll
2011-03-05 09:58:05 ----A---- C:\WINDOWS\system32\icwphbk.dll
2011-03-05 09:58:05 ----A---- C:\WINDOWS\system32\icwdial.dll
2011-03-05 09:58:00 ----D---- C:\Program Files\Internet Explorer
2011-03-05 09:58:00 ----D---- C:\Program Files\Common Files\System
2011-03-05 09:57:33 ----D---- C:\Program Files\ComPlus Applications
2011-03-05 09:57:32 ----A---- C:\WINDOWS\vbaddin.ini
2011-03-05 09:57:32 ----A---- C:\WINDOWS\vb.ini
2011-03-05 09:57:28 ----D---- C:\WINDOWS\Registration
2011-03-05 09:57:22 ----D---- C:\Program Files\Windows Media Player
2011-03-05 09:57:22 ----D---- C:\Program Files\Online Services
2011-03-05 09:57:17 ----D---- C:\Program Files\Messenger
2011-03-05 09:57:14 ----D---- C:\Program Files\MSN Gaming Zone
2011-03-05 09:57:14 ----A---- C:\WINDOWS\system32\write.exe
2011-03-05 09:57:06 ----A---- C:\WINDOWS\system32\sndvol32.exe
2011-03-05 09:57:06 ----A---- C:\WINDOWS\system32\hticons.dll
2011-03-05 09:57:06 ----A---- C:\WINDOWS\system32\avwav.dll
2011-03-05 09:57:06 ----A---- C:\WINDOWS\system32\avtapi.dll
2011-03-05 09:57:06 ----A---- C:\WINDOWS\system32\avmeter.dll
2011-03-05 09:57:05 ----A---- C:\WINDOWS\system32\winchat.exe
2011-03-05 09:56:59 ----A---- C:\WINDOWS\system32\sol.exe
2011-03-05 09:56:59 ----A---- C:\WINDOWS\system32\charmap.exe
2011-03-05 09:56:59 ----A---- C:\WINDOWS\system32\getuname.dll
2011-03-05 09:56:59 ----A---- C:\WINDOWS\system32\calc.exe
2011-03-05 09:56:58 ----A---- C:\WINDOWS\system32\winmine.exe
2011-03-05 09:56:58 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2011-03-05 09:56:58 ----A---- C:\WINDOWS\system32\tskill.exe
2011-03-05 09:56:58 ----A---- C:\WINDOWS\system32\reset.exe
2011-03-05 09:56:58 ----A---- C:\WINDOWS\system32\mshearts.exe
2011-03-05 09:56:58 ----A---- C:\WINDOWS\system32\freecell.exe
2011-03-05 09:56:57 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2011-03-05 09:56:57 ----A---- C:\WINDOWS\system32\tslabels.ini
2011-03-05 09:56:57 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2011-03-05 09:56:57 ----A---- C:\WINDOWS\system32\tscon.exe
2011-03-05 09:56:57 ----A---- C:\WINDOWS\system32\shadow.exe
2011-03-05 09:56:57 ----A---- C:\WINDOWS\system32\rwinsta.exe
2011-03-05 09:56:57 ----A---- C:\WINDOWS\system32\regini.exe
2011-03-05 09:56:57 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2011-03-05 09:56:57 ----A---- C:\WINDOWS\system32\qwinsta.exe
2011-03-05 09:56:57 ----A---- C:\WINDOWS\system32\qappsrv.exe
2011-03-05 09:56:57 ----A---- C:\WINDOWS\system32\msg.exe
2011-03-05 09:56:57 ----A---- C:\WINDOWS\system32\logoff.exe
2011-03-05 09:56:57 ----A---- C:\WINDOWS\system32\cdmodem.dll
2011-03-05 09:56:56 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2011-03-05 09:56:56 ----A---- C:\WINDOWS\system32\mtxex.dll
2011-03-05 09:56:56 ----A---- C:\WINDOWS\system32\mtxdm.dll
2011-03-05 09:56:56 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2011-03-05 09:56:56 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2011-03-05 09:56:55 ----A---- C:\WINDOWS\system32\stclient.dll
2011-03-05 09:56:55 ----A---- C:\WINDOWS\system32\comsnap.dll
2011-03-05 09:56:55 ----A---- C:\WINDOWS\system32\comrepl.dll
2011-03-05 09:56:55 ----A---- C:\WINDOWS\system32\comaddin.dll
2011-03-05 09:56:51 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2011-03-05 09:56:41 ----D---- C:\Program Files\MSN
2011-03-05 09:56:40 ----A---- C:\WINDOWS\system32\sndrec32.exe
2011-03-05 09:56:40 ----A---- C:\WINDOWS\system32\mplay32.exe
2011-03-05 09:56:40 ----A---- C:\WINDOWS\system32\hypertrm.dll
2011-03-05 09:56:40 ----A---- C:\WINDOWS\system32\accwiz.exe
2011-03-05 09:56:39 ----D---- C:\Program Files\Windows NT
2011-03-05 09:56:39 ----A---- C:\WINDOWS\system32\spider.exe
2011-03-05 09:56:39 ----A---- C:\WINDOWS\system32\mspaint.exe
2011-03-05 09:56:39 ----A---- C:\WINDOWS\system32\drivers\tdtcp.sys
2011-03-05 09:56:39 ----A---- C:\WINDOWS\system32\clipbrd.exe
2011-03-05 09:56:38 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2011-03-05 09:56:38 ----A---- C:\WINDOWS\system32\remotepg.dll
2011-03-05 09:56:38 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2011-03-05 09:56:38 ----A---- C:\WINDOWS\system32\mstscax.dll
2011-03-05 09:56:38 ----A---- C:\WINDOWS\system32\mstsc.exe
2011-03-05 09:56:38 ----A---- C:\WINDOWS\system32\drivers\tdpipe.sys
2011-03-05 09:56:38 ----A---- C:\WINDOWS\system32\drivers\rdpwd.sys
2011-03-05 09:56:37 ----A---- C:\WINDOWS\system32\tscupgrd.exe
2011-03-05 09:56:37 ----A---- C:\WINDOWS\system32\termsrv.dll
2011-03-05 09:56:37 ----A---- C:\WINDOWS\system32\sessmgr.exe
2011-03-05 09:56:37 ----A---- C:\WINDOWS\system32\rdshost.exe
2011-03-05 09:56:37 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2011-03-05 09:56:37 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2011-03-05 09:56:37 ----A---- C:\WINDOWS\system32\rdpclip.exe
2011-03-05 09:56:37 ----A---- C:\WINDOWS\system32\rdchost.dll
2011-03-05 09:56:37 ----A---- C:\WINDOWS\system32\qprocess.exe
2011-03-05 09:56:36 ----D---- C:\WINDOWS\system32\MsDtc
2011-03-05 09:56:36 ----A---- C:\WINDOWS\system32\mtxoci.dll
2011-03-05 09:56:36 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2011-03-05 09:56:36 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2011-03-05 09:56:36 ----A---- C:\WINDOWS\system32\icaapi.dll
2011-03-05 09:56:36 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2011-03-05 09:56:35 ----A---- C:\WINDOWS\system32\xolehlp.dll
2011-03-05 09:56:35 ----A---- C:\WINDOWS\system32\msdtctm.dll
2011-03-05 09:56:35 ----A---- C:\WINDOWS\system32\msdtclog.dll
2011-03-05 09:56:35 ----A---- C:\WINDOWS\system32\msdtc.exe
2011-03-05 09:56:34 ----D---- C:\WINDOWS\system32\Com
2011-03-05 09:56:34 ----A---- C:\WINDOWS\system32\colbact.dll
2011-03-05 09:56:34 ----A---- C:\WINDOWS\system32\clbcatex.dll
2011-03-05 09:56:34 ----A---- C:\WINDOWS\system32\catsrvut.dll
2011-03-05 09:56:34 ----A---- C:\WINDOWS\system32\catsrvps.dll
2011-03-05 09:56:34 ----A---- C:\WINDOWS\system32\catsrv.dll
2011-03-05 09:56:33 ----A---- C:\WINDOWS\system32\comuid.dll
2011-03-05 09:56:33 ----A---- C:\WINDOWS\system32\comsvcs.dll
2011-03-05 09:56:33 ----A---- C:\WINDOWS\system32\clbcatq.dll
2011-03-05 09:56:28 ----A---- C:\WINDOWS\system32\servdeps.dll
2011-03-05 09:56:28 ----A---- C:\WINDOWS\system32\mmfutil.dll
2011-03-05 09:56:28 ----A---- C:\WINDOWS\system32\licwmi.dll
2011-03-05 09:56:28 ----A---- C:\WINDOWS\system32\cmprops.dll
2011-03-05 09:56:21 ----A---- C:\WINDOWS\system32\drivers\termdd.sys
2011-03-05 09:56:21 ----A---- C:\WINDOWS\system32\drivers\rdpdr.sys

======List of files/folders modified in the last 1 months======

2011-03-05 15:42:12 ----A---- C:\WINDOWS\win.ini
2011-03-05 10:31:01 ----A---- C:\WINDOWS\system.ini
2011-03-05 09:59:55 ----ASH---- C:\WINDOWS\fonts\desktop.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2011-01-10 135096]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-04 36096]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2010-06-17 28520]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2011-01-10 61960]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-10-13 4879360]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-10-07 6133856]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2006-08-14 83200]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2011-01-10 267944]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2011-01-10 135336]
R2 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-30 69632]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-10-07 163908]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

-----------------EOF-----------------

Re: dlho bez antiviru, vela haveti, kontrola logu prosim

Napsal: 05 bře 2011 19:54
od vyosek
Zdravim a pekny vecer preji :)

:arrow: Stahnete na plochu CKScanner
  • Spustte a kliknete na Search for files
  • Po dokonceni skenu kliknete na Save List to File a nasledne OK
  • Na plose se Vam vytvori log s nazvem ckfiles.txt, jeho obsah mi sem vlozte
PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix

Re: dlho bez antiviru, vela haveti, kontrola logu prosim

Napsal: 05 bře 2011 20:00
od Fony
CKScanner - Additional Security Risks - These are not necessarily bad
scanner sequence 3.RP.11
----- EOF -----

skusim este to combofix a otazka, ked prenasam subory cez bluetooth z PC do mobilu mozem preniest aj nejake viry alebo inu havet?

Re: dlho bez antiviru, vela haveti, kontrola logu prosim

Napsal: 05 bře 2011 20:01
od vyosek
Pokracujte ComboFixem :wink:

Re: dlho bez antiviru, vela haveti, kontrola logu prosim

Napsal: 05 bře 2011 20:21
od Fony
combofix, pocas skenovania mi napisalo nieco o rootkite a vyzadovalo reboot respektive restart inak celkovy sken netrval viac ako 10 minut od zacatia

ked prenasam subory cez bluetooth z PC do mobilu mozem preniest aj nejake viry alebo inu havet? prenasal by som potencialne ciste alebo nezavirene subory ako obrazky a videa prip. hudbu


este mam otazku, som dost aktivny na ruskych warezoch a torrentoch pricom si ma velmi vela ludi (cez 100 minimalne) pridavalo na icq pricom nic odo mna nechceli len mi dole na zelenom kvietku napisalo notifikaciu ze ten a ten si vas chce pridat do zoznamu icq pricom som stale byval na icq aj 15 hodin denne v online stave => mohol by niekto cez icq do mojho pc nejako preniknut? pripadne ci by mohol nejako infikovat pc virom?

Kód: Vybrat vše

ComboFix 11-03-04.06 - fony 05.03.2011  20:14:51.1.1 - x86
Systém Microsoft Windows XP Professional  5.1.2600.2.1250.421.1033.18.1023.718 [GMT 1:00]
Running from: c:\documents and settings\fony\Desktop\ComboFix.exe
AV: AntiVir Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
D:\fk.exe
D:\g12g.exe
D:\gcq6.exe
D:\ggpw.exe
D:\hc3hvi0.exe
D:\i8ikdjwt.exe
D:\img8hi.exe
D:\ji83j.exe
D:\mi9al8rs.exe
D:\qhbfqx.exe
D:\r3fhr.exe
D:\rpw.exe
D:\s1.exe
D:\sdfqh.exe
D:\tgt.exe
D:\twhvna.exe
D:\vgyn6ewc.exe
D:\vlvtdflx.exe
D:\wkimt.exe
D:\xmor.exe
D:\ysyjq1bs.exe
.
.
(((((((((((((((((((((((((   Files Created from 2011-02-05 to 2011-03-05  )))))))))))))))))))))))))))))))
.
.
2011-03-05 18:16 . 2011-03-05 18:17	--------	d-----w-	C:\rsit
2011-03-05 15:47 . 2011-03-05 15:47	--------	d-----r-	C:\AHCache
2011-03-05 14:40 . 2011-03-05 14:40	--------	d-----r-	C:\MSOCache
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-09-28 21:44	1400712	----a-w-	c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"nwiz"="nwiz.exe" [2008-10-07 1630208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"RTHDCPL"="RTHDCPL.EXE" [2008-10-09 17021440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-01-10 281768]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Valve\\hl.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
.
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [5.3.2011 17:44 135336]
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-05 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-09-28 21:44]
.
2011-03-05 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2011-03-05 21:18]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {345230CF-B3FA-4590-AC96-0F0460749CF6} = 10.125.254.254
FF - ProfilePath - c:\documents and settings\fony\Application Data\Mozilla\Firefox\Profiles\k6y9bwa5.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.warxtreme.com/index.php
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Linkification: {35106bca-6c78-48c7-ac28-56df30b51d2a} - %profile%\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2a}
FF - Ext: Greasemonkey: {e4a8a97b-f2ed-450b-b12d-ee082ba24781} - %profile%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
FF - Ext: Download Statusbar: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389} - %profile%\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-05 20:18
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes ...  
.
scanning hidden autostart entries ... 
.
scanning hidden files ...  
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2011-03-05  20:19:50
ComboFix-quarantined-files.txt  2011-03-05 19:19
.
Pre-Run: 40 747 720 704 bytes free
Post-Run: 9 adresárov, 40 859 197 440 voľných bajtov
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - F18FB511E40109B3AB87A9EAD84FC7E1

Re: dlho bez antiviru, vela haveti, kontrola logu prosim

Napsal: 05 bře 2011 21:19
od vyosek
Fony píše:este mam otazku, som dost aktivny na ruskych warezoch a torrentoch
Mam to brat tak ze stahujete nelegalni software apod. :???:

Re: dlho bez antiviru, vela haveti, kontrola logu prosim

Napsal: 05 bře 2011 21:42
od Fony
vyosek píše:
Fony píše:este mam otazku, som dost aktivny na ruskych warezoch a torrentoch
Mam to brat tak ze stahujete nelegalni software apod. :???:
nelegalny ano ale nie software skor ine veci SW preferujem len bez crackov/patchov/keygenov/keymakerov a podobnych prenasacov virov
hlavne hudba a filmy

Re: dlho bez antiviru, vela haveti, kontrola logu prosim

Napsal: 05 bře 2011 21:52
od vyosek
:arrow: Screen z Aviry co jste dal byl ale blby cracku\keygenu a podobnych blbin :?:

:arrow: Nedavejte prosim logy do code

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Folder::
    c:\program files\Ask.com
    
    Registry::
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
    [-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
    [-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Adobe Reader Speed Launcher"=-
    "Adobe ARM"=-
    
    File::
    c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci

Re: dlho bez antiviru, vela haveti, kontrola logu prosim

Napsal: 05 bře 2011 22:16
od Fony
restartlo mi to aj PC ale windows naskocil v pohode a o tomto ask toolbare som pocul nieco ze je to ako virus...



ComboFix 11-03-04.06 - fony 05.03.2011 22:11:14.2.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.421.1033.18.1023.715 [GMT 1:00]
Running from: c:\documents and settings\fony\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\fony\Desktop\CFScript.txt
AV: AntiVir Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
FILE ::
"c:\windows\Tasks\Scheduled Update for Ask Toolbar.job"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Ask.com
c:\program files\Ask.com\cobrand.ico
c:\program files\Ask.com\config.xml
c:\program files\Ask.com\favicon.ico
c:\program files\Ask.com\fv_5c.ico
c:\program files\Ask.com\GenericAskToolbar.dll
c:\program files\Ask.com\mupcfg.xml
c:\program files\Ask.com\SaUpdate.exe
c:\program files\Ask.com\UpdateTask.exe
c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
.
.
((((((((((((((((((((((((( Files Created from 2011-02-05 to 2011-03-05 )))))))))))))))))))))))))))))))
.
.
2011-03-05 18:16 . 2011-03-05 18:17 -------- d-----w- C:\rsit
2011-03-05 15:47 . 2011-03-05 15:47 -------- d-----r- C:\AHCache
2011-03-05 14:40 . 2011-03-05 14:40 -------- d-----r- C:\MSOCache
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((( SnapShot@2011-03-05_19.18.28 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-03-05 19:50 . 2007-01-19 20:15 74802 c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\atl.dll
+ 2011-03-05 08:56 . 2006-03-01 19:42 11776 c:\windows\system32\xolehlp.dll
- 2011-03-05 08:56 . 2004-08-04 12:00 11776 c:\windows\system32\xolehlp.dll
+ 2004-08-04 12:00 . 2006-01-04 03:35 68096 c:\windows\system32\webclnt.dll
+ 2006-03-17 00:38 . 2006-03-17 00:38 28672 c:\windows\system32\verclsid.exe
+ 2004-08-04 12:00 . 2004-12-07 19:32 96768 c:\windows\system32\srvsvc.dll
- 2004-08-04 12:00 . 2004-08-04 12:00 96768 c:\windows\system32\srvsvc.dll
+ 2004-08-04 12:00 . 2005-06-10 23:53 57856 c:\windows\system32\spoolsv.exe
- 2004-08-04 12:00 . 2004-08-04 12:00 57856 c:\windows\system32\spoolsv.exe
+ 2004-08-04 12:00 . 2011-03-05 21:14 49198 c:\windows\system32\perfc009.dat
- 2004-08-04 12:00 . 2011-03-05 17:27 49198 c:\windows\system32\perfc009.dat
+ 2004-08-04 12:00 . 2005-07-26 04:39 37888 c:\windows\system32\olecnv32.dll
+ 2004-08-04 12:00 . 2005-07-26 04:39 74752 c:\windows\system32\olecli32.dll
+ 2004-08-04 12:00 . 2006-10-13 12:35 65536 c:\windows\system32\nwwks.dll
+ 2004-08-04 12:00 . 2006-10-13 12:35 64000 c:\windows\system32\nwapi32.dll
+ 2004-08-04 12:00 . 2008-03-25 04:50 60192 c:\windows\system32\msjter40.dll
+ 2004-08-04 12:00 . 2007-03-08 15:36 40960 c:\windows\system32\mf3216.dll
+ 2004-08-04 12:00 . 2005-09-01 01:41 19968 c:\windows\system32\linkinfo.dll
+ 2004-08-04 12:00 . 2006-06-01 18:47 27648 c:\windows\system32\jgpl400.dll
+ 2004-08-04 12:00 . 2006-05-19 12:59 94720 c:\windows\system32\iphlpapi.dll
- 2004-08-04 12:00 . 2004-08-04 12:00 94720 c:\windows\system32\iphlpapi.dll
+ 2004-08-04 12:00 . 2006-07-21 08:24 72704 c:\windows\system32\hlink.dll
+ 2004-08-04 12:00 . 2005-05-27 02:04 41472 c:\windows\system32\hhsetup.dll
+ 2011-03-05 08:58 . 2006-08-21 09:14 23040 c:\windows\system32\fltmc.exe
- 2011-03-05 08:58 . 2004-08-04 12:00 16896 c:\windows\system32\fltlib.dll
+ 2011-03-05 08:58 . 2006-08-21 12:21 16896 c:\windows\system32\fltlib.dll
- 2011-03-05 09:21 . 2004-08-03 22:15 82944 c:\windows\system32\drivers\wdmaud.sys
+ 2011-03-05 09:21 . 2006-06-14 09:00 82944 c:\windows\system32\drivers\wdmaud.sys
+ 2004-08-04 12:00 . 2007-11-13 10:25 20480 c:\windows\system32\drivers\secdrv.sys
- 2004-08-04 12:00 . 2004-08-04 12:00 45568 c:\windows\system32\dnsrslvr.dll
+ 2004-08-04 12:00 . 2008-02-20 05:32 45568 c:\windows\system32\dnsrslvr.dll
+ 2011-03-05 08:56 . 2006-03-01 19:42 11776 c:\windows\system32\dllcache\xolehlp.dll
- 2011-03-05 08:56 . 2004-08-04 12:00 11776 c:\windows\system32\dllcache\xolehlp.dll
+ 2004-08-04 12:00 . 2006-01-04 03:35 68096 c:\windows\system32\dllcache\webclnt.dll
- 2011-03-05 09:21 . 2004-08-03 22:15 82944 c:\windows\system32\dllcache\wdmaud.sys
+ 2011-03-05 09:21 . 2006-06-14 09:00 82944 c:\windows\system32\dllcache\wdmaud.sys
+ 2011-03-05 08:58 . 2007-05-16 15:12 85504 c:\windows\system32\dllcache\wabimp.dll
- 2004-08-04 12:00 . 2004-08-04 12:00 96768 c:\windows\system32\dllcache\srvsvc.dll
+ 2004-08-04 12:00 . 2004-12-07 19:32 96768 c:\windows\system32\dllcache\srvsvc.dll
+ 2004-08-04 12:00 . 2005-06-10 23:53 57856 c:\windows\system32\dllcache\spoolsv.exe
- 2004-08-04 12:00 . 2004-08-04 12:00 57856 c:\windows\system32\dllcache\spoolsv.exe
+ 2004-08-04 12:00 . 2005-07-26 04:39 37888 c:\windows\system32\dllcache\olecnv32.dll
+ 2004-08-04 12:00 . 2005-07-26 04:39 74752 c:\windows\system32\dllcache\olecli32.dll
+ 2004-08-04 12:00 . 2006-10-13 12:35 65536 c:\windows\system32\dllcache\nwwks.dll
+ 2004-08-04 12:00 . 2006-10-13 12:35 64000 c:\windows\system32\dllcache\nwapi32.dll
+ 2004-08-04 12:00 . 2008-03-25 04:50 60192 c:\windows\system32\dllcache\msjter40.dll
+ 2004-08-04 12:00 . 2007-03-08 15:36 40960 c:\windows\system32\dllcache\mf3216.dll
+ 2004-08-04 12:00 . 2005-09-01 01:41 19968 c:\windows\system32\dllcache\linkinfo.dll
+ 2006-06-01 18:47 . 2006-06-01 18:47 27648 c:\windows\system32\dllcache\jgpl400.dll
+ 2004-08-04 12:00 . 2006-05-19 12:59 94720 c:\windows\system32\dllcache\iphlpapi.dll
- 2004-08-04 12:00 . 2004-08-04 12:00 94720 c:\windows\system32\dllcache\iphlpapi.dll
+ 2004-08-04 12:00 . 2006-07-21 08:24 72704 c:\windows\system32\dllcache\hlink.dll
+ 2004-08-04 12:00 . 2005-05-27 02:04 41472 c:\windows\system32\dllcache\hhsetup.dll
- 2004-08-04 12:00 . 2004-08-04 12:00 10752 c:\windows\system32\dllcache\hh.exe
+ 2004-08-04 12:00 . 2005-05-26 23:22 10752 c:\windows\system32\dllcache\hh.exe
+ 2011-03-05 08:58 . 2006-08-21 09:14 23040 c:\windows\system32\dllcache\fltmc.exe
+ 2011-03-05 08:58 . 2006-08-21 12:21 16896 c:\windows\system32\dllcache\fltlib.dll
- 2011-03-05 08:58 . 2004-08-04 12:00 16896 c:\windows\system32\dllcache\fltlib.dll
- 2004-08-04 12:00 . 2004-08-04 12:00 45568 c:\windows\system32\dllcache\dnsrslvr.dll
+ 2004-08-04 12:00 . 2008-02-20 05:32 45568 c:\windows\system32\dllcache\dnsrslvr.dll
+ 2011-03-05 08:58 . 2007-05-16 15:12 86528 c:\windows\system32\dllcache\directdb.dll
+ 2011-03-05 08:56 . 2005-07-26 04:39 97792 c:\windows\system32\dllcache\comrepl.dll
- 2004-08-04 12:00 . 2004-08-04 12:00 56832 c:\windows\system32\dllcache\authz.dll
+ 2004-08-04 12:00 . 2005-03-02 18:09 56832 c:\windows\system32\dllcache\authz.dll
+ 2004-08-04 12:00 . 2007-03-09 13:46 57344 c:\windows\system32\dllcache\agentdpv.dll
+ 2004-08-04 12:00 . 2006-10-12 14:02 42496 c:\windows\system32\dllcache\agentdp2.dll
+ 2011-03-05 08:56 . 2005-07-26 04:39 97792 c:\windows\system32\comrepl.dll
- 2004-08-04 12:00 . 2004-08-04 12:00 56832 c:\windows\system32\authz.dll
+ 2004-08-04 12:00 . 2005-03-02 18:09 56832 c:\windows\system32\authz.dll
+ 2004-08-04 12:00 . 2007-03-09 13:46 57344 c:\windows\msagent\agentdpv.dll
+ 2004-08-04 12:00 . 2006-10-12 14:02 42496 c:\windows\msagent\agentdp2.dll
+ 2004-08-04 12:00 . 2005-05-26 23:22 10752 c:\windows\hh.exe
- 2004-08-04 12:00 . 2004-08-04 12:00 10752 c:\windows\hh.exe
+ 2006-06-14 09:00 . 2006-06-14 09:00 82944 c:\windows\Driver Cache\i386\wdmaud.sys
+ 2011-03-05 19:52 . 2011-03-05 19:52 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\2b1baeedd37440a5a42d12cf136dfd96\System.Windows.Presentation.ni.dll
+ 2011-03-05 19:52 . 2011-03-05 19:52 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\3027b356d3815032df77cbcc980fd19a\System.AddIn.Contract.ni.dll
+ 2011-03-05 19:52 . 2011-03-05 19:52 15872 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\03fa1aff95db5c71b7fb0c00acb95126\Microsoft.VisualC.ni.dll
+ 2011-03-05 19:51 . 2011-03-05 19:51 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\aa7017f9dbefbd5aebe692efc65a3e5b\dfsvc.ni.exe
+ 2011-03-05 19:51 . 2011-03-05 19:51 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\8f7cb352abc0356968a95d54e2c50ea6\Accessibility.ni.dll
- 2004-08-04 12:00 . 2004-08-04 12:00 8192 c:\windows\system32\rasadhlp.dll
+ 2004-08-04 12:00 . 2006-06-26 17:37 8192 c:\windows\system32\rasadhlp.dll
+ 2011-03-05 09:21 . 2006-06-14 08:47 6400 c:\windows\system32\drivers\splitter.sys
- 2011-03-05 09:21 . 2004-08-03 22:07 6400 c:\windows\system32\drivers\splitter.sys
+ 2011-03-05 09:21 . 2006-06-14 08:47 6400 c:\windows\system32\dllcache\splitter.sys
- 2011-03-05 09:21 . 2004-08-03 22:07 6400 c:\windows\system32\dllcache\splitter.sys
- 2004-08-04 12:00 . 2004-08-04 12:00 8192 c:\windows\system32\dllcache\rasadhlp.dll
+ 2004-08-04 12:00 . 2006-06-26 17:37 8192 c:\windows\system32\dllcache\rasadhlp.dll
- 2011-03-05 09:01 . 2004-08-04 12:00 7680 c:\windows\system32\dllcache\migregdb.exe
+ 2011-03-05 09:01 . 2005-07-25 23:46 7680 c:\windows\system32\dllcache\migregdb.exe
+ 2006-06-14 08:47 . 2006-06-14 08:47 6400 c:\windows\Driver Cache\i386\splitter.sys
+ 2011-03-05 19:50 . 2007-01-19 20:15 401462 c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\msvcp60.dll
+ 2011-03-05 19:50 . 2007-01-19 20:15 995383 c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42.dll
+ 2004-08-04 12:00 . 2007-10-27 16:39 230912 c:\windows\system32\wmasf.dll
+ 2004-08-04 12:00 . 2007-03-17 13:43 292864 c:\windows\system32\winsrv.dll
+ 2004-08-04 12:00 . 2006-12-19 18:16 333824 c:\windows\system32\wiaservc.dll
+ 2004-08-04 12:00 . 2007-03-08 15:36 577536 c:\windows\system32\user32.dll
- 2004-08-04 12:00 . 2004-08-04 12:00 185344 c:\windows\system32\upnphost.dll
+ 2004-08-04 12:00 . 2007-02-05 20:17 185344 c:\windows\system32\upnphost.dll
+ 2004-08-04 12:00 . 2005-08-23 03:35 123392 c:\windows\system32\umpnpmgr.dll
+ 2004-08-04 12:00 . 2005-07-26 04:39 101376 c:\windows\system32\txflog.dll
- 2004-08-04 12:00 . 2004-08-04 12:00 101376 c:\windows\system32\txflog.dll
+ 2004-08-04 12:00 . 2005-07-08 16:27 249344 c:\windows\system32\tapisrv.dll
+ 2004-08-04 12:00 . 2006-10-19 13:56 713216 c:\windows\system32\sxs.dll
- 2004-08-04 12:00 . 2004-08-04 12:00 713216 c:\windows\system32\sxs.dll
- 2004-08-04 12:00 . 2004-08-04 12:00 134656 c:\windows\system32\shsvcs.dll
+ 2004-08-04 12:00 . 2006-12-19 21:52 134656 c:\windows\system32\shsvcs.dll
+ 2004-08-04 12:00 . 2006-11-27 14:54 433152 c:\windows\system32\riched20.dll
+ 2004-08-04 12:00 . 2006-06-22 10:47 181248 c:\windows\system32\rasmans.dll
+ 2004-08-04 12:00 . 2011-03-05 21:14 390094 c:\windows\system32\perfh009.dat
- 2004-08-04 12:00 . 2011-03-05 17:27 390094 c:\windows\system32\perfh009.dat
+ 2004-08-04 12:00 . 2006-10-16 16:15 122880 c:\windows\system32\oledlg.dll
+ 2004-08-04 12:00 . 2007-12-04 18:38 550912 c:\windows\system32\oleaut32.dll
+ 2004-08-04 12:00 . 2006-10-13 12:35 142336 c:\windows\system32\nwprovau.dll
+ 2004-08-04 12:00 . 2005-08-22 18:29 197632 c:\windows\system32\netman.dll
+ 2004-08-04 12:00 . 2008-03-25 04:50 355104 c:\windows\system32\msxbde40.dll
+ 2004-08-04 12:00 . 2008-03-25 04:50 621344 c:\windows\system32\mswstr10.dll
+ 2004-08-04 12:00 . 2008-03-25 04:50 838432 c:\windows\system32\mswdat10.dll
+ 2004-08-04 12:00 . 2008-03-25 04:50 264992 c:\windows\system32\mstext40.dll
+ 2004-08-04 12:00 . 2008-03-25 04:50 559904 c:\windows\system32\msrepl40.dll
+ 2004-08-04 12:00 . 2008-03-25 04:50 322336 c:\windows\system32\msrd3x40.dll
+ 2004-08-04 12:00 . 2008-03-25 04:50 432928 c:\windows\system32\msrd2x40.dll
+ 2004-08-04 12:00 . 2008-03-25 04:50 355104 c:\windows\system32\mspbde40.dll
+ 2004-08-04 12:00 . 2008-03-25 04:50 219936 c:\windows\system32\msltus40.dll
+ 2004-08-04 12:00 . 2008-03-25 04:50 248608 c:\windows\system32\msjtes40.dll
+ 2004-08-04 12:00 . 2008-03-27 08:12 151583 c:\windows\system32\msjint40.dll
- 2004-08-04 12:00 . 2004-08-04 12:00 151583 c:\windows\system32\msjint40.dll
+ 2004-08-04 12:00 . 2008-03-25 04:50 355112 c:\windows\system32\msjetoledb40.dll
+ 2004-08-04 12:00 . 2006-11-27 14:54 539136 c:\windows\system32\msftedit.dll
+ 2004-08-04 12:00 . 2008-03-25 04:50 518944 c:\windows\system32\msexch40.dll
+ 2004-08-04 12:00 . 2008-03-25 04:50 326432 c:\windows\system32\msexcl40.dll
+ 2004-08-04 12:00 . 2006-10-14 08:13 981760 c:\windows\system32\mfc42u.dll
+ 2004-08-04 12:00 . 2006-11-01 19:17 927504 c:\windows\system32\mfc40u.dll
+ 2004-08-04 12:00 . 2006-06-01 18:47 163840 c:\windows\system32\jgdw400.dll
+ 2004-08-04 12:00 . 2005-05-27 02:04 137216 c:\windows\system32\itss.dll
+ 2004-08-04 12:00 . 2005-05-27 02:04 155136 c:\windows\system32\itircl.dll
+ 2004-08-04 12:00 . 2005-06-29 01:46 254976 c:\windows\system32\icm32.dll
+ 2011-03-05 08:56 . 2004-11-17 17:41 347136 c:\windows\system32\hypertrm.dll
+ 2004-08-04 12:00 . 2006-08-22 03:05 498742 c:\windows\system32\dxmasf.dll
+ 2004-08-04 12:00 . 2007-04-23 10:32 364160 c:\windows\system32\drivers\update.sys
+ 2011-03-05 08:56 . 2005-06-10 04:09 139528 c:\windows\system32\drivers\rdpwd.sys
+ 2004-08-04 12:00 . 2006-05-05 09:47 174592 c:\windows\system32\drivers\rdbss.sys
+ 2004-08-04 12:00 . 2006-10-13 10:23 163584 c:\windows\system32\drivers\nwrdr.sys
- 2004-08-04 12:00 . 2004-08-04 12:00 163584 c:\windows\system32\drivers\nwrdr.sys
+ 2004-08-04 12:00 . 2007-02-09 11:10 574464 c:\windows\system32\drivers\ntfs.sys
+ 2004-08-04 12:00 . 2007-12-18 09:51 179584 c:\windows\system32\drivers\mrxdav.sys
+ 2011-03-05 09:21 . 2006-06-14 08:47 172416 c:\windows\system32\drivers\kmixer.sys
- 2004-08-04 12:00 . 2004-08-04 12:00 134912 c:\windows\system32\drivers\ipnat.sys
+ 2004-08-04 12:00 . 2004-09-29 22:28 134912 c:\windows\system32\drivers\ipnat.sys
+ 2004-08-04 12:00 . 2006-03-17 00:33 262784 c:\windows\system32\drivers\http.sys
+ 2011-03-05 08:58 . 2006-08-21 09:14 128896 c:\windows\system32\drivers\fltmgr.sys
- 2011-03-05 09:21 . 2004-08-03 21:39 142464 c:\windows\system32\drivers\aec.sys
+ 2011-03-05 09:21 . 2006-02-15 00:22 142464 c:\windows\system32\drivers\aec.sys
+ 2004-08-04 12:00 . 2007-10-27 16:39 230912 c:\windows\system32\dllcache\wmasf.dll
+ 2004-08-04 12:00 . 2007-03-17 13:43 292864 c:\windows\system32\dllcache\winsrv.dll
+ 2004-08-04 12:00 . 2006-12-19 18:16 333824 c:\windows\system32\dllcache\wiaservc.dll
+ 2011-03-05 08:58 . 2007-05-16 15:12 510976 c:\windows\system32\dllcache\wab32.dll
+ 2011-03-05 08:58 . 2007-06-26 15:13 851968 c:\windows\system32\dllcache\vgx.dll
+ 2004-08-04 12:00 . 2007-03-08 15:36 577536 c:\windows\system32\dllcache\user32.dll
- 2004-08-04 12:00 . 2004-08-04 12:00 185344 c:\windows\system32\dllcache\upnphost.dll
+ 2004-08-04 12:00 . 2007-02-05 20:17 185344 c:\windows\system32\dllcache\upnphost.dll
+ 2004-08-04 12:00 . 2007-04-23 10:32 364160 c:\windows\system32\dllcache\update.sys
+ 2004-08-04 12:00 . 2005-08-23 03:35 123392 c:\windows\system32\dllcache\umpnpmgr.dll
- 2004-08-04 12:00 . 2004-08-04 12:00 101376 c:\windows\system32\dllcache\txflog.dll
+ 2004-08-04 12:00 . 2005-07-26 04:39 101376 c:\windows\system32\dllcache\txflog.dll
+ 2004-08-04 12:00 . 2005-07-08 16:27 249344 c:\windows\system32\dllcache\tapisrv.dll
- 2004-08-04 12:00 . 2004-08-04 12:00 713216 c:\windows\system32\dllcache\sxs.dll
+ 2004-08-04 12:00 . 2006-10-19 13:56 713216 c:\windows\system32\dllcache\sxs.dll
+ 2004-08-04 12:00 . 2006-12-19 21:52 134656 c:\windows\system32\dllcache\shsvcs.dll
- 2004-08-04 12:00 . 2004-08-04 12:00 134656 c:\windows\system32\dllcache\shsvcs.dll
+ 2004-08-04 12:00 . 2006-11-27 14:54 433152 c:\windows\system32\dllcache\riched20.dll
+ 2011-03-05 08:56 . 2005-06-10 04:09 139528 c:\windows\system32\dllcache\rdpwd.sys
+ 2004-08-04 12:00 . 2006-05-05 09:47 174592 c:\windows\system32\dllcache\rdbss.sys
+ 2004-08-04 12:00 . 2006-06-22 10:47 181248 c:\windows\system32\dllcache\rasmans.dll
+ 2004-08-04 12:00 . 2006-10-16 16:15 122880 c:\windows\system32\dllcache\oledlg.dll
+ 2004-08-04 12:00 . 2007-12-04 18:38 550912 c:\windows\system32\dllcache\oleaut32.dll
+ 2004-08-04 12:00 . 2006-10-13 10:23 163584 c:\windows\system32\dllcache\nwrdr.sys
- 2004-08-04 12:00 . 2004-08-04 12:00 163584 c:\windows\system32\dllcache\nwrdr.sys
+ 2004-08-04 12:00 . 2006-10-13 12:35 142336 c:\windows\system32\dllcache\nwprovau.dll
+ 2004-08-04 12:00 . 2007-02-09 11:10 574464 c:\windows\system32\dllcache\ntfs.sys
+ 2011-03-05 08:58 . 2005-11-29 15:27 364544 c:\windows\system32\dllcache\npdsplay.dll
- 2011-03-05 08:58 . 2004-08-04 12:00 364544 c:\windows\system32\dllcache\npdsplay.dll
+ 2004-08-04 12:00 . 2005-08-22 18:29 197632 c:\windows\system32\dllcache\netman.dll
+ 2004-08-04 12:00 . 2008-03-25 04:50 355104 c:\windows\system32\dllcache\msxbde40.dll
+ 2004-08-04 12:00 . 2008-03-25 04:50 621344 c:\windows\system32\dllcache\mswstr10.dll
+ 2004-08-04 12:00 . 2008-03-25 04:50 838432 c:\windows\system32\dllcache\mswdat10.dll
+ 2004-08-04 12:00 . 2008-03-25 04:50 264992 c:\windows\system32\dllcache\mstext40.dll
+ 2004-08-04 12:00 . 2008-03-25 04:50 559904 c:\windows\system32\dllcache\msrepl40.dll
+ 2004-08-04 12:00 . 2008-03-25 04:50 322336 c:\windows\system32\dllcache\msrd3x40.dll
+ 2004-08-04 12:00 . 2008-03-25 04:50 432928 c:\windows\system32\dllcache\msrd2x40.dll
+ 2004-08-04 12:00 . 2008-03-25 04:50 355104 c:\windows\system32\dllcache\mspbde40.dll
+ 2004-08-04 12:00 . 2008-03-25 04:50 219936 c:\windows\system32\dllcache\msltus40.dll
+ 2004-08-04 12:00 . 2008-03-25 04:50 248608 c:\windows\system32\dllcache\msjtes40.dll
+ 2011-03-05 08:58 . 2006-12-26 13:07 102400 c:\windows\system32\dllcache\msjro.dll
- 2011-03-05 08:58 . 2004-08-04 12:00 102400 c:\windows\system32\dllcache\msjro.dll
+ 2004-08-04 12:00 . 2008-03-27 08:12 151583 c:\windows\system32\dllcache\msjint40.dll
- 2004-08-04 12:00 . 2004-08-04 12:00 151583 c:\windows\system32\dllcache\msjint40.dll
+ 2004-08-04 12:00 . 2008-03-25 04:50 355112 c:\windows\system32\dllcache\msjetol1.dll
+ 2004-08-04 12:00 . 2006-11-27 14:54 539136 c:\windows\system32\dllcache\msftedit.dll
+ 2004-08-04 12:00 . 2008-03-25 04:50 518944 c:\windows\system32\dllcache\msexch40.dll
+ 2004-08-04 12:00 . 2008-03-25 04:50 326432 c:\windows\system32\dllcache\msexcl40.dll
- 2011-03-05 08:58 . 2004-08-04 12:00 200704 c:\windows\system32\dllcache\msadox.dll
+ 2011-03-05 08:58 . 2006-12-26 13:07 200704 c:\windows\system32\dllcache\msadox.dll
+ 2011-03-05 08:58 . 2006-12-26 13:07 180224 c:\windows\system32\dllcache\msadomd.dll
- 2011-03-05 08:58 . 2004-08-04 12:00 180224 c:\windows\system32\dllcache\msadomd.dll
+ 2011-03-05 08:58 . 2006-12-26 13:07 536576 c:\windows\system32\dllcache\msado15.dll
- 2011-03-05 08:58 . 2004-08-04 12:00 536576 c:\windows\system32\dllcache\msado15.dll
- 2011-03-05 08:58 . 2004-08-04 12:00 143360 c:\windows\system32\dllcache\msadco.dll
+ 2011-03-05 08:58 . 2006-03-23 05:44 143360 c:\windows\system32\dllcache\msadco.dll
+ 2004-08-04 12:00 . 2007-12-18 09:51 179584 c:\windows\system32\dllcache\mrxdav.sys
+ 2004-08-04 12:00 . 2006-10-14 08:13 981760 c:\windows\system32\dllcache\mfc42u.dll
+ 2004-08-04 12:00 . 2006-11-01 19:17 927504 c:\windows\system32\dllcache\mfc40u.dll
+ 2011-03-05 09:21 . 2006-06-14 08:47 172416 c:\windows\system32\dllcache\kmixer.sys
+ 2006-06-01 18:47 . 2006-06-01 18:47 163840 c:\windows\system32\dllcache\jgdw400.dll
+ 2004-08-04 12:00 . 2005-05-27 02:04 137216 c:\windows\system32\dllcache\itss.dll
+ 2004-08-04 12:00 . 2005-05-27 02:04 155136 c:\windows\system32\dllcache\itircl.dll
- 2004-08-04 12:00 . 2004-08-04 12:00 134912 c:\windows\system32\dllcache\ipnat.sys
+ 2004-08-04 12:00 . 2004-09-29 22:28 134912 c:\windows\system32\dllcache\ipnat.sys
+ 2004-08-04 12:00 . 2005-06-29 01:46 254976 c:\windows\system32\dllcache\icm32.dll
+ 2011-03-05 08:58 . 2006-08-21 09:14 128896 c:\windows\system32\dllcache\fltmgr.sys
+ 2004-08-04 12:00 . 2006-08-22 03:05 498742 c:\windows\system32\dllcache\dxmasf.dll
+ 2004-08-04 12:00 . 2006-05-19 12:59 111616 c:\windows\system32\dllcache\dhcpcsvc.dll
+ 2011-03-05 08:58 . 2008-03-25 04:50 554008 c:\windows\system32\dllcache\dao360.dll
- 2011-03-05 08:56 . 2004-08-04 12:00 540160 c:\windows\system32\dllcache\comuid.dll
+ 2011-03-05 08:56 . 2005-07-26 04:39 540160 c:\windows\system32\dllcache\comuid.dll
+ 2004-08-04 12:00 . 2006-08-25 15:45 617472 c:\windows\system32\dllcache\comctl32.dll
+ 2011-03-05 08:56 . 2005-07-26 04:39 195072 c:\windows\system32\dllcache\comadmin.dll
+ 2011-03-05 08:56 . 2005-07-26 04:39 498688 c:\windows\system32\dllcache\clbcatq.dll
- 2011-03-05 08:56 . 2004-08-04 12:00 110080 c:\windows\system32\dllcache\clbcatex.dll
+ 2011-03-05 08:56 . 2005-07-26 04:39 110080 c:\windows\system32\dllcache\clbcatex.dll
+ 2011-03-05 08:56 . 2005-07-26 04:39 625152 c:\windows\system32\dllcache\catsrvut.dll
+ 2011-03-05 08:56 . 2005-07-26 04:39 225792 c:\windows\system32\dllcache\catsrv.dll
+ 2004-08-04 12:00 . 2006-10-12 11:09 256512 c:\windows\system32\dllcache\agentsvr.exe
- 2004-08-04 12:00 . 2004-08-04 12:00 256512 c:\windows\system32\dllcache\agentsvr.exe
+ 2011-03-05 09:21 . 2006-02-15 00:22 142464 c:\windows\system32\dllcache\aec.sys
- 2011-03-05 09:21 . 2004-08-03 21:39 142464 c:\windows\system32\dllcache\aec.sys
+ 2004-08-04 12:00 . 2006-05-19 12:59 111616 c:\windows\system32\dhcpcsvc.dll
+ 2011-03-05 08:56 . 2005-07-26 04:39 540160 c:\windows\system32\comuid.dll
- 2011-03-05 08:56 . 2004-08-04 12:00 540160 c:\windows\system32\comuid.dll
+ 2004-08-04 12:00 . 2006-08-25 15:45 617472 c:\windows\system32\comctl32.dll
+ 2011-03-05 08:56 . 2005-07-26 04:39 195072 c:\windows\system32\Com\comadmin.dll
+ 2011-03-05 08:56 . 2005-07-26 04:39 498688 c:\windows\system32\clbcatq.dll
- 2011-03-05 08:56 . 2004-08-04 12:00 110080 c:\windows\system32\clbcatex.dll
+ 2011-03-05 08:56 . 2005-07-26 04:39 110080 c:\windows\system32\clbcatex.dll
+ 2011-03-05 08:56 . 2005-07-26 04:39 625152 c:\windows\system32\catsrvut.dll
+ 2011-03-05 08:56 . 2005-07-26 04:39 225792 c:\windows\system32\catsrv.dll
+ 2004-08-04 12:00 . 2006-10-12 11:09 256512 c:\windows\msagent\agentsvr.exe
- 2004-08-04 12:00 . 2004-08-04 12:00 256512 c:\windows\msagent\agentsvr.exe
+ 2006-06-14 08:47 . 2006-06-14 08:47 172416 c:\windows\Driver Cache\i386\kmixer.sys
+ 2006-03-17 00:33 . 2006-03-17 00:33 262784 c:\windows\Driver Cache\i386\http.sys
+ 2006-02-15 00:22 . 2006-02-15 00:22 142464 c:\windows\Driver Cache\i386\aec.sys
+ 2011-03-05 19:52 . 2011-03-05 19:52 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\ec8873ab421e304d56238ac16240b9ae\System.Xml.Linq.ni.dll
+ 2011-03-05 19:52 . 2011-03-05 19:52 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\92575e0796924df0487fe6817b7bd032\System.Transactions.ni.dll
+ 2011-03-05 19:52 . 2011-03-05 19:52 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\b6ea34692f91c59d68558eac913c9776\System.ServiceProcess.ni.dll
+ 2011-03-05 19:52 . 2011-03-05 19:52 676352 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\d23d6f603493554a3ec7c0971e2a568a\System.Security.ni.dll
+ 2011-03-05 19:52 . 2011-03-05 19:52 311296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\00ad2a27bd042bc342d83de29f118683\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2011-03-05 19:52 . 2011-03-05 19:52 758784 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\5e43233be63660c2e064e04c5307c1dc\System.Runtime.Remoting.ni.dll
+ 2011-03-05 19:52 . 2011-03-05 19:52 620032 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\9440a7296e529074a0db655e7bfe1aa1\System.Net.ni.dll
+ 2011-03-05 19:52 . 2011-03-05 19:52 593408 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Messaging\0d1cc1d6b56d6c15bdc56cfb1d3a345b\System.Messaging.ni.dll
+ 2011-03-05 19:52 . 2011-03-05 19:52 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\3ed32a29af34a50a8ef959f3a4eb4404\System.EnterpriseServices.Wrapper.dll
+ 2011-03-05 19:52 . 2011-03-05 19:52 627712 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\3ed32a29af34a50a8ef959f3a4eb4404\System.EnterpriseServices.ni.dll
+ 2011-03-05 19:52 . 2011-03-05 19:52 939520 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\de7f0722af401ea33067297981a3b5ed\System.Data.Services.Client.ni.dll
+ 2011-03-05 19:52 . 2011-03-05 19:52 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\1251c275ae3b3a2e17c3f53f864d96a9\System.Data.DataSetExtensions.ni.dll
+ 2011-03-05 19:52 . 2011-03-05 19:52 970752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\eecd056989bb157d03094acde93890e2\System.Configuration.ni.dll
+ 2011-03-05 19:52 . 2011-03-05 19:52 140800 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\60f0f7f55ab174aed225d1b1e899a4ae\System.Configuration.Install.ni.dll
+ 2011-03-05 19:52 . 2011-03-05 19:52 632832 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\9660d4e5325b8d504adc18fc6058f2a1\System.AddIn.ni.dll
+ 2011-03-05 19:51 . 2011-03-05 19:51 255488 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\49b19ff0815829d3f152ef1a146d2987\SMDiagnostics.ni.dll
+ 2011-03-05 19:51 . 2011-03-05 19:51 304128 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\0a7eb099ac5955efa6c6384553229319\ServiceModelReg.ni.exe
+ 2011-03-05 19:51 . 2011-03-05 19:51 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\761b0413d2816e1b374f2ea87bc00b9f\CustomMarshalers.ni.dll
+ 2011-03-05 19:48 . 2006-08-25 15:45 1054208 c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
+ 2011-03-05 19:50 . 2007-01-19 20:15 1011774 c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42u.dll
+ 2004-08-04 12:00 . 2007-10-27 16:37 2109440 c:\windows\system32\wmvcore.dll
+ 2004-08-04 12:00 . 2005-07-26 04:39 1285120 c:\windows\system32\ole32.dll
+ 2004-08-04 12:00 . 2008-03-25 04:50 1516568 c:\windows\system32\msjet40.dll
+ 2004-08-04 12:00 . 2005-10-20 22:20 1082368 c:\windows\system32\esent.dll
- 2004-08-04 12:00 . 2004-08-04 12:00 1082368 c:\windows\system32\esent.dll
+ 2004-08-04 12:00 . 2007-10-27 16:37 2109440 c:\windows\system32\dllcache\wmvcore.dll
+ 2004-08-04 12:00 . 2005-07-26 04:39 1285120 c:\windows\system32\dllcache\ole32.dll
+ 2004-08-04 12:00 . 2008-03-25 04:50 1516568 c:\windows\system32\dllcache\msjet40.dll
+ 2004-08-04 12:00 . 2007-06-13 10:23 1033216 c:\windows\system32\dllcache\explorer.exe
+ 2004-08-04 12:00 . 2005-10-20 22:20 1082368 c:\windows\system32\dllcache\esent.dll
- 2004-08-04 12:00 . 2004-08-04 12:00 1082368 c:\windows\system32\dllcache\esent.dll
+ 2011-03-05 08:56 . 2005-07-26 04:39 1267200 c:\windows\system32\dllcache\comsvcs.dll
+ 2004-08-04 12:00 . 2005-09-10 01:53 2067968 c:\windows\system32\dllcache\cdosys.dll
- 2004-08-04 12:00 . 2004-08-04 12:00 2067968 c:\windows\system32\dllcache\cdosys.dll
+ 2011-03-05 08:56 . 2005-07-26 04:39 1267200 c:\windows\system32\comsvcs.dll
- 2004-08-04 12:00 . 2004-08-04 12:00 2067968 c:\windows\system32\cdosys.dll
+ 2004-08-04 12:00 . 2005-09-10 01:53 2067968 c:\windows\system32\cdosys.dll
+ 2004-08-04 12:00 . 2007-06-13 10:23 1033216 c:\windows\explorer.exe
+ 2011-03-05 19:52 . 2011-03-05 19:52 1797120 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\d6ef39a102bd49fd66a5fbb9da43a628\System.Web.Services.ni.dll
+ 2011-03-05 19:52 . 2011-03-05 19:52 1704448 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\ffd5027ac56b34efbe63e15e34dafabf\System.ServiceModel.Web.ni.dll
+ 2011-03-05 19:50 . 2011-03-05 19:50 2338304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\d5be58c13b53ed3b74a6b05245cd5aa8\System.Runtime.Serialization.ni.dll
+ 2011-03-05 19:50 . 2011-03-05 19:50 1055744 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\00257661d50377805f0c64115574b942\System.IdentityModel.ni.dll
+ 2011-03-05 19:52 . 2011-03-05 19:52 1116672 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\c7e420095ee79f9559cdc0325c7db97e\System.DirectoryServices.ni.dll
+ 2011-03-05 19:52 . 2011-03-05 19:52 1800704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\def1ced8a1e3a015da82f5239fca1693\System.Deployment.ni.dll
+ 2011-03-05 19:52 . 2011-03-05 19:52 2508800 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\c455910808f8d8165d4c9127c1ff8735\System.Data.SqlXml.ni.dll
+ 2011-03-05 19:51 . 2011-03-05 19:51 1711104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\2c649ae4737b954485b1acdcd2bc632a\Microsoft.VisualBasic.ni.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"nwiz"="nwiz.exe" [2008-10-07 1630208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"RTHDCPL"="RTHDCPL.EXE" [2008-10-09 17021440]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-01-10 281768]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Valve\\hl.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
.
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [5.3.2011 17:44 135336]
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-05 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2011-03-05 21:18]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = hxxp://www.avira.com/
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {345230CF-B3FA-4590-AC96-0F0460749CF6} = 10.125.254.254
FF - ProfilePath - c:\documents and settings\fony\Application Data\Mozilla\Firefox\Profiles\k6y9bwa5.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.warxtreme.com/index.php
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Linkification: {35106bca-6c78-48c7-ac28-56df30b51d2a} - %profile%\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2a}
FF - Ext: Greasemonkey: {e4a8a97b-f2ed-450b-b12d-ee082ba24781} - %profile%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
FF - Ext: Download Statusbar: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389} - %profile%\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-05 22:14
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2011-03-05 22:16:00
ComboFix-quarantined-files.txt 2011-03-05 21:15
ComboFix2.txt 2011-03-05 19:19
.
Pre-Run: 39 512 670 208 bytes free
Post-Run: 9 adresárov, 39 499 128 832 voľných bajtov
.
- - End Of File - - B5891B241EC1F10BF311F97AB42F6DAB

Re: dlho bez antiviru, vela haveti, kontrola logu prosim

Napsal: 06 bře 2011 08:33
od vyosek
:arrow: Ano, veci od ask.com jsou vetsinou haveti, proto jsem jej taky odstrelil

:arrow: Stahnete Malwarebytes' Anti-Malware (zkracene MBAM) (viz muj podpis)
  • Provedte aktualizaci - treti zalozka
  • Provedte uplny sken - nic nemazte :!:
  • MBAM miva obcas falesne detekce, proto vlozte log do prispevku a pockejte na posouzeni

Re: dlho bez antiviru, vela haveti, kontrola logu prosim

Napsal: 06 bře 2011 09:56
od Fony
pocas kontroly ktora este stale trva mi na C: naslo 5 malware zatial ale mam zapnutu aj aviru a ona to chce odstranit teda presunut do karanteny, ignorovat aviru alebo to presunut?

Obrázek

zatial len dokoncieva C:

Re: dlho bez antiviru, vela haveti, kontrola logu prosim

Napsal: 06 bře 2011 10:06
od vyosek
Sup s nimi do karanteny...kdyztak ted Aviru pocas skenu vypnete, at do toho nekeca :James008:

Re: dlho bez antiviru, vela haveti, kontrola logu prosim

Napsal: 06 bře 2011 11:10
od Fony
haveti pozehnane na to ze PC presiel za posledne 2 dni asi troma celkovymi kontrolami 2 roznych antivirov



Malwarebytes' Anti-Malware 1.50.1.1100
http://www.malwarebytes.org

Verzia databázy: 5972

Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

6.3.2011 11:10:30
mbam-log-2011-03-06 (11-10-28).txt

Typ kontroly: Úplná kontrola (C:\|D:\|E:\|)
Objektov kontrolovaných: 334397
Uplynutý čas: 1 hod, 36 min, 41 sek

Infikované služby pamäte: 0
Infikované moduly pamäte: 0
Infikované registračné kľúče: 0
Infikované registračné hodnoty: 0
Infikované položky registračných dát: 0
Infikované priečinky: 0
Infikované súbory: 163

Infikované služby pamäte:
(Škodlivé položky neboli zistené)

Infikované moduly pamäte:
(Škodlivé položky neboli zistené)

Infikované registračné kľúče:
(Škodlivé položky neboli zistené)

Infikované registračné hodnoty:
(Škodlivé položky neboli zistené)

Infikované položky registračných dát:
(Škodlivé položky neboli zistené)

Infikované priečinky:
(Škodlivé položky neboli zistené)

Infikované súbory:
d:\nhx.exe (Spyware.OnlineGames) -> No action taken.
d:\lhhr8.exe (Spyware.OnlineGames) -> No action taken.
d:\utcddeq.exe (Spyware.OnlineGames) -> No action taken.
d:\y6cqb2is.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{6f51e662-f0c6-4e30-95fc-f6e3d73ed812}\RP37\A0003477.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{6f51e662-f0c6-4e30-95fc-f6e3d73ed812}\RP37\A0003498.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{6f51e662-f0c6-4e30-95fc-f6e3d73ed812}\RP37\A0004499.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{6f51e662-f0c6-4e30-95fc-f6e3d73ed812}\RP37\A0005498.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{6f51e662-f0c6-4e30-95fc-f6e3d73ed812}\RP37\A0006498.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{94d7a231-4547-4eb3-9a37-b2e38bd5395b}\RP11\A0021346.exe (RiskWare.Tool.CK) -> No action taken.
d:\system volume information\_restore{94d7a231-4547-4eb3-9a37-b2e38bd5395b}\RP11\A0021332.EXE (Trojan.Downloader) -> No action taken.
d:\system volume information\_restore{94d7a231-4547-4eb3-9a37-b2e38bd5395b}\RP11\A0021333.exe (Backdoor.Bot) -> No action taken.
d:\system volume information\_restore{94d7a231-4547-4eb3-9a37-b2e38bd5395b}\RP11\A0021334.exe (Trojan.Agent) -> No action taken.
d:\system volume information\_restore{94d7a231-4547-4eb3-9a37-b2e38bd5395b}\RP11\A0021336.exe (Trojan.Agent) -> No action taken.
d:\system volume information\_restore{94d7a231-4547-4eb3-9a37-b2e38bd5395b}\RP11\A0021337.exe (Trojan.Agent) -> No action taken.
d:\system volume information\_restore{94d7a231-4547-4eb3-9a37-b2e38bd5395b}\RP11\A0021338.exe (Trojan.Agent) -> No action taken.
d:\system volume information\_restore{94d7a231-4547-4eb3-9a37-b2e38bd5395b}\RP11\A0021339.exe (Trojan.Agent) -> No action taken.
d:\system volume information\_restore{94d7a231-4547-4eb3-9a37-b2e38bd5395b}\RP11\A0021340.exe (Trojan.Agent) -> No action taken.
d:\system volume information\_restore{94d7a231-4547-4eb3-9a37-b2e38bd5395b}\RP11\A0021341.exe (Trojan.Crax) -> No action taken.
d:\system volume information\_restore{94d7a231-4547-4eb3-9a37-b2e38bd5395b}\RP11\A0021342.exe (Trojan.Agent) -> No action taken.
d:\system volume information\_restore{94d7a231-4547-4eb3-9a37-b2e38bd5395b}\RP11\A0021348.exe (Trojan.Agent.CK) -> No action taken.
d:\system volume information\_restore{94d7a231-4547-4eb3-9a37-b2e38bd5395b}\RP11\A0021349.exe (Trojan.Downloader) -> No action taken.
d:\system volume information\_restore{94d7a231-4547-4eb3-9a37-b2e38bd5395b}\RP11\A0021351.exe (Trojan.Agent.CK) -> No action taken.
d:\system volume information\_restore{94d7a231-4547-4eb3-9a37-b2e38bd5395b}\RP11\A0021353.exe (TrojanProxy.Horst) -> No action taken.
d:\system volume information\_restore{94d7a231-4547-4eb3-9a37-b2e38bd5395b}\RP11\A0021355.exe (RiskWare.Tool.CK) -> No action taken.
d:\system volume information\_restore{94d7a231-4547-4eb3-9a37-b2e38bd5395b}\RP11\A0021358.exe (Trojan.Horst) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP1\A0000021.exe (Trojan.IRCBot) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP1\A0000022.exe (Trojan.IRCBot) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP16\A0002149.exe (RiskWare.Tool.CK) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP16\A0002151.exe (Trojan.Dropper.PGen) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP16\A0002152.exe (Malware.Packer.Gen) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP16\A0002156.exe (Trojan.IRCBot) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP16\A0002526.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP16\A0002527.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP16\A0002528.exe (Trojan.Agent.Gen) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP16\A0002529.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP16\A0002530.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP16\A0002531.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP16\A0002532.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP16\A0002533.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP16\A0002534.exe (Worm.Taterf) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP16\A0002535.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP16\A0002536.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP16\A0002537.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP16\A0002538.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP16\A0002539.exe (Spyware.OnLineGames) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP16\A0002540.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP16\A0002542.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP16\A0002543.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP16\A0002544.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP16\A0002545.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP16\A0002546.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP18\A0003636.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP18\A0003637.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP18\A0003638.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP18\A0003639.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP6\A0000453.exe (Trojan.Dropper.PGen) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP6\A0000455.exe (Trojan.Downloader) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP6\A0000456.exe (Trojan.Downloader) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP6\A0000460.exe (Malware.Packer.Gen) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP6\A0000461.exe (Trojan.Downloader) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP6\A0000462.exe (Trojan.Downloader) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP6\A0000463.exe (Trojan.Downloader) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP6\A0000469.exe (Backdoor.IRCBot) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP6\A0000468.exe (Backdoor.RBot) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP6\A0000707.EXE (Dont.Steal.Our.Software) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP6\A0000708.exe (Trojan.Agent.CK) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP6\A0000710.exe (Trojan.Agent.CK) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP6\A0000722.exe (Trojan.IRCBot) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP6\A0000723.exe (Trojan.IRCBot) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP6\A0000749.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP6\A0000750.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP6\A0000751.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP6\A0000752.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP6\A0000753.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP6\A0000754.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP6\A0000755.exe (Worm.Taterf) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP6\A0000756.exe (Worm.Taterf) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP6\A0000757.exe (Worm.Taterf) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP6\A0000759.exe (Worm.AutoRun) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP6\A0000760.exe (Worm.Taterf) -> No action taken.
d:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP6\A0000761.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{b00a15e8-c6b0-43e6-8e45-d4a2ae692885}\RP7\A0000329.exe (Malware.Packer.Gen) -> No action taken.
d:\system volume information\_restore{b00a15e8-c6b0-43e6-8e45-d4a2ae692885}\RP7\A0000694.exe (RiskWare.Tool.CK) -> No action taken.
d:\system volume information\_restore{b00a15e8-c6b0-43e6-8e45-d4a2ae692885}\RP7\A0000697.exe (Trojan.Agent.CK) -> No action taken.
d:\system volume information\_restore{b00a15e8-c6b0-43e6-8e45-d4a2ae692885}\RP7\A0001202.exe (Trojan.Agent) -> No action taken.
d:\system volume information\_restore{d77e88d3-f04c-4efe-b203-c95410811d8d}\RP1\A0000076.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{db137947-a8b0-4561-af42-db894cf1aaf2}\RP23\A0006641.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{db137947-a8b0-4561-af42-db894cf1aaf2}\RP23\A0006685.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{db137947-a8b0-4561-af42-db894cf1aaf2}\RP23\A0006793.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{db137947-a8b0-4561-af42-db894cf1aaf2}\RP23\A0007913.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{db137947-a8b0-4561-af42-db894cf1aaf2}\RP24\A0008088.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{db137947-a8b0-4561-af42-db894cf1aaf2}\RP24\A0008371.exe (Spyware.OnlineGames) -> No action taken.
d:\system volume information\_restore{18548e0c-893b-4617-8003-47ec68a00ea2}\RP1\A0005805.ExE (RiskWare.Agent.CK) -> No action taken.
d:\system volume information\_restore{18548e0c-893b-4617-8003-47ec68a00ea2}\RP2\A0005838.exe (Trojan.Agent.CK) -> No action taken.
d:\Programs\mp3cutterplussetup.exe (Adware.Relevantknowledge) -> No action taken.
d:\Programs\sony vegas movie studio platinum 9.0a build 85\PATCH\patch.exe (Trojan.Downloader) -> No action taken.
d:\Programs\instal setupy\ventrilo-2.1.4-windows-i386.exe (Trojan.Dropper) -> No action taken.
d:\Programs\ultraedit 14.20.1.1000\KEYGEN\CORE10k.EXE (Dont.Steal.Our.Software) -> No action taken.
d:\Programs\macromedia flash 8 cz\cz\flash studio 8 duležite\Keygen.exe (RiskWare.Tool.CK) -> No action taken.
d:\Programs\macromediaflash v.8_full+cz\keygen.exe (RiskWare.Tool.CK) -> No action taken.
d:\Programs\fix-it utilities 8.0.2.2 professional\KeyGen\keygen.exe (Trojan.Dropper.PGen) -> No action taken.
d:\Programs\mediamonkey gold 3.0.5.1186 cz\KEYGEN\keygen.exe (Trojan.Dropper.PGen) -> No action taken.
d:\Programs\microsoft office 2007&2003 sk\Bonus\keygen.exe (RiskWare.Tool.CK) -> No action taken.
d:\Programs\error repair professional 3.8.8\erpsetup388.exe (Rogue.ErrorRepairProfessional) -> No action taken.
d:\Programs\PORTABLE\adobe premiere pro cs3\MSVCP60.DLL (Malware.Packer.Gen) -> No action taken.
d:\Programs\PORTABLE\ms office 2003 sp3+mathtype\thinstall\OFicce\1000000800002i\svchost.exe (Rootkit.Dropper) -> No action taken.
d:\Programs\PORTABLE\ms office 2003 sp3+mathtype\thinstall\OFicce\4000001e800002i\MathType.exe (Rootkit.Dropper) -> No action taken.
d:\Programs\PORTABLE\Opera 9.50\Opera\opera.exe (Spyware.Passwords.XGen) -> No action taken.
d:\Programs\PORTABLE\portable adobe illustrator cs3\program data\400000bb200002i\Bridge.exe (Trojan.IRCBot) -> No action taken.
d:\Programs\prg_2.9.4\keygen\CORE10k.EXE (Dont.Steal.Our.Software) -> No action taken.
d:\Programs\prg_2.9.4\keygen\keygen.exe (Trojan.Agent) -> No action taken.
d:\Programs\pdffactory 3.38\KEYGEN\keygen.exe (RiskWare.Tool.CK) -> No action taken.
e:\pdffactory_3.50_pro_tdw\keygen - zwt\keygen.exe (RiskWare.Tool.CK) -> No action taken.
e:\system volume information\_restore{6f51e662-f0c6-4e30-95fc-f6e3d73ed812}\RP37\A0003479.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{6f51e662-f0c6-4e30-95fc-f6e3d73ed812}\RP37\A0003500.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{6f51e662-f0c6-4e30-95fc-f6e3d73ed812}\RP37\A0004501.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{6f51e662-f0c6-4e30-95fc-f6e3d73ed812}\RP37\A0005500.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{6f51e662-f0c6-4e30-95fc-f6e3d73ed812}\RP37\A0006500.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000768.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000769.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000770.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000771.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000772.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000773.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000774.exe (Worm.Taterf) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000775.exe (Worm.Taterf) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000776.exe (Worm.Taterf) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000778.exe (Worm.AutoRun) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000779.exe (Worm.Taterf) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000780.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000781.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000782.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000789.exe (Malware.Packer.Gen) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000790.exe (Trojan.Agent.Gen) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000791.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000792.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000793.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000794.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000795.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000796.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000797.exe (Worm.Taterf) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000798.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000800.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000801.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000804.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000806.exe (Spyware.OnLineGames) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000807.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000809.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000810.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000811.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000812.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000813.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000814.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000815.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{a917d83b-85f0-4fcb-b4de-4f4c4438aac1}\RP7\A0000805.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{d77e88d3-f04c-4efe-b203-c95410811d8d}\RP1\A0000078.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{db137947-a8b0-4561-af42-db894cf1aaf2}\RP23\A0006643.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{db137947-a8b0-4561-af42-db894cf1aaf2}\RP23\A0006687.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{db137947-a8b0-4561-af42-db894cf1aaf2}\RP23\A0006795.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{db137947-a8b0-4561-af42-db894cf1aaf2}\RP23\A0007915.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{db137947-a8b0-4561-af42-db894cf1aaf2}\RP24\A0008090.exe (Spyware.OnlineGames) -> No action taken.
e:\system volume information\_restore{db137947-a8b0-4561-af42-db894cf1aaf2}\RP24\A0008374.exe (Spyware.OnlineGames) -> No action taken.

Re: dlho bez antiviru, vela haveti, kontrola logu prosim

Napsal: 06 bře 2011 11:21
od vyosek
:arrow: Nalezy MBAMu smazte

:arrow: Stahnete OTM (viz muj podpis)
  • Pokud pouzivate Win Vista ci W7, kliknete na OTM pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do leveho okna Paste Instructions for Items to be Moved (pod zlutou caru) vlozte obsah, ktery mate nize
  • Kód: Vybrat vše

    :files
    %windir%\system32\*.tmp.dll /s
    %windir%\system32\SET*.tmp /s
    %windir%\*.tmp /s
    
    :commands
    [RESETHOSTS]
    [EMPTYTEMP]
    [EMPTYFLASH]
    [CLEARALLRESTOREPOINTS]
  • Kliknete na cervene tlacitko MoveIt!
  • Budete vyzvani na restart, dejte Yes, log pote najdete C:\_OTM\MovedFiles, obsah sem vlozte

Re: dlho bez antiviru, vela haveti, kontrola logu prosim

Napsal: 06 bře 2011 11:47
od Fony
All processes killed
========== FILES ==========
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
C:\WINDOWS\SET3.tmp moved successfully.
C:\WINDOWS\SET4.tmp moved successfully.
C:\WINDOWS\SET8.tmp moved successfully.
C:\WINDOWS\system32\CONFIG.TMP moved successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: fony
->Temp folder emptied: 973752 bytes
->Temporary Internet Files folder emptied: 41825 bytes
->FireFox cache emptied: 61481352 bytes
->Flash cache emptied: 1223 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 60,00 mb


Restore points cleared and new OTM Restore Point set!

OTM by OldTimer - Version 3.1.17.2 log created on 03062011_114121

Files moved on Reboot...

Registry entries deleted on Reboot...