Stránka 1 z 4

FB-vir

Napsal: 27 črc 2011 17:53
od hardman
Dobry den.Mam problem dostal som virus z fb.Bola to aklualizacia adobe flash playeru.Po stiahnuti a spusteni suboru flash.exe ma eset upozornil,dal som remove a PC sa restartol,presiel do save modu,cakal som co PC spravi a po chvilke sa znova resetol a normalne zapol.PC pracuje niekedy spomalene napr pri otvarani okien a pri starte vypisovalo chybu: netsh.exe-Vstupný bod nebol nájdený-Vstupný bod procedúry MigrateWinsockConfiguration sa nepodarilo nájsť v dynamicky prepojovanej knižnici MSWSOCK.dll. ale stahoval som nejake programy napr. WinsockxpFix a tak a teraz mi pri starte chybu nepise PC pracuje normalne,internet ide ale niekedy vobec nechce nacitat ziadnu stranku a dostal som sa aj na FB ale Eset nejde spustit a pri tejto snahe sa objavi cervena tabulka s nadpisom ENCHANCED PROTECTION MODE tak ako pred tim. :(

tu je log
Logfile of random's system information tool 1.09 (written by random/random)
Run by HARDMAN at 2011-07-27 15:36:50
WIN_XP Service Pack 3
System drive C: has 7 GB (22%) free of 29 GB
Total RAM: 1022 MB (28% free)


======Scheduled tasks folder======

C:\WINDOWS\tasks\1-Click Maintenance.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cb0d9d335d472e.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\HARDMAN\Application Data\Mozilla\Firefox\Profiles\2xv5asca.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://start.icq.com/"
prefs.js - "extensions.enabledItems" - "{0BA0192D-94A5-45e3-B2B8-3EC5A1A0B5EC}:1.5.0.850, {2224E955-00E9-4613-A844-CE69FCCAAE91}:3.4.0.4340, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.18"
prefs.js - "keyword.URL" - "http://search.sweetim.com/search.asp?src=2&q="

"{2224E955-00E9-4613-A844-CE69FCCAAE91}"=C:\Program Files\Internet Saving Optimizer\3.4.0.4340\FF
"{0BA0192D-94A5-45e3-B2B8-3EC5A1A0B5EC}"=C:\Program Files\Media Access Startup\1.5.0.850\FF
"bkmrksync@nokia.com"=C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\
"{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}"=C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"smartwebprinting@hp.com"=C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
"{23fcfd51-4958-4f00-80a3-ae97e717ed8b}"=C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0]
"Description"=DivX® Player Plugin for VOD Content
"Path"=C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0]
"Description"=DivX VOD Helper Plug-in
"Path"=C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nppl3260;version=6.0.12.69]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.69]
"Description"=6.0.12.69
"Path"=C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
AskHPRFF.js
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
components.list
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
GPSDGeolocationProvider.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
npCouponPrinter.xpt
nppl3260.xpt
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsFormAutoComplete.js
nsHandlerService.js
nsHelperAppDlg.js
nsINIProcessor.js
nsJSRealPlayerPlugin.xpt
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesAutoComplete.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUpdateServiceStub.js
nsUpdateTimerManager.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js

C:\Program Files\Mozilla Firefox\plugins\
np32dsw.dll
npCouponPrinter.dll
npDivxPlayerPlugin.dll
npMozCouponPrinter.dll
npnul32.dll
NPOFF12.DLL
nppdf32.dll
nppl3260.dll
nprpjplug.dll
nsIDivxPlayerPlugin.xpt
ShockwavePlugin.class

C:\Program Files\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml

C:\Documents and Settings\HARDMAN\Application Data\Mozilla\Firefox\Profiles\2xv5asca.default\extensions\
DTToolbar@toolbarnet.com
{20a82645-c095-46ed-80e3-08825760534b}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-10-22 328248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25B8D58C-B0CB-46b0-BA64-05B3804E4E86}]
Media Access Startup

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}]
DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll [2011-05-23 115072]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35B8D58C-B0CB-46b0-BA64-05B3804E4E86}]
NP Helper Class

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{984A9162-8891-4D19-8CFE-17648BB4E1EC}]
GamePlayLabsBHO Class

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CDBFB47B-58A8-4111-BF95-06178DCE326D}]
System Search Dispatcher

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
VDownloader Toolbar

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-10-22 517688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2010-11-21 1054520]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2009-04-23 937416]
{D4027C7F-154A-4066-A1AD-4243D8127440} -

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"=C:\WINDOWS\system32\HDAShCut.exe [2004-10-27 61952]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2005-05-20 925696]
"SoundMAX"=C:\Program Files\Analog Devices\SoundMAX\Smax4.exe [2005-09-07 716800]
"PAC207_Monitor"=C:\WINDOWS\PixArt\PAC207\Monitor.exe [2006-11-03 319488]
"Monitor"=C:\WINDOWS\PixArt\PAC207\Monitor.exe [2006-11-03 319488]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
"SecurDisc"=C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe [2007-06-25 1629480]
"InCD"=C:\Program Files\Nero\Nero 7\InCD\InCD.exe [2007-06-25 1057064]
"ASUS Update Checker"=C:\Program Files\ASUS\ASUSUpdate\UpdateChecker\UpdateChecker.exe [2008-12-11 114688]
"Ai Nap"=C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe [2007-12-10 1412608]
"CPU Power Monitor"=C:\Program Files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe [2007-10-16 626176]
"Cpu Level Up help"=C:\Program Files\ASUS\AI Suite\CpuLevelUpHelp.exe [2007-11-30 881152]
"NokiaMServer"=C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
"nwiz"=C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [2010-06-03 1753192]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2010-06-07 110696]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2010-06-07 13902440]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-06-08 37296]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-03-30 937920]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2009-11-18 54576]
""= []
"DivXUpdate"=C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2011-03-21 1230704]
"wxpdrv"=C:\WINDOWS\services32.exe [2011-07-20 1147392]
"tray_ico0"=C:\WINDOWS\update.tray-2-0\svchost.exe [2011-07-20 1147392]
"tray_ico1"=C:\WINDOWS\update.tray-3-0\svchost.exe [2011-07-20 1147392]
"8119627.exe"=C:\DOCUME~1\HARDMAN\LOCALS~1\Temp\8119627.exe [2011-07-20 232960]
"sysdriver32.exe"=C:\WINDOWS\sysdriver32.exe [2011-07-25 261632]
"sysdriver32_.exe"=C:\WINDOWS\sysdriver32_.exe [2011-07-25 256000]
"2281941.exe"=C:\DOCUME~1\HARDMAN\LOCALS~1\Temp\2281941.exe [2011-07-20 232960]
"9283901.exe"=C:\WINDOWS\TEMP\9283901.exe [2011-07-20 232960]
"6115264.exe"=C:\WINDOWS\TEMP\6115264.exe [2011-07-20 232960]
"l1rezerv.exe"=C:\WINDOWS\l1rezerv.exe [2011-07-25 235520]
"systemup"=C:\WINDOWS\systemup.exe [2011-07-20 114176]
"8026904.exe"=C:\WINDOWS\TEMP\8026904.exe [2011-07-25 256000]
"5911628.exe"=C:\WINDOWS\TEMP\5911628.exe [2011-07-27 502272]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-06-27 152872]
"STYLEXP"=C:\Program Files\TGTSoft\StyleXP\StyleXP.exe [2006-05-24 1372160]
""= []
"AlcoholAutomount"=C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe [2009-04-24 203928]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
Ralink Wireless Utility.lnk - C:\Program Files\RALINK\Common\RaUI.exe

C:\Documents and Settings\HARDMAN\Start Menu\Programs\Startup
Kalendár.lnk - C:\WINDOWS\MENINY.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-04-16 190464]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\wxpdrivers]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLUA"=0
"EnableSecureUIAPaths"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"Z:\Hry\Rise Of Nations\rise.exe"="Z:\Hry\Rise Of Nations\rise.exe:*:Enabled:Rise of Nations"
"Z:\Hry\Rise of Nations\nations.exe"="Z:\Hry\Rise of Nations\nations.exe:*:Enabled:Rise of Nations"
"Z:\Hry\Codemasters\GRID\GRID.exe"="Z:\Hry\Codemasters\GRID\GRID.exe:*:Enabled:GRID"
"Z:\Hry\EA Sports\NHL 09\nhl2009.exe"="Z:\Hry\EA Sports\NHL 09\nhl2009.exe:*:Enabled:nhl2009"
"Z:\Hry\Far Cry\Bin32\FarCry.exe"="Z:\Hry\Far Cry\Bin32\FarCry.exe:*:Enabled:Far Cry"
"Z:\Hry\EA GAMES\Need for Speed Most Wanted\speed.exe"="Z:\Hry\EA GAMES\Need for Speed Most Wanted\speed.exe:*:Enabled:speed"
"Z:\Hry\Rise of Nations Gold\thrones.exe"="Z:\Hry\Rise of Nations Gold\thrones.exe:*:Enabled:Rise of Nations"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"Z:\ANAL\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutLauncher.exe"="Z:\ANAL\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutLauncher.exe:*:Enabled:Burnout(TM) Paradise The Ultimate Box"
"Z:\ANAL\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutConfigTool.exe"="Z:\ANAL\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutConfigTool.exe:*:Enabled:Burnout(TM) Paradise The Ultimate Box"
"Z:\ANAL\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutParadise.exe"="Z:\ANAL\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutParadise.exe:*:Enabled:Burnout(TM) Paradise The Ultimate Box"
"Z:\Hry\Command & Conquer 3\RetailExe\1.9\cnc3game.dat"="Z:\Hry\Command & Conquer 3\RetailExe\1.9\cnc3game.dat:*:Enabled:Command & Conquer 3 Tiberium Wars"
"C:\Program Files\uTorrent\utorrent.exe"="C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent"
"Z:\Hry\Rise of Nations Gold\patriots.exe"="Z:\Hry\Rise of Nations Gold\patriots.exe:*:Enabled:Rise of Nations"
"C:\Program Files\TeamViewer\Version4\TeamViewer.exe"="C:\Program Files\TeamViewer\Version4\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application"
"C:\WINDOWS\system32\dplaysvr.exe"="C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"C:\Documents and Settings\HARDMAN\Desktop\bulanci.exe"="C:\Documents and Settings\HARDMAN\Desktop\bulanci.exe:*:Enabled:bulanci"
"Z:\Hry\Sniper Elite\SniperElite.exe"="Z:\Hry\Sniper Elite\SniperElite.exe:*:Enabled:SniperElite"
"Z:\Hry\Valve\hl.exe"="Z:\Hry\Valve\hl.exe:*:Enabled:Half-Life Launcher"
"Z:\Hry\Valve\cstrike.exe"="Z:\Hry\Valve\cstrike.exe:*:Enabled:Counter-Strike Launcher"
"Z:\Hry\Worms.4.Mayhem.Multi.part1\Worms.4.Mayhem.Multi\WORMS 4 MAYHEM.EXE"="Z:\Hry\Worms.4.Mayhem.Multi.part1\Worms.4.Mayhem.Multi\WORMS 4 MAYHEM.EXE:*:Enabled:Worms 4 Mayhem"
"C:\Documents and Settings\HARDMAN\Local Settings\Temp\TeamViewer\Version5\TeamViewer.exe"="C:\Documents and Settings\HARDMAN\Local Settings\Temp\TeamViewer\Version5\TeamViewer.exe:*:Enabled:TeamViewer Remote Control Application"
"Z:\Hry\CS1.6 kopia\hlds.exe"="Z:\Hry\CS1.6 kopia\hlds.exe:*:Enabled:HLDS Launcher"
"Z:\Hry\CS1.6 kopia\hltv.exe"="Z:\Hry\CS1.6 kopia\hltv.exe:*:Enabled:HLTV Launcher"
"D:\setup\hpznui01.exe"="D:\setup\hpznui01.exe:*:Enabled:hpznui01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe:*:Enabled:hpqgpc01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe"
"C:\Program Files\HP\HP Software Update\hpwucli.exe"="C:\Program Files\HP\HP Software Update\hpwucli.exe:*:Enabled:hpwucli.exe"
"C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe"="C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe"
"Z:\downloads\facebook-pic000934519.exe"="c:\windows\nvsvc32.exe:*:Enabled:NVIDIA driver monitor"
"C:\Program Files\Garena\Garena.exe"="C:\Program Files\Garena\Garena.exe:*:Enabled:Garena"
"C:\Program Files\ICQ7.5\ICQ.exe"="C:\Program Files\ICQ7.5\ICQ.exe:*:Enabled:ICQ7.5"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype "
"C:\WINDOWS\services32.exe"="C:\WINDOWS\services32.exe:*:Enabled:C:\WINDOWS\services32.exe"
"C:\WINDOWS\update.1\svchost.exe"="C:\WINDOWS\update.1\svchost.exe:*:Enabled:C:\WINDOWS\update.1\svchost.exe"
"C:\WINDOWS\update.tray-2-0\svchost.exe"="C:\WINDOWS\update.tray-2-0\svchost.exe:*:Enabled:C:\WINDOWS\update.tray-2-0\svchost.exe"
"C:\WINDOWS\update.tray-3-0\svchost.exe"="C:\WINDOWS\update.tray-3-0\svchost.exe:*:Enabled:C:\WINDOWS\update.tray-3-0\svchost.exe"
"C:\WINDOWS\update.2\svchost.exe"="C:\WINDOWS\update.2\svchost.exe:*:Enabled:C:\WINDOWS\update.2\svchost.exe"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\WINDOWS\update.tray-3-0-lnk\svchost.exe"="C:\WINDOWS\update.tray-3-0-lnk\svchost.exe:*:Disabled:svchost"
"C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe"="C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe:*:Enabled:Malwarebytes' Anti-Malware"
"C:\WINDOWS\systemup.exe"="C:\WINDOWS\systemup.exe:*:Disabled:systemup"
"C:\WINDOWS\l1rezerv.exe"="C:\WINDOWS\l1rezerv.exe:*:Disabled:l1rezerv"
"C:\Program Files\DivX\DivX Update\DivXUpdate.exe"="C:\Program Files\DivX\DivX Update\DivXUpdate.exe:*:Disabled:DivX Update"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\setup\hpznui01.exe"="D:\setup\hpznui01.exe:*:Enabled:hpznui01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe:*:Enabled:hpqgpc01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe"
"C:\Program Files\HP\HP Software Update\hpwucli.exe"="C:\Program Files\HP\HP Software Update\hpwucli.exe:*:Enabled:hpwucli.exe"
"C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe"="C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe"
"C:\Program Files\ICQ7.5\ICQ.exe"="C:\Program Files\ICQ7.5\ICQ.exe:*:Enabled:ICQ7.5"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"midi"=wdmaud.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\System32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.VP60"=vp6vfw.dll
"VIDC.VP61"=vp6vfw.dll
"VIDC.VP62"=vp6vfw.dll
"VIDC.VP70"=vp7vfw.dll
"msacm.l3fhg"=mp3fhg.acm
"msacm.divxa32"=divxa32.acm
"msacm.vorbis"=vorbis.acm
"VIDC.X264"=x264vfw.dll
"VIDC.XVID"=xvidvfw.dll
"VIDC.HFYU"=huffyuv.dll
"vidc.i263"=i263_32.drv
"msacm.ac3acm"=ac3acm.acm
"msacm.lameacm"=lameACM.acm
"VIDC.FFDS"=ff_vfw.dll
"MSVideo8"=VfWWDM32.dll
"VIDC.FPS1"=frapsvid.dll
"vidc.DIVX"=DivX.dll
"vidc.yv12"=DivX.dll

======File associations======

.reg - open - "regedit.exe" "%1"

======List of files/folders created in the last 1 month======

2011-07-27 15:36:50 ----D---- C:\rsit
2011-07-27 15:36:50 ----D---- C:\Program Files\trend micro
2011-07-22 18:20:34 ----D---- C:\Documents and Settings\HARDMAN\Application Data\Malwarebytes
2011-07-22 18:20:18 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2011-07-22 17:59:32 ----A---- C:\WINDOWS\UPGRADE.TXT
2011-07-22 17:44:40 ----D---- C:\ERDNT
2011-07-20 14:43:39 ----A---- C:\WINDOWS\ddh_iplist.txt
2011-07-20 14:43:30 ----A---- C:\WINDOWS\systemup.exe
2011-07-20 14:43:30 ----A---- C:\WINDOWS\l1rezerv.exe
2011-07-20 14:43:28 ----A---- C:\WINDOWS\iecheck_iplist.txt
2011-07-20 14:43:09 ----D---- C:\WINDOWS\ufa
2011-07-20 14:43:09 ----D---- C:\WINDOWS\rpcminer
2011-07-20 14:43:09 ----D---- C:\WINDOWS\phoenix
2011-07-20 14:43:08 ----HD---- C:\WINDOWS\update.2
2011-07-20 14:42:41 ----A---- C:\WINDOWS\unrar.exe
2011-07-20 14:42:08 ----A---- C:\WINDOWS\btc_client_iplist.txt
2011-07-20 14:41:47 ----HD---- C:\WINDOWS\update.5.0
2011-07-20 14:41:47 ----A---- C:\WINDOWS\sysdriver32_.exe
2011-07-20 14:41:40 ----A---- C:\WINDOWS\iplist.txt
2011-07-20 14:41:29 ----A---- C:\WINDOWS\sysdriver32.exe
2011-07-20 14:40:56 ----A---- C:\WINDOWS\front_ip_list.txt
2011-07-20 14:40:45 ----D---- C:\WINDOWS\av_ico
2011-07-20 14:38:29 ----HD---- C:\WINDOWS\update.1
2011-07-20 14:38:15 ----HD---- C:\WINDOWS\update.tray-3-0-lnk
2011-07-20 14:38:15 ----HD---- C:\WINDOWS\update.tray-3-0
2011-07-20 14:38:14 ----HD---- C:\WINDOWS\update.tray-2-0-lnk
2011-07-20 14:38:14 ----HD---- C:\WINDOWS\update.tray-2-0
2011-07-20 14:27:12 ----A---- C:\WINDOWS\winlog-ids.txt
2011-07-20 14:27:12 ----A---- C:\WINDOWS\winlog-dirs.txt
2011-07-20 14:27:06 ----A---- C:\WINDOWS\services32.exe
2011-07-17 01:21:50 ----HDC---- C:\WINDOWS\$NtUninstallKB2507938$
2011-07-17 01:13:45 ----HDC---- C:\WINDOWS\$NtUninstallKB2555917$
2011-07-06 21:14:38 ----D---- C:\Documents and Settings\HARDMAN\Application Data\go
2011-07-06 21:14:30 ----D---- C:\Documents and Settings\All Users\Application Data\Easybits GO
2011-06-28 23:31:38 ----HDC---- C:\WINDOWS\$NtUninstallKB2541763$

======List of files/folders modified in the last 1 month======

2011-07-27 15:36:50 ----D---- C:\Program Files
2011-07-27 14:58:01 ----D---- C:\WINDOWS\Temp
2011-07-27 14:57:40 ----A---- C:\WINDOWS\win.ini
2011-07-27 14:56:28 ----D---- C:\WINDOWS\system32\drivers
2011-07-25 22:56:35 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-07-25 22:36:24 ----A---- C:\WINDOWS\NeroDigital.ini
2011-07-25 20:54:47 ----D---- C:\WINDOWS
2011-07-22 18:27:36 ----SHD---- C:\WINDOWS\Installer
2011-07-22 18:27:35 ----HD---- C:\Config.Msi
2011-07-22 18:08:26 ----HD---- C:\Program Files\InstallShield Installation Information
2011-07-22 17:36:18 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-07-22 17:36:13 ----D---- C:\WINDOWS\system32
2011-07-22 17:35:52 ----D---- C:\WINDOWS\system32\CatRoot2
2011-07-22 16:57:27 ----D---- C:\Program Files\ICQ6Toolbar
2011-07-22 16:56:27 ----D---- C:\WINDOWS\system32\config
2011-07-22 16:55:47 ----D---- C:\WINDOWS\Registration
2011-07-21 21:21:38 ----D---- C:\WINDOWS\Prefetch
2011-07-20 16:39:04 ----SD---- C:\WINDOWS\Tasks
2011-07-20 14:44:09 ----SHD---- C:\System Volume Information
2011-07-20 14:44:09 ----D---- C:\WINDOWS\system32\Restore
2011-07-20 14:43:29 ----D---- C:\WINDOWS\system32\drivers\etc
2011-07-20 14:38:39 ----A---- C:\boot.ini
2011-07-20 14:33:48 ----D---- C:\Documents and Settings\HARDMAN\Application Data\Skype
2011-07-19 12:56:54 ----RD---- C:\Program Files\Skype
2011-07-19 12:56:45 ----D---- C:\Documents and Settings\All Users\Application Data\Skype
2011-07-19 12:56:19 ----D---- C:\Program Files\Common Files
2011-07-19 12:54:17 ----D---- C:\Documents and Settings\All Users\Application Data\Skype Extras
2011-07-17 01:21:54 ----HD---- C:\WINDOWS\inf
2011-07-17 01:14:02 ----A---- C:\WINDOWS\system32\MRT.exe
2011-07-17 01:13:56 ----A---- C:\WINDOWS\imsins.BAK
2011-07-16 23:27:57 ----HD---- C:\WINDOWS\$hf_mig$
2011-07-06 22:05:39 ----D---- C:\Documents and Settings\All Users\Application Data\2DBoy
2011-07-06 21:13:25 ----D---- C:\Documents and Settings\HARDMAN\Application Data\skypePM
2011-07-03 20:34:53 ----D---- C:\Documents and Settings\HARDMAN\Application Data\HPAppData
2011-07-01 01:23:53 ----D---- C:\Documents and Settings\All Users\Application Data\Norton
2011-06-30 20:14:29 ----D---- C:\WINDOWS\Microsoft.NET
2011-06-30 20:14:24 ----RSD---- C:\WINDOWS\assembly
2011-06-28 23:39:59 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-06-28 23:39:30 ----D---- C:\WINDOWS\WinSxS

Re: FB-vir

Napsal: 27 črc 2011 18:16
od p.Jenan
Hezký večer.

Udělejte kompletní sken MBAM: http://www.malwarebytes.org/mbam.php a dejte log. Předem nic nemažte.

Re: FB-vir

Napsal: 27 črc 2011 18:38
od hardman
ok idem na to :happy:

Re: FB-vir

Napsal: 27 črc 2011 18:59
od hardman
Takze spustil som program mbam,dal som uplnu kontrolu a po par sekundach mi okno zatvorilo.Ked chcem pregram spustit znova pise: System Windows nemoze ziskat pristup k zadanemu zariadeniu,ceste alebo suboru.Mozno nemate prislusne povolenie na pristup k danej polozke.

Re: FB-vir

Napsal: 27 črc 2011 19:12
od p.Jenan
Restartujte PC a přejděte do nouzového režimu - klávesou F8.

A poté udělejte kompletní sken MBAM: http://www.malwarebytes.org/mbam.php a dejte log.

Re: FB-vir

Napsal: 27 črc 2011 21:35
od hardman
Presiel som do safe modu a spustil program ale napisalo mi to znova a navyse ten safe mod sa sam ukonci po cca 35s,resetne sa PC a normalne nacita windows.Myslim ze s timto sa us neda nic delat :(

Re: FB-vir

Napsal: 27 črc 2011 22:02
od p.Jenan
Dejte log z ComboFix. -
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se

jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine

aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode,

pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k

nezadoucim kolizim s rezidentem antispyware

Re: FB-vir

Napsal: 28 črc 2011 13:41
od hardman
Prosim tu je log
ComboFix 11-07-28.01 - HARDMAN 28.07.2011 14:07:33.1.1 - x86
Running from: c:\documents and settings\HARDMAN\Desktop\ComboFix.exe
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\docume~1\HARDMAN\LOCALS~1\Temp\2281941.exe
c:\docume~1\HARDMAN\LOCALS~1\Temp\8119627.exe
c:\documents and settings\HARDMAN\Application Data\Desktopicon
c:\documents and settings\HARDMAN\Application Data\Desktopicon\config.ini
c:\documents and settings\HARDMAN\Local Settings\Application Data\DoubleD
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\config.md
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\ipdata.md
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090710-233423.687.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090710-233639.156.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090710-235531.000.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090711-003040.484.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090711-022742.906.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090711-023819.718.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090711-114903.171.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090712-194021.515.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090712-202523.828.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090712-204045.921.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090712-215712.609.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090713-002835.328.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090713-003931.468.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090713-113400.312.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090714-114204.312.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090714-124253.296.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090714-124254.593.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090714-133902.968.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090714-141353.859.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090714-211315.640.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090715-073659.625.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090715-075815.609.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090715-204654.781.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090716-104126.125.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090716-110657.796.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090716-140636.203.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090716-160554.765.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090716-214427.468.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090716-233327.718.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090717-131548.953.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090717-133920.890.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090717-233635.906.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090718-010118.968.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090718-111254.375.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090718-171523.687.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090718-224714.218.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090719-010822.609.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090719-141717.718.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090719-184334.625.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090719-232037.406.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090720-140104.265.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090720-192354.750.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090721-093906.125.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090721-142259.296.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090721-154437.781.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090722-001009.046.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090722-110619.140.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090722-114846.062.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090722-133325.531.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090722-153416.234.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090723-102902.125.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090723-183318.078.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090723-183427.890.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090724-010656.859.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090724-083037.546.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090725-050451.984.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090725-133544.828.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090726-005902.109.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090726-200711.968.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090727-124650.312.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090727-185724.140.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090727-185808.890.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090727-212221.921.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090728-111110.546.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090728-175239.953.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090728-193923.953.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090728-204116.125.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090729-122401.375.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090729-222546.062.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090729-224307.359.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090729-230722.147.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090730-101005.984.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090730-141459.250.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090731-095156.640.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090731-174134.796.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090801-042153.531.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090802-011218.234.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090802-083552.015.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090802-182434.203.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090802-210549.171.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090803-151523.187.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090803-191758.531.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090804-113144.140.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090804-214237.796.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090805-013637.265.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090805-114547.359.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090805-114555.406.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090805-143116.390.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090806-162245.073.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090807-131210.390.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090807-230648.984.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090809-144957.000.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090809-213859.531.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090809-232334.578.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090810-135654.046.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090810-183345.875.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090810-225603.828.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090811-212601.983.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090812-004345.780.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090812-134105.281.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090812-134535.609.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090812-135058.671.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090812-155351.765.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090812-155417.765.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090812-174358.875.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090812-214633.640.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090813-130612.734.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090814-003611.890.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090814-131253.640.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090814-204035.375.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090815-114825.312.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090815-212922.671.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090817-151242.078.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090818-210332.390.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090818-210727.625.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090818-214537.609.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090818-214941.796.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090818-233438.687.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090819-091550.843.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090819-121105.656.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090819-132838.156.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090819-133714.031.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090819-133852.781.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090819-135350.187.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090819-201027.453.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090819-201054.156.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090820-181731.250.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090820-204640.218.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090820-205130.640.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090820-205251.687.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090820-205552.078.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090821-013359.562.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090821-014122.640.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090821-220605.046.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090822-165536.187.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090822-204604.343.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090823-145820.859.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090823-145953.531.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090823-150025.390.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090824-133510.390.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090824-170954.921.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090825-080854.828.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090825-131829.312.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090826-141535.320.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090826-184249.859.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090827-120601.812.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090827-161756.781.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090828-141953.640.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090829-134710.500.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090830-121040.531.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090831-105852.906.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090831-205925.281.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090901-115427.437.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090901-142820.796.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090901-192547.281.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090903-125827.085.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090903-135906.796.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090903-160753.625.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090904-130610.484.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090904-135737.687.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090904-213720.000.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090904-230414.750.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090905-000153.000.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090905-002845.406.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090906-164723.968.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090906-180037.421.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090906-214110.319.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090906-221028.625.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090906-221326.859.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090908-001618.500.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090908-003707.968.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090908-004809.218.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090908-004847.765.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090908-011146.375.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090908-011631.234.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090908-013431.671.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090908-031637.453.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090909-150145.062.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090909-163412.234.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090910-184126.453.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090910-192311.796.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090910-201313.906.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090910-221349.890.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090911-130945.453.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090911-184858.546.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090911-223620.015.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090911-231058.656.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\NP_20090912-171917.437.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Internet Saving Optimizer\3.4.0.4340\rstatus.md
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.3.0.790\config.md
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090710-233403.781.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090710-233423.625.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090710-233639.140.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090710-235530.984.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090711-003040.468.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090711-022742.859.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090711-023819.671.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090711-114903.046.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090712-194021.453.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090712-202523.812.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090712-204045.906.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090712-215712.593.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090713-002835.312.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090713-003931.453.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090713-113400.296.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090714-114204.296.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090714-124253.281.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\config.md
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090714-114245.375.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090714-124254.578.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090714-133902.953.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090714-141353.843.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090714-211315.625.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090715-073659.609.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090715-075815.593.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090715-204654.312.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090716-104126.078.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090716-110657.765.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090716-140636.156.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090716-160554.734.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090716-214427.359.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090716-233327.671.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090717-131548.937.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090717-133920.875.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090717-233635.890.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090718-010118.937.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090718-111254.359.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090718-171523.656.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090718-224714.203.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090719-010822.593.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090719-141717.703.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090719-184334.515.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090719-232037.343.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090720-140104.250.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090720-192354.718.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090721-093906.062.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090721-142259.234.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090721-154437.750.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090722-001008.906.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090722-110618.734.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090722-114846.015.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090722-133325.500.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090722-153416.078.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090723-102902.093.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090723-183318.000.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090723-183427.859.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090724-010656.687.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090724-083037.171.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090725-050451.453.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090725-133544.734.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090726-005902.031.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090726-200711.921.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090727-124650.281.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090727-185724.109.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090727-185808.859.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090727-212221.906.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090728-111110.531.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090728-175239.906.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090728-193923.937.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090728-204116.109.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090729-122401.343.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090729-222546.031.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090729-224307.328.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090729-230722.131.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090730-101005.968.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090730-141459.234.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090731-095156.625.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090731-174134.781.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090801-042153.500.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090802-011218.202.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090802-083552.000.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090802-182434.187.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090802-210549.156.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090803-151523.171.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090803-191758.484.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090804-113144.125.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090804-214237.750.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090805-013637.234.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090805-114547.125.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090805-114555.390.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090805-143116.296.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090806-162244.901.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090807-131210.328.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090807-230648.906.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090809-144956.937.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090809-213859.484.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090809-232334.546.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090810-135653.937.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090810-183345.843.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090810-225603.796.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090811-212601.796.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090812-004345.749.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090812-134104.859.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090812-134535.578.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090812-135058.437.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090812-155351.734.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090812-155417.734.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090812-174358.828.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090812-214633.625.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090813-130612.421.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090814-003611.859.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090814-131253.531.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090814-204035.343.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090815-114825.281.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090815-212922.593.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090817-151242.015.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090818-210332.203.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090818-210727.437.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090818-214537.593.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090818-214941.781.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090818-233438.578.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090819-091550.828.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090819-121105.578.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090819-132838.109.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090819-133714.015.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090819-133852.765.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090819-135350.171.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090819-201027.437.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090819-201054.140.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090820-181731.218.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090820-204640.203.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090820-205130.625.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090820-205251.609.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090820-205552.046.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090821-013359.546.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090821-014122.625.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090821-220605.031.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090822-165536.171.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090822-204604.296.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090823-145820.843.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090823-145953.500.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090823-150025.359.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090824-133510.140.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090824-170954.859.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090825-080854.703.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090825-131829.203.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090826-141534.883.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090826-184248.421.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090827-120601.750.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090827-161756.671.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090828-141953.578.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090829-134710.484.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090830-121040.421.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090831-105852.640.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090831-205925.140.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090901-115427.375.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090901-142820.734.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090901-192547.250.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090903-125826.460.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090903-135906.703.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090903-160753.593.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090904-130610.468.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090904-135737.640.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090904-213719.984.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090904-230414.703.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090905-000152.953.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090905-002845.390.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090906-164723.953.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090906-180037.312.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090906-214110.100.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090906-221028.421.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090906-221326.828.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090908-001617.468.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090908-003707.921.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090908-004809.171.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090908-004847.750.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090908-011146.359.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090908-011631.218.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090908-013431.656.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090908-031637.437.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090909-150145.015.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090909-163412.218.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090910-184126.437.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090910-192311.781.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090910-201313.890.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090910-221349.859.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090911-130945.437.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090911-184858.453.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090911-223619.921.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090911-231058.625.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\HJHP_20090912-171917.140.log
c:\documents and settings\HARDMAN\Local Settings\Application Data\Media Access Startup\1.5.0.850\ipdata.md
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\_tm1180.tmp
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\bg.jpg
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\CurrentVersion.xml
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\Data\ProductInfo.mx
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\ExtractZipFile.zip
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\icon.ico
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\tdf.dat
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Cache\248d6576afce4ee94af42d7350131106.gif
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Cache\24a70fb875fab686b6b3c217612bc07c.gif
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Cache\2afcf6f3f2e19cc42d7f72f3b18b26ef.gif
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Cache\50bffa6936b3e661971a58e3c8bdf4cb.gif
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Cache\default1.dat
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Cache\loading.dat
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Cache\loading.gif
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Data\Module_Cursor.mx
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Data\Module_DailyVideo.mx
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Data\Module_Game.mx
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Data\Module_Glitter.mx
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Data\Module_Logo.mx
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Data\Module_Option.mx
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Data\Module_Recipe.mx
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Data\Module_Ringtone.mx
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Data\Module_Screensaver.mx
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Data\Module_Search.mx
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Data\Module_Smiley.mx
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Data\Module_Smiley_Config.mx
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Data\Module_Smiley_TellAFriend.mx
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Data\Module_Wallpaper.mx
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Data\Module_Web.mx
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Data\pixel.mx
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Data\ProductInfo.mx
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Data\profile.mx
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Data\SearchEngineList.mx
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Data\tbcore.mx
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Data\ToolbarLayout.mx
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Data\UpdateCentre.mx
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Data\UpdateCentreBk.mx
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Data\URLDynamic.mx
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Data\URLStatic.mx
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\About.mg
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\Component_ComboBox.mg
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\Module_Cursor.mg
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\Module_Cursor.png
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\Module_DailyVideo.mg
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\Module_Game.mg
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\Module_Glitter.mg
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\Module_Glitter.png
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\Module_Logo.mg
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\Module_Option.mg
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\Module_Recipe.mg
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\Module_Ringtone.mg
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\Module_Screensaver.mg
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\Module_Search.mg
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\Module_Smiley.mg
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\Module_Smiley.png
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\Module_Wallpaper.mg
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\Module_Web.mg
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\TBBtnDefault.png
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\TBBtnDisplay.bmp
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\TBBtnDisplay.png
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\TBBtnDisplay18.bmp
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\TBBtnDisplay20.bmp
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\TBBtnGlitters.bmp
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\TBBtnGlitters.png
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\TBBtnGlitters18.bmp
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\TBBtnGlitters20.bmp
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\TBBtnOption.png
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\TBBtnSmiley.bmp
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\TBBtnSmiley.png
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\TBBtnSmiley18.bmp
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\TBBtnSmiley20.bmp
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\TBBtnTellFd.bmp
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\TBBtnTellFd.png
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\TBBtnTellFd18.bmp
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\TBBtnTellFd20.bmp
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\TBBtnWink.bmp
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\TBBtnWink.png
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\TBBtnWink18.bmp
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Icons\TBBtnWink20.bmp
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Skins\myskin1.skf
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Skins\myskin2.skf
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Skins\myskin3.skf
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Skins\myskin4.skf
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Skins\TellafriendSkin.skf
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Skins\TellafriendSkin_s.skf
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\TDF\Skins\ToastSkin.skf
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\ISOSetup.exe
c:\documents and settings\HARDMAN\Local Settings\Temporary Internet Files\stb06759.tmp
c:\documents and settings\HARDMAN\WINDOWS
c:\program files\DoubleD
c:\program files\Internet Saving Optimizer
c:\program files\Internet Saving Optimizer\3.4.0.4340\Data\config.md
c:\program files\Internet Saving Optimizer\3.4.0.4340\FF\components\NPFFAddOn.xpt
c:\program files\Internet Saving Optimizer\3.4.0.4340\FF\components\NPFFHelperComponent.js
c:\program files\Internet Saving Optimizer\3.4.0.4340\FF\chrome.manifest
c:\program files\Internet Saving Optimizer\3.4.0.4340\FF\chrome\content\NPAddOn.js
c:\program files\Internet Saving Optimizer\3.4.0.4340\FF\chrome\content\NPAddOn.xul
c:\program files\Internet Saving Optimizer\3.4.0.4340\FF\chrome\NPAddOn.jar
c:\program files\Internet Saving Optimizer\3.4.0.4340\FF\install.rdf
c:\program files\Internet Saving Optimizer\3.4.0.4340\NPCommon.dll
c:\program files\Internet Saving Optimizer\3.4.0.4340\unins000.dat
c:\program files\Internet Saving Optimizer\3.4.0.4340\unins000.exe
c:\program files\Media Access Startup
c:\program files\Media Access Startup\1.5.0.850\Data\config.md
c:\program files\Media Access Startup\1.5.0.850\FF\components\HPFFAddOn.xpt
c:\program files\Media Access Startup\1.5.0.850\FF\components\HPFFHelperComponent.js
c:\program files\Media Access Startup\1.5.0.850\FF\chrome.manifest
c:\program files\Media Access Startup\1.5.0.850\FF\chrome\content\HPAddOn.js
c:\program files\Media Access Startup\1.5.0.850\FF\chrome\content\HPAddOn.xul
c:\program files\Media Access Startup\1.5.0.850\FF\chrome\HPAddOn.jar
c:\program files\Media Access Startup\1.5.0.850\FF\install.rdf
c:\program files\Media Access Startup\1.5.0.850\HPCommon.dll
c:\program files\Media Access Startup\1.5.0.850\unins000.dat
c:\program files\Media Access Startup\1.5.0.850\unins000.exe
c:\program files\System Search Dispatcher
c:\program files\System Search Dispatcher\1.2.0.750\Data\eacore.mx
c:\program files\System Search Dispatcher\1.2.0.750\Data\URLDynamic.mx
c:\program files\System Search Dispatcher\1.2.0.750\Data\URLStatic.mx
c:\program files\System Search Dispatcher\1.2.0.750\unins000.dat
c:\program files\System Search Dispatcher\1.2.0.750\unins000.exe
c:\windows\$NtUninstallKB35244$\309698336
c:\windows\$NtUninstallKB35244$\3882783037\{1B372133-BFFA-4dba-9CCF-5474BED6A9F6}
c:\windows\$NtUninstallKB35244$\3882783037\click.tlb
c:\windows\$NtUninstallKB35244$\3882783037\L\akygdmgo
c:\windows\$NtUninstallKB35244$\3882783037\loader.tlb
c:\windows\$NtUninstallKB35244$\3882783037\U\@00000001
c:\windows\$NtUninstallKB35244$\3882783037\U\@000000c0
c:\windows\$NtUninstallKB35244$\3882783037\U\@000000cb
c:\windows\$NtUninstallKB35244$\3882783037\U\@000000cf
c:\windows\$NtUninstallKB35244$\3882783037\U\@80000000
c:\windows\$NtUninstallKB35244$\3882783037\U\@800000c0
c:\windows\$NtUninstallKB35244$\3882783037\U\@800000cb
c:\windows\$NtUninstallKB35244$\3882783037\U\@800000cf
c:\windows\btc_client_iplist.txt
c:\windows\ddh_iplist.txt
c:\windows\front_ip_list.txt
c:\windows\geoiplist
c:\windows\geoiplist.rar
c:\windows\iecheck_iplist.txt
c:\windows\info1
c:\windows\iplist.txt
c:\windows\l1rezerv.exe
c:\windows\loader2.exe_ok
c:\windows\phoenix
c:\windows\phoenix.rar
c:\windows\phoenix\kernels\phatk\__init__.py
c:\windows\phoenix\kernels\phatk\__init__.pyc
c:\windows\phoenix\kernels\phatk\BFIPatcher.py
c:\windows\phoenix\kernels\phatk\kernel.cl
c:\windows\phoenix\kernels\poclbm\__init__.py
c:\windows\phoenix\kernels\poclbm\__init__.pyc
c:\windows\phoenix\kernels\poclbm\BFIPatcher.py
c:\windows\phoenix\kernels\poclbm\kernel.cl
c:\windows\phoenix\phoenix.exe
c:\windows\proc_list1.log
c:\windows\rpcminer
c:\windows\rpcminer.rar
c:\windows\rpcminer\bitcoinminercuda_10.cubin
c:\windows\rpcminer\bitcoinminercuda_11.cubin
c:\windows\rpcminer\bitcoinminercuda_20.cubin
c:\windows\rpcminer\bitcoinmineropencl.cl
c:\windows\rpcminer\cudart32_32_16.dll
c:\windows\rpcminer\curllib.dll
c:\windows\rpcminer\libeay32.dll
c:\windows\rpcminer\libsasl.dll
c:\windows\rpcminer\openldap.dll
c:\windows\rpcminer\rpcminer-4way.exe
c:\windows\rpcminer\rpcminer-cpu.exe
c:\windows\rpcminer\rpcminer-cuda.exe
c:\windows\rpcminer\rpcminer-opencl.exe
c:\windows\rpcminer\ssleay32.dll
c:\windows\services32.exe
c:\windows\sysdriver32.exe
c:\windows\sysdriver32_.exe
c:\windows\system32\c_47380.nls
c:\windows\system32\drivers\etc\HSTS~1
c:\windows\system32\kernel1.exe
c:\windows\systemup.exe
c:\windows\TEMP\6115264.exe
c:\windows\TEMP\8026904.exe
c:\windows\TEMP\9283901.exe
c:\windows\ufa.rar
c:\windows\update.1
c:\windows\update.1\svchost.exe
c:\windows\update.2
c:\windows\update.2\svchost.exe
c:\windows\update.5.0
c:\windows\update.5.0\svchost.exe
c:\windows\update.tray-2-0\svchost.exe
c:\windows\update.tray-3-0\svchost.exe
c:\windows\winlog-dirs.txt
c:\windows\winlog-ids.txt
c:\windows\winsetupapi.log
c:\windows\$NtUninstallKB35244$ . . . . Failed to delete
.
Infected copy of c:\windows\system32\drivers\cdrom.sys was found and disinfected
Restored copy from - The cat found it :)
Infected copy of c:\windows\system32\wuauclt.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\wuauclt.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_SRVBTCCLIENT
-------\Legacy_SRVIECHECK
-------\Legacy_SRVSYSDRIVER32
-------\Legacy_SSHNAS
-------\Legacy_WXPDRIVERS
-------\Service_srvbtcclient
-------\Service_srviecheck
-------\Service_srvsysdriver32
-------\Service_SSHNAS
-------\Service_wxpdrivers
.
.
((((((((((((((((((((((((( Files Created from 2011-06-28 to 2011-07-28 )))))))))))))))))))))))))))))))
.
.
2011-07-28 12:02 . 2008-04-13 23:10 62976 ----a-w- c:\windows\system32\drivers\cdrom.sys
2011-07-27 20:13 . 2011-07-27 20:13 -------- d-----w- c:\documents and settings\Administrator
2011-07-27 20:12 . 2011-07-27 20:28 44560 --sha-w- c:\windows\system32\c_47380.nl_
2011-07-27 17:41 . 2011-07-06 17:52 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-27 17:41 . 2011-07-27 20:08 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-07-27 17:41 . 2011-07-06 17:52 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-27 13:36 . 2011-07-27 13:36 -------- d-----w- c:\program files\trend micro
2011-07-27 13:36 . 2011-07-27 13:36 -------- d-----w- C:\rsit
2011-07-22 16:20 . 2011-07-22 16:20 -------- d-----w- c:\documents and settings\HARDMAN\Application Data\Malwarebytes
2011-07-22 16:20 . 2011-07-22 16:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-07-22 15:44 . 2011-07-22 15:44 -------- d-----w- C:\ERDNT
2011-07-20 12:43 . 2011-07-20 12:43 -------- d-----w- c:\windows\ufa
2011-07-20 12:42 . 2011-07-20 12:43 246272 ----a-w- c:\windows\unrar.exe
2011-07-20 12:40 . 2011-07-20 12:40 -------- d-----w- c:\windows\av_ico
2011-07-20 12:38 . 2011-07-28 12:20 -------- d--h--w- c:\windows\update.tray-3-0
2011-07-20 12:38 . 2011-07-20 12:38 -------- d--h--w- c:\windows\update.tray-3-0-lnk
2011-07-20 12:38 . 2011-07-28 12:20 -------- d--h--w- c:\windows\update.tray-2-0
2011-07-20 12:38 . 2011-07-20 12:38 -------- d--h--w- c:\windows\update.tray-2-0-lnk
2011-07-06 19:14 . 2011-07-19 10:54 -------- d-----w- c:\documents and settings\HARDMAN\Application Data\go
2011-07-06 19:14 . 2011-07-19 10:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Easybits GO
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-27 20:19 . 2008-12-11 22:06 115200 ----a-w- c:\windows\system32\drivers\redbook.sys
2011-06-23 13:00 . 2011-05-18 11:53 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-02 17:53 . 2011-06-02 17:53 94208 ----a-w- c:\windows\system32\dpl100.dll
2011-06-02 14:02 . 2001-08-23 12:00 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-05-02 15:31 . 2008-12-14 14:05 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-29 17:25 . 2001-08-23 12:00 151552 ----a-w- c:\windows\system32\schannel.dll
2011-04-29 16:19 . 2001-08-23 12:00 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
"STYLEXP"="c:\program files\TGTSoft\StyleXP\StyleXP.exe" [2006-05-24 1372160]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2009-04-24 203928]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 61952]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"PAC207_Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"SecurDisc"="c:\program files\Nero\Nero 7\InCD\NBHGui.exe" [2007-06-25 1629480]
"InCD"="c:\program files\Nero\Nero 7\InCD\InCD.exe" [2007-06-25 1057064]
"ASUS Update Checker"="c:\program files\ASUS\ASUSUpdate\UpdateChecker\UpdateChecker.exe" [2008-12-11 114688]
"Ai Nap"="c:\program files\ASUS\AI Suite\AiNap\AiNap.exe" [2007-12-10 1412608]
"CPU Power Monitor"="c:\program files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe" [2007-10-16 626176]
"Cpu Level Up help"="c:\program files\ASUS\AI Suite\CpuLevelUpHelp.exe" [2007-11-30 881152]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2010-06-02 1753192]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-06-07 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-06-07 13902440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2009-11-18 54576]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\HARDMAN\Start Menu\Programs\Startup\
Kalend r.lnk - c:\windows\MENINY.EXE [2009-2-15 49312]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-11-18 275072]
Ralink Wireless Utility.lnk - c:\program files\RALINK\Common\RaUI.exe [2008-12-14 614400]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableSecureUIAPaths"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"DisableThumbnailCache"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DivX\\DivX Update\\DivXUpdate.exe"=
"c:\\Documents and Settings\\HARDMAN\\Local Settings\\Application Data\\Google\\Chrome\\Application\\chrome.exe"=
"z:\\Hry\\Valve\\hl.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Program Files\\Google\\Update\\GoogleUpdate.exe"=
"c:\\WINDOWS\\update.tray-3-0-lnk\\svchost.exe"=
.
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [x]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-01 135664]
R3 GGSAFERDriver;GGSAFER Driver;c:\program files\Garena\safedrv.sys [x]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-01 135664]
R3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [2008-01-25 25088]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-02-04 691696]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2009-05-14 107256]
S1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys [2009-05-14 94360]
S2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [2010-11-21 247608]
S3 PAC207;e-Messenger 112;c:\windows\system32\DRIVERS\PFC027.SYS [2007-10-25 616064]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-28 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-11-16 15:54]
.
2011-07-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cb0d9d335d472e.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-01 12:30]
.
2011-07-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-01 12:30]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://start.icq.com/
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\HARDMAN\Application Data\Mozilla\Firefox\Profiles\2xv5asca.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2418376&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://start.icq.com/
FF - prefs.js: keyword.URL - hxxp://search.sweetim.com/search.asp?src=2&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{A057A204-BACC-4D26-C39E-35F1D2A32EC8} - (no file)
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-wxpdrv - c:\windows\services32.exe
HKLM-Run-tray_ico0 - c:\windows\update.tray-2-0\svchost.exe
HKLM-Run-tray_ico1 - c:\windows\update.tray-3-0\svchost.exe
HKLM-Run-l1rezerv.exe - c:\windows\l1rezerv.exe
HKLM-Run-systemup - c:\windows\systemup.exe
HKLM-Run-tray_ico - (no file)
HKLM-Run-tray_ico2 - (no file)
HKLM-Run-tray_ico3 - (no file)
HKLM-Run-tray_ico4 - (no file)
SafeBoot-Wdf01000.sys
AddRemove-{16B6279B-9FF5-41fb-8BF9-404324F5DD1F}}_is1 - c:\program files\Media Access Startup\1.5.0.850\unins000.exe
AddRemove-{1FB52AB3-5987-45a2-85E0-F3EC30DDDC29}}_is1 - c:\program files\Internet Saving Optimizer\3.4.0.4340\unins000.exe
AddRemove-{C5096216-7703-409E-B85A-8A6EE7395128}}_is1 - c:\program files\System Search Dispatcher\1.2.0.750\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-07-28 14:24
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.cdrom]
"ImagePath"="\*"
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.redbook]
"ImagePath"="\*"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1957994488-789336058-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:1b,93,ac,a1,67,b0,04,ef,ce,2d,68,33,de,3f,a4,ad,90,8b,c4,d2,a6,
e6,1d,21,47,01,46,f5,f0,cd,9f,23,5d,1a,7a,b6,0a,b1,54,16,d3,52,56,32,12,71,\
"rkeysecu"=hex:a6,d9,8e,f3,ed,6f,c7,99,40,e5,5c,37,91,b0,fe,85
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(812)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_slk.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.

Re: FB-vir

Napsal: 28 črc 2011 13:43
od hardman
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Nero\Nero 7\InCD\InCDsrv.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\System32\TUProgSt.exe
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
.
**************************************************************************
.
Completion time: 2011-07-28 14:33:06 - machine was rebooted
ComboFix-quarantined-files.txt 2011-07-28 12:32
.
Pre-Run: 6 817 943 552 bytes free
Post-Run: 13 adresárov, 10 905 903 104 voľných bajtov
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /noexecute=AlwaysOff
.
- - End Of File - - 72195F884046B1102D288F614E52BEF8

Re: FB-vir

Napsal: 28 črc 2011 17:45
od p.Jenan
Přesuňte ComboFix na plochu. Otevřte poznámkový blok a zkopírujte do něj:
Collect::
c:\windows\unrar.exe

Folder::
c:\windows\update.tray-3-0
c:\windows\update.tray-3-0-lnk
c:\windows\ufa
c:\windows\av_ico
c:\windows\update.tray-2-0
c:\windows\update.tray-2-0-lnk
Uložte na plochu jako CFScript.txt . Pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.

Obrázek

Otestujte tento soubor - c:\windows\system32\c_47380.nl_
na http://www.virustotal.com/

Re: FB-vir

Napsal: 28 črc 2011 19:18
od hardman
Podarilo sa mi spustit mBam tak prikladam log ale neviem ako mam dalej postupovat.Mam dat Odstranit vybrate?

alwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org

Verzia databázy: 7310

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

28.7.2011 20:13:51
mbam-log-2011-07-28 (20-13-38).txt

Typ kontroly: Úplná kontrola (C:\|Z:\|)
Objektov kontrolovaných: 332273
Uplynutý čas: 1 hod, 43 min, 53 sek

Infikované služby pamäte: 0
Infikované moduly pamäte: 0
Infikované registračné kľúče: 6
Infikované registračné hodnoty: 6
Infikované položky registračných dát: 0
Infikované priečinky: 0
Infikované súbory: 44

Infikované služby pamäte:
(Škodlivé položky neboli zistené)

Infikované moduly pamäte:
(Škodlivé položky neboli zistené)

Infikované registračné kľúče:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5617ECA9-488D-4BA2-8562-9710B9AB78D2} (Adware.DoubleD) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\DoubleD (Adware.DoubleD) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Internet Saving Optimizer (Adware.DoubleD) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Media Access Startup (Adware.DoubleD) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Internet Saving Optimizer (Adware.DoubleD) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Media Access Startup (Adware.DoubleD) -> No action taken.

Infikované registračné hodnoty:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{5617ECA9-488D-4BA2-8562-9710B9AB78D2} (Adware.DoubleD) -> Value: {5617ECA9-488D-4BA2-8562-9710B9AB78D2} -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{5617ECA9-488D-4BA2-8562-9710B9AB78D2} (Adware.DoubleD) -> Value: {5617ECA9-488D-4BA2-8562-9710B9AB78D2} -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extensions\{2224E955-00E9-4613-A844-CE69FCCAAE91} (Adware.DoubleD) -> Value: {2224E955-00E9-4613-A844-CE69FCCAAE91} -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extensions\{2224E955-00E9-4613-A844-CE69FCCAAE91} (Adware.DoubleD) -> Value: {2224E955-00E9-4613-A844-CE69FCCAAE91} -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extensions\{0BA0192D-94A5-45e3-B2B8-3EC5A1A0B5EC} (Adware.DoubleD) -> Value: {0BA0192D-94A5-45e3-B2B8-3EC5A1A0B5EC} -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extensions\{0BA0192D-94A5-45e3-B2B8-3EC5A1A0B5EC} (Adware.DoubleD) -> Value: {0BA0192D-94A5-45e3-B2B8-3EC5A1A0B5EC} -> No action taken.

Infikované položky registračných dát:
(Škodlivé položky neboli zistené)

Infikované priečinky:
(Škodlivé položky neboli zistené)

Infikované súbory:
c:\documents and settings\HARDMAN\Desktop\trainer_4331_fable v1.0 +6 trainer\fabledt_skossino.exe (PUP.HackTool.HotKeysHook) -> No action taken.
c:\documents and settings\HARDMAN\Desktop\gm_xt_5.00.60___2009.2.part1\gm xt 5.00.60 + 2009.2\Unlock\garmin_kgen.exe (RiskWare.Tool.CK) -> No action taken.
c:\documents and settings\HARDMAN\Desktop\Ostatne\USB\legalizuok savo windowsus per 2 sekundes!_by_kunigelis\keyfinder.exe (RiskWare.Tool.CK) -> No action taken.
c:\documents and settings\HARDMAN\Desktop\nfsmw-treiner\pzn-nfst.exe (Malware.Packer.Gen) -> No action taken.
c:\program files\alcohol soft\alcohol 120\Langs\AX_RU.dll (Malware.Packer.GenX) -> No action taken.
c:\Qoobox\quarantine\C\program files\internet saving optimizer\3.4.0.4340\npcommon.dll.vir (Adware.DoubleD) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\l1rezerv.exe.vir (Trojan.Agent) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\services32.exe.vir (Trojan.Dropper) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\sysdriver32_.exe.vir (Trojan.Agent) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\systemup.exe.vir (Trojan.Agent) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\update.1\svchost.exe.vir (Trojan.Dropper) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\update.tray-2-0\svchost.exe.vir (Trojan.Dropper) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\update.tray-3-0\svchost.exe.vir (Trojan.Dropper) -> No action taken.
c:\system volume information\_restore{53af324a-787a-4ec7-aeab-6ce236e4664f}\RP497\A0151640.exe (Trojan.Dropper) -> No action taken.
c:\system volume information\_restore{53af324a-787a-4ec7-aeab-6ce236e4664f}\RP497\A0151641.exe (Trojan.Dropper) -> No action taken.
c:\system volume information\_restore{53af324a-787a-4ec7-aeab-6ce236e4664f}\RP497\A0151642.exe (Trojan.Dropper) -> No action taken.
c:\system volume information\_restore{53af324a-787a-4ec7-aeab-6ce236e4664f}\RP497\A0151643.exe (Trojan.Dropper) -> No action taken.
c:\system volume information\_restore{53af324a-787a-4ec7-aeab-6ce236e4664f}\RP497\A0151648.exe (Trojan.Dropper) -> No action taken.
c:\system volume information\_restore{53af324a-787a-4ec7-aeab-6ce236e4664f}\RP497\A0151649.exe (Trojan.Dropper) -> No action taken.
c:\system volume information\_restore{53af324a-787a-4ec7-aeab-6ce236e4664f}\RP497\A0151650.exe (Trojan.Dropper) -> No action taken.
c:\system volume information\_restore{53af324a-787a-4ec7-aeab-6ce236e4664f}\RP497\A0151651.exe (Trojan.Dropper) -> No action taken.
c:\system volume information\_restore{53af324a-787a-4ec7-aeab-6ce236e4664f}\RP497\A0152656.exe (Trojan.Dropper) -> No action taken.
c:\system volume information\_restore{53af324a-787a-4ec7-aeab-6ce236e4664f}\RP497\A0152657.exe (Trojan.Dropper) -> No action taken.
c:\system volume information\_restore{53af324a-787a-4ec7-aeab-6ce236e4664f}\RP497\A0152658.exe (Trojan.Dropper) -> No action taken.
c:\system volume information\_restore{53af324a-787a-4ec7-aeab-6ce236e4664f}\RP497\A0152659.exe (Trojan.Dropper) -> No action taken.
c:\system volume information\_restore{53af324a-787a-4ec7-aeab-6ce236e4664f}\RP497\A0152664.exe (Trojan.Dropper) -> No action taken.
c:\system volume information\_restore{53af324a-787a-4ec7-aeab-6ce236e4664f}\RP497\A0152665.exe (Trojan.Dropper) -> No action taken.
c:\system volume information\_restore{53af324a-787a-4ec7-aeab-6ce236e4664f}\RP497\A0152666.exe (Trojan.Dropper) -> No action taken.
c:\system volume information\_restore{53af324a-787a-4ec7-aeab-6ce236e4664f}\RP497\A0152667.exe (Trojan.Dropper) -> No action taken.
c:\system volume information\_restore{53af324a-787a-4ec7-aeab-6ce236e4664f}\RP497\A0153749.dll (Adware.DoubleD) -> No action taken.
c:\system volume information\_restore{53af324a-787a-4ec7-aeab-6ce236e4664f}\RP497\A0153755.exe (Trojan.Agent) -> No action taken.
c:\system volume information\_restore{53af324a-787a-4ec7-aeab-6ce236e4664f}\RP497\A0153770.exe (Trojan.Dropper) -> No action taken.
c:\system volume information\_restore{53af324a-787a-4ec7-aeab-6ce236e4664f}\RP497\A0153772.exe (Trojan.Agent) -> No action taken.
c:\system volume information\_restore{53af324a-787a-4ec7-aeab-6ce236e4664f}\RP497\A0153774.exe (Trojan.Agent) -> No action taken.
c:\system volume information\_restore{53af324a-787a-4ec7-aeab-6ce236e4664f}\RP497\A0153775.exe (Trojan.Dropper) -> No action taken.
c:\system volume information\_restore{53af324a-787a-4ec7-aeab-6ce236e4664f}\RP497\A0153778.exe (Trojan.Dropper) -> No action taken.
c:\system volume information\_restore{53af324a-787a-4ec7-aeab-6ce236e4664f}\RP497\A0153779.exe (Trojan.Dropper) -> No action taken.
c:\WINDOWS\update.tray-2-0-lnk\svchost.exe (Trojan.Dropper) -> No action taken.
c:\WINDOWS\update.tray-3-0-lnk\svchost.exe (Trojan.Dropper) -> No action taken.
z:\downloads\facebook-pic000934519.exe (Backdoor.Bot) -> No action taken.
z:\Instal\office2007sk\Bonus\keygen.exe (RiskWare.Tool.CK) -> No action taken.
z:\Instal\Programy\legalizuok savo windowsus per 2 sekundes!_by_kunigelis\keyfinder.exe (RiskWare.Tool.CK) -> No action taken.
z:\my documents\ICQ\387551895\receivedfiles\469150048 maroš\keyfinder.exe (RiskWare.Tool.CK) -> No action taken.
c:\WINDOWS\system32\h@tkeysh@@k.dll (Trojan.Agent) -> No action taken.

Re: FB-vir

Napsal: 28 črc 2011 19:26
od p.Jenan
Provedl jste CF script, jak jsem psal výše? :)

Re: FB-vir

Napsal: 28 črc 2011 19:44
od hardman
Spravil som ten Script.Ked sa to dokonci poslem log :happy:

Re: FB-vir

Napsal: 28 črc 2011 20:12
od hardman
ComboFix 11-07-28.01 - HARDMAN 28.07.2011 20:42:55.2.1 - x86
Running from: c:\documents and settings\HARDMAN\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\HARDMAN\Desktop\CFScript.txt.txt
* Created a new restore point
.
file zipped: c:\windows\unrar.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\av_ico
c:\windows\av_ico\ico_NOD_AV_START.ico
c:\windows\av_ico\ico_NOD_SS_START.ico
c:\windows\av_ico\ico_NOD_SYSINSP.ico
c:\windows\av_ico\ico_NOD_SYSRESC.ico
c:\windows\av_ico\ico_NOD_TXT.ico
c:\windows\av_ico\ico_NOD_UNINSTALL.ico
c:\windows\ufa
c:\windows\ufa\ufa.exe
c:\windows\unrar.exe
c:\windows\update.tray-2-0-lnk
c:\windows\update.tray-2-0
c:\windows\update.tray-3-0-lnk
c:\windows\update.tray-3-0
.
.
((((((((((((((((((((((((( Files Created from 2011-06-28 to 2011-07-28 )))))))))))))))))))))))))))))))
.
.
2011-07-28 12:02 . 2008-04-13 23:10 62976 ----a-w- c:\windows\system32\drivers\cdrom.sys
2011-07-27 20:13 . 2011-07-27 20:13 -------- d-----w- c:\documents and settings\Administrator
2011-07-27 20:12 . 2011-07-27 20:28 44560 --sha-w- c:\windows\system32\c_47380.nl_
2011-07-27 17:41 . 2011-07-06 17:52 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-27 17:41 . 2011-07-28 18:13 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-07-27 17:41 . 2011-07-06 17:52 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-27 13:36 . 2011-07-27 13:36 -------- d-----w- c:\program files\trend micro
2011-07-27 13:36 . 2011-07-27 13:36 -------- d-----w- C:\rsit
2011-07-22 16:20 . 2011-07-22 16:20 -------- d-----w- c:\documents and settings\HARDMAN\Application Data\Malwarebytes
2011-07-22 16:20 . 2011-07-22 16:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-07-22 15:44 . 2011-07-22 15:44 -------- d-----w- C:\ERDNT
2011-07-06 19:14 . 2011-07-19 10:54 -------- d-----w- c:\documents and settings\HARDMAN\Application Data\go
2011-07-06 19:14 . 2011-07-19 10:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Easybits GO
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-27 20:19 . 2008-12-11 22:06 115200 ----a-w- c:\windows\system32\drivers\redbook.sys
2011-06-23 13:00 . 2011-05-18 11:53 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-02 17:53 . 2011-06-02 17:53 94208 ----a-w- c:\windows\system32\dpl100.dll
2011-06-02 14:02 . 2001-08-23 12:00 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-05-02 15:31 . 2008-12-14 14:05 692736 ----a-w- c:\windows\system32\inetcomm.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
"STYLEXP"="c:\program files\TGTSoft\StyleXP\StyleXP.exe" [2006-05-24 1372160]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2009-04-24 203928]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 61952]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"PAC207_Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"SecurDisc"="c:\program files\Nero\Nero 7\InCD\NBHGui.exe" [2007-06-25 1629480]
"InCD"="c:\program files\Nero\Nero 7\InCD\InCD.exe" [2007-06-25 1057064]
"ASUS Update Checker"="c:\program files\ASUS\ASUSUpdate\UpdateChecker\UpdateChecker.exe" [2008-12-11 114688]
"Ai Nap"="c:\program files\ASUS\AI Suite\AiNap\AiNap.exe" [2007-12-10 1412608]
"CPU Power Monitor"="c:\program files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe" [2007-10-16 626176]
"Cpu Level Up help"="c:\program files\ASUS\AI Suite\CpuLevelUpHelp.exe" [2007-11-30 881152]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2010-06-02 1753192]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-06-07 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-06-07 13902440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2009-11-18 54576]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\HARDMAN\Start Menu\Programs\Startup\
Kalend r.lnk - c:\windows\MENINY.EXE [2009-2-15 49312]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-11-18 275072]
Ralink Wireless Utility.lnk - c:\program files\RALINK\Common\RaUI.exe [2008-12-14 614400]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableSecureUIAPaths"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"DisableThumbnailCache"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DivX\\DivX Update\\DivXUpdate.exe"=
"c:\\Documents and Settings\\HARDMAN\\Local Settings\\Application Data\\Google\\Chrome\\Application\\chrome.exe"=
"z:\\Hry\\Valve\\hl.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Program Files\\Google\\Update\\GoogleUpdate.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [x]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-01 135664]
R3 GGSAFERDriver;GGSAFER Driver;c:\program files\Garena\safedrv.sys [x]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-01 135664]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-07-06 41272]
R3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [2008-01-25 25088]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-02-04 691696]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2009-05-14 107256]
S1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys [2009-05-14 94360]
S2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [2010-11-21 247608]
S3 PAC207;e-Messenger 112;c:\windows\system32\DRIVERS\PFC027.SYS [2007-10-25 616064]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-28 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-11-16 15:54]
.
2011-07-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cb0d9d335d472e.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-01 12:30]
.
2011-07-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-01 12:30]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://start.icq.com/
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\HARDMAN\Application Data\Mozilla\Firefox\Profiles\2xv5asca.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2418376&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://start.icq.com/
FF - prefs.js: keyword.URL - hxxp://search.sweetim.com/search.asp?src=2&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-07-28 20:57
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.cdrom]
"ImagePath"="\*"
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.redbook]
"ImagePath"="\*"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1957994488-789336058-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:1b,93,ac,a1,67,b0,04,ef,ce,2d,68,33,de,3f,a4,ad,90,8b,c4,d2,a6,
e6,1d,21,47,01,46,f5,f0,cd,9f,23,5d,1a,7a,b6,0a,b1,54,16,d3,52,56,32,12,71,\
"rkeysecu"=hex:a6,d9,8e,f3,ed,6f,c7,99,40,e5,5c,37,91,b0,fe,85
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(2736)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_slk.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Nero\Nero 7\InCD\InCDsrv.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\System32\TUProgSt.exe
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
.
**************************************************************************
.
Completion time: 2011-07-28 21:05:18 - machine was rebooted
ComboFix-quarantined-files.txt 2011-07-28 19:05
ComboFix2.txt 2011-07-28 12:33
.
Pre-Run: 10 744 610 816 bytes free
Post-Run: 13 adresárov, 10 724 519 936 voľných bajtov
.
- - End Of File - - AB146D7BC0739AA86809CEBAA2CB69F4
Upload was successful

Re: FB-vir

Napsal: 28 črc 2011 20:22
od p.Jenan
ComboFix log je v pořádku. :)

Pro jistotu, udělejte ještě kompletní sken MBAM: http://www.malwarebytes.org/mbam.php a dejte log. Předem nic nemažte.

A jak se PC nyní chová? :) Jsou tam stále nějaké problémy?