facebook vir
Napsal: 16 srp 2011 12:15
Logfile of random's system information tool 1.09 (written by random/random)
Run by chorche at 2011-08-16 13:09:27
Microsoft Windows 7 Home Premium
System drive C: has 8 GB (13%) free of 61 GB
Total RAM: 3071 MB (61% free)
======Scheduled tasks folder======
C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-2641354541-1172337044-3281749162-1000Core.job
C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-2641354541-1172337044-3281749162-1000UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0FB6A909-6086-458F-BD92-1F8EE10042A0}]
AC-Pro - C:\Program Files\AutocompletePro\AutocompletePro.dll [2010-07-14 97760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files\ConduitEngine\ConduitEngine.dll [2010-09-12 3863136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Symantec NCO BHO - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6B5863A0-C43F-4C0A-982B-CC0E9125783F}]
QipLI Class - C:\Users\chorche\AppData\Roaming\Microsoft\Internet Explorer\qstatsrv.dll [2010-04-12 45568]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Symantec Intrusion Prevention - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\IPSBHO.DLL []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class - C:\Users\chorche\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll [2010-04-12 149968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-08-20 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{dfabc5b5-039b-4865-979a-de31cdf3e351}]
Media Star Toolbar - C:\Program Files\Media_Star\tbMedi.dll [2010-09-12 3863136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll []
{dfabc5b5-039b-4865-979a-de31cdf3e351} - Media Star Toolbar - C:\Program Files\Media_Star\tbMedi.dll [2010-09-12 3863136]
{30F9B915-B755-4826-820B-08FBA6BD249D} - Conduit Engine - C:\Program Files\ConduitEngine\ConduitEngine.dll [2010-09-12 3863136]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\windows\system32\NvCpl.dll [2009-07-23 13797920]
"ITSecMng"=C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe [2009-07-22 83336]
"MGSysCtrl"=C:\Program Files\System Control Manager\MGSysCtrl.exe [2009-07-24 2068480]
"ArcSoft Connection Service"=C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2010-10-27 207424]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2009-07-20 7625248]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-07-10 98304]
"Adobe Reader Speed Launcher"=D:\Programy\Acrobat Reader\Reader\Reader_sl.exe [2010-06-20 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-21 932288]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"USBToolTip"=C:\PROGRA~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe [2007-02-20 199752]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"LogMeIn Hamachi Ui"=C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [2010-03-30 1820040]
"wxpdrv"= []
"tray_ico"= []
"tray_ico0"=C:\windows\update.tray-10-0\svchost.exe [2011-07-21 1180672]
"tray_ico1"= []
"tray_ico2"= []
"tray_ico3"= []
"tray_ico4"= []
"Malwarebytes' Anti-Malware"=D:\Programy\Malwarebytes' Anti-Malware\mbamgui.exe [2011-07-06 449584]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\chorche\AppData\Local\Google\Update\GoogleUpdate.exe [2010-06-23 136176]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1173504]
"EA Core"=C:\Program Files\Electronic Arts\EADM\Core.exe [2009-03-28 3325952]
"Steam"=C:\Program Files\Steam\Steam.exe [2011-08-15 1242448]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Users\chorche\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SymEFA.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\wxpdrivers]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableSecureUIAPaths"=0
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"VIDC.CFHD"=cfhd.dll
"vidc.VP60"=C:\windows\system32\vp6vfw.dll
"vidc.VP61"=C:\windows\system32\vp6vfw.dll
"vidc.mjpg"=pvmjpg30.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2011-08-16 13:09:27 ----D---- C:\rsit
2011-08-16 13:09:27 ----D---- C:\Program Files\trend micro
2011-08-15 12:36:47 ----D---- C:\ATI
2011-08-15 12:26:30 ----D---- C:\Program Files\CCleaner
2011-08-15 12:24:52 ----A---- C:\TDSSKiller.2.5.11.0_15.08.2011_12.24.52_log.txt
2011-07-27 15:11:52 ----D---- C:\windows\ufa
2011-07-27 15:11:52 ----D---- C:\windows\rpcminer
2011-07-27 15:11:52 ----D---- C:\windows\phoenix
2011-07-27 15:11:32 ----A---- C:\windows\btc_client_iplist.txt
2011-07-22 12:33:41 ----D---- C:\Users\chorche\AppData\Roaming\Malwarebytes
2011-07-22 12:32:13 ----D---- C:\ProgramData\Malwarebytes
2011-07-22 12:32:13 ----A---- C:\windows\system32\drivers\mbamswissarmy.sys
2011-07-22 12:32:10 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-07-22 12:32:10 ----A---- C:\windows\system32\drivers\mbam.sys
2011-07-21 21:18:14 ----A---- C:\windows\ddh_iplist.txt
2011-07-21 21:17:36 ----A---- C:\windows\l1rezerv.exe
2011-07-21 21:17:30 ----A---- C:\windows\systemup.exe
2011-07-21 21:17:22 ----A---- C:\windows\iecheck_iplist.txt
2011-07-21 21:17:01 ----HD---- C:\windows\update.2
2011-07-21 21:16:54 ----A---- C:\windows\unrar.exe
2011-07-21 21:16:33 ----HD---- C:\windows\update.5.0
2011-07-21 21:16:19 ----A---- C:\windows\sysdriver32_.exe
2011-07-21 21:16:14 ----A---- C:\windows\iplist.txt
2011-07-21 21:16:05 ----A---- C:\windows\sysdriver32.exe
2011-07-21 21:15:38 ----A---- C:\windows\front_ip_list.txt
2011-07-21 21:15:33 ----D---- C:\windows\av_ico
2011-07-21 21:15:14 ----ASH---- C:\pagefile.sys
2011-07-21 21:14:08 ----HD---- C:\windows\update.1
2011-07-21 21:13:57 ----HD---- C:\windows\update.tray-10-0-lnk
2011-07-21 21:13:57 ----HD---- C:\windows\update.tray-10-0
2011-07-21 21:02:02 ----A---- C:\windows\winlog-ids.txt
2011-07-21 21:02:02 ----A---- C:\windows\winlog-dirs.txt
2011-07-21 21:01:58 ----A---- C:\windows\services32.exe
======List of files/folders modified in the last 1 month======
2011-08-16 13:09:32 ----D---- C:\windows\Temp
2011-08-16 13:09:27 ----RD---- C:\Program Files
2011-08-16 13:06:32 ----D---- C:\Program Files\Steam
2011-08-16 13:06:07 ----D---- C:\windows\system32\config
2011-08-16 13:05:36 ----D---- C:\windows\system32\drivers
2011-08-16 13:02:05 ----D---- C:\windows\system32\drivers\etc
2011-08-16 13:02:01 ----SHD---- C:\System Volume Information
2011-08-16 12:49:06 ----D---- C:\windows\Prefetch
2011-08-16 12:01:34 ----D---- C:\Program Files\Common Files\Steam
2011-08-15 12:31:53 ----D---- C:\Windows
2011-08-15 12:28:01 ----D---- C:\Users\chorche\AppData\Roaming\DAEMON Tools Lite
2011-08-15 12:27:44 ----D---- C:\windows\Logs
2011-08-15 12:27:44 ----D---- C:\windows\debug
2011-07-22 12:32:13 ----HD---- C:\ProgramData
2011-07-22 10:31:34 ----D---- C:\windows\System32
2011-07-21 18:34:36 ----D---- C:\windows\inf
2011-07-21 18:34:36 ----A---- C:\windows\system32\PerfStringBackup.INI
2011-07-20 10:43:17 ----D---- C:\windows\system32\NDF
Run by chorche at 2011-08-16 13:09:27
Microsoft Windows 7 Home Premium
System drive C: has 8 GB (13%) free of 61 GB
Total RAM: 3071 MB (61% free)
======Scheduled tasks folder======
C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-2641354541-1172337044-3281749162-1000Core.job
C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-2641354541-1172337044-3281749162-1000UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0FB6A909-6086-458F-BD92-1F8EE10042A0}]
AC-Pro - C:\Program Files\AutocompletePro\AutocompletePro.dll [2010-07-14 97760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files\ConduitEngine\ConduitEngine.dll [2010-09-12 3863136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Symantec NCO BHO - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6B5863A0-C43F-4C0A-982B-CC0E9125783F}]
QipLI Class - C:\Users\chorche\AppData\Roaming\Microsoft\Internet Explorer\qstatsrv.dll [2010-04-12 45568]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Symantec Intrusion Prevention - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\IPSBHO.DLL []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class - C:\Users\chorche\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll [2010-04-12 149968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-08-20 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{dfabc5b5-039b-4865-979a-de31cdf3e351}]
Media Star Toolbar - C:\Program Files\Media_Star\tbMedi.dll [2010-09-12 3863136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll []
{dfabc5b5-039b-4865-979a-de31cdf3e351} - Media Star Toolbar - C:\Program Files\Media_Star\tbMedi.dll [2010-09-12 3863136]
{30F9B915-B755-4826-820B-08FBA6BD249D} - Conduit Engine - C:\Program Files\ConduitEngine\ConduitEngine.dll [2010-09-12 3863136]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\windows\system32\NvCpl.dll [2009-07-23 13797920]
"ITSecMng"=C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe [2009-07-22 83336]
"MGSysCtrl"=C:\Program Files\System Control Manager\MGSysCtrl.exe [2009-07-24 2068480]
"ArcSoft Connection Service"=C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2010-10-27 207424]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2009-07-20 7625248]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-07-10 98304]
"Adobe Reader Speed Launcher"=D:\Programy\Acrobat Reader\Reader\Reader_sl.exe [2010-06-20 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-21 932288]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"USBToolTip"=C:\PROGRA~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe [2007-02-20 199752]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"LogMeIn Hamachi Ui"=C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [2010-03-30 1820040]
"wxpdrv"= []
"tray_ico"= []
"tray_ico0"=C:\windows\update.tray-10-0\svchost.exe [2011-07-21 1180672]
"tray_ico1"= []
"tray_ico2"= []
"tray_ico3"= []
"tray_ico4"= []
"Malwarebytes' Anti-Malware"=D:\Programy\Malwarebytes' Anti-Malware\mbamgui.exe [2011-07-06 449584]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\chorche\AppData\Local\Google\Update\GoogleUpdate.exe [2010-06-23 136176]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1173504]
"EA Core"=C:\Program Files\Electronic Arts\EADM\Core.exe [2009-03-28 3325952]
"Steam"=C:\Program Files\Steam\Steam.exe [2011-08-15 1242448]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Users\chorche\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SymEFA.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\wxpdrivers]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableSecureUIAPaths"=0
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"VIDC.CFHD"=cfhd.dll
"vidc.VP60"=C:\windows\system32\vp6vfw.dll
"vidc.VP61"=C:\windows\system32\vp6vfw.dll
"vidc.mjpg"=pvmjpg30.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2011-08-16 13:09:27 ----D---- C:\rsit
2011-08-16 13:09:27 ----D---- C:\Program Files\trend micro
2011-08-15 12:36:47 ----D---- C:\ATI
2011-08-15 12:26:30 ----D---- C:\Program Files\CCleaner
2011-08-15 12:24:52 ----A---- C:\TDSSKiller.2.5.11.0_15.08.2011_12.24.52_log.txt
2011-07-27 15:11:52 ----D---- C:\windows\ufa
2011-07-27 15:11:52 ----D---- C:\windows\rpcminer
2011-07-27 15:11:52 ----D---- C:\windows\phoenix
2011-07-27 15:11:32 ----A---- C:\windows\btc_client_iplist.txt
2011-07-22 12:33:41 ----D---- C:\Users\chorche\AppData\Roaming\Malwarebytes
2011-07-22 12:32:13 ----D---- C:\ProgramData\Malwarebytes
2011-07-22 12:32:13 ----A---- C:\windows\system32\drivers\mbamswissarmy.sys
2011-07-22 12:32:10 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-07-22 12:32:10 ----A---- C:\windows\system32\drivers\mbam.sys
2011-07-21 21:18:14 ----A---- C:\windows\ddh_iplist.txt
2011-07-21 21:17:36 ----A---- C:\windows\l1rezerv.exe
2011-07-21 21:17:30 ----A---- C:\windows\systemup.exe
2011-07-21 21:17:22 ----A---- C:\windows\iecheck_iplist.txt
2011-07-21 21:17:01 ----HD---- C:\windows\update.2
2011-07-21 21:16:54 ----A---- C:\windows\unrar.exe
2011-07-21 21:16:33 ----HD---- C:\windows\update.5.0
2011-07-21 21:16:19 ----A---- C:\windows\sysdriver32_.exe
2011-07-21 21:16:14 ----A---- C:\windows\iplist.txt
2011-07-21 21:16:05 ----A---- C:\windows\sysdriver32.exe
2011-07-21 21:15:38 ----A---- C:\windows\front_ip_list.txt
2011-07-21 21:15:33 ----D---- C:\windows\av_ico
2011-07-21 21:15:14 ----ASH---- C:\pagefile.sys
2011-07-21 21:14:08 ----HD---- C:\windows\update.1
2011-07-21 21:13:57 ----HD---- C:\windows\update.tray-10-0-lnk
2011-07-21 21:13:57 ----HD---- C:\windows\update.tray-10-0
2011-07-21 21:02:02 ----A---- C:\windows\winlog-ids.txt
2011-07-21 21:02:02 ----A---- C:\windows\winlog-dirs.txt
2011-07-21 21:01:58 ----A---- C:\windows\services32.exe
======List of files/folders modified in the last 1 month======
2011-08-16 13:09:32 ----D---- C:\windows\Temp
2011-08-16 13:09:27 ----RD---- C:\Program Files
2011-08-16 13:06:32 ----D---- C:\Program Files\Steam
2011-08-16 13:06:07 ----D---- C:\windows\system32\config
2011-08-16 13:05:36 ----D---- C:\windows\system32\drivers
2011-08-16 13:02:05 ----D---- C:\windows\system32\drivers\etc
2011-08-16 13:02:01 ----SHD---- C:\System Volume Information
2011-08-16 12:49:06 ----D---- C:\windows\Prefetch
2011-08-16 12:01:34 ----D---- C:\Program Files\Common Files\Steam
2011-08-15 12:31:53 ----D---- C:\Windows
2011-08-15 12:28:01 ----D---- C:\Users\chorche\AppData\Roaming\DAEMON Tools Lite
2011-08-15 12:27:44 ----D---- C:\windows\Logs
2011-08-15 12:27:44 ----D---- C:\windows\debug
2011-07-22 12:32:13 ----HD---- C:\ProgramData
2011-07-22 10:31:34 ----D---- C:\windows\System32
2011-07-21 18:34:36 ----D---- C:\windows\inf
2011-07-21 18:34:36 ----A---- C:\windows\system32\PerfStringBackup.INI
2011-07-20 10:43:17 ----D---- C:\windows\system32\NDF