
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Problem s PC je pomaly
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Problem s PC je pomaly
Prosim o pomoc PC je pomaly a procesor stale pracuje prosim o kontrolu logu DAKUJEM
Logfile of random's system information tool 1.06 (written by random/random)
Run by Adrián Pyteľ at 2010-02-19 19:45:04
Systém Microsoft Windows XP Professional Service Pack 4
System drive C: has 4 GB (21%) free of 20 GB
Total RAM: 1023 MB (23% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:46:20, on 19.2.2010
Platform: Windows XP SP4 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Aware2007.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\RSIT.exe
C:\Program Files\trend micro\Adrián Pyteľ.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://search13.net/search.php?clid=486&q=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search13.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search13.net/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=66022
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search13.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://search13.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Config\csrss.exe
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - D:\Programz\Orbitdownloader\orbitcth.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: BrowserHelper Class - {8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6} - C:\Program Files\SGPSA\SearchAssistant.dll
O2 - BHO: Search Assistant - {F0626A63-410B-45E2-99A1-3F2475B2D695} - C:\Program Files\SGPSA\BHO.dll
O3 - Toolbar: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Compress Image Using Image Compressor 2008 - D:\Programy\image compressor 08 pro ed\imcieex_compress.html
O8 - Extra context menu item: &Download by Orbit - res://D:\Programz\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://D:\Programz\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://D:\Programz\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://D:\Programz\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {248F1F2D-E854-40AD-BB42-2E69EBC1CD8B} (ST WebDialer Control) - https://zona.t-com.sk/VianKampan2007/STWebDialer.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{37A055EB-FE2D-476C-92EE-88BDDD2D3473}: NameServer = 217.119.124.1 217.119.124.146
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\wbsys.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Služba Google Update (gupdate1ca56fca6d5367e) (gupdate1ca56fca6d5367e) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Performance Driver Service - Unknown owner - C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
--
End of file - 9110 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Automatic troubleshooting.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000123B4-9B42-4900-B3F7-F4B073EFC214}]
Octh Class - D:\Programz\Orbitdownloader\orbitcth.dll [2009-12-21 240912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll [2008-02-22 509328]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6}]
BrowserHelper Class - C:\Program Files\SGPSA\SearchAssistant.dll [2009-10-15 123904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F0626A63-410B-45E2-99A1-3F2475B2D695}]
Search Assistant - C:\Program Files\SGPSA\BHO.dll [2009-11-06 293376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2004-08-04 208952]
"MSPY2002"=C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe [2004-08-04 59392]
"nod32kui"=C:\Program Files\Eset\nod32kui.exe [2008-08-15 949376]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-10-07 13574144]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-10-07 86016]
"UserFaultCheck"=C:\WINDOWS\system32\dumprep 0 -u []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
"ISUSPM"=C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe [2006-09-10 218032]
"Pando Media Booster"=C:\Program Files\Pando Networks\Media Booster\PMB.exe [2009-12-20 2935480]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\WINDOWS\system32\wbsys.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\MCPClient]
C:\PROGRA~1\COMMON~1\Stardock\mcpstub.dll [2005-01-31 49152]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WBSrv]
D:\Programy\WindowBlinds\wbsrv.dll [2008-03-16 229376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - C:\PROGRA~1\COMMON~1\stardock\MCPCore.dll [2005-05-10 86016]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-05-09 52224]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2004-08-04 239616]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoResolveSearch"=
"NoDriveTypeAutoRun"=
"NoDrives"=
"NoDriveAutoRun"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Programy\uTorrent\utorrent.exe"="D:\Programy\uTorrent\utorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Windows Media Player\wmplayer.exe"="C:\Program Files\Windows Media Player\wmplayer.exe:*:Enabled:Windows Media Player"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"D:\Programy\Clear FTP 2006\clearftp.exe"="D:\Programy\Clear FTP 2006\clearftp.exe:*:Enabled:clearftp"
"D:\Programy\Fps Creator\MyGames\arenaskuska\arenaskuska.exe"="D:\Programy\Fps Creator\MyGames\arenaskuska\arenaskuska.exe:*:Enabled:FPSC Game"
"D:\Programy\Fps Creator\FPSC-Game.exe"="D:\Programy\Fps Creator\FPSC-Game.exe:*:Enabled:FPSC Game"
"D:\Programy\eDisk klient\eDisk klient.exe"="D:\Programy\eDisk klient\eDisk klient.exe:*:Enabled:eDisk klient"
"D:\Programy\Fps Creator\MyGames\arenaskuska2\arenaskuska2.exe"="D:\Programy\Fps Creator\MyGames\arenaskuska2\arenaskuska2.exe:*:Enabled:FPSC Game"
"D:\Programy\Hamachi\hamachi.exe"="D:\Programy\Hamachi\hamachi.exe:*:Enabled:Hamachi Client"
"D:\Programy\GoQ - NetRadio\NetRadio.exe"="D:\Programy\GoQ - NetRadio\NetRadio.exe:*:Enabled:NetRadio"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"D:\Programy\HLSW\hlsw.exe"="D:\Programy\HLSW\hlsw.exe:*:Enabled:HLSW Application"
"C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe"="C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe:*:Enabled:Nexon Game Manager"
"D:\Programy\QIP Infium\infium.exe"="D:\Programy\QIP Infium\infium.exe:*:Enabled:QIP Infium"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"D:\Programz\Orbitdownloader\orbitdm.exe"="D:\Programz\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit"
"D:\Programz\Orbitdownloader\orbitnet.exe"="D:\Programz\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit"
"D:\Programy\LimeWire\LimeWire.exe"="D:\Programy\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
"D:\HRY\Call of Duty 4 - Modern Warfare\iw3mp.exe"="D:\HRY\Call of Duty 4 - Modern Warfare\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) "
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\WINDOWS\system32\dplaysvr.exe"="C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"D:\Programy\Edisk\eDisk klient\eDisk klient.exe"="D:\Programy\Edisk\eDisk klient\eDisk klient.exe:*:Enabled:eDisk klient"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"D:\Programy\real player\realplay.exe"="D:\Programy\real player\realplay.exe:*:Enabled:RealPlayer"
"D:\Programy\iTunes\iTunes.exe"="D:\Programy\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
"D:\Programy\Plugin Manager\skypePM.exe"="D:\Programy\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"D:\HRY\THPS2\THawk2_smaller.exe"="D:\HRY\THPS2\THawk2_smaller.exe:*:Enabled:THawk2_smaller"
"D:\Programy\Phone\Skype.exe"="D:\Programy\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\HRY\Combat Arms\CombatArms.exe"="D:\HRY\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe"
"D:\HRY\Combat Arms\Engine.exe"="D:\HRY\Combat Arms\Engine.exe:*Enabled:Engine.exe"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\J]
shell\AutoRun\command - J:\setup.exe
======File associations======
.js - edit - "D:\Programy\dreamweaver8\Dreamweaver 8\dreamweaver.exe" "%1"
======List of files/folders created in the last 1 months======
2010-02-19 19:44:08 ----A---- C:\RSIT.exe
2010-02-19 15:14:23 ----A---- C:\WINDOWS\system32\sipr3260.dll
2010-02-19 15:14:23 ----A---- C:\WINDOWS\system32\cook3260.dll
2010-02-19 15:14:22 ----A---- C:\WINDOWS\system32\vp7vfw.dll
2010-02-19 15:14:21 ----A---- C:\WINDOWS\system32\wvc1dmod.dll
2010-02-18 16:19:34 ----D---- C:\Documents and Settings\Adrián Pyteľ\Application Data\id Software
2010-02-18 16:19:27 ----D---- C:\Documents and Settings\All Users\Application Data\id Software
2010-02-12 11:42:16 ----A---- C:\WINDOWS\system32\licence.dll
2010-02-06 14:10:12 ----A---- C:\CEPxEABC.tmp
2010-02-05 13:56:57 ----D---- C:\Documents and Settings\Adrián Pyteľ\Application Data\GetRightToGo
2010-02-03 18:12:32 ----A---- C:\WINDOWS\system32\BReWErS.dll
2010-01-28 10:29:08 ----A---- C:\WINDOWS\system32\TURegOpt.exe
2010-01-28 10:29:07 ----A---- C:\WINDOWS\system32\uxtuneup.dll
2010-01-28 10:28:34 ----D---- C:\Program Files\TuneUp Utilities 2010
======List of files/folders modified in the last 1 months======
2010-02-19 19:45:23 ----D---- C:\Program Files\trend micro
2010-02-19 19:41:50 ----D---- C:\WINDOWS\temp
2010-02-19 19:36:51 ----D---- C:\Program Files\Mozilla Firefox
2010-02-19 19:35:32 ----D---- C:\Documents and Settings\Adrián Pyteľ\Application Data\HLSW
2010-02-19 19:17:46 ----D---- C:\downloads
2010-02-19 16:28:26 ----D---- C:\Documents and Settings\Adrián Pyteľ\Application Data\uTorrent
2010-02-19 16:03:38 ----A---- C:\WINDOWS\NeroDigital.ini
2010-02-19 15:37:40 ----D---- C:\Documents and Settings\Adrián Pyteľ\Application Data\Vso
2010-02-19 15:14:23 ----D---- C:\WINDOWS\system32
2010-02-19 15:14:17 ----D---- C:\Program Files\vso
2010-02-19 13:27:09 ----A---- C:\WINDOWS\system32\PnkBstrB.exe
2010-02-19 13:05:33 ----D---- C:\WINDOWS\Prefetch
2010-02-19 08:38:28 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2010-02-18 20:31:38 ----D---- C:\Documents and Settings\Adrián Pyteľ\Application Data\MyPhoneExplorer
2010-02-18 16:19:37 ----SHD---- C:\WINDOWS\Installer
2010-02-18 16:19:36 ----HD---- C:\Config.Msi
2010-02-18 16:19:31 ----AC---- C:\WINDOWS\system32\pbsvc.exe
2010-02-18 15:42:27 ----D---- C:\WINDOWS\system32\CatRoot2
2010-02-18 15:42:24 ----D---- C:\WINDOWS
2010-02-17 22:06:27 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-02-16 15:51:11 ----D---- C:\Games
2010-02-15 21:17:22 ----SD---- C:\WINDOWS\Temporary Internet Files
2010-02-14 12:45:19 ----SHD---- C:\RECYCLER
2010-02-10 14:45:13 ----A---- C:\WINDOWS\win.ini
2010-02-10 14:45:13 ----A---- C:\WINDOWS\system.ini
2010-02-08 16:03:25 ----D---- C:\Documents and Settings\Adrián Pyteľ\Application Data\Skype
2010-02-08 10:52:25 ----D---- C:\Documents and Settings\Adrián Pyteľ\Application Data\skypePM
2010-02-06 13:44:23 ----D---- C:\Documents and Settings\Adrián Pyteľ\Application Data\Orbit
2010-02-05 15:46:21 ----D---- C:\WINDOWS\Minidump
2010-02-02 16:45:56 ----D---- C:\WINDOWS\system32\DirectX
2010-02-02 16:45:48 ----RSD---- C:\WINDOWS\assembly
2010-02-02 16:13:50 ----HD---- C:\Program Files\InstallShield Installation Information
2010-02-02 14:33:38 ----D---- C:\WINDOWS\system32\drivers
2010-01-28 18:13:09 ----D---- C:\Documents and Settings\All Users\Application Data\Ubisoft
2010-01-28 10:29:14 ----SD---- C:\WINDOWS\Tasks
2010-01-28 10:28:34 ----AD---- C:\Program Files
2010-01-28 10:28:19 ----D---- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2010-01-26 17:22:57 ----D---- C:\Program Files\ICQ6.5
2010-01-23 20:35:40 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-01-23 15:29:51 ----D---- C:\Documents and Settings\All Users\Application Data\PMB Files
2010-01-22 17:52:58 ----D---- C:\Documents and Settings\Adrián Pyteľ\Application Data\Adobe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-04 36096]
R1 nod32drv;nod32drv; C:\WINDOWS\system32\drivers\nod32drv.sys [2008-08-15 15424]
R1 prodrv06;StarForce Protection Environment Driver v6; C:\WINDOWS\System32\drivers\prodrv06.sys [2004-05-13 79488]
R1 SCDEmu;SCDEmu; C:\WINDOWS\system32\drivers\SCDEmu.sys [2007-01-20 31644]
R1 sdpiosys;sdpiosys; C:\WINDOWS\system32\drivers\sdpiosys.sys [2004-11-30 161792]
R1 WS2IFSL;Prostredie podpory poskytovateľa služby Windows Socket 2.0 Non-IFS Service; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]
R2 AMON;AMON; C:\WINDOWS\system32\drivers\amon.sys [2008-08-15 512096]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2007-11-11 278984]
R2 Hardlock;Hardlock; \??\C:\WINDOWS\system32\drivers\hardlock.sys []
R2 Haspnt;Haspnt; \??\C:\WINDOWS\system32\drivers\Haspnt.sys []
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2007-11-11 25416]
R3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
R3 cmuda;C-Media WDM Audio Interface; C:\WINDOWS\system32\drivers\cmuda.sys [2004-01-08 812416]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-10-07 6133856]
R3 PAC207;PC Camera; C:\WINDOWS\system32\DRIVERS\PFC027.SYS [2007-05-29 508160]
R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2009-12-25 47360]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys []
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-04 26624]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
S1 aiptektp;Pen Pad; C:\WINDOWS\system32\DRIVERS\aiptektp.sys [2005-12-23 22656]
S3 actser;actser; C:\WINDOWS\system32\drivers\actser.sys [2004-08-23 29440]
S3 arg7oiy4;arg7oiy4; C:\WINDOWS\system32\drivers\arg7oiy4.sys []
S3 au77ajjc;au77ajjc; C:\WINDOWS\system32\drivers\au77ajjc.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 EagleNT;EagleNT; \??\C:\WINDOWS\system32\drivers\EagleNT.sys []
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2008-03-19 15440]
S3 hamachi_oem;PlayLinc Adapter; C:\WINDOWS\system32\DRIVERS\gan_adapter.sys [2006-08-28 10664]
S3 hidgame;Microsoft Hid to Joystick Port Enabler; C:\WINDOWS\system32\DRIVERS\hidgame.sys [2001-08-17 8576]
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2005-03-08 51120]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2005-03-08 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-03-08 21744]
S3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 NPF;Netgroup Packet Filter; C:\WINDOWS\system32\drivers\npf.sys []
S3 PnkBstrK;PnkBstrK; \??\C:\WINDOWS\system32\drivers\PnkBstrK.sys []
S3 rak;rak; \??\C:\WINDOWS\system32\rakion.sys []
S3 RivaTuner32;RivaTuner32; \??\D:\Programy\RivaTuner v2.06\RivaTuner32.sys []
S3 s716bus;Sony Ericsson Device 716 driver (WDM); C:\WINDOWS\system32\DRIVERS\s716bus.sys [2007-06-29 83208]
S3 s716mdfl;Sony Ericsson Device 716 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s716mdfl.sys [2007-06-29 15112]
S3 s716mdm;Sony Ericsson Device 716 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s716mdm.sys [2007-06-29 108552]
S3 s716mgmt;Sony Ericsson Device 716 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s716mgmt.sys [2007-06-29 100360]
S3 s716nd5;Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (NDIS); C:\WINDOWS\system32\DRIVERS\s716nd5.sys [2007-06-29 23176]
S3 s716obex;Sony Ericsson Device 716 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s716obex.sys [2007-06-29 98568]
S3 s716unic;Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (WDM); C:\WINDOWS\system32\DRIVERS\s716unic.sys [2007-06-29 98952]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 w200bus;Sony Ericsson W200 driver (WDM); C:\WINDOWS\system32\DRIVERS\w200bus.sys [2006-11-07 61504]
S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\w200mdfl.sys [2006-11-07 9328]
S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\w200mdm.sys [2006-11-07 97056]
S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\w200mgmt.sys [2006-11-07 88560]
S3 w200obex;Sony Ericsson W200 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\w200obex.sys [2006-11-07 86368]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-05-09 40704]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-04-11 87808]
S3 zlportio;zlportio; \??\D:\from torrent\ultrastardx-101a-full\zlportio.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R01000000 papycpu2;papycpu2; C:\WINDOWS\System32\DRIVERS\papycpu2.sys [2003-01-17 1984]
R01000000 papyjoy;papyjoy; C:\WINDOWS\System32\DRIVERS\papyjoy.sys [2003-01-17 1856]
R2 aawservice;Ad-Aware 2007 Service; C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe [2007-06-18 565248]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-11-07 132424]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-08-29 238888]
R2 NOD32krn;NOD32 Kernel Service; C:\Program Files\Eset\nod32krn.exe [2008-08-15 552064]
R2 NVIDIA Performance Driver Service;NVIDIA Performance Driver Service; C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe [2008-12-11 3575808]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-10-07 163908]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2009-03-01 75064]
R2 PnkBstrB;PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [2010-02-19 215104]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2009-12-18 1044808]
R2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2004-08-04 14336]
R2 wmcmgc;Windows Management Configuration; C:\WINDOWS\System32\svchost.exe [2004-08-04 14336]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
S2 gupdate1ca56fca6d5367e;Služba Google Update (gupdate1ca56fca6d5367e); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-10-27 133104]
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2004-09-29 69632]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2009-01-13 72704]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-01-17 654848]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2007-10-09 36864]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2007-10-11 864256]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2008-11-20 536872]
S3 Macromedia Licensing Service;Macromedia Licensing Service; C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe [2008-03-03 68096]
S3 MSSQL$SONY_MEDIAMGR;MSSQL$SONY_MEDIAMGR; D:\Programy\Sony SF8 Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe [2002-12-17 7520337]
S3 MSSQLServerADHelper;MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe [2002-12-17 66112]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2006-08-22 724992]
S3 npggsvc;nProtect GameGuard Service; C:\WINDOWS\system32\GameMon.des [2009-10-29 3407292]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 SQLAgent$SONY_MEDIAMGR;SQLAgent$SONY_MEDIAMGR; D:\Programy\Sony SF8 Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE [2002-12-17 311872]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [2010-01-28 435016]
S3 usprserv;User Privilege Service; C:\WINDOWS\System32\svchost.exe [2004-08-04 14336]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-05-09 823808]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2007-10-11 122880]
-----------------EOF-----------------
Logfile of random's system information tool 1.06 (written by random/random)
Run by Adrián Pyteľ at 2010-02-19 19:45:04
Systém Microsoft Windows XP Professional Service Pack 4
System drive C: has 4 GB (21%) free of 20 GB
Total RAM: 1023 MB (23% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:46:20, on 19.2.2010
Platform: Windows XP SP4 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Aware2007.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\RSIT.exe
C:\Program Files\trend micro\Adrián Pyteľ.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://search13.net/search.php?clid=486&q=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search13.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search13.net/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=66022
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search13.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://search13.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Config\csrss.exe
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - D:\Programz\Orbitdownloader\orbitcth.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: BrowserHelper Class - {8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6} - C:\Program Files\SGPSA\SearchAssistant.dll
O2 - BHO: Search Assistant - {F0626A63-410B-45E2-99A1-3F2475B2D695} - C:\Program Files\SGPSA\BHO.dll
O3 - Toolbar: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Compress Image Using Image Compressor 2008 - D:\Programy\image compressor 08 pro ed\imcieex_compress.html
O8 - Extra context menu item: &Download by Orbit - res://D:\Programz\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://D:\Programz\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://D:\Programz\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://D:\Programz\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {248F1F2D-E854-40AD-BB42-2E69EBC1CD8B} (ST WebDialer Control) - https://zona.t-com.sk/VianKampan2007/STWebDialer.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{37A055EB-FE2D-476C-92EE-88BDDD2D3473}: NameServer = 217.119.124.1 217.119.124.146
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\wbsys.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Služba Google Update (gupdate1ca56fca6d5367e) (gupdate1ca56fca6d5367e) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Performance Driver Service - Unknown owner - C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
--
End of file - 9110 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Automatic troubleshooting.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000123B4-9B42-4900-B3F7-F4B073EFC214}]
Octh Class - D:\Programz\Orbitdownloader\orbitcth.dll [2009-12-21 240912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll [2008-02-22 509328]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6}]
BrowserHelper Class - C:\Program Files\SGPSA\SearchAssistant.dll [2009-10-15 123904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F0626A63-410B-45E2-99A1-3F2475B2D695}]
Search Assistant - C:\Program Files\SGPSA\BHO.dll [2009-11-06 293376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2004-08-04 208952]
"MSPY2002"=C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe [2004-08-04 59392]
"nod32kui"=C:\Program Files\Eset\nod32kui.exe [2008-08-15 949376]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-10-07 13574144]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-10-07 86016]
"UserFaultCheck"=C:\WINDOWS\system32\dumprep 0 -u []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
"ISUSPM"=C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe [2006-09-10 218032]
"Pando Media Booster"=C:\Program Files\Pando Networks\Media Booster\PMB.exe [2009-12-20 2935480]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\WINDOWS\system32\wbsys.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\MCPClient]
C:\PROGRA~1\COMMON~1\Stardock\mcpstub.dll [2005-01-31 49152]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WBSrv]
D:\Programy\WindowBlinds\wbsrv.dll [2008-03-16 229376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - C:\PROGRA~1\COMMON~1\stardock\MCPCore.dll [2005-05-10 86016]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-05-09 52224]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2004-08-04 239616]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoResolveSearch"=
"NoDriveTypeAutoRun"=
"NoDrives"=
"NoDriveAutoRun"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Programy\uTorrent\utorrent.exe"="D:\Programy\uTorrent\utorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Windows Media Player\wmplayer.exe"="C:\Program Files\Windows Media Player\wmplayer.exe:*:Enabled:Windows Media Player"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"D:\Programy\Clear FTP 2006\clearftp.exe"="D:\Programy\Clear FTP 2006\clearftp.exe:*:Enabled:clearftp"
"D:\Programy\Fps Creator\MyGames\arenaskuska\arenaskuska.exe"="D:\Programy\Fps Creator\MyGames\arenaskuska\arenaskuska.exe:*:Enabled:FPSC Game"
"D:\Programy\Fps Creator\FPSC-Game.exe"="D:\Programy\Fps Creator\FPSC-Game.exe:*:Enabled:FPSC Game"
"D:\Programy\eDisk klient\eDisk klient.exe"="D:\Programy\eDisk klient\eDisk klient.exe:*:Enabled:eDisk klient"
"D:\Programy\Fps Creator\MyGames\arenaskuska2\arenaskuska2.exe"="D:\Programy\Fps Creator\MyGames\arenaskuska2\arenaskuska2.exe:*:Enabled:FPSC Game"
"D:\Programy\Hamachi\hamachi.exe"="D:\Programy\Hamachi\hamachi.exe:*:Enabled:Hamachi Client"
"D:\Programy\GoQ - NetRadio\NetRadio.exe"="D:\Programy\GoQ - NetRadio\NetRadio.exe:*:Enabled:NetRadio"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"D:\Programy\HLSW\hlsw.exe"="D:\Programy\HLSW\hlsw.exe:*:Enabled:HLSW Application"
"C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe"="C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe:*:Enabled:Nexon Game Manager"
"D:\Programy\QIP Infium\infium.exe"="D:\Programy\QIP Infium\infium.exe:*:Enabled:QIP Infium"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"D:\Programz\Orbitdownloader\orbitdm.exe"="D:\Programz\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit"
"D:\Programz\Orbitdownloader\orbitnet.exe"="D:\Programz\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit"
"D:\Programy\LimeWire\LimeWire.exe"="D:\Programy\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
"D:\HRY\Call of Duty 4 - Modern Warfare\iw3mp.exe"="D:\HRY\Call of Duty 4 - Modern Warfare\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) "
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\WINDOWS\system32\dplaysvr.exe"="C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"D:\Programy\Edisk\eDisk klient\eDisk klient.exe"="D:\Programy\Edisk\eDisk klient\eDisk klient.exe:*:Enabled:eDisk klient"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"D:\Programy\real player\realplay.exe"="D:\Programy\real player\realplay.exe:*:Enabled:RealPlayer"
"D:\Programy\iTunes\iTunes.exe"="D:\Programy\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
"D:\Programy\Plugin Manager\skypePM.exe"="D:\Programy\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"D:\HRY\THPS2\THawk2_smaller.exe"="D:\HRY\THPS2\THawk2_smaller.exe:*:Enabled:THawk2_smaller"
"D:\Programy\Phone\Skype.exe"="D:\Programy\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\HRY\Combat Arms\CombatArms.exe"="D:\HRY\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe"
"D:\HRY\Combat Arms\Engine.exe"="D:\HRY\Combat Arms\Engine.exe:*Enabled:Engine.exe"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\J]
shell\AutoRun\command - J:\setup.exe
======File associations======
.js - edit - "D:\Programy\dreamweaver8\Dreamweaver 8\dreamweaver.exe" "%1"
======List of files/folders created in the last 1 months======
2010-02-19 19:44:08 ----A---- C:\RSIT.exe
2010-02-19 15:14:23 ----A---- C:\WINDOWS\system32\sipr3260.dll
2010-02-19 15:14:23 ----A---- C:\WINDOWS\system32\cook3260.dll
2010-02-19 15:14:22 ----A---- C:\WINDOWS\system32\vp7vfw.dll
2010-02-19 15:14:21 ----A---- C:\WINDOWS\system32\wvc1dmod.dll
2010-02-18 16:19:34 ----D---- C:\Documents and Settings\Adrián Pyteľ\Application Data\id Software
2010-02-18 16:19:27 ----D---- C:\Documents and Settings\All Users\Application Data\id Software
2010-02-12 11:42:16 ----A---- C:\WINDOWS\system32\licence.dll
2010-02-06 14:10:12 ----A---- C:\CEPxEABC.tmp
2010-02-05 13:56:57 ----D---- C:\Documents and Settings\Adrián Pyteľ\Application Data\GetRightToGo
2010-02-03 18:12:32 ----A---- C:\WINDOWS\system32\BReWErS.dll
2010-01-28 10:29:08 ----A---- C:\WINDOWS\system32\TURegOpt.exe
2010-01-28 10:29:07 ----A---- C:\WINDOWS\system32\uxtuneup.dll
2010-01-28 10:28:34 ----D---- C:\Program Files\TuneUp Utilities 2010
======List of files/folders modified in the last 1 months======
2010-02-19 19:45:23 ----D---- C:\Program Files\trend micro
2010-02-19 19:41:50 ----D---- C:\WINDOWS\temp
2010-02-19 19:36:51 ----D---- C:\Program Files\Mozilla Firefox
2010-02-19 19:35:32 ----D---- C:\Documents and Settings\Adrián Pyteľ\Application Data\HLSW
2010-02-19 19:17:46 ----D---- C:\downloads
2010-02-19 16:28:26 ----D---- C:\Documents and Settings\Adrián Pyteľ\Application Data\uTorrent
2010-02-19 16:03:38 ----A---- C:\WINDOWS\NeroDigital.ini
2010-02-19 15:37:40 ----D---- C:\Documents and Settings\Adrián Pyteľ\Application Data\Vso
2010-02-19 15:14:23 ----D---- C:\WINDOWS\system32
2010-02-19 15:14:17 ----D---- C:\Program Files\vso
2010-02-19 13:27:09 ----A---- C:\WINDOWS\system32\PnkBstrB.exe
2010-02-19 13:05:33 ----D---- C:\WINDOWS\Prefetch
2010-02-19 08:38:28 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2010-02-18 20:31:38 ----D---- C:\Documents and Settings\Adrián Pyteľ\Application Data\MyPhoneExplorer
2010-02-18 16:19:37 ----SHD---- C:\WINDOWS\Installer
2010-02-18 16:19:36 ----HD---- C:\Config.Msi
2010-02-18 16:19:31 ----AC---- C:\WINDOWS\system32\pbsvc.exe
2010-02-18 15:42:27 ----D---- C:\WINDOWS\system32\CatRoot2
2010-02-18 15:42:24 ----D---- C:\WINDOWS
2010-02-17 22:06:27 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-02-16 15:51:11 ----D---- C:\Games
2010-02-15 21:17:22 ----SD---- C:\WINDOWS\Temporary Internet Files
2010-02-14 12:45:19 ----SHD---- C:\RECYCLER
2010-02-10 14:45:13 ----A---- C:\WINDOWS\win.ini
2010-02-10 14:45:13 ----A---- C:\WINDOWS\system.ini
2010-02-08 16:03:25 ----D---- C:\Documents and Settings\Adrián Pyteľ\Application Data\Skype
2010-02-08 10:52:25 ----D---- C:\Documents and Settings\Adrián Pyteľ\Application Data\skypePM
2010-02-06 13:44:23 ----D---- C:\Documents and Settings\Adrián Pyteľ\Application Data\Orbit
2010-02-05 15:46:21 ----D---- C:\WINDOWS\Minidump
2010-02-02 16:45:56 ----D---- C:\WINDOWS\system32\DirectX
2010-02-02 16:45:48 ----RSD---- C:\WINDOWS\assembly
2010-02-02 16:13:50 ----HD---- C:\Program Files\InstallShield Installation Information
2010-02-02 14:33:38 ----D---- C:\WINDOWS\system32\drivers
2010-01-28 18:13:09 ----D---- C:\Documents and Settings\All Users\Application Data\Ubisoft
2010-01-28 10:29:14 ----SD---- C:\WINDOWS\Tasks
2010-01-28 10:28:34 ----AD---- C:\Program Files
2010-01-28 10:28:19 ----D---- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2010-01-26 17:22:57 ----D---- C:\Program Files\ICQ6.5
2010-01-23 20:35:40 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-01-23 15:29:51 ----D---- C:\Documents and Settings\All Users\Application Data\PMB Files
2010-01-22 17:52:58 ----D---- C:\Documents and Settings\Adrián Pyteľ\Application Data\Adobe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-04 36096]
R1 nod32drv;nod32drv; C:\WINDOWS\system32\drivers\nod32drv.sys [2008-08-15 15424]
R1 prodrv06;StarForce Protection Environment Driver v6; C:\WINDOWS\System32\drivers\prodrv06.sys [2004-05-13 79488]
R1 SCDEmu;SCDEmu; C:\WINDOWS\system32\drivers\SCDEmu.sys [2007-01-20 31644]
R1 sdpiosys;sdpiosys; C:\WINDOWS\system32\drivers\sdpiosys.sys [2004-11-30 161792]
R1 WS2IFSL;Prostredie podpory poskytovateľa služby Windows Socket 2.0 Non-IFS Service; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]
R2 AMON;AMON; C:\WINDOWS\system32\drivers\amon.sys [2008-08-15 512096]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2007-11-11 278984]
R2 Hardlock;Hardlock; \??\C:\WINDOWS\system32\drivers\hardlock.sys []
R2 Haspnt;Haspnt; \??\C:\WINDOWS\system32\drivers\Haspnt.sys []
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2007-11-11 25416]
R3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
R3 cmuda;C-Media WDM Audio Interface; C:\WINDOWS\system32\drivers\cmuda.sys [2004-01-08 812416]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-10-07 6133856]
R3 PAC207;PC Camera; C:\WINDOWS\system32\DRIVERS\PFC027.SYS [2007-05-29 508160]
R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2009-12-25 47360]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys []
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-04 26624]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
S1 aiptektp;Pen Pad; C:\WINDOWS\system32\DRIVERS\aiptektp.sys [2005-12-23 22656]
S3 actser;actser; C:\WINDOWS\system32\drivers\actser.sys [2004-08-23 29440]
S3 arg7oiy4;arg7oiy4; C:\WINDOWS\system32\drivers\arg7oiy4.sys []
S3 au77ajjc;au77ajjc; C:\WINDOWS\system32\drivers\au77ajjc.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 EagleNT;EagleNT; \??\C:\WINDOWS\system32\drivers\EagleNT.sys []
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2008-03-19 15440]
S3 hamachi_oem;PlayLinc Adapter; C:\WINDOWS\system32\DRIVERS\gan_adapter.sys [2006-08-28 10664]
S3 hidgame;Microsoft Hid to Joystick Port Enabler; C:\WINDOWS\system32\DRIVERS\hidgame.sys [2001-08-17 8576]
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2005-03-08 51120]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2005-03-08 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-03-08 21744]
S3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 NPF;Netgroup Packet Filter; C:\WINDOWS\system32\drivers\npf.sys []
S3 PnkBstrK;PnkBstrK; \??\C:\WINDOWS\system32\drivers\PnkBstrK.sys []
S3 rak;rak; \??\C:\WINDOWS\system32\rakion.sys []
S3 RivaTuner32;RivaTuner32; \??\D:\Programy\RivaTuner v2.06\RivaTuner32.sys []
S3 s716bus;Sony Ericsson Device 716 driver (WDM); C:\WINDOWS\system32\DRIVERS\s716bus.sys [2007-06-29 83208]
S3 s716mdfl;Sony Ericsson Device 716 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s716mdfl.sys [2007-06-29 15112]
S3 s716mdm;Sony Ericsson Device 716 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s716mdm.sys [2007-06-29 108552]
S3 s716mgmt;Sony Ericsson Device 716 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s716mgmt.sys [2007-06-29 100360]
S3 s716nd5;Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (NDIS); C:\WINDOWS\system32\DRIVERS\s716nd5.sys [2007-06-29 23176]
S3 s716obex;Sony Ericsson Device 716 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s716obex.sys [2007-06-29 98568]
S3 s716unic;Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (WDM); C:\WINDOWS\system32\DRIVERS\s716unic.sys [2007-06-29 98952]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 w200bus;Sony Ericsson W200 driver (WDM); C:\WINDOWS\system32\DRIVERS\w200bus.sys [2006-11-07 61504]
S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\w200mdfl.sys [2006-11-07 9328]
S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\w200mdm.sys [2006-11-07 97056]
S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\w200mgmt.sys [2006-11-07 88560]
S3 w200obex;Sony Ericsson W200 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\w200obex.sys [2006-11-07 86368]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-05-09 40704]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-04-11 87808]
S3 zlportio;zlportio; \??\D:\from torrent\ultrastardx-101a-full\zlportio.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R01000000 papycpu2;papycpu2; C:\WINDOWS\System32\DRIVERS\papycpu2.sys [2003-01-17 1984]
R01000000 papyjoy;papyjoy; C:\WINDOWS\System32\DRIVERS\papyjoy.sys [2003-01-17 1856]
R2 aawservice;Ad-Aware 2007 Service; C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe [2007-06-18 565248]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-11-07 132424]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-08-29 238888]
R2 NOD32krn;NOD32 Kernel Service; C:\Program Files\Eset\nod32krn.exe [2008-08-15 552064]
R2 NVIDIA Performance Driver Service;NVIDIA Performance Driver Service; C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe [2008-12-11 3575808]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-10-07 163908]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2009-03-01 75064]
R2 PnkBstrB;PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [2010-02-19 215104]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2009-12-18 1044808]
R2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2004-08-04 14336]
R2 wmcmgc;Windows Management Configuration; C:\WINDOWS\System32\svchost.exe [2004-08-04 14336]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
S2 gupdate1ca56fca6d5367e;Služba Google Update (gupdate1ca56fca6d5367e); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-10-27 133104]
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2004-09-29 69632]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2009-01-13 72704]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-01-17 654848]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2007-10-09 36864]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2007-10-11 864256]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2008-11-20 536872]
S3 Macromedia Licensing Service;Macromedia Licensing Service; C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe [2008-03-03 68096]
S3 MSSQL$SONY_MEDIAMGR;MSSQL$SONY_MEDIAMGR; D:\Programy\Sony SF8 Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe [2002-12-17 7520337]
S3 MSSQLServerADHelper;MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe [2002-12-17 66112]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2006-08-22 724992]
S3 npggsvc;nProtect GameGuard Service; C:\WINDOWS\system32\GameMon.des [2009-10-29 3407292]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 SQLAgent$SONY_MEDIAMGR;SQLAgent$SONY_MEDIAMGR; D:\Programy\Sony SF8 Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE [2002-12-17 311872]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [2010-01-28 435016]
S3 usprserv;User Privilege Service; C:\WINDOWS\System32\svchost.exe [2004-08-04 14336]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-05-09 823808]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2007-10-11 122880]
-----------------EOF-----------------
- Rudy
- Site Admin
- Příspěvky: 119399
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Problem s PC je pomaly
Dejte log z ComboFix.
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
pote spustte aplikaci pod uctem s administratorskym opravnenim
hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.
v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine aplikace ani nic jineho
behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)
upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode, pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k nezadoucim kolizim s rezidentem antispyware
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Problem s PC je pomaly
ComboFix 10-02-18.09 - Adrián Pyteľ 19.02.2010 21:33:48.7.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.4.1250.421.1033.18.1023.524 [GMT 1:00]
Running from: c:\documents and settings\Adrián Pyteľ\Desktop\ComboFix.exe
AV: Eset NOD32 Antivirus 2.70 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\CEPxEABC.tmp
c:\documents and settings\All Users\Application Data\Tiger Install
c:\program files\Search Guard Plus
c:\program files\Search Guard Plus\fbsProtection.xml
c:\program files\Search Guard Plus\fbsSearchProvider.xml
c:\program files\Search Guard Plus\FbsSearchProviderIE8.exe
c:\program files\Search Guard Plus\SearchGuardPlus.exe
c:\program files\Search Guard Plus\SearchGuardPlus.ico
c:\program files\Search Guard Plus\uninstalSGP.exe
c:\program files\SGPSA
c:\program files\SGPSA\BHO.dll
c:\program files\SGPSA\SearchAssistant.dll
c:\recycler\S-1-5-21-2546212155-8632094249-924039719-4871
c:\recycler\S-1-5-21-3601404857-5340136554-625011137-7120
c:\windows\Config\csrss.exe
c:\windows\patchw.dll
c:\windows\regedit.com
c:\windows\system32\BReWErS.dll
c:\windows\system32\drivers\npf.sys
c:\windows\system32\packet.dll
c:\windows\system32\SIntf16.dll
c:\windows\system32\taskmgr.com
c:\windows\system32\twain_32.dll
c:\windows\system32\wpcap.dll
D:\install.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2010-01-19 to 2010-02-19 )))))))))))))))))))))))))))))))
.
2010-02-19 20:19 . 2010-02-19 20:17 388608 ----a-w- c:\windows\system32\CF11096.exe
2010-02-19 18:44 . 2010-02-19 18:44 781909 ----a-w- C:\RSIT.exe
2010-02-19 14:14 . 2007-03-18 19:37 65602 ----a-w- c:\windows\system32\cook3260.dll
2010-02-19 14:14 . 2002-12-10 01:20 102439 ----a-w- c:\windows\system32\sipr3260.dll
2010-02-19 14:14 . 2006-05-11 18:21 626688 ----a-w- c:\windows\system32\vp7vfw.dll
2010-02-19 14:14 . 2006-05-20 15:16 1184984 ----a-w- c:\windows\system32\wvc1dmod.dll
2010-02-18 15:19 . 2010-02-18 15:19 -------- d-----w- c:\documents and settings\All Users\Application Data\id Software
2010-02-12 10:42 . 2008-01-15 16:25 356352 ----a-w- c:\windows\system32\licence.dll
2010-02-01 14:00 . 2010-02-01 14:00 60928 ----a-w- c:\windows\system32\rakion.sys
2010-01-29 22:15 . 2010-01-29 22:15 -------- d-----w- c:\documents and settings\LocalService\Application Data\TuneUp Software
2010-01-28 09:29 . 2009-12-17 23:14 30536 ----a-w- c:\windows\system32\TURegOpt.exe
2010-01-28 09:29 . 2009-12-17 23:08 30024 ----a-w- c:\windows\system32\uxtuneup.dll
2010-01-28 09:28 . 2010-01-28 09:29 -------- d-----w- c:\program files\TuneUp Utilities 2010
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-19 20:12 . 2008-06-04 09:30 215104 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-02-19 19:09 . 2008-06-04 09:30 138576 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-02-19 19:02 . 2007-12-15 09:20 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-02-19 18:45 . 2009-06-24 12:04 -------- d-----w- c:\program files\trend micro
2010-02-19 14:14 . 2009-12-25 13:55 -------- d-----w- c:\program files\vso
2010-02-18 15:19 . 2008-10-24 15:38 2373712 -c--a-w- c:\windows\system32\pbsvc.exe
2010-02-02 15:13 . 2007-09-22 11:54 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-28 17:13 . 2008-09-01 14:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Ubisoft
2010-01-28 09:28 . 2007-09-22 12:06 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2010-01-26 16:22 . 2009-07-11 08:56 -------- d-----w- c:\program files\ICQ6.5
2010-01-23 14:29 . 2009-08-29 10:39 -------- d-----w- c:\documents and settings\All Users\Application Data\PMB Files
2010-01-22 15:48 . 2010-01-22 15:48 0 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\hpq5216.tmp
2010-01-22 15:43 . 2010-01-22 15:43 0 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\hpq5169.tmp
2010-01-22 15:43 . 2010-01-22 15:43 0 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\hpq5164.tmp
2010-01-07 14:47 . 2010-01-07 14:47 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-01-04 20:03 . 2010-01-04 20:03 -------- d-----w- c:\program files\Common Files\Skype
2010-01-04 20:03 . 2007-10-20 13:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-12-26 11:02 . 2009-12-26 11:02 -------- d-----w- c:\program files\Haali
2009-12-26 11:00 . 2009-12-26 11:00 -------- d-----w- c:\program files\CoreCodec
2009-12-26 10:52 . 2009-12-26 10:52 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-12-26 10:45 . 2009-03-01 12:48 -------- d-----w- c:\program files\XviD
2009-12-25 13:55 . 2007-12-20 11:16 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2009-12-17 13:29 . 2009-12-17 13:29 604488 ----a-w- c:\windows\system32\TUProgSt.exe
2009-12-11 18:00 . 2009-12-26 10:52 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2009-12-08 14:44 . 2008-08-10 15:55 304160 ----a-w- C:\PA207.DAT
2009-11-30 11:19 . 2009-11-30 11:19 625728 ----a-w- c:\documents and settings\All Users\Application Data\id Software\QuakeLive\npquakezero.dll
2009-11-30 11:17 . 2009-11-30 11:17 2373712 ----a-w- c:\documents and settings\All Users\Application Data\id Software\QuakeLive\pbsvc.exe
2009-09-25 16:41 . 2009-09-25 16:41 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-09-25 16:41 . 2009-09-25 16:41 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2005-06-29 01:46 . 2004-08-04 12:00 14744064 --sh--w- c:\windows\system32\icm64.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-06-26_16.02.23 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-11-07 01:19 . 2007-11-07 01:19 54272 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_ecc42bd1\vcomp90.dll
+ 2007-11-07 00:19 . 2007-11-07 00:19 54272 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_ecc42bd1\vcomp90.dll
+ 2008-06-12 12:44 . 2005-12-23 11:13 22656 c:\windows\udtablet\AIPTEKTP.SYS
- 2008-06-12 12:44 . 2005-12-23 10:13 22656 c:\windows\udtablet\AIPTEKTP.SYS
- 2008-06-12 12:44 . 2006-01-16 11:32 45056 c:\windows\udtablet\AIPTEKTP.EXE
+ 2008-06-12 12:44 . 2006-01-16 12:32 45056 c:\windows\udtablet\AIPTEKTP.EXE
+ 2010-02-19 20:41 . 2010-02-19 20:41 32768 c:\windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-05-04 17:25 . 2009-09-04 16:44 69464 c:\windows\system32\XAPOFX1_3.dll
+ 2009-05-04 17:25 . 2009-03-16 13:18 22360 c:\windows\system32\X3DAudio1_6.dll
- 2009-05-04 17:25 . 2009-03-16 12:18 22360 c:\windows\system32\X3DAudio1_6.dll
- 2008-06-12 12:44 . 2005-11-24 14:03 69632 c:\windows\system32\WINTAB32.DLL
+ 2008-06-12 12:44 . 2005-11-24 15:03 69632 c:\windows\system32\WINTAB32.DLL
+ 2009-07-06 12:27 . 2009-04-28 20:20 96752 c:\windows\system32\vxblock.dll
- 2008-06-12 12:44 . 2001-05-23 09:58 36864 c:\windows\system32\UTBLFILT.DLL
+ 2008-06-12 12:44 . 2001-05-23 10:58 36864 c:\windows\system32\UTBLFILT.DLL
+ 2008-06-12 12:44 . 2005-06-17 18:09 61440 c:\windows\system32\TBLMOUSE.EXE
- 2008-06-12 12:44 . 2005-06-17 17:09 61440 c:\windows\system32\TBLMOUSE.EXE
+ 2008-06-12 12:44 . 2006-01-10 18:45 61440 c:\windows\system32\Tblfunc.dll
- 2008-06-12 12:44 . 2006-01-10 17:45 61440 c:\windows\system32\Tblfunc.dll
+ 2009-10-21 09:51 . 2009-10-21 09:51 16640 c:\windows\system32\Setup\aladdin\akspccard.sys
+ 2009-11-22 13:54 . 2004-08-04 12:00 24960 c:\windows\system32\ReinstallBackups\0008\DriverFiles\i386\hidparse.sys
+ 2009-11-22 13:54 . 2004-08-04 12:00 36224 c:\windows\system32\ReinstallBackups\0008\DriverFiles\i386\hidclass.sys
+ 2009-11-22 13:54 . 2004-08-04 12:00 20992 c:\windows\system32\ReinstallBackups\0008\DriverFiles\i386\hid.dll
+ 2009-07-06 12:27 . 2009-04-28 20:20 66032 c:\windows\system32\pxinsa64.exe
+ 2009-07-06 12:27 . 2009-04-28 20:20 72176 c:\windows\system32\pxhpinst.exe
+ 2009-07-06 12:27 . 2009-04-28 20:20 66544 c:\windows\system32\pxcpya64.exe
+ 2009-07-20 07:34 . 2009-07-20 07:34 70936 c:\windows\system32\PhysXLoader.dll
- 2009-04-03 10:39 . 2009-04-03 10:39 70936 c:\windows\system32\PhysXLoader.dll
- 2004-08-04 12:00 . 2009-06-19 11:37 79914 c:\windows\system32\perfc009.dat
+ 2004-08-04 12:00 . 2009-10-25 08:12 79914 c:\windows\system32\perfc009.dat
- 2008-12-07 10:39 . 2009-06-10 08:28 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2008-12-07 10:39 . 2009-10-29 11:38 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
- 2008-06-12 12:44 . 2004-01-20 07:00 49152 c:\windows\system32\Funckey.dll
+ 2008-06-12 12:44 . 2004-01-20 08:00 49152 c:\windows\system32\Funckey.dll
+ 2009-08-13 20:18 . 2009-08-13 20:18 34048 c:\windows\system32\eEmpty.exe
+ 2009-07-06 12:27 . 2009-04-28 20:20 44944 c:\windows\system32\drivers\PxHelp20.sys
+ 2009-10-21 09:51 . 2003-12-18 16:53 47616 c:\windows\system32\drivers\Haspnt.sys
- 2008-06-12 12:44 . 2005-12-23 10:13 22656 c:\windows\system32\drivers\aiptektp.sys
+ 2008-06-12 12:44 . 2005-12-23 11:13 22656 c:\windows\system32\drivers\aiptektp.sys
+ 2009-09-25 16:41 . 2009-09-25 16:41 90112 c:\windows\system32\dpl100.dll
+ 2009-06-26 16:04 . 2007-07-30 17:19 53080 c:\windows\system32\dllcache\cache\wuauclt.exe
+ 2009-06-26 16:04 . 2004-08-04 12:00 82944 c:\windows\system32\dllcache\cache\ws2_32.dll
+ 2009-06-26 16:04 . 2004-08-04 12:00 24576 c:\windows\system32\dllcache\cache\userinit.exe
+ 2009-06-26 16:04 . 2004-08-04 12:00 14336 c:\windows\system32\dllcache\cache\svchost.exe
+ 2009-06-26 16:04 . 2005-06-10 23:53 57856 c:\windows\system32\dllcache\cache\spoolsv.exe
+ 2009-06-26 16:04 . 2004-08-04 12:00 17408 c:\windows\system32\dllcache\cache\powrprof.dll
+ 2009-06-26 16:04 . 2004-08-04 12:00 13312 c:\windows\system32\dllcache\cache\lsass.exe
+ 2009-06-26 16:04 . 2004-08-04 12:00 24576 c:\windows\system32\dllcache\cache\kbdclass.sys
+ 2009-06-26 16:04 . 2004-08-04 12:00 29056 c:\windows\system32\dllcache\cache\ip6fw.sys
+ 2009-06-26 16:04 . 2004-08-04 12:00 15360 c:\windows\system32\dllcache\cache\ctfmon.exe
+ 2009-10-19 08:24 . 2009-11-10 15:12 81920 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-10-20 07:59 . 2009-10-20 07:59 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009102020091021\index.dat
+ 2007-09-22 11:23 . 2009-11-10 15:12 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-09-22 11:23 . 2007-09-22 11:23 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-10-20 07:59 . 2009-10-20 07:59 16384 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\MSIMGSIZ.DAT
+ 2007-09-22 11:23 . 2009-11-10 15:12 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-06-12 12:44 . 2005-06-17 17:51 49152 c:\windows\system32\ATWinLog.dll
- 2008-06-12 12:44 . 2005-06-17 16:51 49152 c:\windows\system32\ATWinLog.dll
- 2008-06-12 12:44 . 2006-01-10 17:35 90112 c:\windows\RmTablet.exe
+ 2008-06-12 12:44 . 2006-01-10 18:35 90112 c:\windows\RmTablet.exe
+ 2009-11-18 13:01 . 2009-11-18 13:01 52736 c:\windows\ipuninst.exe
+ 2009-06-05 12:00 . 2009-06-05 12:00 97280 c:\windows\Installer\e54c73.msi
+ 2007-11-08 01:28 . 2007-11-08 01:28 22016 c:\windows\Installer\937792.msp
+ 2007-11-08 01:32 . 2007-11-08 01:32 74240 c:\windows\Installer\93778e.msp
+ 2007-11-08 01:21 . 2007-11-08 01:21 24576 c:\windows\Installer\93778b.msp
+ 2008-09-25 13:43 . 2008-09-25 13:43 20992 c:\windows\Installer\823c9a.msi
+ 2008-09-25 13:42 . 2008-09-25 13:42 24576 c:\windows\Installer\823c94.msi
+ 2008-11-01 09:54 . 2008-11-01 09:54 51712 c:\windows\Installer\3d5909.msi
+ 2010-01-28 09:28 . 2010-01-28 09:28 26624 c:\windows\Installer\29277b.msi
+ 2009-10-31 07:17 . 2009-10-31 07:17 22528 c:\windows\Installer\28e757.msi
+ 2008-05-26 15:49 . 2008-05-26 15:49 22016 c:\windows\Installer\22f50a.msi
+ 2008-05-26 15:43 . 2008-05-26 15:43 32256 c:\windows\Installer\22f4fe.msi
+ 2008-09-14 15:41 . 2008-09-14 15:41 75264 c:\windows\Installer\1b83570.msi
+ 2009-02-15 15:19 . 2009-02-15 15:19 86528 c:\windows\Installer\13f56ce.msi
- 2009-06-19 11:28 . 2009-06-19 11:28 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
- 2009-06-19 11:28 . 2009-06-19 11:28 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2009-10-21 09:52 . 2004-07-06 11:37 7168 c:\windows\system32\Setup\aladdin\hasphl\akscoinst.dll
+ 2009-11-22 13:54 . 2001-08-17 12:02 9600 c:\windows\system32\ReinstallBackups\0008\DriverFiles\i386\hidusb.sys
+ 2007-04-13 14:19 . 2007-04-13 14:19 7680 c:\windows\system32\lsdelete.exe
+ 2009-10-21 09:51 . 2009-10-21 09:51 6656 c:\windows\system32\haspvdd.dll
+ 2007-06-04 14:18 . 2007-06-04 14:18 9344 c:\windows\system32\drivers\NSDriver.sys
+ 2009-07-06 12:27 . 2009-04-28 20:20 9200 c:\windows\system32\drivers\cdralw2k.sys
+ 2009-07-06 12:27 . 2009-04-28 20:20 9072 c:\windows\system32\drivers\cdr4_xp.sys
+ 2007-06-04 14:17 . 2007-06-04 14:17 8320 c:\windows\system32\drivers\AWRTRD.sys
+ 2007-06-04 14:14 . 2007-06-04 14:14 6272 c:\windows\system32\drivers\AWRTPD.sys
+ 2004-08-04 12:00 . 2004-08-04 12:00 2176 c:\windows\system32\dllcache\vga.drv
- 2007-09-22 13:03 . 2004-08-04 12:00 2176 c:\windows\system32\dllcache\vga.drv
+ 2007-09-22 13:03 . 2004-08-04 12:00 9008 c:\windows\system32\dllcache\ver.dll
- 2004-08-04 12:00 . 2004-08-04 12:00 9008 c:\windows\system32\dllcache\ver.dll
- 2004-08-04 12:00 . 2004-08-04 12:00 4048 c:\windows\system32\dllcache\timer.drv
+ 2007-09-22 13:03 . 2004-08-04 12:00 4048 c:\windows\system32\dllcache\timer.drv
- 2007-09-22 13:03 . 2004-08-04 12:00 1744 c:\windows\system32\dllcache\sound.drv
+ 2004-08-04 12:00 . 2004-08-04 12:00 1744 c:\windows\system32\dllcache\sound.drv
- 2007-09-22 13:03 . 2004-08-04 12:00 2032 c:\windows\system32\dllcache\mouse.drv
+ 2004-08-04 12:00 . 2004-08-04 12:00 2032 c:\windows\system32\dllcache\mouse.drv
+ 2007-09-22 13:03 . 2004-08-04 12:00 9936 c:\windows\system32\dllcache\lzexpand.dll
- 2004-08-04 12:00 . 2004-08-04 12:00 9936 c:\windows\system32\dllcache\lzexpand.dll
- 2007-09-22 13:03 . 2004-08-04 12:00 2000 c:\windows\system32\dllcache\keyboard.drv
+ 2004-08-04 12:00 . 2004-08-04 12:00 2000 c:\windows\system32\dllcache\keyboard.drv
+ 2009-11-13 13:55 . 2001-03-23 15:29 880912 c:\windows\WM8EUTIL.exe
+ 2009-07-12 00:12 . 2009-07-12 00:12 632656 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll
+ 2009-07-12 00:09 . 2009-07-12 00:09 554832 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll
+ 2009-07-12 00:08 . 2009-07-12 00:08 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcm80.dll
+ 2007-09-06 09:21 . 2007-09-06 09:21 630784 c:\windows\TruckSaver.scr
+ 2009-12-26 10:52 . 2004-01-25 16:18 217088 c:\windows\system32\yv12vfw.dll
+ 2009-12-26 10:52 . 2009-05-29 21:37 205824 c:\windows\system32\xvidvfw.dll
+ 2009-12-26 10:52 . 2009-05-29 21:31 881664 c:\windows\system32\xvidcore.dll
+ 2009-10-09 10:01 . 2009-09-04 16:44 515416 c:\windows\system32\XAudio2_5.dll
+ 2009-05-04 17:25 . 2009-03-16 13:18 517448 c:\windows\system32\XAudio2_4.dll
- 2009-05-04 17:25 . 2009-03-16 12:18 517448 c:\windows\system32\XAudio2_4.dll
+ 2009-10-09 10:01 . 2009-09-04 16:44 238936 c:\windows\system32\xactengine3_5.dll
+ 2009-05-04 17:25 . 2009-03-16 13:18 235352 c:\windows\system32\xactengine3_4.dll
- 2009-05-04 17:25 . 2009-03-16 12:18 235352 c:\windows\system32\xactengine3_4.dll
+ 2007-12-12 13:47 . 2009-09-13 14:44 444952 c:\windows\system32\wrap_oal.dll
- 2007-12-12 13:47 . 2008-05-15 09:58 444952 c:\windows\system32\wrap_oal.dll
+ 2005-10-14 10:56 . 2009-08-16 15:08 178176 c:\windows\system32\unrar.dll
+ 2009-08-13 20:18 . 2004-08-04 12:00 135680 c:\windows\system32\T.COM
+ 2009-10-21 09:50 . 1998-12-10 17:00 519680 c:\windows\system32\SS32D25.DLL
+ 2009-10-21 09:52 . 2005-07-28 06:18 685056 c:\windows\system32\Setup\aladdin\hasphl\hardlock.sys
+ 2009-10-21 09:52 . 2005-07-20 16:08 100096 c:\windows\system32\Setup\aladdin\hasphl\aksusb.sys
+ 2009-10-21 09:52 . 2005-07-20 16:08 327808 c:\windows\system32\Setup\aladdin\hasphl\akshasp.sys
+ 2009-10-21 09:52 . 2005-07-20 16:08 104576 c:\windows\system32\Setup\aladdin\hasphl\aksclass.sys
+ 2009-07-06 12:27 . 2009-04-28 20:20 436720 c:\windows\system32\pxwave.dll
+ 2009-07-06 12:27 . 2009-04-28 20:20 219632 c:\windows\system32\pxmas.dll
+ 2009-10-27 12:01 . 2009-09-25 16:42 118520 c:\windows\system32\pxinsi64.exe
+ 2009-07-06 12:27 . 2009-04-28 20:20 551408 c:\windows\system32\pxdrv.dll
+ 2009-10-27 12:01 . 2009-09-25 16:42 120056 c:\windows\system32\pxcpyi64.exe
+ 2009-07-06 12:27 . 2009-04-28 20:20 129520 c:\windows\system32\pxafs.dll
+ 2009-07-06 12:27 . 2009-04-28 20:20 670192 c:\windows\system32\px.dll
- 2004-08-04 12:00 . 2009-06-19 11:37 462054 c:\windows\system32\perfh009.dat
+ 2004-08-04 12:00 . 2009-10-25 08:12 462054 c:\windows\system32\perfh009.dat
+ 2007-12-12 13:47 . 2009-09-13 14:44 109080 c:\windows\system32\OpenAL32.dll
- 2007-12-12 13:47 . 2008-05-15 09:58 109080 c:\windows\system32\OpenAL32.dll
+ 2009-07-18 03:21 . 2009-07-18 03:21 257440 c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2009-10-21 09:57 . 2003-12-18 16:53 304640 c:\windows\system32\hlvdd.dll
+ 2009-12-25 13:55 . 2006-09-29 10:24 217127 c:\windows\system32\drv43260.dll
+ 2009-12-25 13:55 . 2006-09-29 10:25 208935 c:\windows\system32\drv33260.dll
+ 2009-12-25 13:55 . 2006-09-29 10:26 176165 c:\windows\system32\drv23260.dll
+ 2009-10-21 09:52 . 2004-01-31 18:14 420000 c:\windows\system32\drivers\hardlock.sys
+ 2009-12-02 10:51 . 2008-04-30 20:01 108488 c:\windows\system32\drivers\dptrackerd.sys
+ 2009-06-26 16:04 . 2004-08-04 12:00 502272 c:\windows\system32\dllcache\cache\winlogon.exe
+ 2009-06-26 16:04 . 2007-06-26 14:09 658944 c:\windows\system32\dllcache\cache\wininet.dll
+ 2009-06-26 16:04 . 2007-03-08 15:36 577536 c:\windows\system32\dllcache\cache\user32.dll
+ 2009-06-26 16:04 . 2004-08-04 12:00 295424 c:\windows\system32\dllcache\cache\termsrv.dll
+ 2009-06-26 16:04 . 2006-04-20 11:51 359808 c:\windows\system32\dllcache\cache\tcpip.sys
+ 2009-06-26 16:04 . 2004-08-04 12:00 108032 c:\windows\system32\dllcache\cache\services.exe
+ 2009-06-26 16:04 . 2004-08-04 12:00 182912 c:\windows\system32\dllcache\cache\ndis.sys
+ 2009-06-26 16:04 . 2007-04-16 15:52 984576 c:\windows\system32\dllcache\cache\kernel32.dll
+ 2009-06-26 16:04 . 2004-08-04 12:00 110080 c:\windows\system32\dllcache\cache\imm32.dll
+ 2009-06-26 16:04 . 2004-08-04 12:00 167936 c:\windows\system32\dllcache\cache\appmgmts.dll
+ 2009-09-25 16:41 . 2009-09-25 16:41 843776 c:\windows\system32\divx_xx16.dll
+ 2009-09-25 16:41 . 2009-09-25 16:41 839680 c:\windows\system32\divx_xx11.dll
+ 2009-09-25 16:41 . 2009-09-25 16:41 856064 c:\windows\system32\divx_xx0c.dll
+ 2009-09-25 16:41 . 2009-09-25 16:41 847872 c:\windows\system32\divx_xx0a.dll
+ 2009-09-25 16:41 . 2009-09-25 16:41 856064 c:\windows\system32\divx_xx07.dll
+ 2009-09-25 16:41 . 2009-09-25 16:41 696320 c:\windows\system32\DivX.dll
+ 2009-10-09 10:01 . 2009-09-04 16:29 235344 c:\windows\system32\d3dx11_42.dll
+ 2009-10-09 10:01 . 2009-09-04 16:29 453456 c:\windows\system32\d3dx10_42.dll
+ 2009-05-04 17:25 . 2009-03-09 14:27 453456 c:\windows\system32\d3dx10_41.dll
- 2009-05-04 17:25 . 2009-03-09 13:27 453456 c:\windows\system32\d3dx10_41.dll
+ 2008-12-12 12:03 . 2008-10-15 05:22 452440 c:\windows\system32\d3dx10_40.dll
- 2008-12-12 12:03 . 2008-10-15 04:22 452440 c:\windows\system32\d3dx10_40.dll
- 2008-06-12 12:44 . 2005-07-27 14:55 290816 c:\windows\system32\atwtusbL.exe
+ 2008-06-12 12:44 . 2005-07-27 15:55 290816 c:\windows\system32\atwtusbL.exe
- 2008-06-12 12:44 . 2006-01-17 14:57 294912 c:\windows\system32\ATWTUSB.EXE
+ 2008-06-12 12:44 . 2006-01-17 15:57 294912 c:\windows\system32\ATWTUSB.EXE
+ 2009-08-13 20:18 . 2004-08-04 12:00 146432 c:\windows\R.COM
+ 2009-06-19 11:37 . 2009-06-19 11:37 634368 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5\vs_setup.msi
+ 2009-10-21 09:50 . 2009-10-21 09:50 106496 c:\windows\kokundo.exe
+ 2009-08-28 11:06 . 1998-01-14 20:06 304128 c:\windows\IsUn0411.exe
+ 2007-10-18 12:02 . 2007-10-18 12:02 282624 c:\windows\Installer\fe5257.msi
+ 2009-10-27 12:01 . 2009-10-27 12:01 169472 c:\windows\Installer\ef24bc.msi
+ 2007-11-18 14:37 . 2007-11-18 14:37 566272 c:\windows\Installer\d2a05c.msi
+ 2009-02-17 09:00 . 2009-02-17 09:01 228352 c:\windows\Installer\cea0e.msi
+ 2007-10-05 12:02 . 2007-10-05 12:02 123904 c:\windows\Installer\c1bdc5.msi
+ 2007-10-05 12:02 . 2007-10-05 12:02 123904 c:\windows\Installer\c1bdbf.msi
+ 2007-10-05 12:02 . 2007-10-05 12:02 123904 c:\windows\Installer\c1bdb9.msi
+ 2008-04-18 11:51 . 2008-04-18 11:51 289792 c:\windows\Installer\b2f4d6.msi
+ 2009-06-19 11:37 . 2009-06-19 11:37 630272 c:\windows\Installer\95acab.msi
+ 2007-11-08 01:34 . 2007-11-08 01:34 273920 c:\windows\Installer\93778f.msp
+ 2009-06-19 11:36 . 2009-06-19 11:36 348160 c:\windows\Installer\937788.msi
+ 2009-06-19 11:35 . 2009-06-19 11:35 871424 c:\windows\Installer\937772.msi
+ 2008-10-06 13:13 . 2008-10-06 13:13 203264 c:\windows\Installer\8a142e.msi
+ 2008-10-06 13:13 . 2008-10-06 13:13 129536 c:\windows\Installer\8a1428.msi
+ 2008-10-06 13:13 . 2008-10-06 13:13 130048 c:\windows\Installer\8a1422.msi
+ 2008-10-06 13:12 . 2008-10-06 13:12 985600 c:\windows\Installer\8a1416.msi
+ 2008-10-06 13:12 . 2008-10-06 13:12 315392 c:\windows\Installer\8a140f.msi
+ 2008-10-06 13:11 . 2008-10-06 13:11 290816 c:\windows\Installer\8a1409.msi
+ 2008-10-06 13:11 . 2008-10-06 13:11 152576 c:\windows\Installer\8a1403.msi
+ 2008-10-06 13:11 . 2008-10-06 13:11 281088 c:\windows\Installer\8a13fd.msi
+ 2008-10-06 13:11 . 2008-10-06 13:11 353792 c:\windows\Installer\8a13f6.msi
+ 2008-10-06 13:11 . 2008-10-06 13:11 528384 c:\windows\Installer\8a13ef.msi
+ 2008-10-06 13:11 . 2008-10-06 13:11 121344 c:\windows\Installer\8a13e1.msi
+ 2008-10-06 13:11 . 2008-10-06 13:11 274432 c:\windows\Installer\8a13db.msi
+ 2008-10-06 13:11 . 2008-10-06 13:11 121344 c:\windows\Installer\8a13d1.msi
+ 2008-10-06 13:10 . 2008-10-06 13:10 299008 c:\windows\Installer\8a13cb.msi
+ 2008-10-06 13:10 . 2008-10-06 13:10 491008 c:\windows\Installer\8a13c3.msi
+ 2008-10-06 13:10 . 2008-10-06 13:10 247296 c:\windows\Installer\8a13bd.msi
+ 2008-10-06 13:10 . 2008-10-06 13:10 589312 c:\windows\Installer\8a13b7.msi
+ 2008-10-06 13:10 . 2008-10-06 13:10 175616 c:\windows\Installer\8a13b0.msi
+ 2008-10-06 13:10 . 2008-10-06 13:10 121344 c:\windows\Installer\8a13aa.msi
+ 2008-10-06 13:10 . 2008-10-06 13:10 247296 c:\windows\Installer\8a13a4.msi
+ 2008-10-06 13:10 . 2008-10-06 13:10 129536 c:\windows\Installer\8a139d.msi
+ 2008-10-06 13:10 . 2008-10-06 13:10 728064 c:\windows\Installer\8a1397.msi
+ 2008-10-06 13:09 . 2008-10-06 13:09 338432 c:\windows\Installer\8a1391.msi
+ 2008-10-06 13:09 . 2008-10-06 13:09 287744 c:\windows\Installer\8a138a.msi
+ 2008-10-06 13:09 . 2008-10-06 13:09 136704 c:\windows\Installer\8a1384.msi
+ 2007-09-27 13:38 . 2007-09-27 13:38 166400 c:\windows\Installer\7f436.msi
+ 2009-05-21 12:50 . 2009-05-21 12:50 515072 c:\windows\Installer\732c9.msi
+ 2008-10-25 09:55 . 2008-10-25 09:55 366592 c:\windows\Installer\728f35.msi
+ 2009-03-05 15:22 . 2009-03-05 15:22 487936 c:\windows\Installer\47fe5c.msi
+ 2008-02-28 10:05 . 2008-02-28 10:05 782336 c:\windows\Installer\443d40.msi
+ 2007-09-25 06:51 . 2007-09-25 06:51 431104 c:\windows\Installer\394d5.msi
+ 2009-01-18 10:18 . 2009-01-18 10:18 228352 c:\windows\Installer\2f563e.msi
+ 2008-11-28 21:42 . 2008-11-28 21:42 874496 c:\windows\Installer\2d32c6b.msi
+ 2009-03-25 08:42 . 2009-03-25 08:42 213504 c:\windows\Installer\2c9411.msi
+ 2010-01-28 09:29 . 2010-01-28 09:29 317952 c:\windows\Installer\29277f.msi
+ 2007-09-22 11:26 . 2007-09-22 11:26 264704 c:\windows\Installer\27ec0.msi
+ 2008-11-04 18:21 . 2008-11-04 18:21 390656 c:\windows\Installer\277af23.msi
+ 2007-09-22 13:43 . 2007-09-22 13:43 178176 c:\windows\Installer\274cfd.msi
+ 2008-09-12 15:47 . 2008-09-12 15:47 580608 c:\windows\Installer\22bafa5.msi
+ 2008-02-25 16:30 . 2008-02-25 16:30 808960 c:\windows\Installer\1a4c722.msi
+ 2009-05-09 16:47 . 2009-05-09 16:47 251392 c:\windows\Installer\17fa90.msi
+ 2007-10-05 15:15 . 2007-10-05 15:15 331264 c:\windows\Installer\1754a5b.msi
+ 2010-02-18 15:19 . 2010-02-18 15:19 178176 c:\windows\Installer\15bf538.msi
+ 2007-11-07 14:07 . 2007-11-07 14:07 999936 c:\windows\Installer\13f56d7.msp
+ 2007-11-07 13:56 . 2007-11-07 13:56 553472 c:\windows\Installer\13f56d4.msp
+ 2007-11-07 13:58 . 2007-11-07 13:58 908800 c:\windows\Installer\13f56d0.msp
+ 2007-11-07 13:54 . 2007-11-07 13:54 507392 c:\windows\Installer\13f56cf.msp
+ 2007-11-26 15:35 . 2007-11-26 15:35 380928 c:\windows\Installer\12cdb5c.msi
+ 2008-02-02 13:39 . 2008-02-02 13:39 926208 c:\windows\Installer\110a178.msi
+ 2007-12-17 13:12 . 2007-12-17 13:12 409600 c:\windows\Installer\10db443.msi
+ 2007-12-08 14:30 . 2007-12-08 14:30 413696 c:\windows\Installer\106d4a8.msi
+ 2010-01-04 20:03 . 2010-01-04 20:03 371272 c:\windows\Installer\{D103C4BA-F905-437A-8049-DB24763BBE36}\SkypeIcon.exe
+ 2009-12-12 10:54 . 2009-12-12 10:54 178688 c:\windows\Installer\{46AC899A-9ECB-43DC-85DE-272E0D116A1E}\Icon0E6AB9FC1.exe
+ 2009-09-14 08:51 . 2009-09-14 15:53 200704 c:\windows\B83FC356B7C0441F8A4DD71E088E7974.TMP\WiseCustomCalla.dll
- 2009-06-19 11:28 . 2009-06-19 11:28 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
- 2009-06-19 11:28 . 2009-06-19 11:28 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
- 2009-06-19 11:28 . 2009-06-19 11:28 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
- 2009-06-19 11:28 . 2009-06-19 11:28 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
- 2009-06-19 11:28 . 2009-06-19 11:28 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
- 2009-06-19 11:28 . 2009-06-19 11:28 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-06-19 11:28 . 2009-06-19 11:28 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-06-19 11:28 . 2009-06-19 11:28 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-06-19 11:28 . 2009-06-19 11:28 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-06-19 11:28 . 2009-06-19 11:28 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-06-19 11:28 . 2009-06-19 11:28 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-06-19 11:28 . 2009-06-19 11:28 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-06-19 11:28 . 2009-06-19 11:28 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-06-19 11:28 . 2009-06-19 11:28 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2008-02-20 14:20 . 2010-02-02 15:47 155648 c:\windows\85EBB28365AF4C539EBE7C0A232762F7.TMP\WiseCustomCalla.dll
- 2008-02-20 14:20 . 2008-02-20 14:20 155648 c:\windows\85EBB28365AF4C539EBE7C0A232762F7.TMP\WiseCustomCalla.dll
+ 2009-09-01 16:52 . 2009-09-02 09:02 155648 c:\windows\10004C34B7194F9186D406FB51AB6BFB.TMP\WiseCustomCalla.dll
+ 2004-08-04 12:00 . 2004-08-04 12:00 1326080 c:\windows\system32\webfldrs.msi
+ 2008-06-12 12:44 . 2005-07-19 14:15 1617920 c:\windows\system32\TblRes.dll
- 2008-06-12 12:44 . 2005-07-19 13:15 1617920 c:\windows\system32\TblRes.dll
+ 2008-07-29 14:05 . 2008-07-29 14:05 1296896 c:\windows\system32\SPort.dll
+ 2009-07-06 12:27 . 2009-04-28 20:20 1858032 c:\windows\system32\pxsfs.dll
+ 2009-07-18 03:21 . 2009-07-18 03:21 3883424 c:\windows\system32\Macromed\Flash\NPSWF32.dll
+ 2007-09-22 13:02 . 2009-11-23 10:05 1912896 c:\windows\system32\FNTCACHE.DAT
+ 2009-06-26 16:04 . 2004-08-04 12:00 1580544 c:\windows\system32\dllcache\cache\sfcfiles.dll
+ 2009-06-26 16:04 . 2007-02-28 09:10 2180352 c:\windows\system32\dllcache\cache\ntoskrnl.exe
+ 2009-06-26 16:04 . 2007-02-28 08:38 2057600 c:\windows\system32\dllcache\cache\ntkrnlpa.exe
+ 2009-06-26 16:04 . 2007-06-13 10:23 1033216 c:\windows\system32\dllcache\cache\explorer.exe
+ 2009-10-09 10:01 . 2009-09-04 16:29 1892184 c:\windows\system32\D3DX9_42.dll
+ 2009-05-04 17:25 . 2009-03-09 14:27 4178264 c:\windows\system32\D3DX9_41.dll
- 2009-05-04 17:25 . 2009-03-09 13:27 4178264 c:\windows\system32\D3DX9_41.dll
+ 2008-12-12 12:03 . 2008-10-15 05:22 4379984 c:\windows\system32\D3DX9_40.dll
- 2008-12-12 12:03 . 2008-10-15 04:22 4379984 c:\windows\system32\D3DX9_40.dll
+ 2009-10-09 10:01 . 2009-09-04 16:29 5501792 c:\windows\system32\d3dcsx_42.dll
+ 2009-10-09 10:01 . 2009-09-04 16:29 1974616 c:\windows\system32\D3DCompiler_42.dll
- 2009-05-04 17:25 . 2009-03-09 13:27 1846632 c:\windows\system32\D3DCompiler_41.dll
+ 2009-05-04 17:25 . 2009-03-09 14:27 1846632 c:\windows\system32\D3DCompiler_41.dll
+ 2008-12-12 12:03 . 2008-10-15 05:22 2036576 c:\windows\system32\D3DCompiler_40.dll
- 2008-12-12 12:03 . 2008-10-15 04:22 2036576 c:\windows\system32\D3DCompiler_40.dll
+ 2008-08-10 15:22 . 2008-08-10 15:22 6232576 c:\windows\Installer\f5fb49.msi
+ 2007-10-20 12:52 . 2007-10-20 12:52 3563520 c:\windows\Installer\d26733.msi
+ 2009-01-08 16:07 . 2009-01-08 16:07 3762688 c:\windows\Installer\c78a1e.msi
+ 2009-01-08 16:01 . 2009-01-08 16:01 8989696 c:\windows\Installer\c78a11.msi
+ 2009-01-08 15:59 . 2009-01-08 15:59 1549312 c:\windows\Installer\c7876e.msi
+ 2009-01-08 15:59 . 2009-01-08 15:59 3152384 c:\windows\Installer\c7873e.msi
+ 2007-10-05 12:03 . 2007-10-05 12:03 3443712 c:\windows\Installer\c55daa.msi
+ 2007-09-22 12:28 . 2007-09-22 12:28 5807104 c:\windows\Installer\bb6a5.msi
+ 2008-09-19 19:34 . 2008-09-19 19:34 3899392 c:\windows\Installer\a404d4.msi
+ 2010-01-04 20:03 . 2010-01-04 20:03 1565696 c:\windows\Installer\9fe433.msi
+ 2007-11-08 01:30 . 2007-11-08 01:30 3962368 c:\windows\Installer\937791.msp
+ 2007-11-08 01:13 . 2007-11-08 01:13 6766592 c:\windows\Installer\937790.msp
+ 2007-11-08 01:26 . 2007-11-08 01:26 4340224 c:\windows\Installer\93778d.msp
+ 2007-11-08 01:24 . 2007-11-08 01:24 5353472 c:\windows\Installer\93778c.msp
+ 2007-11-08 01:18 . 2007-11-08 01:18 2059264 c:\windows\Installer\93778a.msp
+ 2007-11-08 01:16 . 2007-11-08 01:16 1313280 c:\windows\Installer\937789.msp
+ 2008-10-06 13:12 . 2008-10-06 13:12 3658752 c:\windows\Installer\8a141c.msi
+ 2009-03-12 09:42 . 2009-03-12 09:42 3938816 c:\windows\Installer\76767.msi
+ 2007-09-22 14:53 . 2007-09-22 14:53 1769984 c:\windows\Installer\5a7e1d.msi
+ 2007-09-22 14:52 . 2007-09-22 14:52 1767424 c:\windows\Installer\5a7e11.msi
+ 2007-09-22 14:48 . 2007-09-22 14:48 1845248 c:\windows\Installer\5a7e0b.msi
+ 2007-09-22 14:48 . 2007-09-22 14:48 1768448 c:\windows\Installer\5a7dab.msi
+ 2007-09-22 14:38 . 2007-09-22 14:38 3035648 c:\windows\Installer\5a7da4.msi
+ 2009-12-12 10:54 . 2009-12-12 10:54 3027968 c:\windows\Installer\52d92.msi
+ 2008-01-12 16:38 . 2008-01-12 16:38 5885952 c:\windows\Installer\51bfce.msi
+ 2008-01-20 14:14 . 2008-01-20 14:14 4337664 c:\windows\Installer\47162f.msi
+ 2008-01-20 14:12 . 2008-01-20 14:12 8448512 c:\windows\Installer\471621.msi
+ 2008-11-20 08:56 . 2008-11-20 08:56 8742912 c:\windows\Installer\3f5515.msi
+ 2008-10-05 03:12 . 2008-10-05 03:12 4784128 c:\windows\Installer\3d5910.msp
+ 2009-08-13 17:44 . 2009-08-13 17:44 1500160 c:\windows\Installer\306e72.msi
+ 2007-09-30 11:16 . 2007-09-30 11:16 7898624 c:\windows\Installer\233ee.msi
+ 2009-01-17 18:44 . 2009-01-17 18:45 2428416 c:\windows\Installer\2199ab0.msi
+ 2009-01-17 18:42 . 2009-01-17 18:42 1780224 c:\windows\Installer\2199aa6.msi
+ 2009-01-17 18:41 . 2009-01-17 18:41 1718272 c:\windows\Installer\2199aa0.msi
+ 2009-01-17 18:41 . 2009-01-17 18:41 1725952 c:\windows\Installer\2199a9a.msi
+ 2009-01-17 18:40 . 2009-01-17 18:40 1954304 c:\windows\Installer\2199a94.msi
+ 2009-01-17 18:40 . 2009-01-17 18:40 1826816 c:\windows\Installer\2199a8e.msi
+ 2009-01-17 18:39 . 2009-01-17 18:39 1726976 c:\windows\Installer\2199a88.msi
+ 2009-01-17 18:38 . 2009-01-17 18:38 1879040 c:\windows\Installer\2199a82.msi
+ 2009-01-17 18:38 . 2009-01-17 18:38 1730048 c:\windows\Installer\2199a7c.msi
+ 2009-01-17 18:37 . 2009-01-17 18:37 1761792 c:\windows\Installer\2199a76.msi
+ 2009-01-17 18:37 . 2009-01-17 18:37 1735680 c:\windows\Installer\2199a70.msi
+ 2009-01-17 18:36 . 2009-01-17 18:36 1744384 c:\windows\Installer\2199a6a.msi
+ 2009-01-17 18:35 . 2009-01-17 18:35 2159104 c:\windows\Installer\2199a64.msi
+ 2009-01-17 18:33 . 2009-01-17 18:33 1715712 c:\windows\Installer\2199a5e.msi
+ 2009-01-17 18:33 . 2009-01-17 18:33 1715712 c:\windows\Installer\2199a57.msi
+ 2009-01-17 18:32 . 2009-01-17 18:32 1716736 c:\windows\Installer\2199a50.msi
+ 2009-01-17 18:32 . 2009-01-17 18:32 1715712 c:\windows\Installer\2199a49.msi
+ 2009-01-17 18:31 . 2009-01-17 18:31 1718272 c:\windows\Installer\2199a42.msi
+ 2009-01-17 18:31 . 2009-01-17 18:31 1761792 c:\windows\Installer\2199a3c.msi
+ 2009-01-17 18:30 . 2009-01-17 18:30 1753088 c:\windows\Installer\2199a36.msi
+ 2009-01-17 18:30 . 2009-01-17 18:30 1720832 c:\windows\Installer\2199a30.msi
+ 2009-01-17 18:29 . 2009-01-17 18:29 2595840 c:\windows\Installer\2199a2a.msi
+ 2009-01-17 18:25 . 2009-01-17 18:25 1826304 c:\windows\Installer\2199a24.msi
+ 2009-01-17 18:25 . 2009-01-17 18:25 1716736 c:\windows\Installer\2199a1e.msi
+ 2007-12-24 19:34 . 2007-12-24 19:34 1880576 c:\windows\Installer\1f6afa6.msi
+ 2009-01-17 18:14 . 2009-01-17 18:14 1767424 c:\windows\Installer\1db580e.msi
+ 2008-02-25 09:21 . 2008-02-25 09:21 3680768 c:\windows\Installer\191b8f.msi
+ 2007-11-07 13:50 . 2007-11-07 13:50 6055936 c:\windows\Installer\13f56d6.msp
+ 2007-11-07 14:00 . 2007-11-07 14:00 3407360 c:\windows\Installer\13f56d5.msp
+ 2007-11-07 13:46 . 2007-11-07 13:46 3010560 c:\windows\Installer\13f56d3.msp
+ 2007-11-07 14:02 . 2007-11-07 14:02 6473216 c:\windows\Installer\13f56d2.msp
+ 2007-11-07 14:12 . 2007-11-07 14:12 2533376 c:\windows\Installer\13f56d1.msp
+ 2008-11-20 13:24 . 2008-11-20 13:24 1154048 c:\windows\Installer\13edd61.msi
+ 2007-09-25 12:43 . 2007-09-25 12:43 5573120 c:\windows\Installer\125af51.msi
+ 2009-04-14 14:12 . 2009-04-14 14:12 1492992 c:\windows\Installer\10f1bf1.msi
+ 2009-12-12 10:54 . 2009-12-12 10:54 1038336 c:\windows\Installer\{46AC899A-9ECB-43DC-85DE-272E0D116A1E}\Icon0E6AB9FC.exe
+ 2008-02-28 10:04 . 2008-02-28 10:04 6435328 c:\windows\Downloaded Installations\{FCC57BD8-B1F2-4EA1-A39E-E115E6C9D4FA}\Image Compressor 2008 Pro Edition.msi
- 2009-06-19 11:28 . 2009-06-19 11:28 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-06-19 11:28 . 2009-06-19 11:28 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2007-10-20 12:54 . 2007-10-20 12:54 23867392 c:\windows\Installer\d26745.msi
+ 2007-09-27 13:40 . 2007-09-27 13:40 10237952 c:\windows\Installer\7f43b.msi
+ 2008-01-20 14:16 . 2008-01-20 14:16 12388864 c:\windows\Installer\471632.msi
+ 2009-01-13 17:21 . 2009-01-13 17:21 13948416 c:\windows\Installer\245e74d.msi
+ 2007-12-04 16:57 . 2007-12-04 16:57 19210240 c:\windows\Installer\19fe12d.msp
+ 2005-08-31 02:31 . 2005-08-31 02:31 23870464 c:\windows\Downloaded Installations\Macromedia Flash 8\Macromedia Flash 8.msi
+ 2007-09-30 11:13 . 2007-09-30 11:12 39060840 c:\windows\Downloaded Installations\{B56B1487-9A26-4AFD-A1FD-949C40F5F2BC}\Sony Ericsson PC Suite.msi
+ 2008-03-25 14:33 . 2008-03-25 14:33 12406272 c:\windows\Downloaded Installations\{97F709BD-5B08-4007-B4AE-08C6277EDCC5}\GameShadow.msi
+ 2008-03-05 13:09 . 2008-03-24 19:59 10854784 c:\windows\Downloaded Installations\{6358ABF1-38A3-493A-AFF2-679D6D09B12E}\GameShadow.msi
+ 2008-03-05 13:51 . 2008-03-25 09:20 10853760 c:\windows\Downloaded Installations\{63256143-86D7-4354-AF75-7580F4B0C359}\GameShadow.msi
+ 2008-08-10 15:21 . 2008-08-10 15:21 11049984 c:\windows\Downloaded Installations\{51C8736D-4956-4172-AACA-0A8FFC4BC652}\PC Camera .msi
+ 2007-09-26 15:13 . 2007-09-30 11:12 39060840 c:\windows\Downloaded Installations\{2352A5E3-0109-4D7F-BF13-16A5C01AB37D}\Sony Ericsson PC Suite.msi
+ 2008-11-20 13:22 . 2008-11-20 13:22 241051648 c:\windows\Installer\13edd5a.msi
.
-- Snapshot reset to current date --
.
Systém Microsoft Windows XP Professional 5.1.2600.4.1250.421.1033.18.1023.524 [GMT 1:00]
Running from: c:\documents and settings\Adrián Pyteľ\Desktop\ComboFix.exe
AV: Eset NOD32 Antivirus 2.70 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\CEPxEABC.tmp
c:\documents and settings\All Users\Application Data\Tiger Install
c:\program files\Search Guard Plus
c:\program files\Search Guard Plus\fbsProtection.xml
c:\program files\Search Guard Plus\fbsSearchProvider.xml
c:\program files\Search Guard Plus\FbsSearchProviderIE8.exe
c:\program files\Search Guard Plus\SearchGuardPlus.exe
c:\program files\Search Guard Plus\SearchGuardPlus.ico
c:\program files\Search Guard Plus\uninstalSGP.exe
c:\program files\SGPSA
c:\program files\SGPSA\BHO.dll
c:\program files\SGPSA\SearchAssistant.dll
c:\recycler\S-1-5-21-2546212155-8632094249-924039719-4871
c:\recycler\S-1-5-21-3601404857-5340136554-625011137-7120
c:\windows\Config\csrss.exe
c:\windows\patchw.dll
c:\windows\regedit.com
c:\windows\system32\BReWErS.dll
c:\windows\system32\drivers\npf.sys
c:\windows\system32\packet.dll
c:\windows\system32\SIntf16.dll
c:\windows\system32\taskmgr.com
c:\windows\system32\twain_32.dll
c:\windows\system32\wpcap.dll
D:\install.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2010-01-19 to 2010-02-19 )))))))))))))))))))))))))))))))
.
2010-02-19 20:19 . 2010-02-19 20:17 388608 ----a-w- c:\windows\system32\CF11096.exe
2010-02-19 18:44 . 2010-02-19 18:44 781909 ----a-w- C:\RSIT.exe
2010-02-19 14:14 . 2007-03-18 19:37 65602 ----a-w- c:\windows\system32\cook3260.dll
2010-02-19 14:14 . 2002-12-10 01:20 102439 ----a-w- c:\windows\system32\sipr3260.dll
2010-02-19 14:14 . 2006-05-11 18:21 626688 ----a-w- c:\windows\system32\vp7vfw.dll
2010-02-19 14:14 . 2006-05-20 15:16 1184984 ----a-w- c:\windows\system32\wvc1dmod.dll
2010-02-18 15:19 . 2010-02-18 15:19 -------- d-----w- c:\documents and settings\All Users\Application Data\id Software
2010-02-12 10:42 . 2008-01-15 16:25 356352 ----a-w- c:\windows\system32\licence.dll
2010-02-01 14:00 . 2010-02-01 14:00 60928 ----a-w- c:\windows\system32\rakion.sys
2010-01-29 22:15 . 2010-01-29 22:15 -------- d-----w- c:\documents and settings\LocalService\Application Data\TuneUp Software
2010-01-28 09:29 . 2009-12-17 23:14 30536 ----a-w- c:\windows\system32\TURegOpt.exe
2010-01-28 09:29 . 2009-12-17 23:08 30024 ----a-w- c:\windows\system32\uxtuneup.dll
2010-01-28 09:28 . 2010-01-28 09:29 -------- d-----w- c:\program files\TuneUp Utilities 2010
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-19 20:12 . 2008-06-04 09:30 215104 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-02-19 19:09 . 2008-06-04 09:30 138576 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-02-19 19:02 . 2007-12-15 09:20 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-02-19 18:45 . 2009-06-24 12:04 -------- d-----w- c:\program files\trend micro
2010-02-19 14:14 . 2009-12-25 13:55 -------- d-----w- c:\program files\vso
2010-02-18 15:19 . 2008-10-24 15:38 2373712 -c--a-w- c:\windows\system32\pbsvc.exe
2010-02-02 15:13 . 2007-09-22 11:54 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-28 17:13 . 2008-09-01 14:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Ubisoft
2010-01-28 09:28 . 2007-09-22 12:06 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2010-01-26 16:22 . 2009-07-11 08:56 -------- d-----w- c:\program files\ICQ6.5
2010-01-23 14:29 . 2009-08-29 10:39 -------- d-----w- c:\documents and settings\All Users\Application Data\PMB Files
2010-01-22 15:48 . 2010-01-22 15:48 0 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\hpq5216.tmp
2010-01-22 15:43 . 2010-01-22 15:43 0 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\hpq5169.tmp
2010-01-22 15:43 . 2010-01-22 15:43 0 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\hpq5164.tmp
2010-01-07 14:47 . 2010-01-07 14:47 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-01-04 20:03 . 2010-01-04 20:03 -------- d-----w- c:\program files\Common Files\Skype
2010-01-04 20:03 . 2007-10-20 13:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-12-26 11:02 . 2009-12-26 11:02 -------- d-----w- c:\program files\Haali
2009-12-26 11:00 . 2009-12-26 11:00 -------- d-----w- c:\program files\CoreCodec
2009-12-26 10:52 . 2009-12-26 10:52 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-12-26 10:45 . 2009-03-01 12:48 -------- d-----w- c:\program files\XviD
2009-12-25 13:55 . 2007-12-20 11:16 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2009-12-17 13:29 . 2009-12-17 13:29 604488 ----a-w- c:\windows\system32\TUProgSt.exe
2009-12-11 18:00 . 2009-12-26 10:52 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2009-12-08 14:44 . 2008-08-10 15:55 304160 ----a-w- C:\PA207.DAT
2009-11-30 11:19 . 2009-11-30 11:19 625728 ----a-w- c:\documents and settings\All Users\Application Data\id Software\QuakeLive\npquakezero.dll
2009-11-30 11:17 . 2009-11-30 11:17 2373712 ----a-w- c:\documents and settings\All Users\Application Data\id Software\QuakeLive\pbsvc.exe
2009-09-25 16:41 . 2009-09-25 16:41 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-09-25 16:41 . 2009-09-25 16:41 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2005-06-29 01:46 . 2004-08-04 12:00 14744064 --sh--w- c:\windows\system32\icm64.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-06-26_16.02.23 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-11-07 01:19 . 2007-11-07 01:19 54272 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_ecc42bd1\vcomp90.dll
+ 2007-11-07 00:19 . 2007-11-07 00:19 54272 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_ecc42bd1\vcomp90.dll
+ 2008-06-12 12:44 . 2005-12-23 11:13 22656 c:\windows\udtablet\AIPTEKTP.SYS
- 2008-06-12 12:44 . 2005-12-23 10:13 22656 c:\windows\udtablet\AIPTEKTP.SYS
- 2008-06-12 12:44 . 2006-01-16 11:32 45056 c:\windows\udtablet\AIPTEKTP.EXE
+ 2008-06-12 12:44 . 2006-01-16 12:32 45056 c:\windows\udtablet\AIPTEKTP.EXE
+ 2010-02-19 20:41 . 2010-02-19 20:41 32768 c:\windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-05-04 17:25 . 2009-09-04 16:44 69464 c:\windows\system32\XAPOFX1_3.dll
+ 2009-05-04 17:25 . 2009-03-16 13:18 22360 c:\windows\system32\X3DAudio1_6.dll
- 2009-05-04 17:25 . 2009-03-16 12:18 22360 c:\windows\system32\X3DAudio1_6.dll
- 2008-06-12 12:44 . 2005-11-24 14:03 69632 c:\windows\system32\WINTAB32.DLL
+ 2008-06-12 12:44 . 2005-11-24 15:03 69632 c:\windows\system32\WINTAB32.DLL
+ 2009-07-06 12:27 . 2009-04-28 20:20 96752 c:\windows\system32\vxblock.dll
- 2008-06-12 12:44 . 2001-05-23 09:58 36864 c:\windows\system32\UTBLFILT.DLL
+ 2008-06-12 12:44 . 2001-05-23 10:58 36864 c:\windows\system32\UTBLFILT.DLL
+ 2008-06-12 12:44 . 2005-06-17 18:09 61440 c:\windows\system32\TBLMOUSE.EXE
- 2008-06-12 12:44 . 2005-06-17 17:09 61440 c:\windows\system32\TBLMOUSE.EXE
+ 2008-06-12 12:44 . 2006-01-10 18:45 61440 c:\windows\system32\Tblfunc.dll
- 2008-06-12 12:44 . 2006-01-10 17:45 61440 c:\windows\system32\Tblfunc.dll
+ 2009-10-21 09:51 . 2009-10-21 09:51 16640 c:\windows\system32\Setup\aladdin\akspccard.sys
+ 2009-11-22 13:54 . 2004-08-04 12:00 24960 c:\windows\system32\ReinstallBackups\0008\DriverFiles\i386\hidparse.sys
+ 2009-11-22 13:54 . 2004-08-04 12:00 36224 c:\windows\system32\ReinstallBackups\0008\DriverFiles\i386\hidclass.sys
+ 2009-11-22 13:54 . 2004-08-04 12:00 20992 c:\windows\system32\ReinstallBackups\0008\DriverFiles\i386\hid.dll
+ 2009-07-06 12:27 . 2009-04-28 20:20 66032 c:\windows\system32\pxinsa64.exe
+ 2009-07-06 12:27 . 2009-04-28 20:20 72176 c:\windows\system32\pxhpinst.exe
+ 2009-07-06 12:27 . 2009-04-28 20:20 66544 c:\windows\system32\pxcpya64.exe
+ 2009-07-20 07:34 . 2009-07-20 07:34 70936 c:\windows\system32\PhysXLoader.dll
- 2009-04-03 10:39 . 2009-04-03 10:39 70936 c:\windows\system32\PhysXLoader.dll
- 2004-08-04 12:00 . 2009-06-19 11:37 79914 c:\windows\system32\perfc009.dat
+ 2004-08-04 12:00 . 2009-10-25 08:12 79914 c:\windows\system32\perfc009.dat
- 2008-12-07 10:39 . 2009-06-10 08:28 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2008-12-07 10:39 . 2009-10-29 11:38 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
- 2008-06-12 12:44 . 2004-01-20 07:00 49152 c:\windows\system32\Funckey.dll
+ 2008-06-12 12:44 . 2004-01-20 08:00 49152 c:\windows\system32\Funckey.dll
+ 2009-08-13 20:18 . 2009-08-13 20:18 34048 c:\windows\system32\eEmpty.exe
+ 2009-07-06 12:27 . 2009-04-28 20:20 44944 c:\windows\system32\drivers\PxHelp20.sys
+ 2009-10-21 09:51 . 2003-12-18 16:53 47616 c:\windows\system32\drivers\Haspnt.sys
- 2008-06-12 12:44 . 2005-12-23 10:13 22656 c:\windows\system32\drivers\aiptektp.sys
+ 2008-06-12 12:44 . 2005-12-23 11:13 22656 c:\windows\system32\drivers\aiptektp.sys
+ 2009-09-25 16:41 . 2009-09-25 16:41 90112 c:\windows\system32\dpl100.dll
+ 2009-06-26 16:04 . 2007-07-30 17:19 53080 c:\windows\system32\dllcache\cache\wuauclt.exe
+ 2009-06-26 16:04 . 2004-08-04 12:00 82944 c:\windows\system32\dllcache\cache\ws2_32.dll
+ 2009-06-26 16:04 . 2004-08-04 12:00 24576 c:\windows\system32\dllcache\cache\userinit.exe
+ 2009-06-26 16:04 . 2004-08-04 12:00 14336 c:\windows\system32\dllcache\cache\svchost.exe
+ 2009-06-26 16:04 . 2005-06-10 23:53 57856 c:\windows\system32\dllcache\cache\spoolsv.exe
+ 2009-06-26 16:04 . 2004-08-04 12:00 17408 c:\windows\system32\dllcache\cache\powrprof.dll
+ 2009-06-26 16:04 . 2004-08-04 12:00 13312 c:\windows\system32\dllcache\cache\lsass.exe
+ 2009-06-26 16:04 . 2004-08-04 12:00 24576 c:\windows\system32\dllcache\cache\kbdclass.sys
+ 2009-06-26 16:04 . 2004-08-04 12:00 29056 c:\windows\system32\dllcache\cache\ip6fw.sys
+ 2009-06-26 16:04 . 2004-08-04 12:00 15360 c:\windows\system32\dllcache\cache\ctfmon.exe
+ 2009-10-19 08:24 . 2009-11-10 15:12 81920 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-10-20 07:59 . 2009-10-20 07:59 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009102020091021\index.dat
+ 2007-09-22 11:23 . 2009-11-10 15:12 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-09-22 11:23 . 2007-09-22 11:23 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-10-20 07:59 . 2009-10-20 07:59 16384 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\MSIMGSIZ.DAT
+ 2007-09-22 11:23 . 2009-11-10 15:12 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-06-12 12:44 . 2005-06-17 17:51 49152 c:\windows\system32\ATWinLog.dll
- 2008-06-12 12:44 . 2005-06-17 16:51 49152 c:\windows\system32\ATWinLog.dll
- 2008-06-12 12:44 . 2006-01-10 17:35 90112 c:\windows\RmTablet.exe
+ 2008-06-12 12:44 . 2006-01-10 18:35 90112 c:\windows\RmTablet.exe
+ 2009-11-18 13:01 . 2009-11-18 13:01 52736 c:\windows\ipuninst.exe
+ 2009-06-05 12:00 . 2009-06-05 12:00 97280 c:\windows\Installer\e54c73.msi
+ 2007-11-08 01:28 . 2007-11-08 01:28 22016 c:\windows\Installer\937792.msp
+ 2007-11-08 01:32 . 2007-11-08 01:32 74240 c:\windows\Installer\93778e.msp
+ 2007-11-08 01:21 . 2007-11-08 01:21 24576 c:\windows\Installer\93778b.msp
+ 2008-09-25 13:43 . 2008-09-25 13:43 20992 c:\windows\Installer\823c9a.msi
+ 2008-09-25 13:42 . 2008-09-25 13:42 24576 c:\windows\Installer\823c94.msi
+ 2008-11-01 09:54 . 2008-11-01 09:54 51712 c:\windows\Installer\3d5909.msi
+ 2010-01-28 09:28 . 2010-01-28 09:28 26624 c:\windows\Installer\29277b.msi
+ 2009-10-31 07:17 . 2009-10-31 07:17 22528 c:\windows\Installer\28e757.msi
+ 2008-05-26 15:49 . 2008-05-26 15:49 22016 c:\windows\Installer\22f50a.msi
+ 2008-05-26 15:43 . 2008-05-26 15:43 32256 c:\windows\Installer\22f4fe.msi
+ 2008-09-14 15:41 . 2008-09-14 15:41 75264 c:\windows\Installer\1b83570.msi
+ 2009-02-15 15:19 . 2009-02-15 15:19 86528 c:\windows\Installer\13f56ce.msi
- 2009-06-19 11:28 . 2009-06-19 11:28 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
- 2009-06-19 11:28 . 2009-06-19 11:28 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2009-10-21 09:52 . 2004-07-06 11:37 7168 c:\windows\system32\Setup\aladdin\hasphl\akscoinst.dll
+ 2009-11-22 13:54 . 2001-08-17 12:02 9600 c:\windows\system32\ReinstallBackups\0008\DriverFiles\i386\hidusb.sys
+ 2007-04-13 14:19 . 2007-04-13 14:19 7680 c:\windows\system32\lsdelete.exe
+ 2009-10-21 09:51 . 2009-10-21 09:51 6656 c:\windows\system32\haspvdd.dll
+ 2007-06-04 14:18 . 2007-06-04 14:18 9344 c:\windows\system32\drivers\NSDriver.sys
+ 2009-07-06 12:27 . 2009-04-28 20:20 9200 c:\windows\system32\drivers\cdralw2k.sys
+ 2009-07-06 12:27 . 2009-04-28 20:20 9072 c:\windows\system32\drivers\cdr4_xp.sys
+ 2007-06-04 14:17 . 2007-06-04 14:17 8320 c:\windows\system32\drivers\AWRTRD.sys
+ 2007-06-04 14:14 . 2007-06-04 14:14 6272 c:\windows\system32\drivers\AWRTPD.sys
+ 2004-08-04 12:00 . 2004-08-04 12:00 2176 c:\windows\system32\dllcache\vga.drv
- 2007-09-22 13:03 . 2004-08-04 12:00 2176 c:\windows\system32\dllcache\vga.drv
+ 2007-09-22 13:03 . 2004-08-04 12:00 9008 c:\windows\system32\dllcache\ver.dll
- 2004-08-04 12:00 . 2004-08-04 12:00 9008 c:\windows\system32\dllcache\ver.dll
- 2004-08-04 12:00 . 2004-08-04 12:00 4048 c:\windows\system32\dllcache\timer.drv
+ 2007-09-22 13:03 . 2004-08-04 12:00 4048 c:\windows\system32\dllcache\timer.drv
- 2007-09-22 13:03 . 2004-08-04 12:00 1744 c:\windows\system32\dllcache\sound.drv
+ 2004-08-04 12:00 . 2004-08-04 12:00 1744 c:\windows\system32\dllcache\sound.drv
- 2007-09-22 13:03 . 2004-08-04 12:00 2032 c:\windows\system32\dllcache\mouse.drv
+ 2004-08-04 12:00 . 2004-08-04 12:00 2032 c:\windows\system32\dllcache\mouse.drv
+ 2007-09-22 13:03 . 2004-08-04 12:00 9936 c:\windows\system32\dllcache\lzexpand.dll
- 2004-08-04 12:00 . 2004-08-04 12:00 9936 c:\windows\system32\dllcache\lzexpand.dll
- 2007-09-22 13:03 . 2004-08-04 12:00 2000 c:\windows\system32\dllcache\keyboard.drv
+ 2004-08-04 12:00 . 2004-08-04 12:00 2000 c:\windows\system32\dllcache\keyboard.drv
+ 2009-11-13 13:55 . 2001-03-23 15:29 880912 c:\windows\WM8EUTIL.exe
+ 2009-07-12 00:12 . 2009-07-12 00:12 632656 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll
+ 2009-07-12 00:09 . 2009-07-12 00:09 554832 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll
+ 2009-07-12 00:08 . 2009-07-12 00:08 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcm80.dll
+ 2007-09-06 09:21 . 2007-09-06 09:21 630784 c:\windows\TruckSaver.scr
+ 2009-12-26 10:52 . 2004-01-25 16:18 217088 c:\windows\system32\yv12vfw.dll
+ 2009-12-26 10:52 . 2009-05-29 21:37 205824 c:\windows\system32\xvidvfw.dll
+ 2009-12-26 10:52 . 2009-05-29 21:31 881664 c:\windows\system32\xvidcore.dll
+ 2009-10-09 10:01 . 2009-09-04 16:44 515416 c:\windows\system32\XAudio2_5.dll
+ 2009-05-04 17:25 . 2009-03-16 13:18 517448 c:\windows\system32\XAudio2_4.dll
- 2009-05-04 17:25 . 2009-03-16 12:18 517448 c:\windows\system32\XAudio2_4.dll
+ 2009-10-09 10:01 . 2009-09-04 16:44 238936 c:\windows\system32\xactengine3_5.dll
+ 2009-05-04 17:25 . 2009-03-16 13:18 235352 c:\windows\system32\xactengine3_4.dll
- 2009-05-04 17:25 . 2009-03-16 12:18 235352 c:\windows\system32\xactengine3_4.dll
+ 2007-12-12 13:47 . 2009-09-13 14:44 444952 c:\windows\system32\wrap_oal.dll
- 2007-12-12 13:47 . 2008-05-15 09:58 444952 c:\windows\system32\wrap_oal.dll
+ 2005-10-14 10:56 . 2009-08-16 15:08 178176 c:\windows\system32\unrar.dll
+ 2009-08-13 20:18 . 2004-08-04 12:00 135680 c:\windows\system32\T.COM
+ 2009-10-21 09:50 . 1998-12-10 17:00 519680 c:\windows\system32\SS32D25.DLL
+ 2009-10-21 09:52 . 2005-07-28 06:18 685056 c:\windows\system32\Setup\aladdin\hasphl\hardlock.sys
+ 2009-10-21 09:52 . 2005-07-20 16:08 100096 c:\windows\system32\Setup\aladdin\hasphl\aksusb.sys
+ 2009-10-21 09:52 . 2005-07-20 16:08 327808 c:\windows\system32\Setup\aladdin\hasphl\akshasp.sys
+ 2009-10-21 09:52 . 2005-07-20 16:08 104576 c:\windows\system32\Setup\aladdin\hasphl\aksclass.sys
+ 2009-07-06 12:27 . 2009-04-28 20:20 436720 c:\windows\system32\pxwave.dll
+ 2009-07-06 12:27 . 2009-04-28 20:20 219632 c:\windows\system32\pxmas.dll
+ 2009-10-27 12:01 . 2009-09-25 16:42 118520 c:\windows\system32\pxinsi64.exe
+ 2009-07-06 12:27 . 2009-04-28 20:20 551408 c:\windows\system32\pxdrv.dll
+ 2009-10-27 12:01 . 2009-09-25 16:42 120056 c:\windows\system32\pxcpyi64.exe
+ 2009-07-06 12:27 . 2009-04-28 20:20 129520 c:\windows\system32\pxafs.dll
+ 2009-07-06 12:27 . 2009-04-28 20:20 670192 c:\windows\system32\px.dll
- 2004-08-04 12:00 . 2009-06-19 11:37 462054 c:\windows\system32\perfh009.dat
+ 2004-08-04 12:00 . 2009-10-25 08:12 462054 c:\windows\system32\perfh009.dat
+ 2007-12-12 13:47 . 2009-09-13 14:44 109080 c:\windows\system32\OpenAL32.dll
- 2007-12-12 13:47 . 2008-05-15 09:58 109080 c:\windows\system32\OpenAL32.dll
+ 2009-07-18 03:21 . 2009-07-18 03:21 257440 c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2009-10-21 09:57 . 2003-12-18 16:53 304640 c:\windows\system32\hlvdd.dll
+ 2009-12-25 13:55 . 2006-09-29 10:24 217127 c:\windows\system32\drv43260.dll
+ 2009-12-25 13:55 . 2006-09-29 10:25 208935 c:\windows\system32\drv33260.dll
+ 2009-12-25 13:55 . 2006-09-29 10:26 176165 c:\windows\system32\drv23260.dll
+ 2009-10-21 09:52 . 2004-01-31 18:14 420000 c:\windows\system32\drivers\hardlock.sys
+ 2009-12-02 10:51 . 2008-04-30 20:01 108488 c:\windows\system32\drivers\dptrackerd.sys
+ 2009-06-26 16:04 . 2004-08-04 12:00 502272 c:\windows\system32\dllcache\cache\winlogon.exe
+ 2009-06-26 16:04 . 2007-06-26 14:09 658944 c:\windows\system32\dllcache\cache\wininet.dll
+ 2009-06-26 16:04 . 2007-03-08 15:36 577536 c:\windows\system32\dllcache\cache\user32.dll
+ 2009-06-26 16:04 . 2004-08-04 12:00 295424 c:\windows\system32\dllcache\cache\termsrv.dll
+ 2009-06-26 16:04 . 2006-04-20 11:51 359808 c:\windows\system32\dllcache\cache\tcpip.sys
+ 2009-06-26 16:04 . 2004-08-04 12:00 108032 c:\windows\system32\dllcache\cache\services.exe
+ 2009-06-26 16:04 . 2004-08-04 12:00 182912 c:\windows\system32\dllcache\cache\ndis.sys
+ 2009-06-26 16:04 . 2007-04-16 15:52 984576 c:\windows\system32\dllcache\cache\kernel32.dll
+ 2009-06-26 16:04 . 2004-08-04 12:00 110080 c:\windows\system32\dllcache\cache\imm32.dll
+ 2009-06-26 16:04 . 2004-08-04 12:00 167936 c:\windows\system32\dllcache\cache\appmgmts.dll
+ 2009-09-25 16:41 . 2009-09-25 16:41 843776 c:\windows\system32\divx_xx16.dll
+ 2009-09-25 16:41 . 2009-09-25 16:41 839680 c:\windows\system32\divx_xx11.dll
+ 2009-09-25 16:41 . 2009-09-25 16:41 856064 c:\windows\system32\divx_xx0c.dll
+ 2009-09-25 16:41 . 2009-09-25 16:41 847872 c:\windows\system32\divx_xx0a.dll
+ 2009-09-25 16:41 . 2009-09-25 16:41 856064 c:\windows\system32\divx_xx07.dll
+ 2009-09-25 16:41 . 2009-09-25 16:41 696320 c:\windows\system32\DivX.dll
+ 2009-10-09 10:01 . 2009-09-04 16:29 235344 c:\windows\system32\d3dx11_42.dll
+ 2009-10-09 10:01 . 2009-09-04 16:29 453456 c:\windows\system32\d3dx10_42.dll
+ 2009-05-04 17:25 . 2009-03-09 14:27 453456 c:\windows\system32\d3dx10_41.dll
- 2009-05-04 17:25 . 2009-03-09 13:27 453456 c:\windows\system32\d3dx10_41.dll
+ 2008-12-12 12:03 . 2008-10-15 05:22 452440 c:\windows\system32\d3dx10_40.dll
- 2008-12-12 12:03 . 2008-10-15 04:22 452440 c:\windows\system32\d3dx10_40.dll
- 2008-06-12 12:44 . 2005-07-27 14:55 290816 c:\windows\system32\atwtusbL.exe
+ 2008-06-12 12:44 . 2005-07-27 15:55 290816 c:\windows\system32\atwtusbL.exe
- 2008-06-12 12:44 . 2006-01-17 14:57 294912 c:\windows\system32\ATWTUSB.EXE
+ 2008-06-12 12:44 . 2006-01-17 15:57 294912 c:\windows\system32\ATWTUSB.EXE
+ 2009-08-13 20:18 . 2004-08-04 12:00 146432 c:\windows\R.COM
+ 2009-06-19 11:37 . 2009-06-19 11:37 634368 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5\vs_setup.msi
+ 2009-10-21 09:50 . 2009-10-21 09:50 106496 c:\windows\kokundo.exe
+ 2009-08-28 11:06 . 1998-01-14 20:06 304128 c:\windows\IsUn0411.exe
+ 2007-10-18 12:02 . 2007-10-18 12:02 282624 c:\windows\Installer\fe5257.msi
+ 2009-10-27 12:01 . 2009-10-27 12:01 169472 c:\windows\Installer\ef24bc.msi
+ 2007-11-18 14:37 . 2007-11-18 14:37 566272 c:\windows\Installer\d2a05c.msi
+ 2009-02-17 09:00 . 2009-02-17 09:01 228352 c:\windows\Installer\cea0e.msi
+ 2007-10-05 12:02 . 2007-10-05 12:02 123904 c:\windows\Installer\c1bdc5.msi
+ 2007-10-05 12:02 . 2007-10-05 12:02 123904 c:\windows\Installer\c1bdbf.msi
+ 2007-10-05 12:02 . 2007-10-05 12:02 123904 c:\windows\Installer\c1bdb9.msi
+ 2008-04-18 11:51 . 2008-04-18 11:51 289792 c:\windows\Installer\b2f4d6.msi
+ 2009-06-19 11:37 . 2009-06-19 11:37 630272 c:\windows\Installer\95acab.msi
+ 2007-11-08 01:34 . 2007-11-08 01:34 273920 c:\windows\Installer\93778f.msp
+ 2009-06-19 11:36 . 2009-06-19 11:36 348160 c:\windows\Installer\937788.msi
+ 2009-06-19 11:35 . 2009-06-19 11:35 871424 c:\windows\Installer\937772.msi
+ 2008-10-06 13:13 . 2008-10-06 13:13 203264 c:\windows\Installer\8a142e.msi
+ 2008-10-06 13:13 . 2008-10-06 13:13 129536 c:\windows\Installer\8a1428.msi
+ 2008-10-06 13:13 . 2008-10-06 13:13 130048 c:\windows\Installer\8a1422.msi
+ 2008-10-06 13:12 . 2008-10-06 13:12 985600 c:\windows\Installer\8a1416.msi
+ 2008-10-06 13:12 . 2008-10-06 13:12 315392 c:\windows\Installer\8a140f.msi
+ 2008-10-06 13:11 . 2008-10-06 13:11 290816 c:\windows\Installer\8a1409.msi
+ 2008-10-06 13:11 . 2008-10-06 13:11 152576 c:\windows\Installer\8a1403.msi
+ 2008-10-06 13:11 . 2008-10-06 13:11 281088 c:\windows\Installer\8a13fd.msi
+ 2008-10-06 13:11 . 2008-10-06 13:11 353792 c:\windows\Installer\8a13f6.msi
+ 2008-10-06 13:11 . 2008-10-06 13:11 528384 c:\windows\Installer\8a13ef.msi
+ 2008-10-06 13:11 . 2008-10-06 13:11 121344 c:\windows\Installer\8a13e1.msi
+ 2008-10-06 13:11 . 2008-10-06 13:11 274432 c:\windows\Installer\8a13db.msi
+ 2008-10-06 13:11 . 2008-10-06 13:11 121344 c:\windows\Installer\8a13d1.msi
+ 2008-10-06 13:10 . 2008-10-06 13:10 299008 c:\windows\Installer\8a13cb.msi
+ 2008-10-06 13:10 . 2008-10-06 13:10 491008 c:\windows\Installer\8a13c3.msi
+ 2008-10-06 13:10 . 2008-10-06 13:10 247296 c:\windows\Installer\8a13bd.msi
+ 2008-10-06 13:10 . 2008-10-06 13:10 589312 c:\windows\Installer\8a13b7.msi
+ 2008-10-06 13:10 . 2008-10-06 13:10 175616 c:\windows\Installer\8a13b0.msi
+ 2008-10-06 13:10 . 2008-10-06 13:10 121344 c:\windows\Installer\8a13aa.msi
+ 2008-10-06 13:10 . 2008-10-06 13:10 247296 c:\windows\Installer\8a13a4.msi
+ 2008-10-06 13:10 . 2008-10-06 13:10 129536 c:\windows\Installer\8a139d.msi
+ 2008-10-06 13:10 . 2008-10-06 13:10 728064 c:\windows\Installer\8a1397.msi
+ 2008-10-06 13:09 . 2008-10-06 13:09 338432 c:\windows\Installer\8a1391.msi
+ 2008-10-06 13:09 . 2008-10-06 13:09 287744 c:\windows\Installer\8a138a.msi
+ 2008-10-06 13:09 . 2008-10-06 13:09 136704 c:\windows\Installer\8a1384.msi
+ 2007-09-27 13:38 . 2007-09-27 13:38 166400 c:\windows\Installer\7f436.msi
+ 2009-05-21 12:50 . 2009-05-21 12:50 515072 c:\windows\Installer\732c9.msi
+ 2008-10-25 09:55 . 2008-10-25 09:55 366592 c:\windows\Installer\728f35.msi
+ 2009-03-05 15:22 . 2009-03-05 15:22 487936 c:\windows\Installer\47fe5c.msi
+ 2008-02-28 10:05 . 2008-02-28 10:05 782336 c:\windows\Installer\443d40.msi
+ 2007-09-25 06:51 . 2007-09-25 06:51 431104 c:\windows\Installer\394d5.msi
+ 2009-01-18 10:18 . 2009-01-18 10:18 228352 c:\windows\Installer\2f563e.msi
+ 2008-11-28 21:42 . 2008-11-28 21:42 874496 c:\windows\Installer\2d32c6b.msi
+ 2009-03-25 08:42 . 2009-03-25 08:42 213504 c:\windows\Installer\2c9411.msi
+ 2010-01-28 09:29 . 2010-01-28 09:29 317952 c:\windows\Installer\29277f.msi
+ 2007-09-22 11:26 . 2007-09-22 11:26 264704 c:\windows\Installer\27ec0.msi
+ 2008-11-04 18:21 . 2008-11-04 18:21 390656 c:\windows\Installer\277af23.msi
+ 2007-09-22 13:43 . 2007-09-22 13:43 178176 c:\windows\Installer\274cfd.msi
+ 2008-09-12 15:47 . 2008-09-12 15:47 580608 c:\windows\Installer\22bafa5.msi
+ 2008-02-25 16:30 . 2008-02-25 16:30 808960 c:\windows\Installer\1a4c722.msi
+ 2009-05-09 16:47 . 2009-05-09 16:47 251392 c:\windows\Installer\17fa90.msi
+ 2007-10-05 15:15 . 2007-10-05 15:15 331264 c:\windows\Installer\1754a5b.msi
+ 2010-02-18 15:19 . 2010-02-18 15:19 178176 c:\windows\Installer\15bf538.msi
+ 2007-11-07 14:07 . 2007-11-07 14:07 999936 c:\windows\Installer\13f56d7.msp
+ 2007-11-07 13:56 . 2007-11-07 13:56 553472 c:\windows\Installer\13f56d4.msp
+ 2007-11-07 13:58 . 2007-11-07 13:58 908800 c:\windows\Installer\13f56d0.msp
+ 2007-11-07 13:54 . 2007-11-07 13:54 507392 c:\windows\Installer\13f56cf.msp
+ 2007-11-26 15:35 . 2007-11-26 15:35 380928 c:\windows\Installer\12cdb5c.msi
+ 2008-02-02 13:39 . 2008-02-02 13:39 926208 c:\windows\Installer\110a178.msi
+ 2007-12-17 13:12 . 2007-12-17 13:12 409600 c:\windows\Installer\10db443.msi
+ 2007-12-08 14:30 . 2007-12-08 14:30 413696 c:\windows\Installer\106d4a8.msi
+ 2010-01-04 20:03 . 2010-01-04 20:03 371272 c:\windows\Installer\{D103C4BA-F905-437A-8049-DB24763BBE36}\SkypeIcon.exe
+ 2009-12-12 10:54 . 2009-12-12 10:54 178688 c:\windows\Installer\{46AC899A-9ECB-43DC-85DE-272E0D116A1E}\Icon0E6AB9FC1.exe
+ 2009-09-14 08:51 . 2009-09-14 15:53 200704 c:\windows\B83FC356B7C0441F8A4DD71E088E7974.TMP\WiseCustomCalla.dll
- 2009-06-19 11:28 . 2009-06-19 11:28 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
- 2009-06-19 11:28 . 2009-06-19 11:28 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
- 2009-06-19 11:28 . 2009-06-19 11:28 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
- 2009-06-19 11:28 . 2009-06-19 11:28 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
- 2009-06-19 11:28 . 2009-06-19 11:28 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
- 2009-06-19 11:28 . 2009-06-19 11:28 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-06-19 11:28 . 2009-06-19 11:28 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-06-19 11:28 . 2009-06-19 11:28 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-06-19 11:28 . 2009-06-19 11:28 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-06-19 11:28 . 2009-06-19 11:28 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-06-19 11:28 . 2009-06-19 11:28 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-06-19 11:28 . 2009-06-19 11:28 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-06-19 11:28 . 2009-06-19 11:28 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-06-19 11:28 . 2009-06-19 11:28 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2008-02-20 14:20 . 2010-02-02 15:47 155648 c:\windows\85EBB28365AF4C539EBE7C0A232762F7.TMP\WiseCustomCalla.dll
- 2008-02-20 14:20 . 2008-02-20 14:20 155648 c:\windows\85EBB28365AF4C539EBE7C0A232762F7.TMP\WiseCustomCalla.dll
+ 2009-09-01 16:52 . 2009-09-02 09:02 155648 c:\windows\10004C34B7194F9186D406FB51AB6BFB.TMP\WiseCustomCalla.dll
+ 2004-08-04 12:00 . 2004-08-04 12:00 1326080 c:\windows\system32\webfldrs.msi
+ 2008-06-12 12:44 . 2005-07-19 14:15 1617920 c:\windows\system32\TblRes.dll
- 2008-06-12 12:44 . 2005-07-19 13:15 1617920 c:\windows\system32\TblRes.dll
+ 2008-07-29 14:05 . 2008-07-29 14:05 1296896 c:\windows\system32\SPort.dll
+ 2009-07-06 12:27 . 2009-04-28 20:20 1858032 c:\windows\system32\pxsfs.dll
+ 2009-07-18 03:21 . 2009-07-18 03:21 3883424 c:\windows\system32\Macromed\Flash\NPSWF32.dll
+ 2007-09-22 13:02 . 2009-11-23 10:05 1912896 c:\windows\system32\FNTCACHE.DAT
+ 2009-06-26 16:04 . 2004-08-04 12:00 1580544 c:\windows\system32\dllcache\cache\sfcfiles.dll
+ 2009-06-26 16:04 . 2007-02-28 09:10 2180352 c:\windows\system32\dllcache\cache\ntoskrnl.exe
+ 2009-06-26 16:04 . 2007-02-28 08:38 2057600 c:\windows\system32\dllcache\cache\ntkrnlpa.exe
+ 2009-06-26 16:04 . 2007-06-13 10:23 1033216 c:\windows\system32\dllcache\cache\explorer.exe
+ 2009-10-09 10:01 . 2009-09-04 16:29 1892184 c:\windows\system32\D3DX9_42.dll
+ 2009-05-04 17:25 . 2009-03-09 14:27 4178264 c:\windows\system32\D3DX9_41.dll
- 2009-05-04 17:25 . 2009-03-09 13:27 4178264 c:\windows\system32\D3DX9_41.dll
+ 2008-12-12 12:03 . 2008-10-15 05:22 4379984 c:\windows\system32\D3DX9_40.dll
- 2008-12-12 12:03 . 2008-10-15 04:22 4379984 c:\windows\system32\D3DX9_40.dll
+ 2009-10-09 10:01 . 2009-09-04 16:29 5501792 c:\windows\system32\d3dcsx_42.dll
+ 2009-10-09 10:01 . 2009-09-04 16:29 1974616 c:\windows\system32\D3DCompiler_42.dll
- 2009-05-04 17:25 . 2009-03-09 13:27 1846632 c:\windows\system32\D3DCompiler_41.dll
+ 2009-05-04 17:25 . 2009-03-09 14:27 1846632 c:\windows\system32\D3DCompiler_41.dll
+ 2008-12-12 12:03 . 2008-10-15 05:22 2036576 c:\windows\system32\D3DCompiler_40.dll
- 2008-12-12 12:03 . 2008-10-15 04:22 2036576 c:\windows\system32\D3DCompiler_40.dll
+ 2008-08-10 15:22 . 2008-08-10 15:22 6232576 c:\windows\Installer\f5fb49.msi
+ 2007-10-20 12:52 . 2007-10-20 12:52 3563520 c:\windows\Installer\d26733.msi
+ 2009-01-08 16:07 . 2009-01-08 16:07 3762688 c:\windows\Installer\c78a1e.msi
+ 2009-01-08 16:01 . 2009-01-08 16:01 8989696 c:\windows\Installer\c78a11.msi
+ 2009-01-08 15:59 . 2009-01-08 15:59 1549312 c:\windows\Installer\c7876e.msi
+ 2009-01-08 15:59 . 2009-01-08 15:59 3152384 c:\windows\Installer\c7873e.msi
+ 2007-10-05 12:03 . 2007-10-05 12:03 3443712 c:\windows\Installer\c55daa.msi
+ 2007-09-22 12:28 . 2007-09-22 12:28 5807104 c:\windows\Installer\bb6a5.msi
+ 2008-09-19 19:34 . 2008-09-19 19:34 3899392 c:\windows\Installer\a404d4.msi
+ 2010-01-04 20:03 . 2010-01-04 20:03 1565696 c:\windows\Installer\9fe433.msi
+ 2007-11-08 01:30 . 2007-11-08 01:30 3962368 c:\windows\Installer\937791.msp
+ 2007-11-08 01:13 . 2007-11-08 01:13 6766592 c:\windows\Installer\937790.msp
+ 2007-11-08 01:26 . 2007-11-08 01:26 4340224 c:\windows\Installer\93778d.msp
+ 2007-11-08 01:24 . 2007-11-08 01:24 5353472 c:\windows\Installer\93778c.msp
+ 2007-11-08 01:18 . 2007-11-08 01:18 2059264 c:\windows\Installer\93778a.msp
+ 2007-11-08 01:16 . 2007-11-08 01:16 1313280 c:\windows\Installer\937789.msp
+ 2008-10-06 13:12 . 2008-10-06 13:12 3658752 c:\windows\Installer\8a141c.msi
+ 2009-03-12 09:42 . 2009-03-12 09:42 3938816 c:\windows\Installer\76767.msi
+ 2007-09-22 14:53 . 2007-09-22 14:53 1769984 c:\windows\Installer\5a7e1d.msi
+ 2007-09-22 14:52 . 2007-09-22 14:52 1767424 c:\windows\Installer\5a7e11.msi
+ 2007-09-22 14:48 . 2007-09-22 14:48 1845248 c:\windows\Installer\5a7e0b.msi
+ 2007-09-22 14:48 . 2007-09-22 14:48 1768448 c:\windows\Installer\5a7dab.msi
+ 2007-09-22 14:38 . 2007-09-22 14:38 3035648 c:\windows\Installer\5a7da4.msi
+ 2009-12-12 10:54 . 2009-12-12 10:54 3027968 c:\windows\Installer\52d92.msi
+ 2008-01-12 16:38 . 2008-01-12 16:38 5885952 c:\windows\Installer\51bfce.msi
+ 2008-01-20 14:14 . 2008-01-20 14:14 4337664 c:\windows\Installer\47162f.msi
+ 2008-01-20 14:12 . 2008-01-20 14:12 8448512 c:\windows\Installer\471621.msi
+ 2008-11-20 08:56 . 2008-11-20 08:56 8742912 c:\windows\Installer\3f5515.msi
+ 2008-10-05 03:12 . 2008-10-05 03:12 4784128 c:\windows\Installer\3d5910.msp
+ 2009-08-13 17:44 . 2009-08-13 17:44 1500160 c:\windows\Installer\306e72.msi
+ 2007-09-30 11:16 . 2007-09-30 11:16 7898624 c:\windows\Installer\233ee.msi
+ 2009-01-17 18:44 . 2009-01-17 18:45 2428416 c:\windows\Installer\2199ab0.msi
+ 2009-01-17 18:42 . 2009-01-17 18:42 1780224 c:\windows\Installer\2199aa6.msi
+ 2009-01-17 18:41 . 2009-01-17 18:41 1718272 c:\windows\Installer\2199aa0.msi
+ 2009-01-17 18:41 . 2009-01-17 18:41 1725952 c:\windows\Installer\2199a9a.msi
+ 2009-01-17 18:40 . 2009-01-17 18:40 1954304 c:\windows\Installer\2199a94.msi
+ 2009-01-17 18:40 . 2009-01-17 18:40 1826816 c:\windows\Installer\2199a8e.msi
+ 2009-01-17 18:39 . 2009-01-17 18:39 1726976 c:\windows\Installer\2199a88.msi
+ 2009-01-17 18:38 . 2009-01-17 18:38 1879040 c:\windows\Installer\2199a82.msi
+ 2009-01-17 18:38 . 2009-01-17 18:38 1730048 c:\windows\Installer\2199a7c.msi
+ 2009-01-17 18:37 . 2009-01-17 18:37 1761792 c:\windows\Installer\2199a76.msi
+ 2009-01-17 18:37 . 2009-01-17 18:37 1735680 c:\windows\Installer\2199a70.msi
+ 2009-01-17 18:36 . 2009-01-17 18:36 1744384 c:\windows\Installer\2199a6a.msi
+ 2009-01-17 18:35 . 2009-01-17 18:35 2159104 c:\windows\Installer\2199a64.msi
+ 2009-01-17 18:33 . 2009-01-17 18:33 1715712 c:\windows\Installer\2199a5e.msi
+ 2009-01-17 18:33 . 2009-01-17 18:33 1715712 c:\windows\Installer\2199a57.msi
+ 2009-01-17 18:32 . 2009-01-17 18:32 1716736 c:\windows\Installer\2199a50.msi
+ 2009-01-17 18:32 . 2009-01-17 18:32 1715712 c:\windows\Installer\2199a49.msi
+ 2009-01-17 18:31 . 2009-01-17 18:31 1718272 c:\windows\Installer\2199a42.msi
+ 2009-01-17 18:31 . 2009-01-17 18:31 1761792 c:\windows\Installer\2199a3c.msi
+ 2009-01-17 18:30 . 2009-01-17 18:30 1753088 c:\windows\Installer\2199a36.msi
+ 2009-01-17 18:30 . 2009-01-17 18:30 1720832 c:\windows\Installer\2199a30.msi
+ 2009-01-17 18:29 . 2009-01-17 18:29 2595840 c:\windows\Installer\2199a2a.msi
+ 2009-01-17 18:25 . 2009-01-17 18:25 1826304 c:\windows\Installer\2199a24.msi
+ 2009-01-17 18:25 . 2009-01-17 18:25 1716736 c:\windows\Installer\2199a1e.msi
+ 2007-12-24 19:34 . 2007-12-24 19:34 1880576 c:\windows\Installer\1f6afa6.msi
+ 2009-01-17 18:14 . 2009-01-17 18:14 1767424 c:\windows\Installer\1db580e.msi
+ 2008-02-25 09:21 . 2008-02-25 09:21 3680768 c:\windows\Installer\191b8f.msi
+ 2007-11-07 13:50 . 2007-11-07 13:50 6055936 c:\windows\Installer\13f56d6.msp
+ 2007-11-07 14:00 . 2007-11-07 14:00 3407360 c:\windows\Installer\13f56d5.msp
+ 2007-11-07 13:46 . 2007-11-07 13:46 3010560 c:\windows\Installer\13f56d3.msp
+ 2007-11-07 14:02 . 2007-11-07 14:02 6473216 c:\windows\Installer\13f56d2.msp
+ 2007-11-07 14:12 . 2007-11-07 14:12 2533376 c:\windows\Installer\13f56d1.msp
+ 2008-11-20 13:24 . 2008-11-20 13:24 1154048 c:\windows\Installer\13edd61.msi
+ 2007-09-25 12:43 . 2007-09-25 12:43 5573120 c:\windows\Installer\125af51.msi
+ 2009-04-14 14:12 . 2009-04-14 14:12 1492992 c:\windows\Installer\10f1bf1.msi
+ 2009-12-12 10:54 . 2009-12-12 10:54 1038336 c:\windows\Installer\{46AC899A-9ECB-43DC-85DE-272E0D116A1E}\Icon0E6AB9FC.exe
+ 2008-02-28 10:04 . 2008-02-28 10:04 6435328 c:\windows\Downloaded Installations\{FCC57BD8-B1F2-4EA1-A39E-E115E6C9D4FA}\Image Compressor 2008 Pro Edition.msi
- 2009-06-19 11:28 . 2009-06-19 11:28 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-02-02 15:45 . 2010-02-02 15:45 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-06-19 11:28 . 2009-06-19 11:28 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2007-10-20 12:54 . 2007-10-20 12:54 23867392 c:\windows\Installer\d26745.msi
+ 2007-09-27 13:40 . 2007-09-27 13:40 10237952 c:\windows\Installer\7f43b.msi
+ 2008-01-20 14:16 . 2008-01-20 14:16 12388864 c:\windows\Installer\471632.msi
+ 2009-01-13 17:21 . 2009-01-13 17:21 13948416 c:\windows\Installer\245e74d.msi
+ 2007-12-04 16:57 . 2007-12-04 16:57 19210240 c:\windows\Installer\19fe12d.msp
+ 2005-08-31 02:31 . 2005-08-31 02:31 23870464 c:\windows\Downloaded Installations\Macromedia Flash 8\Macromedia Flash 8.msi
+ 2007-09-30 11:13 . 2007-09-30 11:12 39060840 c:\windows\Downloaded Installations\{B56B1487-9A26-4AFD-A1FD-949C40F5F2BC}\Sony Ericsson PC Suite.msi
+ 2008-03-25 14:33 . 2008-03-25 14:33 12406272 c:\windows\Downloaded Installations\{97F709BD-5B08-4007-B4AE-08C6277EDCC5}\GameShadow.msi
+ 2008-03-05 13:09 . 2008-03-24 19:59 10854784 c:\windows\Downloaded Installations\{6358ABF1-38A3-493A-AFF2-679D6D09B12E}\GameShadow.msi
+ 2008-03-05 13:51 . 2008-03-25 09:20 10853760 c:\windows\Downloaded Installations\{63256143-86D7-4354-AF75-7580F4B0C359}\GameShadow.msi
+ 2008-08-10 15:21 . 2008-08-10 15:21 11049984 c:\windows\Downloaded Installations\{51C8736D-4956-4172-AACA-0A8FFC4BC652}\PC Camera .msi
+ 2007-09-26 15:13 . 2007-09-30 11:12 39060840 c:\windows\Downloaded Installations\{2352A5E3-0109-4D7F-BF13-16A5C01AB37D}\Sony Ericsson PC Suite.msi
+ 2008-11-20 13:22 . 2008-11-20 13:22 241051648 c:\windows\Installer\13edd5a.msi
.
-- Snapshot reset to current date --
.
Re: Problem s PC je pomaly
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-09-10 218032]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2009-12-20 2935480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2008-08-15 949376]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"nwiz"="nwiz.exe" [2009-03-27 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 53760]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-11 282624]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient]
2005-01-31 14:13 49152 ----a-w- c:\progra~1\COMMON~1\stardock\MCPStub.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
2008-03-16 13:31 229376 ----a-w- d:\programy\WindowBlinds\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\wbsys.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Skype"="d:\programy\Phone\Skype.exe" /nosplash /minimized
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
"DAEMON Tools Lite"="d:\programy\DAEMON Tools Lite\daemon.exe" -autorun
"DAEMON Tools Pro Agent"="d:\programy\DAEMON Tools Pro\DTProAgent.exe"
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
"µTorrent"=d:\programy\uTorrent\utorrent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
"NeroFilterCheck"=c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
"ISUSPM Startup"=c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" -start
"QuickTime Task"="d:\programy\QuickTIme\qttask.exe" -atboottime
"RivaTunerStartupDaemon"="d:\programy\RivaTuner v2.06\RivaTuner.exe" /S
"atwtusb"=atwtusb.exe beta
"PWRISOVM.EXE"=d:\programy\PowerISO\PWRISOVM.EXE
"PHIME2002ASync"=c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
"PHIME2002A"=c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"HP Software Update"=c:\program files\HP\HP Software Update\HPWuSchd2.exe
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe"
"iTunesHelper"="d:\programy\iTunes\iTunesHelper.exe"
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"FBSearch"=c:\program files\Search Guard Plus\SearchGuardPlus.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices-]
"Audio Sound Blaster System"=sabhost.exe
"Running Task Manager"=rtshost.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Programy\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"d:\\Programy\\Clear FTP 2006\\clearftp.exe"=
"d:\\Programy\\Fps Creator\\MyGames\\arenaskuska\\arenaskuska.exe"=
"d:\\Programy\\Fps Creator\\FPSC-Game.exe"=
"d:\\Programy\\eDisk klient\\eDisk klient.exe"=
"d:\\Programy\\Fps Creator\\MyGames\\arenaskuska2\\arenaskuska2.exe"=
"d:\\Programy\\Hamachi\\hamachi.exe"=
"d:\\Programy\\GoQ - NetRadio\\NetRadio.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"d:\\Programy\\HLSW\\hlsw.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"d:\\Programy\\QIP Infium\\infium.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"d:\\Programz\\Orbitdownloader\\orbitdm.exe"=
"d:\\Programz\\Orbitdownloader\\orbitnet.exe"=
"d:\\Programy\\LimeWire\\LimeWire.exe"=
"d:\\HRY\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"d:\\Programy\\Edisk\\eDisk klient\\eDisk klient.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"d:\\Programy\\real player\\realplay.exe"=
"d:\\Programy\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"d:\\Programy\\Plugin Manager\\skypePM.exe"=
"d:\\HRY\\THPS2\\THawk2_smaller.exe"=
"d:\\Programy\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"59137:TCP"= 59137:TCP:Pando Media Booster
"59137:UDP"= 59137:UDP:Pando Media Booster
"56096:TCP"= 56096:TCP:Pando Media Booster
"56096:UDP"= 56096:UDP:Pando Media Booster
R?2 wmcmgc;Windows Management Configuration;c:\windows\System32\svchost.exe -k netsvcs [4.8.2004 13:00 14336]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [4.10.2007 10:57 717296]
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [15.8.2008 12:13 15424]
R1 sdpiosys;sdpiosys;c:\windows\system32\drivers\SDPIOSYS.SYS [30.11.2004 12:10 161792]
R2 NVIDIA Performance Driver Service;NVIDIA Performance Driver Service;c:\program files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe [11.12.2008 6:08 3575808]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [18.12.2009 0:12 1044808]
R3 PAC207;PC Camera;c:\windows\system32\drivers\PFC027.SYS [29.5.2007 12:30 508160]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [14.10.2009 7:24 10064]
S1 aiptektp;Pen Pad;c:\windows\system32\drivers\aiptektp.sys [12.6.2008 13:44 22656]
S2 gupdate1ca56fca6d5367e;Služba Google Update (gupdate1ca56fca6d5367e);c:\program files\Google\Update\GoogleUpdate.exe [27.10.2009 12:57 133104]
S3 hamachi_oem;PlayLinc Adapter;c:\windows\system32\drivers\gan_adapter.sys [28.8.2006 22:54 10664]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 rak;rak;c:\windows\system32\rakion.sys [1.2.2010 15:00 60928]
S3 zlportio;zlportio;\??\d:\from torrent\ultrastardx-101a-full\zlportio.sys --> d:\from torrent\ultrastardx-101a-full\zlportio.sys [?]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2010-02-19 c:\windows\Tasks\Automatic troubleshooting.job
- c:\program files\TuneUp Utilities 2010\TuneUpSystemStatusCheck.exe [2009-12-17 23:18]
2010-02-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-27 11:57]
2010-02-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-27 11:57]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uDefault_Search_URL = hxxp://search13.net/
mStart Page = about:blank
uSearchAssistant = hxxp://search13.net/
uCustomizeSearch = hxxp://search13.net/
IE: &Compress Image Using Image Compressor 2008 - d:\programy\image compressor 08 pro ed\imcieex_compress.html
IE: &Download by Orbit - d:\programz\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - d:\programz\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - d:\programz\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - d:\programz\Orbitdownloader\orbitmxt.dll/202
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\windows\system32\imon.dll
Trusted Zone: ketsujin.com\fighterace
Trusted Zone: ketsujin.com\primary
Trusted Zone: ketsujin.com\update
Trusted Zone: ketsujin.com\www
Trusted Zone: stormofaces.com\www
DPF: {248F1F2D-E854-40AD-BB42-2E69EBC1CD8B} - hxxps://zona.t-com.sk/VianKampan2007/STWebDialer.cab
FF - ProfilePath - c:\documents and settings\Adrián Pyteľ\Application Data\Mozilla\Firefox\Profiles\xevyq5n9.default\
FF - prefs.js: browser.search.selectedEngine - Fast Browser Search
FF - prefs.js: browser.startup.homepage - hxxp://cs.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:cs:official
FF - component: d:\programz\Orbitdownloader\addons\OneClickYouTubeDownloader\components\GrabXpcom.dll
FF - plugin: c:\documents and settings\All Users\Application Data\id Software\QuakeLive\npquakezero.dll
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: d:\programy\iTunes\Mozilla Plugins\npitunes.dll
FF - plugin: d:\programy\QuickTIme\Plugins\npqtplugin.dll
FF - plugin: d:\programy\QuickTIme\Plugins\npqtplugin2.dll
FF - plugin: d:\programy\QuickTIme\Plugins\npqtplugin3.dll
FF - plugin: d:\programy\QuickTIme\Plugins\npqtplugin4.dll
FF - plugin: d:\programy\QuickTIme\Plugins\npqtplugin5.dll
FF - plugin: d:\programy\QuickTIme\Plugins\npqtplugin6.dll
FF - plugin: d:\programy\QuickTIme\Plugins\npqtplugin7.dll
FF - plugin: d:\programy\real player\Netscape6\nppl3260.dll
FF - plugin: d:\programy\real player\Netscape6\nprjplug.dll
FF - plugin: d:\programy\real player\Netscape6\nprpjplug.dll
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 200000
FF - user.js: content.notify.interval - 100000
FF - user.js: content.switch.threshold - 650000
FF - user.js: nglayout.initialpaint.delay - 300
FF - user.js: browser.sessionstore.resume_from_crash - false
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - ORPHANS REMOVED - - - -
BHO-{8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6} - c:\program files\SGPSA\SearchAssistant.dll
BHO-{F0626A63-410B-45E2-99A1-3F2475B2D695} - c:\program files\SGPSA\BHO.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-19 21:44
Windows 5.1.2600 Service Pack 4 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x86FDB1F8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf761bfc3
\Driver\ACPI -> ACPI.sys @ 0xf7476cb8
\Driver\atapi -> 0x86fdb1f8
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0004
ParseProcedure -> ntoskrnl.exe @ 0x8056f00e
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0004
ParseProcedure -> ntoskrnl.exe @ 0x8056f00e
NDIS: Realtek RTL8139 Family PCI Fast Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0xf7300bc3
PacketIndicateHandler -> NDIS.sys @ 0xf730cb21
SendHandler -> NDIS.sys @ 0xf7300d33
Warning: possible MBR rootkit infection !
user & kernel MBR OK
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1960408961-73586283-682003330-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-1960408961-73586283-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C66FA57D-0266-5A04-AB49-A8256C658F9F}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"abfmakgldgiobkfcenkkoncjcpoohjkiml"=hex:61,62,70,6d,6c,6e,62,6d,6c,61,67,6e,
63,69,70,6b,61,6f,65,6d,65,69,69,6f,6b,67,69,62,69,6f,6c,6e,6c,6d,00,77
"bbfmakgldgiobkfcenjkfagobogohfjhoeam"=hex:61,62,6d,6d,64,6f,66,64,6c,67,6b,6c,
6c,65,61,69,6f,6f,64,67,63,66,69,6a,67,6f,68,64,6c,70,68,65,6d,6c,00,77
[HKEY_USERS\S-1-5-21-1960408961-73586283-682003330-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:72,f7,86,67,84,fe,af,46,a1,b9,5d,18,88,32,ef,ca,8f,6d,19,8c,a0,d0,ab,
e8,9f,9a,10,0e,9e,8c,d6,cb,d7,e4,4b,75,3f,47,ac,50,7b,56,fb,c2,ea,de,c6,25,\
"??"=hex:39,bd,5a,39,e5,b7,ad,ba,3d,64,ca,36,89,78,e2,2f
[HKEY_USERS\S-1-5-21-1960408961-73586283-682003330-1003\Software\SecuROM\License information*]
"datasecu"=hex:be,75,c4,7e,3d,b1,80,76,bb,2f,5f,6a,94,2f,75,c2,72,d2,a4,1f,29,
00,70,46,c6,6b,69,89,ef,b6,9c,e0,82,9f,f3,b4,12,53,95,e8,9f,f3,70,0f,d3,29,\
"rkeysecu"=hex:9b,a5,e5,7b,6c,6f,14,86,bc,6c,97,d1,a0,ab,4f,86
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{469bb76b-d2d4-4723-8d9c-227b21a487cc}]
@Denied: (Full) (Everyone)
"Model"=dword:0000014d
"Therad"=dword:0000000f
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):58,f3,a7,45,21,67,e1,76,a3,e4,d5,f2,71,5e,90,5c,52,ee,54,29,04,
9e,30,3b,86,80,e4,93,af,61,d4,91,d3,25,24,e7,a8,85,d9,a2,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ř•€|˙˙˙˙•€|ů•A~*]
"AB141C35E9F4BF344B9FC010BB17F68A"=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(580)
c:\progra~1\COMMON~1\Stardock\mcpstub.dll
d:\programy\WindowBlinds\wbsrv.dll
- - - - - - - > 'lsass.exe'(636)
c:\windows\system32\imon.dll
c:\program files\Eset\pr_imon.dll
- - - - - - - > 'explorer.exe'(3132)
c:\windows\system32\msi.dll
d:\programy\WindowBlinds\tray.dll
c:\progra~1\COMMON~1\stardock\MCPCore.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\imon.dll
c:\program files\Eset\pr_imon.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\progra~1\COMMON~1\Stardock\SDMCP.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Eset\nod32krn.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
c:\windows\system32\wscntfy.exe
c:\program files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
.
**************************************************************************
.
Completion time: 2010-02-19 21:47:08 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-19 20:46
ComboFix2.txt 2009-06-26 16:05
ComboFix3.txt 2008-09-27 14:23
Pre-Run: 6 335 451 136 bytes free
Post-Run: 6 902 956 032 voľných bajtov
- - End Of File - - F80B68595B87C439438C29122876CA16
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-09-10 218032]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2009-12-20 2935480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2008-08-15 949376]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"nwiz"="nwiz.exe" [2009-03-27 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 53760]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-11 282624]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient]
2005-01-31 14:13 49152 ----a-w- c:\progra~1\COMMON~1\stardock\MCPStub.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
2008-03-16 13:31 229376 ----a-w- d:\programy\WindowBlinds\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\wbsys.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Skype"="d:\programy\Phone\Skype.exe" /nosplash /minimized
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
"DAEMON Tools Lite"="d:\programy\DAEMON Tools Lite\daemon.exe" -autorun
"DAEMON Tools Pro Agent"="d:\programy\DAEMON Tools Pro\DTProAgent.exe"
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
"µTorrent"=d:\programy\uTorrent\utorrent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
"NeroFilterCheck"=c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
"ISUSPM Startup"=c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" -start
"QuickTime Task"="d:\programy\QuickTIme\qttask.exe" -atboottime
"RivaTunerStartupDaemon"="d:\programy\RivaTuner v2.06\RivaTuner.exe" /S
"atwtusb"=atwtusb.exe beta
"PWRISOVM.EXE"=d:\programy\PowerISO\PWRISOVM.EXE
"PHIME2002ASync"=c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
"PHIME2002A"=c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"HP Software Update"=c:\program files\HP\HP Software Update\HPWuSchd2.exe
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe"
"iTunesHelper"="d:\programy\iTunes\iTunesHelper.exe"
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"FBSearch"=c:\program files\Search Guard Plus\SearchGuardPlus.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices-]
"Audio Sound Blaster System"=sabhost.exe
"Running Task Manager"=rtshost.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Programy\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"d:\\Programy\\Clear FTP 2006\\clearftp.exe"=
"d:\\Programy\\Fps Creator\\MyGames\\arenaskuska\\arenaskuska.exe"=
"d:\\Programy\\Fps Creator\\FPSC-Game.exe"=
"d:\\Programy\\eDisk klient\\eDisk klient.exe"=
"d:\\Programy\\Fps Creator\\MyGames\\arenaskuska2\\arenaskuska2.exe"=
"d:\\Programy\\Hamachi\\hamachi.exe"=
"d:\\Programy\\GoQ - NetRadio\\NetRadio.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"d:\\Programy\\HLSW\\hlsw.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"d:\\Programy\\QIP Infium\\infium.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"d:\\Programz\\Orbitdownloader\\orbitdm.exe"=
"d:\\Programz\\Orbitdownloader\\orbitnet.exe"=
"d:\\Programy\\LimeWire\\LimeWire.exe"=
"d:\\HRY\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"d:\\Programy\\Edisk\\eDisk klient\\eDisk klient.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"d:\\Programy\\real player\\realplay.exe"=
"d:\\Programy\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"d:\\Programy\\Plugin Manager\\skypePM.exe"=
"d:\\HRY\\THPS2\\THawk2_smaller.exe"=
"d:\\Programy\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"59137:TCP"= 59137:TCP:Pando Media Booster
"59137:UDP"= 59137:UDP:Pando Media Booster
"56096:TCP"= 56096:TCP:Pando Media Booster
"56096:UDP"= 56096:UDP:Pando Media Booster
R?2 wmcmgc;Windows Management Configuration;c:\windows\System32\svchost.exe -k netsvcs [4.8.2004 13:00 14336]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [4.10.2007 10:57 717296]
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [15.8.2008 12:13 15424]
R1 sdpiosys;sdpiosys;c:\windows\system32\drivers\SDPIOSYS.SYS [30.11.2004 12:10 161792]
R2 NVIDIA Performance Driver Service;NVIDIA Performance Driver Service;c:\program files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe [11.12.2008 6:08 3575808]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [18.12.2009 0:12 1044808]
R3 PAC207;PC Camera;c:\windows\system32\drivers\PFC027.SYS [29.5.2007 12:30 508160]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [14.10.2009 7:24 10064]
S1 aiptektp;Pen Pad;c:\windows\system32\drivers\aiptektp.sys [12.6.2008 13:44 22656]
S2 gupdate1ca56fca6d5367e;Služba Google Update (gupdate1ca56fca6d5367e);c:\program files\Google\Update\GoogleUpdate.exe [27.10.2009 12:57 133104]
S3 hamachi_oem;PlayLinc Adapter;c:\windows\system32\drivers\gan_adapter.sys [28.8.2006 22:54 10664]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 rak;rak;c:\windows\system32\rakion.sys [1.2.2010 15:00 60928]
S3 zlportio;zlportio;\??\d:\from torrent\ultrastardx-101a-full\zlportio.sys --> d:\from torrent\ultrastardx-101a-full\zlportio.sys [?]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2010-02-19 c:\windows\Tasks\Automatic troubleshooting.job
- c:\program files\TuneUp Utilities 2010\TuneUpSystemStatusCheck.exe [2009-12-17 23:18]
2010-02-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-27 11:57]
2010-02-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-27 11:57]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uDefault_Search_URL = hxxp://search13.net/
mStart Page = about:blank
uSearchAssistant = hxxp://search13.net/
uCustomizeSearch = hxxp://search13.net/
IE: &Compress Image Using Image Compressor 2008 - d:\programy\image compressor 08 pro ed\imcieex_compress.html
IE: &Download by Orbit - d:\programz\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - d:\programz\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - d:\programz\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - d:\programz\Orbitdownloader\orbitmxt.dll/202
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\windows\system32\imon.dll
Trusted Zone: ketsujin.com\fighterace
Trusted Zone: ketsujin.com\primary
Trusted Zone: ketsujin.com\update
Trusted Zone: ketsujin.com\www
Trusted Zone: stormofaces.com\www
DPF: {248F1F2D-E854-40AD-BB42-2E69EBC1CD8B} - hxxps://zona.t-com.sk/VianKampan2007/STWebDialer.cab
FF - ProfilePath - c:\documents and settings\Adrián Pyteľ\Application Data\Mozilla\Firefox\Profiles\xevyq5n9.default\
FF - prefs.js: browser.search.selectedEngine - Fast Browser Search
FF - prefs.js: browser.startup.homepage - hxxp://cs.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:cs:official
FF - component: d:\programz\Orbitdownloader\addons\OneClickYouTubeDownloader\components\GrabXpcom.dll
FF - plugin: c:\documents and settings\All Users\Application Data\id Software\QuakeLive\npquakezero.dll
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: d:\programy\iTunes\Mozilla Plugins\npitunes.dll
FF - plugin: d:\programy\QuickTIme\Plugins\npqtplugin.dll
FF - plugin: d:\programy\QuickTIme\Plugins\npqtplugin2.dll
FF - plugin: d:\programy\QuickTIme\Plugins\npqtplugin3.dll
FF - plugin: d:\programy\QuickTIme\Plugins\npqtplugin4.dll
FF - plugin: d:\programy\QuickTIme\Plugins\npqtplugin5.dll
FF - plugin: d:\programy\QuickTIme\Plugins\npqtplugin6.dll
FF - plugin: d:\programy\QuickTIme\Plugins\npqtplugin7.dll
FF - plugin: d:\programy\real player\Netscape6\nppl3260.dll
FF - plugin: d:\programy\real player\Netscape6\nprjplug.dll
FF - plugin: d:\programy\real player\Netscape6\nprpjplug.dll
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 200000
FF - user.js: content.notify.interval - 100000
FF - user.js: content.switch.threshold - 650000
FF - user.js: nglayout.initialpaint.delay - 300
FF - user.js: browser.sessionstore.resume_from_crash - false
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - ORPHANS REMOVED - - - -
BHO-{8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6} - c:\program files\SGPSA\SearchAssistant.dll
BHO-{F0626A63-410B-45E2-99A1-3F2475B2D695} - c:\program files\SGPSA\BHO.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-19 21:44
Windows 5.1.2600 Service Pack 4 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x86FDB1F8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf761bfc3
\Driver\ACPI -> ACPI.sys @ 0xf7476cb8
\Driver\atapi -> 0x86fdb1f8
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0004
ParseProcedure -> ntoskrnl.exe @ 0x8056f00e
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0004
ParseProcedure -> ntoskrnl.exe @ 0x8056f00e
NDIS: Realtek RTL8139 Family PCI Fast Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0xf7300bc3
PacketIndicateHandler -> NDIS.sys @ 0xf730cb21
SendHandler -> NDIS.sys @ 0xf7300d33
Warning: possible MBR rootkit infection !
user & kernel MBR OK
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1960408961-73586283-682003330-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-1960408961-73586283-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C66FA57D-0266-5A04-AB49-A8256C658F9F}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"abfmakgldgiobkfcenkkoncjcpoohjkiml"=hex:61,62,70,6d,6c,6e,62,6d,6c,61,67,6e,
63,69,70,6b,61,6f,65,6d,65,69,69,6f,6b,67,69,62,69,6f,6c,6e,6c,6d,00,77
"bbfmakgldgiobkfcenjkfagobogohfjhoeam"=hex:61,62,6d,6d,64,6f,66,64,6c,67,6b,6c,
6c,65,61,69,6f,6f,64,67,63,66,69,6a,67,6f,68,64,6c,70,68,65,6d,6c,00,77
[HKEY_USERS\S-1-5-21-1960408961-73586283-682003330-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:72,f7,86,67,84,fe,af,46,a1,b9,5d,18,88,32,ef,ca,8f,6d,19,8c,a0,d0,ab,
e8,9f,9a,10,0e,9e,8c,d6,cb,d7,e4,4b,75,3f,47,ac,50,7b,56,fb,c2,ea,de,c6,25,\
"??"=hex:39,bd,5a,39,e5,b7,ad,ba,3d,64,ca,36,89,78,e2,2f
[HKEY_USERS\S-1-5-21-1960408961-73586283-682003330-1003\Software\SecuROM\License information*]
"datasecu"=hex:be,75,c4,7e,3d,b1,80,76,bb,2f,5f,6a,94,2f,75,c2,72,d2,a4,1f,29,
00,70,46,c6,6b,69,89,ef,b6,9c,e0,82,9f,f3,b4,12,53,95,e8,9f,f3,70,0f,d3,29,\
"rkeysecu"=hex:9b,a5,e5,7b,6c,6f,14,86,bc,6c,97,d1,a0,ab,4f,86
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{469bb76b-d2d4-4723-8d9c-227b21a487cc}]
@Denied: (Full) (Everyone)
"Model"=dword:0000014d
"Therad"=dword:0000000f
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):58,f3,a7,45,21,67,e1,76,a3,e4,d5,f2,71,5e,90,5c,52,ee,54,29,04,
9e,30,3b,86,80,e4,93,af,61,d4,91,d3,25,24,e7,a8,85,d9,a2,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ř•€|˙˙˙˙•€|ů•A~*]
"AB141C35E9F4BF344B9FC010BB17F68A"=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(580)
c:\progra~1\COMMON~1\Stardock\mcpstub.dll
d:\programy\WindowBlinds\wbsrv.dll
- - - - - - - > 'lsass.exe'(636)
c:\windows\system32\imon.dll
c:\program files\Eset\pr_imon.dll
- - - - - - - > 'explorer.exe'(3132)
c:\windows\system32\msi.dll
d:\programy\WindowBlinds\tray.dll
c:\progra~1\COMMON~1\stardock\MCPCore.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\imon.dll
c:\program files\Eset\pr_imon.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\progra~1\COMMON~1\Stardock\SDMCP.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Eset\nod32krn.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
c:\windows\system32\wscntfy.exe
c:\program files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
.
**************************************************************************
.
Completion time: 2010-02-19 21:47:08 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-19 20:46
ComboFix2.txt 2009-06-26 16:05
ComboFix3.txt 2008-09-27 14:23
Pre-Run: 6 335 451 136 bytes free
Post-Run: 6 902 956 032 voľných bajtov
- - End Of File - - F80B68595B87C439438C29122876CA16
- Rudy
- Site Admin
- Příspěvky: 119399
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Problem s PC je pomaly
Několik položek bylo smazáno. Ještě proveďte kontrolu MBR: http://www2.gmer.net/mbr/mbr.exe a dejte log.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Problem s PC je pomaly
z mbr:
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
combofix:
ComboFix 10-02-18.09 - Adrián Pyteľ 20.02.2010 11:04:34.8.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.4.1250.421.1033.18.1023.505 [GMT 1:00]
Running from: c:\documents and settings\Adrián Pyteľ\Desktop\ComboFix.exe
AV: Eset NOD32 Antivirus 2.70 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2010-01-20 to 2010-02-20 )))))))))))))))))))))))))))))))
.
2010-02-20 09:45 . 2010-02-20 09:45 77312 ----a-w- C:\mbr.exe
2010-02-19 20:19 . 2010-02-19 20:17 388608 ----a-w- c:\windows\system32\CF11096.exe
2010-02-19 18:44 . 2010-02-19 18:44 781909 ----a-w- C:\RSIT.exe
2010-02-19 14:14 . 2007-03-18 19:37 65602 ----a-w- c:\windows\system32\cook3260.dll
2010-02-19 14:14 . 2002-12-10 01:20 102439 ----a-w- c:\windows\system32\sipr3260.dll
2010-02-19 14:14 . 2006-05-11 18:21 626688 ----a-w- c:\windows\system32\vp7vfw.dll
2010-02-19 14:14 . 2006-05-20 15:16 1184984 ----a-w- c:\windows\system32\wvc1dmod.dll
2010-02-18 15:19 . 2010-02-18 15:19 -------- d-----w- c:\documents and settings\All Users\Application Data\id Software
2010-02-12 10:42 . 2008-01-15 16:25 356352 ----a-w- c:\windows\system32\licence.dll
2010-02-01 14:00 . 2010-02-01 14:00 60928 ----a-w- c:\windows\system32\rakion.sys
2010-01-29 22:15 . 2010-01-29 22:15 -------- d-----w- c:\documents and settings\LocalService\Application Data\TuneUp Software
2010-01-28 09:29 . 2009-12-17 23:14 30536 ----a-w- c:\windows\system32\TURegOpt.exe
2010-01-28 09:29 . 2009-12-17 23:08 30024 ----a-w- c:\windows\system32\uxtuneup.dll
2010-01-28 09:28 . 2010-01-28 09:29 -------- d-----w- c:\program files\TuneUp Utilities 2010
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-19 20:12 . 2008-06-04 09:30 215104 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-02-19 19:09 . 2008-06-04 09:30 138576 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-02-19 19:02 . 2007-12-15 09:20 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-02-19 18:45 . 2009-06-24 12:04 -------- d-----w- c:\program files\trend micro
2010-02-19 14:14 . 2009-12-25 13:55 -------- d-----w- c:\program files\vso
2010-02-18 15:19 . 2008-10-24 15:38 2373712 -c--a-w- c:\windows\system32\pbsvc.exe
2010-02-02 15:13 . 2007-09-22 11:54 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-28 17:13 . 2008-09-01 14:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Ubisoft
2010-01-28 09:28 . 2007-09-22 12:06 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2010-01-26 16:22 . 2009-07-11 08:56 -------- d-----w- c:\program files\ICQ6.5
2010-01-23 14:29 . 2009-08-29 10:39 -------- d-----w- c:\documents and settings\All Users\Application Data\PMB Files
2010-01-22 15:48 . 2010-01-22 15:48 0 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\hpq5216.tmp
2010-01-22 15:43 . 2010-01-22 15:43 0 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\hpq5169.tmp
2010-01-22 15:43 . 2010-01-22 15:43 0 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\hpq5164.tmp
2010-01-07 14:47 . 2010-01-07 14:47 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-01-04 20:03 . 2010-01-04 20:03 -------- d-----w- c:\program files\Common Files\Skype
2010-01-04 20:03 . 2007-10-20 13:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-12-26 11:02 . 2009-12-26 11:02 -------- d-----w- c:\program files\Haali
2009-12-26 11:00 . 2009-12-26 11:00 -------- d-----w- c:\program files\CoreCodec
2009-12-26 10:52 . 2009-12-26 10:52 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-12-26 10:45 . 2009-03-01 12:48 -------- d-----w- c:\program files\XviD
2009-12-25 13:55 . 2007-12-20 11:16 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2009-12-17 13:29 . 2009-12-17 13:29 604488 ----a-w- c:\windows\system32\TUProgSt.exe
2009-12-11 18:00 . 2009-12-26 10:52 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2009-12-08 14:44 . 2008-08-10 15:55 304160 ----a-w- C:\PA207.DAT
2009-11-30 11:19 . 2009-11-30 11:19 625728 ----a-w- c:\documents and settings\All Users\Application Data\id Software\QuakeLive\npquakezero.dll
2009-11-30 11:17 . 2009-11-30 11:17 2373712 ----a-w- c:\documents and settings\All Users\Application Data\id Software\QuakeLive\pbsvc.exe
2009-09-25 16:41 . 2009-09-25 16:41 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-09-25 16:41 . 2009-09-25 16:41 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2005-06-29 01:46 . 2004-08-04 12:00 14744064 --sh--w- c:\windows\system32\icm64.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-09-10 218032]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2009-12-20 2935480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2008-08-15 949376]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"nwiz"="nwiz.exe" [2009-03-27 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 53760]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-11 282624]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient]
2005-01-31 14:13 49152 ----a-w- c:\progra~1\COMMON~1\stardock\MCPStub.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
2008-03-16 13:31 229376 ----a-w- d:\programy\WindowBlinds\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\wbsys.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Skype"="d:\programy\Phone\Skype.exe" /nosplash /minimized
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
"DAEMON Tools Lite"="d:\programy\DAEMON Tools Lite\daemon.exe" -autorun
"DAEMON Tools Pro Agent"="d:\programy\DAEMON Tools Pro\DTProAgent.exe"
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
"µTorrent"=d:\programy\uTorrent\utorrent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
"NeroFilterCheck"=c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
"ISUSPM Startup"=c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" -start
"QuickTime Task"="d:\programy\QuickTIme\qttask.exe" -atboottime
"RivaTunerStartupDaemon"="d:\programy\RivaTuner v2.06\RivaTuner.exe" /S
"atwtusb"=atwtusb.exe beta
"PWRISOVM.EXE"=d:\programy\PowerISO\PWRISOVM.EXE
"PHIME2002ASync"=c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
"PHIME2002A"=c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"HP Software Update"=c:\program files\HP\HP Software Update\HPWuSchd2.exe
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe"
"iTunesHelper"="d:\programy\iTunes\iTunesHelper.exe"
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"FBSearch"=c:\program files\Search Guard Plus\SearchGuardPlus.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices-]
"Audio Sound Blaster System"=sabhost.exe
"Running Task Manager"=rtshost.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Programy\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"d:\\Programy\\Clear FTP 2006\\clearftp.exe"=
"d:\\Programy\\Fps Creator\\MyGames\\arenaskuska\\arenaskuska.exe"=
"d:\\Programy\\Fps Creator\\FPSC-Game.exe"=
"d:\\Programy\\eDisk klient\\eDisk klient.exe"=
"d:\\Programy\\Fps Creator\\MyGames\\arenaskuska2\\arenaskuska2.exe"=
"d:\\Programy\\Hamachi\\hamachi.exe"=
"d:\\Programy\\GoQ - NetRadio\\NetRadio.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"d:\\Programy\\HLSW\\hlsw.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"d:\\Programy\\QIP Infium\\infium.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"d:\\Programz\\Orbitdownloader\\orbitdm.exe"=
"d:\\Programz\\Orbitdownloader\\orbitnet.exe"=
"d:\\Programy\\LimeWire\\LimeWire.exe"=
"d:\\HRY\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"d:\\Programy\\Edisk\\eDisk klient\\eDisk klient.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"d:\\Programy\\real player\\realplay.exe"=
"d:\\Programy\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"d:\\Programy\\Plugin Manager\\skypePM.exe"=
"d:\\HRY\\THPS2\\THawk2_smaller.exe"=
"d:\\Programy\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"59137:TCP"= 59137:TCP:Pando Media Booster
"59137:UDP"= 59137:UDP:Pando Media Booster
"56096:TCP"= 56096:TCP:Pando Media Booster
"56096:UDP"= 56096:UDP:Pando Media Booster
R?2 wmcmgc;Windows Management Configuration;c:\windows\System32\svchost.exe -k netsvcs [4.8.2004 13:00 14336]
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [15.8.2008 12:13 15424]
R1 sdpiosys;sdpiosys;c:\windows\system32\drivers\SDPIOSYS.SYS [30.11.2004 12:10 161792]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [18.12.2009 0:12 1044808]
R3 PAC207;PC Camera;c:\windows\system32\drivers\PFC027.SYS [29.5.2007 12:30 508160]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [14.10.2009 7:24 10064]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [4.10.2007 10:57 717296]
S1 aiptektp;Pen Pad;c:\windows\system32\drivers\aiptektp.sys [12.6.2008 13:44 22656]
S2 gupdate1ca56fca6d5367e;Služba Google Update (gupdate1ca56fca6d5367e);c:\program files\Google\Update\GoogleUpdate.exe [27.10.2009 12:57 133104]
S2 NVIDIA Performance Driver Service;NVIDIA Performance Driver Service;c:\program files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe [11.12.2008 6:08 3575808]
S3 hamachi_oem;PlayLinc Adapter;c:\windows\system32\drivers\gan_adapter.sys [28.8.2006 22:54 10664]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 rak;rak;c:\windows\system32\rakion.sys [1.2.2010 15:00 60928]
S3 zlportio;zlportio;\??\d:\from torrent\ultrastardx-101a-full\zlportio.sys --> d:\from torrent\ultrastardx-101a-full\zlportio.sys [?]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2010-02-20 c:\windows\Tasks\Automatic troubleshooting.job
- c:\program files\TuneUp Utilities 2010\TuneUpSystemStatusCheck.exe [2009-12-17 23:18]
2010-02-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-27 11:57]
2010-02-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-27 11:57]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uDefault_Search_URL = hxxp://search13.net/
mStart Page = about:blank
uSearchAssistant = hxxp://search13.net/
uCustomizeSearch = hxxp://search13.net/
IE: &Compress Image Using Image Compressor 2008 - d:\programy\image compressor 08 pro ed\imcieex_compress.html
IE: &Download by Orbit - d:\programz\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - d:\programz\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - d:\programz\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - d:\programz\Orbitdownloader\orbitmxt.dll/202
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\windows\system32\imon.dll
Trusted Zone: ketsujin.com\fighterace
Trusted Zone: ketsujin.com\primary
Trusted Zone: ketsujin.com\update
Trusted Zone: ketsujin.com\www
Trusted Zone: stormofaces.com\www
DPF: {248F1F2D-E854-40AD-BB42-2E69EBC1CD8B} - hxxps://zona.t-com.sk/VianKampan2007/STWebDialer.cab
FF - ProfilePath - c:\documents and settings\Adrián Pyteľ\Application Data\Mozilla\Firefox\Profiles\xevyq5n9.default\
FF - prefs.js: browser.search.selectedEngine - Fast Browser Search
FF - prefs.js: browser.startup.homepage - hxxp://cs.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:cs:official
FF - component: d:\programz\Orbitdownloader\addons\OneClickYouTubeDownloader\components\GrabXpcom.dll
FF - plugin: c:\documents and settings\All Users\Application Data\id Software\QuakeLive\npquakezero.dll
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: d:\programy\iTunes\Mozilla Plugins\npitunes.dll
FF - plugin: d:\programy\QuickTIme\Plugins\npqtplugin.dll
FF - plugin: d:\programy\QuickTIme\Plugins\npqtplugin2.dll
FF - plugin: d:\programy\QuickTIme\Plugins\npqtplugin3.dll
FF - plugin: d:\programy\QuickTIme\Plugins\npqtplugin4.dll
FF - plugin: d:\programy\QuickTIme\Plugins\npqtplugin5.dll
FF - plugin: d:\programy\QuickTIme\Plugins\npqtplugin6.dll
FF - plugin: d:\programy\QuickTIme\Plugins\npqtplugin7.dll
FF - plugin: d:\programy\real player\Netscape6\nppl3260.dll
FF - plugin: d:\programy\real player\Netscape6\nprjplug.dll
FF - plugin: d:\programy\real player\Netscape6\nprpjplug.dll
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 200000
FF - user.js: content.notify.interval - 100000
FF - user.js: content.switch.threshold - 650000
FF - user.js: nglayout.initialpaint.delay - 300
FF - user.js: browser.sessionstore.resume_from_crash - false
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-20 11:09
Windows 5.1.2600 Service Pack 4 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1960408961-73586283-682003330-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-1960408961-73586283-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C66FA57D-0266-5A04-AB49-A8256C658F9F}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"abfmakgldgiobkfcenkkoncjcpoohjkiml"=hex:61,62,70,6d,6c,6e,62,6d,6c,61,67,6e,
63,69,70,6b,61,6f,65,6d,65,69,69,6f,6b,67,69,62,69,6f,6c,6e,6c,6d,00,77
"bbfmakgldgiobkfcenjkfagobogohfjhoeam"=hex:61,62,6d,6d,64,6f,66,64,6c,67,6b,6c,
6c,65,61,69,6f,6f,64,67,63,66,69,6a,67,6f,68,64,6c,70,68,65,6d,6c,00,77
[HKEY_USERS\S-1-5-21-1960408961-73586283-682003330-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:72,f7,86,67,84,fe,af,46,a1,b9,5d,18,88,32,ef,ca,8f,6d,19,8c,a0,d0,ab,
e8,9f,9a,10,0e,9e,8c,d6,cb,d7,e4,4b,75,3f,47,ac,50,7b,56,fb,c2,ea,de,c6,25,\
"??"=hex:39,bd,5a,39,e5,b7,ad,ba,3d,64,ca,36,89,78,e2,2f
[HKEY_USERS\S-1-5-21-1960408961-73586283-682003330-1003\Software\SecuROM\License information*]
"datasecu"=hex:be,75,c4,7e,3d,b1,80,76,bb,2f,5f,6a,94,2f,75,c2,72,d2,a4,1f,29,
00,70,46,c6,6b,69,89,ef,b6,9c,e0,82,9f,f3,b4,12,53,95,e8,9f,f3,70,0f,d3,29,\
"rkeysecu"=hex:9b,a5,e5,7b,6c,6f,14,86,bc,6c,97,d1,a0,ab,4f,86
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{469bb76b-d2d4-4723-8d9c-227b21a487cc}]
@Denied: (Full) (Everyone)
"Model"=dword:0000014d
"Therad"=dword:0000000f
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):58,f3,a7,45,21,67,e1,76,a3,e4,d5,f2,71,5e,90,5c,52,ee,54,29,04,
9e,30,3b,86,80,e4,93,af,61,d4,91,d3,25,24,e7,a8,85,d9,a2,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ř•€|˙˙˙˙•€|ů•A~*]
"AB141C35E9F4BF344B9FC010BB17F68A"=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(552)
c:\progra~1\COMMON~1\Stardock\mcpstub.dll
d:\programy\WindowBlinds\wbsrv.dll
- - - - - - - > 'lsass.exe'(608)
c:\windows\system32\imon.dll
c:\program files\Eset\pr_imon.dll
.
Completion time: 2010-02-20 11:12:34
ComboFix-quarantined-files.txt 2010-02-20 10:12
ComboFix2.txt 2010-02-19 20:47
ComboFix3.txt 2009-06-26 16:05
ComboFix4.txt 2008-09-27 14:23
Pre-Run: 6 319 259 648 bytes free
Post-Run: 6 814 203 904 voľných bajtov
- - End Of File - - 67BC1B93B34D3226F2C5255B7F38CBA1
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
combofix:
ComboFix 10-02-18.09 - Adrián Pyteľ 20.02.2010 11:04:34.8.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.4.1250.421.1033.18.1023.505 [GMT 1:00]
Running from: c:\documents and settings\Adrián Pyteľ\Desktop\ComboFix.exe
AV: Eset NOD32 Antivirus 2.70 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2010-01-20 to 2010-02-20 )))))))))))))))))))))))))))))))
.
2010-02-20 09:45 . 2010-02-20 09:45 77312 ----a-w- C:\mbr.exe
2010-02-19 20:19 . 2010-02-19 20:17 388608 ----a-w- c:\windows\system32\CF11096.exe
2010-02-19 18:44 . 2010-02-19 18:44 781909 ----a-w- C:\RSIT.exe
2010-02-19 14:14 . 2007-03-18 19:37 65602 ----a-w- c:\windows\system32\cook3260.dll
2010-02-19 14:14 . 2002-12-10 01:20 102439 ----a-w- c:\windows\system32\sipr3260.dll
2010-02-19 14:14 . 2006-05-11 18:21 626688 ----a-w- c:\windows\system32\vp7vfw.dll
2010-02-19 14:14 . 2006-05-20 15:16 1184984 ----a-w- c:\windows\system32\wvc1dmod.dll
2010-02-18 15:19 . 2010-02-18 15:19 -------- d-----w- c:\documents and settings\All Users\Application Data\id Software
2010-02-12 10:42 . 2008-01-15 16:25 356352 ----a-w- c:\windows\system32\licence.dll
2010-02-01 14:00 . 2010-02-01 14:00 60928 ----a-w- c:\windows\system32\rakion.sys
2010-01-29 22:15 . 2010-01-29 22:15 -------- d-----w- c:\documents and settings\LocalService\Application Data\TuneUp Software
2010-01-28 09:29 . 2009-12-17 23:14 30536 ----a-w- c:\windows\system32\TURegOpt.exe
2010-01-28 09:29 . 2009-12-17 23:08 30024 ----a-w- c:\windows\system32\uxtuneup.dll
2010-01-28 09:28 . 2010-01-28 09:29 -------- d-----w- c:\program files\TuneUp Utilities 2010
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-19 20:12 . 2008-06-04 09:30 215104 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-02-19 19:09 . 2008-06-04 09:30 138576 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-02-19 19:02 . 2007-12-15 09:20 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-02-19 18:45 . 2009-06-24 12:04 -------- d-----w- c:\program files\trend micro
2010-02-19 14:14 . 2009-12-25 13:55 -------- d-----w- c:\program files\vso
2010-02-18 15:19 . 2008-10-24 15:38 2373712 -c--a-w- c:\windows\system32\pbsvc.exe
2010-02-02 15:13 . 2007-09-22 11:54 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-28 17:13 . 2008-09-01 14:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Ubisoft
2010-01-28 09:28 . 2007-09-22 12:06 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2010-01-26 16:22 . 2009-07-11 08:56 -------- d-----w- c:\program files\ICQ6.5
2010-01-23 14:29 . 2009-08-29 10:39 -------- d-----w- c:\documents and settings\All Users\Application Data\PMB Files
2010-01-22 15:48 . 2010-01-22 15:48 0 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\hpq5216.tmp
2010-01-22 15:43 . 2010-01-22 15:43 0 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\hpq5169.tmp
2010-01-22 15:43 . 2010-01-22 15:43 0 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\hpq5164.tmp
2010-01-07 14:47 . 2010-01-07 14:47 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-01-04 20:03 . 2010-01-04 20:03 -------- d-----w- c:\program files\Common Files\Skype
2010-01-04 20:03 . 2007-10-20 13:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-12-26 11:02 . 2009-12-26 11:02 -------- d-----w- c:\program files\Haali
2009-12-26 11:00 . 2009-12-26 11:00 -------- d-----w- c:\program files\CoreCodec
2009-12-26 10:52 . 2009-12-26 10:52 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-12-26 10:45 . 2009-03-01 12:48 -------- d-----w- c:\program files\XviD
2009-12-25 13:55 . 2007-12-20 11:16 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2009-12-17 13:29 . 2009-12-17 13:29 604488 ----a-w- c:\windows\system32\TUProgSt.exe
2009-12-11 18:00 . 2009-12-26 10:52 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2009-12-08 14:44 . 2008-08-10 15:55 304160 ----a-w- C:\PA207.DAT
2009-11-30 11:19 . 2009-11-30 11:19 625728 ----a-w- c:\documents and settings\All Users\Application Data\id Software\QuakeLive\npquakezero.dll
2009-11-30 11:17 . 2009-11-30 11:17 2373712 ----a-w- c:\documents and settings\All Users\Application Data\id Software\QuakeLive\pbsvc.exe
2009-09-25 16:41 . 2009-09-25 16:41 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-09-25 16:41 . 2009-09-25 16:41 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2005-06-29 01:46 . 2004-08-04 12:00 14744064 --sh--w- c:\windows\system32\icm64.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-09-10 218032]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2009-12-20 2935480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2008-08-15 949376]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"nwiz"="nwiz.exe" [2009-03-27 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 53760]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-11 282624]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient]
2005-01-31 14:13 49152 ----a-w- c:\progra~1\COMMON~1\stardock\MCPStub.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
2008-03-16 13:31 229376 ----a-w- d:\programy\WindowBlinds\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\wbsys.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Skype"="d:\programy\Phone\Skype.exe" /nosplash /minimized
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
"DAEMON Tools Lite"="d:\programy\DAEMON Tools Lite\daemon.exe" -autorun
"DAEMON Tools Pro Agent"="d:\programy\DAEMON Tools Pro\DTProAgent.exe"
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
"µTorrent"=d:\programy\uTorrent\utorrent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
"NeroFilterCheck"=c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
"ISUSPM Startup"=c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" -start
"QuickTime Task"="d:\programy\QuickTIme\qttask.exe" -atboottime
"RivaTunerStartupDaemon"="d:\programy\RivaTuner v2.06\RivaTuner.exe" /S
"atwtusb"=atwtusb.exe beta
"PWRISOVM.EXE"=d:\programy\PowerISO\PWRISOVM.EXE
"PHIME2002ASync"=c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
"PHIME2002A"=c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"HP Software Update"=c:\program files\HP\HP Software Update\HPWuSchd2.exe
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe"
"iTunesHelper"="d:\programy\iTunes\iTunesHelper.exe"
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"FBSearch"=c:\program files\Search Guard Plus\SearchGuardPlus.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices-]
"Audio Sound Blaster System"=sabhost.exe
"Running Task Manager"=rtshost.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Programy\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"d:\\Programy\\Clear FTP 2006\\clearftp.exe"=
"d:\\Programy\\Fps Creator\\MyGames\\arenaskuska\\arenaskuska.exe"=
"d:\\Programy\\Fps Creator\\FPSC-Game.exe"=
"d:\\Programy\\eDisk klient\\eDisk klient.exe"=
"d:\\Programy\\Fps Creator\\MyGames\\arenaskuska2\\arenaskuska2.exe"=
"d:\\Programy\\Hamachi\\hamachi.exe"=
"d:\\Programy\\GoQ - NetRadio\\NetRadio.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"d:\\Programy\\HLSW\\hlsw.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"d:\\Programy\\QIP Infium\\infium.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"d:\\Programz\\Orbitdownloader\\orbitdm.exe"=
"d:\\Programz\\Orbitdownloader\\orbitnet.exe"=
"d:\\Programy\\LimeWire\\LimeWire.exe"=
"d:\\HRY\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"d:\\Programy\\Edisk\\eDisk klient\\eDisk klient.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"d:\\Programy\\real player\\realplay.exe"=
"d:\\Programy\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"d:\\Programy\\Plugin Manager\\skypePM.exe"=
"d:\\HRY\\THPS2\\THawk2_smaller.exe"=
"d:\\Programy\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"59137:TCP"= 59137:TCP:Pando Media Booster
"59137:UDP"= 59137:UDP:Pando Media Booster
"56096:TCP"= 56096:TCP:Pando Media Booster
"56096:UDP"= 56096:UDP:Pando Media Booster
R?2 wmcmgc;Windows Management Configuration;c:\windows\System32\svchost.exe -k netsvcs [4.8.2004 13:00 14336]
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [15.8.2008 12:13 15424]
R1 sdpiosys;sdpiosys;c:\windows\system32\drivers\SDPIOSYS.SYS [30.11.2004 12:10 161792]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [18.12.2009 0:12 1044808]
R3 PAC207;PC Camera;c:\windows\system32\drivers\PFC027.SYS [29.5.2007 12:30 508160]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [14.10.2009 7:24 10064]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [4.10.2007 10:57 717296]
S1 aiptektp;Pen Pad;c:\windows\system32\drivers\aiptektp.sys [12.6.2008 13:44 22656]
S2 gupdate1ca56fca6d5367e;Služba Google Update (gupdate1ca56fca6d5367e);c:\program files\Google\Update\GoogleUpdate.exe [27.10.2009 12:57 133104]
S2 NVIDIA Performance Driver Service;NVIDIA Performance Driver Service;c:\program files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe [11.12.2008 6:08 3575808]
S3 hamachi_oem;PlayLinc Adapter;c:\windows\system32\drivers\gan_adapter.sys [28.8.2006 22:54 10664]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 rak;rak;c:\windows\system32\rakion.sys [1.2.2010 15:00 60928]
S3 zlportio;zlportio;\??\d:\from torrent\ultrastardx-101a-full\zlportio.sys --> d:\from torrent\ultrastardx-101a-full\zlportio.sys [?]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2010-02-20 c:\windows\Tasks\Automatic troubleshooting.job
- c:\program files\TuneUp Utilities 2010\TuneUpSystemStatusCheck.exe [2009-12-17 23:18]
2010-02-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-27 11:57]
2010-02-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-27 11:57]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uDefault_Search_URL = hxxp://search13.net/
mStart Page = about:blank
uSearchAssistant = hxxp://search13.net/
uCustomizeSearch = hxxp://search13.net/
IE: &Compress Image Using Image Compressor 2008 - d:\programy\image compressor 08 pro ed\imcieex_compress.html
IE: &Download by Orbit - d:\programz\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - d:\programz\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - d:\programz\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - d:\programz\Orbitdownloader\orbitmxt.dll/202
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\windows\system32\imon.dll
Trusted Zone: ketsujin.com\fighterace
Trusted Zone: ketsujin.com\primary
Trusted Zone: ketsujin.com\update
Trusted Zone: ketsujin.com\www
Trusted Zone: stormofaces.com\www
DPF: {248F1F2D-E854-40AD-BB42-2E69EBC1CD8B} - hxxps://zona.t-com.sk/VianKampan2007/STWebDialer.cab
FF - ProfilePath - c:\documents and settings\Adrián Pyteľ\Application Data\Mozilla\Firefox\Profiles\xevyq5n9.default\
FF - prefs.js: browser.search.selectedEngine - Fast Browser Search
FF - prefs.js: browser.startup.homepage - hxxp://cs.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:cs:official
FF - component: d:\programz\Orbitdownloader\addons\OneClickYouTubeDownloader\components\GrabXpcom.dll
FF - plugin: c:\documents and settings\All Users\Application Data\id Software\QuakeLive\npquakezero.dll
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: d:\programy\iTunes\Mozilla Plugins\npitunes.dll
FF - plugin: d:\programy\QuickTIme\Plugins\npqtplugin.dll
FF - plugin: d:\programy\QuickTIme\Plugins\npqtplugin2.dll
FF - plugin: d:\programy\QuickTIme\Plugins\npqtplugin3.dll
FF - plugin: d:\programy\QuickTIme\Plugins\npqtplugin4.dll
FF - plugin: d:\programy\QuickTIme\Plugins\npqtplugin5.dll
FF - plugin: d:\programy\QuickTIme\Plugins\npqtplugin6.dll
FF - plugin: d:\programy\QuickTIme\Plugins\npqtplugin7.dll
FF - plugin: d:\programy\real player\Netscape6\nppl3260.dll
FF - plugin: d:\programy\real player\Netscape6\nprjplug.dll
FF - plugin: d:\programy\real player\Netscape6\nprpjplug.dll
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 200000
FF - user.js: content.notify.interval - 100000
FF - user.js: content.switch.threshold - 650000
FF - user.js: nglayout.initialpaint.delay - 300
FF - user.js: browser.sessionstore.resume_from_crash - false
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-20 11:09
Windows 5.1.2600 Service Pack 4 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1960408961-73586283-682003330-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-1960408961-73586283-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C66FA57D-0266-5A04-AB49-A8256C658F9F}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"abfmakgldgiobkfcenkkoncjcpoohjkiml"=hex:61,62,70,6d,6c,6e,62,6d,6c,61,67,6e,
63,69,70,6b,61,6f,65,6d,65,69,69,6f,6b,67,69,62,69,6f,6c,6e,6c,6d,00,77
"bbfmakgldgiobkfcenjkfagobogohfjhoeam"=hex:61,62,6d,6d,64,6f,66,64,6c,67,6b,6c,
6c,65,61,69,6f,6f,64,67,63,66,69,6a,67,6f,68,64,6c,70,68,65,6d,6c,00,77
[HKEY_USERS\S-1-5-21-1960408961-73586283-682003330-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:72,f7,86,67,84,fe,af,46,a1,b9,5d,18,88,32,ef,ca,8f,6d,19,8c,a0,d0,ab,
e8,9f,9a,10,0e,9e,8c,d6,cb,d7,e4,4b,75,3f,47,ac,50,7b,56,fb,c2,ea,de,c6,25,\
"??"=hex:39,bd,5a,39,e5,b7,ad,ba,3d,64,ca,36,89,78,e2,2f
[HKEY_USERS\S-1-5-21-1960408961-73586283-682003330-1003\Software\SecuROM\License information*]
"datasecu"=hex:be,75,c4,7e,3d,b1,80,76,bb,2f,5f,6a,94,2f,75,c2,72,d2,a4,1f,29,
00,70,46,c6,6b,69,89,ef,b6,9c,e0,82,9f,f3,b4,12,53,95,e8,9f,f3,70,0f,d3,29,\
"rkeysecu"=hex:9b,a5,e5,7b,6c,6f,14,86,bc,6c,97,d1,a0,ab,4f,86
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{469bb76b-d2d4-4723-8d9c-227b21a487cc}]
@Denied: (Full) (Everyone)
"Model"=dword:0000014d
"Therad"=dword:0000000f
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):58,f3,a7,45,21,67,e1,76,a3,e4,d5,f2,71,5e,90,5c,52,ee,54,29,04,
9e,30,3b,86,80,e4,93,af,61,d4,91,d3,25,24,e7,a8,85,d9,a2,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ř•€|˙˙˙˙•€|ů•A~*]
"AB141C35E9F4BF344B9FC010BB17F68A"=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(552)
c:\progra~1\COMMON~1\Stardock\mcpstub.dll
d:\programy\WindowBlinds\wbsrv.dll
- - - - - - - > 'lsass.exe'(608)
c:\windows\system32\imon.dll
c:\program files\Eset\pr_imon.dll
.
Completion time: 2010-02-20 11:12:34
ComboFix-quarantined-files.txt 2010-02-20 10:12
ComboFix2.txt 2010-02-19 20:47
ComboFix3.txt 2009-06-26 16:05
ComboFix4.txt 2008-09-27 14:23
Pre-Run: 6 319 259 648 bytes free
Post-Run: 6 814 203 904 voľných bajtov
- - End Of File - - 67BC1B93B34D3226F2C5255B7F38CBA1
- Rudy
- Site Admin
- Příspěvky: 119399
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Problem s PC je pomaly
Otevřte poznámkový blok a zkopírujte do něj:

Tento soubor: c:\windows\system32\icm64.dll otestujte online na www.virustotal.com .
Uložte na plochu jako CFScript.txt. Pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkaz ze skriptu.Regnull::
[HKEY_USERS\S-1-5-21-1960408961-73586283-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C66FA57D-0266-5A04-AB49-A8256C658F9F}*]

Tento soubor: c:\windows\system32\icm64.dll otestujte online na www.virustotal.com .
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Problem s PC je pomaly
bohuzial ten subor icm64.dll sa tam uz nenachadza.. je tam iba icm32.dll
- Rudy
- Site Admin
- Příspěvky: 119399
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Problem s PC je pomaly
V tom případě je to vše v případě, že jste spustil znovu CF skriptem. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Problem s PC je pomaly
ďakujem, vyzerá to byť všetko v poriadku.
- Rudy
- Site Admin
- Příspěvky: 119399
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Problem s PC je pomaly
Nemáte zač!
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.