Preventivní kontrola logu HJT Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

TravisX90
Level 1
Level 1
Příspěvky: 54
Registrován: květen 10
Pohlaví: Muž
Stav:
Offline

Preventivní kontrola logu HJT

Příspěvekod TravisX90 » 03 dub 2011 19:26

Zdravím,

prosím o preventivní kontrolu logu. Dekuju :bigups:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:25:04, on 3.4.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal

Running processes:
G:\Install\Spybot - Search & Destroy\TeaTimer.exe
G:\Install\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\SONY\ISB Utility\ISBMgr.exe
C:\Program Files (x86)\SONY\PMB\PMBVolumeWatcher.exe
C:\Program Files (x86)\SONY\Marketing Tools\MarketingTools.exe
G:\Install\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files\Sony\VAIO Care\listener.exe
G:\Install\Trillian\trillian.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
G:\Install\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qip.ru
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - G:\Install\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
O4 - HKLM\..\Run: [MarketingTools] C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "G:\Install\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] G:\Install\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "G:\Install\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ICQ] "G:\Install\ICQ7.2\ICQ.exe" silent loginmode=4
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
O4 - Startup: Trillian.lnk = G:\Install\Trillian\trillian.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube Download - C:\Users\user\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\user\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - G:\Install\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - G:\Install\ICQ7.2\ICQ.exe
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - G:\Install\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - G:\Install\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files (x86)\Evernote\Evernote3.5\enbar.dll
O9 - Extra 'Tools' menuitem: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files (x86)\Evernote\Evernote3.5\enbar.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} (WRC Class) - http://trial.trymicrosoftoffice.com/tri ... /wrc32.ocx
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - (no file)
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - (no file)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PMBDeviceInfoProvider - Sony Corporation - C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: VAIO Care Performance Service (SampleCollector) - Sony Corporation - C:\Program Files\Sony\VAIO Care\VCPerfService.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - G:\Install\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: VAIO Media plus Content Importer (SOHCImp) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe
O23 - Service: VAIO Media plus Database Manager (SOHDBSvr) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe
O23 - Service: VAIO Media plus Digital Media Server (SOHDms) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe
O23 - Service: VAIO Media plus Device Searcher (SOHDs) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe
O23 - Service: VAIO Media plus Playlist Manager (SOHPlMgr) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files (x86)\SONY\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Power Management - Sony Corporation - C:\Program Files\Sony\VAIO Power Management\SPMService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: VAIO Content Folder Watcher (VCFw) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Content Metadata Intelligent Network Service Manager (VcmINSMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VSNService - Sony Corporation - C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: VUAgent - Sony Corporation - C:\Program Files\Sony\VAIO Update 5\VUAgent.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 16354 bytes

Reklama
Uživatelský avatar
Žbeky
Moderátor
Guru Level 13
Guru Level 13
Příspěvky: 22288
Registrován: květen 08
Bydliště: Vsetín - Pardubice
Pohlaví: Muž
Stav:
Offline

Re: Preventivní kontrola logu HJT

Příspěvekod Žbeky » 03 dub 2011 19:51

Vidím služby esetu, ale není spuštěný a ani se nemá spustit se startem WIN. Proč?

Odinstaluj:
Spybot S&D

V HJT fixni:

Kód: Vybrat vše

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - G:\Install\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "G:\Install\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] G:\Install\Spybot - Search & Destroy\TeaTimer.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - G:\Install\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - G:\Install\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} (WRC Class) - http://trial.trymicrosoftoffice.com/tri ... /wrc32.ocx
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - (no file)
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - (no file)

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.

Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Update Malwarebytes' Anti-Malware (Aktualizace Malwarebytes' Anti-Malware) a Launch Malwarebytes' Anti-Malware (Spustit aplikaci Malwarebytes' Anti-Malware), pokud jo tak klikni na tlačítko Finish
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Perform Quick Scan (Provést rychlý sken) a klikni na tlačítko Scan (Skenovat)
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Show Results
- pak zvol možnost Save Logfile a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.

HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra

TravisX90
Level 1
Level 1
Příspěvky: 54
Registrován: květen 10
Pohlaví: Muž
Stav:
Offline

Re: Preventivní kontrola logu HJT

Příspěvekod TravisX90 » 03 dub 2011 20:36

NOD32 se mi ukazuje jako zapnutý,
HJT jsem fixnul,
Spybot odinstalován,
ATF hotovo,

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Verze databáze: 6258

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

3.4.2011 20:36:41
mbam-log-2011-04-03 (20-36-41).txt

Typ kontroly: Rychlý test
Testované objekty: 165694
Uplynulý čas: 2 minut, 37 sekund

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 0
Infikované hodnoty v registru: 0
Infikované datové položky v registru: 0
Infikované složky: 0
Infikované soubory: 0

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované hodnoty v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)

Infikované soubory:
(Žádné škodlivé položky nebyly zjištěny)

Uživatelský avatar
Žbeky
Moderátor
Guru Level 13
Guru Level 13
Příspěvky: 22288
Registrován: květen 08
Bydliště: Vsetín - Pardubice
Pohlaví: Muž
Stav:
Offline

Re: Preventivní kontrola logu HJT

Příspěvekod Žbeky » 03 dub 2011 20:40

Vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.

HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra

TravisX90
Level 1
Level 1
Příspěvky: 54
Registrován: květen 10
Pohlaví: Muž
Stav:
Offline

Re: Preventivní kontrola logu HJT

Příspěvekod TravisX90 » 10 dub 2011 23:09

Omlouvám se za pozdní rekaci, ale musel jsem zařizovat nějaké věci.

Combo

ComboFix 11-04-10.01 - user 10.04.2011 22:54:10.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.420.1029.18.3950.2399 [GMT 2:00]
Spuštěný z: c:\users\user\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5}
SP: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\user\AppData\Roaming\.#
c:\users\user\AppData\Roaming\Desktopicon
c:\users\user\AppData\Roaming\Desktopicon\eBay.ico
c:\users\user\AppData\Roaming\Desktopicon\uninst.exe
c:\windows\SysWow64\Packet.dll
c:\windows\SysWow64\pthreadVC.dll
c:\windows\SysWow64\wpcap.dll
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_NPF
-------\Service_npf
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-03-10 do 2011-04-10 )))))))))))))))))))))))))))))))
.
.
2011-04-10 20:59 . 2011-04-10 20:59 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-04-10 17:27 . 2011-04-10 17:27 -------- d-----w- c:\users\user\AppData\Local\Apple
2011-04-10 14:56 . 2011-04-10 14:56 -------- d-----w- c:\users\user\AppData\Local\{47868CFE-F941-48A1-A542-32CE720A0A5D}
2011-04-10 09:07 . 2011-04-10 09:07 -------- d-----w- c:\users\user\AppData\Local\{B6BCE3EA-7E69-4BAD-95A4-FE4626C7E3DC}
2011-04-09 09:23 . 2011-04-09 09:24 -------- d-----w- c:\users\user\AppData\Local\{B8C1B409-BE99-45EE-BA73-1471BE9B8082}
2011-04-08 14:38 . 2011-03-15 05:17 8424784 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C87DD498-F4C4-41F4-973B-BE41CDDB6A41}\mpengine.dll
2011-04-08 02:54 . 2011-04-08 02:54 -------- d-----w- c:\users\user\AppData\Local\{DB7187BB-01DE-4688-BCC7-336687635CC7}
2011-04-08 02:51 . 2011-04-08 02:51 -------- d-----w- c:\windows\cs
2011-04-08 02:50 . 2010-08-11 05:19 3860992 ----a-w- c:\windows\system32\UIRibbon.dll
2011-04-08 02:50 . 2010-08-11 05:13 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2011-04-08 02:50 . 2010-08-11 04:44 2983424 ----a-w- c:\windows\SysWow64\UIRibbon.dll
2011-04-08 02:50 . 2010-08-11 04:35 1164800 ----a-w- c:\windows\SysWow64\UIRibbonRes.dll
2011-04-08 02:49 . 2011-04-08 02:49 469256 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\9848c07c1cbf5970f\InstallManager_WLE_WLE.exe
2011-04-08 02:49 . 2011-04-08 02:49 15712 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\956915661cbf5970e\MeshBetaRemover.exe
2011-04-07 21:41 . 2011-04-07 21:41 -------- d-----w- c:\users\user\AppData\Local\ArcSoft
2011-04-07 21:18 . 2011-04-07 21:18 -------- d-----w- c:\users\user\AppData\Roaming\DVDVideoSoft
2011-04-07 07:54 . 2011-04-07 07:54 -------- d-----w- c:\users\user\AppData\Local\{8B6352FE-8096-4532-8BB6-D977A15A9F55}
2011-04-06 15:08 . 2011-04-06 15:08 -------- d-----w- c:\users\user\AppData\Local\Apps
2011-04-06 07:19 . 2011-04-06 07:19 -------- d-----w- c:\users\user\AppData\Local\{CA54DBBB-67C6-459A-A9DC-B96A0E296E6E}
2011-04-04 09:58 . 2011-04-04 09:58 -------- d-----w- c:\users\user\AppData\Local\Adobe
2011-04-04 07:38 . 2011-04-04 07:38 -------- d-----w- c:\users\user\AppData\Local\{7151BF5F-736C-45D4-A2DD-68635B272DFC}
2011-04-03 18:54 . 2011-04-03 18:54 -------- d-----w- c:\users\user\AppData\Local\ATI
2011-04-03 18:53 . 2011-04-03 18:53 -------- d-----w- c:\users\user\AppData\Local\AOL
2011-04-03 18:00 . 2011-04-03 18:01 -------- d-----w- c:\users\user\AppData\Local\{294286C4-98F3-4E46-8A0B-443BC3D2765C}
2011-04-03 16:14 . 2011-04-03 16:14 388096 ----a-r- c:\users\user\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-04-03 07:12 . 2011-04-03 07:12 -------- d-----w- c:\users\user\AppData\Local\{22EDDD46-8635-4B21-8F61-7DA91C56F28B}
2011-04-02 16:42 . 2011-04-02 16:42 -------- d-----w- c:\users\user\AppData\Local\{A5127446-5C3E-40FE-BE08-D476D83306E2}
2011-04-01 16:55 . 2011-04-01 16:55 -------- d-----w- c:\users\user\AppData\Local\{F4843B76-7437-4D8B-8545-F5756452C41C}
2011-04-01 11:14 . 2011-04-01 11:14 -------- d-----w- c:\users\user\AppData\Local\{239AA0A7-7A4C-4A03-8F35-4745D1A57EA3}
2011-03-31 14:26 . 2011-03-31 14:26 -------- d-----w- c:\users\user\AppData\Local\{B82BB879-C14B-4709-88A5-1562C5A43674}
2011-03-23 22:55 . 2011-03-23 22:55 -------- d-----w- c:\windows\system32\SPReview
2011-03-23 22:54 . 2011-03-23 22:54 -------- d-----w- c:\windows\system32\EventProviders
2011-03-23 22:48 . 2011-02-19 06:37 1135104 ----a-w- c:\windows\system32\FntCache.dll
2011-03-23 22:48 . 2011-02-19 06:37 1540608 ----a-w- c:\windows\system32\DWrite.dll
2011-03-23 22:48 . 2011-02-19 06:36 902656 ----a-w- c:\windows\system32\d2d1.dll
2011-03-23 22:48 . 2011-02-19 05:32 1074176 ----a-w- c:\windows\SysWow64\DWrite.dll
2011-03-23 22:48 . 2011-02-19 05:32 739840 ----a-w- c:\windows\SysWow64\d2d1.dll
2011-03-20 16:04 . 2010-12-23 06:07 961024 ----a-w- c:\windows\system32\CPFilters.dll
2011-03-20 16:04 . 2010-12-23 06:07 723968 ----a-w- c:\windows\system32\EncDec.dll
2011-03-20 16:04 . 2010-12-23 05:28 642048 ----a-w- c:\windows\SysWow64\CPFilters.dll
2011-03-20 16:04 . 2010-12-23 06:07 1118720 ----a-w- c:\windows\system32\sbe.dll
2011-03-20 16:04 . 2010-12-23 06:02 259072 ----a-w- c:\windows\system32\mpg2splt.ax
2011-03-20 16:04 . 2010-12-23 05:28 850432 ----a-w- c:\windows\SysWow64\sbe.dll
2011-03-20 16:04 . 2010-12-23 05:28 534528 ----a-w- c:\windows\SysWow64\EncDec.dll
2011-03-20 16:04 . 2010-12-23 05:24 199680 ----a-w- c:\windows\SysWow64\mpg2splt.ax
2011-03-20 16:04 . 2010-12-18 06:12 3138048 ----a-w- c:\windows\system32\mstscax.dll
2011-03-20 16:04 . 2010-12-18 05:30 2690560 ----a-w- c:\windows\SysWow64\mstscax.dll
2011-03-20 16:04 . 2010-12-18 05:26 1034240 ----a-w- c:\windows\SysWow64\mstsc.exe
2011-03-20 16:04 . 2010-12-18 06:08 1097216 ----a-w- c:\windows\system32\mstsc.exe
2011-03-12 10:28 . 2011-03-12 10:28 103864 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-21 10:35 . 2010-06-24 10:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-02-02 20:40 . 2010-06-14 16:32 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-02-02 17:11 . 2010-06-14 20:00 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-01-26 06:53 . 2011-02-09 08:11 982912 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-01-26 06:53 . 2011-02-09 08:11 265088 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2011-01-26 06:31 . 2011-02-09 08:11 144384 ----a-w- c:\windows\system32\cdd.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="g:\install\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"msnmsgr"="c:\program files (x86)\Windows Live\Messenger\msnmsgr.exe" [2010-11-10 4240760]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"ICQ"="g:\install\ICQ7.2\ICQ.exe" [2011-01-05 133432]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2009-11-20 284696]
"ISBMgr.exe"="c:\program files (x86)\Sony\ISB Utility\ISBMgr.exe" [2009-08-26 320880]
"PMBVolumeWatcher"="c:\program files (x86)\Sony\PMB\PMBVolumeWatcher.exe" [2010-01-21 597792]
"MarketingTools"="c:\program files (x86)\Sony\Marketing Tools\MarketingTools.exe" [2010-01-13 26624]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-03-17 421888]
"iTunesHelper"="g:\install\iTunesHelper.exe" [2010-07-21 141608]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-09-20 102400]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
.
c:\users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.2.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-2-16 384512]
Trillian.lnk - g:\install\Trillian\trillian.exe [2011-2-15 2068832]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-9-4 1081632]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2009-12-01 22:03 98304 ------w- c:\windows\System32\VESWinlogon.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-13 133104]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~2\mcafee\SITEAD~1\mcsacore.exe [x]
R3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [x]
R3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
R3 SOHCImp;VAIO Media plus Content Importer;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe [2009-10-15 120104]
R3 SOHDBSvr;VAIO Media plus Database Manager;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [2009-10-15 70952]
R3 SOHDms;VAIO Media plus Digital Media Server;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe [2009-10-15 427304]
R3 SOHDs;VAIO Media plus Device Searcher;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe [2009-10-15 75048]
R3 SOHPlMgr;VAIO Media plus Playlist Manager;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [2009-10-15 91432]
R3 TVICHW64;TVICHW64;c:\windows\system32\DRIVERS\TVICHW64.SYS [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe [2010-02-19 115568]
R3 VUAgent;VUAgent;c:\program files\Sony\VAIO Update 5\VUAgent.exe [2010-04-09 1223024]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2010-04-07 810120]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-11-20 13336]
S2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe [2009-10-24 360224]
S2 rimspci;rimspci;c:\windows\system32\drivers\rimssne64.sys [x]
S2 risdsnpe;risdsnpe;c:\windows\system32\drivers\risdsne64.sys [x]
S2 SampleCollector;VAIO Care Performance Service;c:\program files\Sony\VAIO Care\VCPerfService.exe [2010-08-12 257936]
S2 uCamMonitor;CamMonitor;c:\program files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [2008-09-18 104960]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-12-14 2320920]
S2 VCFw;VAIO Content Folder Watcher;c:\program files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [2009-09-14 642416]
S2 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2010-02-19 529776]
S2 VcmINSMgr;VAIO Content Metadata Intelligent Network Service Manager;c:\program files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe [2010-02-19 386416]
S2 VSNService;VSNService;c:\program files\Sony\VAIO Smart Network\VSNService.exe [2010-08-11 845312]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\DRIVERS\ArcSoftKsUFilter.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\drivers\HECIx64.sys [x]
S3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\drivers\SFEP.sys [x]
S3 VAIO Power Management;VAIO Power Management;c:\program files\Sony\VAIO Power Management\SPMService.exe [2009-11-30 571248]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2011-04-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-13 14:30]
.
2011-04-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-13 14:30]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF28384.cfxxe" [X]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-12-16 9636896]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-01-13 171520]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-04-07 2839840]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\users\user\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\users\user\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} - hxxp://trial.trymicrosoftoffice.com/tri ... /wrc32.ocx
FF - ProfilePath - c:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ceduj8wc.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - g:\install\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - g:\install\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - g:\install\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - g:\install\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - g:\install\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - g:\install\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: DVDVideoSoft Menu: {ACAA314B-EEBA-48e4-AD47-84E31C44796C} - %profile%\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
FF - Ext: DVDVideoSoftTB Toolbar: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - %profile%\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
SafeBoot-mcmscsvc
SafeBoot-MCODS
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-Apoint - %ProgramFiles%\Apoint\Apoint.exe
AddRemove-eBay Icon - c:\users\user\AppData\Roaming\Desktopicon\uninst.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SampleCollector]
"ImagePath"="\"c:\program files\Sony\VAIO Care\VCPerfService.exe\" \"/service\" \"/sstates\" \"/sampleinterval=5000\" \"/procinterval=5\" \"/dllinterval=120\" \"/counter=\Processor(_Total)\% Processor Time:1/counter=\PhysicalDisk(_Total)\Disk Bytes/sec:1\" \"/counter=\Network Interface(*)\Bytes Total/sec:1\" \"/expandcounter=\Processor Information(*)\Processor Frequency:1\" \"/expandcounter=\Processor(*)\% Idle Time:1\" \"/expandcounter=\Processor(*)\% C1 Time:1\" \"/expandcounter=\Processor(*)\% C2 Time:1\" \"/expandcounter=\Processor(*)\% C3 Time:1\" \"/expandcounter=\Processor(*)\% Processor Time:1\" \"/directory=inteldata\""
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-2835324808-1647480109-3611849097-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-2835324808-1647480109-3611849097-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_USERS\S-1-5-21-2835324808-1647480109-3611849097-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:28,37,c0,8a,95,9d,c5,61,37,af,c8,7b,11,86,a9,36,cc,8b,58,45,76,aa,6a,
e5,ca,7c,c1,c7,25,ef,77,54,b4,38,bd,0e,de,6f,6e,f6,a9,9d,6b,14,34,6a,ca,fb,\
"??"=hex:62,bc,fc,43,8b,ca,7a,13,7a,1e,59,23,89,7c,e0,eb
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\SONY\VAIO Event Service\VESMgr.exe
c:\windows\SysWOW64\DllHost.exe
c:\program files (x86)\SONY\VAIO Event Service\VESMgrSub.exe
c:\program files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
c:\program files\Sony\VAIO Care\VCSpt.exe
c:\program files (x86)\OpenOffice.org 3\program\soffice.exe
c:\program files (x86)\OpenOffice.org 3\program\soffice.bin
c:\program files\Sony\VAIO Care\listener.exe
.
**************************************************************************
.
Celkový čas: 2011-04-10 23:06:57 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-04-10 21:06
.
Před spuštěním: Volných bajtů: 15 822 823 424
Po spuštění: Volných bajtů: 15 368 728 576
.
- - End Of File - - 46A4F06EA658E01293C999742A731AD0

Uživatelský avatar
Žbeky
Moderátor
Guru Level 13
Guru Level 13
Příspěvky: 22288
Registrován: květen 08
Bydliště: Vsetín - Pardubice
Pohlaví: Muž
Stav:
Offline

Re: Preventivní kontrola logu HJT

Příspěvekod Žbeky » 11 dub 2011 12:31

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE

Kód: Vybrat vše

KillAll::

DirLook::
c:\users\user\AppData\Local\{47868CFE-F941-48A1-A542-32CE720A0A5D}
c:\users\user\AppData\Local\{B6BCE3EA-7E69-4BAD-95A4-FE4626C7E3DC}
c:\users\user\AppData\Local\{B8C1B409-BE99-45EE-BA73-1471BE9B8082}
c:\users\user\AppData\Local\{DB7187BB-01DE-4688-BCC7-336687635CC7}
c:\users\user\AppData\Local\{8B6352FE-8096-4532-8BB6-D977A15A9F55}
c:\users\user\AppData\Local\{CA54DBBB-67C6-459A-A9DC-B96A0E296E6E}
c:\users\user\AppData\Local\{7151BF5F-736C-45D4-A2DD-68635B272DFC}
c:\users\user\AppData\Local\{294286C4-98F3-4E46-8A0B-443BC3D2765C}
c:\users\user\AppData\Local\{22EDDD46-8635-4B21-8F61-7DA91C56F28B}
c:\users\user\AppData\Local\{A5127446-5C3E-40FE-BE08-D476D83306E2}
c:\users\user\AppData\Local\{F4843B76-7437-4D8B-8545-F5756452C41C}
c:\users\user\AppData\Local\{239AA0A7-7A4C-4A03-8F35-4745D1A57EA3}
c:\users\user\AppData\Local\{B82BB879-C14B-4709-88A5-1562C5A43674}

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"=-
"ConsentPromptBehaviorUser"=-
"EnableUIADesktopToggle"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=-

Driver::
McAfee SiteAdvisor Service

Folder::
c:\progra~2\mcafee

File::
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

Firefox::
FF - ProfilePath - c:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ceduj8wc.default\
FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query=

RegLock::
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.

HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra

TravisX90
Level 1
Level 1
Příspěvky: 54
Registrován: květen 10
Pohlaví: Muž
Stav:
Offline

Re: Preventivní kontrola logu HJT

Příspěvekod TravisX90 » 12 dub 2011 15:22

ComboFix 11-04-10.01 - user 12.04.2011 15:07:22.2.4 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.420.1029.18.3950.2506 [GMT 2:00]
Spuštěný z: c:\users\user\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\user\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5}
SP: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\progra~2\mcafee
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_McAfee SiteAdvisor Service
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-03-12 do 2011-04-12 )))))))))))))))))))))))))))))))
.
.
2011-04-12 13:16 . 2011-04-12 13:16 -------- d-----w- c:\users\user\AppData\Local\{E72B3324-0897-42E8-9443-EA9D73ABBDD1}
2011-04-12 13:13 . 2011-04-12 13:13 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-04-11 08:32 . 2011-04-11 08:33 -------- d-----w- c:\users\user\AppData\Local\{20DC730D-4D02-4E2D-883F-13C64947662A}
2011-04-10 17:27 . 2011-04-10 17:27 -------- d-----w- c:\users\user\AppData\Local\Apple
2011-04-10 14:56 . 2011-04-10 14:56 -------- d-----w- c:\users\user\AppData\Local\{47868CFE-F941-48A1-A542-32CE720A0A5D}
2011-04-10 09:07 . 2011-04-10 09:07 -------- d-----w- c:\users\user\AppData\Local\{B6BCE3EA-7E69-4BAD-95A4-FE4626C7E3DC}
2011-04-09 09:23 . 2011-04-09 09:24 -------- d-----w- c:\users\user\AppData\Local\{B8C1B409-BE99-45EE-BA73-1471BE9B8082}
2011-04-08 14:38 . 2011-03-15 05:17 8424784 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C87DD498-F4C4-41F4-973B-BE41CDDB6A41}\mpengine.dll
2011-04-08 02:54 . 2011-04-08 02:54 -------- d-----w- c:\users\user\AppData\Local\{DB7187BB-01DE-4688-BCC7-336687635CC7}
2011-04-08 02:51 . 2011-04-08 02:51 -------- d-----w- c:\windows\cs
2011-04-08 02:50 . 2010-08-11 05:19 3860992 ----a-w- c:\windows\system32\UIRibbon.dll
2011-04-08 02:50 . 2010-08-11 05:13 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2011-04-08 02:50 . 2010-08-11 04:44 2983424 ----a-w- c:\windows\SysWow64\UIRibbon.dll
2011-04-08 02:50 . 2010-08-11 04:35 1164800 ----a-w- c:\windows\SysWow64\UIRibbonRes.dll
2011-04-08 02:49 . 2011-04-08 02:49 469256 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\9848c07c1cbf5970f\InstallManager_WLE_WLE.exe
2011-04-08 02:49 . 2011-04-08 02:49 15712 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\956915661cbf5970e\MeshBetaRemover.exe
2011-04-07 21:41 . 2011-04-07 21:41 -------- d-----w- c:\users\user\AppData\Local\ArcSoft
2011-04-07 21:18 . 2011-04-07 21:18 -------- d-----w- c:\users\user\AppData\Roaming\DVDVideoSoft
2011-04-07 07:54 . 2011-04-07 07:54 -------- d-----w- c:\users\user\AppData\Local\{8B6352FE-8096-4532-8BB6-D977A15A9F55}
2011-04-06 15:08 . 2011-04-06 15:08 -------- d-----w- c:\users\user\AppData\Local\Apps
2011-04-06 07:19 . 2011-04-06 07:19 -------- d-----w- c:\users\user\AppData\Local\{CA54DBBB-67C6-459A-A9DC-B96A0E296E6E}
2011-04-04 09:58 . 2011-04-04 09:58 -------- d-----w- c:\users\user\AppData\Local\Adobe
2011-04-04 07:38 . 2011-04-04 07:38 -------- d-----w- c:\users\user\AppData\Local\{7151BF5F-736C-45D4-A2DD-68635B272DFC}
2011-04-03 18:54 . 2011-04-03 18:54 -------- d-----w- c:\users\user\AppData\Local\ATI
2011-04-03 18:53 . 2011-04-03 18:53 -------- d-----w- c:\users\user\AppData\Local\AOL
2011-04-03 18:00 . 2011-04-03 18:01 -------- d-----w- c:\users\user\AppData\Local\{294286C4-98F3-4E46-8A0B-443BC3D2765C}
2011-04-03 16:14 . 2011-04-03 16:14 388096 ----a-r- c:\users\user\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-04-03 07:12 . 2011-04-03 07:12 -------- d-----w- c:\users\user\AppData\Local\{22EDDD46-8635-4B21-8F61-7DA91C56F28B}
2011-04-02 16:42 . 2011-04-02 16:42 -------- d-----w- c:\users\user\AppData\Local\{A5127446-5C3E-40FE-BE08-D476D83306E2}
2011-04-01 16:55 . 2011-04-01 16:55 -------- d-----w- c:\users\user\AppData\Local\{F4843B76-7437-4D8B-8545-F5756452C41C}
2011-04-01 11:14 . 2011-04-01 11:14 -------- d-----w- c:\users\user\AppData\Local\{239AA0A7-7A4C-4A03-8F35-4745D1A57EA3}
2011-03-31 14:26 . 2011-03-31 14:26 -------- d-----w- c:\users\user\AppData\Local\{B82BB879-C14B-4709-88A5-1562C5A43674}
2011-03-23 22:55 . 2011-03-23 22:55 -------- d-----w- c:\windows\system32\SPReview
2011-03-23 22:54 . 2011-03-23 22:54 -------- d-----w- c:\windows\system32\EventProviders
2011-03-23 22:48 . 2011-02-19 06:37 1135104 ----a-w- c:\windows\system32\FntCache.dll
2011-03-23 22:48 . 2011-02-19 06:37 1540608 ----a-w- c:\windows\system32\DWrite.dll
2011-03-23 22:48 . 2011-02-19 06:36 902656 ----a-w- c:\windows\system32\d2d1.dll
2011-03-23 22:48 . 2011-02-19 05:32 1074176 ----a-w- c:\windows\SysWow64\DWrite.dll
2011-03-23 22:48 . 2011-02-19 05:32 739840 ----a-w- c:\windows\SysWow64\d2d1.dll
2011-03-20 16:04 . 2010-12-23 06:07 961024 ----a-w- c:\windows\system32\CPFilters.dll
2011-03-20 16:04 . 2010-12-23 06:07 723968 ----a-w- c:\windows\system32\EncDec.dll
2011-03-20 16:04 . 2010-12-23 05:28 642048 ----a-w- c:\windows\SysWow64\CPFilters.dll
2011-03-20 16:04 . 2010-12-23 06:07 1118720 ----a-w- c:\windows\system32\sbe.dll
2011-03-20 16:04 . 2010-12-23 06:02 259072 ----a-w- c:\windows\system32\mpg2splt.ax
2011-03-20 16:04 . 2010-12-23 05:28 850432 ----a-w- c:\windows\SysWow64\sbe.dll
2011-03-20 16:04 . 2010-12-23 05:28 534528 ----a-w- c:\windows\SysWow64\EncDec.dll
2011-03-20 16:04 . 2010-12-23 05:24 199680 ----a-w- c:\windows\SysWow64\mpg2splt.ax
2011-03-20 16:04 . 2010-12-18 06:12 3138048 ----a-w- c:\windows\system32\mstscax.dll
2011-03-20 16:04 . 2010-12-18 05:30 2690560 ----a-w- c:\windows\SysWow64\mstscax.dll
2011-03-20 16:04 . 2010-12-18 05:26 1034240 ----a-w- c:\windows\SysWow64\mstsc.exe
2011-03-20 16:04 . 2010-12-18 06:08 1097216 ----a-w- c:\windows\system32\mstsc.exe
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-21 10:35 . 2010-06-24 10:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-02-02 20:40 . 2010-06-14 16:32 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-02-02 17:11 . 2010-06-14 20:00 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-01-26 06:53 . 2011-02-09 08:11 982912 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-01-26 06:53 . 2011-02-09 08:11 265088 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2011-01-26 06:31 . 2011-02-09 08:11 144384 ----a-w- c:\windows\system32\cdd.dll
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\users\user\AppData\Local\{22EDDD46-8635-4B21-8F61-7DA91C56F28B} ----
.
.
---- Directory of c:\users\user\AppData\Local\{239AA0A7-7A4C-4A03-8F35-4745D1A57EA3} ----
.
.
---- Directory of c:\users\user\AppData\Local\{294286C4-98F3-4E46-8A0B-443BC3D2765C} ----
.
.
---- Directory of c:\users\user\AppData\Local\{47868CFE-F941-48A1-A542-32CE720A0A5D} ----
.
.
---- Directory of c:\users\user\AppData\Local\{7151BF5F-736C-45D4-A2DD-68635B272DFC} ----
.
.
---- Directory of c:\users\user\AppData\Local\{8B6352FE-8096-4532-8BB6-D977A15A9F55} ----
.
.
---- Directory of c:\users\user\AppData\Local\{A5127446-5C3E-40FE-BE08-D476D83306E2} ----
.
.
---- Directory of c:\users\user\AppData\Local\{B6BCE3EA-7E69-4BAD-95A4-FE4626C7E3DC} ----
.
.
---- Directory of c:\users\user\AppData\Local\{B82BB879-C14B-4709-88A5-1562C5A43674} ----
.
.
---- Directory of c:\users\user\AppData\Local\{B8C1B409-BE99-45EE-BA73-1471BE9B8082} ----
.
.
---- Directory of c:\users\user\AppData\Local\{CA54DBBB-67C6-459A-A9DC-B96A0E296E6E} ----
.
.
---- Directory of c:\users\user\AppData\Local\{DB7187BB-01DE-4688-BCC7-336687635CC7} ----
.
.
---- Directory of c:\users\user\AppData\Local\{F4843B76-7437-4D8B-8545-F5756452C41C} ----
.
.
.
((((((((((((((((((((((((((((( SnapShot@2011-04-10_21.01.31 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-14 04:54 . 2011-04-12 13:14 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2011-04-10 21:00 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2011-04-10 21:00 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-04-12 13:14 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-04-10 21:00 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-04-12 13:14 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-12-26 00:54 . 2011-04-12 11:38 58146 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
- 2009-07-14 05:10 . 2011-04-10 14:56 33322 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-04-12 11:38 33322 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2010-06-09 12:25 . 2011-04-12 11:38 10484 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2835324808-1647480109-3611849097-1000_UserData.bin
+ 2010-01-13 14:29 . 2011-04-12 13:15 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-01-13 14:29 . 2011-04-10 21:01 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2011-04-12 13:15 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2011-04-10 21:01 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-06-13 21:04 . 2011-04-12 13:13 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-06-13 21:04 . 2011-04-10 20:11 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-06-13 21:04 . 2011-04-12 13:13 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-06-13 21:04 . 2011-04-10 20:11 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-04-12 13:14 . 2011-04-12 13:14 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-04-10 21:00 . 2011-04-10 21:00 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-04-12 13:14 . 2011-04-12 13:14 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-04-10 21:00 . 2011-04-10 21:00 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-14 05:12 . 2011-04-11 08:38 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2009-07-14 05:12 . 2011-04-10 15:02 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2010-01-13 14:29 . 2011-04-12 13:15 196608 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-01-13 14:29 . 2011-04-10 21:01 196608 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 05:01 . 2011-04-12 13:13 468380 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2011-04-10 20:59 468380 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2010-06-09 13:42 . 2011-04-10 20:59 824596 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2835324808-1647480109-3611849097-1000-8192.dat
+ 2010-06-09 13:42 . 2011-04-12 13:13 824596 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2835324808-1647480109-3611849097-1000-8192.dat
- 2009-07-14 02:34 . 2011-04-10 16:40 10223616 c:\windows\system32\SMI\Store\Machine\schema.dat
+ 2009-07-14 02:34 . 2011-04-12 11:49 10223616 c:\windows\system32\SMI\Store\Machine\schema.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="g:\install\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"msnmsgr"="c:\program files (x86)\Windows Live\Messenger\msnmsgr.exe" [2010-11-10 4240760]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"ICQ"="g:\install\ICQ7.2\ICQ.exe" [2011-01-05 133432]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2009-11-20 284696]
"ISBMgr.exe"="c:\program files (x86)\Sony\ISB Utility\ISBMgr.exe" [2009-08-26 320880]
"PMBVolumeWatcher"="c:\program files (x86)\Sony\PMB\PMBVolumeWatcher.exe" [2010-01-21 597792]
"MarketingTools"="c:\program files (x86)\Sony\Marketing Tools\MarketingTools.exe" [2010-01-13 26624]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-03-17 421888]
"iTunesHelper"="g:\install\iTunesHelper.exe" [2010-07-21 141608]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-09-20 102400]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
.
c:\users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.2.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-2-16 384512]
Trillian.lnk - g:\install\Trillian\trillian.exe [2011-2-15 2068832]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-9-4 1081632]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2009-12-01 22:03 98304 ------w- c:\windows\System32\VESWinlogon.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-13 133104]
R3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [x]
R3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
R3 SOHCImp;VAIO Media plus Content Importer;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe [2009-10-15 120104]
R3 SOHDBSvr;VAIO Media plus Database Manager;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [2009-10-15 70952]
R3 SOHDms;VAIO Media plus Digital Media Server;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe [2009-10-15 427304]
R3 SOHDs;VAIO Media plus Device Searcher;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe [2009-10-15 75048]
R3 SOHPlMgr;VAIO Media plus Playlist Manager;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [2009-10-15 91432]
R3 TVICHW64;TVICHW64;c:\windows\system32\DRIVERS\TVICHW64.SYS [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe [2010-02-19 115568]
R3 VUAgent;VUAgent;c:\program files\Sony\VAIO Update 5\VUAgent.exe [2010-04-09 1223024]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2010-04-07 810120]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-11-20 13336]
S2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe [2009-10-24 360224]
S2 rimspci;rimspci;c:\windows\system32\drivers\rimssne64.sys [x]
S2 risdsnpe;risdsnpe;c:\windows\system32\drivers\risdsne64.sys [x]
S2 SampleCollector;VAIO Care Performance Service;c:\program files\Sony\VAIO Care\VCPerfService.exe [2010-08-12 257936]
S2 uCamMonitor;CamMonitor;c:\program files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [2008-09-18 104960]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-12-14 2320920]
S2 VCFw;VAIO Content Folder Watcher;c:\program files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [2009-09-14 642416]
S2 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2010-02-19 529776]
S2 VcmINSMgr;VAIO Content Metadata Intelligent Network Service Manager;c:\program files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe [2010-02-19 386416]
S2 VSNService;VSNService;c:\program files\Sony\VAIO Smart Network\VSNService.exe [2010-08-11 845312]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\DRIVERS\ArcSoftKsUFilter.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\drivers\HECIx64.sys [x]
S3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\drivers\SFEP.sys [x]
S3 VAIO Power Management;VAIO Power Management;c:\program files\Sony\VAIO Power Management\SPMService.exe [2009-11-30 571248]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF9279.cfxxe" [X]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-12-16 9636896]
"Apoint"="%ProgramFiles%\Apoint\Apoint.exe" [BU]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-01-13 171520]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-04-07 2839840]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\users\user\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\users\user\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} - hxxp://trial.trymicrosoftoffice.com/tri ... /wrc32.ocx
FF - ProfilePath - c:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ceduj8wc.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - g:\install\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - g:\install\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - g:\install\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - g:\install\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - g:\install\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - g:\install\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: DVDVideoSoft Menu: {ACAA314B-EEBA-48e4-AD47-84E31C44796C} - %profile%\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
FF - Ext: DVDVideoSoftTB Toolbar: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - %profile%\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SampleCollector]
"ImagePath"="\"c:\program files\Sony\VAIO Care\VCPerfService.exe\" \"/service\" \"/sstates\" \"/sampleinterval=5000\" \"/procinterval=5\" \"/dllinterval=120\" \"/counter=\Processor(_Total)\% Processor Time:1/counter=\PhysicalDisk(_Total)\Disk Bytes/sec:1\" \"/counter=\Network Interface(*)\Bytes Total/sec:1\" \"/expandcounter=\Processor Information(*)\Processor Frequency:1\" \"/expandcounter=\Processor(*)\% Idle Time:1\" \"/expandcounter=\Processor(*)\% C1 Time:1\" \"/expandcounter=\Processor(*)\% C2 Time:1\" \"/expandcounter=\Processor(*)\% C3 Time:1\" \"/expandcounter=\Processor(*)\% Processor Time:1\" \"/directory=inteldata\""
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-2835324808-1647480109-3611849097-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-2835324808-1647480109-3611849097-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_USERS\S-1-5-21-2835324808-1647480109-3611849097-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:28,37,c0,8a,95,9d,c5,61,37,af,c8,7b,11,86,a9,36,cc,8b,58,45,76,aa,6a,
e5,ca,7c,c1,c7,25,ef,77,54,b4,38,bd,0e,de,6f,6e,f6,a9,9d,6b,14,34,6a,ca,fb,\
"??"=hex:62,bc,fc,43,8b,ca,7a,13,7a,1e,59,23,89,7c,e0,eb
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\SONY\VAIO Event Service\VESMgr.exe
c:\windows\SysWOW64\DllHost.exe
c:\program files (x86)\SONY\VAIO Event Service\VESMgrSub.exe
c:\program files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
c:\program files\Sony\VAIO Care\VCSpt.exe
c:\program files (x86)\OpenOffice.org 3\program\soffice.exe
c:\program files (x86)\OpenOffice.org 3\program\soffice.bin
c:\program files\Sony\VAIO Care\listener.exe
.
**************************************************************************
.
Celkový čas: 2011-04-12 15:20:54 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-04-12 13:20
ComboFix2.txt 2011-04-10 21:06
.
Před spuštěním: Volných bajtů: 15 684 083 712
Po spuštění: Volných bajtů: 15 362 908 160
.
- - End Of File - - BB8FE808B08F86D31F4E7022617CC5E4

Uživatelský avatar
Žbeky
Moderátor
Guru Level 13
Guru Level 13
Příspěvky: 22288
Registrován: květen 08
Bydliště: Vsetín - Pardubice
Pohlaví: Muž
Stav:
Offline

Re: Preventivní kontrola logu HJT

Příspěvekod Žbeky » 12 dub 2011 15:59

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE

Kód: Vybrat vše

Folder::
c:\users\user\AppData\Local\{47868CFE-F941-48A1-A542-32CE720A0A5D}
c:\users\user\AppData\Local\{B6BCE3EA-7E69-4BAD-95A4-FE4626C7E3DC}
c:\users\user\AppData\Local\{B8C1B409-BE99-45EE-BA73-1471BE9B8082}
c:\users\user\AppData\Local\{DB7187BB-01DE-4688-BCC7-336687635CC7}
c:\users\user\AppData\Local\{8B6352FE-8096-4532-8BB6-D977A15A9F55}
c:\users\user\AppData\Local\{CA54DBBB-67C6-459A-A9DC-B96A0E296E6E}
c:\users\user\AppData\Local\{7151BF5F-736C-45D4-A2DD-68635B272DFC}
c:\users\user\AppData\Local\{294286C4-98F3-4E46-8A0B-443BC3D2765C}
c:\users\user\AppData\Local\{22EDDD46-8635-4B21-8F61-7DA91C56F28B}
c:\users\user\AppData\Local\{A5127446-5C3E-40FE-BE08-D476D83306E2}
c:\users\user\AppData\Local\{F4843B76-7437-4D8B-8545-F5756452C41C}
c:\users\user\AppData\Local\{239AA0A7-7A4C-4A03-8F35-4745D1A57EA3}
c:\users\user\AppData\Local\{B82BB879-C14B-4709-88A5-1562C5A43674}

Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.

HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra

TravisX90
Level 1
Level 1
Příspěvky: 54
Registrován: květen 10
Pohlaví: Muž
Stav:
Offline

Re: Preventivní kontrola logu HJT

Příspěvekod TravisX90 » 13 dub 2011 16:22

Ten log z CF je hodně dlouhý, proto jsem ho uploadoval na ulozto> http://www.ulozto.cz/8644227/combofix-txt :bigups:

HJT:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:17:00, on 13.4.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
G:\Install\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
G:\Install\Trillian\trillian.exe
C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\SONY\ISB Utility\ISBMgr.exe
C:\Program Files (x86)\SONY\PMB\PMBVolumeWatcher.exe
C:\Program Files (x86)\SONY\Marketing Tools\MarketingTools.exe
G:\Install\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Sony\VAIO Care\listener.exe
G:\Install\firefox.exe
G:\Install\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
O4 - HKLM\..\Run: [MarketingTools] C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "G:\Install\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "G:\Install\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ICQ] "G:\Install\ICQ7.2\ICQ.exe" silent loginmode=4
O4 - Startup: EvernoteClipper.lnk = C:\Program Files (x86)\Evernote\Evernote3.5\EvernoteClipper.exe
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
O4 - Startup: Trillian.lnk = G:\Install\Trillian\trillian.exe
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Add to Evernote 4.0 - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube Download - C:\Users\user\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\user\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - G:\Install\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - G:\Install\ICQ7.2\ICQ.exe
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} (WRC Class) - http://trial.trymicrosoftoffice.com/tri ... /wrc32.ocx
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - (no file)
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - (no file)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PMBDeviceInfoProvider - Sony Corporation - C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: VAIO Care Performance Service (SampleCollector) - Sony Corporation - C:\Program Files\Sony\VAIO Care\VCPerfService.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: VAIO Media plus Content Importer (SOHCImp) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe
O23 - Service: VAIO Media plus Database Manager (SOHDBSvr) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe
O23 - Service: VAIO Media plus Digital Media Server (SOHDms) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe
O23 - Service: VAIO Media plus Device Searcher (SOHDs) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe
O23 - Service: VAIO Media plus Playlist Manager (SOHPlMgr) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files (x86)\SONY\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Power Management - Sony Corporation - C:\Program Files\Sony\VAIO Power Management\SPMService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: VAIO Content Folder Watcher (VCFw) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Content Metadata Intelligent Network Service Manager (VcmINSMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VSNService - Sony Corporation - C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: VUAgent - Sony Corporation - C:\Program Files\Sony\VAIO Update 5\VUAgent.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 14859 bytes

Uživatelský avatar
Žbeky
Moderátor
Guru Level 13
Guru Level 13
Příspěvky: 22288
Registrován: květen 08
Bydliště: Vsetín - Pardubice
Pohlaví: Muž
Stav:
Offline

Re: Preventivní kontrola logu HJT

Příspěvekod Žbeky » 13 dub 2011 21:44

Dej ten log z CF sem na víc příspěvků
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.

HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra

TravisX90
Level 1
Level 1
Příspěvky: 54
Registrován: květen 10
Pohlaví: Muž
Stav:
Offline

Re: Preventivní kontrola logu HJT

Příspěvekod TravisX90 » 17 dub 2011 15:04

ComboFix 11-04-10.01 - user 13.04.2011 16:06:21.3.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3950.2555 [GMT 2:00]
Spuštěný z: c:\users\user\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\user\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5}
SP: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\user\AppData\Local\{22EDDD46-8635-4B21-8F61-7DA91C56F28B}
c:\users\user\AppData\Local\{239AA0A7-7A4C-4A03-8F35-4745D1A57EA3}
c:\users\user\AppData\Local\{294286C4-98F3-4E46-8A0B-443BC3D2765C}
c:\users\user\AppData\Local\{47868CFE-F941-48A1-A542-32CE720A0A5D}
c:\users\user\AppData\Local\{7151BF5F-736C-45D4-A2DD-68635B272DFC}
c:\users\user\AppData\Local\{8B6352FE-8096-4532-8BB6-D977A15A9F55}
c:\users\user\AppData\Local\{A5127446-5C3E-40FE-BE08-D476D83306E2}
c:\users\user\AppData\Local\{B6BCE3EA-7E69-4BAD-95A4-FE4626C7E3DC}
c:\users\user\AppData\Local\{B82BB879-C14B-4709-88A5-1562C5A43674}
c:\users\user\AppData\Local\{B8C1B409-BE99-45EE-BA73-1471BE9B8082}
c:\users\user\AppData\Local\{CA54DBBB-67C6-459A-A9DC-B96A0E296E6E}
c:\users\user\AppData\Local\{DB7187BB-01DE-4688-BCC7-336687635CC7}
c:\users\user\AppData\Local\{F4843B76-7437-4D8B-8545-F5756452C41C}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-03-13 do 2011-04-13 )))))))))))))))))))))))))))))))
.
.
2011-04-13 14:12 . 2011-04-13 14:12 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-04-13 11:20 . 2011-04-13 11:20 -------- d-----w- c:\program files (x86)\Evernote
2011-04-13 10:44 . 2011-02-05 17:10 642944 ----a-w- c:\windows\system32\winload.efi
2011-04-13 10:44 . 2011-02-05 17:10 20352 ----a-w- c:\windows\system32\kdusb.dll
2011-04-13 10:44 . 2011-02-05 17:10 19328 ----a-w- c:\windows\system32\kd1394.dll
2011-04-13 10:44 . 2011-02-05 17:10 17792 ----a-w- c:\windows\system32\kdcom.dll
2011-04-13 10:44 . 2011-02-05 17:06 605552 ----a-w- c:\windows\system32\winload.exe
2011-04-13 10:44 . 2011-02-05 17:06 518672 ----a-w- c:\windows\system32\winresume.exe
2011-04-13 10:44 . 2011-02-23 04:56 158208 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-13 10:44 . 2011-02-23 04:55 287744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-04-13 10:44 . 2011-02-23 04:55 128000 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-04-13 10:44 . 2011-02-23 04:55 90624 ----a-w- c:\windows\system32\drivers\bowser.sys
2011-04-13 10:44 . 2011-02-12 11:34 267776 ----a-w- c:\windows\system32\FXSCOVER.exe
2011-04-13 07:58 . 2011-04-13 07:58 -------- d-----w- c:\windows\system32\SPReview
2011-04-13 07:54 . 2010-11-05 01:57 48976 ----a-w- c:\windows\system32\netfxperf.dll
2011-04-13 07:54 . 2010-11-05 01:57 1942856 ----a-w- c:\windows\system32\dfshim.dll
2011-04-13 07:54 . 2010-11-05 01:58 1130824 ----a-w- c:\windows\SysWow64\dfshim.dll
2011-04-13 07:54 . 2010-11-20 13:33 5563776 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-04-13 07:54 . 2010-11-20 13:27 12288 ----a-w- c:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2011-04-13 07:54 . 2010-11-20 13:27 3715584 ----a-w- c:\windows\system32\mstscax.dll
2011-04-13 07:54 . 2010-11-20 11:07 59392 ----a-w- c:\windows\system32\drivers\TsUsbFlt.sys
2011-04-13 07:54 . 2010-11-20 13:27 14967808 ----a-w- c:\program files\DVD Maker\OmdBase.dll
2011-04-13 07:54 . 2010-11-20 13:26 1838080 ----a-w- c:\windows\system32\d3d10warp.dll
2011-04-13 07:54 . 2010-11-20 12:19 3215872 ----a-w- c:\windows\SysWow64\mstscax.dll
2011-04-13 07:54 . 2010-11-20 12:18 1171456 ----a-w- c:\windows\SysWow64\d3d10warp.dll
2011-04-13 07:52 . 2010-11-20 13:33 189824 ----a-w- c:\windows\system32\drivers\storport.sys
2011-04-13 07:51 . 2010-11-20 13:27 200192 ----a-w- c:\windows\system32\syncui.dll
2011-04-13 07:50 . 2010-11-20 12:21 189952 ----a-w- c:\windows\SysWow64\wdscore.dll
2011-04-13 07:50 . 2010-11-20 12:17 209920 ----a-w- c:\windows\SysWow64\PkgMgr.exe
2011-04-13 07:50 . 2010-11-20 12:18 323072 ----a-w- c:\windows\SysWow64\drvstore.dll
2011-04-13 07:50 . 2010-11-20 12:18 257024 ----a-w- c:\windows\SysWow64\dpx.dll
2011-04-13 07:50 . 2010-11-20 12:21 363008 ----a-w- c:\windows\SysWow64\wbemcomn.dll
2011-04-13 07:50 . 2010-11-20 12:19 606208 ----a-w- c:\windows\SysWow64\wbem\fastprox.dll
2011-04-13 07:47 . 2010-11-20 13:27 524288 ----a-w- c:\windows\system32\wmicmiplugin.dll
2011-04-13 07:47 . 2010-11-20 13:27 529408 ----a-w- c:\windows\system32\wbemcomn.dll
2011-04-13 07:47 . 2010-11-20 13:27 1225216 ----a-w- c:\windows\system32\wbem\wbemcore.dll
2011-04-13 07:47 . 2010-11-20 13:27 933376 ----a-w- c:\windows\system32\SmiEngine.dll
2011-04-13 07:47 . 2010-11-20 13:25 199168 ----a-w- c:\windows\system32\PkgMgr.exe
2011-04-13 07:46 . 2010-11-20 13:26 422912 ----a-w- c:\windows\system32\drvstore.dll
2011-04-13 07:46 . 2010-11-20 13:26 399872 ----a-w- c:\windows\system32\dpx.dll
2011-04-13 07:16 . 2011-04-13 07:16 -------- d-----w- c:\users\user\AppData\Local\{35F51424-0158-43C7-A65A-E268A36E45B1}
2011-04-12 15:13 . 2011-03-15 05:17 8424784 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{EF2DE9DB-0380-4BE0-9C96-34F969E1F11F}\mpengine.dll
2011-04-12 13:16 . 2011-04-12 13:16 -------- d-----w- c:\users\user\AppData\Local\{E72B3324-0897-42E8-9443-EA9D73ABBDD1}
2011-04-11 08:32 . 2011-04-11 08:33 -------- d-----w- c:\users\user\AppData\Local\{20DC730D-4D02-4E2D-883F-13C64947662A}
2011-04-10 17:27 . 2011-04-10 17:27 -------- d-----w- c:\users\user\AppData\Local\Apple
2011-04-08 02:51 . 2011-04-08 02:51 -------- d-----w- c:\windows\cs
2011-04-08 02:49 . 2011-04-08 02:49 469256 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\9848c07c1cbf5970f\InstallManager_WLE_WLE.exe
2011-04-08 02:49 . 2011-04-08 02:49 15712 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\956915661cbf5970e\MeshBetaRemover.exe
2011-04-07 21:41 . 2011-04-07 21:41 -------- d-----w- c:\users\user\AppData\Local\ArcSoft
2011-04-07 21:18 . 2011-04-07 21:18 -------- d-----w- c:\users\user\AppData\Roaming\DVDVideoSoft
2011-04-06 15:08 . 2011-04-06 15:08 -------- d-----w- c:\users\user\AppData\Local\Apps
2011-04-04 09:58 . 2011-04-04 09:58 -------- d-----w- c:\users\user\AppData\Local\Adobe
2011-04-03 18:54 . 2011-04-03 18:54 -------- d-----w- c:\users\user\AppData\Local\ATI
2011-04-03 18:53 . 2011-04-03 18:53 -------- d-----w- c:\users\user\AppData\Local\AOL
2011-04-03 16:14 . 2011-04-03 16:14 388096 ----a-r- c:\users\user\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-03-23 22:54 . 2011-03-23 22:54 -------- d-----w- c:\windows\system32\EventProviders
2011-03-23 22:48 . 2011-02-19 12:05 1139200 ----a-w- c:\windows\system32\FntCache.dll
2011-03-23 22:48 . 2011-02-19 12:04 1544192 ----a-w- c:\windows\system32\DWrite.dll
2011-03-23 22:48 . 2011-02-19 06:30 1076736 ----a-w- c:\windows\SysWow64\DWrite.dll
2011-03-23 22:48 . 2011-02-19 12:04 902656 ----a-w- c:\windows\system32\d2d1.dll
2011-03-23 22:48 . 2011-02-19 06:30 739840 ----a-w- c:\windows\SysWow64\d2d1.dll
2011-03-20 16:04 . 2010-12-23 10:42 961024 ----a-w- c:\windows\system32\CPFilters.dll
2011-03-20 16:04 . 2010-12-23 10:42 723968 ----a-w- c:\windows\system32\EncDec.dll
2011-03-20 16:04 . 2010-12-23 05:54 642048 ----a-w- c:\windows\SysWow64\CPFilters.dll
2011-03-20 16:04 . 2010-12-23 10:42 1118720 ----a-w- c:\windows\system32\sbe.dll
2011-03-20 16:04 . 2010-12-23 10:36 259072 ----a-w- c:\windows\system32\mpg2splt.ax
2011-03-20 16:04 . 2010-12-23 05:54 850944 ----a-w- c:\windows\SysWow64\sbe.dll
2011-03-20 16:04 . 2010-12-23 05:54 534528 ----a-w- c:\windows\SysWow64\EncDec.dll
2011-03-20 16:04 . 2010-12-23 05:50 199680 ----a-w- c:\windows\SysWow64\mpg2splt.ax
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-13 08:36 . 2011-04-13 08:36 249344 ----a-w- c:\windows\system32\webcheck.dll
2011-04-13 08:36 . 2011-04-13 08:36 203776 ----a-w- c:\windows\SysWow64\webcheck.dll
2011-04-13 08:06 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-04-13 08:06 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-03-21 10:35 . 2010-06-24 10:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-02-02 20:40 . 2010-06-14 16:32 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-02-02 17:11 . 2010-06-14 20:00 270720 ------w- c:\windows\system32\MpSigStub.exe
.
.
((((((((((((((((((((((((((((( SnapShot@2011-04-10_21.01.31 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-04-13 07:51 . 2010-11-20 12:21 51200 c:\windows\twain_32.dll
- 2009-07-14 00:14 . 2009-07-14 01:16 51200 c:\windows\twain_32.dll
+ 2011-04-13 07:51 . 2010-11-20 12:21 27648 c:\windows\SysWOW64\wups.dll
+ 2011-04-13 07:51 . 2010-11-20 12:21 87552 c:\windows\SysWOW64\wudriver.dll
- 2009-07-14 00:14 . 2009-07-14 01:16 87552 c:\windows\SysWOW64\wudriver.dll
- 2009-07-14 00:14 . 2009-07-14 01:14 33792 c:\windows\SysWOW64\wuapp.exe
+ 2011-04-13 07:51 . 2010-11-20 12:17 33792 c:\windows\SysWOW64\wuapp.exe
+ 2011-04-13 07:51 . 2010-11-20 12:21 40448 c:\windows\SysWOW64\wtsapi32.dll
- 2009-07-13 23:55 . 2009-07-14 01:16 51712 c:\windows\SysWOW64\wsnmp32.dll
+ 2011-04-13 07:51 . 2010-11-20 12:21 51712 c:\windows\SysWOW64\wsnmp32.dll
+ 2011-04-13 07:51 . 2010-11-20 12:21 11264 c:\windows\SysWOW64\wshirda.dll
+ 2011-04-13 07:51 . 2010-11-20 12:21 36352 c:\windows\SysWOW64\wshbth.dll
+ 2011-04-13 07:51 . 2010-11-20 12:21 21504 c:\windows\SysWOW64\wsdchngr.dll
+ 2011-04-13 07:52 . 2010-11-20 12:21 51712 c:\windows\SysWOW64\wscapi.dll
- 2009-07-13 23:37 . 2009-07-14 01:16 47104 c:\windows\SysWOW64\wkscli.dll
+ 2011-04-13 07:51 . 2010-11-20 12:21 47104 c:\windows\SysWOW64\wkscli.dll
- 2009-07-13 23:27 . 2009-07-14 01:14 28672 c:\windows\SysWOW64\WerFaultSecure.exe
+ 2011-04-13 07:51 . 2010-11-20 12:17 28672 c:\windows\SysWOW64\WerFaultSecure.exe
- 2009-07-13 23:31 . 2009-07-14 01:16 89600 c:\windows\SysWOW64\wbem\WmiApRpl.dll
+ 2011-04-13 07:51 . 2010-11-20 12:21 89600 c:\windows\SysWOW64\wbem\WmiApRpl.dll
+ 2011-04-13 07:52 . 2010-11-20 12:17 66048 c:\windows\SysWOW64\w32tm.exe
+ 2011-04-13 07:51 . 2010-11-20 12:21 25600 c:\windows\SysWOW64\vpnikeapi.dll
+ 2011-04-13 07:51 . 2010-11-20 12:21 56832 c:\windows\SysWOW64\vfwwdm32.dll
- 2009-07-14 00:03 . 2009-07-14 01:16 56832 c:\windows\SysWOW64\vfwwdm32.dll
- 2009-07-14 00:02 . 2009-07-14 01:16 31744 c:\windows\SysWOW64\utildll.dll
+ 2011-04-13 07:51 . 2010-11-20 12:21 31744 c:\windows\SysWOW64\utildll.dll
+ 2011-04-13 07:52 . 2010-11-20 12:17 26624 c:\windows\SysWOW64\userinit.exe
+ 2011-04-13 07:52 . 2010-11-20 12:21 81920 c:\windows\SysWOW64\userenv.dll
+ 2011-04-13 07:51 . 2010-11-20 12:21 78848 c:\windows\SysWOW64\UserAccountControlSettings.dll
- 2009-07-13 23:40 . 2009-07-14 01:16 78848 c:\windows\SysWOW64\UserAccountControlSettings.dll
+ 2011-04-13 07:51 . 2010-11-20 12:17 34304 c:\windows\SysWOW64\unlodctr.exe
+ 2011-04-13 07:51 . 2010-11-20 12:21 59392 c:\windows\SysWOW64\unimdmat.dll
- 2009-07-13 23:55 . 2009-07-14 01:16 59392 c:\windows\SysWOW64\unimdmat.dll
+ 2011-04-13 07:51 . 2010-11-20 12:17 47616 c:\windows\SysWOW64\tzutil.exe
- 2009-07-13 23:15 . 2009-07-14 01:14 47616 c:\windows\SysWOW64\tzutil.exe
- 2009-07-13 23:34 . 2009-07-14 01:16 65024 c:\windows\SysWOW64\TSpkg.dll
+ 2011-04-13 07:51 . 2010-11-20 12:21 65024 c:\windows\SysWOW64\TSpkg.dll
+ 2011-04-13 07:51 . 2010-11-20 12:21 36864 c:\windows\SysWOW64\tsgqec.dll
- 2009-07-14 00:02 . 2009-07-14 01:16 36864 c:\windows\SysWOW64\tsgqec.dll
- 2010-06-14 10:38 . 2009-12-19 09:02 12288 c:\windows\SysWOW64\tsbyuv.dll
+ 2011-04-13 07:51 . 2010-11-20 12:21 12288 c:\windows\SysWOW64\tsbyuv.dll
+ 2011-04-13 07:51 . 2010-11-20 12:21 21504 c:\windows\SysWOW64\TRAPI.dll
+ 2011-04-13 07:51 . 2010-11-20 12:21 69632 c:\windows\SysWOW64\tlscsp.dll
+ 2011-04-13 07:52 . 2010-11-20 12:21 82944 c:\windows\SysWOW64\thumbcache.dll
- 2009-07-13 23:40 . 2009-07-14 01:16 82944 c:\windows\SysWOW64\thumbcache.dll
+ 2011-04-13 07:53 . 2009-07-14 01:16 61440 c:\windows\SysWOW64\tcpmonui.dll
+ 2011-04-13 07:51 . 2010-11-20 12:17 51200 c:\windows\SysWOW64\takeown.exe
+ 2011-04-13 07:51 . 2010-11-20 12:21 14848 c:\windows\SysWOW64\syssetup.dll
- 2010-06-14 10:38 . 2009-12-11 07:36 96768 c:\windows\SysWOW64\sspicli.dll
+ 2011-04-13 07:51 . 2010-11-20 12:08 96768 c:\windows\SysWOW64\sspicli.dll
- 2009-07-13 23:37 . 2009-07-14 01:16 90112 c:\windows\SysWOW64\srvcli.dll
+ 2011-04-13 07:51 . 2010-11-20 12:21 90112 c:\windows\SysWOW64\srvcli.dll
- 2009-07-13 23:17 . 2009-07-14 01:16 19968 c:\windows\SysWOW64\spopk.dll
+ 2011-04-13 07:51 . 2010-11-20 12:21 19968 c:\windows\SysWOW64\spopk.dll
- 2009-07-13 23:17 . 2009-07-14 01:16 61952 c:\windows\SysWOW64\spbcd.dll
+ 2011-04-13 07:51 . 2010-11-20 12:21 61952 c:\windows\SysWOW64\spbcd.dll
- 2011-02-09 08:11 . 2010-12-21 05:38 14336 c:\windows\SysWOW64\slwga.dll
+ 2011-04-13 07:51 . 2010-11-20 12:21 14336 c:\windows\SysWOW64\slwga.dll
- 2009-07-13 23:14 . 2009-07-14 01:16 19456 c:\windows\SysWOW64\sisbkup.dll
+ 2011-04-13 07:51 . 2010-11-20 12:21 19456 c:\windows\SysWOW64\sisbkup.dll
+ 2011-04-13 07:51 . 2010-11-20 12:21 17408 c:\windows\SysWOW64\schedcli.dll
- 2009-07-13 23:37 . 2009-07-14 01:16 17408 c:\windows\SysWOW64\schedcli.dll
+ 2011-04-13 07:51 . 2010-11-20 12:21 10752 c:\windows\SysWOW64\shunimpl.dll
- 2009-07-13 23:39 . 2009-07-14 01:16 35840 c:\windows\SysWOW64\shimgvw.dll
+ 2011-04-13 07:51 . 2010-11-20 12:21 35840 c:\windows\SysWOW64\shimgvw.dll
+ 2011-04-13 07:51 . 2010-11-20 12:21 20992 c:\windows\SysWOW64\shgina.dll
- 2009-07-13 23:40 . 2009-07-14 01:16 20992 c:\windows\SysWOW64\shgina.dll
- 2010-06-14 10:39 . 2009-12-22 08:23 25600 c:\windows\SysWOW64\setup16.exe
+ 2009-07-13 23:16 . 2009-07-14 01:14 25600 c:\windows\SysWOW64\setup16.exe
+ 2011-04-13 07:53 . 2010-11-20 12:20 67584 c:\windows\SysWOW64\Setup\pbkmigr.dll
+ 2011-04-13 08:36 . 2011-04-13 08:36 76800 c:\windows\SysWOW64\SetIEInstalledDate.exe
+ 2011-04-13 07:51 . 2010-11-20 12:21 22016 c:\windows\SysWOW64\secur32.dll
- 2010-06-14 10:38 . 2009-12-11 07:39 22016 c:\windows\SysWOW64\secur32.dll
- 2010-06-14 10:39 . 2010-01-18 23:29 85504 c:\windows\SysWOW64\secproc_ssp_isv.dll
+ 2011-04-13 07:51 . 2010-11-20 12:21 85504 c:\windows\SysWOW64\secproc_ssp_isv.dll
- 2010-06-14 10:39 . 2010-01-18 23:29 85504 c:\windows\SysWOW64\secproc_ssp.dll
+ 2011-04-13 07:51 . 2010-11-20 12:21 85504 c:\windows\SysWOW64\secproc_ssp.dll
+ 2011-04-13 07:52 . 2010-11-20 12:21 51200 c:\windows\SysWOW64\samcli.dll
+ 2011-04-13 07:51 . 2010-11-20 12:17 50688 c:\windows\SysWOW64\runonce.exe
- 2009-07-13 23:41 . 2009-07-14 01:14 50688 c:\windows\SysWOW64\runonce.exe
+ 2011-04-13 07:51 . 2010-11-20 12:21 37376 c:\windows\SysWOW64\rtutils.dll
- 2010-08-11 13:13 . 2010-06-19 06:23 37376 c:\windows\SysWOW64\rtutils.dll
+ 2011-04-13 07:52 . 2010-11-20 12:21 46080 c:\windows\SysWOW64\RpcRtRemote.dll
+ 2011-04-13 07:52 . 2010-11-20 12:17 98816 c:\windows\SysWOW64\Robocopy.exe
- 2009-07-13 23:21 . 2009-07-14 01:16 71168 c:\windows\SysWOW64\resutils.dll
+ 2011-04-13 07:51 . 2010-11-20 12:21 71168 c:\windows\SysWOW64\resutils.dll
+ 2011-04-13 07:51 . 2010-11-20 12:17 37888 c:\windows\SysWOW64\relog.exe
+ 2011-04-13 08:36 . 2011-04-13 08:36 74752 c:\windows\SysWOW64\RegisterIEPKEYs.exe
+ 2011-04-13 07:52 . 2010-11-20 12:21 72192 c:\windows\SysWOW64\regapi.dll
+ 2011-04-13 07:51 . 2010-11-20 12:17 22016 c:\windows\SysWOW64\ReAgentc.exe
- 2009-07-14 00:01 . 2009-07-14 01:16 21504 c:\windows\SysWOW64\rdprefdrvapi.dll
+ 2011-04-13 07:51 . 2010-11-20 12:21 21504 c:\windows\SysWOW64\rdprefdrvapi.dll
+ 2011-04-13 07:51 . 2010-11-20 12:21 52224 c:\windows\SysWOW64\rdpd3d.dll
- 2009-07-14 00:02 . 2009-07-14 01:16 52224 c:\windows\SysWOW64\rdpd3d.dll
+ 2011-04-13 07:51 . 2010-11-20 12:21 69632 c:\windows\SysWOW64\rastapi.dll
- 2009-07-13 23:54 . 2009-07-14 01:16 69632 c:\windows\SysWOW64\rastapi.dll
- 2009-07-13 23:52 . 2009-07-14 01:16 80896 c:\windows\SysWOW64\QUTIL.DLL
+ 2011-04-13 07:51 . 2010-11-20 12:21 80896 c:\windows\SysWOW64\QUTIL.DLL
- 2009-07-13 23:52 . 2009-07-14 01:16 99328 c:\windows\SysWOW64\QSVRMGMT.DLL
+ 2011-04-13 07:51 . 2010-11-20 12:20 99328 c:\windows\SysWOW64\QSVRMGMT.DLL
+ 2011-04-13 07:51 . 2010-11-20 12:20 71680 c:\windows\SysWOW64\QCLIPROV.DLL
- 2009-07-13 23:52 . 2009-07-14 01:16 71680 c:\windows\SysWOW64\QCLIPROV.DLL
+ 2011-04-13 07:52 . 2010-11-20 12:17 28672 c:\windows\SysWOW64\proquota.exe
- 2009-07-13 23:39 . 2009-07-14 01:14 31232 c:\windows\SysWOW64\prevhost.exe
+ 2011-04-13 07:51 . 2010-11-20 12:17 31232 c:\windows\SysWOW64\prevhost.exe
+ 2011-04-13 07:53 . 2010-11-05 01:53 99176 c:\windows\SysWOW64\PresentationHostProxy.dll
- 2010-06-23 13:01 . 2009-11-25 10:47 99176 c:\windows\SysWOW64\PresentationHostProxy.dll
+ 2011-04-13 08:36 . 2011-04-13 08:36 54272 c:\windows\SysWOW64\pngfilt.dll
+ 2011-04-13 07:51 . 2010-11-20 12:05 35328 c:\windows\SysWOW64\pifmgr.dll
+ 2011-04-13 07:51 . 2010-11-20 12:20 17408 c:\windows\SysWOW64\perfts.dll
- 2009-07-14 00:02 . 2009-07-14 01:16 17408 c:\windows\SysWOW64\perfts.dll
+ 2011-04-13 07:51 . 2010-11-20 12:20 46592 c:\windows\SysWOW64\pdhui.dll
+ 2011-04-13 07:51 . 2010-11-20 12:20 77824 c:\windows\SysWOW64\olethk32.dll
+ 2011-04-13 07:51 . 2010-11-20 12:20 90112 c:\windows\SysWOW64\olepro32.dll
- 2009-07-13 23:43 . 2009-07-14 01:16 90112 c:\windows\SysWOW64\olepro32.dll
+ 2011-04-13 07:51 . 2010-11-20 12:20 40960 c:\windows\SysWOW64\odbcconf.dll
- 2009-07-14 00:12 . 2009-07-14 01:16 40960 c:\windows\SysWOW64\odbcconf.dll
+ 2009-07-13 23:15 . 2009-07-14 01:16 14336 c:\windows\SysWOW64\ntvdm64.dll
- 2010-06-14 10:39 . 2009-12-22 08:24 14336 c:\windows\SysWOW64\ntvdm64.dll
- 2009-07-13 23:31 . 2009-07-14 01:16 69120 c:\windows\SysWOW64\ntlanman.dll
+ 2011-04-13 07:51 . 2010-11-20 12:20 69120 c:\windows\SysWOW64\ntlanman.dll
+ 2011-04-13 07:51 . 2010-11-20 12:17 98304 c:\windows\SysWOW64\nslookup.exe
+ 2011-04-13 07:51 . 2010-11-20 12:06 69120 c:\windows\SysWOW64\nlsbres.dll
+ 2011-04-13 07:51 . 2010-11-20 12:20 52224 c:\windows\SysWOW64\nlaapi.dll
+ 2011-04-13 07:51 . 2010-11-20 12:20 22528 c:\windows\SysWOW64\netutils.dll
+ 2011-04-13 07:51 . 2010-11-20 12:17 25600 c:\windows\SysWOW64\netiougc.exe
+ 2011-04-13 07:52 . 2010-11-05 01:58 49488 c:\windows\SysWOW64\netfxperf.dll
- 2009-07-13 23:53 . 2009-07-14 01:14 24064 c:\windows\SysWOW64\netbtugc.exe
+ 2011-04-13 07:51 . 2010-11-20 12:17 24064 c:\windows\SysWOW64\netbtugc.exe
- 2009-07-13 23:37 . 2009-07-14 01:16 56832 c:\windows\SysWOW64\netapi32.dll
+ 2011-04-13 07:51 . 2010-11-20 12:20 56832 c:\windows\SysWOW64\netapi32.dll
- 2009-07-13 23:32 . 2009-07-14 01:16 60928 c:\windows\SysWOW64\ncryptui.dll
+ 2011-04-13 07:51 . 2010-11-20 12:20 60928 c:\windows\SysWOW64\ncryptui.dll
+ 2011-04-13 07:52 . 2010-11-20 12:20 78848 c:\windows\SysWOW64\nci.dll
+ 2011-04-13 07:51 . 2010-11-20 12:20 68096 c:\windows\SysWOW64\napdsnap.dll
+ 2011-04-13 07:51 . 2010-11-20 12:36 46080 c:\windows\SysWOW64\NAPCRYPT.DLL
- 2009-07-13 23:53 . 2009-07-14 01:22 46080 c:\windows\SysWOW64\NAPCRYPT.DLL
- 2009-07-13 23:13 . 2009-07-14 01:14 70656 c:\windows\SysWOW64\MuiUnattend.exe
+ 2011-04-13 07:51 . 2010-11-20 12:17 70656 c:\windows\SysWOW64\MuiUnattend.exe
- 2009-07-13 23:25 . 2009-07-14 01:15 13312 c:\windows\SysWOW64\muifontsetup.dll
+ 2011-04-13 07:51 . 2010-11-20 12:19 13312 c:\windows\SysWOW64\muifontsetup.dll
+ 2011-04-13 07:51 . 2010-11-05 01:58 11600 c:\windows\SysWOW64\MUI\0409\mscorees.dll
- 2010-06-23 13:01 . 2009-11-25 10:47 11600 c:\windows\SysWOW64\MUI\0409\mscorees.dll
+ 2011-04-13 07:51 . 2010-11-05 01:53 12112 c:\windows\SysWOW64\MUI\0405\mscorees.dll
+ 2011-04-13 07:51 . 2010-11-20 12:19 22528 c:\windows\SysWOW64\msyuv.dll
+ 2011-04-13 07:51 . 2010-11-20 12:19 31744 c:\windows\SysWOW64\msvidc32.dll
- 2010-06-14 10:38 . 2009-12-19 09:02 31744 c:\windows\SysWOW64\msvidc32.dll
- 2010-06-14 10:38 . 2009-12-19 09:02 13312 c:\windows\SysWOW64\msrle32.dll
+ 2011-04-13 07:51 . 2010-11-20 12:19 13312 c:\windows\SysWOW64\msrle32.dll
+ 2011-04-13 07:51 . 2010-11-20 12:17 73216 c:\windows\SysWOW64\msiexec.exe
- 2009-07-13 23:31 . 2009-07-14 01:14 73216 c:\windows\SysWOW64\msiexec.exe
+ 2011-04-13 08:36 . 2011-04-13 08:36 48640 c:\windows\SysWOW64\mshtmler.dll
+ 2011-04-13 08:36 . 2011-04-13 08:36 72704 c:\windows\SysWOW64\mshtmled.dll
+ 2011-04-13 08:36 . 2011-04-13 08:36 11776 c:\windows\SysWOW64\mshta.exe
+ 2011-04-13 08:36 . 2011-04-13 08:36 10752 c:\windows\SysWOW64\msfeedssync.exe
+ 2011-04-13 08:36 . 2011-04-13 08:36 41472 c:\windows\SysWOW64\msfeedsbs.dll
+ 2011-04-13 07:51 . 2010-11-20 12:19 30720 c:\windows\SysWOW64\msdmo.dll
- 2009-07-13 20:46 . 2009-06-10 21:23 80720 c:\windows\SysWOW64\mscories.dll
+ 2011-04-13 07:52 . 2010-11-05 01:58 80720 c:\windows\SysWOW64\mscories.dll
+ 2011-04-13 07:52 . 2010-11-20 12:19 34304 c:\windows\SysWOW64\msasn1.dll
+ 2011-04-13 07:52 . 2010-11-20 12:19 42496 c:\windows\SysWOW64\mimefilt.dll
+ 2011-04-13 07:51 . 2010-11-20 12:21 90112 c:\windows\SysWOW64\migwiz\replacementmanifests\microsoft-windows-shmig\shmig.dll
- 2009-07-13 23:42 . 2009-07-14 01:16 90112 c:\windows\SysWOW64\migwiz\replacementmanifests\microsoft-windows-shmig\shmig.dll
- 2009-07-13 23:42 . 2009-07-14 01:16 90112 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-shmig-DL\shmig.dll
+ 2011-04-13 07:51 . 2010-11-20 12:21 90112 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-shmig-DL\shmig.dll
+ 2011-04-13 07:53 . 2010-11-20 12:21 67584 c:\windows\SysWOW64\migration\WSMT\rras\replacementmanifests\Microsoft-Windows-RasApi-MigPlugin\pbkmigr-Mig.dll
+ 2011-04-13 08:36 . 2011-04-13 08:36 66048 c:\windows\SysWOW64\migration\WininetPlugin.dll
+ 2011-04-13 07:51 . 2010-11-20 12:21 90112 c:\windows\SysWOW64\migration\shmig.dll
- 2009-07-13 23:41 . 2009-07-14 01:16 90112 c:\windows\SysWOW64\migration\shmig.dll
- 2009-07-14 00:03 . 2009-07-14 01:15 36352 c:\windows\SysWOW64\mciqtz32.dll
+ 2011-04-13 07:51 . 2010-11-20 12:19 36352 c:\windows\SysWOW64\mciqtz32.dll
- 2010-06-14 10:38 . 2009-12-19 09:02 84480 c:\windows\SysWOW64\mciavi32.dll
+ 2011-04-13 07:51 . 2010-11-20 12:19 84480 c:\windows\SysWOW64\mciavi32.dll
+ 2011-04-13 07:51 . 2010-11-20 12:19 76800 c:\windows\SysWOW64\mapistub.dll
- 2009-07-14 00:12 . 2009-07-14 01:15 76800 c:\windows\SysWOW64\mapistub.dll
- 2009-07-14 00:12 . 2009-07-14 01:15 76800 c:\windows\SysWOW64\mapi32.dll
+ 2011-04-13 07:51 . 2010-11-20 12:19 76800 c:\windows\SysWOW64\mapi32.dll
+ 2011-04-13 07:51 . 2010-11-20 12:19 41984 c:\windows\SysWOW64\luainstall.dll
+ 2011-04-13 07:51 . 2010-11-20 12:19 21504 c:\windows\SysWOW64\lsmproxy.dll
+ 2011-04-13 07:51 . 2010-11-20 12:17 82944 c:\windows\SysWOW64\logman.exe
+ 2011-04-13 07:51 . 2010-11-20 12:17 95232 c:\windows\SysWOW64\logagent.exe
- 2009-07-14 00:08 . 2009-07-14 01:14 95232 c:\windows\SysWOW64\logagent.exe
+ 2011-04-13 08:36 . 2011-04-13 08:36 23552 c:\windows\SysWOW64\licmgr10.dll
+ 2011-04-13 08:36 . 2011-04-13 08:36 65024 c:\windows\SysWOW64\jsproxy.dll
+ 2011-04-13 07:51 . 2010-11-20 12:19 50176 c:\windows\SysWOW64\iyuv_32.dll
- 2010-06-14 10:38 . 2009-12-19 09:02 50176 c:\windows\SysWOW64\iyuv_32.dll
- 2009-07-13 23:40 . 2009-07-14 01:14 86528 c:\windows\SysWOW64\isoburn.exe
+ 2011-04-13 07:51 . 2010-11-20 12:17 86528 c:\windows\SysWOW64\isoburn.exe
- 2009-07-13 23:46 . 2009-07-14 01:15 28672 c:\windows\SysWOW64\iscsium.dll
+ 2011-04-13 07:51 . 2010-11-20 12:19 28672 c:\windows\SysWOW64\iscsium.dll
+ 2011-04-13 08:36 . 2011-04-13 08:36 78848 c:\windows\SysWOW64\inseng.dll
+ 2011-04-13 07:51 . 2010-11-20 12:19 52736 c:\windows\SysWOW64\inetmib1.dll
+ 2011-04-13 08:36 . 2011-04-13 08:36 35840 c:\windows\SysWOW64\imgutil.dll
- 2009-07-13 23:26 . 2009-07-14 01:14 90112 c:\windows\SysWOW64\IME\IMESC5\IMSCPROP.exe
+ 2011-04-13 07:51 . 2010-11-20 12:17 90112 c:\windows\SysWOW64\IME\IMESC5\IMSCPROP.exe
+ 2011-04-13 08:36 . 2011-04-13 08:36 86528 c:\windows\SysWOW64\iesysprep.dll
+ 2011-04-13 08:36 . 2011-04-13 08:36 74752 c:\windows\SysWOW64\iesetup.dll
+ 2011-04-13 08:36 . 2011-04-13 08:36 31744 c:\windows\SysWOW64\iernonce.dll
+ 2011-04-13 08:36 . 2011-04-13 08:36 74240 c:\windows\SysWOW64\ie4uinit.exe
- 2010-08-11 13:13 . 2010-07-29 06:30 82944 c:\windows\SysWOW64\iccvid.dll
+ 2011-04-13 07:51 . 2010-11-20 12:19 82944 c:\windows\SysWOW64\iccvid.dll
+ 2011-04-13 08:36 . 2011-04-13 08:36 66048 c:\windows\SysWOW64\icardie.dll
+ 2011-04-13 07:52 . 2010-11-20 12:19 78848 c:\windows\SysWOW64\iasacct.dll
+ 2011-04-13 07:51 . 2010-11-20 12:19 34816 c:\windows\SysWOW64\httpapi.dll
- 2009-07-13 23:12 . 2009-07-14 01:15 34816 c:\windows\SysWOW64\httpapi.dll
+ 2011-04-13 07:52 . 2010-11-20 12:19 66560 c:\windows\SysWOW64\hbaapi.dll
- 2009-07-13 23:55 . 2009-07-14 01:14 42496 c:\windows\SysWOW64\ftp.exe
+ 2011-04-13 07:51 . 2010-11-20 12:17 42496 c:\windows\SysWOW64\ftp.exe
+ 2011-04-13 07:51 . 2010-11-20 12:19 98304 c:\windows\SysWOW64\fphc.dll
- 2010-06-14 10:38 . 2009-10-19 14:10 70656 c:\windows\SysWOW64\fontsub.dll
+ 2011-02-09 08:10 . 2010-09-30 06:47 70656 c:\windows\SysWOW64\fontsub.dll
+ 2011-04-13 07:51 . 2010-11-20 12:19 93696 c:\windows\SysWOW64\fms.dll
- 2009-07-13 23:25 . 2009-07-14 01:15 93696 c:\windows\SysWOW64\fms.dll
+ 2011-04-13 07:51 . 2010-11-20 12:17 62976 c:\windows\SysWOW64\findstr.exe
+ 2011-04-13 07:51 . 2010-11-20 12:19 59904 c:\windows\SysWOW64\fdeploy.dll
+ 2011-04-13 07:51 . 2010-11-20 12:18 22528 c:\windows\SysWOW64\elsTrans.dll
+ 2011-04-13 07:51 . 2010-11-20 12:18 94208 c:\windows\SysWOW64\eappgnui.dll
- 2009-07-13 23:56 . 2009-07-14 01:15 94208 c:\windows\SysWOW64\eappgnui.dll
+ 2011-04-13 07:51 . 2010-11-20 12:18 30208 c:\windows\SysWOW64\dsauth.dll
+ 2011-04-13 07:51 . 2010-11-20 12:18 82432 c:\windows\SysWOW64\dot3cfg.dll
+ 2011-04-13 07:53 . 2010-11-20 12:18 91136 c:\windows\SysWOW64\dot3api.dll
+ 2011-04-13 10:45 . 2011-03-03 05:36 28672 c:\windows\SysWOW64\dnscacheugc.exe
- 2009-07-13 23:38 . 2009-07-14 01:14 28672 c:\windows\SysWOW64\dnscacheugc.exe
- 2009-07-13 23:18 . 2009-07-14 01:15 89600 c:\windows\SysWOW64\Dism\LogProvider.dll
+ 2011-04-13 07:51 . 2010-11-20 12:19 89600 c:\windows\SysWOW64\Dism\LogProvider.dll
- 2009-07-13 23:18 . 2009-07-14 01:15 49152 c:\windows\SysWOW64\Dism\FolderProvider.dll
+ 2011-04-13 07:51 . 2010-11-20 12:19 49152 c:\windows\SysWOW64\Dism\FolderProvider.dll
- 2009-07-13 23:18 . 2009-07-14 01:14 82944 c:\windows\SysWOW64\Dism\DismHost.exe
+ 2011-04-13 07:51 . 2010-11-20 12:17 82944 c:\windows\SysWOW64\Dism\DismHost.exe
+ 2011-04-13 07:51 . 2010-11-20 12:18 50688 c:\windows\SysWOW64\Dism\DismCorePS.dll
+ 2011-04-13 07:52 . 2010-11-20 12:18 80384 c:\windows\SysWOW64\davclnt.dll
- 2011-02-09 08:11 . 2010-12-21 05:34 80384 c:\windows\SysWOW64\davclnt.dll
+ 2011-04-13 07:51 . 2010-11-20 12:18 23040 c:\windows\SysWOW64\cscdll.dll
- 2009-07-13 23:14 . 2009-07-14 01:15 23040 c:\windows\SysWOW64\cscdll.dll
- 2009-07-13 23:14 . 2009-07-14 01:15 34816 c:\windows\SysWOW64\cscapi.dll
+ 2011-04-13 07:51 . 2010-11-20 12:18 34816 c:\windows\SysWOW64\cscapi.dll
+ 2011-04-13 07:51 . 2010-11-20 12:54 69632 c:\windows\SysWOW64\cs\AuthFWWizFwk.Resources.dll
- 2009-12-26 01:01 . 2009-12-26 01:01 69632 c:\windows\SysWOW64\cs\AuthFWWizFwk.Resources.dll
+ 2011-04-13 07:51 . 2010-11-20 12:18 17408 c:\windows\SysWOW64\credssp.dll
+ 2009-07-14 04:54 . 2011-04-13 11:10 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2011-04-10 21:00 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2011-04-13 11:10 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-04-10 21:00 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-04-10 21:00 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-04-13 11:10 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-13 23:54 . 2009-07-14 01:14 84992 c:\windows\SysWOW64\cmstp.exe
+ 2011-04-13 07:51 . 2010-11-20 12:17 84992 c:\windows\SysWOW64\cmstp.exe
- 2009-07-13 23:36 . 2009-07-14 01:15 65024 c:\windows\SysWOW64\CertPolEng.dll
+ 2011-04-13 07:51 . 2010-11-20 12:18 65024 c:\windows\SysWOW64\CertPolEng.dll
- 2009-07-14 00:05 . 2009-07-14 01:15 66560 c:\windows\SysWOW64\cca.dll
+ 2011-04-13 07:51 . 2010-11-20 12:18 66560 c:\windows\SysWOW64\cca.dll
+ 2011-04-13 07:51 . 2010-11-20 12:18 73216 c:\windows\SysWOW64\cabinet.dll
+ 2011-04-13 07:51 . 2010-11-20 12:18 11264 c:\windows\SysWOW64\C_ISCII.DLL
+ 2011-04-13 07:51 . 2010-11-20 12:18 10752 c:\windows\SysWOW64\browseui.dll
+ 2011-04-13 07:51 . 2010-11-20 12:18 41984 c:\windows\SysWOW64\browcli.dll
+ 2011-04-13 07:51 . 2010-11-20 12:18 19456 c:\windows\SysWOW64\bitsperf.dll
+ 2011-04-13 07:51 . 2010-11-20 12:18 28160 c:\windows\SysWOW64\AzSqlExt.dll
+ 2011-04-13 07:51 . 2010-11-20 12:18 91648 c:\windows\SysWOW64\avifil32.dll
- 2010-06-14 10:38 . 2009-12-19 09:02 91648 c:\windows\SysWOW64\avifil32.dll
- 2011-02-09 08:10 . 2011-01-07 07:27 34304 c:\windows\SysWOW64\atmlib.dll
+ 2011-04-13 10:45 . 2011-02-19 06:30 34304 c:\windows\SysWOW64\atmlib.dll
+ 2011-04-13 07:51 . 2010-11-20 12:18 67584 c:\windows\SysWOW64\asycfilt.dll
- 2010-06-14 10:39 . 2010-03-05 07:42 67584 c:\windows\SysWOW64\asycfilt.dll
+ 2011-04-13 07:51 . 2010-11-20 12:18 70656 c:\windows\SysWOW64\amstream.dll
- 2009-07-14 00:03 . 2009-07-14 01:14 70656 c:\windows\SysWOW64\amstream.dll
+ 2011-04-13 07:51 . 2010-11-20 12:18 45568 c:\windows\SysWOW64\acppage.dll
- 2009-07-13 23:26 . 2009-07-14 01:14 45568 c:\windows\SysWOW64\acppage.dll
- 2009-07-14 00:12 . 2009-07-14 01:41 48640 c:\windows\system32\wwanprotdim.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 48640 c:\windows\system32\wwanprotdim.dll
- 2009-07-14 00:34 . 2009-07-14 01:41 37376 c:\windows\system32\wups2.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 37376 c:\windows\system32\wups2.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 33280 c:\windows\system32\wups.dll
- 2009-07-14 00:34 . 2009-07-14 01:41 98304 c:\windows\system32\wudriver.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 98304 c:\windows\system32\wudriver.dll
+ 2011-04-13 07:52 . 2010-11-20 13:27 78848 c:\windows\system32\WUDFSvc.dll
- 2009-07-14 00:06 . 2009-07-14 01:41 44544 c:\windows\system32\WUDFCoinstaller.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 44544 c:\windows\system32\WUDFCoinstaller.dll
+ 2011-04-13 07:51 . 2010-11-20 13:25 51200 c:\windows\system32\wuauclt.exe
- 2009-07-14 00:34 . 2009-07-14 01:39 51200 c:\windows\system32\wuauclt.exe
- 2009-07-14 00:34 . 2009-07-14 01:39 36864 c:\windows\system32\wuapp.exe
+ 2011-04-13 07:51 . 2010-11-20 13:25 36864 c:\windows\system32\wuapp.exe
- 2009-07-14 00:10 . 2009-07-14 01:41 67072 c:\windows\system32\wsnmp32.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 67072 c:\windows\system32\wsnmp32.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 13824 c:\windows\system32\wshirda.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 47104 c:\windows\system32\wshbth.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 26112 c:\windows\system32\wsdchngr.dll
- 2011-02-09 08:11 . 2010-12-21 06:16 97280 c:\windows\system32\wscsvc.dll
+ 2009-07-13 23:48 . 2009-07-14 01:41 97280 c:\windows\system32\wscsvc.dll
+ 2011-04-13 07:52 . 2010-11-20 13:27 63488 c:\windows\system32\wscapi.dll
- 2009-07-13 23:26 . 2009-07-14 01:41 13312 c:\windows\system32\wow64cpu.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 13312 c:\windows\system32\wow64cpu.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 71680 c:\windows\system32\wkscli.dll
- 2009-07-13 23:53 . 2009-07-14 01:41 71680 c:\windows\system32\wkscli.dll
+ 2011-04-13 07:51 . 2010-11-20 13:25 26112 c:\windows\system32\WerFaultSecure.exe
- 2009-07-13 23:40 . 2009-07-14 01:39 26112 c:\windows\system32\WerFaultSecure.exe
+ 2011-04-13 07:51 . 2010-11-20 13:27 36352 c:\windows\system32\wdiasqmmodule.dll
+ 2009-12-26 00:54 . 2011-04-13 13:41 59316 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-04-13 13:41 33346 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2010-06-09 12:25 . 2011-04-13 13:41 10584 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2835324808-1647480109-3611849097-1000_UserData.bin
+ 2011-04-13 07:51 . 2010-11-20 13:27 61952 c:\windows\system32\WavDest.dll
- 2009-07-14 00:25 . 2009-07-14 01:41 61952 c:\windows\system32\WavDest.dll
- 2009-07-13 23:36 . 2009-07-14 01:41 61952 c:\windows\system32\vss_ps.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 61952 c:\windows\system32\vss_ps.dll
+ 2011-04-13 07:52 . 2010-11-20 13:27 38912 c:\windows\system32\vpnikeapi.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 68096 c:\windows\system32\vfwwdm32.dll
- 2009-07-14 00:18 . 2009-07-14 01:41 68096 c:\windows\system32\vfwwdm32.dll
+ 2011-04-13 07:52 . 2010-11-20 13:25 30720 c:\windows\system32\userinit.exe
+ 2011-04-13 07:51 . 2010-11-20 13:27 84480 c:\windows\system32\UserAccountControlSettings.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 73216 c:\windows\system32\unimdmat.dll
- 2009-07-14 00:10 . 2009-07-14 01:41 73216 c:\windows\system32\unimdmat.dll
- 2009-07-13 23:35 . 2009-07-14 01:41 59904 c:\windows\system32\umb.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 59904 c:\windows\system32\umb.dll
+ 2011-04-13 07:51 . 2010-11-20 13:25 58368 c:\windows\system32\tzutil.exe
+ 2011-04-13 07:52 . 2010-11-20 13:27 40960 c:\windows\system32\TsUsbGDCoInstaller.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 86016 c:\windows\system32\TSpkg.dll
- 2009-07-13 23:50 . 2009-07-14 01:41 86016 c:\windows\system32\TSpkg.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 44032 c:\windows\system32\tsgqec.dll
- 2009-07-14 00:17 . 2009-07-14 01:41 44032 c:\windows\system32\tsgqec.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 14848 c:\windows\system32\tsbyuv.dll
- 2010-06-14 10:38 . 2009-12-19 09:50 14848 c:\windows\system32\tsbyuv.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 21504 c:\windows\system32\TRAPI.dll
- 2009-07-14 00:16 . 2009-07-14 01:41 73728 c:\windows\system32\tlscsp.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 73728 c:\windows\system32\tlscsp.dll
- 2009-07-13 23:31 . 2009-07-14 01:39 69120 c:\windows\system32\taskhost.exe
+ 2011-04-13 07:52 . 2010-11-20 13:25 69120 c:\windows\system32\taskhost.exe
+ 2011-04-13 07:51 . 2010-11-20 13:25 63488 c:\windows\system32\takeown.exe
+ 2011-04-13 07:52 . 2010-11-20 13:27 92672 c:\windows\system32\TabSvc.dll
+ 2011-04-13 07:51 . 2010-11-20 13:25 78848 c:\windows\system32\tabcal.exe
- 2009-07-14 00:03 . 2009-07-14 01:39 78848 c:\windows\system32\tabcal.exe
+ 2011-04-13 07:51 . 2010-11-20 13:27 17408 c:\windows\system32\syssetup.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 29184 c:\windows\system32\sspisrv.dll
- 2009-07-13 23:53 . 2009-07-14 01:41 13312 c:\windows\system32\sscore.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 13312 c:\windows\system32\sscore.dll
- 2009-07-13 23:29 . 2009-07-14 01:41 18944 c:\windows\system32\spopk.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 18944 c:\windows\system32\spopk.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 39424 c:\windows\system32\spool\prtprocs\x64\winprint.dll
- 2009-07-14 00:39 . 2009-07-14 01:41 39424 c:\windows\system32\spool\prtprocs\x64\winprint.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 78848 c:\windows\system32\spbcd.dll
- 2009-07-13 23:29 . 2009-07-14 01:41 78848 c:\windows\system32\spbcd.dll
- 2011-02-09 08:11 . 2010-12-21 06:15 15360 c:\windows\system32\slwga.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 15360 c:\windows\system32\slwga.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 24064 c:\windows\system32\sisbkup.dll
- 2009-07-13 23:23 . 2009-07-14 01:41 24064 c:\windows\system32\sisbkup.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 24064 c:\windows\system32\schedcli.dll
- 2009-07-13 23:53 . 2009-07-14 01:41 24064 c:\windows\system32\schedcli.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 11264 c:\windows\system32\shunimpl.dll
- 2009-07-13 23:55 . 2009-07-14 01:41 37376 c:\windows\system32\shimgvw.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 37376 c:\windows\system32\shimgvw.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 28160 c:\windows\system32\shgina.dll
- 2009-07-13 23:55 . 2009-07-14 01:41 28160 c:\windows\system32\shgina.dll
+ 2011-04-13 07:52 . 2010-11-20 13:25 88576 c:\windows\system32\setupcl.exe
+ 2011-04-13 07:52 . 2010-11-20 13:27 57856 c:\windows\system32\Setup\pbkmigr.dll
+ 2011-04-13 08:36 . 2011-04-13 08:36 91648 c:\windows\system32\SetIEInstalledDate.exe
+ 2011-04-13 07:51 . 2010-11-20 13:27 63488 c:\windows\system32\setbcdlocale.dll
- 2009-07-13 23:50 . 2009-07-14 01:41 28160 c:\windows\system32\secur32.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 28160 c:\windows\system32\secur32.dll
- 2009-07-13 23:53 . 2009-07-14 01:41 30720 c:\windows\system32\seclogon.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 30720 c:\windows\system32\seclogon.dll
+ 2011-04-13 07:52 . 2010-11-20 13:27 67584 c:\windows\system32\samcli.dll
+ 2011-04-13 07:51 . 2010-11-20 13:25 56832 c:\windows\system32\runonce.exe
- 2009-07-13 23:57 . 2009-07-14 01:39 56832 c:\windows\system32\runonce.exe
- 2010-08-11 13:13 . 2010-06-19 06:53 52224 c:\windows\system32\rtutils.dll
+ 2011-04-13 07:52 . 2010-11-20 13:27 52224 c:\windows\system32\rtutils.dll
+ 2011-04-13 07:52 . 2010-11-20 13:27 65536 c:\windows\system32\RpcRtRemote.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 10752 c:\windows\system32\riched32.dll
+ 2011-04-13 07:51 . 2010-11-20 13:25 51712 c:\windows\system32\repair-bde.exe
- 2009-07-13 23:22 . 2009-07-14 01:39 51712 c:\windows\system32\repair-bde.exe
+ 2011-04-13 07:51 . 2010-11-20 13:25 43008 c:\windows\system32\relog.exe
+ 2011-04-13 08:36 . 2011-04-13 08:36 89088 c:\windows\system32\RegisterIEPKEYs.exe
+ 2011-04-13 07:52 . 2010-11-20 13:27 95232 c:\windows\system32\regapi.dll
+ 2011-04-13 07:52 . 2010-11-20 13:27 77312 c:\windows\system32\rdpwsx.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 23040 c:\windows\system32\rdprefdrvapi.dll
- 2009-07-14 00:16 . 2009-07-14 01:41 23040 c:\windows\system32\rdprefdrvapi.dll
- 2009-07-14 00:17 . 2009-07-14 01:41 68096 c:\windows\system32\rdpd3d.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 68096 c:\windows\system32\rdpd3d.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 10240 c:\windows\system32\rdpcfgex.dll
- 2009-07-14 00:17 . 2009-07-14 01:41 10240 c:\windows\system32\rdpcfgex.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 79872 c:\windows\system32\QCLIPROV.DLL
- 2009-07-14 00:07 . 2009-07-14 01:41 79872 c:\windows\system32\QCLIPROV.DLL
+ 2011-04-13 07:52 . 2010-11-20 13:25 31744 c:\windows\system32\proquota.exe
+ 2011-04-13 07:51 . 2010-11-20 13:27 33792 c:\windows\system32\profprov.dll
- 2009-07-14 00:39 . 2009-07-14 01:41 48128 c:\windows\system32\PrintIsolationProxy.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 48128 c:\windows\system32\PrintIsolationProxy.dll
+ 2011-04-13 07:51 . 2010-11-20 13:25 31232 c:\windows\system32\prevhost.exe
- 2009-07-13 23:55 . 2009-07-14 01:39 31232 c:\windows\system32\prevhost.exe
+ 2011-04-13 07:51 . 2010-11-20 13:25 62976 c:\windows\system32\PnPUnattend.exe
+ 2011-04-13 08:36 . 2011-04-13 08:36 65024 c:\windows\system32\pngfilt.dll
+ 2011-04-13 07:51 . 2010-11-20 13:12 35328 c:\windows\system32\pifmgr.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 57856 c:\windows\system32\oobe\spprgrss.dll
- 2009-07-13 23:57 . 2009-07-14 01:39 71168 c:\windows\system32\oobe\msoobe.exe
+ 2011-04-13 07:51 . 2010-11-20 13:24 71168 c:\windows\system32\oobe\msoobe.exe
+ 2011-04-13 07:51 . 2010-11-20 13:27 53248 c:\windows\system32\odbcconf.dll
- 2009-07-14 00:28 . 2009-07-14 01:41 53248 c:\windows\system32\odbcconf.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 15360 c:\windows\system32\nrpsrv.dll
+ 2011-04-13 07:51 . 2010-11-20 13:13 69120 c:\windows\system32\nlsbres.dll
+ 2011-04-13 07:52 . 2010-11-20 13:27 70656 c:\windows\system32\nlaapi.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 29184 c:\windows\system32\netutils.dll
- 2009-07-13 23:53 . 2009-07-14 01:41 72704 c:\windows\system32\netapi32.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 72704 c:\windows\system32\netapi32.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 66048 c:\windows\system32\ncryptui.dll
- 2009-07-13 23:49 . 2009-07-14 01:41 66048 c:\windows\system32\ncryptui.dll
+ 2011-04-13 07:52 . 2010-11-20 13:27 90112 c:\windows\system32\nci.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 72192 c:\windows\system32\napdsnap.dll
- 2009-07-14 00:09 . 2009-07-14 01:51 50176 c:\windows\system32\NAPCRYPT.DLL
+ 2011-04-13 07:51 . 2010-11-20 13:44 50176 c:\windows\system32\NAPCRYPT.DLL
+ 2011-04-13 07:51 . 2010-11-20 13:25 51712 c:\windows\system32\MultiDigiMon.exe
- 2009-07-14 00:03 . 2009-07-14 01:39 51712 c:\windows\system32\MultiDigiMon.exe
+ 2011-04-13 07:51 . 2010-11-20 13:27 16896 c:\windows\system32\muifontsetup.dll
- 2010-06-23 13:01 . 2009-11-25 10:47 11600 c:\windows\system32\MUI\0409\mscorees.dll
+ 2011-04-13 07:51 . 2010-11-05 01:57 11600 c:\windows\system32\MUI\0409\mscorees.dll
- 2009-12-26 01:02 . 2009-12-26 01:02 12112 c:\windows\system32\MUI\0405\mscorees.dll
+ 2011-04-13 07:51 . 2010-11-05 01:54 12112 c:\windows\system32\MUI\0405\mscorees.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 25600 c:\windows\system32\msyuv.dll
- 2010-06-14 10:38 . 2009-12-19 09:47 38912 c:\windows\system32\msvidc32.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 38912 c:\windows\system32\msvidc32.dll
- 2010-06-14 10:38 . 2009-12-19 09:47 16384 c:\windows\system32\msrle32.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 16384 c:\windows\system32\msrle32.dll
+ 2011-04-13 08:36 . 2011-04-13 08:36 48640 c:\windows\system32\mshtmler.dll
+ 2011-04-13 08:36 . 2011-04-13 08:36 96256 c:\windows\system32\mshtmled.dll
+ 2011-04-13 08:36 . 2011-04-13 08:36 12288 c:\windows\system32\mshta.exe
+ 2011-04-13 08:36 . 2011-04-13 08:36 10752 c:\windows\system32\msfeedssync.exe
+ 2011-04-13 08:36 . 2011-04-13 08:36 55296 c:\windows\system32\msfeedsbs.dll
+ 2011-04-13 07:51 . 2010-11-20 13:27 35840 c:\windows\system32\msdmo.dll
- 2009-12-28 17:27 . 2009-08-29 07:50 46592 c:\windows\system32\msasn1.dll
+ 2011-04-13 07:52 . 2010-11-20 13:27 46592 c:\windows\system32\msasn1.dll
+ 2011-04-13 07:52 . 2010-11-20 13:26 41472 c:\windows\system32\mimefilt.dll
+ 2011-04-13 07:52 . 2010-11-20 13:27 57856 c:\windows\system32\migration\WSMT\rras\replacementmanifests\Microsoft-Windows-RasApi-MigPlugin\pbkmigr-Mig.dll
+ 2011-04-13 08:36 . 2011-04-13 08:36 86528 c:\windows\system32\migration\WininetPlugin.dll

TravisX90
Level 1
Level 1
Příspěvky: 54
Registrován: květen 10
Pohlaví: Muž
Stav:
Offline

Re: Preventivní kontrola logu HJT

Příspěvekod TravisX90 » 17 dub 2011 15:08

+ 2011-04-13 07:51 . 2010-11-20 13:26 84992 c:\windows\system32\Mcx2Svc.dll
+ 2011-04-13 07:51 . 2010-11-20 13:26 41472 c:\windows\system32\mciqtz32.dll
- 2009-07-14 00:18 . 2009-07-14 01:41 41472 c:\windows\system32\mciqtz32.dll
+ 2011-04-13 07:51 . 2010-11-20 13:26 91648 c:\windows\system32\mapistub.dll
+ 2011-04-13 07:51 . 2010-11-20 13:26 91648 c:\windows\system32\mapi32.dll
+ 2011-04-13 07:51 . 2010-11-20 13:24 79872 c:\windows\system32\manage-bde.exe
- 2009-07-13 23:22 . 2009-07-14 01:39 79872 c:\windows\system32\manage-bde.exe
+ 2011-04-13 07:51 . 2010-11-20 13:26 48640 c:\windows\system32\luainstall.dll
+ 2011-04-13 07:52 . 2010-11-20 13:26 50176 c:\windows\system32\lsmproxy.dll
- 2009-07-13 23:52 . 2009-07-14 01:39 27648 c:\windows\system32\LogonUI.exe
+ 2011-04-13 07:51 . 2010-11-20 13:24 27648 c:\windows\system32\LogonUI.exe
+ 2011-04-13 08:36 . 2011-04-13 08:36 30720 c:\windows\system32\licmgr10.dll
+ 2011-04-13 07:51 . 2010-11-20 13:26 90624 c:\windows\system32\KMSVC.DLL
- 2009-07-14 00:07 . 2009-07-14 01:41 90624 c:\windows\system32\KMSVC.DLL
+ 2011-04-13 08:36 . 2011-04-13 08:36 85504 c:\windows\system32\jsproxy.dll
+ 2011-04-13 07:51 . 2010-11-20 13:26 54272 c:\windows\system32\iyuv_32.dll
- 2010-06-14 10:38 . 2009-12-19 09:46 54272 c:\windows\system32\iyuv_32.dll
+ 2011-04-13 07:51 . 2010-11-20 13:24 91648 c:\windows\system32\isoburn.exe
+ 2011-04-13 07:51 . 2010-11-20 13:26 37376 c:\windows\system32\iscsium.dll
+ 2011-04-13 07:51 . 2010-11-20 13:26 65536 c:\windows\system32\inetmib1.dll
+ 2011-04-13 08:36 . 2011-04-13 08:36 49664 c:\windows\system32\imgutil.dll
+ 2011-04-13 07:51 . 2010-11-20 13:26 76800 c:\windows\system32\imagehlp.dll
+ 2011-04-13 08:36 . 2011-04-13 08:36 85504 c:\windows\system32\iesetup.dll
+ 2011-04-13 08:36 . 2011-04-13 08:36 39936 c:\windows\system32\iernonce.dll
+ 2011-04-13 08:36 . 2011-04-13 08:36 89088 c:\windows\system32\ie4uinit.exe
+ 2011-04-13 08:36 . 2011-04-13 08:36 82432 c:\windows\system32\icardie.dll
+ 2011-04-13 07:51 . 2010-11-20 13:24 36864 c:\windows\system32\choice.exe
+ 2011-04-13 07:51 . 2010-11-20 13:26 45056 c:\windows\system32\httpapi.dll
- 2009-07-13 23:21 . 2009-07-14 01:41 45056 c:\windows\system32\httpapi.dll
- 2009-07-13 23:55 . 2009-07-14 01:41 27136 c:\windows\system32\HotStartUserAgent.dll
+ 2011-04-13 07:51 . 2010-11-20 13:26 27136 c:\windows\system32\HotStartUserAgent.dll
- 2009-07-14 00:01 . 2009-07-14 01:40 78848 c:\windows\system32\hbaapi.dll
+ 2011-04-13 07:52 . 2010-11-20 13:26 78848 c:\windows\system32\hbaapi.dll
+ 2011-04-13 07:51 . 2010-11-20 13:24 18432 c:\windows\system32\FXSUNATD.exe
+ 2011-04-13 07:51 . 2010-11-20 13:26 41984 c:\windows\system32\FXSMON.dll
+ 2011-04-13 07:51 . 2010-11-20 13:24 48128 c:\windows\system32\ftp.exe
- 2009-07-14 00:10 . 2009-07-14 01:39 48128 c:\windows\system32\ftp.exe
+ 2011-04-13 07:51 . 2010-11-20 13:24 17920 c:\windows\system32\fixmapi.exe
+ 2011-04-13 07:51 . 2010-11-20 13:24 71168 c:\windows\system32\findstr.exe
+ 2011-04-13 07:51 . 2010-11-20 13:26 74240 c:\windows\system32\fdProxy.dll
+ 2011-04-13 07:52 . 2010-11-20 13:26 72192 c:\windows\system32\fdeploy.dll
+ 2011-04-13 07:51 . 2010-11-20 13:26 25600 c:\windows\system32\elsTrans.dll
+ 2011-04-13 07:51 . 2010-11-20 13:26 36864 c:\windows\system32\dsauth.dll
+ 2009-07-14 05:30 . 2011-04-13 08:49 86016 c:\windows\system32\DriverStore\infpub.dat
- 2009-07-14 05:30 . 2011-02-01 11:13 86016 c:\windows\system32\DriverStore\infpub.dat
+ 2011-04-13 07:51 . 2010-11-20 13:27 83968 c:\windows\system32\DriverStore\FileRepository\wpdcomp.inf_amd64_neutral_11bbf54c8508434e\Wpdcomp.dll
+ 2011-04-13 07:52 . 2010-11-20 10:43 41984 c:\windows\system32\DriverStore\FileRepository\winusb.inf_amd64_neutral_6cb50ae9f480775b\winusb.sys
+ 2011-04-13 07:52 . 2010-11-20 10:44 91648 c:\windows\system32\DriverStore\FileRepository\usbstor.inf_amd64_neutral_0725c2806a159a9d\USBSTOR.SYS
+ 2009-07-14 00:06 . 2009-07-14 00:06 30720 c:\windows\system32\DriverStore\FileRepository\usbport.inf_amd64_neutral_f935002f367d5bb0\usbuhci.sys
+ 2009-07-14 00:06 . 2009-07-14 00:06 25600 c:\windows\system32\DriverStore\FileRepository\usbport.inf_amd64_neutral_f935002f367d5bb0\usbohci.sys
+ 2011-04-13 07:52 . 2010-11-20 10:43 52224 c:\windows\system32\DriverStore\FileRepository\usbport.inf_amd64_neutral_f935002f367d5bb0\usbehci.sys
+ 2011-04-13 07:51 . 2010-11-20 10:44 98816 c:\windows\system32\DriverStore\FileRepository\usb.inf_amd64_neutral_269d7150439b3372\usbccgp.sys
+ 2011-04-13 07:51 . 2010-11-20 10:44 48640 c:\windows\system32\DriverStore\FileRepository\umbus.inf_amd64_neutral_2d4257afa2e35253\umbus.sys
+ 2011-04-13 07:54 . 2010-11-20 11:07 31232 c:\windows\system32\DriverStore\FileRepository\tsgenericusbdriver.inf_amd64_neutral_24c807694f614911\TsUsbGD.sys
+ 2011-04-13 07:52 . 2010-11-20 10:43 41984 c:\windows\system32\DriverStore\FileRepository\transfercable.inf_amd64_neutral_82f4c743c8996d67\amd64\winusb.sys
+ 2011-04-13 07:51 . 2010-11-20 10:34 14336 c:\windows\system32\DriverStore\FileRepository\sffdisk.inf_amd64_neutral_d2425e60845d17d3\sffp_sd.sys
+ 2009-07-14 00:01 . 2009-07-14 00:01 13824 c:\windows\system32\DriverStore\FileRepository\sffdisk.inf_amd64_neutral_d2425e60845d17d3\sffp_mmc.sys
+ 2009-07-14 00:01 . 2009-07-14 00:01 14336 c:\windows\system32\DriverStore\FileRepository\sffdisk.inf_amd64_neutral_d2425e60845d17d3\sffdisk.sys
+ 2011-04-13 07:51 . 2010-11-20 13:27 22016 c:\windows\system32\DriverStore\FileRepository\ntprint.inf_amd64_neutral_4616c3de1949be6d\Amd64\PJLMON.DLL
+ 2009-07-13 23:19 . 2009-07-14 01:45 17488 c:\windows\system32\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\viaide.sys
+ 2009-07-13 23:19 . 2009-07-14 01:45 48720 c:\windows\system32\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\pciidex.sys
+ 2009-07-13 23:19 . 2009-07-14 01:45 12352 c:\windows\system32\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\pciide.sys
+ 2011-04-13 07:52 . 2010-11-20 13:33 31104 c:\windows\system32\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\msahci.sys
+ 2009-07-13 23:19 . 2009-07-14 01:48 16960 c:\windows\system32\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\intelide.sys
+ 2009-07-13 23:19 . 2009-07-14 01:52 17488 c:\windows\system32\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\cmdide.sys
+ 2009-07-13 23:19 . 2009-07-14 01:52 24128 c:\windows\system32\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
+ 2009-07-13 23:19 . 2009-07-14 01:52 15440 c:\windows\system32\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\amdide.sys
+ 2009-07-13 23:19 . 2009-07-14 01:52 15440 c:\windows\system32\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\aliide.sys
+ 2009-07-14 00:10 . 2009-07-14 00:10 24064 c:\windows\system32\DriverStore\FileRepository\modemcsa.inf_amd64_neutral_b64a610f1f09f267\MODEMCSA.sys
+ 2011-04-13 07:51 . 2010-11-20 10:34 12800 c:\windows\system32\DriverStore\FileRepository\mchgr.inf_amd64_neutral_407146dba80d1566\spctramc.sys
+ 2011-04-13 07:51 . 2010-11-20 10:34 15360 c:\windows\system32\DriverStore\FileRepository\mchgr.inf_amd64_neutral_407146dba80d1566\sonymc.sys
+ 2011-04-13 07:51 . 2010-11-20 10:34 12288 c:\windows\system32\DriverStore\FileRepository\mchgr.inf_amd64_neutral_407146dba80d1566\snyaitmc.sys
+ 2011-04-13 07:51 . 2010-11-20 10:34 12800 c:\windows\system32\DriverStore\FileRepository\mchgr.inf_amd64_neutral_407146dba80d1566\seaddsmc.sys
+ 2011-04-13 07:51 . 2010-11-20 10:34 11264 c:\windows\system32\DriverStore\FileRepository\mchgr.inf_amd64_neutral_407146dba80d1566\qntmmc.sys
+ 2011-04-13 07:51 . 2010-11-20 10:34 13824 c:\windows\system32\DriverStore\FileRepository\mchgr.inf_amd64_neutral_407146dba80d1566\qlstrmc.sys
+ 2011-04-13 07:51 . 2010-11-20 10:34 15360 c:\windows\system32\DriverStore\FileRepository\mchgr.inf_amd64_neutral_407146dba80d1566\powerfil.sys
+ 2011-04-13 07:51 . 2010-11-20 10:34 12800 c:\windows\system32\DriverStore\FileRepository\mchgr.inf_amd64_neutral_407146dba80d1566\pnrmc.sys
+ 2011-04-13 07:51 . 2010-11-20 10:34 14848 c:\windows\system32\DriverStore\FileRepository\mchgr.inf_amd64_neutral_407146dba80d1566\plasmc.sys
+ 2011-04-13 07:51 . 2010-11-20 10:34 12800 c:\windows\system32\DriverStore\FileRepository\mchgr.inf_amd64_neutral_407146dba80d1566\nsmmc.sys
+ 2011-04-13 07:51 . 2010-11-20 10:34 11264 c:\windows\system32\DriverStore\FileRepository\mchgr.inf_amd64_neutral_407146dba80d1566\m4mc.sys
+ 2011-04-13 07:51 . 2010-11-20 10:34 13824 c:\windows\system32\DriverStore\FileRepository\mchgr.inf_amd64_neutral_407146dba80d1566\libxprmc.sys
+ 2011-04-13 07:51 . 2010-11-20 10:34 12800 c:\windows\system32\DriverStore\FileRepository\mchgr.inf_amd64_neutral_407146dba80d1566\jvcmc.sys
+ 2011-04-13 07:51 . 2010-11-20 10:34 17920 c:\windows\system32\DriverStore\FileRepository\mchgr.inf_amd64_neutral_407146dba80d1566\hpmc.sys
+ 2011-04-13 07:51 . 2010-11-20 10:34 15360 c:\windows\system32\DriverStore\FileRepository\mchgr.inf_amd64_neutral_407146dba80d1566\examc.sys
+ 2011-04-13 07:51 . 2010-11-20 10:34 12288 c:\windows\system32\DriverStore\FileRepository\mchgr.inf_amd64_neutral_407146dba80d1566\elmsmc.sys
+ 2011-04-13 07:51 . 2010-11-20 10:34 13312 c:\windows\system32\DriverStore\FileRepository\mchgr.inf_amd64_neutral_407146dba80d1566\ddsmc.sys
+ 2011-04-13 07:51 . 2010-11-20 10:34 12288 c:\windows\system32\DriverStore\FileRepository\mchgr.inf_amd64_neutral_407146dba80d1566\breecemc.sys
+ 2011-04-13 07:51 . 2010-11-20 10:34 12800 c:\windows\system32\DriverStore\FileRepository\mchgr.inf_amd64_neutral_407146dba80d1566\atlmc.sys
+ 2011-04-13 07:51 . 2010-11-20 10:34 12800 c:\windows\system32\DriverStore\FileRepository\mchgr.inf_amd64_neutral_407146dba80d1566\adicvls.sys
+ 2011-04-13 07:51 . 2010-11-20 10:34 13824 c:\windows\system32\DriverStore\FileRepository\mchgr.inf_amd64_neutral_407146dba80d1566\adicsc.sys
+ 2011-04-13 07:51 . 2010-11-20 10:43 32768 c:\windows\system32\DriverStore\FileRepository\mdmcpq.inf_amd64_neutral_fbc4a14a6a13d0c8\usbser.sys
+ 2011-04-13 07:52 . 2010-11-20 13:34 71552 c:\windows\system32\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\volmgr.sys
+ 2009-07-14 00:01 . 2009-07-14 01:45 36432 c:\windows\system32\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\vdrvroot.sys
+ 2009-07-13 23:38 . 2009-07-14 01:45 64592 c:\windows\system32\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\ULIAGPKX.SYS
+ 2011-04-13 07:52 . 2010-11-20 13:33 63360 c:\windows\system32\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\termdd.sys
+ 2009-07-14 00:00 . 2009-07-14 01:45 12496 c:\windows\system32\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\swenum.sys
+ 2009-07-14 00:18 . 2009-07-14 01:45 24144 c:\windows\system32\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\streamci.dll
+ 2009-07-13 23:31 . 2009-07-14 01:48 32320 c:\windows\system32\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\mssmbios.sys
+ 2009-07-13 23:19 . 2009-07-14 01:48 15424 c:\windows\system32\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\msisadrv.sys
+ 2009-07-13 23:31 . 2009-07-14 01:48 20544 c:\windows\system32\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\isapnp.sys
+ 2009-07-13 23:38 . 2009-07-14 01:52 61008 c:\windows\system32\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
+ 2011-04-13 07:51 . 2010-11-20 10:33 33280 c:\windows\system32\DriverStore\FileRepository\keyboard.inf_amd64_neutral_0684fdc43059f486\kbdhid.sys
+ 2009-07-13 23:19 . 2009-07-14 01:48 50768 c:\windows\system32\DriverStore\FileRepository\keyboard.inf_amd64_neutral_0684fdc43059f486\kbdclass.sys
+ 2009-07-14 00:01 . 2009-07-14 01:28 16384 c:\windows\system32\DriverStore\FileRepository\iscsi.inf_amd64_neutral_2ef24e9270d8b2a9\iscsilog.dll
+ 2011-04-13 07:51 . 2010-11-20 10:04 78848 c:\windows\system32\DriverStore\FileRepository\ipmidrv.inf_amd64_neutral_1cb648411f252d13\IPMIDrv.sys
+ 2011-04-13 07:51 . 2010-11-20 10:43 30208 c:\windows\system32\DriverStore\FileRepository\input.inf_amd64_neutral_8693053514b10ee9\hidusb.sys
+ 2009-07-14 00:06 . 2009-07-14 00:06 32896 c:\windows\system32\DriverStore\FileRepository\input.inf_amd64_neutral_8693053514b10ee9\hidparse.sys
+ 2011-04-13 07:52 . 2010-11-20 10:43 76800 c:\windows\system32\DriverStore\FileRepository\input.inf_amd64_neutral_8693053514b10ee9\hidclass.sys
+ 2011-04-13 07:52 . 2010-11-20 13:33 78720 c:\windows\system32\DriverStore\FileRepository\hpsamd.inf_amd64_neutral_84ae149ecc9f8033\HpSAMD.sys
+ 2011-04-13 07:51 . 2010-11-20 10:32 19968 c:\windows\system32\DriverStore\FileRepository\dot4prt.inf_amd64_neutral_e7d3f62d0d4411db\Dot4Prt.sys
+ 2011-04-13 07:51 . 2010-11-20 10:33 38912 c:\windows\system32\DriverStore\FileRepository\compositebus.inf_amd64_neutral_b9280780a8000d4b\CompositeBus.sys
+ 2011-04-13 07:52 . 2010-11-20 10:44 80384 c:\windows\system32\DriverStore\FileRepository\bth.inf_amd64_neutral_e54666f6a3e5af91\BTHUSB.SYS
+ 2009-07-14 00:06 . 2009-07-14 00:06 41984 c:\windows\system32\DriverStore\FileRepository\bth.inf_amd64_neutral_e54666f6a3e5af91\bthenum.sys
+ 2009-07-13 21:59 . 2009-07-14 01:40 50688 c:\windows\system32\DriverStore\FileRepository\atiilhag.inf_amd64_neutral_0a660e899f5038a2\amdpcom64.dll
+ 2009-07-13 21:59 . 2009-07-14 01:40 50688 c:\windows\system32\DriverStore\FileRepository\atiilhag.inf_amd64_neutral_0a660e899f5038a2\amdpcom32.dll
+ 2011-04-13 07:52 . 2010-11-20 13:32 27008 c:\windows\system32\DriverStore\FileRepository\amdsata.inf_amd64_neutral_67db50590108ebd9\amdxata.sys
+ 2011-04-13 07:51 . 2010-11-20 09:30 12800 c:\windows\system32\DriverStore\FileRepository\acpipmi.inf_amd64_neutral_256ad642985694b3\acpipmi.sys
+ 2009-07-13 23:31 . 2009-07-13 23:31 14336 c:\windows\system32\DriverStore\FileRepository\acpi.inf_amd64_neutral_aed2e7a487803437\wmiacpi.sys
+ 2009-07-14 00:06 . 2009-07-14 00:06 72832 c:\windows\system32\DriverStore\FileRepository\1394.inf_amd64_neutral_0b11366838152a76\ohci1394.sys
+ 2009-07-14 00:06 . 2009-07-14 00:06 68096 c:\windows\system32\DriverStore\FileRepository\1394.inf_amd64_neutral_0b11366838152a76\1394bus.sys
+ 2011-04-13 07:52 . 2010-11-20 10:43 41984 c:\windows\system32\drivers\winusb.sys
- 2009-07-14 00:10 . 2009-07-14 00:10 88576 c:\windows\system32\drivers\wanarp.sys
+ 2011-04-13 07:52 . 2010-11-20 10:52 88576 c:\windows\system32\drivers\wanarp.sys
+ 2011-04-13 07:52 . 2010-11-20 13:34 71552 c:\windows\system32\drivers\volmgr.sys
+ 2011-04-13 07:52 . 2010-11-20 10:44 91648 c:\windows\system32\drivers\USBSTOR.SYS
+ 2011-04-13 07:51 . 2010-11-20 11:37 31744 c:\windows\system32\drivers\usbrpm.sys
- 2009-07-14 00:35 . 2009-07-14 00:35 31744 c:\windows\system32\drivers\usbrpm.sys
+ 2011-04-13 07:52 . 2010-11-20 10:43 52224 c:\windows\system32\drivers\usbehci.sys
+ 2011-04-13 07:51 . 2010-11-20 10:44 98816 c:\windows\system32\drivers\usbccgp.sys
- 2009-07-14 00:06 . 2009-07-14 00:06 98816 c:\windows\system32\drivers\usbccgp.sys
- 2009-07-14 00:06 . 2009-07-14 00:06 32896 c:\windows\system32\drivers\USBCAMD2.sys
+ 2011-04-13 07:51 . 2010-11-20 10:44 32896 c:\windows\system32\drivers\USBCAMD2.sys
+ 2011-04-13 07:51 . 2010-11-20 10:44 48640 c:\windows\system32\drivers\umbus.sys
- 2009-07-14 00:06 . 2009-07-14 00:06 48640 c:\windows\system32\drivers\umbus.sys
+ 2011-04-13 07:52 . 2010-11-20 11:04 39424 c:\windows\system32\drivers\tssecsrv.sys
+ 2011-04-13 07:52 . 2010-11-20 13:33 63360 c:\windows\system32\drivers\termdd.sys
- 2009-07-13 23:21 . 2009-07-13 23:21 26624 c:\windows\system32\drivers\tdi.sys
+ 2011-04-13 07:51 . 2010-11-20 09:22 26624 c:\windows\system32\drivers\tdi.sys
+ 2011-04-13 07:51 . 2010-11-20 10:51 45056 c:\windows\system32\drivers\tcpipreg.sys
- 2010-07-13 18:43 . 2009-10-10 03:17 14336 c:\windows\system32\drivers\sffp_sd.sys
+ 2011-04-13 07:51 . 2010-11-20 10:34 14336 c:\windows\system32\drivers\sffp_sd.sys
- 2009-07-13 23:50 . 2009-07-13 23:50 29696 c:\windows\system32\drivers\scfilter.sys
+ 2011-04-13 07:51 . 2010-11-20 10:09 29696 c:\windows\system32\drivers\scfilter.sys
+ 2011-04-13 07:52 . 2010-11-20 13:33 75136 c:\windows\system32\drivers\partmgr.sys
+ 2011-04-13 07:51 . 2010-11-20 10:52 57856 c:\windows\system32\drivers\ndproxy.sys
- 2009-07-14 00:10 . 2009-07-14 00:10 57856 c:\windows\system32\drivers\ndproxy.sys
+ 2011-04-13 07:51 . 2010-11-20 10:50 56832 c:\windows\system32\drivers\ndisuio.sys
+ 2011-04-13 07:52 . 2010-11-20 13:33 31104 c:\windows\system32\drivers\msahci.sys
+ 2011-04-13 07:52 . 2010-11-20 13:33 94592 c:\windows\system32\drivers\mountmgr.sys
+ 2011-04-13 07:52 . 2010-11-20 13:33 95616 c:\windows\system32\drivers\ksecdd.sys
+ 2011-04-13 07:51 . 2010-11-20 10:33 33280 c:\windows\system32\drivers\kbdhid.sys
- 2009-07-14 00:00 . 2009-07-14 00:00 33280 c:\windows\system32\drivers\kbdhid.sys
- 2009-07-13 23:47 . 2009-07-13 23:47 78848 c:\windows\system32\drivers\IPMIDrv.sys
+ 2011-04-13 07:51 . 2010-11-20 10:04 78848 c:\windows\system32\drivers\IPMIDrv.sys
- 2009-07-14 00:10 . 2009-07-14 00:10 82944 c:\windows\system32\drivers\ipfltdrv.sys
+ 2011-04-13 07:52 . 2010-11-20 10:52 82944 c:\windows\system32\drivers\ipfltdrv.sys
+ 2011-04-13 07:52 . 2010-11-20 13:33 14720 c:\windows\system32\drivers\hwpolicy.sys
+ 2011-04-13 07:52 . 2010-11-20 13:33 78720 c:\windows\system32\drivers\HpSAMD.sys
+ 2011-04-13 07:51 . 2010-11-20 10:43 30208 c:\windows\system32\drivers\hidusb.sys
- 2009-07-14 00:06 . 2009-07-14 00:06 30208 c:\windows\system32\drivers\hidusb.sys
+ 2011-04-13 07:52 . 2010-11-20 10:43 76800 c:\windows\system32\drivers\hidclass.sys
+ 2011-04-13 07:52 . 2010-11-20 13:33 27520 c:\windows\system32\drivers\Diskdump.sys
- 2009-07-14 00:00 . 2009-07-14 00:00 38912 c:\windows\system32\drivers\CompositeBus.sys
+ 2011-04-13 07:51 . 2010-11-20 10:33 38912 c:\windows\system32\drivers\CompositeBus.sys
+ 2011-04-13 07:52 . 2010-11-20 10:44 80384 c:\windows\system32\drivers\BTHUSB.SYS
+ 2011-04-13 07:51 . 2010-11-20 10:14 61440 c:\windows\system32\drivers\appid.sys
- 2009-07-13 23:52 . 2009-07-13 23:52 61440 c:\windows\system32\drivers\appid.sys
+ 2011-04-13 07:52 . 2010-11-20 13:32 27008 c:\windows\system32\drivers\amdxata.sys
+ 2011-04-13 07:51 . 2010-11-20 09:30 12800 c:\windows\system32\drivers\acpipmi.sys
+ 2011-04-13 07:52 . 2010-11-20 13:26 69120 c:\windows\system32\dot3cfg.dll
+ 2011-04-13 07:52 . 2010-11-20 13:26 84992 c:\windows\system32\dot3api.dll
+ 2011-04-13 10:45 . 2011-03-03 06:21 30208 c:\windows\system32\dnscacheugc.exe
- 2009-07-13 23:54 . 2009-07-14 01:39 30208 c:\windows\system32\dnscacheugc.exe
+ 2011-04-13 07:51 . 2010-11-20 13:24 61440 c:\windows\system32\djoin.exe
- 2009-07-13 23:53 . 2009-07-14 01:39 61440 c:\windows\system32\djoin.exe
+ 2011-04-13 07:51 . 2010-11-20 13:25 30208 c:\windows\system32\cscdll.dll
- 2009-07-13 23:23 . 2009-07-14 01:40 30208 c:\windows\system32\cscdll.dll
+ 2011-04-13 07:51 . 2010-11-20 13:25 46080 c:\windows\system32\cscapi.dll
- 2009-07-13 23:24 . 2009-07-14 01:40 46080 c:\windows\system32\cscapi.dll
+ 2011-04-13 07:52 . 2010-11-20 13:25 22016 c:\windows\system32\credssp.dll
- 2010-01-13 14:29 . 2011-04-10 21:01 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-01-13 14:29 . 2011-04-13 13:47 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2011-04-10 21:01 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-04-13 13:47 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-04-13 07:51 . 2010-11-20 13:24 92160 c:\windows\system32\cmstp.exe
- 2009-07-14 00:10 . 2009-07-14 01:39 92160 c:\windows\system32\cmstp.exe
- 2009-07-13 23:50 . 2009-07-14 01:40 80384 c:\windows\system32\certprop.dll
+ 2011-04-13 07:51 . 2010-11-20 13:25 80384 c:\windows\system32\certprop.dll
+ 2011-04-13 07:51 . 2010-11-20 13:25 71680 c:\windows\system32\CertPolEng.dll
- 2009-07-13 23:52 . 2009-07-14 01:40 71680 c:\windows\system32\CertPolEng.dll
+ 2011-04-13 07:51 . 2010-11-20 13:25 95232 c:\windows\system32\cca.dll
+ 2011-04-13 07:51 . 2010-11-20 13:25 94720 c:\windows\system32\cabinet.dll
+ 2011-04-13 07:51 . 2010-11-20 13:25 13312 c:\windows\system32\C_ISCII.DLL
+ 2011-04-13 07:51 . 2010-11-20 13:25 14848 c:\windows\system32\BWUnpairElevated.dll
- 2009-07-13 23:57 . 2009-07-14 01:40 14848 c:\windows\system32\BWUnpairElevated.dll
+ 2011-04-13 07:51 . 2010-11-20 13:25 14336 c:\windows\system32\browseui.dll
+ 2011-04-13 07:51 . 2010-11-20 13:25 58880 c:\windows\system32\browcli.dll
+ 2011-04-13 07:51 . 2010-11-20 12:54 52736 c:\windows\system32\BlbEvents.dll
+ 2011-04-13 07:51 . 2010-11-20 13:25 24576 c:\windows\system32\bitsperf.dll
- 2009-07-13 23:50 . 2009-07-14 01:40 31744 c:\windows\system32\AzSqlExt.dll
+ 2011-04-13 07:51 . 2010-11-20 13:25 31744 c:\windows\system32\AzSqlExt.dll
+ 2011-04-13 10:45 . 2011-02-19 12:03 46080 c:\windows\system32\atmlib.dll
- 2011-02-09 08:10 . 2011-01-07 08:06 46080 c:\windows\system32\atmlib.dll
+ 2011-04-13 07:51 . 2010-11-20 13:25 84992 c:\windows\system32\asycfilt.dll
- 2010-06-14 10:39 . 2010-03-05 07:52 84992 c:\windows\system32\asycfilt.dll
+ 2011-04-13 07:51 . 2010-11-20 13:25 70656 c:\windows\system32\appinfo.dll
- 2009-07-14 00:18 . 2009-07-14 01:40 89088 c:\windows\system32\amstream.dll
+ 2011-04-13 07:51 . 2010-11-20 13:25 89088 c:\windows\system32\amstream.dll
- 2009-07-13 23:40 . 2009-07-14 01:40 53248 c:\windows\system32\acppage.dll
+ 2011-04-13 07:51 . 2010-11-20 13:25 53248 c:\windows\system32\acppage.dll
+ 2011-04-13 07:52 . 2010-11-20 13:25 67072 c:\windows\splwow64.exe
- 2010-06-14 10:42 . 2010-02-02 08:39 49664 c:\windows\servicing\GC64\tzupd.exe
+ 2011-04-13 07:51 . 2010-11-20 13:25 49664 c:\windows\servicing\GC64\tzupd.exe
+ 2009-07-14 04:46 . 2011-04-13 13:47 91888 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
+ 2010-06-13 21:04 . 2011-04-13 08:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-06-13 21:04 . 2011-04-10 20:11 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-06-13 21:04 . 2011-04-10 20:11 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-06-13 21:04 . 2011-04-13 08:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-03-18 12:27 . 2010-03-18 12:27 67920 c:\windows\Microsoft.NET\Framework64\v4.0.30319\nlssorting.dll
+ 2011-02-10 03:15 . 2011-02-10 03:15 67920 c:\windows\Microsoft.NET\Framework64\v4.0.30319\nlssorting.dll
+ 2011-04-13 07:52 . 2010-11-05 01:53 83792 c:\windows\Microsoft.NET\Framework64\v3.5\MSBuild.exe
- 2009-07-13 20:54 . 2009-06-10 20:31 91976 c:\windows\Microsoft.NET\Framework64\v3.5\EdmGen.exe
+ 2011-04-13 07:51 . 2010-11-05 01:53 91976 c:\windows\Microsoft.NET\Framework64\v3.5\EdmGen.exe
+ 2011-04-13 07:52 . 2010-11-05 01:53 71512 c:\windows\Microsoft.NET\Framework64\v3.5\DataSvcUtil.exe
+ 2011-04-13 07:51 . 2010-11-05 01:54 42848 c:\windows\Microsoft.NET\Framework64\v3.5\cs\MSBuild.resources.dll
- 2009-12-26 01:02 . 2009-12-26 01:02 42848 c:\windows\Microsoft.NET\Framework64\v3.5\cs\MSBuild.resources.dll
+ 2011-04-13 07:51 . 2010-11-05 01:54 18272 c:\windows\Microsoft.NET\Framework64\v3.5\cs\EdmGen.Resources.dll
+ 2011-04-13 07:51 . 2010-11-05 01:54 14696 c:\windows\Microsoft.NET\Framework64\v3.5\cs\DataSvcUtil.resources.dll
+ 2011-04-13 07:52 . 2010-11-05 01:53 38736 c:\windows\Microsoft.NET\Framework64\v3.5\AddInUtil.exe
- 2009-07-13 20:54 . 2009-06-10 20:31 38744 c:\windows\Microsoft.NET\Framework64\v3.5\AddInProcess32.exe
+ 2011-04-13 07:51 . 2010-11-05 01:53 38744 c:\windows\Microsoft.NET\Framework64\v3.5\AddInProcess32.exe
+ 2011-04-13 07:52 . 2010-11-05 01:53 38744 c:\windows\Microsoft.NET\Framework64\v3.5\AddInProcess.exe
+ 2011-04-13 07:52 . 2010-11-05 01:53 22368 c:\windows\Microsoft.NET\Framework64\v3.0\WPF\XamlViewer\XamlViewer_v0300.exe
+ 2011-04-13 07:52 . 2010-11-05 01:53 42856 c:\windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
+ 2011-04-13 07:52 . 2010-11-05 01:53 84808 c:\windows\Microsoft.NET\Framework64\v3.0\WPF\PenIMC.dll
+ 2011-04-13 07:51 . 2010-11-05 01:52 32768 c:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll
- 2009-07-14 01:01 . 2009-06-10 20:30 32768 c:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll
- 2009-07-14 01:01 . 2009-06-10 20:30 73728 c:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\System.ServiceModel.Install.dll
+ 2011-04-13 07:51 . 2010-11-05 01:52 73728 c:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\System.ServiceModel.Install.dll
- 2009-07-14 01:01 . 2009-06-10 20:30 94208 c:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMdiagnostics.dll
+ 2011-04-13 07:51 . 2010-11-05 01:52 94208 c:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMdiagnostics.dll
+ 2011-04-13 07:51 . 2010-11-05 01:54 38760 c:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\cs\WsatConfig.resources.dll
- 2009-12-26 01:02 . 2009-12-26 01:02 32768 c:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\cs\System.ServiceModel.Install.Resources.dll
+ 2011-04-13 07:51 . 2010-11-05 01:54 32768 c:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\cs\System.ServiceModel.Install.Resources.dll
+ 2011-04-13 07:51 . 2010-11-05 01:54 16232 c:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\cs\SMSvcHost.resources.dll
+ 2011-04-13 07:51 . 2010-11-05 01:54 34672 c:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\cs\ServiceModelReg.resources.dll
+ 2011-04-13 07:51 . 2010-11-05 01:54 28672 c:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\cs\Microsoft.Transactions.Bridge.Resources.dll
- 2009-12-26 01:02 . 2009-12-26 01:02 28672 c:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\cs\Microsoft.Transactions.Bridge.Resources.dll
+ 2011-04-13 07:51 . 2010-11-05 01:54 38760 c:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\cs\ComSvcConfig.resources.dll
+ 2011-04-13 07:52 . 2010-11-05 01:57 42328 c:\windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dll
+ 2011-04-13 07:51 . 2010-11-05 01:56 81920 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.Configuration.Install.dll
- 2009-07-13 20:37 . 2009-06-10 20:40 81920 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.Configuration.Install.dll
- 2009-07-13 20:37 . 2009-06-10 20:40 28672 c:\windows\Microsoft.NET\Framework64\v2.0.50727\RegSvcs.exe
+ 2011-04-13 07:51 . 2010-11-05 01:56 28672 c:\windows\Microsoft.NET\Framework64\v2.0.50727\RegSvcs.exe
- 2009-07-13 20:37 . 2009-06-10 20:40 49152 c:\windows\Microsoft.NET\Framework64\v2.0.50727\RegAsm.exe
+ 2011-04-13 07:51 . 2010-11-05 01:56 49152 c:\windows\Microsoft.NET\Framework64\v2.0.50727\RegAsm.exe
- 2009-12-26 01:02 . 2009-12-26 01:02 27984 c:\windows\Microsoft.NET\Framework64\v2.0.50727\MUI\0405\mscorsecr.dll
+ 2011-04-13 07:51 . 2010-11-05 01:54 27984 c:\windows\Microsoft.NET\Framework64\v2.0.50727\MUI\0405\mscorsecr.dll
+ 2011-04-13 07:51 . 2010-11-05 01:56 36688 c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorie.dll
- 2009-07-13 20:37 . 2009-06-10 20:39 36688 c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorie.dll
- 2009-07-13 20:37 . 2009-06-10 20:39 65536 c:\windows\Microsoft.NET\Framework64\v2.0.50727\MSBuild.exe
+ 2011-04-13 07:51 . 2010-11-05 01:56 65536 c:\windows\Microsoft.NET\Framework64\v2.0.50727\MSBuild.exe
- 2009-07-13 20:37 . 2009-06-10 20:39 77824 c:\windows\Microsoft.NET\Framework64\v2.0.50727\Microsoft.Build.Utilities.dll
+ 2011-04-13 07:51 . 2010-11-05 01:56 77824 c:\windows\Microsoft.NET\Framework64\v2.0.50727\Microsoft.Build.Utilities.dll
- 2009-07-13 20:37 . 2009-06-10 20:39 36864 c:\windows\Microsoft.NET\Framework64\v2.0.50727\Microsoft.Build.Framework.dll
+ 2011-04-13 07:51 . 2010-11-05 01:56 36864 c:\windows\Microsoft.NET\Framework64\v2.0.50727\Microsoft.Build.Framework.dll
- 2009-07-13 20:37 . 2009-06-10 20:39 89600 c:\windows\Microsoft.NET\Framework64\v2.0.50727\ISymWrapper.dll
+ 2011-04-13 07:51 . 2010-11-05 01:56 89600 c:\windows\Microsoft.NET\Framework64\v2.0.50727\ISymWrapper.dll
+ 2011-04-13 07:51 . 2010-11-05 01:56 24576 c:\windows\Microsoft.NET\Framework64\v2.0.50727\InstallUtil.exe
- 2009-07-13 20:37 . 2009-06-10 20:39 24576 c:\windows\Microsoft.NET\Framework64\v2.0.50727\InstallUtil.exe
+ 2011-04-13 07:52 . 2010-11-05 01:56 38216 c:\windows\Microsoft.NET\Framework64\v2.0.50727\cvtres.exe
- 2009-07-13 20:37 . 2009-06-10 20:39 38216 c:\windows\Microsoft.NET\Framework64\v2.0.50727\cvtres.exe


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: DotNetDotCom.org [Bot] a 35 hostů