Takze logy prikladam nize. Jen pri instalaci adobe mi to napsalo, ze "inicializace se nezdarila". Takze jsem ho nenainstaloval... Nevim.
Log hijackthis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:16:27, on 5.8.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ATKGFNEX\GFNEXSrv.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\ASUS\ATK Hotkey\MsgTranAgt.exe
C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
C:\Program Files\ASUS\ATK Hotkey\HControl.exe
C:\Program Files\ATKOSD2\ATKOSD2.exe
C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Documents and Settings\Sašenka\Local Settings\Data aplikací\Facebook\Update\FacebookUpdate.exe
C:\Documents and Settings\Sašenka\Local Settings\Data aplikací\Facebook\Messenger\2.1.4590.0\FacebookMessenger.exe
C:\Program Files\ASUS\ATK Hotkey\ATKOSD.exe
C:\Program Files\ASUS\ATK Hotkey\KBFiltr.exe
C:\Program Files\ASUS\ATK Hotkey\WDC.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Sašenka\Plocha\hijackthis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [MsgTranAgt] C:\Program Files\ASUS\ATK Hotkey\MsgTranAgt.exe
O4 - HKLM\..\Run: [HControlUser] C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [ATKHOTKEY] C:\Program Files\ASUS\ATK Hotkey\HControl.exe
O4 - HKLM\..\Run: [ATKOSD2] "C:\Program Files\ATKOSD2\ATKOSD2.exe"
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Power_Gear] C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe 1
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [Facebook Update] "C:\Documents and Settings\Sašenka\Local Settings\Data aplikací\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: CCC.lnk = ?
O4 - Startup: Facebook Messenger.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Sony Ericsson PCCompanion - Avanquest Software - C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
--
End of file - 7448 bytes
Poprosím o kontrolu logu-pomalý a sekající se notebook.Díky
Re: Poprosím o kontrolu logu-pomalý a sekající se notebook.D
Log ASWMBR:
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-08-05 19:46:18
-----------------------------
19:46:18.437 OS Version: Windows 5.1.2600 Service Pack 3
19:46:18.437 Number of processors: 2 586 0xF0D
19:46:18.437 ComputerName: ALEX UserName:
19:46:19.031 Initialize success
19:46:19.406 AVAST engine defs: 12080500
19:47:18.078 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-5
19:47:18.078 Disk 0 Vendor: WDC_WD3200BEVT-22ZCT0 11.01A11 Size: 305245MB BusType: 3
19:47:18.078 Device \Driver\atapi -> DriverStartIo b9f10864
19:47:18.078 Device \Driver\atapi -> MajorFunction 8a95ef00
19:47:18.125 Disk 0 MBR read successfully
19:47:18.125 Disk 0 MBR scan
19:47:18.125 Disk 0 Windows XP default MBR code
19:47:18.125 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 49999 MB offset 63
19:47:18.125 Disk 0 Partition - 00 0F Extended LBA 255235 MB offset 102398310
19:47:18.140 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 255235 MB offset 102398373
19:47:18.140 Disk 0 scanning sectors +625121280
19:47:18.203 Disk 0 scanning C:\WINDOWS\system32\drivers
19:47:25.140 Service scanning
19:47:26.359 Service atapi C:\WINDOWS\system32\DRIVERS\atapi.sys **LOCKED** 32
19:47:36.015 Modules scanning
19:47:40.593 Disk 0 trace - called modules:
19:47:40.640 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8a95ef00]<<
19:47:40.656 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8aa70ab8]
19:47:40.671 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\00000079[0x8aaa43b8]
19:47:40.687 5 ACPI.sys[b9f57620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-5[0x8aa74d98]
19:47:40.703 \Driver\atapi[0x8ab13b60] -> IRP_MJ_CREATE -> 0x8a95ef00
19:47:41.078 AVAST engine scan C:\WINDOWS
19:47:48.484 AVAST engine scan C:\WINDOWS\system32
19:49:03.093 AVAST engine scan C:\WINDOWS\system32\drivers
19:49:10.296 AVAST engine scan C:\Documents and Settings\Sašenka
19:52:04.656 AVAST engine scan C:\Documents and Settings\All Users
19:52:37.000 Scan finished successfully
19:55:26.328 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Sašenka\Plocha\MBR.dat"
19:55:26.328 The log file has been saved successfully to "C:\Documents and Settings\Sašenka\Plocha\aswMBR.txt"
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-08-05 19:46:18
-----------------------------
19:46:18.437 OS Version: Windows 5.1.2600 Service Pack 3
19:46:18.437 Number of processors: 2 586 0xF0D
19:46:18.437 ComputerName: ALEX UserName:
19:46:19.031 Initialize success
19:46:19.406 AVAST engine defs: 12080500
19:47:18.078 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-5
19:47:18.078 Disk 0 Vendor: WDC_WD3200BEVT-22ZCT0 11.01A11 Size: 305245MB BusType: 3
19:47:18.078 Device \Driver\atapi -> DriverStartIo b9f10864
19:47:18.078 Device \Driver\atapi -> MajorFunction 8a95ef00
19:47:18.125 Disk 0 MBR read successfully
19:47:18.125 Disk 0 MBR scan
19:47:18.125 Disk 0 Windows XP default MBR code
19:47:18.125 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 49999 MB offset 63
19:47:18.125 Disk 0 Partition - 00 0F Extended LBA 255235 MB offset 102398310
19:47:18.140 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 255235 MB offset 102398373
19:47:18.140 Disk 0 scanning sectors +625121280
19:47:18.203 Disk 0 scanning C:\WINDOWS\system32\drivers
19:47:25.140 Service scanning
19:47:26.359 Service atapi C:\WINDOWS\system32\DRIVERS\atapi.sys **LOCKED** 32
19:47:36.015 Modules scanning
19:47:40.593 Disk 0 trace - called modules:
19:47:40.640 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8a95ef00]<<
19:47:40.656 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8aa70ab8]
19:47:40.671 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\00000079[0x8aaa43b8]
19:47:40.687 5 ACPI.sys[b9f57620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-5[0x8aa74d98]
19:47:40.703 \Driver\atapi[0x8ab13b60] -> IRP_MJ_CREATE -> 0x8a95ef00
19:47:41.078 AVAST engine scan C:\WINDOWS
19:47:48.484 AVAST engine scan C:\WINDOWS\system32
19:49:03.093 AVAST engine scan C:\WINDOWS\system32\drivers
19:49:10.296 AVAST engine scan C:\Documents and Settings\Sašenka
19:52:04.656 AVAST engine scan C:\Documents and Settings\All Users
19:52:37.000 Scan finished successfully
19:55:26.328 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Sašenka\Plocha\MBR.dat"
19:55:26.328 The log file has been saved successfully to "C:\Documents and Settings\Sašenka\Plocha\aswMBR.txt"
Re: Poprosím o kontrolu logu-pomalý a sekající se notebook.D
Tak jsem odinstaloval adobe a pri instalaci mi to pise, ze "inicializace se nezdarila", takze neni nainstalovan.
Combofix:
ComboFix 12-08-05.02 - Sašenka 05.08.2012 20:00:01.4.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.3071.2254 [GMT 2:00]
Spuštěný z: c:\documents and settings\Sašenka\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Sašenka\Plocha\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: avast! Internet Security *Disabled* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
FILE ::
"c:\program files\Google\Update\GoogleUpdate.exe"
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_GUPDATE
-------\Legacy_GUPDATEM
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-07-05 do 2012-08-05 )))))))))))))))))))))))))))))))
.
.
2012-08-03 15:51 . 2012-08-03 15:51 -------- d-----w- c:\documents and settings\Sašenka\Local Settings\Data aplikací\Facebook
2012-08-02 19:31 . 2012-08-02 19:31 -------- d-sh--w- c:\documents and settings\Sašenka\PrivacIE
2012-08-02 19:29 . 2012-08-02 19:29 -------- d-sh--w- c:\documents and settings\Sašenka\IETldCache
2012-08-02 19:24 . 2012-08-02 19:25 -------- dc-h--w- c:\windows\ie8
2012-08-02 19:20 . 2012-05-11 14:44 521728 -c----w- c:\windows\system32\dllcache\jsdbgui.dll
2012-08-02 19:20 . 2011-08-16 10:45 6144 -c----w- c:\windows\system32\dllcache\iecompat.dll
2012-08-02 19:20 . 2012-05-11 14:44 629760 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2012-08-02 19:20 . 2012-05-11 14:44 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2012-08-02 19:20 . 2012-05-11 14:44 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2012-08-02 19:20 . 2012-05-11 14:44 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2012-08-02 19:20 . 2012-05-11 14:44 2000384 -c----w- c:\windows\system32\dllcache\iertutil.dll
2012-08-02 19:20 . 2012-05-11 14:44 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2012-08-02 19:20 . 2012-05-11 18:14 11111424 -c----w- c:\windows\system32\dllcache\ieframe.dll
2012-07-12 18:20 . 2012-07-12 18:20 -------- d-----w- c:\documents and settings\Sašenka\Data aplikací\Malwarebytes
2012-07-12 18:20 . 2012-07-12 18:20 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2012-07-12 18:20 . 2012-07-21 21:12 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-07-12 18:20 . 2012-07-03 11:46 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-03 16:21 . 2011-11-12 16:41 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-07-03 16:21 . 2011-11-12 16:41 353688 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-07-03 16:21 . 2011-11-12 16:41 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-07-03 16:21 . 2011-11-12 16:41 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-07-03 16:21 . 2011-11-12 16:41 721000 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-07-03 16:21 . 2011-11-12 16:41 97608 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-07-03 16:21 . 2011-11-12 16:41 89624 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-07-03 16:21 . 2011-11-12 16:41 25256 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-07-03 16:21 . 2011-11-12 16:41 41224 ----a-w- c:\windows\avastSS.scr
2012-07-03 16:21 . 2011-11-12 16:41 227648 ----a-w- c:\windows\system32\aswBoot.exe
2012-06-13 13:55 . 2008-04-14 12:00 1866112 ----a-w- c:\windows\system32\win32k.sys
2012-06-05 15:49 . 2008-04-14 12:00 1372672 ----a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:49 . 2008-04-14 12:00 1172480 ----a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2008-04-14 12:00 152576 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 13:19 . 2008-10-16 13:07 15384 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 13:19 . 2008-10-16 13:08 22552 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 13:19 . 2009-01-04 21:08 329240 ----a-w- c:\windows\system32\wucltui.dll
2012-06-02 13:19 . 2009-01-04 21:08 210968 ----a-w- c:\windows\system32\wuweb.dll
2012-06-02 13:19 . 2009-01-04 21:07 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 13:19 . 2009-01-04 21:07 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 13:19 . 2009-01-04 21:07 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 13:19 . 2008-10-16 13:09 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 13:19 . 2008-10-16 13:07 15384 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 13:19 . 2008-10-16 13:07 18456 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 13:19 . 2008-04-14 12:00 97304 ----a-w- c:\windows\system32\cdm.dll
2012-06-02 13:19 . 2009-01-04 21:07 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 13:19 . 2009-01-04 21:07 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-05-31 13:22 . 2008-04-14 12:00 602112 ----a-w- c:\windows\system32\crypt32.dll
2012-05-16 15:09 . 2008-04-14 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-05-11 14:44 . 2008-04-14 12:00 43520 ------w- c:\windows\system32\licmgr10.dll
2012-05-11 14:44 . 2008-04-14 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38 . 2008-04-14 12:00 385024 ------w- c:\windows\system32\html.iec
2012-07-22 18:51 . 2011-05-04 07:22 136672 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2008-04-14 12:00 . !HASH: COULD NOT OPEN FILE !!!!! . 96512 . . [------] . . c:\windows\system32\drivers\atapi.sys
.
((((((((((((((((((((((((((((( SnapShot_2012-07-22_11.44.18 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-08-05 18:07 . 2012-08-05 18:07 16384 c:\windows\Temp\Perflib_Perfdata_6b4.dat
+ 2009-01-05 08:03 . 2009-01-07 16:21 26144 c:\windows\system32\spupdsvc.exe
+ 2009-03-12 16:15 . 2009-01-07 16:20 16928 c:\windows\system32\spmsg.dll
+ 2008-04-14 12:00 . 2009-03-08 02:31 46592 c:\windows\system32\pngfilt.dll
+ 2006-06-29 07:05 . 2009-01-07 16:20 23552 c:\windows\system32\normaliz.dll
- 2006-06-29 07:05 . 2006-06-29 07:05 23552 c:\windows\system32\normaliz.dll
+ 2006-06-28 16:59 . 2009-01-07 16:20 24576 c:\windows\system32\nlsdl.dll
- 2006-06-28 16:59 . 2006-06-28 16:59 24576 c:\windows\system32\nlsdl.dll
+ 2008-04-14 12:00 . 2009-03-08 02:31 48128 c:\windows\system32\mshtmler.dll
+ 2008-04-14 12:00 . 2012-05-11 14:44 67072 c:\windows\system32\mshtmled.dll
+ 2008-04-14 12:00 . 2009-03-08 02:31 45568 c:\windows\system32\mshta.exe
+ 2009-03-08 02:31 . 2009-03-08 02:31 13312 c:\windows\system32\msfeedssync.exe
+ 2009-03-08 02:31 . 2012-05-11 14:44 55296 c:\windows\system32\msfeedsbs.dll
+ 2008-04-14 12:00 . 2012-05-11 14:44 25600 c:\windows\system32\jsproxy.dll
+ 2008-04-14 12:00 . 2009-03-08 02:32 94720 c:\windows\system32\inseng.dll
+ 2008-04-14 12:00 . 2009-03-08 02:31 34816 c:\windows\system32\imgutil.dll
+ 2009-03-08 02:32 . 2009-03-08 02:32 36864 c:\windows\system32\ieudinit.exe
+ 2008-04-14 12:00 . 2009-03-08 02:32 71680 c:\windows\system32\iesetup.dll
+ 2008-04-14 12:00 . 2009-03-08 02:32 55808 c:\windows\system32\iernonce.dll
+ 2006-06-29 07:05 . 2009-01-07 16:20 26112 c:\windows\system32\idndl.dll
- 2006-06-29 07:05 . 2006-06-29 07:05 26112 c:\windows\system32\idndl.dll
+ 2009-03-08 02:31 . 2009-03-08 02:31 59904 c:\windows\system32\icardie.dll
+ 2008-04-14 12:00 . 2009-03-08 02:31 46592 c:\windows\system32\dllcache\pngfilt.dll
+ 2008-04-14 12:00 . 2009-03-08 02:31 48128 c:\windows\system32\dllcache\mshtmler.dll
+ 2008-04-14 12:00 . 2012-05-11 14:44 67072 c:\windows\system32\dllcache\mshtmled.dll
+ 2008-04-14 12:00 . 2009-03-08 02:31 45568 c:\windows\system32\dllcache\mshta.exe
+ 2008-04-14 12:00 . 2012-05-11 14:44 43520 c:\windows\system32\dllcache\licmgr10.dll
+ 2008-04-14 12:00 . 2012-05-11 14:44 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2008-04-14 12:00 . 2009-03-08 02:32 94720 c:\windows\system32\dllcache\inseng.dll
+ 2008-04-14 12:00 . 2009-03-08 02:31 34816 c:\windows\system32\dllcache\imgutil.dll
+ 2008-04-14 12:00 . 2009-03-08 02:32 71680 c:\windows\system32\dllcache\iesetup.dll
+ 2008-04-14 12:00 . 2009-03-08 02:32 55808 c:\windows\system32\dllcache\iernonce.dll
+ 2009-01-04 21:07 . 2009-03-08 02:24 68608 c:\windows\system32\dllcache\hmmapi.dll
+ 2008-04-14 12:00 . 2009-03-08 02:33 18944 c:\windows\system32\dllcache\corpol.dll
+ 2008-04-14 12:00 . 2009-03-08 02:32 72704 c:\windows\system32\dllcache\admparse.dll
+ 2008-04-14 12:00 . 2009-03-08 02:33 18944 c:\windows\system32\corpol.dll
+ 2008-04-14 12:00 . 2009-03-08 02:32 72704 c:\windows\system32\admparse.dll
+ 2012-07-22 18:44 . 2012-07-22 18:44 22016 c:\windows\Installer\d69bc.msi
+ 2012-08-02 19:26 . 2009-03-08 02:33 12288 c:\windows\ie8updates\KB982381-IE8\xpshims.dll
+ 2012-08-02 19:26 . 2009-03-08 02:31 55296 c:\windows\ie8updates\KB982381-IE8\msfeedsbs.dll
+ 2012-08-02 19:26 . 2009-03-08 02:33 25600 c:\windows\ie8updates\KB982381-IE8\jsproxy.dll
+ 2012-08-02 19:27 . 2011-11-04 19:13 12800 c:\windows\ie8updates\KB2699988-IE8\xpshims.dll
+ 2012-08-02 19:27 . 2011-11-04 19:13 66560 c:\windows\ie8updates\KB2699988-IE8\mshtmled.dll
+ 2012-08-02 19:27 . 2011-11-04 19:13 55296 c:\windows\ie8updates\KB2699988-IE8\msfeedsbs.dll
+ 2012-08-02 19:27 . 2011-11-04 19:13 43520 c:\windows\ie8updates\KB2699988-IE8\licmgr10.dll
+ 2012-08-02 19:27 . 2011-11-04 19:13 25600 c:\windows\ie8updates\KB2699988-IE8\jsproxy.dll
+ 2012-08-02 19:27 . 2010-05-06 10:35 12800 c:\windows\ie8updates\KB2618444-IE8\xpshims.dll
+ 2012-08-02 19:27 . 2009-03-08 02:31 66560 c:\windows\ie8updates\KB2618444-IE8\mshtmled.dll
+ 2012-08-02 19:27 . 2010-05-06 10:35 55296 c:\windows\ie8updates\KB2618444-IE8\msfeedsbs.dll
+ 2012-08-02 19:27 . 2009-03-08 02:34 43008 c:\windows\ie8updates\KB2618444-IE8\licmgr10.dll
+ 2012-08-02 19:27 . 2010-05-06 10:35 25600 c:\windows\ie8updates\KB2618444-IE8\jsproxy.dll
+ 2012-08-02 19:24 . 2012-04-20 19:30 37888 c:\windows\ie8\url.dll
+ 2012-08-02 19:24 . 2009-03-08 12:23 58464 c:\windows\ie8\spuninst\iecustom.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 39424 c:\windows\ie8\pngfilt.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 96768 c:\windows\ie8\occache.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 56832 c:\windows\ie8\mshtmler.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 29184 c:\windows\ie8\mshta.exe
+ 2012-08-02 19:24 . 2008-04-14 12:00 22016 c:\windows\ie8\licmgr10.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 15872 c:\windows\ie8\jsproxy.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 96768 c:\windows\ie8\inseng.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 35840 c:\windows\ie8\imgutil.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 93184 c:\windows\ie8\iexplore.exe
+ 2012-08-02 19:24 . 2008-04-14 12:00 62976 c:\windows\ie8\iesetup.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 48128 c:\windows\ie8\iernonce.dll
+ 2012-08-02 19:24 . 2012-04-20 19:30 81920 c:\windows\ie8\ieencode.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 34304 c:\windows\ie8\ie4uinit.exe
+ 2012-08-02 19:24 . 2008-04-14 12:00 38912 c:\windows\ie8\hmmapi.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 35328 c:\windows\ie8\corpol.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 61440 c:\windows\ie8\admparse.dll
+ 2012-08-02 19:27 . 2009-03-08 02:35 2048 c:\windows\ie8updates\KB2598845-IE8\iecompat.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 121856 c:\windows\system32\xmllite.dll
+ 2008-04-14 12:00 . 2009-01-07 16:21 121856 c:\windows\system32\xmllite.dll
+ 2009-03-08 02:34 . 2009-03-08 02:34 208384 c:\windows\system32\WinFXDocObj.exe
+ 2008-04-14 12:00 . 2009-03-08 02:34 236544 c:\windows\system32\webcheck.dll
+ 2008-04-14 12:00 . 2011-03-04 06:36 420864 c:\windows\system32\vbscript.dll
+ 2008-04-14 12:00 . 2012-05-11 14:44 105984 c:\windows\system32\url.dll
+ 2008-04-14 12:00 . 2012-05-11 14:44 206848 c:\windows\system32\occache.dll
+ 2008-04-14 12:00 . 2012-05-11 14:44 611840 c:\windows\system32\mstime.dll
+ 2008-04-14 12:00 . 2009-03-08 02:34 193536 c:\windows\system32\msrating.dll
+ 2008-04-14 12:00 . 2009-03-08 02:22 156160 c:\windows\system32\msls31.dll
+ 2009-03-08 02:32 . 2012-05-11 14:44 629760 c:\windows\system32\msfeeds.dll
+ 2009-01-07 16:20 . 2009-01-07 16:20 265720 c:\windows\system32\msdbg2.dll
+ 2008-04-14 12:00 . 2011-03-04 06:36 726528 c:\windows\system32\jscript.dll
+ 2009-03-08 02:22 . 2009-03-08 02:22 164352 c:\windows\system32\ieui.dll
+ 2008-04-14 12:00 . 2012-05-11 14:44 184320 c:\windows\system32\iepeers.dll
+ 2008-04-14 12:00 . 2012-05-11 14:44 387584 c:\windows\system32\iedkcs32.dll
+ 2009-03-08 02:11 . 2009-03-08 02:11 445952 c:\windows\system32\ieapfltr.dll
+ 2008-04-14 12:00 . 2009-03-08 02:32 163840 c:\windows\system32\ieakui.dll
+ 2008-04-14 12:00 . 2009-03-08 02:33 229376 c:\windows\system32\ieaksie.dll
+ 2008-04-14 12:00 . 2009-03-08 02:33 125952 c:\windows\system32\ieakeng.dll
+ 2008-04-14 12:00 . 2012-05-11 11:38 174080 c:\windows\system32\ie4uinit.exe
+ 2008-04-14 12:00 . 2009-03-08 02:31 216064 c:\windows\system32\dxtrans.dll
+ 2008-04-14 12:00 . 2009-03-08 02:31 348160 c:\windows\system32\dxtmsft.dll
+ 2008-04-14 12:00 . 2012-05-16 15:09 916992 c:\windows\system32\dllcache\wininet.dll
+ 2008-04-14 12:00 . 2009-03-08 02:34 236544 c:\windows\system32\dllcache\webcheck.dll
+ 2009-01-04 21:08 . 2011-04-30 03:00 758784 c:\windows\system32\dllcache\vgx.dll
+ 2008-04-14 12:00 . 2011-03-04 06:36 420864 c:\windows\system32\dllcache\vbscript.dll
+ 2008-04-14 12:00 . 2012-05-11 14:44 105984 c:\windows\system32\dllcache\url.dll
+ 2009-01-07 16:20 . 2009-01-07 16:20 134144 c:\windows\system32\dllcache\sqmapi.dll
+ 2008-04-14 12:00 . 2012-05-11 14:44 206848 c:\windows\system32\dllcache\occache.dll
+ 2008-04-14 12:00 . 2012-05-11 14:44 611840 c:\windows\system32\dllcache\mstime.dll
+ 2008-04-14 12:00 . 2009-03-08 02:34 193536 c:\windows\system32\dllcache\msrating.dll
+ 2008-04-14 12:00 . 2009-03-08 02:22 156160 c:\windows\system32\dllcache\msls31.dll
+ 2008-04-14 12:00 . 2011-03-04 06:36 726528 c:\windows\system32\dllcache\jscript.dll
+ 2009-01-04 21:07 . 2009-03-08 12:09 638816 c:\windows\system32\dllcache\iexplore.exe
+ 2008-04-14 12:00 . 2012-05-11 14:44 184320 c:\windows\system32\dllcache\iepeers.dll
+ 2008-04-14 12:00 . 2012-05-11 14:44 387584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2008-04-14 12:00 . 2009-03-08 02:32 163840 c:\windows\system32\dllcache\ieakui.dll
+ 2008-04-14 12:00 . 2009-03-08 02:33 229376 c:\windows\system32\dllcache\ieaksie.dll
+ 2008-04-14 12:00 . 2009-03-08 02:33 125952 c:\windows\system32\dllcache\ieakeng.dll
+ 2008-04-14 12:00 . 2012-05-11 11:38 174080 c:\windows\system32\dllcache\ie4uinit.exe
+ 2008-04-14 12:00 . 2009-03-08 02:31 216064 c:\windows\system32\dllcache\dxtrans.dll
+ 2008-04-14 12:00 . 2009-03-08 02:31 348160 c:\windows\system32\dllcache\dxtmsft.dll
+ 2008-04-14 12:00 . 2009-03-08 02:32 128512 c:\windows\system32\dllcache\advpack.dll
+ 2008-04-14 12:00 . 2009-03-08 02:32 128512 c:\windows\system32\advpack.dll
+ 2012-08-03 15:51 . 2012-08-03 15:51 199168 c:\windows\Installer\84517e.msi
+ 2012-08-02 19:26 . 2009-03-08 02:34 914944 c:\windows\ie8updates\KB982381-IE8\wininet.dll
+ 2012-08-02 19:26 . 2010-02-22 14:21 391032 c:\windows\ie8updates\KB982381-IE8\spuninst\updspapi.dll
+ 2012-08-02 19:26 . 2008-07-08 12:59 233848 c:\windows\ie8updates\KB982381-IE8\spuninst\spuninst.exe
+ 2012-08-02 19:26 . 2009-03-08 02:34 109568 c:\windows\ie8updates\KB982381-IE8\occache.dll
+ 2012-08-02 19:26 . 2009-03-08 02:32 611840 c:\windows\ie8updates\KB982381-IE8\mstime.dll
+ 2012-08-02 19:26 . 2009-03-08 02:32 594432 c:\windows\ie8updates\KB982381-IE8\msfeeds.dll
+ 2012-08-02 19:26 . 2009-03-08 02:33 246784 c:\windows\ie8updates\KB982381-IE8\ieproxy.dll
+ 2012-08-02 19:26 . 2009-03-08 02:31 183808 c:\windows\ie8updates\KB982381-IE8\iepeers.dll
+ 2012-08-02 19:26 . 2009-03-08 02:35 742912 c:\windows\ie8updates\KB982381-IE8\iedvtool.dll
+ 2012-08-02 19:26 . 2009-03-08 12:09 391536 c:\windows\ie8updates\KB982381-IE8\iedkcs32.dll
+ 2012-08-02 19:26 . 2009-03-08 02:32 173056 c:\windows\ie8updates\KB982381-IE8\ie4uinit.exe
+ 2012-08-02 19:27 . 2011-11-04 19:13 916992 c:\windows\ie8updates\KB2699988-IE8\wininet.dll
+ 2012-08-02 19:27 . 2011-11-04 19:13 105984 c:\windows\ie8updates\KB2699988-IE8\url.dll
+ 2012-08-02 19:27 . 2010-07-05 13:13 391032 c:\windows\ie8updates\KB2699988-IE8\spuninst\updspapi.dll
+ 2012-08-02 19:27 . 2010-07-05 13:13 233848 c:\windows\ie8updates\KB2699988-IE8\spuninst\spuninst.exe
+ 2012-08-02 19:27 . 2011-11-04 19:13 206848 c:\windows\ie8updates\KB2699988-IE8\occache.dll
+ 2012-08-02 19:27 . 2011-11-04 19:13 611840 c:\windows\ie8updates\KB2699988-IE8\mstime.dll
+ 2012-08-02 19:27 . 2011-11-04 19:13 602112 c:\windows\ie8updates\KB2699988-IE8\msfeeds.dll
+ 2012-08-02 19:27 . 2009-03-08 02:35 521216 c:\windows\ie8updates\KB2699988-IE8\jsdbgui.dll
+ 2012-08-02 19:27 . 2011-11-04 19:13 247808 c:\windows\ie8updates\KB2699988-IE8\ieproxy.dll
+ 2012-08-02 19:27 . 2011-11-04 19:13 184320 c:\windows\ie8updates\KB2699988-IE8\iepeers.dll
+ 2012-08-02 19:27 . 2011-11-04 19:13 743424 c:\windows\ie8updates\KB2699988-IE8\iedvtool.dll
+ 2012-08-02 19:27 . 2011-11-04 19:13 387584 c:\windows\ie8updates\KB2699988-IE8\iedkcs32.dll
+ 2012-08-02 19:27 . 2011-11-04 11:24 174080 c:\windows\ie8updates\KB2699988-IE8\ie4uinit.exe
+ 2012-08-02 19:27 . 2010-05-06 10:35 916480 c:\windows\ie8updates\KB2618444-IE8\wininet.dll
+ 2012-08-02 19:27 . 2009-03-08 02:34 105984 c:\windows\ie8updates\KB2618444-IE8\url.dll
+ 2012-08-02 19:27 . 2010-07-05 13:13 391032 c:\windows\ie8updates\KB2618444-IE8\spuninst\updspapi.dll
+ 2012-08-02 19:27 . 2010-07-05 13:13 233848 c:\windows\ie8updates\KB2618444-IE8\spuninst\spuninst.exe
+ 2012-08-02 19:27 . 2010-05-06 10:35 206848 c:\windows\ie8updates\KB2618444-IE8\occache.dll
+ 2012-08-02 19:27 . 2010-05-06 10:35 611840 c:\windows\ie8updates\KB2618444-IE8\mstime.dll
+ 2012-08-02 19:27 . 2010-05-06 10:35 599040 c:\windows\ie8updates\KB2618444-IE8\msfeeds.dll
+ 2012-08-02 19:27 . 2010-05-06 10:35 247808 c:\windows\ie8updates\KB2618444-IE8\ieproxy.dll
+ 2012-08-02 19:27 . 2010-05-06 10:35 184320 c:\windows\ie8updates\KB2618444-IE8\iepeers.dll
+ 2012-08-02 19:27 . 2010-05-06 10:35 743424 c:\windows\ie8updates\KB2618444-IE8\iedvtool.dll
+ 2012-08-02 19:27 . 2010-05-06 10:35 387584 c:\windows\ie8updates\KB2618444-IE8\iedkcs32.dll
+ 2012-08-02 19:27 . 2010-05-05 13:30 173056 c:\windows\ie8updates\KB2618444-IE8\ie4uinit.exe
+ 2012-08-02 19:27 . 2010-02-22 14:21 391032 c:\windows\ie8updates\KB2598845-IE8\spuninst\updspapi.dll
+ 2012-08-02 19:27 . 2010-02-22 14:20 233848 c:\windows\ie8updates\KB2598845-IE8\spuninst\spuninst.exe
+ 2012-08-05 17:36 . 2009-03-08 02:33 759296 c:\windows\ie8updates\KB2544521-IE8\vgx.dll
+ 2012-08-05 17:36 . 2010-07-05 13:13 391032 c:\windows\ie8updates\KB2544521-IE8\spuninst\updspapi.dll
+ 2012-08-05 17:36 . 2010-07-05 13:13 233848 c:\windows\ie8updates\KB2544521-IE8\spuninst\spuninst.exe
+ 2012-08-05 17:37 . 2009-03-08 02:33 420352 c:\windows\ie8updates\KB2510531-IE8\vbscript.dll
+ 2012-08-05 17:37 . 2010-07-05 13:13 391032 c:\windows\ie8updates\KB2510531-IE8\spuninst\updspapi.dll
+ 2012-08-05 17:37 . 2010-07-05 13:13 233848 c:\windows\ie8updates\KB2510531-IE8\spuninst\spuninst.exe
+ 2012-08-05 17:37 . 2009-03-08 02:33 726528 c:\windows\ie8updates\KB2510531-IE8\jscript.dll
+ 2012-08-02 19:24 . 2012-05-16 07:59 668160 c:\windows\ie8\wininet.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 278528 c:\windows\ie8\webcheck.dll
+ 2012-08-02 19:24 . 2011-04-29 19:07 852480 c:\windows\ie8\vgx.dll
+ 2012-08-02 19:24 . 2011-03-04 06:43 434176 c:\windows\ie8\vbscript.dll
+ 2012-08-02 19:24 . 2012-04-20 19:30 627712 c:\windows\ie8\urlmon.dll
+ 2012-08-02 19:24 . 2009-01-07 16:21 382496 c:\windows\ie8\spuninst\updspapi.dll
+ 2012-08-02 19:24 . 2009-01-07 16:20 231456 c:\windows\ie8\spuninst\spuninst.exe
+ 2012-08-02 19:24 . 2012-04-20 19:30 532480 c:\windows\ie8\mstime.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 146432 c:\windows\ie8\msrating.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 146432 c:\windows\ie8\msls31.dll
+ 2012-08-02 19:24 . 2012-04-20 19:30 449536 c:\windows\ie8\mshtmled.dll
+ 2012-08-02 19:24 . 2011-03-04 06:43 512000 c:\windows\ie8\jscript.dll
+ 2012-08-02 19:24 . 2012-04-20 19:30 251904 c:\windows\ie8\iepeers.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 323584 c:\windows\ie8\iedkcs32.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 225280 c:\windows\ie8\ieakui.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 219136 c:\windows\ie8\ieaksie.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 143360 c:\windows\ie8\ieakeng.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 205312 c:\windows\ie8\dxtrans.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 357888 c:\windows\ie8\dxtmsft.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 100352 c:\windows\ie8\advpack.dll
+ 2008-04-14 12:00 . 2012-05-11 14:44 1212416 c:\windows\system32\urlmon.dll
+ 2008-04-14 12:00 . 2012-05-11 14:44 6007808 c:\windows\system32\mshtml.dll
+ 2009-03-08 02:32 . 2012-05-11 14:44 2000384 c:\windows\system32\iertutil.dll
+ 2009-02-06 19:07 . 2009-02-06 19:07 3698584 c:\windows\system32\ieapfltr.dat
+ 2008-04-14 12:00 . 2012-05-11 14:44 1212416 c:\windows\system32\dllcache\urlmon.dll
+ 2008-04-14 12:00 . 2012-05-11 14:44 6007808 c:\windows\system32\dllcache\mshtml.dll
+ 2012-08-02 19:26 . 2009-03-08 02:34 1206784 c:\windows\ie8updates\KB982381-IE8\urlmon.dll
+ 2012-08-02 19:26 . 2009-03-08 02:41 5937152 c:\windows\ie8updates\KB982381-IE8\mshtml.dll
+ 2012-08-02 19:26 . 2009-03-08 02:32 1985024 c:\windows\ie8updates\KB982381-IE8\iertutil.dll
+ 2012-08-02 19:27 . 2011-11-04 19:13 1212416 c:\windows\ie8updates\KB2699988-IE8\urlmon.dll
+ 2012-08-02 19:27 . 2011-11-04 19:13 5978112 c:\windows\ie8updates\KB2699988-IE8\mshtml.dll
+ 2012-08-02 19:27 . 2011-11-04 19:13 2000384 c:\windows\ie8updates\KB2699988-IE8\iertutil.dll
+ 2012-08-02 19:27 . 2010-05-06 10:35 1209344 c:\windows\ie8updates\KB2618444-IE8\urlmon.dll
+ 2012-08-02 19:27 . 2010-05-06 10:35 5950976 c:\windows\ie8updates\KB2618444-IE8\mshtml.dll
+ 2012-08-02 19:27 . 2010-05-06 10:35 1985536 c:\windows\ie8updates\KB2618444-IE8\iertutil.dll
+ 2012-08-02 19:24 . 2012-04-20 19:30 3109376 c:\windows\ie8\mshtml.dll
+ 2009-03-08 02:39 . 2012-05-11 18:14 11111424 c:\windows\system32\ieframe.dll
+ 2012-08-02 19:26 . 2009-03-08 02:39 11063808 c:\windows\ie8updates\KB982381-IE8\ieframe.dll
+ 2012-08-02 19:27 . 2011-11-05 12:13 11081728 c:\windows\ie8updates\KB2699988-IE8\ieframe.dll
+ 2012-08-02 19:27 . 2010-05-06 10:35 11076096 c:\windows\ie8updates\KB2618444-IE8\ieframe.dll
.
-- Snímek resetován k současnému datu --
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-07-03 16:21 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Facebook Update"="c:\documents and settings\Sašenka\Local Settings\Data aplikací\Facebook\Update\FacebookUpdate.exe" [2012-08-03 138096]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsgTranAgt"="c:\program files\ASUS\ATK Hotkey\MsgTranAgt.exe" [2007-11-04 106496]
"HControlUser"="c:\program files\ASUS\ATK Hotkey\HControlUser.exe" [2008-01-11 98304]
"ATKHOTKEY"="c:\program files\ASUS\ATK Hotkey\HControl.exe" [2008-06-26 217088]
"ATKOSD2"="c:\program files\ATKOSD2\ATKOSD2.exe" [2008-01-23 7766016]
"ATKMEDIA"="c:\program files\ASUS\ATK Media\DMEDIA.EXE" [2008-02-01 61440]
"RTHDCPL"="RTHDCPL.EXE" [2008-06-20 16872448]
"Power_Gear"="c:\program files\ASUS\Power4 Gear\BatteryLife.exe" [2006-07-26 90112]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-07-03 4273976]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\Sašenka\Nabídka Start\Programy\Po spuštění\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
CCC.lnk - c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [2007-7-17 49152]
Facebook Messenger.lnk - c:\documents and settings\Sašenka\Local Settings\Data aplikací\Facebook\Messenger\2.1.4590.0\FacebookMessenger.exe [2012-7-26 244656]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Bluetooth.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesHelper]
2011-09-29 14:19 929680 ----a-w- c:\program files\Samsung\Kies\KiesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesPDLR]
2011-09-29 14:19 20880 ----a-w- c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]
2011-09-29 14:19 3508112 ----a-w- c:\program files\Samsung\Kies\KiesTrayAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyTomTomSA.exe]
2011-11-14 11:02 435672 ----a-w- c:\program files\MyTomTom 3\MyTomTomSA.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Seznam Postak]
2009-11-02 13:05 448664 ----a-w- c:\program files\Seznam.cz\postak.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Companion]
2011-10-21 13:06 433872 ----a-w- c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Sony Ericsson\\Update Engine\\Sony Ericsson Update Engine.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\ICQ7.5\\ICQ.exe"=
.
R0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [5.1.2009 9:55 160640]
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [5.1.2009 9:55 5248]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [12.11.2011 18:41 721000]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [12.11.2011 18:41 353688]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [12.11.2011 18:41 21256]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [12.7.2012 20:20 655944]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [5.1.2009 9:08 36608]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [12.7.2012 20:20 22344]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\drivers\ssadadb.sys [9.10.2011 10:35 30312]
S3 IpwP;IPWireless 3G Network Adapter;c:\windows\system32\drivers\ipw3gnet.sys [5.1.2009 21:25 51040]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [3.5.2012 17:49 113120]
S3 s0017bus;Sony Ericsson Device 0017 driver (WDM);c:\windows\system32\drivers\s0017bus.sys [19.3.2011 19:40 86824]
S3 s0017mdfl;Sony Ericsson Device 0017 USB WMC Modem Filter;c:\windows\system32\drivers\s0017mdfl.sys [19.3.2011 19:40 15016]
S3 s0017mdm;Sony Ericsson Device 0017 USB WMC Modem Driver;c:\windows\system32\drivers\s0017mdm.sys [19.3.2011 19:40 114600]
S3 s0017mgmt;Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0017mgmt.sys [19.3.2011 19:40 108328]
S3 s0017nd5;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS);c:\windows\system32\drivers\s0017nd5.sys [19.3.2011 19:40 26024]
S3 s0017obex;Sony Ericsson Device 0017 USB WMC OBEX Interface;c:\windows\system32\drivers\s0017obex.sys [19.3.2011 19:40 104616]
S3 s0017unic;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM);c:\windows\system32\drivers\s0017unic.sys [19.3.2011 19:40 109736]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [19.3.2011 19:39 155344]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [9.10.2011 10:35 121064]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [9.10.2011 10:35 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [9.10.2011 10:35 136808]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\drivers\ssadserd.sys [9.10.2011 10:35 114280]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [24.6.2010 7:51 11520]
.
Obsah adresáře 'Naplánované úlohy'
.
2012-08-05 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2012-07-20 16:21]
.
2012-08-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-23 07:52]
.
2012-08-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-23 07:52]
.
.
------- Doplňkový sken -------
.
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
FF - ProfilePath - c:\documents and settings\Sašenka\Data aplikací\Mozilla\Firefox\Profiles\0xa4a2pg.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.oblibene-stranky.cz/
pref('extensions.shownSelectionUI',true); pref('extensions.autoDisableScopes',0);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-05 20:08
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(988)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(5372)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\ATKGFNEX\GFNEXSrv.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\RTHDCPL.EXE
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\documents and settings\Sac:\documents and settings\Sac:\program files\ASUS\ATK Hotkey\ATKOSD.exe
c:\program files\ASUS\ATK Hotkey\KBFiltr.exe
c:\program files\ASUS\ATK Hotkey\WDC.exe
.
**************************************************************************
.
Celkový čas: 2012-08-05 20:13:32 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-08-05 18:13
ComboFix2.txt 2012-01-06 21:25
ComboFix3.txt 2011-11-12 16:29
.
Před spuštěním: 3 489 894 400
Po spuštění: 3 426 832 384
.
- - End Of File - - 7B151E3FBB5366C75CAA3DFD66DFD20D
Combofix:
ComboFix 12-08-05.02 - Sašenka 05.08.2012 20:00:01.4.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.3071.2254 [GMT 2:00]
Spuštěný z: c:\documents and settings\Sašenka\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Sašenka\Plocha\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: avast! Internet Security *Disabled* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
FILE ::
"c:\program files\Google\Update\GoogleUpdate.exe"
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_GUPDATE
-------\Legacy_GUPDATEM
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-07-05 do 2012-08-05 )))))))))))))))))))))))))))))))
.
.
2012-08-03 15:51 . 2012-08-03 15:51 -------- d-----w- c:\documents and settings\Sašenka\Local Settings\Data aplikací\Facebook
2012-08-02 19:31 . 2012-08-02 19:31 -------- d-sh--w- c:\documents and settings\Sašenka\PrivacIE
2012-08-02 19:29 . 2012-08-02 19:29 -------- d-sh--w- c:\documents and settings\Sašenka\IETldCache
2012-08-02 19:24 . 2012-08-02 19:25 -------- dc-h--w- c:\windows\ie8
2012-08-02 19:20 . 2012-05-11 14:44 521728 -c----w- c:\windows\system32\dllcache\jsdbgui.dll
2012-08-02 19:20 . 2011-08-16 10:45 6144 -c----w- c:\windows\system32\dllcache\iecompat.dll
2012-08-02 19:20 . 2012-05-11 14:44 629760 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2012-08-02 19:20 . 2012-05-11 14:44 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2012-08-02 19:20 . 2012-05-11 14:44 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2012-08-02 19:20 . 2012-05-11 14:44 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2012-08-02 19:20 . 2012-05-11 14:44 2000384 -c----w- c:\windows\system32\dllcache\iertutil.dll
2012-08-02 19:20 . 2012-05-11 14:44 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2012-08-02 19:20 . 2012-05-11 18:14 11111424 -c----w- c:\windows\system32\dllcache\ieframe.dll
2012-07-12 18:20 . 2012-07-12 18:20 -------- d-----w- c:\documents and settings\Sašenka\Data aplikací\Malwarebytes
2012-07-12 18:20 . 2012-07-12 18:20 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2012-07-12 18:20 . 2012-07-21 21:12 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-07-12 18:20 . 2012-07-03 11:46 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-03 16:21 . 2011-11-12 16:41 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-07-03 16:21 . 2011-11-12 16:41 353688 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-07-03 16:21 . 2011-11-12 16:41 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-07-03 16:21 . 2011-11-12 16:41 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-07-03 16:21 . 2011-11-12 16:41 721000 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-07-03 16:21 . 2011-11-12 16:41 97608 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-07-03 16:21 . 2011-11-12 16:41 89624 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-07-03 16:21 . 2011-11-12 16:41 25256 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-07-03 16:21 . 2011-11-12 16:41 41224 ----a-w- c:\windows\avastSS.scr
2012-07-03 16:21 . 2011-11-12 16:41 227648 ----a-w- c:\windows\system32\aswBoot.exe
2012-06-13 13:55 . 2008-04-14 12:00 1866112 ----a-w- c:\windows\system32\win32k.sys
2012-06-05 15:49 . 2008-04-14 12:00 1372672 ----a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:49 . 2008-04-14 12:00 1172480 ----a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2008-04-14 12:00 152576 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 13:19 . 2008-10-16 13:07 15384 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 13:19 . 2008-10-16 13:08 22552 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 13:19 . 2009-01-04 21:08 329240 ----a-w- c:\windows\system32\wucltui.dll
2012-06-02 13:19 . 2009-01-04 21:08 210968 ----a-w- c:\windows\system32\wuweb.dll
2012-06-02 13:19 . 2009-01-04 21:07 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 13:19 . 2009-01-04 21:07 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 13:19 . 2009-01-04 21:07 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 13:19 . 2008-10-16 13:09 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 13:19 . 2008-10-16 13:07 15384 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 13:19 . 2008-10-16 13:07 18456 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 13:19 . 2008-04-14 12:00 97304 ----a-w- c:\windows\system32\cdm.dll
2012-06-02 13:19 . 2009-01-04 21:07 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 13:19 . 2009-01-04 21:07 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-05-31 13:22 . 2008-04-14 12:00 602112 ----a-w- c:\windows\system32\crypt32.dll
2012-05-16 15:09 . 2008-04-14 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-05-11 14:44 . 2008-04-14 12:00 43520 ------w- c:\windows\system32\licmgr10.dll
2012-05-11 14:44 . 2008-04-14 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38 . 2008-04-14 12:00 385024 ------w- c:\windows\system32\html.iec
2012-07-22 18:51 . 2011-05-04 07:22 136672 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2008-04-14 12:00 . !HASH: COULD NOT OPEN FILE !!!!! . 96512 . . [------] . . c:\windows\system32\drivers\atapi.sys
.
((((((((((((((((((((((((((((( SnapShot_2012-07-22_11.44.18 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-08-05 18:07 . 2012-08-05 18:07 16384 c:\windows\Temp\Perflib_Perfdata_6b4.dat
+ 2009-01-05 08:03 . 2009-01-07 16:21 26144 c:\windows\system32\spupdsvc.exe
+ 2009-03-12 16:15 . 2009-01-07 16:20 16928 c:\windows\system32\spmsg.dll
+ 2008-04-14 12:00 . 2009-03-08 02:31 46592 c:\windows\system32\pngfilt.dll
+ 2006-06-29 07:05 . 2009-01-07 16:20 23552 c:\windows\system32\normaliz.dll
- 2006-06-29 07:05 . 2006-06-29 07:05 23552 c:\windows\system32\normaliz.dll
+ 2006-06-28 16:59 . 2009-01-07 16:20 24576 c:\windows\system32\nlsdl.dll
- 2006-06-28 16:59 . 2006-06-28 16:59 24576 c:\windows\system32\nlsdl.dll
+ 2008-04-14 12:00 . 2009-03-08 02:31 48128 c:\windows\system32\mshtmler.dll
+ 2008-04-14 12:00 . 2012-05-11 14:44 67072 c:\windows\system32\mshtmled.dll
+ 2008-04-14 12:00 . 2009-03-08 02:31 45568 c:\windows\system32\mshta.exe
+ 2009-03-08 02:31 . 2009-03-08 02:31 13312 c:\windows\system32\msfeedssync.exe
+ 2009-03-08 02:31 . 2012-05-11 14:44 55296 c:\windows\system32\msfeedsbs.dll
+ 2008-04-14 12:00 . 2012-05-11 14:44 25600 c:\windows\system32\jsproxy.dll
+ 2008-04-14 12:00 . 2009-03-08 02:32 94720 c:\windows\system32\inseng.dll
+ 2008-04-14 12:00 . 2009-03-08 02:31 34816 c:\windows\system32\imgutil.dll
+ 2009-03-08 02:32 . 2009-03-08 02:32 36864 c:\windows\system32\ieudinit.exe
+ 2008-04-14 12:00 . 2009-03-08 02:32 71680 c:\windows\system32\iesetup.dll
+ 2008-04-14 12:00 . 2009-03-08 02:32 55808 c:\windows\system32\iernonce.dll
+ 2006-06-29 07:05 . 2009-01-07 16:20 26112 c:\windows\system32\idndl.dll
- 2006-06-29 07:05 . 2006-06-29 07:05 26112 c:\windows\system32\idndl.dll
+ 2009-03-08 02:31 . 2009-03-08 02:31 59904 c:\windows\system32\icardie.dll
+ 2008-04-14 12:00 . 2009-03-08 02:31 46592 c:\windows\system32\dllcache\pngfilt.dll
+ 2008-04-14 12:00 . 2009-03-08 02:31 48128 c:\windows\system32\dllcache\mshtmler.dll
+ 2008-04-14 12:00 . 2012-05-11 14:44 67072 c:\windows\system32\dllcache\mshtmled.dll
+ 2008-04-14 12:00 . 2009-03-08 02:31 45568 c:\windows\system32\dllcache\mshta.exe
+ 2008-04-14 12:00 . 2012-05-11 14:44 43520 c:\windows\system32\dllcache\licmgr10.dll
+ 2008-04-14 12:00 . 2012-05-11 14:44 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2008-04-14 12:00 . 2009-03-08 02:32 94720 c:\windows\system32\dllcache\inseng.dll
+ 2008-04-14 12:00 . 2009-03-08 02:31 34816 c:\windows\system32\dllcache\imgutil.dll
+ 2008-04-14 12:00 . 2009-03-08 02:32 71680 c:\windows\system32\dllcache\iesetup.dll
+ 2008-04-14 12:00 . 2009-03-08 02:32 55808 c:\windows\system32\dllcache\iernonce.dll
+ 2009-01-04 21:07 . 2009-03-08 02:24 68608 c:\windows\system32\dllcache\hmmapi.dll
+ 2008-04-14 12:00 . 2009-03-08 02:33 18944 c:\windows\system32\dllcache\corpol.dll
+ 2008-04-14 12:00 . 2009-03-08 02:32 72704 c:\windows\system32\dllcache\admparse.dll
+ 2008-04-14 12:00 . 2009-03-08 02:33 18944 c:\windows\system32\corpol.dll
+ 2008-04-14 12:00 . 2009-03-08 02:32 72704 c:\windows\system32\admparse.dll
+ 2012-07-22 18:44 . 2012-07-22 18:44 22016 c:\windows\Installer\d69bc.msi
+ 2012-08-02 19:26 . 2009-03-08 02:33 12288 c:\windows\ie8updates\KB982381-IE8\xpshims.dll
+ 2012-08-02 19:26 . 2009-03-08 02:31 55296 c:\windows\ie8updates\KB982381-IE8\msfeedsbs.dll
+ 2012-08-02 19:26 . 2009-03-08 02:33 25600 c:\windows\ie8updates\KB982381-IE8\jsproxy.dll
+ 2012-08-02 19:27 . 2011-11-04 19:13 12800 c:\windows\ie8updates\KB2699988-IE8\xpshims.dll
+ 2012-08-02 19:27 . 2011-11-04 19:13 66560 c:\windows\ie8updates\KB2699988-IE8\mshtmled.dll
+ 2012-08-02 19:27 . 2011-11-04 19:13 55296 c:\windows\ie8updates\KB2699988-IE8\msfeedsbs.dll
+ 2012-08-02 19:27 . 2011-11-04 19:13 43520 c:\windows\ie8updates\KB2699988-IE8\licmgr10.dll
+ 2012-08-02 19:27 . 2011-11-04 19:13 25600 c:\windows\ie8updates\KB2699988-IE8\jsproxy.dll
+ 2012-08-02 19:27 . 2010-05-06 10:35 12800 c:\windows\ie8updates\KB2618444-IE8\xpshims.dll
+ 2012-08-02 19:27 . 2009-03-08 02:31 66560 c:\windows\ie8updates\KB2618444-IE8\mshtmled.dll
+ 2012-08-02 19:27 . 2010-05-06 10:35 55296 c:\windows\ie8updates\KB2618444-IE8\msfeedsbs.dll
+ 2012-08-02 19:27 . 2009-03-08 02:34 43008 c:\windows\ie8updates\KB2618444-IE8\licmgr10.dll
+ 2012-08-02 19:27 . 2010-05-06 10:35 25600 c:\windows\ie8updates\KB2618444-IE8\jsproxy.dll
+ 2012-08-02 19:24 . 2012-04-20 19:30 37888 c:\windows\ie8\url.dll
+ 2012-08-02 19:24 . 2009-03-08 12:23 58464 c:\windows\ie8\spuninst\iecustom.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 39424 c:\windows\ie8\pngfilt.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 96768 c:\windows\ie8\occache.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 56832 c:\windows\ie8\mshtmler.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 29184 c:\windows\ie8\mshta.exe
+ 2012-08-02 19:24 . 2008-04-14 12:00 22016 c:\windows\ie8\licmgr10.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 15872 c:\windows\ie8\jsproxy.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 96768 c:\windows\ie8\inseng.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 35840 c:\windows\ie8\imgutil.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 93184 c:\windows\ie8\iexplore.exe
+ 2012-08-02 19:24 . 2008-04-14 12:00 62976 c:\windows\ie8\iesetup.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 48128 c:\windows\ie8\iernonce.dll
+ 2012-08-02 19:24 . 2012-04-20 19:30 81920 c:\windows\ie8\ieencode.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 34304 c:\windows\ie8\ie4uinit.exe
+ 2012-08-02 19:24 . 2008-04-14 12:00 38912 c:\windows\ie8\hmmapi.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 35328 c:\windows\ie8\corpol.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 61440 c:\windows\ie8\admparse.dll
+ 2012-08-02 19:27 . 2009-03-08 02:35 2048 c:\windows\ie8updates\KB2598845-IE8\iecompat.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 121856 c:\windows\system32\xmllite.dll
+ 2008-04-14 12:00 . 2009-01-07 16:21 121856 c:\windows\system32\xmllite.dll
+ 2009-03-08 02:34 . 2009-03-08 02:34 208384 c:\windows\system32\WinFXDocObj.exe
+ 2008-04-14 12:00 . 2009-03-08 02:34 236544 c:\windows\system32\webcheck.dll
+ 2008-04-14 12:00 . 2011-03-04 06:36 420864 c:\windows\system32\vbscript.dll
+ 2008-04-14 12:00 . 2012-05-11 14:44 105984 c:\windows\system32\url.dll
+ 2008-04-14 12:00 . 2012-05-11 14:44 206848 c:\windows\system32\occache.dll
+ 2008-04-14 12:00 . 2012-05-11 14:44 611840 c:\windows\system32\mstime.dll
+ 2008-04-14 12:00 . 2009-03-08 02:34 193536 c:\windows\system32\msrating.dll
+ 2008-04-14 12:00 . 2009-03-08 02:22 156160 c:\windows\system32\msls31.dll
+ 2009-03-08 02:32 . 2012-05-11 14:44 629760 c:\windows\system32\msfeeds.dll
+ 2009-01-07 16:20 . 2009-01-07 16:20 265720 c:\windows\system32\msdbg2.dll
+ 2008-04-14 12:00 . 2011-03-04 06:36 726528 c:\windows\system32\jscript.dll
+ 2009-03-08 02:22 . 2009-03-08 02:22 164352 c:\windows\system32\ieui.dll
+ 2008-04-14 12:00 . 2012-05-11 14:44 184320 c:\windows\system32\iepeers.dll
+ 2008-04-14 12:00 . 2012-05-11 14:44 387584 c:\windows\system32\iedkcs32.dll
+ 2009-03-08 02:11 . 2009-03-08 02:11 445952 c:\windows\system32\ieapfltr.dll
+ 2008-04-14 12:00 . 2009-03-08 02:32 163840 c:\windows\system32\ieakui.dll
+ 2008-04-14 12:00 . 2009-03-08 02:33 229376 c:\windows\system32\ieaksie.dll
+ 2008-04-14 12:00 . 2009-03-08 02:33 125952 c:\windows\system32\ieakeng.dll
+ 2008-04-14 12:00 . 2012-05-11 11:38 174080 c:\windows\system32\ie4uinit.exe
+ 2008-04-14 12:00 . 2009-03-08 02:31 216064 c:\windows\system32\dxtrans.dll
+ 2008-04-14 12:00 . 2009-03-08 02:31 348160 c:\windows\system32\dxtmsft.dll
+ 2008-04-14 12:00 . 2012-05-16 15:09 916992 c:\windows\system32\dllcache\wininet.dll
+ 2008-04-14 12:00 . 2009-03-08 02:34 236544 c:\windows\system32\dllcache\webcheck.dll
+ 2009-01-04 21:08 . 2011-04-30 03:00 758784 c:\windows\system32\dllcache\vgx.dll
+ 2008-04-14 12:00 . 2011-03-04 06:36 420864 c:\windows\system32\dllcache\vbscript.dll
+ 2008-04-14 12:00 . 2012-05-11 14:44 105984 c:\windows\system32\dllcache\url.dll
+ 2009-01-07 16:20 . 2009-01-07 16:20 134144 c:\windows\system32\dllcache\sqmapi.dll
+ 2008-04-14 12:00 . 2012-05-11 14:44 206848 c:\windows\system32\dllcache\occache.dll
+ 2008-04-14 12:00 . 2012-05-11 14:44 611840 c:\windows\system32\dllcache\mstime.dll
+ 2008-04-14 12:00 . 2009-03-08 02:34 193536 c:\windows\system32\dllcache\msrating.dll
+ 2008-04-14 12:00 . 2009-03-08 02:22 156160 c:\windows\system32\dllcache\msls31.dll
+ 2008-04-14 12:00 . 2011-03-04 06:36 726528 c:\windows\system32\dllcache\jscript.dll
+ 2009-01-04 21:07 . 2009-03-08 12:09 638816 c:\windows\system32\dllcache\iexplore.exe
+ 2008-04-14 12:00 . 2012-05-11 14:44 184320 c:\windows\system32\dllcache\iepeers.dll
+ 2008-04-14 12:00 . 2012-05-11 14:44 387584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2008-04-14 12:00 . 2009-03-08 02:32 163840 c:\windows\system32\dllcache\ieakui.dll
+ 2008-04-14 12:00 . 2009-03-08 02:33 229376 c:\windows\system32\dllcache\ieaksie.dll
+ 2008-04-14 12:00 . 2009-03-08 02:33 125952 c:\windows\system32\dllcache\ieakeng.dll
+ 2008-04-14 12:00 . 2012-05-11 11:38 174080 c:\windows\system32\dllcache\ie4uinit.exe
+ 2008-04-14 12:00 . 2009-03-08 02:31 216064 c:\windows\system32\dllcache\dxtrans.dll
+ 2008-04-14 12:00 . 2009-03-08 02:31 348160 c:\windows\system32\dllcache\dxtmsft.dll
+ 2008-04-14 12:00 . 2009-03-08 02:32 128512 c:\windows\system32\dllcache\advpack.dll
+ 2008-04-14 12:00 . 2009-03-08 02:32 128512 c:\windows\system32\advpack.dll
+ 2012-08-03 15:51 . 2012-08-03 15:51 199168 c:\windows\Installer\84517e.msi
+ 2012-08-02 19:26 . 2009-03-08 02:34 914944 c:\windows\ie8updates\KB982381-IE8\wininet.dll
+ 2012-08-02 19:26 . 2010-02-22 14:21 391032 c:\windows\ie8updates\KB982381-IE8\spuninst\updspapi.dll
+ 2012-08-02 19:26 . 2008-07-08 12:59 233848 c:\windows\ie8updates\KB982381-IE8\spuninst\spuninst.exe
+ 2012-08-02 19:26 . 2009-03-08 02:34 109568 c:\windows\ie8updates\KB982381-IE8\occache.dll
+ 2012-08-02 19:26 . 2009-03-08 02:32 611840 c:\windows\ie8updates\KB982381-IE8\mstime.dll
+ 2012-08-02 19:26 . 2009-03-08 02:32 594432 c:\windows\ie8updates\KB982381-IE8\msfeeds.dll
+ 2012-08-02 19:26 . 2009-03-08 02:33 246784 c:\windows\ie8updates\KB982381-IE8\ieproxy.dll
+ 2012-08-02 19:26 . 2009-03-08 02:31 183808 c:\windows\ie8updates\KB982381-IE8\iepeers.dll
+ 2012-08-02 19:26 . 2009-03-08 02:35 742912 c:\windows\ie8updates\KB982381-IE8\iedvtool.dll
+ 2012-08-02 19:26 . 2009-03-08 12:09 391536 c:\windows\ie8updates\KB982381-IE8\iedkcs32.dll
+ 2012-08-02 19:26 . 2009-03-08 02:32 173056 c:\windows\ie8updates\KB982381-IE8\ie4uinit.exe
+ 2012-08-02 19:27 . 2011-11-04 19:13 916992 c:\windows\ie8updates\KB2699988-IE8\wininet.dll
+ 2012-08-02 19:27 . 2011-11-04 19:13 105984 c:\windows\ie8updates\KB2699988-IE8\url.dll
+ 2012-08-02 19:27 . 2010-07-05 13:13 391032 c:\windows\ie8updates\KB2699988-IE8\spuninst\updspapi.dll
+ 2012-08-02 19:27 . 2010-07-05 13:13 233848 c:\windows\ie8updates\KB2699988-IE8\spuninst\spuninst.exe
+ 2012-08-02 19:27 . 2011-11-04 19:13 206848 c:\windows\ie8updates\KB2699988-IE8\occache.dll
+ 2012-08-02 19:27 . 2011-11-04 19:13 611840 c:\windows\ie8updates\KB2699988-IE8\mstime.dll
+ 2012-08-02 19:27 . 2011-11-04 19:13 602112 c:\windows\ie8updates\KB2699988-IE8\msfeeds.dll
+ 2012-08-02 19:27 . 2009-03-08 02:35 521216 c:\windows\ie8updates\KB2699988-IE8\jsdbgui.dll
+ 2012-08-02 19:27 . 2011-11-04 19:13 247808 c:\windows\ie8updates\KB2699988-IE8\ieproxy.dll
+ 2012-08-02 19:27 . 2011-11-04 19:13 184320 c:\windows\ie8updates\KB2699988-IE8\iepeers.dll
+ 2012-08-02 19:27 . 2011-11-04 19:13 743424 c:\windows\ie8updates\KB2699988-IE8\iedvtool.dll
+ 2012-08-02 19:27 . 2011-11-04 19:13 387584 c:\windows\ie8updates\KB2699988-IE8\iedkcs32.dll
+ 2012-08-02 19:27 . 2011-11-04 11:24 174080 c:\windows\ie8updates\KB2699988-IE8\ie4uinit.exe
+ 2012-08-02 19:27 . 2010-05-06 10:35 916480 c:\windows\ie8updates\KB2618444-IE8\wininet.dll
+ 2012-08-02 19:27 . 2009-03-08 02:34 105984 c:\windows\ie8updates\KB2618444-IE8\url.dll
+ 2012-08-02 19:27 . 2010-07-05 13:13 391032 c:\windows\ie8updates\KB2618444-IE8\spuninst\updspapi.dll
+ 2012-08-02 19:27 . 2010-07-05 13:13 233848 c:\windows\ie8updates\KB2618444-IE8\spuninst\spuninst.exe
+ 2012-08-02 19:27 . 2010-05-06 10:35 206848 c:\windows\ie8updates\KB2618444-IE8\occache.dll
+ 2012-08-02 19:27 . 2010-05-06 10:35 611840 c:\windows\ie8updates\KB2618444-IE8\mstime.dll
+ 2012-08-02 19:27 . 2010-05-06 10:35 599040 c:\windows\ie8updates\KB2618444-IE8\msfeeds.dll
+ 2012-08-02 19:27 . 2010-05-06 10:35 247808 c:\windows\ie8updates\KB2618444-IE8\ieproxy.dll
+ 2012-08-02 19:27 . 2010-05-06 10:35 184320 c:\windows\ie8updates\KB2618444-IE8\iepeers.dll
+ 2012-08-02 19:27 . 2010-05-06 10:35 743424 c:\windows\ie8updates\KB2618444-IE8\iedvtool.dll
+ 2012-08-02 19:27 . 2010-05-06 10:35 387584 c:\windows\ie8updates\KB2618444-IE8\iedkcs32.dll
+ 2012-08-02 19:27 . 2010-05-05 13:30 173056 c:\windows\ie8updates\KB2618444-IE8\ie4uinit.exe
+ 2012-08-02 19:27 . 2010-02-22 14:21 391032 c:\windows\ie8updates\KB2598845-IE8\spuninst\updspapi.dll
+ 2012-08-02 19:27 . 2010-02-22 14:20 233848 c:\windows\ie8updates\KB2598845-IE8\spuninst\spuninst.exe
+ 2012-08-05 17:36 . 2009-03-08 02:33 759296 c:\windows\ie8updates\KB2544521-IE8\vgx.dll
+ 2012-08-05 17:36 . 2010-07-05 13:13 391032 c:\windows\ie8updates\KB2544521-IE8\spuninst\updspapi.dll
+ 2012-08-05 17:36 . 2010-07-05 13:13 233848 c:\windows\ie8updates\KB2544521-IE8\spuninst\spuninst.exe
+ 2012-08-05 17:37 . 2009-03-08 02:33 420352 c:\windows\ie8updates\KB2510531-IE8\vbscript.dll
+ 2012-08-05 17:37 . 2010-07-05 13:13 391032 c:\windows\ie8updates\KB2510531-IE8\spuninst\updspapi.dll
+ 2012-08-05 17:37 . 2010-07-05 13:13 233848 c:\windows\ie8updates\KB2510531-IE8\spuninst\spuninst.exe
+ 2012-08-05 17:37 . 2009-03-08 02:33 726528 c:\windows\ie8updates\KB2510531-IE8\jscript.dll
+ 2012-08-02 19:24 . 2012-05-16 07:59 668160 c:\windows\ie8\wininet.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 278528 c:\windows\ie8\webcheck.dll
+ 2012-08-02 19:24 . 2011-04-29 19:07 852480 c:\windows\ie8\vgx.dll
+ 2012-08-02 19:24 . 2011-03-04 06:43 434176 c:\windows\ie8\vbscript.dll
+ 2012-08-02 19:24 . 2012-04-20 19:30 627712 c:\windows\ie8\urlmon.dll
+ 2012-08-02 19:24 . 2009-01-07 16:21 382496 c:\windows\ie8\spuninst\updspapi.dll
+ 2012-08-02 19:24 . 2009-01-07 16:20 231456 c:\windows\ie8\spuninst\spuninst.exe
+ 2012-08-02 19:24 . 2012-04-20 19:30 532480 c:\windows\ie8\mstime.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 146432 c:\windows\ie8\msrating.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 146432 c:\windows\ie8\msls31.dll
+ 2012-08-02 19:24 . 2012-04-20 19:30 449536 c:\windows\ie8\mshtmled.dll
+ 2012-08-02 19:24 . 2011-03-04 06:43 512000 c:\windows\ie8\jscript.dll
+ 2012-08-02 19:24 . 2012-04-20 19:30 251904 c:\windows\ie8\iepeers.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 323584 c:\windows\ie8\iedkcs32.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 225280 c:\windows\ie8\ieakui.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 219136 c:\windows\ie8\ieaksie.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 143360 c:\windows\ie8\ieakeng.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 205312 c:\windows\ie8\dxtrans.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 357888 c:\windows\ie8\dxtmsft.dll
+ 2012-08-02 19:24 . 2008-04-14 12:00 100352 c:\windows\ie8\advpack.dll
+ 2008-04-14 12:00 . 2012-05-11 14:44 1212416 c:\windows\system32\urlmon.dll
+ 2008-04-14 12:00 . 2012-05-11 14:44 6007808 c:\windows\system32\mshtml.dll
+ 2009-03-08 02:32 . 2012-05-11 14:44 2000384 c:\windows\system32\iertutil.dll
+ 2009-02-06 19:07 . 2009-02-06 19:07 3698584 c:\windows\system32\ieapfltr.dat
+ 2008-04-14 12:00 . 2012-05-11 14:44 1212416 c:\windows\system32\dllcache\urlmon.dll
+ 2008-04-14 12:00 . 2012-05-11 14:44 6007808 c:\windows\system32\dllcache\mshtml.dll
+ 2012-08-02 19:26 . 2009-03-08 02:34 1206784 c:\windows\ie8updates\KB982381-IE8\urlmon.dll
+ 2012-08-02 19:26 . 2009-03-08 02:41 5937152 c:\windows\ie8updates\KB982381-IE8\mshtml.dll
+ 2012-08-02 19:26 . 2009-03-08 02:32 1985024 c:\windows\ie8updates\KB982381-IE8\iertutil.dll
+ 2012-08-02 19:27 . 2011-11-04 19:13 1212416 c:\windows\ie8updates\KB2699988-IE8\urlmon.dll
+ 2012-08-02 19:27 . 2011-11-04 19:13 5978112 c:\windows\ie8updates\KB2699988-IE8\mshtml.dll
+ 2012-08-02 19:27 . 2011-11-04 19:13 2000384 c:\windows\ie8updates\KB2699988-IE8\iertutil.dll
+ 2012-08-02 19:27 . 2010-05-06 10:35 1209344 c:\windows\ie8updates\KB2618444-IE8\urlmon.dll
+ 2012-08-02 19:27 . 2010-05-06 10:35 5950976 c:\windows\ie8updates\KB2618444-IE8\mshtml.dll
+ 2012-08-02 19:27 . 2010-05-06 10:35 1985536 c:\windows\ie8updates\KB2618444-IE8\iertutil.dll
+ 2012-08-02 19:24 . 2012-04-20 19:30 3109376 c:\windows\ie8\mshtml.dll
+ 2009-03-08 02:39 . 2012-05-11 18:14 11111424 c:\windows\system32\ieframe.dll
+ 2012-08-02 19:26 . 2009-03-08 02:39 11063808 c:\windows\ie8updates\KB982381-IE8\ieframe.dll
+ 2012-08-02 19:27 . 2011-11-05 12:13 11081728 c:\windows\ie8updates\KB2699988-IE8\ieframe.dll
+ 2012-08-02 19:27 . 2010-05-06 10:35 11076096 c:\windows\ie8updates\KB2618444-IE8\ieframe.dll
.
-- Snímek resetován k současnému datu --
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-07-03 16:21 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Facebook Update"="c:\documents and settings\Sašenka\Local Settings\Data aplikací\Facebook\Update\FacebookUpdate.exe" [2012-08-03 138096]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsgTranAgt"="c:\program files\ASUS\ATK Hotkey\MsgTranAgt.exe" [2007-11-04 106496]
"HControlUser"="c:\program files\ASUS\ATK Hotkey\HControlUser.exe" [2008-01-11 98304]
"ATKHOTKEY"="c:\program files\ASUS\ATK Hotkey\HControl.exe" [2008-06-26 217088]
"ATKOSD2"="c:\program files\ATKOSD2\ATKOSD2.exe" [2008-01-23 7766016]
"ATKMEDIA"="c:\program files\ASUS\ATK Media\DMEDIA.EXE" [2008-02-01 61440]
"RTHDCPL"="RTHDCPL.EXE" [2008-06-20 16872448]
"Power_Gear"="c:\program files\ASUS\Power4 Gear\BatteryLife.exe" [2006-07-26 90112]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-07-03 4273976]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\Sašenka\Nabídka Start\Programy\Po spuštění\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
CCC.lnk - c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [2007-7-17 49152]
Facebook Messenger.lnk - c:\documents and settings\Sašenka\Local Settings\Data aplikací\Facebook\Messenger\2.1.4590.0\FacebookMessenger.exe [2012-7-26 244656]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Bluetooth.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesHelper]
2011-09-29 14:19 929680 ----a-w- c:\program files\Samsung\Kies\KiesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesPDLR]
2011-09-29 14:19 20880 ----a-w- c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]
2011-09-29 14:19 3508112 ----a-w- c:\program files\Samsung\Kies\KiesTrayAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyTomTomSA.exe]
2011-11-14 11:02 435672 ----a-w- c:\program files\MyTomTom 3\MyTomTomSA.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Seznam Postak]
2009-11-02 13:05 448664 ----a-w- c:\program files\Seznam.cz\postak.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Companion]
2011-10-21 13:06 433872 ----a-w- c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Sony Ericsson\\Update Engine\\Sony Ericsson Update Engine.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\ICQ7.5\\ICQ.exe"=
.
R0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [5.1.2009 9:55 160640]
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [5.1.2009 9:55 5248]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [12.11.2011 18:41 721000]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [12.11.2011 18:41 353688]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [12.11.2011 18:41 21256]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [12.7.2012 20:20 655944]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [5.1.2009 9:08 36608]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [12.7.2012 20:20 22344]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\drivers\ssadadb.sys [9.10.2011 10:35 30312]
S3 IpwP;IPWireless 3G Network Adapter;c:\windows\system32\drivers\ipw3gnet.sys [5.1.2009 21:25 51040]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [3.5.2012 17:49 113120]
S3 s0017bus;Sony Ericsson Device 0017 driver (WDM);c:\windows\system32\drivers\s0017bus.sys [19.3.2011 19:40 86824]
S3 s0017mdfl;Sony Ericsson Device 0017 USB WMC Modem Filter;c:\windows\system32\drivers\s0017mdfl.sys [19.3.2011 19:40 15016]
S3 s0017mdm;Sony Ericsson Device 0017 USB WMC Modem Driver;c:\windows\system32\drivers\s0017mdm.sys [19.3.2011 19:40 114600]
S3 s0017mgmt;Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0017mgmt.sys [19.3.2011 19:40 108328]
S3 s0017nd5;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS);c:\windows\system32\drivers\s0017nd5.sys [19.3.2011 19:40 26024]
S3 s0017obex;Sony Ericsson Device 0017 USB WMC OBEX Interface;c:\windows\system32\drivers\s0017obex.sys [19.3.2011 19:40 104616]
S3 s0017unic;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM);c:\windows\system32\drivers\s0017unic.sys [19.3.2011 19:40 109736]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [19.3.2011 19:39 155344]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [9.10.2011 10:35 121064]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [9.10.2011 10:35 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [9.10.2011 10:35 136808]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\drivers\ssadserd.sys [9.10.2011 10:35 114280]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [24.6.2010 7:51 11520]
.
Obsah adresáře 'Naplánované úlohy'
.
2012-08-05 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2012-07-20 16:21]
.
2012-08-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-23 07:52]
.
2012-08-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-23 07:52]
.
.
------- Doplňkový sken -------
.
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
FF - ProfilePath - c:\documents and settings\Sašenka\Data aplikací\Mozilla\Firefox\Profiles\0xa4a2pg.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.oblibene-stranky.cz/
pref('extensions.shownSelectionUI',true); pref('extensions.autoDisableScopes',0);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-05 20:08
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(988)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(5372)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\ATKGFNEX\GFNEXSrv.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\RTHDCPL.EXE
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\documents and settings\Sac:\documents and settings\Sac:\program files\ASUS\ATK Hotkey\ATKOSD.exe
c:\program files\ASUS\ATK Hotkey\KBFiltr.exe
c:\program files\ASUS\ATK Hotkey\WDC.exe
.
**************************************************************************
.
Celkový čas: 2012-08-05 20:13:32 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-08-05 18:13
ComboFix2.txt 2012-01-06 21:25
ComboFix3.txt 2011-11-12 16:29
.
Před spuštěním: 3 489 894 400
Po spuštění: 3 426 832 384
.
- - End Of File - - 7B151E3FBB5366C75CAA3DFD66DFD20D
Re: Poprosím o kontrolu logu-pomalý a sekající se notebook.D
Teda ne adobe, ale flashplayer... Uz blbnu... Diky.
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Poprosím o kontrolu logu-pomalý a sekající se notebook.D
Start-spustit-napiš: notepad ,do něho vlož tento celý text:
uložit na plochu s názvem: find.bat (typ souboru- všechny soubory)
Najdi ho na ploše, poklepej na něj a počkej až se okno zavře a objeví se soubor.txt
Vlož sem potom celý text z tohoto souboru.
Kód: Vybrat vše
dir \atapi.sys /a h /s > File.txt
uložit na plochu s názvem: find.bat (typ souboru- všechny soubory)
Najdi ho na ploše, poklepej na něj a počkej až se okno zavře a objeví se soubor.txt
Vlož sem potom celý text z tohoto souboru.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Poprosím o kontrolu logu-pomalý a sekající se notebook.D
Ok, udelam. Co mam delat s tim flashplayerem?
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Poprosím o kontrolu logu-pomalý a sekající se notebook.D
S Playerem? Chci abys měl aktuální verzi.
a atapi.sys je to horší , budeme muset soubor vyměnit...
Udělej o co jsem Tě žádal..
+
Stáhni si Security Check by screen317 z některého odkazu
http://screen317.spywareinfoforum.org/SecurityCheck.exe
http://screen317.changelog.fr/SecurityCheck.exe
ulož si ho na plochu, poklepej na něj a postupuj podle instrukcí v černém okně. Potom se automaticky otevře pozn. Blok, bude mít název checkup.txt. Jeho obsah sem prosím zkopíruj.
a atapi.sys je to horší , budeme muset soubor vyměnit...
Udělej o co jsem Tě žádal..
+
Stáhni si Security Check by screen317 z některého odkazu
http://screen317.spywareinfoforum.org/SecurityCheck.exe
http://screen317.changelog.fr/SecurityCheck.exe
ulož si ho na plochu, poklepej na něj a postupuj podle instrukcí v černém okně. Potom se automaticky otevře pozn. Blok, bude mít název checkup.txt. Jeho obsah sem prosím zkopíruj.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Poprosím o kontrolu logu-pomalý a sekající se notebook.D
Takze security Check:
Results of screen317's Security Check version 0.99.43
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
avast! Free Antivirus
`````````Anti-malware/Other Utilities Check:`````````
Out of date HijackThis installed!
Malwarebytes Anti-Malware verze 1.62.0.1300
HijackThis 2.0.2
CCleaner
Java(TM) 6 Update 30
Java version out of Date!
Adobe Reader 8 Adobe Reader out of Date!
Adobe Reader X KB403742.. Adobe Reader out of Date!
Mozilla Firefox (14.0.1)
Google Chrome 20.0.1132.57
Google Chrome 21.0.1180.60
Google Chrome VisualElementsManifest.xml..
````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
AVAST Software Avast AvastSvc.exe
AVAST Software Avast avastUI.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C::
````````````````````End of Log``````````````````````
a find.bat log:
Svazek v jednotce C je Systém.
Sériové číslo svazku je 24EC-0066.
Výpis adresáře C:\WINDOWS\system32\drivers
14.04.2008 14:00 96 512 atapi.sys
1 souborů, 96 512 bajtů
Results of screen317's Security Check version 0.99.43
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
avast! Free Antivirus
`````````Anti-malware/Other Utilities Check:`````````
Out of date HijackThis installed!
Malwarebytes Anti-Malware verze 1.62.0.1300
HijackThis 2.0.2
CCleaner
Java(TM) 6 Update 30
Java version out of Date!
Adobe Reader 8 Adobe Reader out of Date!
Adobe Reader X KB403742.. Adobe Reader out of Date!
Mozilla Firefox (14.0.1)
Google Chrome 20.0.1132.57
Google Chrome 21.0.1180.60
Google Chrome VisualElementsManifest.xml..
````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
AVAST Software Avast AvastSvc.exe
AVAST Software Avast avastUI.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C::
````````````````````End of Log``````````````````````
a find.bat log:
Svazek v jednotce C je Systém.
Sériové číslo svazku je 24EC-0066.
Výpis adresáře C:\WINDOWS\system32\drivers
14.04.2008 14:00 96 512 atapi.sys
1 souborů, 96 512 bajtů
Re: Poprosím o kontrolu logu-pomalý a sekající se notebook.D
Jeste jsem se nekde docetl o programu RSIT vuci atapi.sys. Je to k necemu nebo k nicemu?
) Ale necham to samozrejme na tobe. Diky.

- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Poprosím o kontrolu logu-pomalý a sekající se notebook.D
jaro3 píše:Start-spustit-napiš: notepad ,do něho vlož tento celý text:Kód: Vybrat vše
dir \atapi.sys /a h /s > File.txt
uložit na plochu s názvem: find.bat (typ souboru- všechny soubory)
Najdi ho na ploše, poklepej na něj a počkej až se okno zavře a objeví se soubor.txt
Vlož sem potom celý text z tohoto souboru.
Kde je ten log?
Nevím o co se jedná , nerozumím..Jeste jsem se nekde docetl o programu RSIT vuci atapi.sys. Je to k necemu nebo k nicemu? ) Ale necham to samozrejme na tobe. Diky.
Java version out of Date!
Adobe Reader 8 Adobe Reader out of Date!
Adobe Reader X KB403742.. Adobe Reader out of Date!
Aktualizuj javu:
Java SE Runtime Environment 7
Klikni na Accept License Agreement
Vyber si OS (Windows nebo Windows x64, Offline Installation)
jre-7-windows-i586-p.exe nebo
jre-7-windows-x64.exe
Stáhni ( download) a nainstaluj.
Ostatní javy odeber v přidat/odebrat programy.
Adobe Reader---aktualizuj:
http://get.adobe.com/cz/reader/
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Poprosím o kontrolu logu-pomalý a sekající se notebook.D
Ten jsem sem uz vkladal... Tak znovu:
Svazek v jednotce C je Systém.
Sériové číslo svazku je 24EC-0066.
Výpis adresáře C:\WINDOWS\system32\drivers
14.04.2008 14:00 96 512 atapi.sys
1 souborů, 96 512 bajtů
Svazek v jednotce C je Systém.
Sériové číslo svazku je 24EC-0066.
Výpis adresáře C:\WINDOWS\system32\drivers
14.04.2008 14:00 96 512 atapi.sys
1 souborů, 96 512 bajtů
Re: Poprosím o kontrolu logu-pomalý a sekající se notebook.D
U Adobe Readeru mi to napsalo to same jako u flashplayeru - u padesati procent instalace "iniciace selhala"...
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 83 hostů