Obsah fóra
PravidláRegistrovaťPrihlásenie




Odpovedať na tému [ Príspevkov: 22 ] 
AutorSpráva
Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 25.12.08
Prihlásený: 15.06.10
Príspevky: 76
Témy: 12
Príspevok NapísalOffline : 17.10.2009 14:14

zdravím,
mal som v compe norton antivirus a potom som prešiel na norton internet security. teraz, keď naštartujem systém, vždy mi vyhadzuje tabuľku, že sa chce spustiť inštalácia norton antivirus i keď som ho z počítača vymazal.
vie niekto poradiť? ďakujem


Offline

Čestný člen
Čestný člen
norton

Registrovaný: 25.05.05
Prihlásený: 15.11.21
Príspevky: 1446
Témy: 24
Bydlisko: Zeměpisná š...
Príspevok NapísalOffline : 17.10.2009 22:16

Každopádne Ti poradim aby jsi si upravil název tematu, tohle má nekomu říct co mas za problem?
Unistal jsi neprovedl dobre, neco je jeste spuštěno, takže vyčisti registry a podivej se do položky po spušteni v msconfig. Věštím z koule, jelikož nejsi ani schopny nám řict co máš za system!







_________________
CPU: AMD Barton 2600Mobile@3512+ 205x11,5 2360MHz, Cooling: Arctic-Cooling Copper Silent 2L, RAM: Geil Ultra Dual Channel 2x512MB 11-3-3-2 MB: Epox 8RDA3+(nforce2,rev.2.x) VGA: NV Gainward 8248-Bliss 7600GT GPU 668 DDR3 1560, HDD: SATA Baracuda 80GB, SATA WD 160GB, DVD RW: Teac DV-W516D, CD RW: BENQ CRW4816P, TV karta: LeadtekWinFast, Sat.karta: SkyStar 2, Monitor: LCD AOC LM 729, Case: Neon Light, 2xSharkoon Fan, Repro: Hercules XPS 2100, Zdroj: Fortron 350W, OS: Win: ME,XP, Linux: SuSE
[b]Acer TravelMate 4502LCi
Přes ICQ a SZ mě kvůli PC nekontaktujte, proto tu je naše fórum;-)
Offline

Skúsený užívateľ
Skúsený užívateľ
Obrázok užívateľa

Registrovaný: 15.08.09
Prihlásený: 05.02.10
Príspevky: 355
Témy: 0
Príspevok NapísalOffline : 18.10.2009 13:47

>>Tu<< najdes oficialny odinstalator.


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 25.12.08
Prihlásený: 15.06.10
Príspevky: 76
Témy: 12
Príspevok Napísal autor témyOffline : 18.10.2009 18:12

som schopný ti to povedať, len som nevedel, že to je dôležité. mám vistu home basic 32 bit.
idem skúsiť ten uninstall...


no, tak práve som to odinštaloval cez ten removal tool. reštartol som počítač a zasa sa mi chcel sám od seba inštalovať norton antivirus.


Offline

Skúsený užívateľ
Skúsený užívateľ
Obrázok užívateľa

Registrovaný: 15.08.09
Prihlásený: 05.02.10
Príspevky: 355
Témy: 0
Príspevok NapísalOffline : 18.10.2009 21:43

Stiahni RSIT. Spust, klik na "Continue". Po dokoneceni by se ti mal otvorit textovy subor. Ten skopiruj sem.
Pokial by sa nieco stalo, najdes ho aj na adrese "C:\rsit\log.txt".


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 25.12.08
Prihlásený: 15.06.10
Príspevky: 76
Témy: 12
Príspevok Napísal autor témyOffline : 18.10.2009 21:51

hádam to je správne...

Logfile of random's system information tool 1.06 (written by random/random)
Run by pepinho at 2009-10-18 21:48:09
Microsoft® Windows Vista™ Home Basic Service Pack 1
System drive C: has 8 GB (21%) free of 40 GB
Total RAM: 3070 MB (62% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:48:16, on 18. 10. 2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\SYSTEM32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\System Control Manager\MGSysCtrl.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\SweetIM\Messenger\SweetIM.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\ICQ6.5\ICQ.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\explorer.exe
G:\downloads\RSIT.exe
C:\Program Files\trend micro\pepinho.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\ProgramData\LangSoft\WebIE.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\17.0.0.136\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\17.0.0.136\IPSBHO.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\ProgramData\LangSoft\WebIE.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\17.0.0.136\coIEPlg.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [MGSysCtrl] C:\Program Files\System Control Manager\MGSysCtrl.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [winlog.exe] C:\Users\pepinho\AppData\Roaming\Microsoft\winlog.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Defragmentation-Service (DfSdkS) - mst software GmbH, Germany - C:\Program Files\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe
O23 - Service: Micro Star SCM - Unknown owner - C:\Program Files\System Control Manager\MSIService.exe
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\17.0.0.136\ccSvcHst.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe

--
End of file - 7518 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\ProgramData\LangSoft\WebIE.dll [2009-10-14 520192]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Symantec NCO BHO - C:\Program Files\Norton Internet Security\Engine\17.0.0.136\coIEPlg.dll [2009-08-29 392560]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Symantec Intrusion Prevention - C:\Program Files\Norton Internet Security\Engine\17.0.0.136\IPSBHO.DLL [2009-08-30 79224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
SweetIM Toolbar Helper - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2009-05-20 1258808]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EEE6C35B-6118-11DC-9C72-001320C79847} - SweetIM Toolbar for Internet Explorer - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2009-05-20 1258808]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2009-04-23 937416]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\ProgramData\LangSoft\WebIE.dll [2009-10-14 520192]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files\Norton Internet Security\Engine\17.0.0.136\coIEPlg.dll [2009-08-29 392560]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-01-21 61440]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-08-20 6265376]
"Skytel"=C:\Windows\Skytel.exe [2008-08-20 1833504]
"MGSysCtrl"=C:\Program Files\System Control Manager\MGSysCtrl.exe [2008-08-26 708608]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"SweetIM"=C:\Program Files\SweetIM\Messenger\SweetIM.exe [2009-08-26 111928]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-01-21 1233920]
"winlog.exe"=C:\Users\pepinho\AppData\Roaming\Microsoft\winlog.exe [2009-10-08 77434880]
"OEXPRESS"= []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\psfus]
C:\Windows\system32\psqlpwd.dll [2008-04-29 96008]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
psqlpwd

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
"DisableCAD"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoResolveTrack"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0625ea88-b4ce-11de-a50e-002185d9f9f6}]
shell\AutoRun\command - F:\AUTOSTARTER.EXE


======List of files/folders created in the last 1 months======

2009-10-18 21:48:09 ----D---- C:\rsit
2009-10-18 21:48:09 ----D---- C:\Program Files\trend micro
2009-10-18 18:47:40 ----D---- C:\Users\pepinho\AppData\Roaming\Tific
2009-10-18 18:36:08 ----D---- C:\Program Files\Symantec
2009-10-18 18:36:08 ----D---- C:\Program Files\Common Files\Symantec Shared
2009-10-18 18:35:17 ----D---- C:\Program Files\Norton Internet Security
2009-10-18 18:29:08 ----D---- C:\Program Files\NortonInstaller
2009-10-14 16:38:27 ----D---- C:\Program Files\Common Files\Adobe AIR
2009-10-14 16:36:31 ----D---- C:\ProgramData\Adobe
2009-10-14 16:36:28 ----D---- C:\Program Files\Common Files\Adobe
2009-10-14 16:36:28 ----D---- C:\Program Files\Adobe
2009-10-14 10:25:22 ----A---- C:\Windows\TRNCOM.INI
2009-10-14 10:23:39 ----A---- C:\Windows\WTRDCTM.INI
2009-10-14 10:22:41 ----D---- C:\ProgramData\LangSoft
2009-10-14 10:22:30 ----D---- C:\Users\pepinho\AppData\Roaming\LangSoft
2009-10-11 13:04:54 ----D---- C:\Users\pepinho\AppData\Roaming\Ashampoo
2009-10-09 14:51:39 ----D---- C:\Windows\system32\AGEIA
2009-10-09 14:51:39 ----D---- C:\Program Files\AGEIA Technologies
2009-10-09 14:51:22 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2009-10-09 14:50:49 ----A---- C:\Windows\system32\XAudio2_3.dll
2009-10-09 14:50:49 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2009-10-09 14:50:49 ----A---- C:\Windows\system32\D3DX9_40.dll
2009-10-09 14:50:49 ----A---- C:\Windows\system32\d3dx10_40.dll
2009-10-09 14:50:49 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2009-10-09 14:50:47 ----A---- C:\Windows\system32\xactengine3_3.dll
2009-10-09 14:50:47 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2009-10-09 14:50:46 ----A---- C:\Windows\system32\XAudio2_2.dll
2009-10-09 14:50:46 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2009-10-09 14:50:45 ----A---- C:\Windows\system32\xactengine3_2.dll
2009-10-09 14:50:45 ----A---- C:\Windows\system32\D3DX9_39.dll
2009-10-09 14:50:45 ----A---- C:\Windows\system32\d3dx10_39.dll
2009-10-09 14:50:45 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2009-10-09 14:50:44 ----A---- C:\Windows\system32\XAudio2_1.dll
2009-10-09 14:50:44 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2009-10-09 14:50:43 ----A---- C:\Windows\system32\xactengine3_1.dll
2009-10-09 14:50:42 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2009-10-09 14:50:42 ----A---- C:\Windows\system32\D3DX9_38.dll
2009-10-09 14:50:42 ----A---- C:\Windows\system32\d3dx10_38.dll
2009-10-09 14:50:42 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2009-10-09 14:50:40 ----A---- C:\Windows\system32\XAudio2_0.dll
2009-10-09 14:50:40 ----A---- C:\Windows\system32\xactengine3_0.dll
2009-10-09 14:50:39 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2009-10-09 14:50:39 ----A---- C:\Windows\system32\d3dx10_37.dll
2009-10-09 14:50:39 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2009-10-09 14:50:37 ----A---- C:\Windows\system32\D3DX9_37.dll
2009-10-09 14:50:36 ----A---- C:\Windows\system32\xactengine2_10.dll
2009-10-09 14:50:34 ----A---- C:\Windows\system32\d3dx10_36.dll
2009-10-09 14:50:34 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2009-10-09 14:50:33 ----A---- C:\Windows\system32\xactengine2_9.dll
2009-10-09 14:50:33 ----A---- C:\Windows\system32\d3dx9_36.dll
2009-10-09 14:50:32 ----A---- C:\Windows\system32\d3dx9_35.dll
2009-10-09 14:50:32 ----A---- C:\Windows\system32\d3dx10_35.dll
2009-10-09 14:50:32 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2009-10-09 14:50:31 ----A---- C:\Windows\system32\xactengine2_8.dll
2009-10-09 14:50:31 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2009-10-09 14:50:31 ----A---- C:\Windows\system32\d3dx9_34.dll
2009-10-09 14:50:31 ----A---- C:\Windows\system32\d3dx10_34.dll
2009-10-09 14:50:31 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2009-10-09 14:50:30 ----A---- C:\Windows\system32\xinput1_3.dll
2009-10-09 14:50:29 ----A---- C:\Windows\system32\xactengine2_7.dll
2009-10-09 14:50:29 ----A---- C:\Windows\system32\d3dx10_33.dll
2009-10-09 14:50:29 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2009-10-09 14:50:28 ----A---- C:\Windows\system32\xactengine2_6.dll
2009-10-09 14:50:28 ----A---- C:\Windows\system32\d3dx9_33.dll
2009-10-09 14:50:27 ----A---- C:\Windows\system32\xactengine2_5.dll
2009-10-09 14:50:27 ----A---- C:\Windows\system32\d3dx9_32.dll
2009-10-09 14:50:27 ----A---- C:\Windows\system32\d3dx10.dll
2009-10-09 14:50:26 ----A---- C:\Windows\system32\xactengine2_4.dll
2009-10-09 14:50:26 ----A---- C:\Windows\system32\x3daudio1_1.dll
2009-10-09 14:50:26 ----A---- C:\Windows\system32\d3dx9_31.dll
2009-10-09 14:50:25 ----A---- C:\Windows\system32\xactengine2_3.dll
2009-10-09 14:50:24 ----A---- C:\Windows\system32\xinput1_2.dll
2009-10-09 14:50:24 ----A---- C:\Windows\system32\xactengine2_2.dll
2009-10-09 14:50:23 ----A---- C:\Windows\system32\xinput1_1.dll
2009-10-09 14:50:23 ----A---- C:\Windows\system32\xactengine2_1.dll
2009-10-09 14:50:16 ----A---- C:\Windows\system32\d3dx9_30.dll
2009-10-09 14:50:15 ----A---- C:\Windows\system32\xactengine2_0.dll
2009-10-09 14:50:15 ----A---- C:\Windows\system32\x3daudio1_0.dll
2009-10-09 14:50:15 ----A---- C:\Windows\system32\d3dx9_29.dll
2009-10-09 14:50:14 ----A---- C:\Windows\system32\d3dx9_28.dll
2009-10-09 14:50:14 ----A---- C:\Windows\system32\d3dx9_27.dll
2009-10-09 14:50:14 ----A---- C:\Windows\system32\d3dx9_26.dll
2009-10-09 14:50:13 ----A---- C:\Windows\system32\d3dx9_25.dll
2009-10-09 14:50:12 ----A---- C:\Windows\system32\d3dx9_24.dll
2009-10-09 14:23:43 ----D---- C:\Users\pepinho\AppData\Roaming\DAEMON Tools Pro
2009-10-09 14:23:43 ----D---- C:\Users\pepinho\AppData\Roaming\DAEMON Tools
2009-10-09 14:22:48 ----D---- C:\ProgramData\DAEMON Tools Lite
2009-10-09 14:22:25 ----D---- C:\Program Files\DAEMON Tools Toolbar
2009-10-09 14:21:52 ----D---- C:\Program Files\DAEMON Tools Lite
2009-10-09 14:17:29 ----D---- C:\Users\pepinho\AppData\Roaming\DAEMON Tools Lite
2009-10-08 20:03:05 ----D---- C:\ProgramData\Norton
2009-10-08 20:02:16 ----D---- C:\ProgramData\NortonInstaller
2009-10-08 16:55:03 ----D---- C:\ProgramData\SweetIM
2009-10-08 16:55:03 ----D---- C:\Program Files\SweetIM
2009-10-08 12:05:58 ----A---- C:\Windows\system32\msonpmon.dll
2009-10-08 12:04:49 ----D---- C:\Program Files\Microsoft Works
2009-10-08 12:04:15 ----D---- C:\Program Files\Microsoft Visual Studio
2009-10-08 12:04:15 ----D---- C:\Program Files\Common Files\DESIGNER
2009-10-08 12:03:34 ----D---- C:\Windows\PCHEALTH
2009-10-08 12:03:34 ----D---- C:\Program Files\Microsoft.NET
2009-10-08 12:01:47 ----D---- C:\Program Files\Microsoft Visual Studio 8
2009-10-08 12:01:15 ----D---- C:\Windows\SHELLNEW
2009-10-08 12:00:49 ----D---- C:\ProgramData\Microsoft Help
2009-10-08 12:00:49 ----D---- C:\Program Files\Microsoft Office
2009-10-08 11:53:31 ----D---- C:\Program Files\uTorrent
2009-10-08 11:53:21 ----D---- C:\Users\pepinho\AppData\Roaming\uTorrent
2009-10-08 11:44:08 ----D---- C:\Program Files\The KMPlayer
2009-10-08 11:36:53 ----D---- C:\Users\pepinho\AppData\Roaming\ICQ
2009-10-08 11:36:26 ----D---- C:\Program Files\ICQ6.5
2009-10-08 10:40:30 ----D---- C:\Users\pepinho\AppData\Roaming\WinRAR
2009-10-08 10:39:50 ----D---- C:\Program Files\WinRAR
2009-10-08 09:47:40 ----A---- C:\Windows\system32\DfSdkBt.exe
2009-10-08 09:47:35 ----D---- C:\Program Files\Ashampoo
2009-10-08 08:48:09 ----A---- C:\Windows\system32\MSVCR71.dll
2009-10-08 08:48:09 ----A---- C:\Windows\system32\MSVCP71.dll
2009-10-08 08:48:09 ----A---- C:\Windows\system32\MFC71.dll
2009-10-08 08:48:07 ----D---- C:\Program Files\Alwil Software
2009-10-07 23:30:34 ----D---- C:\ProgramData\Backup
2009-10-07 22:31:27 ----D---- C:\Users\pepinho\AppData\Roaming\Mozilla
2009-10-07 22:31:22 ----D---- C:\Program Files\Mozilla Firefox
2009-10-07 22:22:46 ----D---- C:\Program Files\Toshiba
2009-10-07 22:20:15 ----A---- C:\ProgramData\CameraRecorder.ini
2009-10-07 22:19:58 ----D---- C:\Program Files\Camera Recorder
2009-10-07 22:16:34 ----D---- C:\Program Files\Dolby
2009-10-07 22:14:14 ----N---- C:\Windows\system32\MpSigStub.exe
2009-10-07 21:54:06 ----A---- C:\Windows\system32\msiapcfg.dll
2009-10-07 21:54:04 ----D---- C:\Program Files\System Control Manager
2009-10-07 21:46:49 ----D---- C:\Users\pepinho\AppData\Roaming\Protector Suite
2009-10-07 21:42:54 ----D---- C:\Program Files\RSA
2009-10-07 21:42:54 ----D---- C:\Program Files\Common Files\SPBA
2009-10-07 21:42:49 ----D---- C:\Program Files\Protector Suite QL
2009-10-07 21:42:19 ----D---- C:\ProgramData\UIB
2009-10-07 21:41:43 ----D---- C:\Windows\Panther
2009-10-07 21:41:17 ----D---- C:\Users\pepinho\AppData\Roaming\Macromedia
2009-10-07 21:41:17 ----D---- C:\Users\pepinho\AppData\Roaming\Adobe
2009-10-07 21:41:16 ----D---- C:\Windows\system32\Macromed
2009-10-07 21:39:52 ----A---- C:\Windows\system32\wups2.dll
2009-10-07 21:39:52 ----A---- C:\Windows\system32\wucltux.dll
2009-10-07 21:39:52 ----A---- C:\Windows\system32\wuaueng.dll
2009-10-07 21:39:52 ----A---- C:\Windows\system32\wuauclt.exe
2009-10-07 21:39:35 ----A---- C:\Windows\system32\wups.dll
2009-10-07 21:39:35 ----A---- C:\Windows\system32\wudriver.dll
2009-10-07 21:39:35 ----A---- C:\Windows\system32\wuapi.dll
2009-10-07 21:39:11 ----A---- C:\Windows\system32\wuwebv.dll
2009-10-07 21:39:11 ----A---- C:\Windows\system32\wuapp.exe
2009-10-07 21:38:51 ----D---- C:\Program Files\DIFX
2009-10-07 21:35:14 ----N---- C:\Windows\system32\agrscoin.dll
2009-10-07 21:35:14 ----A---- C:\Windows\system32\agrsmsvc.exe
2009-10-07 21:35:14 ----A---- C:\Windows\agrsmdel.exe
2009-10-07 21:35:04 ----D---- C:\Windows\Options
2009-10-07 21:33:31 ----D---- C:\Windows\system32\nn-NO
2009-10-07 21:33:30 ----A---- C:\Windows\system32\S64CPA.exe
2009-10-07 21:33:30 ----A---- C:\Windows\system32\athihvui.dll
2009-10-07 21:33:26 ----A---- C:\Windows\system32\athihvs.dll
2009-10-07 21:31:50 ----D---- C:\Program Files\Cisco
2009-10-07 21:31:50 ----D---- C:\Program Files\Atheros
2009-10-07 21:31:14 ----D---- C:\ProgramData\Atheros
2009-10-07 21:30:16 ----D---- C:\Users\pepinho\AppData\Roaming\InstallShield
2009-10-07 21:24:50 ----D---- C:\Windows\system32\RTCOM
2009-10-07 21:24:18 ----A---- C:\Windows\DIFxAPI.dll
2009-10-07 21:24:17 ----A---- C:\Windows\system32\RtkHDMI.dll
2009-10-07 21:24:17 ----A---- C:\Windows\system32\RHDMIExt.dll
2009-10-07 21:24:17 ----A---- C:\Windows\RtkUpd.exe
2009-10-07 21:24:15 ----A---- C:\Windows\system32\WavesLib.dll
2009-10-07 21:24:15 ----A---- C:\Windows\system32\SRSWOW.dll
2009-10-07 21:24:15 ----A---- C:\Windows\system32\SRSTSXT.dll
2009-10-07 21:24:15 ----A---- C:\Windows\system32\SRSTSHD.dll
2009-10-07 21:24:15 ----A---- C:\Windows\system32\SRSHP360.dll
2009-10-07 21:24:15 ----A---- C:\Windows\SkyTel.exe
2009-10-07 21:24:15 ----A---- C:\Windows\RtlUpd.exe
2009-10-07 21:24:14 ----A---- C:\Windows\system32\RtkPgExt.dll
2009-10-07 21:24:14 ----A---- C:\Windows\system32\RtkCoInst.dll
2009-10-07 21:24:14 ----A---- C:\Windows\system32\RtkApoApi.dll
2009-10-07 21:24:14 ----A---- C:\Windows\system32\RtkAPO.dll
2009-10-07 21:24:13 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2009-10-07 21:24:13 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2009-10-07 21:24:13 ----A---- C:\Windows\system32\MaxxAudioAPO.dll
2009-10-07 21:24:13 ----A---- C:\Windows\RtHDVCpl.exe
2009-10-07 21:24:12 ----HD---- C:\Program Files\InstallShield Installation Information
2009-10-07 21:24:12 ----D---- C:\Program Files\Realtek
2009-10-07 21:24:12 ----A---- C:\Windows\system32\FMAPO.dll
2009-10-07 21:24:10 ----R---- C:\Windows\RtlExUpd.dll
2009-10-07 21:24:10 ----A---- C:\Windows\HideWin.exe
2009-10-07 21:24:07 ----D---- C:\Program Files\Common Files\InstallShield
2009-10-07 21:18:37 ----D---- C:\Users\pepinho\AppData\Roaming\ATI
2009-10-07 21:18:37 ----D---- C:\ProgramData\ATI
2009-10-07 21:14:40 ----A---- C:\Windows\system32\ATIDEMGX.dll
2009-10-07 21:13:31 ----SHD---- C:\Windows\Installer
2009-10-07 21:13:31 ----D---- C:\Program Files\ATI
2009-10-07 21:12:52 ----D---- C:\Program Files\ATI Technologies
2009-10-07 21:06:20 ----RA---- C:\Windows\system32\CSVer.dll
2009-10-07 21:06:20 ----D---- C:\Program Files\Intel
2009-10-07 21:03:07 ----D---- C:\Users\pepinho\AppData\Roaming\Identities
2009-10-07 21:02:50 ----SD---- C:\Users\pepinho\AppData\Roaming\Microsoft
2009-10-07 20:58:01 ----D---- C:\Windows\Debug
2009-10-07 20:49:30 ----D---- C:\Windows\SoftwareDistribution
2009-10-07 20:43:01 ----D---- C:\Windows\Prefetch
2009-10-07 20:32:42 ----RAS---- C:\BOOTSECT.BAK
2009-10-07 20:32:42 ----H---- C:\Boot.BAK
2009-10-07 20:32:35 ----SHD---- C:\Boot

======List of files/folders modified in the last 1 months======

2009-10-18 21:48:09 ----RD---- C:\Program Files
2009-10-18 21:47:28 ----D---- C:\Windows\Temp
2009-10-18 18:37:20 ----SHD---- C:\System Volume Information
2009-10-18 18:36:47 ----D---- C:\Windows\system32\Tasks
2009-10-18 18:36:23 ----D---- C:\Windows\system32\drivers
2009-10-18 18:36:08 ----D---- C:\Program Files\Common Files
2009-10-18 18:35:26 ----D---- C:\Windows\System32
2009-10-18 18:35:26 ----A---- C:\Windows\system32\PerfStringBackup.INI
2009-10-18 18:35:25 ----D---- C:\Windows\inf
2009-10-18 18:31:18 ----D---- C:\Windows
2009-10-14 16:36:31 ----HD---- C:\ProgramData
2009-10-14 10:25:40 ----D---- C:\TRANSLAT
2009-10-13 15:24:17 ----D---- C:\Windows\system32\catroot2
2009-10-12 22:19:33 ----D---- C:\Windows\system32\NDF
2009-10-09 14:50:23 ----RSD---- C:\Windows\assembly
2009-10-09 14:50:17 ----D---- C:\Windows\Microsoft.NET
2009-10-09 14:49:51 ----D---- C:\Windows\Logs
2009-10-08 21:01:38 ----D---- C:\Windows\rescache
2009-10-08 19:37:35 ----A---- C:\deviceInfo.txt
2009-10-08 19:03:34 ----D---- C:\Windows\system32\WDI
2009-10-08 12:06:22 ----D---- C:\Windows\winsxs
2009-10-08 12:04:45 ----D---- C:\Program Files\Common Files\microsoft shared
2009-10-08 12:04:35 ----D---- C:\Program Files\MSBuild
2009-10-08 12:03:46 ----RSD---- C:\Windows\Fonts
2009-10-08 12:03:34 ----SD---- C:\ProgramData\Microsoft
2009-10-08 12:01:28 ----A---- C:\Windows\win.ini
2009-10-08 12:01:26 ----D---- C:\Program Files\Common Files\System
2009-10-08 08:19:45 ----D---- C:\Windows\Tasks
2009-10-08 08:19:44 ----D---- C:\Windows\system32\catroot
2009-10-07 21:45:36 ----D---- C:\Windows\system32\sk-SK
2009-10-07 21:41:29 ----RASH---- C:\Boot.ini.saved
2009-10-07 21:41:17 ----SD---- C:\Windows\Downloaded Program Files
2009-10-07 21:34:42 ----D---- C:\Windows\system
2009-10-07 21:33:31 ----D---- C:\Windows\system32\zh-TW
2009-10-07 21:33:31 ----D---- C:\Windows\system32\zh-CN
2009-10-07 21:33:31 ----D---- C:\Windows\system32\tr-TR
2009-10-07 21:33:31 ----D---- C:\Windows\system32\sv-SE
2009-10-07 21:33:31 ----D---- C:\Windows\system32\ru-RU
2009-10-07 21:33:31 ----D---- C:\Windows\system32\pt-PT
2009-10-07 21:33:31 ----D---- C:\Windows\system32\pl-PL
2009-10-07 21:33:31 ----D---- C:\Windows\system32\nl-NL
2009-10-07 21:33:31 ----D---- C:\Windows\system32\ko-KR
2009-10-07 21:33:31 ----D---- C:\Windows\system32\ja-JP
2009-10-07 21:33:31 ----D---- C:\Windows\system32\it-IT
2009-10-07 21:33:31 ----D---- C:\Windows\system32\hu-HU
2009-10-07 21:33:31 ----D---- C:\Windows\system32\fr-FR
2009-10-07 21:33:31 ----D---- C:\Windows\system32\fi-FI
2009-10-07 21:33:31 ----D---- C:\Windows\system32\es-ES
2009-10-07 21:33:31 ----D---- C:\Windows\system32\en-US
2009-10-07 21:33:31 ----D---- C:\Windows\system32\el-GR
2009-10-07 21:33:30 ----D---- C:\Windows\system32\de-DE
2009-10-07 21:33:30 ----D---- C:\Windows\system32\da-DK
2009-10-07 21:33:30 ----D---- C:\Windows\system32\cs-CZ
2009-10-07 21:06:23 ----D---- C:\Windows\system32\restore
2009-10-07 21:03:27 ----SHD---- C:\$Recycle.Bin
2009-10-07 21:02:50 ----RD---- C:\Users

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 BHDrvx86;BHDrvx86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20090921.001\BHDrvx86.sys [2009-09-22 507440]
R1 ccHP;Symantec Hash Provider; C:\Windows\system32\drivers\NIS\1100000.088\ccHPx86.sys [2009-08-25 501888]
R1 IDSVix86;IDSVix86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20090911.001\IDSvix86.sys [2009-09-10 342576]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL); C:\Windows\system32\drivers\NIS\1100000.088\SRTSPX.SYS [2009-08-30 43696]
R1 SymIRON;Symantec Iron Driver; C:\Windows\system32\drivers\NIS\1100000.088\Ironx86.SYS [2009-08-30 114736]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver; C:\Windows\system32\drivers\NIS\1100000.088\SYMTDIV.SYS [2009-08-30 338480]
R1 Tosrfcom;Bluetooth RFCOMM; C:\Windows\System32\Drivers\tosrfcom.sys [2007-10-02 64128]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2009-10-09 281760]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2009-10-09 25888]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2008-03-21 1203776]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2008-06-30 917504]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2008-05-14 3691520]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-21 14208]
R3 enecir;ENE CIR Receiver; C:\Windows\system32\DRIVERS\enecir.sys [2008-04-28 54784]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-08-20 2160792]
R3 NAVENG;NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20091018.003\NAVENG.SYS [2009-08-29 84912]
R3 NAVEX15;NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20091018.003\NAVEX15.SYS [2009-08-29 1323568]
R3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIV.sys [2008-04-14 142624]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2008-05-02 122368]
R3 RTSTOR;Realtek USB 2.0 Card Reader; C:\Windows\system32\drivers\RTSTOR.SYS [2008-06-05 62464]
R3 SRTSP;Symantec Real Time Storage Protection; C:\Windows\system32\drivers\NIS\1100000.088\SRTSP.SYS [2009-08-30 325168]
R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT.SYS [2009-10-18 124976]
R3 TcUsb;TC USB Kernel Driver; C:\Windows\System32\Drivers\tcusb.sys [2008-06-02 50576]
R3 tosporte;Bluetooth COM Port; C:\Windows\system32\DRIVERS\tosporte.sys [2006-10-10 41600]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264]
S3 a15kfkvk;a15kfkvk; C:\Windows\system32\drivers\a15kfkvk.sys []
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 tosrfbd;Bluetooth RFBUS; C:\Windows\system32\DRIVERS\tosrfbd.sys [2008-02-15 131712]
S3 tosrfbnp;Bluetooth RFBNEP; C:\Windows\System32\Drivers\tosrfbnp.sys [2007-11-29 36608]
S3 Tosrfhid;Bluetooth RFHID; C:\Windows\system32\DRIVERS\Tosrfhid.sys [2008-01-31 74240]
S3 tosrfnds;Bluetooth Personal Area Network; C:\Windows\system32\DRIVERS\tosrfnds.sys [2005-01-07 18612]
S3 TosRfSnd;Bluetooth Audio; C:\Windows\system32\drivers\tosrfsnd.sys [2008-01-22 54144]
S3 Tosrfusb;Bluetooth USB Controller; C:\Windows\system32\DRIVERS\tosrfusb.sys [2007-10-18 41856]
S3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Windows\system32\agrsmsvc.exe [2008-03-18 13312]
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2008-05-14 679936]
R2 Micro Star SCM;Micro Star SCM; C:\Program Files\System Control Manager\MSIService.exe [2008-08-26 159744]
R2 NIS;Norton Internet Security; C:\Program Files\Norton Internet Security\Engine\17.0.0.136\ccSvcHst.exe [2009-08-25 126392]
R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2007-09-28 128360]
S3 DfSdkS;Defragmentation-Service; C:\Program Files\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe [2009-08-24 406016]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

-----------------EOF-----------------


Offline

Skúsený užívateľ
Skúsený užívateľ
Obrázok užívateľa

Registrovaný: 15.08.09
Prihlásený: 05.02.10
Príspevky: 355
Témy: 0
Príspevok NapísalOffline : 19.10.2009 7:56

Je to spravne...

Spravime to ale takto (kedze nedokazem rozoznat, ktore procesy a ovladace patria pod NIS a ktore pod NAV):

1) Pomocou toho odinstalatoru, ktory som ti poslal, si odstranis z PC vsetky produkty od Symantecu (no maj v PC stiahnutu instalacku NISu, hned po skonceni roboty ju tam nahodis).


2) Nepaci sa mi tam jeden subor, je mozne, ze ide o malware. Preto otestuj subor(y) na >>VIRUSTOTALe<<:

Kód:
C:\Users\pepinho\AppData\Roaming\Microsoft\winlog.exe

Ak vypise, ze subor uz bol testovany, daj ho otestovat znovu. Vysledok posli ako LINK.


3) Mohol by si sem este vlozit screen-shot toho, ako sa ti tam ten AV tlaci - moze to pomoct ;)


4) Ked to vsetko spravis, hod sem novy log z RSITu a odpalime zvysky.


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 25.12.08
Prihlásený: 15.06.10
Príspevky: 76
Témy: 12
Príspevok Napísal autor témyOffline : 19.10.2009 11:12

1) hotovo

2) odoslal som to tam, ale údajne je súbor príliš veľký...

Bigger than max permited size / Mayor del tamaño máximo permitido

3) fakt sry, ale neviem sem vložiť obrázok... som asi trošku lama!

- najprv mi vypíše, že program norton antivirus prestal pracovať
- nasleduje klasická visťácka tabuľka... povoliť alebo zrušiť prístup k programu
- ak dám zrušiť, tak vypíše:
this process requires administrative privileges. please
accept the user access prompt. Or, if needed, enter your administrator credentials.
Po zrušení sa toto zopakuje ešte raz a ďalej už NAV problémy nerobí.
- ak dám povoliť, tak mi vyskočí tabuľka nortonu, že sa vyskytol problém, ktorý potrebuje moju pozornosť. Vraj sa pokúšam inštalovať NAV, ale v počítači mám program, ktorý poskytuje vyššiu ochranu a ten by následne musel byť odinštalovaný. Vypýta si continue...
- keď dám dokončiť, tak už mi vyhodí klasickú inštaláciu NAV
- keď dám zrušiť, tak mi vyhodí zasa to isté, ako v 3. odrážke
Hádam to je ako tak zrozumiteľné!?

4) Logfile of random's system information tool 1.06 (written by random/random)
Run by pepinho at 2009-10-19 10:52:40
Microsoft® Windows Vista™ Home Basic Service Pack 1
System drive C: has 8 GB (19%) free of 40 GB
Total RAM: 3070 MB (67% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:52:54, on 19. 10. 2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\SYSTEM32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\System Control Manager\MGSysCtrl.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\SweetIM\Messenger\SweetIM.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Norton Internet Security\Engine\17.0.0.136\ccSvcHst.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Sidebar\sidebar.exe
G:\downloads\RSIT.exe
C:\Program Files\trend micro\pepinho.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eu.ask.com?o=15161&l=dis
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\ProgramData\LangSoft\WebIE.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\17.0.0.136\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\17.0.0.136\IPSBHO.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\ProgramData\LangSoft\WebIE.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\17.0.0.136\coIEPlg.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [MGSysCtrl] C:\Program Files\System Control Manager\MGSysCtrl.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [winlog.exe] C:\Users\pepinho\AppData\Roaming\Microsoft\winlog.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Defragmentation-Service (DfSdkS) - mst software GmbH, Germany - C:\Program Files\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe
O23 - Service: Micro Star SCM - Unknown owner - C:\Program Files\System Control Manager\MSIService.exe
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\17.0.0.136\ccSvcHst.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe

--
End of file - 7755 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\ProgramData\LangSoft\WebIE.dll [2009-10-14 520192]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Symantec NCO BHO - C:\Program Files\Norton Internet Security\Engine\17.0.0.136\coIEPlg.dll [2009-08-29 392560]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Symantec Intrusion Prevention - C:\Program Files\Norton Internet Security\Engine\17.0.0.136\IPSBHO.DLL [2009-08-30 79224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2009-09-02 1175944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
SweetIM Toolbar Helper - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2009-05-20 1258808]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EEE6C35B-6118-11DC-9C72-001320C79847} - SweetIM Toolbar for Internet Explorer - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2009-05-20 1258808]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2009-04-23 937416]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\ProgramData\LangSoft\WebIE.dll [2009-10-14 520192]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2009-09-02 1175944]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files\Norton Internet Security\Engine\17.0.0.136\coIEPlg.dll [2009-08-29 392560]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-01-21 61440]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-08-20 6265376]
"Skytel"=C:\Windows\Skytel.exe [2008-08-20 1833504]
"MGSysCtrl"=C:\Program Files\System Control Manager\MGSysCtrl.exe [2008-08-26 708608]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"SweetIM"=C:\Program Files\SweetIM\Messenger\SweetIM.exe [2009-08-26 111928]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-01-21 1233920]
"winlog.exe"=C:\Users\pepinho\AppData\Roaming\Microsoft\winlog.exe [2009-10-08 77434880]
"OEXPRESS"= []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\psfus]
C:\Windows\system32\psqlpwd.dll [2008-04-29 96008]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
psqlpwd

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
"DisableCAD"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoResolveTrack"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0625ea88-b4ce-11de-a50e-002185d9f9f6}]
shell\AutoRun\command - F:\AUTOSTARTER.EXE


======List of files/folders created in the last 1 months======

2009-10-19 10:48:39 ----D---- C:\Program Files\Symantec
2009-10-19 10:48:39 ----D---- C:\Program Files\Common Files\Symantec Shared
2009-10-19 10:47:47 ----D---- C:\Program Files\Norton Internet Security
2009-10-19 10:47:32 ----D---- C:\Program Files\NortonInstaller
2009-10-18 23:28:07 ----D---- C:\Program Files\uTorrent
2009-10-18 23:24:52 ----D---- C:\Program Files\Ask.com
2009-10-18 21:48:09 ----D---- C:\rsit
2009-10-18 21:48:09 ----D---- C:\Program Files\trend micro
2009-10-18 18:47:40 ----D---- C:\Users\pepinho\AppData\Roaming\Tific
2009-10-14 16:38:27 ----D---- C:\Program Files\Common Files\Adobe AIR
2009-10-14 16:36:31 ----D---- C:\ProgramData\Adobe
2009-10-14 16:36:28 ----D---- C:\Program Files\Common Files\Adobe
2009-10-14 16:36:28 ----D---- C:\Program Files\Adobe
2009-10-14 10:25:22 ----A---- C:\Windows\TRNCOM.INI
2009-10-14 10:23:39 ----A---- C:\Windows\WTRDCTM.INI
2009-10-14 10:22:41 ----D---- C:\ProgramData\LangSoft
2009-10-14 10:22:30 ----D---- C:\Users\pepinho\AppData\Roaming\LangSoft
2009-10-11 13:04:54 ----D---- C:\Users\pepinho\AppData\Roaming\Ashampoo
2009-10-09 14:51:39 ----D---- C:\Windows\system32\AGEIA
2009-10-09 14:51:39 ----D---- C:\Program Files\AGEIA Technologies
2009-10-09 14:51:22 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2009-10-09 14:50:49 ----A---- C:\Windows\system32\XAudio2_3.dll
2009-10-09 14:50:49 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2009-10-09 14:50:49 ----A---- C:\Windows\system32\D3DX9_40.dll
2009-10-09 14:50:49 ----A---- C:\Windows\system32\d3dx10_40.dll
2009-10-09 14:50:49 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2009-10-09 14:50:47 ----A---- C:\Windows\system32\xactengine3_3.dll
2009-10-09 14:50:47 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2009-10-09 14:50:46 ----A---- C:\Windows\system32\XAudio2_2.dll
2009-10-09 14:50:46 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2009-10-09 14:50:45 ----A---- C:\Windows\system32\xactengine3_2.dll
2009-10-09 14:50:45 ----A---- C:\Windows\system32\D3DX9_39.dll
2009-10-09 14:50:45 ----A---- C:\Windows\system32\d3dx10_39.dll
2009-10-09 14:50:45 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2009-10-09 14:50:44 ----A---- C:\Windows\system32\XAudio2_1.dll
2009-10-09 14:50:44 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2009-10-09 14:50:43 ----A---- C:\Windows\system32\xactengine3_1.dll
2009-10-09 14:50:42 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2009-10-09 14:50:42 ----A---- C:\Windows\system32\D3DX9_38.dll
2009-10-09 14:50:42 ----A---- C:\Windows\system32\d3dx10_38.dll
2009-10-09 14:50:42 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2009-10-09 14:50:40 ----A---- C:\Windows\system32\XAudio2_0.dll
2009-10-09 14:50:40 ----A---- C:\Windows\system32\xactengine3_0.dll
2009-10-09 14:50:39 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2009-10-09 14:50:39 ----A---- C:\Windows\system32\d3dx10_37.dll
2009-10-09 14:50:39 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2009-10-09 14:50:37 ----A---- C:\Windows\system32\D3DX9_37.dll
2009-10-09 14:50:36 ----A---- C:\Windows\system32\xactengine2_10.dll
2009-10-09 14:50:34 ----A---- C:\Windows\system32\d3dx10_36.dll
2009-10-09 14:50:34 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2009-10-09 14:50:33 ----A---- C:\Windows\system32\xactengine2_9.dll
2009-10-09 14:50:33 ----A---- C:\Windows\system32\d3dx9_36.dll
2009-10-09 14:50:32 ----A---- C:\Windows\system32\d3dx9_35.dll
2009-10-09 14:50:32 ----A---- C:\Windows\system32\d3dx10_35.dll
2009-10-09 14:50:32 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2009-10-09 14:50:31 ----A---- C:\Windows\system32\xactengine2_8.dll
2009-10-09 14:50:31 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2009-10-09 14:50:31 ----A---- C:\Windows\system32\d3dx9_34.dll
2009-10-09 14:50:31 ----A---- C:\Windows\system32\d3dx10_34.dll
2009-10-09 14:50:31 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2009-10-09 14:50:30 ----A---- C:\Windows\system32\xinput1_3.dll
2009-10-09 14:50:29 ----A---- C:\Windows\system32\xactengine2_7.dll
2009-10-09 14:50:29 ----A---- C:\Windows\system32\d3dx10_33.dll
2009-10-09 14:50:29 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2009-10-09 14:50:28 ----A---- C:\Windows\system32\xactengine2_6.dll
2009-10-09 14:50:28 ----A---- C:\Windows\system32\d3dx9_33.dll
2009-10-09 14:50:27 ----A---- C:\Windows\system32\xactengine2_5.dll
2009-10-09 14:50:27 ----A---- C:\Windows\system32\d3dx9_32.dll
2009-10-09 14:50:27 ----A---- C:\Windows\system32\d3dx10.dll
2009-10-09 14:50:26 ----A---- C:\Windows\system32\xactengine2_4.dll
2009-10-09 14:50:26 ----A---- C:\Windows\system32\x3daudio1_1.dll
2009-10-09 14:50:26 ----A---- C:\Windows\system32\d3dx9_31.dll
2009-10-09 14:50:25 ----A---- C:\Windows\system32\xactengine2_3.dll
2009-10-09 14:50:24 ----A---- C:\Windows\system32\xinput1_2.dll
2009-10-09 14:50:24 ----A---- C:\Windows\system32\xactengine2_2.dll
2009-10-09 14:50:23 ----A---- C:\Windows\system32\xinput1_1.dll
2009-10-09 14:50:23 ----A---- C:\Windows\system32\xactengine2_1.dll
2009-10-09 14:50:16 ----A---- C:\Windows\system32\d3dx9_30.dll
2009-10-09 14:50:15 ----A---- C:\Windows\system32\xactengine2_0.dll
2009-10-09 14:50:15 ----A---- C:\Windows\system32\x3daudio1_0.dll
2009-10-09 14:50:15 ----A---- C:\Windows\system32\d3dx9_29.dll
2009-10-09 14:50:14 ----A---- C:\Windows\system32\d3dx9_28.dll
2009-10-09 14:50:14 ----A---- C:\Windows\system32\d3dx9_27.dll
2009-10-09 14:50:14 ----A---- C:\Windows\system32\d3dx9_26.dll
2009-10-09 14:50:13 ----A---- C:\Windows\system32\d3dx9_25.dll
2009-10-09 14:50:12 ----A---- C:\Windows\system32\d3dx9_24.dll
2009-10-09 14:23:43 ----D---- C:\Users\pepinho\AppData\Roaming\DAEMON Tools Pro
2009-10-09 14:23:43 ----D---- C:\Users\pepinho\AppData\Roaming\DAEMON Tools
2009-10-09 14:22:48 ----D---- C:\ProgramData\DAEMON Tools Lite
2009-10-09 14:22:25 ----D---- C:\Program Files\DAEMON Tools Toolbar
2009-10-09 14:21:52 ----D---- C:\Program Files\DAEMON Tools Lite
2009-10-09 14:17:29 ----D---- C:\Users\pepinho\AppData\Roaming\DAEMON Tools Lite
2009-10-08 20:03:05 ----D---- C:\ProgramData\Norton
2009-10-08 20:02:16 ----D---- C:\ProgramData\NortonInstaller
2009-10-08 16:55:03 ----D---- C:\ProgramData\SweetIM
2009-10-08 16:55:03 ----D---- C:\Program Files\SweetIM
2009-10-08 12:05:58 ----A---- C:\Windows\system32\msonpmon.dll
2009-10-08 12:04:49 ----D---- C:\Program Files\Microsoft Works
2009-10-08 12:04:15 ----D---- C:\Program Files\Microsoft Visual Studio
2009-10-08 12:04:15 ----D---- C:\Program Files\Common Files\DESIGNER
2009-10-08 12:03:34 ----D---- C:\Windows\PCHEALTH
2009-10-08 12:03:34 ----D---- C:\Program Files\Microsoft.NET
2009-10-08 12:01:47 ----D---- C:\Program Files\Microsoft Visual Studio 8
2009-10-08 12:01:15 ----D---- C:\Windows\SHELLNEW
2009-10-08 12:00:49 ----D---- C:\ProgramData\Microsoft Help
2009-10-08 12:00:49 ----D---- C:\Program Files\Microsoft Office
2009-10-08 11:53:21 ----D---- C:\Users\pepinho\AppData\Roaming\uTorrent
2009-10-08 11:44:08 ----D---- C:\Program Files\The KMPlayer
2009-10-08 11:36:53 ----D---- C:\Users\pepinho\AppData\Roaming\ICQ
2009-10-08 11:36:26 ----D---- C:\Program Files\ICQ6.5
2009-10-08 10:40:30 ----D---- C:\Users\pepinho\AppData\Roaming\WinRAR
2009-10-08 10:39:50 ----D---- C:\Program Files\WinRAR
2009-10-08 09:47:40 ----A---- C:\Windows\system32\DfSdkBt.exe
2009-10-08 09:47:35 ----D---- C:\Program Files\Ashampoo
2009-10-08 08:48:09 ----A---- C:\Windows\system32\MSVCR71.dll
2009-10-08 08:48:09 ----A---- C:\Windows\system32\MSVCP71.dll
2009-10-08 08:48:09 ----A---- C:\Windows\system32\MFC71.dll
2009-10-08 08:48:07 ----D---- C:\Program Files\Alwil Software
2009-10-07 23:30:34 ----D---- C:\ProgramData\Backup
2009-10-07 22:31:27 ----D---- C:\Users\pepinho\AppData\Roaming\Mozilla
2009-10-07 22:31:22 ----D---- C:\Program Files\Mozilla Firefox
2009-10-07 22:22:46 ----D---- C:\Program Files\Toshiba
2009-10-07 22:20:15 ----A---- C:\ProgramData\CameraRecorder.ini
2009-10-07 22:19:58 ----D---- C:\Program Files\Camera Recorder
2009-10-07 22:16:34 ----D---- C:\Program Files\Dolby
2009-10-07 22:14:14 ----N---- C:\Windows\system32\MpSigStub.exe
2009-10-07 21:54:06 ----A---- C:\Windows\system32\msiapcfg.dll
2009-10-07 21:54:04 ----D---- C:\Program Files\System Control Manager
2009-10-07 21:46:49 ----D---- C:\Users\pepinho\AppData\Roaming\Protector Suite
2009-10-07 21:42:54 ----D---- C:\Program Files\RSA
2009-10-07 21:42:54 ----D---- C:\Program Files\Common Files\SPBA
2009-10-07 21:42:49 ----D---- C:\Program Files\Protector Suite QL
2009-10-07 21:42:19 ----D---- C:\ProgramData\UIB
2009-10-07 21:41:43 ----D---- C:\Windows\Panther
2009-10-07 21:41:17 ----D---- C:\Users\pepinho\AppData\Roaming\Macromedia
2009-10-07 21:41:17 ----D---- C:\Users\pepinho\AppData\Roaming\Adobe
2009-10-07 21:41:16 ----D---- C:\Windows\system32\Macromed
2009-10-07 21:39:52 ----A---- C:\Windows\system32\wups2.dll
2009-10-07 21:39:52 ----A---- C:\Windows\system32\wucltux.dll
2009-10-07 21:39:52 ----A---- C:\Windows\system32\wuaueng.dll
2009-10-07 21:39:52 ----A---- C:\Windows\system32\wuauclt.exe
2009-10-07 21:39:35 ----A---- C:\Windows\system32\wups.dll
2009-10-07 21:39:35 ----A---- C:\Windows\system32\wudriver.dll
2009-10-07 21:39:35 ----A---- C:\Windows\system32\wuapi.dll
2009-10-07 21:39:11 ----A---- C:\Windows\system32\wuwebv.dll
2009-10-07 21:39:11 ----A---- C:\Windows\system32\wuapp.exe
2009-10-07 21:38:51 ----D---- C:\Program Files\DIFX
2009-10-07 21:35:14 ----N---- C:\Windows\system32\agrscoin.dll
2009-10-07 21:35:14 ----A---- C:\Windows\system32\agrsmsvc.exe
2009-10-07 21:35:14 ----A---- C:\Windows\agrsmdel.exe
2009-10-07 21:35:04 ----D---- C:\Windows\Options
2009-10-07 21:33:31 ----D---- C:\Windows\system32\nn-NO
2009-10-07 21:33:30 ----A---- C:\Windows\system32\S64CPA.exe
2009-10-07 21:33:30 ----A---- C:\Windows\system32\athihvui.dll
2009-10-07 21:33:26 ----A---- C:\Windows\system32\athihvs.dll
2009-10-07 21:31:50 ----D---- C:\Program Files\Cisco
2009-10-07 21:31:50 ----D---- C:\Program Files\Atheros
2009-10-07 21:31:14 ----D---- C:\ProgramData\Atheros
2009-10-07 21:30:16 ----D---- C:\Users\pepinho\AppData\Roaming\InstallShield
2009-10-07 21:24:50 ----D---- C:\Windows\system32\RTCOM
2009-10-07 21:24:18 ----A---- C:\Windows\DIFxAPI.dll
2009-10-07 21:24:17 ----A---- C:\Windows\system32\RtkHDMI.dll
2009-10-07 21:24:17 ----A---- C:\Windows\system32\RHDMIExt.dll
2009-10-07 21:24:17 ----A---- C:\Windows\RtkUpd.exe
2009-10-07 21:24:15 ----A---- C:\Windows\system32\WavesLib.dll
2009-10-07 21:24:15 ----A---- C:\Windows\system32\SRSWOW.dll
2009-10-07 21:24:15 ----A---- C:\Windows\system32\SRSTSXT.dll
2009-10-07 21:24:15 ----A---- C:\Windows\system32\SRSTSHD.dll
2009-10-07 21:24:15 ----A---- C:\Windows\system32\SRSHP360.dll
2009-10-07 21:24:15 ----A---- C:\Windows\SkyTel.exe
2009-10-07 21:24:15 ----A---- C:\Windows\RtlUpd.exe
2009-10-07 21:24:14 ----A---- C:\Windows\system32\RtkPgExt.dll
2009-10-07 21:24:14 ----A---- C:\Windows\system32\RtkCoInst.dll
2009-10-07 21:24:14 ----A---- C:\Windows\system32\RtkApoApi.dll
2009-10-07 21:24:14 ----A---- C:\Windows\system32\RtkAPO.dll
2009-10-07 21:24:13 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2009-10-07 21:24:13 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2009-10-07 21:24:13 ----A---- C:\Windows\system32\MaxxAudioAPO.dll
2009-10-07 21:24:13 ----A---- C:\Windows\RtHDVCpl.exe
2009-10-07 21:24:12 ----HD---- C:\Program Files\InstallShield Installation Information
2009-10-07 21:24:12 ----D---- C:\Program Files\Realtek
2009-10-07 21:24:12 ----A---- C:\Windows\system32\FMAPO.dll
2009-10-07 21:24:10 ----R---- C:\Windows\RtlExUpd.dll
2009-10-07 21:24:10 ----A---- C:\Windows\HideWin.exe
2009-10-07 21:24:07 ----D---- C:\Program Files\Common Files\InstallShield
2009-10-07 21:18:37 ----D---- C:\Users\pepinho\AppData\Roaming\ATI
2009-10-07 21:18:37 ----D---- C:\ProgramData\ATI
2009-10-07 21:14:40 ----A---- C:\Windows\system32\ATIDEMGX.dll
2009-10-07 21:13:31 ----SHD---- C:\Windows\Installer
2009-10-07 21:13:31 ----D---- C:\Program Files\ATI
2009-10-07 21:12:52 ----D---- C:\Program Files\ATI Technologies
2009-10-07 21:06:20 ----RA---- C:\Windows\system32\CSVer.dll
2009-10-07 21:06:20 ----D---- C:\Program Files\Intel
2009-10-07 21:03:07 ----D---- C:\Users\pepinho\AppData\Roaming\Identities
2009-10-07 21:02:50 ----SD---- C:\Users\pepinho\AppData\Roaming\Microsoft
2009-10-07 20:58:01 ----D---- C:\Windows\Debug
2009-10-07 20:49:30 ----D---- C:\Windows\SoftwareDistribution
2009-10-07 20:43:01 ----D---- C:\Windows\Prefetch
2009-10-07 20:32:42 ----RAS---- C:\BOOTSECT.BAK
2009-10-07 20:32:42 ----H---- C:\Boot.BAK
2009-10-07 20:32:35 ----SHD---- C:\Boot

======List of files/folders modified in the last 1 months======

2009-10-19 10:52:44 ----D---- C:\Windows\Temp
2009-10-19 10:49:46 ----SHD---- C:\System Volume Information
2009-10-19 10:49:13 ----D---- C:\Windows\system32\Tasks
2009-10-19 10:48:41 ----D---- C:\Windows\system32\drivers
2009-10-19 10:48:39 ----RD---- C:\Program Files
2009-10-19 10:48:39 ----D---- C:\Program Files\Common Files
2009-10-19 10:40:15 ----D---- C:\Windows\System32
2009-10-19 10:40:15 ----D---- C:\Windows\inf
2009-10-19 10:40:15 ----A---- C:\Windows\system32\PerfStringBackup.INI
2009-10-19 08:48:20 ----D---- C:\Windows
2009-10-14 16:36:31 ----HD---- C:\ProgramData
2009-10-14 10:25:40 ----D---- C:\TRANSLAT
2009-10-13 15:24:17 ----D---- C:\Windows\system32\catroot2
2009-10-12 22:19:33 ----D---- C:\Windows\system32\NDF
2009-10-09 14:50:23 ----RSD---- C:\Windows\assembly
2009-10-09 14:50:17 ----D---- C:\Windows\Microsoft.NET
2009-10-09 14:49:51 ----D---- C:\Windows\Logs
2009-10-08 21:01:38 ----D---- C:\Windows\rescache
2009-10-08 19:37:35 ----A---- C:\deviceInfo.txt
2009-10-08 19:03:34 ----D---- C:\Windows\system32\WDI
2009-10-08 12:06:22 ----D---- C:\Windows\winsxs
2009-10-08 12:04:45 ----D---- C:\Program Files\Common Files\microsoft shared
2009-10-08 12:04:35 ----D---- C:\Program Files\MSBuild
2009-10-08 12:03:46 ----RSD---- C:\Windows\Fonts
2009-10-08 12:03:34 ----SD---- C:\ProgramData\Microsoft
2009-10-08 12:01:28 ----A---- C:\Windows\win.ini
2009-10-08 12:01:26 ----D---- C:\Program Files\Common Files\System
2009-10-08 08:19:45 ----D---- C:\Windows\Tasks
2009-10-08 08:19:44 ----D---- C:\Windows\system32\catroot
2009-10-07 21:45:36 ----D---- C:\Windows\system32\sk-SK
2009-10-07 21:41:29 ----RASH---- C:\Boot.ini.saved
2009-10-07 21:41:17 ----SD---- C:\Windows\Downloaded Program Files
2009-10-07 21:34:42 ----D---- C:\Windows\system
2009-10-07 21:33:31 ----D---- C:\Windows\system32\zh-TW
2009-10-07 21:33:31 ----D---- C:\Windows\system32\zh-CN
2009-10-07 21:33:31 ----D---- C:\Windows\system32\tr-TR
2009-10-07 21:33:31 ----D---- C:\Windows\system32\sv-SE
2009-10-07 21:33:31 ----D---- C:\Windows\system32\ru-RU
2009-10-07 21:33:31 ----D---- C:\Windows\system32\pt-PT
2009-10-07 21:33:31 ----D---- C:\Windows\system32\pl-PL
2009-10-07 21:33:31 ----D---- C:\Windows\system32\nl-NL
2009-10-07 21:33:31 ----D---- C:\Windows\system32\ko-KR
2009-10-07 21:33:31 ----D---- C:\Windows\system32\ja-JP
2009-10-07 21:33:31 ----D---- C:\Windows\system32\it-IT
2009-10-07 21:33:31 ----D---- C:\Windows\system32\hu-HU
2009-10-07 21:33:31 ----D---- C:\Windows\system32\fr-FR
2009-10-07 21:33:31 ----D---- C:\Windows\system32\fi-FI
2009-10-07 21:33:31 ----D---- C:\Windows\system32\es-ES
2009-10-07 21:33:31 ----D---- C:\Windows\system32\en-US
2009-10-07 21:33:31 ----D---- C:\Windows\system32\el-GR
2009-10-07 21:33:30 ----D---- C:\Windows\system32\de-DE
2009-10-07 21:33:30 ----D---- C:\Windows\system32\da-DK
2009-10-07 21:33:30 ----D---- C:\Windows\system32\cs-CZ
2009-10-07 21:06:23 ----D---- C:\Windows\system32\restore
2009-10-07 21:03:27 ----SHD---- C:\$Recycle.Bin
2009-10-07 21:02:50 ----RD---- C:\Users

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 BHDrvx86;BHDrvx86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20090921.001\BHDrvx86.sys [2009-09-22 507440]
R1 ccHP;Symantec Hash Provider; C:\Windows\system32\drivers\NIS\1100000.088\ccHPx86.sys [2009-08-25 501888]
R1 IDSVix86;IDSVix86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20090911.001\IDSvix86.sys [2009-09-10 342576]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL); C:\Windows\system32\drivers\NIS\1100000.088\SRTSPX.SYS [2009-08-30 43696]
R1 SymIRON;Symantec Iron Driver; C:\Windows\system32\drivers\NIS\1100000.088\Ironx86.SYS [2009-08-30 114736]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver; C:\Windows\system32\drivers\NIS\1100000.088\SYMTDIV.SYS [2009-08-30 338480]
R1 Tosrfcom;Bluetooth RFCOMM; C:\Windows\System32\Drivers\tosrfcom.sys [2007-10-02 64128]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2009-10-09 281760]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2009-10-09 25888]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2008-03-21 1203776]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2008-06-30 917504]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2008-05-14 3691520]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-21 14208]
R3 enecir;ENE CIR Receiver; C:\Windows\system32\DRIVERS\enecir.sys [2008-04-28 54784]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-08-20 2160792]
R3 NAVENG;NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20091018.020\NAVENG.SYS [2009-08-29 84912]
R3 NAVEX15;NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20091018.020\NAVEX15.SYS [2009-08-29 1323568]
R3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIV.sys [2008-04-14 142624]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2008-05-02 122368]
R3 RTSTOR;Realtek USB 2.0 Card Reader; C:\Windows\system32\drivers\RTSTOR.SYS [2008-06-05 62464]
R3 SRTSP;Symantec Real Time Storage Protection; C:\Windows\system32\drivers\NIS\1100000.088\SRTSP.SYS [2009-08-30 325168]
R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT.SYS [2009-10-19 124976]
R3 TcUsb;TC USB Kernel Driver; C:\Windows\System32\Drivers\tcusb.sys [2008-06-02 50576]
R3 tosporte;Bluetooth COM Port; C:\Windows\system32\DRIVERS\tosporte.sys [2006-10-10 41600]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264]
S3 azfcsz4t;azfcsz4t; C:\Windows\system32\drivers\azfcsz4t.sys []
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 tosrfbd;Bluetooth RFBUS; C:\Windows\system32\DRIVERS\tosrfbd.sys [2008-02-15 131712]
S3 tosrfbnp;Bluetooth RFBNEP; C:\Windows\System32\Drivers\tosrfbnp.sys [2007-11-29 36608]
S3 Tosrfhid;Bluetooth RFHID; C:\Windows\system32\DRIVERS\Tosrfhid.sys [2008-01-31 74240]
S3 tosrfnds;Bluetooth Personal Area Network; C:\Windows\system32\DRIVERS\tosrfnds.sys [2005-01-07 18612]
S3 TosRfSnd;Bluetooth Audio; C:\Windows\system32\drivers\tosrfsnd.sys [2008-01-22 54144]
S3 Tosrfusb;Bluetooth USB Controller; C:\Windows\system32\DRIVERS\tosrfusb.sys [2007-10-18 41856]
S3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Windows\system32\agrsmsvc.exe [2008-03-18 13312]
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2008-05-14 679936]
R2 Micro Star SCM;Micro Star SCM; C:\Program Files\System Control Manager\MSIService.exe [2008-08-26 159744]
R2 NIS;Norton Internet Security; C:\Program Files\Norton Internet Security\Engine\17.0.0.136\ccSvcHst.exe [2009-08-25 126392]
R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2007-09-28 128360]
S3 DfSdkS;Defragmentation-Service; C:\Program Files\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe [2009-08-24 406016]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

-----------------EOF-----------------
[/img][/b]


Offline

Skúsený užívateľ
Skúsený užívateľ
Obrázok užívateľa

Registrovaný: 15.08.09
Prihlásený: 05.02.10
Príspevky: 355
Témy: 0
Príspevok NapísalOffline : 19.10.2009 18:17

Na test toho suboru skus pouzit virscan.org

A stale tam vidim nejake zvysky NISu - naozaj si ho odinstaloval?


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 25.12.08
Prihlásený: 15.06.10
Príspevky: 76
Témy: 12
Príspevok Napísal autor témyOffline : 19.10.2009 20:08

ani virscan.org ten súbor nechce vziať...
- ERROR: Maximum upload size of 20 exceeded. Your upload has failed!

ešte som zabudol, že mi to vyhadzuje ďalšie okno, ale nie vždy...
- exception EThread in module winlog.exe at 000173DC. Thread creation error: %1 nie je platnou aplikáciou Win32.

odinštaloval som NIS, použil som removal tool a spravil znova ten RSIT

Logfile of random's system information tool 1.06 (written by random/random)
Run by pepinho at 2009-10-19 20:01:25
Microsoft® Windows Vista™ Home Basic Service Pack 1
System drive C: has 8 GB (20%) free of 40 GB
Total RAM: 3070 MB (74% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:01:26, on 19. 10. 2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\SYSTEM32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\System Control Manager\MGSysCtrl.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\SweetIM\Messenger\SweetIM.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\SYSTEM32\taskeng.exe
G:\downloads\RSIT.exe
C:\Program Files\trend micro\pepinho.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eu.ask.com?o=15161&l=dis
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\ProgramData\LangSoft\WebIE.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\ProgramData\LangSoft\WebIE.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [MGSysCtrl] C:\Program Files\System Control Manager\MGSysCtrl.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [winlog.exe] C:\Users\pepinho\AppData\Roaming\Microsoft\winlog.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Defragmentation-Service (DfSdkS) - mst software GmbH, Germany - C:\Program Files\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe
O23 - Service: Micro Star SCM - Unknown owner - C:\Program Files\System Control Manager\MSIService.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe

--
End of file - 7179 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\ProgramData\LangSoft\WebIE.dll [2009-10-14 520192]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2009-09-02 1175944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
SweetIM Toolbar Helper - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2009-05-20 1258808]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EEE6C35B-6118-11DC-9C72-001320C79847} - SweetIM Toolbar for Internet Explorer - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2009-05-20 1258808]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2009-04-23 937416]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\ProgramData\LangSoft\WebIE.dll [2009-10-14 520192]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2009-09-02 1175944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-01-21 61440]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-08-20 6265376]
"Skytel"=C:\Windows\Skytel.exe [2008-08-20 1833504]
"MGSysCtrl"=C:\Program Files\System Control Manager\MGSysCtrl.exe [2008-08-26 708608]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"SweetIM"=C:\Program Files\SweetIM\Messenger\SweetIM.exe [2009-08-26 111928]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-01-21 1233920]
"winlog.exe"=C:\Users\pepinho\AppData\Roaming\Microsoft\winlog.exe [2009-10-08 77434880]
"OEXPRESS"= []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\psfus]
C:\Windows\system32\psqlpwd.dll [2008-04-29 96008]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
psqlpwd

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
"DisableCAD"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoResolveTrack"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0625ea88-b4ce-11de-a50e-002185d9f9f6}]
shell\AutoRun\command - F:\AUTOSTARTER.EXE


======List of files/folders created in the last 1 months======

2009-10-18 23:28:07 ----D---- C:\Program Files\uTorrent
2009-10-18 23:24:52 ----D---- C:\Program Files\Ask.com
2009-10-18 21:48:09 ----D---- C:\rsit
2009-10-18 21:48:09 ----D---- C:\Program Files\trend micro
2009-10-18 18:47:40 ----D---- C:\Users\pepinho\AppData\Roaming\Tific
2009-10-14 16:38:27 ----D---- C:\Program Files\Common Files\Adobe AIR
2009-10-14 16:36:31 ----D---- C:\ProgramData\Adobe
2009-10-14 16:36:28 ----D---- C:\Program Files\Common Files\Adobe
2009-10-14 16:36:28 ----D---- C:\Program Files\Adobe
2009-10-14 10:25:22 ----A---- C:\Windows\TRNCOM.INI
2009-10-14 10:23:39 ----A---- C:\Windows\WTRDCTM.INI
2009-10-14 10:22:41 ----D---- C:\ProgramData\LangSoft
2009-10-14 10:22:30 ----D---- C:\Users\pepinho\AppData\Roaming\LangSoft
2009-10-11 13:04:54 ----D---- C:\Users\pepinho\AppData\Roaming\Ashampoo
2009-10-09 14:51:39 ----D---- C:\Windows\system32\AGEIA
2009-10-09 14:51:39 ----D---- C:\Program Files\AGEIA Technologies
2009-10-09 14:51:22 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2009-10-09 14:50:49 ----A---- C:\Windows\system32\XAudio2_3.dll
2009-10-09 14:50:49 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2009-10-09 14:50:49 ----A---- C:\Windows\system32\D3DX9_40.dll
2009-10-09 14:50:49 ----A---- C:\Windows\system32\d3dx10_40.dll
2009-10-09 14:50:49 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2009-10-09 14:50:47 ----A---- C:\Windows\system32\xactengine3_3.dll
2009-10-09 14:50:47 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2009-10-09 14:50:46 ----A---- C:\Windows\system32\XAudio2_2.dll
2009-10-09 14:50:46 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2009-10-09 14:50:45 ----A---- C:\Windows\system32\xactengine3_2.dll
2009-10-09 14:50:45 ----A---- C:\Windows\system32\D3DX9_39.dll
2009-10-09 14:50:45 ----A---- C:\Windows\system32\d3dx10_39.dll
2009-10-09 14:50:45 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2009-10-09 14:50:44 ----A---- C:\Windows\system32\XAudio2_1.dll
2009-10-09 14:50:44 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2009-10-09 14:50:43 ----A---- C:\Windows\system32\xactengine3_1.dll
2009-10-09 14:50:42 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2009-10-09 14:50:42 ----A---- C:\Windows\system32\D3DX9_38.dll
2009-10-09 14:50:42 ----A---- C:\Windows\system32\d3dx10_38.dll
2009-10-09 14:50:42 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2009-10-09 14:50:40 ----A---- C:\Windows\system32\XAudio2_0.dll
2009-10-09 14:50:40 ----A---- C:\Windows\system32\xactengine3_0.dll
2009-10-09 14:50:39 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2009-10-09 14:50:39 ----A---- C:\Windows\system32\d3dx10_37.dll
2009-10-09 14:50:39 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2009-10-09 14:50:37 ----A---- C:\Windows\system32\D3DX9_37.dll
2009-10-09 14:50:36 ----A---- C:\Windows\system32\xactengine2_10.dll
2009-10-09 14:50:34 ----A---- C:\Windows\system32\d3dx10_36.dll
2009-10-09 14:50:34 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2009-10-09 14:50:33 ----A---- C:\Windows\system32\xactengine2_9.dll
2009-10-09 14:50:33 ----A---- C:\Windows\system32\d3dx9_36.dll
2009-10-09 14:50:32 ----A---- C:\Windows\system32\d3dx9_35.dll
2009-10-09 14:50:32 ----A---- C:\Windows\system32\d3dx10_35.dll
2009-10-09 14:50:32 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2009-10-09 14:50:31 ----A---- C:\Windows\system32\xactengine2_8.dll
2009-10-09 14:50:31 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2009-10-09 14:50:31 ----A---- C:\Windows\system32\d3dx9_34.dll
2009-10-09 14:50:31 ----A---- C:\Windows\system32\d3dx10_34.dll
2009-10-09 14:50:31 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2009-10-09 14:50:30 ----A---- C:\Windows\system32\xinput1_3.dll
2009-10-09 14:50:29 ----A---- C:\Windows\system32\xactengine2_7.dll
2009-10-09 14:50:29 ----A---- C:\Windows\system32\d3dx10_33.dll
2009-10-09 14:50:29 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2009-10-09 14:50:28 ----A---- C:\Windows\system32\xactengine2_6.dll
2009-10-09 14:50:28 ----A---- C:\Windows\system32\d3dx9_33.dll
2009-10-09 14:50:27 ----A---- C:\Windows\system32\xactengine2_5.dll
2009-10-09 14:50:27 ----A---- C:\Windows\system32\d3dx9_32.dll
2009-10-09 14:50:27 ----A---- C:\Windows\system32\d3dx10.dll
2009-10-09 14:50:26 ----A---- C:\Windows\system32\xactengine2_4.dll
2009-10-09 14:50:26 ----A---- C:\Windows\system32\x3daudio1_1.dll
2009-10-09 14:50:26 ----A---- C:\Windows\system32\d3dx9_31.dll
2009-10-09 14:50:25 ----A---- C:\Windows\system32\xactengine2_3.dll
2009-10-09 14:50:24 ----A---- C:\Windows\system32\xinput1_2.dll
2009-10-09 14:50:24 ----A---- C:\Windows\system32\xactengine2_2.dll
2009-10-09 14:50:23 ----A---- C:\Windows\system32\xinput1_1.dll
2009-10-09 14:50:23 ----A---- C:\Windows\system32\xactengine2_1.dll
2009-10-09 14:50:16 ----A---- C:\Windows\system32\d3dx9_30.dll
2009-10-09 14:50:15 ----A---- C:\Windows\system32\xactengine2_0.dll
2009-10-09 14:50:15 ----A---- C:\Windows\system32\x3daudio1_0.dll
2009-10-09 14:50:15 ----A---- C:\Windows\system32\d3dx9_29.dll
2009-10-09 14:50:14 ----A---- C:\Windows\system32\d3dx9_28.dll
2009-10-09 14:50:14 ----A---- C:\Windows\system32\d3dx9_27.dll
2009-10-09 14:50:14 ----A---- C:\Windows\system32\d3dx9_26.dll
2009-10-09 14:50:13 ----A---- C:\Windows\system32\d3dx9_25.dll
2009-10-09 14:50:12 ----A---- C:\Windows\system32\d3dx9_24.dll
2009-10-09 14:23:43 ----D---- C:\Users\pepinho\AppData\Roaming\DAEMON Tools Pro
2009-10-09 14:23:43 ----D---- C:\Users\pepinho\AppData\Roaming\DAEMON Tools
2009-10-09 14:22:48 ----D---- C:\ProgramData\DAEMON Tools Lite
2009-10-09 14:22:25 ----D---- C:\Program Files\DAEMON Tools Toolbar
2009-10-09 14:21:52 ----D---- C:\Program Files\DAEMON Tools Lite
2009-10-09 14:17:29 ----D---- C:\Users\pepinho\AppData\Roaming\DAEMON Tools Lite
2009-10-08 20:03:05 ----D---- C:\ProgramData\Norton
2009-10-08 20:02:16 ----D---- C:\ProgramData\NortonInstaller
2009-10-08 16:55:03 ----D---- C:\ProgramData\SweetIM
2009-10-08 16:55:03 ----D---- C:\Program Files\SweetIM
2009-10-08 12:05:58 ----A---- C:\Windows\system32\msonpmon.dll
2009-10-08 12:04:49 ----D---- C:\Program Files\Microsoft Works
2009-10-08 12:04:15 ----D---- C:\Program Files\Microsoft Visual Studio
2009-10-08 12:04:15 ----D---- C:\Program Files\Common Files\DESIGNER
2009-10-08 12:03:34 ----D---- C:\Windows\PCHEALTH
2009-10-08 12:03:34 ----D---- C:\Program Files\Microsoft.NET
2009-10-08 12:01:47 ----D---- C:\Program Files\Microsoft Visual Studio 8
2009-10-08 12:01:15 ----D---- C:\Windows\SHELLNEW
2009-10-08 12:00:49 ----D---- C:\ProgramData\Microsoft Help
2009-10-08 12:00:49 ----D---- C:\Program Files\Microsoft Office
2009-10-08 11:53:21 ----D---- C:\Users\pepinho\AppData\Roaming\uTorrent
2009-10-08 11:44:08 ----D---- C:\Program Files\The KMPlayer
2009-10-08 11:36:53 ----D---- C:\Users\pepinho\AppData\Roaming\ICQ
2009-10-08 11:36:26 ----D---- C:\Program Files\ICQ6.5
2009-10-08 10:40:30 ----D---- C:\Users\pepinho\AppData\Roaming\WinRAR
2009-10-08 10:39:50 ----D---- C:\Program Files\WinRAR
2009-10-08 09:47:40 ----A---- C:\Windows\system32\DfSdkBt.exe
2009-10-08 09:47:35 ----D---- C:\Program Files\Ashampoo
2009-10-08 08:48:09 ----A---- C:\Windows\system32\MSVCR71.dll
2009-10-08 08:48:09 ----A---- C:\Windows\system32\MSVCP71.dll
2009-10-08 08:48:09 ----A---- C:\Windows\system32\MFC71.dll
2009-10-08 08:48:07 ----D---- C:\Program Files\Alwil Software
2009-10-07 23:30:34 ----D---- C:\ProgramData\Backup
2009-10-07 22:31:27 ----D---- C:\Users\pepinho\AppData\Roaming\Mozilla
2009-10-07 22:31:22 ----D---- C:\Program Files\Mozilla Firefox
2009-10-07 22:22:46 ----D---- C:\Program Files\Toshiba
2009-10-07 22:20:15 ----A---- C:\ProgramData\CameraRecorder.ini
2009-10-07 22:19:58 ----D---- C:\Program Files\Camera Recorder
2009-10-07 22:16:34 ----D---- C:\Program Files\Dolby
2009-10-07 22:14:14 ----N---- C:\Windows\system32\MpSigStub.exe
2009-10-07 21:54:06 ----A---- C:\Windows\system32\msiapcfg.dll
2009-10-07 21:54:04 ----D---- C:\Program Files\System Control Manager
2009-10-07 21:46:49 ----D---- C:\Users\pepinho\AppData\Roaming\Protector Suite
2009-10-07 21:42:54 ----D---- C:\Program Files\RSA
2009-10-07 21:42:54 ----D---- C:\Program Files\Common Files\SPBA
2009-10-07 21:42:49 ----D---- C:\Program Files\Protector Suite QL
2009-10-07 21:42:19 ----D---- C:\ProgramData\UIB
2009-10-07 21:41:43 ----D---- C:\Windows\Panther
2009-10-07 21:41:17 ----D---- C:\Users\pepinho\AppData\Roaming\Macromedia
2009-10-07 21:41:17 ----D---- C:\Users\pepinho\AppData\Roaming\Adobe
2009-10-07 21:41:16 ----D---- C:\Windows\system32\Macromed
2009-10-07 21:39:52 ----A---- C:\Windows\system32\wups2.dll
2009-10-07 21:39:52 ----A---- C:\Windows\system32\wucltux.dll
2009-10-07 21:39:52 ----A---- C:\Windows\system32\wuaueng.dll
2009-10-07 21:39:52 ----A---- C:\Windows\system32\wuauclt.exe
2009-10-07 21:39:35 ----A---- C:\Windows\system32\wups.dll
2009-10-07 21:39:35 ----A---- C:\Windows\system32\wudriver.dll
2009-10-07 21:39:35 ----A---- C:\Windows\system32\wuapi.dll
2009-10-07 21:39:11 ----A---- C:\Windows\system32\wuwebv.dll
2009-10-07 21:39:11 ----A---- C:\Windows\system32\wuapp.exe
2009-10-07 21:38:51 ----D---- C:\Program Files\DIFX
2009-10-07 21:35:14 ----N---- C:\Windows\system32\agrscoin.dll
2009-10-07 21:35:14 ----A---- C:\Windows\system32\agrsmsvc.exe
2009-10-07 21:35:14 ----A---- C:\Windows\agrsmdel.exe
2009-10-07 21:35:04 ----D---- C:\Windows\Options
2009-10-07 21:33:31 ----D---- C:\Windows\system32\nn-NO
2009-10-07 21:33:30 ----A---- C:\Windows\system32\S64CPA.exe
2009-10-07 21:33:30 ----A---- C:\Windows\system32\athihvui.dll
2009-10-07 21:33:26 ----A---- C:\Windows\system32\athihvs.dll
2009-10-07 21:31:50 ----D---- C:\Program Files\Cisco
2009-10-07 21:31:50 ----D---- C:\Program Files\Atheros
2009-10-07 21:31:14 ----D---- C:\ProgramData\Atheros
2009-10-07 21:30:16 ----D---- C:\Users\pepinho\AppData\Roaming\InstallShield
2009-10-07 21:24:50 ----D---- C:\Windows\system32\RTCOM
2009-10-07 21:24:18 ----A---- C:\Windows\DIFxAPI.dll
2009-10-07 21:24:17 ----A---- C:\Windows\system32\RtkHDMI.dll
2009-10-07 21:24:17 ----A---- C:\Windows\system32\RHDMIExt.dll
2009-10-07 21:24:17 ----A---- C:\Windows\RtkUpd.exe
2009-10-07 21:24:15 ----A---- C:\Windows\system32\WavesLib.dll
2009-10-07 21:24:15 ----A---- C:\Windows\system32\SRSWOW.dll
2009-10-07 21:24:15 ----A---- C:\Windows\system32\SRSTSXT.dll
2009-10-07 21:24:15 ----A---- C:\Windows\system32\SRSTSHD.dll
2009-10-07 21:24:15 ----A---- C:\Windows\system32\SRSHP360.dll
2009-10-07 21:24:15 ----A---- C:\Windows\SkyTel.exe
2009-10-07 21:24:15 ----A---- C:\Windows\RtlUpd.exe
2009-10-07 21:24:14 ----A---- C:\Windows\system32\RtkPgExt.dll
2009-10-07 21:24:14 ----A---- C:\Windows\system32\RtkCoInst.dll
2009-10-07 21:24:14 ----A---- C:\Windows\system32\RtkApoApi.dll
2009-10-07 21:24:14 ----A---- C:\Windows\system32\RtkAPO.dll
2009-10-07 21:24:13 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2009-10-07 21:24:13 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2009-10-07 21:24:13 ----A---- C:\Windows\system32\MaxxAudioAPO.dll
2009-10-07 21:24:13 ----A---- C:\Windows\RtHDVCpl.exe
2009-10-07 21:24:12 ----HD---- C:\Program Files\InstallShield Installation Information
2009-10-07 21:24:12 ----D---- C:\Program Files\Realtek
2009-10-07 21:24:12 ----A---- C:\Windows\system32\FMAPO.dll
2009-10-07 21:24:10 ----R---- C:\Windows\RtlExUpd.dll
2009-10-07 21:24:10 ----A---- C:\Windows\HideWin.exe
2009-10-07 21:24:07 ----D---- C:\Program Files\Common Files\InstallShield
2009-10-07 21:18:37 ----D---- C:\Users\pepinho\AppData\Roaming\ATI
2009-10-07 21:18:37 ----D---- C:\ProgramData\ATI
2009-10-07 21:14:40 ----A---- C:\Windows\system32\ATIDEMGX.dll
2009-10-07 21:13:31 ----SHD---- C:\Windows\Installer
2009-10-07 21:13:31 ----D---- C:\Program Files\ATI
2009-10-07 21:12:52 ----D---- C:\Program Files\ATI Technologies
2009-10-07 21:06:20 ----RA---- C:\Windows\system32\CSVer.dll
2009-10-07 21:06:20 ----D---- C:\Program Files\Intel
2009-10-07 21:03:07 ----D---- C:\Users\pepinho\AppData\Roaming\Identities
2009-10-07 21:02:50 ----SD---- C:\Users\pepinho\AppData\Roaming\Microsoft
2009-10-07 20:58:01 ----D---- C:\Windows\Debug
2009-10-07 20:49:30 ----D---- C:\Windows\SoftwareDistribution
2009-10-07 20:43:01 ----D---- C:\Windows\Prefetch
2009-10-07 20:32:42 ----RAS---- C:\BOOTSECT.BAK
2009-10-07 20:32:42 ----H---- C:\Boot.BAK
2009-10-07 20:32:35 ----SHD---- C:\Boot

======List of files/folders modified in the last 1 months======

2009-10-19 20:01:24 ----D---- C:\Windows\Temp
2009-10-19 19:57:10 ----RD---- C:\Program Files
2009-10-19 19:57:08 ----SHD---- C:\System Volume Information
2009-10-19 19:57:08 ----D---- C:\Program Files\Common Files
2009-10-19 19:55:49 ----D---- C:\Windows\system32\drivers
2009-10-19 19:49:54 ----D---- C:\Windows\System32
2009-10-19 19:49:54 ----D---- C:\Windows\inf
2009-10-19 19:49:54 ----A---- C:\Windows\system32\PerfStringBackup.INI
2009-10-19 10:49:13 ----D---- C:\Windows\system32\Tasks
2009-10-19 08:48:20 ----D---- C:\Windows
2009-10-14 16:36:31 ----HD---- C:\ProgramData
2009-10-14 10:25:40 ----D---- C:\TRANSLAT
2009-10-13 15:24:17 ----D---- C:\Windows\system32\catroot2
2009-10-12 22:19:33 ----D---- C:\Windows\system32\NDF
2009-10-09 14:50:23 ----RSD---- C:\Windows\assembly
2009-10-09 14:50:17 ----D---- C:\Windows\Microsoft.NET
2009-10-09 14:49:51 ----D---- C:\Windows\Logs
2009-10-08 21:01:38 ----D---- C:\Windows\rescache
2009-10-08 19:37:35 ----A---- C:\deviceInfo.txt
2009-10-08 19:03:34 ----D---- C:\Windows\system32\WDI
2009-10-08 12:06:22 ----D---- C:\Windows\winsxs
2009-10-08 12:04:45 ----D---- C:\Program Files\Common Files\microsoft shared
2009-10-08 12:04:35 ----D---- C:\Program Files\MSBuild
2009-10-08 12:03:46 ----RSD---- C:\Windows\Fonts
2009-10-08 12:03:34 ----SD---- C:\ProgramData\Microsoft
2009-10-08 12:01:28 ----A---- C:\Windows\win.ini
2009-10-08 12:01:26 ----D---- C:\Program Files\Common Files\System
2009-10-08 08:19:45 ----D---- C:\Windows\Tasks
2009-10-08 08:19:44 ----D---- C:\Windows\system32\catroot
2009-10-07 21:45:36 ----D---- C:\Windows\system32\sk-SK
2009-10-07 21:41:29 ----RASH---- C:\Boot.ini.saved
2009-10-07 21:41:17 ----SD---- C:\Windows\Downloaded Program Files
2009-10-07 21:34:42 ----D---- C:\Windows\system
2009-10-07 21:33:31 ----D---- C:\Windows\system32\zh-TW
2009-10-07 21:33:31 ----D---- C:\Windows\system32\zh-CN
2009-10-07 21:33:31 ----D---- C:\Windows\system32\tr-TR
2009-10-07 21:33:31 ----D---- C:\Windows\system32\sv-SE
2009-10-07 21:33:31 ----D---- C:\Windows\system32\ru-RU
2009-10-07 21:33:31 ----D---- C:\Windows\system32\pt-PT
2009-10-07 21:33:31 ----D---- C:\Windows\system32\pl-PL
2009-10-07 21:33:31 ----D---- C:\Windows\system32\nl-NL
2009-10-07 21:33:31 ----D---- C:\Windows\system32\ko-KR
2009-10-07 21:33:31 ----D---- C:\Windows\system32\ja-JP
2009-10-07 21:33:31 ----D---- C:\Windows\system32\it-IT
2009-10-07 21:33:31 ----D---- C:\Windows\system32\hu-HU
2009-10-07 21:33:31 ----D---- C:\Windows\system32\fr-FR
2009-10-07 21:33:31 ----D---- C:\Windows\system32\fi-FI
2009-10-07 21:33:31 ----D---- C:\Windows\system32\es-ES
2009-10-07 21:33:31 ----D---- C:\Windows\system32\en-US
2009-10-07 21:33:31 ----D---- C:\Windows\system32\el-GR
2009-10-07 21:33:30 ----D---- C:\Windows\system32\de-DE
2009-10-07 21:33:30 ----D---- C:\Windows\system32\da-DK
2009-10-07 21:33:30 ----D---- C:\Windows\system32\cs-CZ
2009-10-07 21:06:23 ----D---- C:\Windows\system32\restore
2009-10-07 21:03:27 ----SHD---- C:\$Recycle.Bin
2009-10-07 21:02:50 ----RD---- C:\Users

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Tosrfcom;Bluetooth RFCOMM; C:\Windows\System32\Drivers\tosrfcom.sys [2007-10-02 64128]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2009-10-09 281760]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2009-10-09 25888]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2008-03-21 1203776]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2008-06-30 917504]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2008-05-14 3691520]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-21 14208]
R3 enecir;ENE CIR Receiver; C:\Windows\system32\DRIVERS\enecir.sys [2008-04-28 54784]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-08-20 2160792]
R3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIV.sys [2008-04-14 142624]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2008-05-02 122368]
R3 RTSTOR;Realtek USB 2.0 Card Reader; C:\Windows\system32\drivers\RTSTOR.SYS [2008-06-05 62464]
R3 TcUsb;TC USB Kernel Driver; C:\Windows\System32\Drivers\tcusb.sys [2008-06-02 50576]
R3 tosporte;Bluetooth COM Port; C:\Windows\system32\DRIVERS\tosporte.sys [2006-10-10 41600]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264]
S3 aagjeq2a;aagjeq2a; C:\Windows\system32\drivers\aagjeq2a.sys []
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 tosrfbd;Bluetooth RFBUS; C:\Windows\system32\DRIVERS\tosrfbd.sys [2008-02-15 131712]
S3 tosrfbnp;Bluetooth RFBNEP; C:\Windows\System32\Drivers\tosrfbnp.sys [2007-11-29 36608]
S3 Tosrfhid;Bluetooth RFHID; C:\Windows\system32\DRIVERS\Tosrfhid.sys [2008-01-31 74240]
S3 tosrfnds;Bluetooth Personal Area Network; C:\Windows\system32\DRIVERS\tosrfnds.sys [2005-01-07 18612]
S3 TosRfSnd;Bluetooth Audio; C:\Windows\system32\drivers\tosrfsnd.sys [2008-01-22 54144]
S3 Tosrfusb;Bluetooth USB Controller; C:\Windows\system32\DRIVERS\tosrfusb.sys [2007-10-18 41856]
S3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Windows\system32\agrsmsvc.exe [2008-03-18 13312]
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2008-05-14 679936]
R2 Micro Star SCM;Micro Star SCM; C:\Program Files\System Control Manager\MSIService.exe [2008-08-26 159744]
R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2007-09-28 128360]
S3 DfSdkS;Defragmentation-Service; C:\Program Files\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe [2009-08-24 406016]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

-----------------EOF-----------------


Offline

Skúsený užívateľ
Skúsený užívateľ
Obrázok užívateľa

Registrovaný: 15.08.09
Prihlásený: 05.02.10
Príspevky: 355
Témy: 0
Príspevok NapísalOffline : 20.10.2009 16:44

Stale si nie som isty tym suborom...preto to spravime takto:
Ten subor si pre istotu zazalohuj (vloz ho do raru pod heslo) a ak by sa cosi nepodarilo, daj ho nas5. Malo by sa jednat o malware, no kedze to nemam ako poriadne potvrdit (test je nemozny), musime to spravit rucne-strucne ;)

Kód:
C:\Users\pepinho\AppData\Roaming\Microsoft\winlog.exe


Ak budes mat hotovo, mozes prejst k dalsiemu bodu:

Stiahni ComboFix, najlepsie na plochu. Vypni vsetky otvorene aplikacie, ako aj rezidenty antiviru, antispywaru a firewall. Spust program cez ucet s administratorskymi pravami a postupuj podla instrukcii. Cely sken bude trvat cca 10 minut. Pocas neho moze byt PC restartovane. Log, ktory ComboFix vytvori, najdes na adrese "C:\ComboFix.txt".
Ten vloz sem.

Pozor: Kym ComboFix nevytvori log, na nic neklikat, nic nestlacat !!


Dame to dole cez CF, som zvedavy, co povie on na ten subor ;)


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 25.12.08
Prihlásený: 15.06.10
Príspevky: 76
Témy: 12
Príspevok Napísal autor témyOffline : 20.10.2009 18:40

nie som momentálne doma, ale hneď zajtra sa na to vrhnem podľa tvojich inštrukcií. potom podám hlásenie..
inak veľmi ti ďakujem za trpezlivosť a ochotu!!


Offline

Skúsený užívateľ
Skúsený užívateľ
Obrázok užívateľa

Registrovaný: 15.08.09
Prihlásený: 05.02.10
Príspevky: 355
Témy: 0
Príspevok NapísalOffline : 20.10.2009 19:46

OK, cakam...

Este nedakuj, zatial nemas za co :D


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 25.12.08
Prihlásený: 15.06.10
Príspevky: 76
Témy: 12
Príspevok Napísal autor témyOffline : 21.10.2009 18:20

k tomu súboru winlog.exe sa vôbec neviem dostať!

log z ComboFix....

ComboFix 09-10-20.03 - pepinho . 10. 2009 18:02.1.2 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1250.421.1051.18.3070.2293 [GMT 2:00]
Running from: c:\users\pepinho\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\data
c:\recycler\S-1-5-21-1409082233-1563985344-725345543-1003
c:\users\pepinho\AppData\Roaming\Microsoft\winlog.exe

.
((((((((((((((((((((((((( Files Created from 2009-09-21 to 2009-10-21 )))))))))))))))))))))))))))))))
.

2009-10-21 16:07 . 2009-10-21 16:08 -------- d-----w- c:\users\pepinho\AppData\Local\temp
2009-10-21 16:07 . 2009-10-21 16:07 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-10-20 06:19 . 2009-10-20 06:19 -------- d-----w- c:\users\pepinho\AppData\Roaming\Media Player Classic
2009-10-20 05:22 . 2008-09-16 19:23 168448 ----a-w- c:\windows\system32\unrar.dll
2009-10-20 05:22 . 2008-12-07 18:08 795648 ----a-w- c:\windows\system32\xvidcore.dll
2009-10-20 05:22 . 2008-12-07 18:08 130048 ----a-w- c:\windows\system32\xvidvfw.dll
2009-10-20 05:22 . 2004-01-25 16:18 217088 ----a-w- c:\windows\system32\yv12vfw.dll
2009-10-20 05:22 . 2008-12-11 00:33 86016 ----a-w- c:\windows\system32\dpl100.dll
2009-10-20 05:22 . 2008-11-06 16:37 3596288 ----a-w- c:\windows\system32\qt-dx331.dll
2009-10-20 05:22 . 2008-11-06 16:33 684032 ----a-w- c:\windows\system32\divx.dll
2009-10-20 05:22 . 2008-12-08 11:53 57344 ----a-w- c:\windows\system32\ff_vfw.dll
2009-10-20 05:22 . 2009-10-20 05:22 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-10-19 19:53 . 2009-10-19 19:53 -------- d-----w- c:\program files\YouTube Downloader
2009-10-18 21:28 . 2009-10-18 21:28 -------- d-----w- c:\program files\uTorrent
2009-10-18 21:24 . 2009-10-18 21:25 -------- d-----w- c:\program files\Ask.com
2009-10-18 19:48 . 2009-10-19 18:01 -------- d-----w- c:\program files\trend micro
2009-10-18 19:48 . 2009-10-18 19:48 -------- d-----w- C:\rsit
2009-10-18 16:47 . 2009-10-18 18:51 -------- d-----w- c:\users\pepinho\AppData\Local\Tific
2009-10-18 16:47 . 2009-10-18 16:47 -------- d-----w- c:\users\pepinho\AppData\Roaming\Tific
2009-10-18 16:47 . 2009-10-18 16:47 -------- d-----w- c:\users\pepinho\AppData\Local\Symantec
2009-10-14 14:39 . 2009-10-14 14:39 -------- d-----w- c:\users\pepinho\AppData\Local\Adobe
2009-10-14 14:38 . 2009-10-14 14:38 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-10-14 14:36 . 2009-10-14 16:29 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-14 08:22 . 2009-10-14 08:25 -------- d-----w- c:\programdata\LangSoft
2009-10-14 08:22 . 2009-10-14 08:29 -------- d-----w- c:\users\pepinho\AppData\Roaming\LangSoft
2009-10-11 11:04 . 2009-10-11 11:04 -------- d-----w- c:\users\pepinho\AppData\Roaming\Ashampoo
2009-10-09 12:53 . 2009-10-09 12:54 -------- d-----w- c:\users\pepinho\AppData\Local\Risen
2009-10-09 12:52 . 2009-10-09 12:52 281760 ----a-w- c:\windows\system32\drivers\atksgt.sys
2009-10-09 12:52 . 2009-10-09 12:52 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2009-10-09 12:51 . 2009-10-09 12:51 -------- d-----w- c:\program files\AGEIA Technologies
2009-10-09 12:51 . 2009-10-09 12:51 -------- d-----w- c:\windows\system32\AGEIA
2009-10-09 12:51 . 2009-10-09 12:51 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-10-09 12:23 . 2009-10-09 12:23 -------- d-----w- c:\users\pepinho\AppData\Roaming\DAEMON Tools Pro
2009-10-09 12:23 . 2009-10-09 12:23 -------- d-----w- c:\users\pepinho\AppData\Roaming\DAEMON Tools
2009-10-09 12:22 . 2009-10-09 12:22 -------- d-----w- c:\programdata\DAEMON Tools Lite
2009-10-09 12:22 . 2009-10-09 12:22 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2009-10-09 12:21 . 2009-10-09 12:22 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-10-09 12:17 . 2009-10-09 12:17 717296 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-10-09 12:17 . 2009-10-09 12:24 -------- d-----w- c:\users\pepinho\AppData\Roaming\DAEMON Tools Lite
2009-10-08 20:34 . 2009-10-21 15:55 -------- d-----w- c:\users\pepinho\AppData\Local\CrashDumps
2009-10-08 18:03 . 2009-10-19 17:57 -------- d-----w- c:\programdata\Norton
2009-10-08 18:02 . 2009-10-19 08:24 -------- d-----w- c:\programdata\NortonInstaller
2009-10-08 14:55 . 2009-10-08 14:55 -------- d-----w- c:\program files\SweetIM
2009-10-08 14:55 . 2009-10-08 14:55 -------- d-----w- c:\programdata\SweetIM
2009-10-08 10:05 . 2006-10-26 17:56 32592 ----a-w- c:\windows\system32\msonpmon.dll
2009-10-08 10:04 . 2009-10-08 10:04 -------- d-----w- c:\program files\Microsoft Works
2009-10-08 10:03 . 2009-10-08 10:03 -------- d-----w- c:\windows\PCHEALTH
2009-10-08 10:03 . 2009-10-08 10:03 -------- d-----w- c:\program files\Microsoft.NET
2009-10-08 10:01 . 2009-10-08 10:01 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-10-08 10:01 . 2009-10-08 10:04 -------- d-----w- c:\windows\SHELLNEW
2009-10-08 10:00 . 2009-10-08 10:00 -------- d-----w- c:\users\pepinho\AppData\Local\Microsoft Help
2009-10-08 10:00 . 2009-10-08 10:06 -------- d-----w- c:\programdata\Microsoft Help
2009-10-08 09:53 . 2009-10-19 15:47 -------- d-----w- c:\users\pepinho\AppData\Roaming\uTorrent
2009-10-08 09:44 . 2009-10-08 09:44 -------- d-----w- c:\program files\The KMPlayer
2009-10-08 09:36 . 2009-10-08 10:17 -------- d-----w- c:\users\pepinho\AppData\Roaming\ICQ
2009-10-08 09:36 . 2009-10-08 10:17 -------- d-----w- c:\program files\ICQ6.5
2009-10-08 07:47 . 2009-08-24 20:08 28160 ----a-w- c:\windows\system32\DfSdkBt.exe
2009-10-08 07:47 . 2009-10-08 08:43 -------- d-----w- c:\program files\Ashampoo
2009-10-08 06:48 . 2003-03-18 19:20 1060864 ----a-w- c:\windows\system32\MFC71.dll
2009-10-08 06:48 . 2003-03-18 18:14 499712 ----a-w- c:\windows\system32\MSVCP71.dll
2009-10-08 06:48 . 2003-02-21 02:42 348160 ----a-w- c:\windows\system32\MSVCR71.dll
2009-10-08 06:48 . 2009-10-08 06:48 -------- d-----w- c:\program files\Alwil Software
2009-10-07 22:03 . 2009-10-07 22:04 -------- d-----w- c:\users\pepinho\AppData\Local\MigWiz
2009-10-07 21:30 . 2009-10-07 21:30 -------- d-----w- c:\programdata\Backup
2009-10-07 20:31 . 2009-10-07 20:31 -------- d-----w- c:\users\pepinho\AppData\Local\Mozilla
2009-10-07 20:28 . 2009-10-07 20:28 -------- d-----w- c:\users\pepinho\AppData\Local\Toshiba
2009-10-07 20:22 . 2009-10-07 20:22 -------- d-----w- c:\program files\Toshiba
2009-10-07 20:19 . 2009-10-07 20:19 -------- d-----w- c:\program files\Camera Recorder
2009-10-07 20:16 . 2009-10-07 20:16 -------- d-----w- c:\program files\Dolby
2009-10-07 20:14 . 2009-10-01 08:29 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-10-07 19:54 . 2008-08-25 09:20 4096 ----a-w- c:\windows\system32\msiapcfg.dll
2009-10-07 19:54 . 2009-10-07 19:54 -------- d-----w- c:\program files\System Control Manager
2009-10-07 19:46 . 2009-10-08 09:16 -------- d-----w- c:\users\pepinho\AppData\Roaming\Protector Suite
2009-10-07 19:42 . 2009-10-07 19:42 -------- d-----w- c:\program files\RSA
2009-10-07 19:42 . 2009-10-07 19:42 -------- d-----w- c:\program files\Common Files\SPBA
2009-10-07 19:42 . 2009-10-07 19:43 -------- d-----w- c:\program files\Protector Suite QL
2009-10-07 19:42 . 2009-10-07 19:42 -------- d-----w- c:\programdata\UIB
2009-10-07 19:41 . 2009-10-07 18:54 -------- d-----w- c:\windows\Panther
2009-10-07 19:41 . 2009-10-07 19:41 -------- d-----w- c:\windows\system32\Macromed
2009-10-07 19:39 . 2008-10-16 21:13 1809944 ----a-w- c:\windows\system32\wuaueng.dll
2009-10-07 19:39 . 2008-10-16 21:09 51224 ----a-w- c:\windows\system32\wuauclt.exe
2009-10-07 19:39 . 2008-10-16 21:09 43544 ----a-w- c:\windows\system32\wups2.dll
2009-10-07 19:39 . 2008-10-16 20:56 1524736 ----a-w- c:\windows\system32\wucltux.dll
2009-10-07 19:39 . 2008-10-16 21:12 561688 ----a-w- c:\windows\system32\wuapi.dll
2009-10-07 19:39 . 2008-10-16 21:08 34328 ----a-w- c:\windows\system32\wups.dll
2009-10-07 19:39 . 2008-10-16 20:55 83456 ----a-w- c:\windows\system32\wudriver.dll
2009-10-07 19:39 . 2008-10-16 12:08 162064 ----a-w- c:\windows\system32\wuwebv.dll
2009-10-07 19:39 . 2008-10-16 11:56 31232 ----a-w- c:\windows\system32\wuapp.exe
2009-10-07 19:38 . 2009-10-07 19:38 -------- d-----w- c:\program files\DIFX
2009-10-07 19:38 . 2008-04-28 17:54 54784 ----a-w- c:\windows\system32\drivers\enecir.sys
2009-10-07 19:35 . 2008-03-28 02:46 54824 ----a-w- c:\windows\agrsmdel.exe
2009-10-07 19:35 . 2008-03-21 04:13 1203776 ----a-w- c:\windows\system32\drivers\AGRSM.sys
2009-10-07 19:35 . 2008-03-18 04:27 13312 ----a-w- c:\windows\system32\agrsmsvc.exe
2009-10-07 19:35 . 2007-12-11 04:40 13312 ------w- c:\windows\system32\agrscoin.dll
2009-10-07 19:35 . 2009-10-07 19:35 -------- d-----w- c:\windows\Options
2009-10-07 19:34 . 2008-06-05 17:01 62464 ----a-w- c:\windows\system32\drivers\RTSTOR.sys
2009-10-07 19:34 . 2008-05-06 15:41 6416928 ----a-w- c:\windows\system\DriveIcon.dll
2009-10-07 19:33 . 2009-10-07 19:33 -------- d-----w- c:\windows\system32\nn-NO
2009-10-07 19:33 . 2008-06-30 17:56 917504 ----a-w- c:\windows\system32\drivers\athr.sys
2009-10-07 19:33 . 2008-06-30 17:56 917504 ----a-w- c:\windows\system32\athr.sys
2009-10-07 19:33 . 2008-06-30 11:50 376832 ----a-w- c:\windows\system32\S64CPA.exe
2009-10-07 19:33 . 2008-06-30 11:50 53248 ----a-w- c:\windows\system32\athihvui.dll
2009-10-07 19:33 . 2008-06-30 11:49 393216 ----a-w- c:\windows\system32\athihvs.dll
2009-10-07 19:31 . 2009-10-07 19:33 -------- d-----w- c:\program files\Atheros
2009-10-07 19:31 . 2009-10-07 19:31 -------- d-----w- c:\program files\Cisco
2009-10-07 19:31 . 2009-10-07 19:31 -------- d-----w- c:\programdata\Atheros
2009-10-07 19:30 . 2008-05-02 05:59 122368 ----a-w- c:\windows\system32\drivers\Rtlh86.sys
2009-10-07 19:30 . 2009-10-07 19:30 -------- d-----w- c:\users\pepinho\AppData\Roaming\InstallShield
2009-10-07 19:18 . 2009-10-07 19:18 -------- d-----w- c:\users\pepinho\AppData\Roaming\ATI
2009-10-07 19:18 . 2009-10-07 19:18 -------- d-----w- c:\users\pepinho\AppData\Local\ATI
2009-10-07 19:18 . 2009-10-07 19:18 -------- d-----w- c:\programdata\ATI
2009-10-07 19:17 . 2009-10-07 19:17 0 ----a-w- c:\windows\ativpsrm.bin
2009-10-07 19:14 . 2008-05-14 14:04 413696 ----a-w- c:\windows\system32\ATIDEMGX.dll
2009-10-07 19:14 . 2008-05-14 13:33 3107788 ----a-w- c:\windows\system32\atiumdva.dat
2009-10-07 19:13 . 2009-10-18 21:25 -------- d-sh--w- c:\windows\Installer
2009-10-07 19:13 . 2009-10-07 19:13 -------- d-----w- c:\program files\ATI
2009-10-07 19:12 . 2009-10-07 19:15 -------- d-----w- c:\program files\ATI Technologies
2009-10-07 19:06 . 2009-10-07 19:06 -------- d-----w- c:\program files\Intel
2009-10-07 19:06 . 2008-02-22 05:06 53248 ----a-r- c:\windows\system32\CSVer.dll
2009-10-07 19:03 . 2009-10-08 10:12 99864 ----a-w- c:\users\pepinho\AppData\Local\GDIPFONTCACHEV1.DAT
2009-10-07 18:58 . 2009-10-08 07:51 -------- d-----w- c:\windows\Debug
2009-10-07 18:32 . 2009-10-07 19:41 -------- d-----w- C:\Boot

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-19 17:45 . 2009-10-07 19:02 7512 ----a-w- c:\users\pepinho\AppData\Local\d3d9caps.dat
2009-10-09 12:41 . 2009-10-07 19:24 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-08 10:04 . 2006-11-02 12:35 -------- d-----w- c:\program files\MSBuild
2009-10-07 19:30 . 2009-10-07 19:24 -------- d-----w- c:\program files\Realtek
2009-10-07 19:24 . 2009-10-07 19:24 319456 ----a-w- c:\windows\DIFxAPI.dll
2009-10-07 19:24 . 2009-10-07 19:24 319488 ----a-w- c:\windows\HideWin.exe
2009-10-07 19:24 . 2009-10-07 19:24 -------- d-----w- c:\program files\Common Files\InstallShield
2009-10-07 18:52 . 2009-10-07 18:52 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{EEE6C35D-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [2009-05-20 177464]

[HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-09-02 12:56 1175944 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2009-05-20 12:36 1258808 ----a-w- c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2009-05-20 1258808]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-09-02 1175944]

[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2009-05-20 1258808]

[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@="{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}"
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2008-04-29 16:55 4232968 ----a-w- c:\program files\Protector Suite QL\farchns.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@="{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}"
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2008-04-29 16:55 4232968 ----a-w- c:\program files\Protector Suite QL\farchns.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"MGSysCtrl"="c:\program files\System Control Manager\MGSysCtrl.exe" [2008-08-26 708608]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2009-08-26 111928]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-08-20 6265376]
"Skytel"="Skytel.exe" - c:\windows\SkyTel.exe [2008-08-20 1833504]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"DisableCAD"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2008-04-29 16:43 96008 ----a-w- c:\windows\System32\psqlpwd.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli psqlpwd

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

R3 enecir;ENE CIR Receiver;c:\windows\System32\drivers\enecir.sys [7. 10. 2009 21:38 54784]
S2 Micro Star SCM;Micro Star SCM;c:\program files\System Control Manager\MSIService.exe [7. 10. 2009 21:54 159744]
S3 DfSdkS;Defragmentation-Service;c:\program files\Ashampoo\Ashampoo WinOptimizer 6\DfSdkS.exe [8. 10. 2009 9:47 406016]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://eu.ask.com?o=15161&l=dis
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\programdata\LangSoft\WebIE.dll
FF - ProfilePath - c:\users\pepinho\AppData\Roaming\Mozilla\Firefox\Profiles\w4torgga.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://hnonline.sk/
FF - prefs.js: keyword.URL - hxxp://supertoolbar.ask.com/redirect?cl ... e=en_EU&q=
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-OEXPRESS - (no file)
AddRemove-PC Translator - c:\users\pepinho\AppData\Local\Temp\UN32.EXE



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-21 18:08
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(700)
c:\windows\system32\psqlpwd.dll
c:\program files\Protector Suite QL\homefus2.dll
c:\program files\Protector Suite QL\infql2.dll
.
Completion time: 2009-10-21 18:09
ComboFix-quarantined-files.txt 2009-10-21 16:09

Pre-Run: 10 739 716 096 bytes free
Post-Run: 10 243 731 456 bytes free

- - End Of File - - 4F99912CE2F6930998336BD750A9B8C0


Offline

Skúsený užívateľ
Skúsený užívateľ
Obrázok užívateľa

Registrovaný: 15.08.09
Prihlásený: 05.02.10
Príspevky: 355
Témy: 0
Príspevok NapísalOffline : 21.10.2009 18:44

Presun ikonu CF na plochu, vypni vsetky otvorene aplikacie, ako aj rezidenty antiviru, antispywaru a firewall a otvor poznamkovy blok. Donho skopiruj:

Kód:
KillAll::
Folder::
c:\program files\Ask.com
c:\program files\DAEMON Tools Toolbar
c:\programdata\Norton
c:\programdata\NortonInstaller
c:\users\pepinho\AppData\Local\Symantec

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
[-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

DDS::
uStart Page = hxxp://eu.ask.com?o=15161&l=dis

FireFox::
FF - ProfilePath - c:\users\pepinho\AppData\Roaming\Mozilla\Firefox\Profiles\w4torgga.default\
FF - prefs.js: keyword.URL - hxxp://supertoolbar.ask.com/redirect?client=ff&src=kw&tb=UT2V5&o=15158&locale=en_EU&q=

RegLockDel::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

Extra::

Uloz na plochu ako CFScript.txt a mysou pretiahni nad ikonou CF.

norton

Program script spracuje a spravi novy log.


Pozor: Ak po aplikacii skriptu nenabehne Windows, restartuj PC, stlac F8 a zvol Poslednu znamu funkcnu konfiguraciu.


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 25.12.08
Prihlásený: 15.06.10
Príspevky: 76
Témy: 12
Príspevok Napísal autor témyOffline : 21.10.2009 19:13

síce som to urobil, ale mám teraz problémy s compom. nejde mi spustiť mozilla, explorer, ovládací panel a neviem ešte čo všetko. vyhadzuje tabuľku, v ktorej píše:
Vyskytol sa pokus o nepovolenú operáciu s kľúčom databázy Registry, ktorý bol označený na odstránenie.

log z CF

ComboFix 09-10-20.03 - pepinho . 10. 2009 18:51.2.2 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1250.421.1051.18.3070.2194 [GMT 2:00]
Running from: c:\users\pepinho\Desktop\ComboFix.exe
Command switches used :: c:\users\pepinho\Desktop\CFScript.txt.txt
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Ask.com
c:\program files\Ask.com\cobrand.ico
c:\program files\Ask.com\config.xml
c:\program files\Ask.com\favicon.ico
c:\program files\Ask.com\GenericAskToolbar.dll
c:\program files\Ask.com\mupcfg.xml
c:\program files\Ask.com\SaUpdate.exe
c:\program files\Ask.com\UpdateTask.exe
c:\program files\DAEMON Tools Toolbar
c:\program files\DAEMON Tools Toolbar\_DTLite.xml
c:\program files\DAEMON Tools Toolbar\DTToolbar.dll
c:\program files\DAEMON Tools Toolbar\Resources\about.ico
c:\program files\DAEMON Tools Toolbar\Resources\AboutWindow.ico
c:\program files\DAEMON Tools Toolbar\Resources\AddRadioStation.ico
c:\program files\DAEMON Tools Toolbar\Resources\as.ico
c:\program files\DAEMON Tools Toolbar\Resources\as.png
c:\program files\DAEMON Tools Toolbar\Resources\astro.ico
c:\program files\DAEMON Tools Toolbar\Resources\az.ico
c:\program files\DAEMON Tools Toolbar\Resources\b1.bmp
c:\program files\DAEMON Tools Toolbar\Resources\b1.png
c:\program files\DAEMON Tools Toolbar\Resources\BurnImage.ico
c:\program files\DAEMON Tools Toolbar\Resources\buy.ico
c:\program files\DAEMON Tools Toolbar\Resources\cond000.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond001.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond003.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond004.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond005.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond006.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond007.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond008.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond009.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond010.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond011.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond019.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond020.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond021.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond022.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond023.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond024.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond025.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond026.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond037.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond038.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond039.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond040.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond041.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond046.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond048.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond050.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond051.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond052.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond053.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond054.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond055.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond056.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond057.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond058.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond059.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond060.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond061.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond062.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond063.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond064.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond065.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond066.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond067.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond068.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond069.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond075.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond076.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond077.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond078.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond079.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond080.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond084.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond085.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond086.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond087.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond088.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond089.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond090.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond091.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond092.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond093.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond094.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond095.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond108.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond109.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond110.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond111.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond112.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond113.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond120.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond121.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond122.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond126.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond127.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond128.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond129.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond130.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond131.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond132.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond133.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond134.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond135.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond136.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond137.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond138.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond140.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond141.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond142.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond143.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond148.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond149.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond152.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond154.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond155.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond156.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond157.gif
c:\program files\DAEMON Tools Toolbar\Resources\Config.ico
c:\program files\DAEMON Tools Toolbar\Resources\d.ico
c:\program files\DAEMON Tools Toolbar\Resources\d2.ico
c:\program files\DAEMON Tools Toolbar\Resources\daemon.ico
c:\program files\DAEMON Tools Toolbar\Resources\dot_disabled.bmp
c:\program files\DAEMON Tools Toolbar\Resources\dot_enabled.bmp
c:\program files\DAEMON Tools Toolbar\Resources\dot_on_over.bmp
c:\program files\DAEMON Tools Toolbar\Resources\ds.ico
c:\program files\DAEMON Tools Toolbar\Resources\dsearch.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt.ico
c:\program files\DAEMON Tools Toolbar\Resources\DTPro.ico
c:\program files\DAEMON Tools Toolbar\Resources\dtt16.ico
c:\program files\DAEMON Tools Toolbar\Resources\dtt32.ico
c:\program files\DAEMON Tools Toolbar\Resources\Dwnl.ico
c:\program files\DAEMON Tools Toolbar\Resources\emulation.ico
c:\program files\DAEMON Tools Toolbar\Resources\favicon.ico
c:\program files\DAEMON Tools Toolbar\Resources\features.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrix.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameS.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameSA.ico
c:\program files\DAEMON Tools Toolbar\Resources\gd.ico
c:\program files\DAEMON Tools Toolbar\Resources\genre.xml
c:\program files\DAEMON Tools Toolbar\Resources\globe.ico
c:\program files\DAEMON Tools Toolbar\Resources\GrabImage.ico
c:\program files\DAEMON Tools Toolbar\Resources\hb.bmp
c:\program files\DAEMON Tools Toolbar\Resources\hb.ico
c:\program files\DAEMON Tools Toolbar\Resources\help.ico
c:\program files\DAEMON Tools Toolbar\Resources\hide.ico
c:\program files\DAEMON Tools Toolbar\Resources\ImageS.ico
c:\program files\DAEMON Tools Toolbar\Resources\ImageSA.ico
c:\program files\DAEMON Tools Toolbar\Resources\ip.ico
c:\program files\DAEMON Tools Toolbar\Resources\lang.xml
c:\program files\DAEMON Tools Toolbar\Resources\lingvo.ico
c:\program files\DAEMON Tools Toolbar\Resources\m.ico
c:\program files\DAEMON Tools Toolbar\Resources\mail.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_disable.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_disable.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\MenuRadioConfig.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuRadioStation.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuRSCur.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuTr.ico
c:\program files\DAEMON Tools Toolbar\Resources\next.bmp
c:\program files\DAEMON Tools Toolbar\Resources\next_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\next_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\next_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\none.bmp
c:\program files\DAEMON Tools Toolbar\Resources\none_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\noW.gif
c:\program files\DAEMON Tools Toolbar\Resources\op.ico
c:\program files\DAEMON Tools Toolbar\Resources\play.bmp
c:\program files\DAEMON Tools Toolbar\Resources\play.ico
c:\program files\DAEMON Tools Toolbar\Resources\play_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\play_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\play_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\pragma.ico
c:\program files\DAEMON Tools Toolbar\Resources\prev.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prev_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prev_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prev_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prod.ico
c:\program files\DAEMON Tools Toolbar\Resources\Radio.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioBg.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioBg.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioBgMask.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDisp.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDisp_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioE.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioG.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioL.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLDotMask.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLeft.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLeftMask.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLM.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioM.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioN.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioR.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioR.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioRM.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioRU.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioW.bmp
c:\program files\DAEMON Tools Toolbar\Resources\rbcheck.ico
c:\program files\DAEMON Tools Toolbar\Resources\rbtxt.ico
c:\program files\DAEMON Tools Toolbar\Resources\refresh.bmp
c:\program files\DAEMON Tools Toolbar\Resources\refresh_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\refresh_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\refresh_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Rss.ico
c:\program files\DAEMON Tools Toolbar\Resources\Rss1.ico
c:\program files\DAEMON Tools Toolbar\Resources\RssA.ico
c:\program files\DAEMON Tools Toolbar\Resources\RssA1.ico
c:\program files\DAEMON Tools Toolbar\Resources\rssClose.ico
c:\program files\DAEMON Tools Toolbar\Resources\rssL.bmp
c:\program files\DAEMON Tools Toolbar\Resources\rssOpen.ico
c:\program files\DAEMON Tools Toolbar\Resources\RssRefresh.ico
c:\program files\DAEMON Tools Toolbar\Resources\s2.ico
c:\program files\DAEMON Tools Toolbar\Resources\show.ico
c:\program files\DAEMON Tools Toolbar\Resources\size.bmp
c:\program files\DAEMON Tools Toolbar\Resources\size_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\skins.ico
c:\program files\DAEMON Tools Toolbar\Resources\spt.ico
c:\program files\DAEMON Tools Toolbar\Resources\stop.bmp
c:\program files\DAEMON Tools Toolbar\Resources\stop.ico
c:\program files\DAEMON Tools Toolbar\Resources\stop_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\stop_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\stop_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\style.ico
c:\program files\DAEMON Tools Toolbar\Resources\SupportRequest.ico
c:\program files\DAEMON Tools Toolbar\Resources\time.ico
c:\program files\DAEMON Tools Toolbar\Resources\TitleIcon.ico
c:\program files\DAEMON Tools Toolbar\Resources\toolbar.xml
c:\program files\DAEMON Tools Toolbar\Resources\trans.ico
c:\program files\DAEMON Tools Toolbar\Resources\Trash.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_disable.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\u.ico
c:\program files\DAEMON Tools Toolbar\Resources\vol.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol.ico
c:\program files\DAEMON Tools Toolbar\Resources\vol_back.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_dott.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_dott_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_mute.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_mute_check.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wb.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Weather_m42.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Weather_m43.bmp
c:\program files\DAEMON Tools Toolbar\Resources\WebS.ico
c:\program files\DAEMON Tools Toolbar\Resources\WebSa.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi0.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi1.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi10.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi11.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi12.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi13.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi14.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi2.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi3.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi4.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi5.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi6.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi7.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi8.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi9.ico
c:\program files\DAEMON Tools Toolbar\uninst.exe
c:\programdata\Norton
c:\programdata\Norton\{086A63F0-6B13-4F29-9695-134E7A01E963}\LC.INI
c:\programdata\Norton\00000082\00000109\000003c3\cltLMS1.dat
c:\programdata\Norton\00000082\00000109\000003c3\cltLMS2.dat
c:\programdata\Norton\00000082\00000109\000003c6\cltLMS1.dat
c:\programdata\Norton\00000082\00000109\000003c6\cltLMS2.dat
c:\programdata\Norton\00000082\00000109\cltupgrade.dat
c:\programdata\Norton\00000082\00000109\key.txt
c:\programdata\NortonInstaller
c:\programdata\NortonInstaller\Logs\2009-10-09-19h08m38s.7z
c:\programdata\NortonInstaller\Logs\2009-10-09-19h08m48s.7z
c:\programdata\NortonInstaller\Logs\2009-10-09-19h08m59s.7z
c:\programdata\NortonInstaller\Logs\2009-10-12-09h24m47s.7z
c:\programdata\NortonInstaller\Logs\2009-10-12-09h24m50s.7z
c:\programdata\NortonInstaller\Logs\2009-10-12-09h25m07s.7z
c:\programdata\NortonInstaller\Logs\2009-10-18-18h29m07s\Log.Lue
c:\programdata\NortonInstaller\Logs\2009-10-18-18h29m07s\NortonInstall-2009-10-18-18h29m07s.log
c:\programdata\NortonInstaller\Logs\2009-10-18-18h29m13s\SymNRT 10-18-2009 18h29m10s.log
c:\programdata\NortonInstaller\Logs\2009-10-18-18h29m32s\NortonInstall-2009-10-18-18h29m32s.log
c:\programdata\NortonInstaller\Logs\2009-10-18-18h35m08s\BHCA-0x0D50.log
c:\programdata\NortonInstaller\Logs\2009-10-18-18h35m08s\Install.1.mft
c:\programdata\NortonInstaller\Logs\2009-10-18-18h35m08s\Log.Lue
c:\programdata\NortonInstaller\Logs\2009-10-18-18h35m08s\NortonInstall-2009-10-18-18h35m08s.log
c:\programdata\NortonInstaller\Logs\2009-10-18-18h35m08s\SymIMexe-0x0AB8.log
c:\programdata\NortonInstaller\Logs\2009-10-18-18h35m13s\SymNRT 10-18-2009 18h35m10s.log
c:\programdata\NortonInstaller\Logs\2009-10-19-10h23m58s\Log.Lue
c:\programdata\NortonInstaller\Logs\2009-10-19-10h23m58s\NortonInstall-2009-10-19-10h23m58s.log
c:\programdata\NortonInstaller\Logs\2009-10-19-10h24m03s\SymNRT 10-19-2009 10h24m1s.log
c:\programdata\NortonInstaller\Logs\2009-10-19-10h26m34s\NortonInstall-2009-10-19-10h26m34s.log
c:\programdata\NortonInstaller\Logs\2009-10-19-10h29m27s\NortonInstall-2009-10-19-10h29m27s.log
c:\programdata\NortonInstaller\Logs\2009-10-19-10h29m52s\BHCA-0x1310.log
c:\programdata\NortonInstaller\Logs\2009-10-19-10h29m52s\Install.1.mft
c:\programdata\NortonInstaller\Logs\2009-10-19-10h29m52s\NortonInstall-2009-10-19-10h29m52s.log
c:\programdata\NortonInstaller\Logs\2009-10-19-10h29m52s\SymIMexe-0x0E68.log
c:\programdata\NortonInstaller\Logs\2009-10-19-10h29m52s\WFPUninstexe-0x12E0.log
c:\programdata\NortonInstaller\Logs\2009-10-19-10h32m20s\NortonInstall-2009-10-19-10h32m20s.log
c:\programdata\NortonInstaller\Logs\2009-10-19-10h47m32s\BHCA-0x0D68.log
c:\programdata\NortonInstaller\Logs\2009-10-19-10h47m32s\Install.1.mft
c:\programdata\NortonInstaller\Logs\2009-10-19-10h47m32s\NortonInstall-2009-10-19-10h47m32s.log
c:\programdata\NortonInstaller\Logs\2009-10-19-10h47m32s\SymIMexe-0x0B80.log
c:\programdata\NortonInstaller\Logs\2009-10-19-10h47m35s\SymNRT 10-19-2009 10h47m34s.log
c:\programdata\NortonInstaller\Logs\2009-10-19-19h54m55s\BHCA-0x12F8.log
c:\programdata\NortonInstaller\Logs\2009-10-19-19h54m55s\Install.1.mft
c:\programdata\NortonInstaller\Logs\2009-10-19-19h54m55s\NortonInstall-2009-10-19-19h54m55s.log
c:\programdata\NortonInstaller\Logs\2009-10-19-19h54m55s\SymIMexe-0x12CC.log
c:\programdata\NortonInstaller\Logs\2009-10-19-19h54m55s\WFPUninstexe-0x1224.log
c:\programdata\NortonInstaller\Logs\2009-10-19-19h56m04s\NortonInstall-2009-10-19-19h56m04s.log
c:\programdata\NortonInstaller\Logs\Norton AntiVirus.dat
c:\programdata\NortonInstaller\Logs\Url.txt
c:\users\pepinho\AppData\Local\Symantec
c:\users\pepinho\AppData\Local\Symantec\CEDUrl.txt

.
((((((((((((((((((((((((( Files Created from 2009-09-21 to 2009-10-21 )))))))))))))))))))))))))))))))
.

2009-10-21 16:56 . 2009-10-21 16:57 -------- d-----w- c:\users\pepinho\AppData\Local\temp
2009-10-20 06:19 . 2009-10-20 06:19 -------- d-----w- c:\users\pepinho\AppData\Roaming\Media Player Classic
2009-10-20 05:22 . 2008-09-16 19:23 168448 ----a-w- c:\windows\system32\unrar.dll
2009-10-20 05:22 . 2008-12-07 18:08 795648 ----a-w- c:\windows\system32\xvidcore.dll
2009-10-20 05:22 . 2008-12-07 18:08 130048 ----a-w- c:\windows\system32\xvidvfw.dll
2009-10-20 05:22 . 2004-01-25 16:18 217088 ----a-w- c:\windows\system32\yv12vfw.dll
2009-10-20 05:22 . 2008-12-11 00:33 86016 ----a-w- c:\windows\system32\dpl100.dll
2009-10-20 05:22 . 2008-11-06 16:37 3596288 ----a-w- c:\windows\system32\qt-dx331.dll
2009-10-20 05:22 . 2008-11-06 16:33 684032 ----a-w- c:\windows\system32\divx.dll
2009-10-20 05:22 . 2008-12-08 11:53 57344 ----a-w- c:\windows\system32\ff_vfw.dll
2009-10-20 05:22 . 2009-10-20 05:22 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-10-19 19:53 . 2009-10-19 19:53 -------- d-----w- c:\program files\YouTube Downloader
2009-10-18 21:28 . 2009-10-18 21:28 -------- d-----w- c:\program files\uTorrent
2009-10-18 19:48 . 2009-10-19 18:01 -------- d-----w- c:\program files\trend micro
2009-10-18 19:48 . 2009-10-18 19:48 -------- d-----w- C:\rsit
2009-10-18 16:47 . 2009-10-18 18:51 -------- d-----w- c:\users\pepinho\AppData\Local\Tific
2009-10-18 16:47 . 2009-10-18 16:47 -------- d-----w- c:\users\pepinho\AppData\Roaming\Tific
2009-10-14 14:39 . 2009-10-14 14:39 -------- d-----w- c:\users\pepinho\AppData\Local\Adobe
2009-10-14 14:38 . 2009-10-14 14:38 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-10-14 14:36 . 2009-10-14 16:29 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-14 08:22 . 2009-10-14 08:25 -------- d-----w- c:\programdata\LangSoft
2009-10-14 08:22 . 2009-10-14 08:29 -------- d-----w- c:\users\pepinho\AppData\Roaming\LangSoft
2009-10-11 11:04 . 2009-10-11 11:04 -------- d-----w- c:\users\pepinho\AppData\Roaming\Ashampoo
2009-10-09 12:53 . 2009-10-09 12:54 -------- d-----w- c:\users\pepinho\AppData\Local\Risen
2009-10-09 12:52 . 2009-10-09 12:52 281760 ----a-w- c:\windows\system32\drivers\atksgt.sys
2009-10-09 12:52 . 2009-10-09 12:52 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2009-10-09 12:51 . 2009-10-09 12:51 -------- d-----w- c:\program files\AGEIA Technologies
2009-10-09 12:51 . 2009-10-09 12:51 -------- d-----w- c:\windows\system32\AGEIA
2009-10-09 12:51 . 2009-10-09 12:51 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-10-09 12:23 . 2009-10-09 12:23 -------- d-----w- c:\users\pepinho\AppData\Roaming\DAEMON Tools Pro
2009-10-09 12:23 . 2009-10-09 12:23 -------- d-----w- c:\users\pepinho\AppData\Roaming\DAEMON Tools
2009-10-09 12:22 . 2009-10-09 12:22 -------- d-----w- c:\programdata\DAEMON Tools Lite
2009-10-09 12:21 . 2009-10-09 12:22 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-10-09 12:17 . 2009-10-09 12:17 717296 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-10-09 12:17 . 2009-10-09 12:24 -------- d-----w- c:\users\pepinho\AppData\Roaming\DAEMON Tools Lite
2009-10-08 20:34 . 2009-10-21 15:55 -------- d-----w- c:\users\pepinho\AppData\Local\CrashDumps
2009-10-08 14:55 . 2009-10-08 14:55 -------- d-----w- c:\program files\SweetIM
2009-10-08 14:55 . 2009-10-08 14:55 -------- d-----w- c:\programdata\SweetIM
2009-10-08 10:05 . 2006-10-26 17:56 32592 ----a-w- c:\windows\system32\msonpmon.dll
2009-10-08 10:04 . 2009-10-08 10:04 -------- d-----w- c:\program files\Microsoft Works
2009-10-08 10:03 . 2009-10-08 10:03 -------- d-----w- c:\windows\PCHEALTH
2009-10-08 10:03 . 2009-10-08 10:03 -------- d-----w- c:\program files\Microsoft.NET
2009-10-08 10:01 . 2009-10-08 10:01 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-10-08 10:01 . 2009-10-08 10:04 -------- d-----w- c:\windows\SHELLNEW
2009-10-08 10:00 . 2009-10-08 10:00 -------- d-----w- c:\users\pepinho\AppData\Local\Microsoft Help
2009-10-08 10:00 . 2009-10-08 10:06 -------- d-----w- c:\programdata\Microsoft Help
2009-10-08 09:53 . 2009-10-19 15:47 -------- d-----w- c:\users\pepinho\AppData\Roaming\uTorrent
2009-10-08 09:44 . 2009-10-08 09:44 -------- d-----w- c:\program files\The KMPlayer
2009-10-08 09:36 . 2009-10-08 10:17 -------- d-----w- c:\users\pepinho\AppData\Roaming\ICQ
2009-10-08 09:36 . 2009-10-08 10:17 -------- d-----w- c:\program files\ICQ6.5
2009-10-08 07:47 . 2009-08-24 20:08 28160 ----a-w- c:\windows\system32\DfSdkBt.exe
2009-10-08 07:47 . 2009-10-08 08:43 -------- d-----w- c:\program files\Ashampoo
2009-10-08 06:48 . 2003-03-18 19:20 1060864 ----a-w- c:\windows\system32\MFC71.dll
2009-10-08 06:48 . 2003-03-18 18:14 499712 ----a-w- c:\windows\system32\MSVCP71.dll
2009-10-08 06:48 . 2003-02-21 02:42 348160 ----a-w- c:\windows\system32\MSVCR71.dll
2009-10-08 06:48 . 2009-10-08 06:48 -------- d-----w- c:\program files\Alwil Software
2009-10-07 22:03 . 2009-10-07 22:04 -------- d-----w- c:\users\pepinho\AppData\Local\MigWiz
2009-10-07 21:30 . 2009-10-07 21:30 -------- d-----w- c:\programdata\Backup
2009-10-07 20:31 . 2009-10-07 20:31 -------- d-----w- c:\users\pepinho\AppData\Local\Mozilla
2009-10-07 20:28 . 2009-10-07 20:28 -------- d-----w- c:\users\pepinho\AppData\Local\Toshiba
2009-10-07 20:22 . 2009-10-07 20:22 -------- d-----w- c:\program files\Toshiba
2009-10-07 20:19 . 2009-10-07 20:19 -------- d-----w- c:\program files\Camera Recorder
2009-10-07 20:16 . 2009-10-07 20:16 -------- d-----w- c:\program files\Dolby
2009-10-07 20:14 . 2009-10-01 08:29 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-10-07 19:54 . 2008-08-25 09:20 4096 ----a-w- c:\windows\system32\msiapcfg.dll
2009-10-07 19:54 . 2009-10-07 19:54 -------- d-----w- c:\program files\System Control Manager
2009-10-07 19:46 . 2009-10-08 09:16 -------- d-----w- c:\users\pepinho\AppData\Roaming\Protector Suite
2009-10-07 19:42 . 2009-10-07 19:42 -------- d-----w- c:\program files\RSA
2009-10-07 19:42 . 2009-10-07 19:42 -------- d-----w- c:\program files\Common Files\SPBA
2009-10-07 19:42 . 2009-10-07 19:43 -------- d-----w- c:\program files\Protector Suite QL
2009-10-07 19:42 . 2009-10-07 19:42 -------- d-----w- c:\programdata\UIB
2009-10-07 19:41 . 2009-10-07 18:54 -------- d-----w- c:\windows\Panther
2009-10-07 19:41 . 2009-10-07 19:41 -------- d-----w- c:\windows\system32\Macromed
2009-10-07 19:39 . 2008-10-16 21:13 1809944 ----a-w- c:\windows\system32\wuaueng.dll
2009-10-07 19:39 . 2008-10-16 21:09 51224 ----a-w- c:\windows\system32\wuauclt.exe
2009-10-07 19:39 . 2008-10-16 21:09 43544 ----a-w- c:\windows\system32\wups2.dll
2009-10-07 19:39 . 2008-10-16 20:56 1524736 ----a-w- c:\windows\system32\wucltux.dll
2009-10-07 19:39 . 2008-10-16 21:12 561688 ----a-w- c:\windows\system32\wuapi.dll
2009-10-07 19:39 . 2008-10-16 21:08 34328 ----a-w- c:\windows\system32\wups.dll
2009-10-07 19:39 . 2008-10-16 20:55 83456 ----a-w- c:\windows\system32\wudriver.dll
2009-10-07 19:39 . 2008-10-16 12:08 162064 ----a-w- c:\windows\system32\wuwebv.dll
2009-10-07 19:39 . 2008-10-16 11:56 31232 ----a-w- c:\windows\system32\wuapp.exe
2009-10-07 19:38 . 2009-10-07 19:38 -------- d-----w- c:\program files\DIFX
2009-10-07 19:38 . 2008-04-28 17:54 54784 ----a-w- c:\windows\system32\drivers\enecir.sys
2009-10-07 19:35 . 2008-03-28 02:46 54824 ----a-w- c:\windows\agrsmdel.exe
2009-10-07 19:35 . 2008-03-21 04:13 1203776 ----a-w- c:\windows\system32\drivers\AGRSM.sys
2009-10-07 19:35 . 2008-03-18 04:27 13312 ----a-w- c:\windows\system32\agrsmsvc.exe
2009-10-07 19:35 . 2007-12-11 04:40 13312 ------w- c:\windows\system32\agrscoin.dll
2009-10-07 19:35 . 2009-10-07 19:35 -------- d-----w- c:\windows\Options
2009-10-07 19:34 . 2008-06-05 17:01 62464 ----a-w- c:\windows\system32\drivers\RTSTOR.sys
2009-10-07 19:34 . 2008-05-06 15:41 6416928 ----a-w- c:\windows\system\DriveIcon.dll
2009-10-07 19:33 . 2009-10-07 19:33 -------- d-----w- c:\windows\system32\nn-NO
2009-10-07 19:33 . 2008-06-30 17:56 917504 ----a-w- c:\windows\system32\drivers\athr.sys
2009-10-07 19:33 . 2008-06-30 17:56 917504 ----a-w- c:\windows\system32\athr.sys
2009-10-07 19:33 . 2008-06-30 11:50 376832 ----a-w- c:\windows\system32\S64CPA.exe
2009-10-07 19:33 . 2008-06-30 11:50 53248 ----a-w- c:\windows\system32\athihvui.dll
2009-10-07 19:33 . 2008-06-30 11:49 393216 ----a-w- c:\windows\system32\athihvs.dll
2009-10-07 19:31 . 2009-10-07 19:33 -------- d-----w- c:\program files\Atheros
2009-10-07 19:31 . 2009-10-07 19:31 -------- d-----w- c:\program files\Cisco
2009-10-07 19:31 . 2009-10-07 19:31 -------- d-----w- c:\programdata\Atheros
2009-10-07 19:30 . 2008-05-02 05:59 122368 ----a-w- c:\windows\system32\drivers\Rtlh86.sys
2009-10-07 19:30 . 2009-10-07 19:30 -------- d-----w- c:\users\pepinho\AppData\Roaming\InstallShield
2009-10-07 19:18 . 2009-10-07 19:18 -------- d-----w- c:\users\pepinho\AppData\Roaming\ATI
2009-10-07 19:18 . 2009-10-07 19:18 -------- d-----w- c:\users\pepinho\AppData\Local\ATI
2009-10-07 19:18 . 2009-10-07 19:18 -------- d-----w- c:\programdata\ATI
2009-10-07 19:17 . 2009-10-07 19:17 0 ----a-w- c:\windows\ativpsrm.bin
2009-10-07 19:14 . 2008-05-14 14:04 413696 ----a-w- c:\windows\system32\ATIDEMGX.dll
2009-10-07 19:14 . 2008-05-14 13:33 3107788 ----a-w- c:\windows\system32\atiumdva.dat
2009-10-07 19:13 . 2009-10-18 21:25 -------- d-sh--w- c:\windows\Installer
2009-10-07 19:13 . 2009-10-07 19:13 -------- d-----w- c:\program files\ATI
2009-10-07 19:12 . 2009-10-07 19:15 -------- d-----w- c:\program files\ATI Technologies
2009-10-07 19:06 . 2009-10-07 19:06 -------- d-----w- c:\program files\Intel
2009-10-07 19:06 . 2008-02-22 05:06 53248 ----a-r- c:\windows\system32\CSVer.dll
2009-10-07 19:03 . 2009-10-08 10:12 99864 ----a-w- c:\users\pepinho\AppData\Local\GDIPFONTCACHEV1.DAT
2009-10-07 18:58 . 2009-10-08 07:51 -------- d-----w- c:\windows\Debug
2009-10-07 18:32 . 2009-10-07 19:41 -------- d-----w- C:\Boot

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-19 17:45 . 2009-10-07 19:02 7512 ----a-w- c:\users\pepinho\AppData\Local\d3d9caps.dat
2009-10-09 12:41 . 2009-10-07 19:24 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-08 10:04 . 2006-11-02 12:35 -------- d-----w- c:\program files\MSBuild
2009-10-07 19:30 . 2009-10-07 19:24 -------- d-----w- c:\program files\Realtek
2009-10-07 19:24 . 2009-10-07 19:24 319456 ----a-w- c:\windows\DIFxAPI.dll
2009-10-07 19:24 . 2009-10-07 19:24 319488 ----a-w- c:\windows\HideWin.exe
2009-10-07 19:24 . 2009-10-07 19:24 -------- d-----w- c:\program files\Common Files\InstallShield
2009-10-07 18:52 . 2009-10-07 18:52 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{EEE6C35D-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [2009-05-20 177464]

[HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2009-05-20 12:36 1258808 ----a-w- c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2009-05-20 1258808]

[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2009-05-20 1258808]

[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@="{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}"
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2008-04-29 16:55 4232968 ----a-w- c:\program files\Protector Suite QL\farchns.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@="{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}"
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2008-04-29 16:55 4232968 ----a-w- c:\program files\Protector Suite QL\farchns.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"MGSysCtrl"="c:\program files\System Control Manager\MGSysCtrl.exe" [2008-08-26 708608]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2009-08-26 111928]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-08-20 6265376]
"Skytel"="Skytel.exe" - c:\windows\SkyTel.exe [2008-08-20 1833504]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"DisableCAD"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2008-04-29 16:43 96008 ----a-w- c:\windows\System32\psqlpwd.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli psqlpwd

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

R2 Micro Star SCM;Micro Star SCM;c:\program files\System Control Manager\MSIService.exe [7. 10. 2009 21:54 159744]
R3 enecir;ENE CIR Receiver;c:\windows\System32\drivers\enecir.sys [7. 10. 2009 21:38 54784]
S3 DfSdkS;Defragmentation-Service;c:\program files\Ashampoo\Ashampoo WinOptimizer 6\DfSdkS.exe [8. 10. 2009 9:47 406016]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
.
.
------- Supplementary Scan -------
.
IE: E&xportova do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\programdata\LangSoft\WebIE.dll
FF - ProfilePath - c:\users\pepinho\AppData\Roaming\Mozilla\Firefox\Profiles\w4torgga.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://hnonline.sk/
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
.
- - - - ORPHANS REMOVED - - - -

AddRemove-DAEMON Tools Toolbar - c:\program files\DAEMON Tools Toolbar\uninst.exe



**************************************************************************
scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files:

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(700)
c:\windows\system32\psqlpwd.dll
c:\program files\Protector Suite QL\homefus2.dll
c:\program files\Protector Suite QL\infql2.dll

- - - - - - - > 'Explorer.exe'(1824)
c:\program files\Protector Suite QL\farchns.dll
c:\program files\Protector Suite QL\infql2.dll
c:\program files\Protector Suite QL\qlbase.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Protector Suite QL\upeksvr.exe
c:\windows\system32\WLANExt.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\combofix\CF27344.exe
c:\combofix\PEV.cfxxe
.
**************************************************************************
.
Completion time: 2009-10-21 18:59 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-21 16:59
ComboFix2.txt 2009-10-21 16:09

Pre-Run: 10 167 582 720 bytes free
Post-Run: 10 124 664 832 bytes free

- - End Of File - - 6B96EAE6A7C3DD695AC530A13A89680A


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 25.12.08
Prihlásený: 15.06.10
Príspevky: 76
Témy: 12
Príspevok Napísal autor témyOffline : 22.10.2009 15:44

po reštarte to už ide všetko, ako má. aj problém s nortonom antivirus zrejme skončil. dúfam, že keď tam znova dám norton internet security, tak to bude v poriadku.
dík za pomoc!


Offline

Skúsený užívateľ
Skúsený užívateľ
Obrázok užívateľa

Registrovaný: 15.08.09
Prihlásený: 05.02.10
Príspevky: 355
Témy: 0
Príspevok NapísalOffline : 22.10.2009 19:03

To rad pocujem.

1) Docistime to:

  • Odinstaluj Combofix:
    Start -> Spustit -> (napis) combofix /u
  • Pouzi T-Cleaner (ak by ho antivirus hlasil ako smejda, nic sa netreba bat, ide len o paranoju AV programu).
  • Pouzi TFC (spust program a klikni na "Start". Pozor, PC moze byt restartovane).



2) Vloz log z HJT.

V pripade nezrovnalosti sa >>tu<< nachadza navod.


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 25.12.08
Prihlásený: 15.06.10
Príspevky: 76
Témy: 12
Príspevok Napísal autor témyOffline : 22.10.2009 19:38

malo by to byť všetko spravené, ako treba...

tu je log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:37:23, on 22. 10. 2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\System32\rundll32.exe
C:\Windows\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\ProgramData\LangSoft\WebIE.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - (no file)
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\ProgramData\LangSoft\WebIE.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [MGSysCtrl] C:\Program Files\System Control Manager\MGSysCtrl.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Defragmentation-Service (DfSdkS) - mst software GmbH, Germany - C:\Program Files\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe
O23 - Service: Micro Star SCM - Unknown owner - C:\Program Files\System Control Manager\MSIService.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe

--
End of file - 5718 bytes


Offline

Skúsený užívateľ
Skúsený užívateľ
Obrázok užívateľa

Registrovaný: 15.08.09
Prihlásený: 05.02.10
Príspevky: 355
Témy: 0
Príspevok NapísalOffline : 22.10.2009 20:40

1) Fixni v HJT (zasrktni stvorcek pri danom riadku a stlac "Fix Checked"):

Kód:
O3 - Toolbar: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - (no file)
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab


2) ASAP doinstaluj nas5 ten NIS.


3) Updatuj Adobe Reader (poslednu verziu najdes >>tu<<).

A malo by to byt cele ;)


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 25.12.08
Prihlásený: 15.06.10
Príspevky: 76
Témy: 12
Príspevok Napísal autor témyOffline : 22.10.2009 20:55

malo by to byť...
ešte raz ďakujem!!!


Offline

Skúsený užívateľ
Skúsený užívateľ
Obrázok užívateľa

Registrovaný: 15.08.09
Prihlásený: 05.02.10
Príspevky: 355
Témy: 0
Príspevok NapísalOffline : 22.10.2009 21:02

Za malo :)


Odpovedať na tému [ Príspevkov: 22 ] 


Podobné témy

 Témy  Odpovede  Zobrazenia  Posledný príspevok 
V tomto fóre nie sú ďalšie neprečítané témy. Norton SystemWorks

v Ostatné programy

1

1182

17.01.2006 14:00

Spirit Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. Norton Ghost

v Ostatné programy

1

588

11.06.2009 12:37

shiro Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. Norton 360

v Antivíry a antispywary

2

595

11.11.2008 15:37

Sabina Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. Norton Internet Security

v Antivíry a antispywary

6

1468

05.02.2006 17:38

gen1us Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. Norton Internet Security

v Antivíry a antispywary

0

298

26.12.2014 23:58

samuel747 Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. Norton AntiVirus Corporate

v Antivíry a antispywary

2

500

29.11.2008 8:21

cuMphort Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. Norton - preťaženie procesora

v Antivíry a antispywary

2

315

21.03.2013 14:22

Vydribor Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. Norton Ghost 10

v Ostatné programy

0

821

16.04.2007 9:25

sTromSK Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. Norton Partition Magic

v Ostatné programy

3

806

29.10.2009 17:30

pablox Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. Norton alebo BitDefender

v Antivíry a antispywary

5

319

20.01.2014 23:48

Kraliček Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. nejde odstranit norton

v Operačné systémy Microsoft

14

1193

08.02.2009 17:54

McDog Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. norton ghost --- nemam privilegia...

v Operačné systémy Microsoft

2

339

19.04.2008 14:50

yterbium Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. Sleep - Norton Internet Security

v Antivíry a antispywary

1

597

24.10.2010 15:06

remus Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. Norton Antivirus - nejde odstrániť

v Antivíry a antispywary

3

815

27.09.2007 15:51

Rbot Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. Norton Internet Security 2005

v Bezpečnosť a firewally

1

1010

31.10.2005 20:56

johny128 Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. Norton Ghost a partition

v Ostatné programy

2

335

21.11.2012 15:30

dano Zobrazenie posledných príspevkov


Nemôžete zakladať nové témy v tomto fóre
Nemôžete odpovedať na témy v tomto fóre
Nemôžete upravovať svoje príspevky v tomto fóre
Nemôžete mazať svoje príspevky v tomto fóre

Skočiť na:  

Powered by phpBB Jarvis © 2005 - 2024 PCforum, webhosting by WebSupport, secured by GeoTrust, edited by JanoF
Ako väčšina webových stránok aj my používame cookies. Zotrvaním na webovej stránke súhlasíte, že ich môžeme používať.
Všeobecné podmienky, spracovanie osobných údajov a pravidlá fóra