[ Príspevkov: 15 ] 
AutorSpráva
Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 25.12.07
Prihlásený: 13.05.15
Príspevky: 62
Témy: 20 | 20
NapísalOffline : 23.11.2009 15:15 | Win32/Delf.NFB worm

Caute, prosim vas pomozte mi vzdy ked pripojim nejake USB do pocitaca, nod mi zahlasi ze sa tam infiltroval nejaky Win32/Delf.NFB worm. Ako ho mam odstranit??


_________________
CPU: Intel Core 2 Duo E7200, CPU COOLER: Thermaltake BlueOrb II, MB:Asus P5Q PRO, RAM: [OCZ DDR2 PC2-6400 ATI CrossFire 1024MB Passive Cooling] x 3, GPU: Ati Radeon HD 4850 HIS, HDD: Samsung Spinpoint F1 512GB, DVD: Toshiba CD/DVD SH-S202J, PSU: Thermaltake Toughpower QFan 500W, Case: NZXT Alpha, 2nd Case Fan: 120mm AKASA AK-191SM Blue
Offline

Užívateľ
Užívateľ
Win32/Delf.NFB worm

Registrovaný: 12.09.08
Prihlásený: 27.10.17
Príspevky: 383
Témy: 16 | 16
Bydlisko: Košice
NapísalOffline : 23.11.2009 16:31 | Win32/Delf.NFB worm

no ved pomocou AV a AS(AM), ktore mas v PC ho skus dostat prec, kedze sa domnievam ze s USB preskocil aj do PC. Ak ti az potom ten problem nevyriesia, bude sa to riesit dalej. Ak bol ten "cerv" aj na USB, tak treba vycistit aj USB.


_________________
PC2= MB: Gigabyte M52L-S3P; CPU: AMD Athlon 64 X2 5200+ 2,7Ghz; RAM: 2x2GB 667Mhz Kingston HyperX CL5; VGA: Sapphire HD6670 1GB GDDR5; HDD: WD Caviar Blue 320GB; DVD RW: Sony Optiarc AD 7201S; LCD: Acer V223W "22"; PSU: Seasonic S12-II 430W; AUDIO: Teac PowerMax 200; KEY: Genius; MOUSE: E-BLUE Silenz; OS: Win Vista Bussiness 32bit,
USB: SanDisk Cruzer Extreme 32GB 3.0
Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 25.12.07
Prihlásený: 13.05.15
Príspevky: 62
Témy: 20 | 20
Napísal autor témyOffline : 23.11.2009 16:33 | Win32/Delf.NFB worm

hm to AV a AS(AM) kde najdem?


_________________
CPU: Intel Core 2 Duo E7200, CPU COOLER: Thermaltake BlueOrb II, MB:Asus P5Q PRO, RAM: [OCZ DDR2 PC2-6400 ATI CrossFire 1024MB Passive Cooling] x 3, GPU: Ati Radeon HD 4850 HIS, HDD: Samsung Spinpoint F1 512GB, DVD: Toshiba CD/DVD SH-S202J, PSU: Thermaltake Toughpower QFan 500W, Case: NZXT Alpha, 2nd Case Fan: 120mm AKASA AK-191SM Blue
Offline

Užívateľ
Užívateľ
Win32/Delf.NFB worm

Registrovaný: 12.09.08
Prihlásený: 27.10.17
Príspevky: 383
Témy: 16 | 16
Bydlisko: Košice
NapísalOffline : 23.11.2009 16:34 | Win32/Delf.NFB worm

AV - antivir, AS - antispyware, AM - antimalware. No a to mas v PC predpokladam.


_________________
PC2= MB: Gigabyte M52L-S3P; CPU: AMD Athlon 64 X2 5200+ 2,7Ghz; RAM: 2x2GB 667Mhz Kingston HyperX CL5; VGA: Sapphire HD6670 1GB GDDR5; HDD: WD Caviar Blue 320GB; DVD RW: Sony Optiarc AD 7201S; LCD: Acer V223W "22"; PSU: Seasonic S12-II 430W; AUDIO: Teac PowerMax 200; KEY: Genius; MOUSE: E-BLUE Silenz; OS: Win Vista Bussiness 32bit,
USB: SanDisk Cruzer Extreme 32GB 3.0
Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 25.12.07
Prihlásený: 13.05.15
Príspevky: 62
Témy: 20 | 20
Napísal autor témyOffline : 23.11.2009 17:43 | Win32/Delf.NFB worm

hm skusil som nieco naslo a odstranilo, len problem je ze sa to dostalo do mojho ipodu, ako to viem dostat odtial?
Len je problem ze ho neviem odstranit z tych usbeciek a ipodu, do pocitaca sa mi nevie dostat lebo ho este pravdepodobne nepusti... neviete mi plis poradit ako to dostanem odtial?


_________________
CPU: Intel Core 2 Duo E7200, CPU COOLER: Thermaltake BlueOrb II, MB:Asus P5Q PRO, RAM: [OCZ DDR2 PC2-6400 ATI CrossFire 1024MB Passive Cooling] x 3, GPU: Ati Radeon HD 4850 HIS, HDD: Samsung Spinpoint F1 512GB, DVD: Toshiba CD/DVD SH-S202J, PSU: Thermaltake Toughpower QFan 500W, Case: NZXT Alpha, 2nd Case Fan: 120mm AKASA AK-191SM Blue
Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 28.01.09
Prihlásený: 26.09.17
Príspevky: 274
Témy: 17 | 17
Bydlisko: Bratislava
Vek: 23
NapísalOffline : 24.11.2009 13:01 | Win32/Delf.NFB worm

sprav si log z RSIT a potom ho daj prekontrolovat niekomu kto sa do toho vyzna napr. pitimir


_________________
Acer Aspire V15 Nitro - Black edition
Offline

Skúsený užívateľ
Skúsený užívateľ
Obrázok užívateľa

Registrovaný: 15.08.09
Prihlásený: 05.02.10
Príspevky: 355
Témy: 0 | 0
NapísalOffline : 24.11.2009 16:43 | Win32/Delf.NFB worm

Yop, tu mas na RSIT aj navod:

Stiahni RSIT. Spust, klik na "Continue". Po dokoneceni by se ti mal otvorit textovy subor. Ten skopiruj sem.
Pokial by sa nieco stalo, najdes ho aj na adrese "C:\rsit\log.txt".


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 25.12.07
Prihlásený: 13.05.15
Príspevky: 62
Témy: 20 | 20
Napísal autor témyOffline : 24.11.2009 20:14 | Win32/Delf.NFB worm

Diki, tu je ten log

Logfile of random's system information tool 1.06 (written by random/random)
Run by Administrator at 2009-11-24 20:11:14
Microsoft Windows XP Professional Service Pack 3
System drive C: has 500 MB (2%) free of 25 GB
Total RAM: 3071 MB (62% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:11:40, on 24. 11. 2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.21115)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Mouse Driver\KMWDSrv.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\oodag.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Program Files\Common Files\ParetoLogic\PLAS\plasservice.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe
C:\Program Files\Eset\nod32kui.exe
D:\Adobe Master CS4\Acrobat 9.0\Acrobat\Acrotray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\service.exe
C:\Program Files\ParetoLogic\Anti-Virus PLUS\Pareto_AV.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Sweex\MI570\Software_X86\wh_exec.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\IObit\Advanced WindowsCare V2 Pro\Awc.exe
C:\Program Files\TC UP\TOTALCMD.EXE
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\ICQ6.5\ICQ.exe
C:\Program Files\iTunes\iTunes.exe
D:\1\The Big Bang Theory\RSIT.exe
C:\Program Files\trend micro\Administrator.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - D:\Adobe Master CS4\/Adobe Contribute CS4/contributeieplugin.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - D:\Adobe Master CS4\/Adobe Contribute CS4/contributeieplugin.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Ai Nap] "C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe"
O4 - HKLM\..\Run: [QFan Help] "C:\Program Files\ASUS\AI Suite\QFan3\QFanHelp.exe"
O4 - HKLM\..\Run: [Cpu Level Up help] C:\Program Files\ASUS\AI Suite\CpuLevelUpHelp.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "D:\Adobe Master CS4\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "D:\Adobe Master CS4\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe_ID0ENQBO] C:\PROGRA~1\COMMON~1\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4Tray.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Windows Services] service.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ParetoLogic Anti-Virus PLUS] "C:\Program Files\ParetoLogic\Anti-Virus PLUS\Pareto_AV.lnk" -NM -hidesplash
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')
O4 - Startup: Sweex MI570 Sweex Nitro Gaming Laser Mouse USB 2.0.lnk = C:\Program Files\Sweex\MI570\Software_X86\wh_exec.exe
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open Client to monitor &1 - C:\WINDOWS\web\AOpenClient.htm
O8 - Extra context menu item: Open Client to monitor &2 - C:\WINDOWS\web\AOpenClient.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\inethttpfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\inethttpfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\inethttpfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\inethttpfilter.dll
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://icq.oberon-media.com/Gameshell/G ... meHost.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: ABBYY FineReader 9.0 PE Licensing Service (ABBYY.Licensing.FineReader.Professional.9.0) - ABBYY (BIT Software) - C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe
O23 - Service: Adobe Version Cue CS4 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Dragon Age: Origins - Content Updater (DAUpdaterSvc) - BioWare - D:\Hry\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Keyboard And Mouse Communication Service (KMWDSERVICE) - UASSOFT.COM - C:\Program Files\Mouse Driver\KMWDSrv.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: plasservice (ZeppelinService) - ParetoLogic Inc. - C:\Program Files\Common Files\ParetoLogic\PLAS\plasservice.exe

--
End of file - 12092 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Advanced WindowsCare V2 Pro.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\ParetoLogic Anti-Virus PLUS.job
C:\WINDOWS\tasks\ParetoLogic Anti-Virus PLUS_dbsummary.job
C:\WINDOWS\tasks\ParetoLogic Registration.job
C:\WINDOWS\tasks\ParetoLogic Update Version2.job
C:\WINDOWS\tasks\WGASetup.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{074C1DC5-9320-4A9A-947D-C042949C6216}]
ContributeBHO Class - D:\Adobe Master CS4\/Adobe Contribute CS4/contributeieplugin.dll [2008-09-10 136560]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}]
FGCatchUrl - C:\Program Files\FlashGet\jccatch.dll [2007-08-06 94308]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2009-02-02 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11 345480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-02-02 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-02-02 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F156768E-81EF-470C-9057-481BA8380DBA}]
FlashGet GetFlash Class - C:\Program Files\FlashGet\getflash.dll [2007-05-18 163840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
SmartSelect Class - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11 345480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11 345480]
{517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - Contribute Toolbar - D:\Adobe Master CS4\/Adobe Contribute CS4/contributeieplugin.dll [2008-09-10 136560]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2008-05-16 16862720]
"Ai Nap"=C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe [2008-05-21 1423360]
"QFan Help"=C:\Program Files\ASUS\AI Suite\QFan3\QFanHelp.exe [2008-05-06 594432]
"Cpu Level Up help"=C:\Program Files\ASUS\AI Suite\CpuLevelUpHelp.exe [2007-11-30 881152]
"nod32kui"=C:\Program Files\Eset\nod32kui.exe [2008-10-25 949376]
"Adobe Acrobat Speed Launcher"=D:\Adobe Master CS4\Acrobat 9.0\Acrobat\Acrobat_sl.exe [2008-06-12 37232]
"Acrobat Assistant 8.0"=D:\Adobe Master CS4\Acrobat 9.0\Acrobat\Acrotray.exe [2008-06-11 640376]
"Adobe_ID0ENQBO"=C:\PROGRA~1\COMMON~1\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4Tray.exe [2008-08-15 378224]
"ZoneAlarm Client"=C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe [2009-09-23 1011080]
"Windows Services"=C:\WINDOWS\service.exe [2009-11-19 438272]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-11-10 417792]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-11-12 141600]
"ParetoLogic Anti-Virus PLUS"=C:\Program Files\ParetoLogic\Anti-Virus PLUS\Pareto_AV.lnk [2009-11-24 2363]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"AdobeBridge"= []
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2009-09-15 1998576]

C:\Documents and Settings\Administrator\Start Menu\Programs\Startup
Sweex MI570 Sweex Nitro Gaming Laser Mouse USB 2.0.lnk - C:\Program Files\Sweex\MI570\Software_X86\wh_exec.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2009-09-03 548352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2009-09-23 155648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-09-05 241704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2007-07-22 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"NoDispAppearancePage"=0
"NoColorChoice"=0
"NoDispCPL"=0
"NoDispSettingsPage"=0
"NoDispScrSavPage"=0
"NoVisualStyleChoice"=0
"NoSizeChoice"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SynchronousMachineGroupPolicy"=0
"SynchronousUserGroupPolicy"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoSMBalloonTip"=1
"NoDriveTypeAutoRun"=149
"MemCheckBoxInRunDlg"=0
"NoClose"=0
"NoAutoTrayNotify"=0
"NoResolveTrack"=0
"NoResolveSearch"=1
"NoWelcomeScreen"=1
"NoRecentDocsNetHood"=1
"NoDesktopCleanupWizard"=1
"NoSharedDocuments"=1
"NoThemesTab"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoResolveSearch"=
"HonorAutoRunSetting"=
"NoStrCmpLogical"=
"NoClose"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Program Files\Xfire\xfire.exe"="C:\Program Files\Xfire\xfire.exe:*:Enabled:Xfire"
"D:\Games\iw3mp.exe"="D:\Games\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) "
"D:\Hry\Assassin's Creed\AssassinsCreed_Dx9.exe"="D:\Hry\Assassin's Creed\AssassinsCreed_Dx9.exe:*:Enabled:Assassin's Creed Dx9"
"D:\Hry\Assassin's Creed\AssassinsCreed_Dx10.exe"="D:\Hry\Assassin's Creed\AssassinsCreed_Dx10.exe:*:Enabled:Assassin's Creed Dx10"
"D:\Hry\Assassin's Creed\AssassinsCreed_Launcher.exe"="D:\Hry\Assassin's Creed\AssassinsCreed_Launcher.exe:*:Enabled:Assassin's Creed Update"
"D:\RA3\Command.and.Conquer.Red.Alert.3.Multi4.Full-Rip.Skullptura\Command.and.Conquer.Red.Alert.3.Multi4.Full-Rip.Skullptura.www.LatestMedia.net\Red Alert 3\Data\ra3_1.0.game"="D:\RA3\Command.and.Conquer.Red.Alert.3.Multi4.Full-Rip.Skullptura\Command.and.Conquer.Red.Alert.3.Multi4.Full-Rip.Skullptura.www.LatestMedia.net\Red Alert 3\Data\ra3_1.0.game:*:Enabled:Command & Conquer™ Red Alert™ 3"
"C:\Program Files\Garena\Garena.exe"="C:\Program Files\Garena\Garena.exe:*:Enabled:Garena"
"D:\Hry\Rokstar\Socialclub\Rockstar Games Social Club\RGSCLauncher.exe"="D:\Hry\Rokstar\Socialclub\Rockstar Games Social Club\RGSCLauncher.exe:*:Enabled:Rockstar Games Social Club"
"D:\Hry\GtaIV\Grand Theft Auto IV\LaunchGTAIV.exe"="D:\Hry\GtaIV\Grand Theft Auto IV\LaunchGTAIV.exe:*:Enabled:Grand Theft Auto IV"
"D:\Hry\Crysis\Bin32\Crysis.exe"="D:\Hry\Crysis\Bin32\Crysis.exe:*:Enabled:Crysis_32"
"D:\Hry\Crysis\Bin32\CrysisDedicatedServer.exe"="D:\Hry\Crysis\Bin32\CrysisDedicatedServer.exe:*:Enabled:CrysisDedicatedServer_32"
"D:\Hry\Far Cry 2\bin\FarCry2.exe"="D:\Hry\Far Cry 2\bin\FarCry2.exe:*:Enabled:Far Cry 2"
"D:\Hry\Far Cry 2\bin\FC2Launcher.exe"="D:\Hry\Far Cry 2\bin\FC2Launcher.exe:*:Enabled:Far Cry 2 Updater"
"D:\Hry\Far Cry 2\bin\FC2Editor.exe"="D:\Hry\Far Cry 2\bin\FC2Editor.exe:*:Enabled:Editor"
"C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe"="C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4"
"C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe"="C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe:*:Enabled:Adobe Version Cue CS4 Server"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"D:\Hry\GearsofWar\Binaries\WarGame-G4WLive.exe"="D:\Hry\GearsofWar\Binaries\WarGame-G4WLive.exe:*:Enabled:Gears of War"
"D:\Hry\NeverwinterNights\nwn2main.exe"="D:\Hry\NeverwinterNights\nwn2main.exe:*:Enabled:Neverwinter Nights 2 Main"
"D:\Hry\NeverwinterNights\nwn2main_amdxp.exe"="D:\Hry\NeverwinterNights\nwn2main_amdxp.exe:*:Enabled:Neverwinter Nights 2 AMD"
"D:\Hry\NeverwinterNights\nwupdate.exe"="D:\Hry\NeverwinterNights\nwupdate.exe:*:Enabled:Neverwinter Nights 2 Updater"
"D:\Hry\NeverwinterNights\nwn2server.exe"="D:\Hry\NeverwinterNights\nwn2server.exe:*:Enabled:Neverwinter Nights 2 Server"
"D:\Hry\NwN2\nwn2main.exe"="D:\Hry\NwN2\nwn2main.exe:*:Enabled:Neverwinter Nights 2 Main"
"D:\Hry\NwN2\nwn2main_amdxp.exe"="D:\Hry\NwN2\nwn2main_amdxp.exe:*:Enabled:Neverwinter Nights 2 AMD"
"D:\Hry\NwN2\nwupdate.exe"="D:\Hry\NwN2\nwupdate.exe:*:Enabled:Neverwinter Nights 2 Updater"
"D:\Hry\NwN2\nwn2server.exe"="D:\Hry\NwN2\nwn2server.exe:*:Enabled:Neverwinter Nights 2 Server"
"D:\Hry\Metin2\metin2.bin"="D:\Hry\Metin2\metin2.bin:*:Enabled:metin2"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"D:\Hry\CoJ\CoJBiBGame_x86.exe"="D:\Hry\CoJ\CoJBiBGame_x86.exe:*:Enabled:Call of Juarez - Bound in Blood"
"C:\Program Files\Ventrilo\Ventrilo.exe"="C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe"
"C:\Program Files\FlashGet\FlashGet.exe"="C:\Program Files\FlashGet\FlashGet.exe:*:Enabled:Flashget"
"D:\Hry\Dragon Age\bin_ship\daorigins.exe"="D:\Hry\Dragon Age\bin_ship\daorigins.exe:*:Enabled:Dragon Age Origins Game"
"D:\Hry\Dragon Age\DAOriginsLauncher.exe"="D:\Hry\Dragon Age\DAOriginsLauncher.exe:*:Enabled:Dragon Age Origins Launcher"
"D:\Hry\Dragon Age\bin_ship\daupdatersvc.service.exe"="D:\Hry\Dragon Age\bin_ship\daupdatersvc.service.exe:*:Enabled:Dragon Age Origins Updater"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======File associations======

.js - open - "D:\Adobe Master CS4\Adobe Dreamweaver CS4\Dreamweaver.exe","%1"
.reg - edit -
.reg - open - c:\Winnt\Regedit.exe %1
.scr - open - "C:\WINDOWS\notepad.exe" "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 months======

2009-11-24 20:11:15 ----D---- C:\Program Files\trend micro
2009-11-24 20:11:14 ----D---- C:\rsit
2009-11-24 15:36:59 ----A---- C:\rollback.ini
2009-11-23 17:50:48 ----D---- C:\Program Files\ParetoLogic
2009-11-23 17:50:48 ----D---- C:\Program Files\Common Files\ParetoLogic
2009-11-23 17:50:48 ----D---- C:\Documents and Settings\All Users\Application Data\ParetoLogic Anti-Virus PLUS
2009-11-23 17:50:48 ----D---- C:\Documents and Settings\All Users\Application Data\ParetoLogic
2009-11-23 17:47:29 ----A---- C:\WINDOWS\eSellerateEngine.dll
2009-11-23 17:47:29 ----A---- C:\WINDOWS\eSellerateControl350.dll
2009-11-23 17:47:27 ----D---- C:\Program Files\True Sword 5
2009-11-23 16:41:32 ----D---- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2009-11-23 16:41:22 ----D---- C:\Program Files\SUPERAntiSpyware
2009-11-23 16:41:22 ----D---- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2009-11-23 15:03:10 ----A---- C:\WINDOWS\system32\GEARAspi.dll
2009-11-23 15:02:18 ----D---- C:\Program Files\iPod
2009-11-23 15:02:16 ----D---- C:\Program Files\iTunes
2009-11-23 15:02:16 ----D---- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-11-23 15:02:02 ----D---- C:\Program Files\Bonjour
2009-11-23 15:00:23 ----A---- C:\WINDOWS\system32\usbaaplrc.dll
2009-11-23 14:59:55 ----D---- C:\Program Files\Common Files\Apple
2009-11-22 22:50:26 ----A---- C:\Notepad.exe
2009-11-19 22:04:10 ----RSH---- C:\WINDOWS\service.exe
2009-11-15 20:48:24 ----N---- C:\WINDOWS\system32\ati2sgag.exe
2009-11-12 14:46:06 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$
2009-11-08 20:09:47 ----D---- C:\Documents and Settings\All Users\Application Data\BioWare
2009-11-08 20:06:55 ----D---- C:\Program Files\AGEIA Technologies
2009-11-08 19:52:39 ----D---- C:\Program Files\Common Files\BioWare
2009-11-06 03:14:42 ----A---- C:\WINDOWS\system32\xfcodec.dll
2009-11-05 18:00:34 ----D---- C:\Program Files\Active Data Recovery Services
2009-11-05 17:45:53 ----D---- C:\Program Files\Phoenix Technologies

======List of files/folders modified in the last 1 months======

2009-11-24 20:11:30 ----D---- C:\WINDOWS\Prefetch
2009-11-24 20:11:19 ----D---- C:\WINDOWS\Temp
2009-11-24 20:11:15 ----RD---- C:\Program Files
2009-11-24 20:10:56 ----D---- C:\WINDOWS\Internet Logs
2009-11-24 20:04:49 ----D---- C:\Documents and Settings\Administrator\Application Data\uTorrent
2009-11-24 19:37:47 ----D---- C:\Program Files\Mozilla Firefox
2009-11-24 19:08:18 ----A---- C:\WINDOWS\system32\PnkBstrB.exe
2009-11-24 14:28:29 ----D---- C:\WINDOWS\system32\CatRoot2
2009-11-23 23:03:03 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-11-23 19:53:31 ----SD---- C:\WINDOWS\Tasks
2009-11-23 19:39:30 ----D---- C:\Documents and Settings\Administrator\Application Data\Xfire
2009-11-23 18:43:50 ----D---- C:\WINDOWS\system32
2009-11-23 17:58:32 ----D---- C:\WINDOWS\system32\drivers
2009-11-23 17:52:06 ----SHD---- C:\WINDOWS\Installer
2009-11-23 17:50:48 ----D---- C:\Program Files\Common Files
2009-11-23 17:47:29 ----D---- C:\WINDOWS
2009-11-23 17:44:03 ----D---- C:\WINDOWS\system32\oodag
2009-11-23 17:41:57 ----D---- C:\Program Files\FlashGet
2009-11-23 17:33:03 ----SD---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2009-11-23 16:41:06 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2009-11-23 15:10:27 ----HD---- C:\WINDOWS\inf
2009-11-23 15:09:39 ----D---- C:\Documents and Settings\Administrator\Application Data\Apple Computer
2009-11-23 15:03:10 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-11-23 15:02:16 ----D---- C:\Documents and Settings\All Users\Application Data\Apple Computer
2009-11-23 15:01:49 ----D---- C:\Program Files\QuickTime
2009-11-23 14:59:57 ----D---- C:\WINDOWS\WinSxS
2009-11-19 19:26:24 ----D---- C:\Program Files\Xfire
2009-11-19 19:26:04 ----D---- C:\Documents and Settings\Administrator\Application Data\Skype
2009-11-19 19:11:51 ----D---- C:\Documents and Settings\Administrator\Application Data\skypePM
2009-11-17 21:34:12 ----D---- C:\Program Files\Garena
2009-11-17 11:42:31 ----D---- C:\WINDOWS\system32\ZoneLabs
2009-11-15 20:48:27 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-11-15 20:48:17 ----D---- C:\WINDOWS\system32\CatRoot
2009-11-15 20:35:38 ----HD---- C:\Program Files\InstallShield Installation Information
2009-11-15 20:34:58 ----RSD---- C:\WINDOWS\assembly
2009-11-15 20:34:19 ----A---- C:\WINDOWS\WININIT.INI
2009-11-14 20:02:54 ----D---- C:\WINDOWS\system32\config
2009-11-12 14:50:07 ----A---- C:\WINDOWS\win.ini
2009-11-12 14:45:55 ----HD---- C:\WINDOWS\$hf_mig$
2009-11-11 17:35:30 ----D---- C:\Program Files\Scorpions WinCheater
2009-11-08 20:07:14 ----D---- C:\WINDOWS\system32\AGEIA
2009-11-05 18:36:21 ----A---- C:\WINDOWS\system32\MRT.exe
2009-11-05 14:34:00 ----A---- C:\WINDOWS\imsins.BAK
2009-11-05 14:33:54 ----D---- C:\WINDOWS\ie7updates
2009-10-27 14:41:40 ----D---- C:\WINDOWS\Help
2009-10-26 14:56:52 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AsIO;AsIO; C:\WINDOWS\system32\drivers\AsIO.sys [2007-12-17 12400]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 36352]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 KLIF;KLIF; C:\WINDOWS\System32\DRIVERS\klif.sys [2009-02-18 186128]
R1 nod32drv;nod32drv; C:\WINDOWS\system32\drivers\nod32drv.sys [2008-10-25 15424]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
R1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2006-07-24 5632]
R1 StyleXPHelper;StyleXPHelper; \??\C:\Program Files\TGTSoft\StyleXP\StyleXPHelper.exe []
R1 VD_FileDisk;VD_FileDisk; C:\WINDOWS\system32\drivers\VD_FileDisk.sys [2006-01-13 15872]
R1 vsdatant;vsdatant; C:\WINDOWS\System32\vsdatant.sys [2009-09-23 482696]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-08-23 12032]
R2 adfs;adfs; C:\WINDOWS\system32\drivers\adfs.sys [2008-08-14 74720]
R2 AMON;AMON; C:\WINDOWS\system32\drivers\amon.sys [2008-10-25 512096]
R2 CdaC15BA;CdaC15BA; \??\C:\WINDOWS\system32\drivers\CDAC15BA.SYS []
R2 rspndr;Link-Layer Topology Discovery Responder; C:\WINDOWS\system32\DRIVERS\rspndr.sys [2007-07-22 62336]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2009-09-23 4481024]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2008-11-15 25280]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2007-07-22 138752]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-05-20 4800000]
R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller; C:\WINDOWS\system32\DRIVERS\l1e51x86.sys [2008-06-25 36864]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
R3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2009-08-28 40448]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 whfltr2k;Sweex Nitro gaming laser Mouse Lower Filter Driver; C:\WINDOWS\system32\DRIVERS\MI570.sys [2007-01-25 6784]
S3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 cglptnt;cglptnt; \??\C:\Program Files\TC UP\cglptnt.sys []
S3 GarenaPEngine;GarenaPEngine; \??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\VHTE8E.tmp []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2009-02-09 17664]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2009-02-09 22016]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent; C:\WINDOWS\system32\drivers\nmwcdnsu.sys [2009-03-19 136704]
S3 nmwcdnsuc;Nokia USB Flashing Generic; C:\WINDOWS\system32\drivers\nmwcdnsuc.sys [2009-03-19 8320]
S3 npkcrypt;npkcrypt; \??\D:\Hry\LineageII\system\npkcrypt.sys []
S3 npkcusb;npkcusb; \??\D:\Hry\LineageII\system\npkcusb.sys []
S3 PCASp50;PCASp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\PCASp50.sys []
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 sscdbus;SAMSUNG USB Composite Device driver (WDM); C:\WINDOWS\system32\DRIVERS\sscdbus.sys [2008-02-22 87936]
S3 sscdmdfl;SAMSUNG Mobile Modem Filter; C:\WINDOWS\system32\DRIVERS\sscdmdfl.sys [2008-02-22 14976]
S3 sscdmdm;SAMSUNG Mobile Modem Drivers; C:\WINDOWS\system32\DRIVERS\sscdmdm.sys [2008-02-22 114304]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2009-02-09 7808]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2009-02-09 7808]
S3 vmfilter323;323 filter service, Normal; C:\WINDOWS\system32\drivers\vmfilter323.sys [2007-09-21 420480]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2007-07-22 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]
S3 ZSMC326;Vimicro USB2.0 PC Camera(VC0323); C:\WINDOWS\System32\Drivers\usbvm323.sys [2008-02-18 260608]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service; C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [2008-10-27 759072]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2009-09-23 602112]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 C-DillaCdaC11BA;C-DillaCdaC11BA; C:\WINDOWS\system32\drivers\CDAC11BA.EXE [2009-01-22 54784]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-02-02 152984]
R2 KMWDSERVICE;Keyboard And Mouse Communication Service; C:\Program Files\Mouse Driver\KMWDSrv.exe [2007-09-07 204800]
R2 NOD32krn;NOD32 Kernel Service; C:\Program Files\Eset\nod32krn.exe [2008-10-25 552064]
R2 O&O Defrag;O&O Defrag; C:\WINDOWS\system32\oodag.exe [2007-05-11 1050120]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2009-05-04 75064]
R2 PnkBstrB;PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [2009-11-24 215104]
R2 PSI_SVC_2;Protexis Licensing V2; C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2007-07-24 185632]
R2 StarWindService;StarWind iSCSI Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe [2005-04-02 217600]
R2 StyleXPService;StyleXPService; C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe [2006-05-24 372736]
R2 vsmon;TrueVector Internet Monitor; C:\WINDOWS\system32\ZoneLabs\vsmon.exe [2009-09-23 2383728]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 ZeppelinService;plasservice; C:\Program Files\Common Files\ParetoLogic\PLAS\plasservice.exe [2009-02-18 587216]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-11-12 545568]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2009-09-25 593920]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4; C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2008-08-15 284016]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater; D:\Hry\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-07-26 25832]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-01-23 655624]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2009-06-02 637952]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------


_________________
CPU: Intel Core 2 Duo E7200, CPU COOLER: Thermaltake BlueOrb II, MB:Asus P5Q PRO, RAM: [OCZ DDR2 PC2-6400 ATI CrossFire 1024MB Passive Cooling] x 3, GPU: Ati Radeon HD 4850 HIS, HDD: Samsung Spinpoint F1 512GB, DVD: Toshiba CD/DVD SH-S202J, PSU: Thermaltake Toughpower QFan 500W, Case: NZXT Alpha, 2nd Case Fan: 120mm AKASA AK-191SM Blue
Offline

Skúsený užívateľ
Skúsený užívateľ
Obrázok užívateľa

Registrovaný: 15.08.09
Prihlásený: 05.02.10
Príspevky: 355
Témy: 0 | 0
NapísalOffline : 25.11.2009 20:40 | Win32/Delf.NFB worm

Coze to tam mas za bordel? :)

1) Stiahni SecurityCheck. Spust ho a postupuj podla instrukcii. Nakoniec vyhodi log, ktory skopiruj sem.



2) Stiahni USBFix. Ukonci vsetky spustene veci a spust program. Vyber jazyk - v pripade anglictiny stlac E -> Enter. Dostanes do dalsieho menu. V nom stlac 2 -> Enter. Zacne sa scan, nezasahuj donho. Mozny je restart PC. Vytvoreny log najdes na "C:\UsbFix.txt", vloz ho sem.


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 25.12.07
Prihlásený: 13.05.15
Príspevky: 62
Témy: 20 | 20
Napísal autor témyOffline : 29.11.2009 18:41 | Win32/Delf.NFB worm

Ked mam pravdu povedat vobec netusim..:D, takze tu je ten log z Security Checku:
Results of screen317's Security Check version 0.99.1
Windows XP Service Pack 3
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Disabled!
NOD32 antivirus system
ParetoLogic Anti-Virus PLUS
ZoneAlarm Pro
Antivirus up to date!
``````````````````````````````
Anti-malware/Other Utilities Check:

SUPERAntiSpyware Professional
Advanced WindowsCare Professional
HijackThis 2.0.2
Java(TM) 6 Update 11
Out of date Java installed!
Adobe Flash Player 10
Adobe Reader 9
``````````````````````````````
Process Check:
objlist.exe by Laurent

Eset nod32krn.exe
Eset nod32kui.exe
Zone Labs ZoneAlarm zlclient.exe
``````````````````````````````
DNS Vulnerability Check:

GREAT! (Not vulnerable to DNS cache poisoning)

`````````End of Log```````````
S tym USBFixom mam problem vzdy sa mi zasekne na 80% a nechce ist dalej.. netusim co s tym je...


//edit takze nakoniec to nejako preslo tu je log:


############################## | UsbFix V6.058 |

User : Administrator (Administrators) # DEJWOO
Update on 26/11/2009 by Chiquitine29, C_XX & Chimay8
Start at: 22:49:10 | 29. 11. 2009
Website : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com

Intel Pentium III Xeon processor
Microsoft Windows XP Professional (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 7.0.5730.11
Windows Firewall Status : Disabled
AV : ESET NOD32 antivirus system 2.70 2.70 [ Enabled | Updated ]
FW : ZoneAlarm Pro Firewall[ (!) Disabled ]9.0.114.000

A:\ -> 3 1/2 Inch Floppy Drive
C:\ -> Local Fixed Disk # 24,41 Go (588,16 Mo free) # NTFS
D:\ -> Local Fixed Disk # 441,34 Go (32,74 Go free) # NTFS
E:\ -> CD-ROM Disc
F:\ -> CD-ROM Disc # 7,72 Go (0 Mo free) [DragonAge] # CDFS
G:\ -> Removable Disk
H:\ -> Removable Disk
I:\ -> Removable Disk
J:\ -> Removable Disk

############################## | Active processes |

C:\WINDOWS\System32\smss.exe 876
C:\WINDOWS\system32\csrss.exe 948
C:\WINDOWS\system32\winlogon.exe 980
C:\WINDOWS\system32\services.exe 1024
C:\WINDOWS\system32\lsass.exe 1036
C:\WINDOWS\system32\Ati2evxx.exe 1216
C:\WINDOWS\system32\svchost.exe 1236
C:\WINDOWS\system32\svchost.exe 1304
C:\WINDOWS\System32\svchost.exe 1676
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe 1704
C:\WINDOWS\system32\svchost.exe 1724
C:\WINDOWS\system32\ZoneLabs\vsmon.exe 2012
C:\WINDOWS\system32\Ati2evxx.exe 480
C:\WINDOWS\system32\spoolsv.exe 1588
C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe 1444
C:\WINDOWS\system32\WgaTray.exe 1796
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 1804
C:\WINDOWS\Explorer.EXE 1896
C:\Program Files\Bonjour\mDNSResponder.exe 1928
C:\WINDOWS\system32\drivers\CDAC11BA.EXE 272
C:\Program Files\Java\jre6\bin\jqs.exe 744
C:\Program Files\Mouse Driver\KMWDSrv.exe 1852
C:\Program Files\Eset\nod32krn.exe 340
C:\WINDOWS\system32\oodag.exe 1864
C:\WINDOWS\system32\PnkBstrA.exe 2268
C:\WINDOWS\system32\PnkBstrB.exe 2292
C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe 2344
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe 2396
C:\WINDOWS\RTHDCPL.EXE 3024
C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe 3032
C:\Program Files\Common Files\ParetoLogic\PLAS\plasservice.exe 3108
C:\Program Files\Eset\nod32kui.exe 3448
D:\Adobe Master CS4\Acrobat 9.0\Acrobat\Acrotray.exe 3892
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe 1872
C:\WINDOWS\system32\ctfmon.exe 904
C:\WINDOWS\service.exe 932
C:\Program Files\Sweex\MI570\Software_X86\wh_exec.exe 2144
C:\WINDOWS\system32\svchost.exe 2676
C:\WINDOWS\System32\alg.exe 3924
C:\WINDOWS\System32\svchost.exe 3008
C:\WINDOWS\system32\wbem\wmiprvse.exe 1932
C:\Program Files\Mozilla Firefox\firefox.exe 3220
C:\WINDOWS\system32\svchost.exe 3968
C:\Program Files\iTunes\iTunes.exe 2580
C:\Program Files\iPod\bin\iPodService.exe 3188
C:\WINDOWS\system32\rundll32.exe 3520

################## | Files # Infected Folders |

C:\WINDOWS\service.exe
C:\Notepad.exe
F:\autorun.inf

################## | Registry # Infected Keys |

[HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "Windows Services"
[HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoClose"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoClose"
[HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoResolveSearch"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoResolveSearch"

################## | Registry # Mountpoints2 |

HKCU\..\..\Explorer\MountPoints2\{0ce955ba-a350-11dd-bb7c-002215641b6c}
Shell\AutoRun\command =F:\autorun.exe -auto

################## | Cracks / Keygens / Serials |

"D:\1\keygen.exe"
17. 11. 2009 15:33 |Size 430080 |Crc32 3f4918b4 |Md5 a525eb7d242f3345a1046025a3c8ba9b

"D:\1\The Hangover (2009) DVDSCR-MAXSPEED\Active_File_Recovery_7.3_Build_103\Active File Recovery 7.3 Build 103\KEYGEN\KeyGen.exe"
08. 09. 2007 03:50 |Size 77824 |Crc32 4a757d98 |Md5 842342caa73c8314f6315c78ae00707e

"D:\Hry\Fifa Manager 09\Crack\Manager09.exe"
29. 10. 2008 23:54 |Size 47453440 |Crc32 b9d1e83d |Md5 a2559c50b2b32f6da1ebec89a2651c0f

"D:\Hry\Fifa Manager 09\Crack\rld-fim9.exe"
29. 10. 2008 11:45 |Size 8192 |Crc32 1fddeee5 |Md5 f608d85aef5ef8bd6e01b153ee59a891

"D:\ZALOHA REINSTALACIA\Store\Applications\Adobe_Master_Collection_CS4\Crack\7z460.exe"
20. 10. 2008 12:47 |Size 923547 |Crc32 96973cea |Md5 f1b6a4043da41b65b7500cacef5494f8

"D:\ZALOHA REINSTALACIA\Store\Applications\Adobe_Master_Collection_CS4\Crack\adobe-master-cs4-keygen.exe"
20. 10. 2008 12:43 |Size 94208 |Crc32 86ac7237 |Md5 4a0924ec5a96895ef65666a0cc97b48c

"D:\ZALOHA REINSTALACIA\Store\Applications\AdvancedWindowsCare\Keygen.exe"
19. 12. 2006 01:16 |Size 59392 |Crc32 6bae6f0b |Md5 8de9e8c876ec72b9fcfe311d316928cb

"D:\ZALOHA REINSTALACIA\Store\Applications\Alcohol.120.v1.9.5.3105\crack\Alcohol.exe"
02. 02. 2002 00:02 |Size 1311744 |Crc32 4ae4ca9c |Md5 5deb692b15c01cc94f149cadd6f0be7b

"D:\ZALOHA REINSTALACIA\Store\Applications\Alcohol.120.v1.9.5.3105\crack\AxCmd.exe"
02. 02. 2002 00:02 |Size 204288 |Crc32 fc7450ad |Md5 6ae25e6c467fc4cdf78bac0aac65b518

"D:\ZALOHA REINSTALACIA\Store\Applications\File_Renamer_Deluxe_4.0.3.typhoon\File Renamer Deluxe 4.0.3.typhoon\File Renamer Deluxe 4.0.3 Keygen from ORiON\Keygen.exe"
16. 03. 2008 17:59 |Size 130560 |Crc32 9d6f1c41 |Md5 27085a08c75ab43379d8671ff05c4263

"D:\ZALOHA REINSTALACIA\Store\Applications\Internet.Download.Manager 5.11\cracked\IDMan.exe"
11. 10. 2007 16:10 |Size 925104 |Crc32 33e785fe |Md5 6e85cbf35ad02aa2e2eda8b5d3ce7975

"D:\ZALOHA REINSTALACIA\Store\Applications\Nero 8 Lite\KeyGen.exe"
16. 09. 2007 20:25 |Size 126976 |Crc32 cc6bcd4a |Md5 795ba9f2ade95e31925cf7fb698f4f68

"D:\ZALOHA REINSTALACIA\Store\Applications\O_O_Defrag_10\O_O_Defrag_10_Keygen.exe"
08. 09. 2007 01:29 |Size 58368 |Crc32 f8473b4e |Md5 b13414516661f58778357bc320c65994

"D:\ZALOHA REINSTALACIA\Store\Applications\SlySoft CloneDVD 2.9.0.1\CloneDVD2Keygen.exe"
04. 09. 2006 23:29 |Size 78485 |Crc32 4a694156 |Md5 2430371996e6714bcd6e9815e730facf

"D:\ZALOHA REINSTALACIA\Store\Applications\Sony.Vegas.With.Plugins\Plugins\SpiceMASTER Pro v. 2.5\Keygen.exe"
05. 04. 2007 15:23 |Size 60928 |Crc32 64a8781b |Md5 531332d080ac9903b9c28ea3549a295a

"D:\ZALOHA REINSTALACIA\Store\Applications\Winamp\winamp_pro_keygen-COOLSCORPIOROHAN_WBB_.exe"
03. 10. 2008 12:54 |Size 47104 |Crc32 d0a597a8 |Md5 344fefcd19a6b3f144ce95c3ad125c2f

"D:\ZALOHA REINSTALACIA\Store\Applications\Zone Alarm Pro 8.0.059.000 Final\SND\ZoneAlarmProKeygen.exe"
17. 09. 2008 20:58 |Size 235153 |Crc32 750c4b47 |Md5 96ab8b65faebf2fc1c6d63bd551367d6

"D:\ZALOHA REINSTALACIA\Store\Games\Crysis Warhead\CryWarKeyCrk-Reloaded\Crack-Reloaded\rld-crwk.exe"
17. 09. 2008 15:59 |Size 8192 |Crc32 0a3674a0 |Md5 d3367d1ed7f6502861378f36d10e7042

"D:\ZALOHA REINSTALACIA\Store\Games\Crysis Warhead\CryWarKeyCrk-Reloaded\Crack-Reloaded\Bin32\Crysis.exe"
22. 09. 2008 12:02 |Size 6414336 |Crc32 8d6f10b5 |Md5 d42165515684a8748f7a86d26d911883

"D:\ZALOHA REINSTALACIA\Store\Games\Halo\Crack\Cracktro.exe"
21. 05. 2006 08:45 |Size 111616 |Crc32 7fa9fe27 |Md5 39380126c0b58016c4cfecc713d77392

"D:\ZALOHA REINSTALACIA\Store\Games\Halo\Crack\halo.exe"
21. 05. 2006 08:33 |Size 2806272 |Crc32 e4a1f8b9 |Md5 a5bac36bbcc33f31eed05585d2769ce6

"D:\ZALOHA REINSTALACIA\Store\Games\Halo\Crack\HaloPC107.exe"
30. 08. 2008 18:26 |Size 4795104 |Crc32 efc3d950 |Md5 d74f74de5257dcf7b630f1bdef03a3a8

"D:\ZALOHA REINSTALACIA\Store\Games\Halo\Crack\HaloCombatEvolvedv1.07NoCDFixedexeEng\Cracktro.exe"
21. 05. 2006 08:45 |Size 111616 |Crc32 7fa9fe27 |Md5 39380126c0b58016c4cfecc713d77392

"D:\ZALOHA REINSTALACIA\Store\Games\Halo\Crack\HaloCombatEvolvedv1.07NoCDFixedexeEng\halo.exe"
21. 05. 2006 08:33 |Size 2806272 |Crc32 e4a1f8b9 |Md5 a5bac36bbcc33f31eed05585d2769ce6

"D:\ZALOHA REINSTALACIA\Store\Games\Medal of Honor Allied Assault\Crack\MOHAA.exe"
03. 02. 2007 18:12 |Size 1540096 |Crc32 60a713ae |Md5 a045fab2e7df3313a7cc2554455dc28f

"D:\ZALOHA REINSTALACIA\Store\Games\Rome Total War\Crack\rometotalwar_cz.exe"
06. 10. 2006 18:37 |Size 1958818 |Crc32 23a5f85a |Md5 93a9593f60b4e482f80e27a530f10a77

"D:\ZALOHA REINSTALACIA\Store\Games\Rome Total War\Crack\ROME.TOTAL.WAR.V1.0.ENG.RELOADED.BACKUPCD\RomeTW.exe"
24. 09. 2004 23:01 |Size 8884224 |Crc32 55ae300d |Md5 3667a1484937fe9ce12bff32b0c749f7

"D:\ZALOHA REINSTALACIA\Store\Games\Splinter Cell Double Agent\SCDA.NODVD_CRACK\SCDA-Offline\System\SplinterCell4.exe"
21. 10. 2006 17:55 |Size 339968 |Crc32 d3350627 |Md5 5224c6fb3fc740c3f52dff6cb97678d2

"D:\ZALOHA REINSTALACIA\Store\Games\Splinter Cell Double Agent\SCDA.NODVD_CRACK\SCDA-Online\System\SCDA_Online.exe"
19. 10. 2006 18:00 |Size 7696384 |Crc32 1524e941 |Md5 88838a5905b81ea35ab605dd385db06b

"D:\ZALOHA REINSTALACIA\Store\Games\Warcraft 3 Frozen Throne\Warcraft3tft\crack\SetupReg.exe"
22. 06. 2003 00:06 |Size 9617 |Crc32 c2a619b9 |Md5 b003cc19b775c2310c102fd4a018f143

"D:\ZALOHA REINSTALACIA\Store\Games\Warcraft 3 Frozen Throne\Warcraft3tft\crack\War3.exe"
21. 06. 2003 16:59 |Size 385024 |Crc32 e55aa355 |Md5 fa216bca88ff9e73267708b48e0796ca

"D:\ZALOHA REINSTALACIA\Store\Games\Warcraft 3 Frozen Throne\Warcraft3tft\crack\WorldEdit.exe"
21. 06. 2003 16:59 |Size 3964928 |Crc32 c99c59c7 |Md5 d93ea74c5f442114f0dcb1c9c9a4c154

"D:\ZALOHA REINSTALACIA\Store\Java Games\Geopod\Geopod\keygen.exe"
19. 01. 2003 10:29 |Size 41472 |Crc32 d5cf8787 |Md5 aa125ebc42afc2862c961350c8054d1b

"D:\ZALOHA REINSTALACIA\Store\Java Games\MGS-Silverball_v1.60\Silverball_v1.60\keygen.exe"
25. 12. 2002 20:49 |Size 40960 |Crc32 4bc0cc3f |Md5 eb65218e8c2508b7779e35c87ffb0ddc

"D:\ZALOHA REINSTALACIA\Store\Java Games\MGSkarting_cracked\karting\keygen.exe"
08. 01. 2003 18:08 |Size 40960 |Crc32 15bfb83b |Md5 1bdbbe7e1fd74e0096fe39e5742cd60f

"D:\ZALOHA REINSTALACIA\Store\Java Games\MVRPool\MVRPool\keygen.exe"
25. 12. 2002 20:48 |Size 40960 |Crc32 b8845cc0 |Md5 04fc025e958d58513b76b3287d4a39b6

"D:\ZALOHA REINSTALACIA\Store\Java Games\Tennis Maniac\keygen.exe"
06. 01. 2003 21:07 |Size 39936 |Crc32 77eb39ba |Md5 5424601e3191aad337482d78bbd9e50a

"D:\ZALOHA REINSTALACIA\zaloha usb 2 gb kluca\Zone Alarm Pro 8.0.059.000 Final\SND\ZoneAlarmProKeygen.exe"
17. 09. 2008 19:58 |Size 235153 |Crc32 750c4b47 |Md5 96ab8b65faebf2fc1c6d63bd551367d6

"D:\ZALOHA REINSTALACIA\Store\Games\Rome Total War\Crack\ROME.TOTAL.WAR.V1.0.ENG.BLACKICE.NOCD.ZIP"
-> Contain : RomeTW.exe 8884224 DFLT-N 55% 4022768 25-09-2004 08:01:42 55ae300d

"D:\ZALOHA REINSTALACIA\Store\Games\Rome Total War\Crack\ROME.TOTAL.WAR.V1.0.ENG.RELOADED.BACKUPCD.ZIP"
-> Contain : RomeTW.exe 8884224 DFLT-N 55% 4022768 24-09-2004 23:01:42 55ae300d

"C:\Documents and Settings\Administrator\Desktop\fonekat.stylexp3-_keygen.rar"
-> contain : FoNeKat.StyleXP3- keygen\FoNeKat.DocToR.StyleXP3- keygen.exe

"D:\photoshop tuty\Swat.4.Crack.MasteR-Moo.Warez-BB.org.rar"
-> contain : Swat.4.Crack.MasteR-Moo.Warez-BB.org\SWAT fix.exe


_________________
CPU: Intel Core 2 Duo E7200, CPU COOLER: Thermaltake BlueOrb II, MB:Asus P5Q PRO, RAM: [OCZ DDR2 PC2-6400 ATI CrossFire 1024MB Passive Cooling] x 3, GPU: Ati Radeon HD 4850 HIS, HDD: Samsung Spinpoint F1 512GB, DVD: Toshiba CD/DVD SH-S202J, PSU: Thermaltake Toughpower QFan 500W, Case: NZXT Alpha, 2nd Case Fan: 120mm AKASA AK-191SM Blue
Offline

Skúsený užívateľ
Skúsený užívateľ
Obrázok užívateľa

Registrovaný: 15.08.09
Prihlásený: 05.02.10
Príspevky: 355
Témy: 0 | 0
NapísalOffline : 30.11.2009 19:40 | Win32/Delf.NFB worm

A jej...pokial si nespravis poriadok v PC, co sa tyka crackov a keygenov, tak nema vyznam pokracovat...kvoli tym veciam to o chvilu mas nas5...


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 25.12.07
Prihlásený: 13.05.15
Príspevky: 62
Témy: 20 | 20
Napísal autor témyOffline : 01.12.2009 19:57 | Win32/Delf.NFB worm

pitimir píše:
A jej...pokial si nespravis poriadok v PC, co sa tyka crackov a keygenov, tak nema vyznam pokracovat...kvoli tym veciam to o chvilu mas nas5...

Okej, staci ked vsetky len vymazem?


_________________
CPU: Intel Core 2 Duo E7200, CPU COOLER: Thermaltake BlueOrb II, MB:Asus P5Q PRO, RAM: [OCZ DDR2 PC2-6400 ATI CrossFire 1024MB Passive Cooling] x 3, GPU: Ati Radeon HD 4850 HIS, HDD: Samsung Spinpoint F1 512GB, DVD: Toshiba CD/DVD SH-S202J, PSU: Thermaltake Toughpower QFan 500W, Case: NZXT Alpha, 2nd Case Fan: 120mm AKASA AK-191SM Blue
Offline

Užívateľ
Užívateľ
Win32/Delf.NFB worm

Registrovaný: 02.12.09
Prihlásený: 10.10.12
Príspevky: 8
Témy: 1 | 1
NapísalOffline : 02.12.2009 14:20 | Win32/Delf.NFB worm

skus MicroWorld Anti virus & Spyware Toolkit Utility
Kód:
http://www.upnito.sk/download.php?dwToken=6e606a08c103064269c664ecdb42fb5b


PS.nezabudni aktualizovat a po vyhadzani bordelu restartovat PC
;)


Offline

Skúsený užívateľ
Skúsený užívateľ
Obrázok užívateľa

Registrovaný: 15.08.09
Prihlásený: 05.02.10
Príspevky: 355
Témy: 0 | 0
NapísalOffline : 02.12.2009 20:25 | Win32/Delf.NFB worm

Stiahni CKScanner na plochu. Spust program dvojklikom na ikonu. Otvori sa okno, v nom klik na "Search For Files". Zacne scan, po jeho skonceni klikni na "Save List To File" -> "OK". Na ploche by sa mal objavit subor s nazvom CKFiles.txt, jeho obsah mi sem skopiruj.


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 16.03.10
Prihlásený: 31.03.10
Príspevky: 16
Témy: 1 | 1
NapísalOffline : 16.03.2010 13:15 | Win32/Delf.NFB worm

Ahoj.

Mám problém stímto programom všimol som si ,že vo vyššie uvedených loggoch sa tam tento program nachádza tak sa chcem opýtat, že či to je vírus. Od kedy som nainštaloval GTA IV pre ktorý je potrebný RockStar Social Game Club (Dalej ako RGSC) Sa začal počítač samovelne reštartovat. Po reštarte mi bud vyhodí "System recovery error" a je tam napísané, že systém prestal pracovat pretože chcel zachránit niake dáta. Ked sa nalogujem normálne do Windowsu (Windows 7) Tak mi to vyhodí : Systém bol reštarovaný kvôli tomu, že prestal pracovat RGSCLauncher.exe. Tak som odinštaloval GTA IV aj všetky jeho" :shit: " Ale robí to aj nadalej. Kamarát ešte spomínal niečo ohlade chybných blockov na diskoch. Kto sa o tento problém bude zaujímat, tak pošlem aj screene "BlueScreen erroru".

Ešte by som dodal pokial budete mat vážny záujem o riešenie tohto problému kontaktuje ma na skype : enjoyed4 alebo na e-mail enjoyed@azet.sk.

Pridávam sem ešte výpis RSIT (Prvý krát v živote som sa dozvedel o tomto programe takže neviem či som to skopíroval správne. )


2010-03-16 21:00:01 ----D---- C:\Windows\Tasks
2010-03-16 21:00:01 ----D---- C:\Windows\system32\wfp
2010-03-16 21:00:01 ----D---- C:\Windows\system32\wbem
2010-03-16 21:00:01 ----D---- C:\Windows\system32\DriverStore
2010-03-16 21:00:01 ----D---- C:\Windows\system32\catroot2
2010-03-16 21:00:01 ----D---- C:\Windows
2010-03-16 20:59:58 ----D---- C:\Windows\registration
2010-03-16 20:59:57 ----D---- C:\Windows\system32\Tasks
2010-03-16 13:23:15 ----D---- C:\Windows\Temp
2010-03-16 13:23:12 ----RD---- C:\Program Files
2010-03-16 13:02:45 ----D---- C:\Windows\System32
2010-03-16 13:02:45 ----D---- C:\Windows\inf
2010-03-16 12:24:30 ----D---- C:\Windows\system32\config
2010-03-15 03:10:42 ----D---- C:\Windows\system32\drivers
2010-03-15 03:10:41 ----D---- C:\Windows\system32\CodeIntegrity
2010-03-15 03:10:41 ----D---- C:\Windows\AppCompat
2010-03-14 21:15:58 ----D---- C:\Windows\system32\catroot
2010-03-14 21:11:41 ----D---- C:\Windows\rescache
2010-03-14 21:10:16 ----SD---- C:\ProgramData\Microsoft
2010-03-10 22:39:09 ----D---- C:\Windows\winsxs
2010-03-10 22:39:06 ----D---- C:\Windows\AppPatch
2010-03-09 14:41:04 ----D---- C:\Windows\system32\NDF
2010-03-03 13:48:56 ----D---- C:\Windows\LiveKernelReports
2010-02-28 10:31:57 ----HD---- C:\ProgramData
2010-02-28 10:29:59 ----RSD---- C:\Windows\assembly
2010-02-25 16:26:24 ----D---- C:\Windows\system
2010-02-24 19:54:39 ----D---- C:\Windows\Microsoft.NET
2010-02-24 17:44:50 ----D---- C:\Windows\ehome
2010-02-24 17:44:40 ----D---- C:\Windows\system32\sk-SK
2010-02-24 17:44:40 ----D---- C:\Windows\system32\en-US
2010-02-22 20:35:30 ----D---- C:\Windows\Logs
2010-02-22 16:20:24 ----D---- C:\Program Files\Common Files
2010-02-20 19:01:02 ----D---- C:\Windows\system32\LogFiles
2010-02-20 11:34:53 ----D---- C:\Program Files\Internet Explorer
2010-02-20 11:31:33 ----D---- C:\Program Files\Common Files\microsoft shared
2010-02-20 11:08:58 ----D---- C:\Windows\system32\Boot
2010-02-20 11:08:58 ----D---- C:\Program Files\Windows Media Player
2010-02-20 10:45:11 ----D---- C:\Program Files\Windows Sidebar
2010-02-20 10:45:10 ----D---- C:\Windows\servicing
2010-02-20 10:45:10 ----D---- C:\Program Files\Windows Photo Viewer
2010-02-20 10:45:10 ----D---- C:\Program Files\Windows Mail
2010-02-20 10:45:10 ----D---- C:\Program Files\Windows Journal
2010-02-20 10:45:10 ----D---- C:\Program Files\Windows Defender
2010-02-20 10:45:10 ----D---- C:\Program Files\DVD Maker
2010-02-20 10:45:10 ----D---- C:\Program Files\Common Files\System
2010-02-20 10:45:09 ----D---- C:\Windows\system32\sysprep
2010-02-20 10:45:09 ----D---- C:\Windows\system32\oobe
2010-02-20 10:45:09 ----D---- C:\Windows\system32\migwiz
2010-02-20 10:45:09 ----D---- C:\Windows\PolicyDefinitions
2010-02-20 10:45:07 ----D---- C:\Windows\system32\WCN
2010-02-20 02:08:01 ----D---- C:\Windows\CSC
2010-02-20 02:06:16 ----D---- C:\Windows\Setup
2010-02-19 23:35:30 ----D---- C:\Windows\debug
2010-02-19 23:33:31 ----D---- C:\Windows\system32\wdi
2010-02-19 19:12:06 ----D---- C:\Windows\system32\restore
2010-02-19 17:38:09 ----SHD---- C:\$Recycle.Bin
2010-02-19 17:37:55 ----RD---- C:\Users
2010-02-19 17:19:21 ----D---- C:\Windows\system32\Recovery

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2010-02-11 23376]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2010-02-11 162512]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2010-02-11 46672]
R1 blbdrive;blbdrive; C:\Windows\system32\DRIVERS\blbdrive.sys [2009-07-14 35328]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 DfsC;@%systemroot%\system32\drivers\dfsc.sys,-101; C:\Windows\System32\Drivers\dfsc.sys [2009-07-14 78336]
R1 discache;@%systemroot%\system32\drivers\discache.sys,-102; C:\Windows\System32\drivers\discache.sys [2009-07-14 32256]
R1 nsiproxy;@%SystemRoot%\system32\drivers\nsiproxy.sys,-2; C:\Windows\system32\drivers\nsiproxy.sys [2009-07-14 16896]
R1 RDPENCDD;@%systemroot%\system32\drivers\RDPENCDD.sys,-101; C:\Windows\system32\drivers\rdpencdd.sys [2009-07-14 6656]
R1 RDPREFMP;@%systemroot%\system32\drivers\RdpRefMp.sys,-101; C:\Windows\system32\drivers\rdprefmp.sys [2009-07-14 7168]
R1 tdx;@%SystemRoot%\system32\tcpipcfg.dll,-50004; C:\Windows\system32\DRIVERS\tdx.sys [2009-07-14 74240]
R1 Wanarpv6;@%systemroot%\system32\rascfg.dll,-32012; C:\Windows\system32\DRIVERS\wanarp.sys [2009-07-14 63488]
R1 WfpLwf;WFP Lightweight Filter; C:\Windows\system32\DRIVERS\wfplwf.sys [2009-07-14 9728]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2010-02-11 19024]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2010-02-11 51792]
R2 lltdio;Link-Layer Topology Discovery Mapper I/O Driver; C:\Windows\system32\DRIVERS\lltdio.sys [2009-07-14 48128]
R2 luafv;@%systemroot%\system32\drivers\luafv.sys,-100; C:\Windows\system32\drivers\luafv.sys [2009-07-14 86528]
R2 PEAUTH;PEAUTH; C:\Windows\system32\drivers\peauth.sys [2009-07-14 586752]
R2 rspndr;Link-Layer Topology Discovery Responder; C:\Windows\system32\DRIVERS\rspndr.sys [2009-07-14 60928]
R2 tcpipreg;TCP/IP Registry Compatibility; C:\Windows\System32\drivers\tcpipreg.sys [2009-07-14 34816]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-08-18 4994560]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
R3 bowser;@%systemroot%\system32\browser.dll,-102; C:\Windows\system32\DRIVERS\bowser.sys [2009-07-14 69632]
R3 cmpci;C-Media PCI Audio Driver (WDM); C:\Windows\system32\drivers\cmaudio.sys [2002-11-18 377358]
R3 CompositeBus;Composite Bus Enumerator Driver; C:\Windows\system32\DRIVERS\CompositeBus.sys [2009-07-14 31232]
R3 DXGKrnl;LDDM Graphics Subsystem; C:\Windows\System32\drivers\dxgkrnl.sys [2009-10-02 728648]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2009-07-14 304128]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\Windows\system32\DRIVERS\HDAudBus.sys [2009-07-14 108544]
R3 HidUsb;Microsoft HID Class Driver; C:\Windows\system32\DRIVERS\hidusb.sys [2009-07-14 24064]
R3 intelppm;Intel Processor Driver; C:\Windows\system32\DRIVERS\intelppm.sys [2009-07-14 53760]
R3 monitor;Microsoft Monitor Class Function Driver Service; C:\Windows\system32\DRIVERS\monitor.sys [2009-07-14 23552]
R3 mouhid;Mouse HID Driver; C:\Windows\system32\DRIVERS\mouhid.sys [2009-07-14 26112]
R3 mpsdrv;@%SystemRoot%\system32\FirewallAPI.dll,-23092; C:\Windows\System32\drivers\mpsdrv.sys [2009-07-14 60416]
R3 mrxsmb10;@%systemroot%\system32\wkssvc.dll,-1004; C:\Windows\system32\DRIVERS\mrxsmb10.sys [2010-01-08 221184]
R3 mrxsmb20;@%systemroot%\system32\wkssvc.dll,-1006; C:\Windows\system32\DRIVERS\mrxsmb20.sys [2009-07-14 95744]
R3 RasAgileVpn;WAN Miniport (IKEv2); C:\Windows\system32\DRIVERS\AgileVpn.sys [2009-07-14 49152]
R3 RasSstp;@%systemroot%\system32\sstpsvc.dll,-202; C:\Windows\system32\DRIVERS\rassstp.sys [2009-07-14 75264]
R3 rdpbus;Remote Desktop Device Redirector Bus Driver; C:\Windows\system32\DRIVERS\rdpbus.sys [2009-07-14 18944]
R3 srv2;@%systemroot%\system32\srvsvc.dll,-104; C:\Windows\System32\DRIVERS\srv2.sys [2009-07-14 306688]
R3 srvnet;srvnet; C:\Windows\System32\DRIVERS\srvnet.sys [2009-12-08 113664]
R3 tunnel;Microsoft Tunnel Miniport Adapter Driver; C:\Windows\system32\DRIVERS\tunnel.sys [2009-07-14 108544]
R3 umbus;UMBus Enumerator Driver; C:\Windows\system32\DRIVERS\umbus.sys [2009-07-14 39936]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\Windows\system32\DRIVERS\usbehci.sys [2009-07-14 41472]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\Windows\system32\DRIVERS\usbhub.sys [2009-07-14 258560]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\Windows\system32\DRIVERS\usbuhci.sys [2009-07-14 24064]
R3 WudfPf;User Mode Driver Frameworks Platform Driver; C:\Windows\system32\drivers\WudfPf.sys [2009-07-14 92672]
S3 1394ohci;1394 OHCI Compliant Host Controller; C:\Windows\system32\DRIVERS\1394ohci.sys [2009-07-14 163328]
S3 a89kdyzp;a89kdyzp; C:\Windows\system32\drivers\a89kdyzp.sys []
S3 AcpiPmi;ACPI Power Meter Driver; C:\Windows\system32\DRIVERS\acpipmi.sys [2009-07-14 9728]
S3 adp94xx;adp94xx; C:\Windows\system32\DRIVERS\adp94xx.sys [2009-07-14 422976]
S3 adpahci;adpahci; C:\Windows\system32\DRIVERS\adpahci.sys [2009-07-14 297552]
S3 adpu320;adpu320; C:\Windows\system32\DRIVERS\adpu320.sys [2009-07-14 146512]
S3 agp440;Intel AGP Bus Filter; C:\Windows\system32\DRIVERS\agp440.sys [2009-07-14 53312]
S3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\Windows\system32\drivers\RTKVAC.SYS [2009-06-18 4172832]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 amdide;amdide; C:\Windows\system32\DRIVERS\amdide.sys [2009-07-14 14912]
S3 AmdK8;AMD K8 Processor Driver; C:\Windows\system32\DRIVERS\amdk8.sys [2009-07-14 55296]
S3 AmdPPM;AMD Processor Driver; C:\Windows\system32\DRIVERS\amdppm.sys [2009-07-14 52736]
S3 amdsata;amdsata; C:\Windows\system32\DRIVERS\amdsata.sys [2009-07-14 79952]
S3 amdsbs;amdsbs; C:\Windows\system32\DRIVERS\amdsbs.sys [2009-07-14 159312]
S3 AppID;@%systemroot%\system32\appidsvc.dll,-102; C:\Windows\system32\drivers\appid.sys [2009-07-14 50176]
S3 arc;arc; C:\Windows\system32\DRIVERS\arc.sys [2009-07-14 76368]
S3 arcsas;arcsas; C:\Windows\system32\DRIVERS\arcsas.sys [2009-07-14 86608]
S3 b06bdrv;Broadcom NetXtreme II VBD; C:\Windows\system32\DRIVERS\bxvbdx.sys [2009-07-13 430080]
S3 BrFiltLo;Brother USB Mass-Storage Lower Filter Driver; C:\Windows\system32\DRIVERS\BrFiltLo.sys [2009-07-13 13568]
S3 BrFiltUp;Brother USB Mass-Storage Upper Filter Driver; C:\Windows\system32\DRIVERS\BrFiltUp.sys [2009-07-13 5248]
S3 Brserid;Brother MFC Serial Port Interface Driver (WDM); C:\Windows\System32\Drivers\Brserid.sys [2009-07-14 272128]
S3 BrSerWdm;Brother WDM Serial driver; C:\Windows\System32\Drivers\BrSerWdm.sys [2009-07-13 62336]
S3 BrUsbMdm;Brother MFC USB Fax Only Modem; C:\Windows\System32\Drivers\BrUsbMdm.sys [2009-07-13 12160]
S3 BrUsbSer;Brother MFC USB Serial WDM Driver; C:\Windows\System32\Drivers\BrUsbSer.sys [2009-07-13 11904]
S3 BTHMODEM;Bluetooth Serial Communications Driver; C:\Windows\system32\DRIVERS\bthmodem.sys [2009-07-14 56320]
S3 circlass;Consumer IR Devices; C:\Windows\system32\DRIVERS\circlass.sys [2009-07-14 37888]
S3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2009-07-14 14080]
S3 Compbatt;Compbatt; C:\Windows\system32\DRIVERS\compbatt.sys [2009-07-14 19024]
S3 DAdderFltr;DeathAdder Mouse; C:\Windows\system32\drivers\dadder.sys [2007-08-02 22784]
S3 ebdrv;Broadcom NetXtreme II 10 GigE VBD; C:\Windows\system32\DRIVERS\evbdx.sys [2009-07-13 3100160]
S3 elxstor;elxstor; C:\Windows\system32\DRIVERS\elxstor.sys [2009-07-14 453712]
S3 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\DRIVERS\errdev.sys [2009-07-14 7168]
S3 exfat;exFAT File System Driver; C:\Windows\system32\drivers\exfat.sys [2009-07-14 142336]
S3 Filetrace;@%SystemRoot%\system32\drivers\filetrace.sys,-10001; C:\Windows\system32\drivers\filetrace.sys [2009-07-14 28160]
S3 FsDepends;@%SystemRoot%\system32\drivers\fsdepends.sys,-10001; C:\Windows\System32\drivers\FsDepends.sys [2009-07-14 46160]
S3 gagp30kx;Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms; C:\Windows\system32\DRIVERS\gagp30kx.sys [2009-07-14 57936]
S3 GarenaPEngine;GarenaPEngine; \??\C:\Users\Uzivatel\AppData\Local\Temp\GQNEF76.tmp [2010-02-25 25616]
S3 hcw85cir;Hauppauge Consumer Infrared Receiver; C:\Windows\system32\drivers\hcw85cir.sys [2009-07-13 26624]
S3 HidBatt;HID UPS Battery Driver; C:\Windows\system32\DRIVERS\HidBatt.sys [2009-07-14 21504]
S3 HidBth;Microsoft Bluetooth HID Miniport; C:\Windows\system32\DRIVERS\hidbth.sys [2009-07-14 91136]
S3 HidIr;Microsoft Infrared HID Driver; C:\Windows\system32\DRIVERS\hidir.sys [2009-07-14 37888]
S3 HpSAMD;HpSAMD; C:\Windows\system32\DRIVERS\HpSAMD.sys [2009-07-14 67152]
S3 iaStorV;iaStorV; C:\Windows\system32\DRIVERS\iaStorV.sys [2009-07-14 332352]
S3 iirsp;iirsp; C:\Windows\system32\DRIVERS\iirsp.sys [2009-07-14 41040]
S3 IPMIDRV;IPMIDRV; C:\Windows\system32\DRIVERS\IPMIDrv.sys [2009-07-14 65536]
S3 isapnp;isapnp; C:\Windows\system32\DRIVERS\isapnp.sys [2009-07-14 46656]
S3 iScsiPrt;iScsiPort Driver; C:\Windows\system32\DRIVERS\msiscsi.sys [2009-07-14 186960]
S3 kbdhid;Keyboard HID Driver; C:\Windows\system32\DRIVERS\kbdhid.sys [2009-07-14 28160]
S3 LSI_FC;LSI_FC; C:\Windows\system32\DRIVERS\lsi_fc.sys [2009-07-14 95824]
S3 LSI_SAS;LSI_SAS; C:\Windows\system32\DRIVERS\lsi_sas.sys [2009-07-14 89168]
S3 LSI_SAS2;LSI_SAS2; C:\Windows\system32\DRIVERS\lsi_sas2.sys [2009-07-14 54864]
S3 LSI_SCSI;LSI_SCSI; C:\Windows\system32\DRIVERS\lsi_scsi.sys [2009-07-14 96848]
S3 megasas;megasas; C:\Windows\system32\DRIVERS\megasas.sys [2009-07-14 30800]
S3 MegaSR;MegaSR; C:\Windows\system32\DRIVERS\MegaSR.sys [2009-07-14 235584]
S3 mpio;mpio; C:\Windows\system32\DRIVERS\mpio.sys [2009-07-14 130624]
S3 msahci;msahci; C:\Windows\system32\DRIVERS\msahci.sys [2009-07-14 27712]
S3 msdsm;msdsm; C:\Windows\system32\DRIVERS\msdsm.sys [2009-07-14 115792]
S3 mshidkmdf;@%SystemRoot%\system32\drivers\mshidkmdf.sys,-100; C:\Windows\System32\drivers\mshidkmdf.sys [2009-07-14 4096]
S3 MsRPC;MsRPC; C:\Windows\system32\drivers\MsRPC.sys [2009-07-14 162896]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2009-07-14 6144]
S3 MTConfig;Microsoft Input Configuration Driver; C:\Windows\system32\DRIVERS\MTConfig.sys [2009-07-14 12288]
S3 NativeWifiP;NativeWiFi Filter; C:\Windows\system32\DRIVERS\nwifi.sys [2009-07-14 267264]
S3 NdisCap;NDIS Capture LightWeight Filter; C:\Windows\system32\DRIVERS\ndiscap.sys [2009-07-14 27136]
S3 nfrd960;nfrd960; C:\Windows\system32\DRIVERS\nfrd960.sys [2009-07-14 44624]
S3 nv_agp;NVIDIA nForce AGP Bus Filter; C:\Windows\system32\DRIVERS\nv_agp.sys [2009-07-14 105024]
S3 nvraid;nvraid; C:\Windows\system32\DRIVERS\nvraid.sys [2009-07-14 117312]
S3 nvstor;nvstor; C:\Windows\system32\DRIVERS\nvstor.sys [2009-07-14 142416]
S3 ohci1394;1394 OHCI Compliant Host Controller (Legacy); C:\Windows\system32\DRIVERS\ohci1394.sys [2009-07-14 62464]
S3 ql2300;ql2300; C:\Windows\system32\DRIVERS\ql2300.sys [2009-07-14 1383488]
S3 ql40xx;ql40xx; C:\Windows\system32\DRIVERS\ql40xx.sys [2009-07-14 106064]
S3 QWAVEdrv;@%SystemRoot%\system32\drivers\qwavedrv.sys,-1; C:\Windows\system32\drivers\qwavedrv.sys [2009-07-14 31744]
S3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIV.sys [2009-09-25 159232]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sbp2port;sbp2port; C:\Windows\system32\DRIVERS\sbp2port.sys [2009-07-14 85568]
S3 scfilter;@%SystemRoot%\System32\drivers\scfilter.sys,-11; C:\Windows\System32\DRIVERS\scfilter.sys [2009-07-14 26624]
S3 sermouse;Serial Mouse Driver; C:\Windows\system32\DRIVERS\sermouse.sys [2009-07-14 19968]
S3 sffdisk;SFF Storage Class Driver; C:\Windows\system32\DRIVERS\sffdisk.sys [2009-07-14 11264]
S3 sffp_mmc;SFF Storage Protocol Driver for MMC; C:\Windows\system32\DRIVERS\sffp_mmc.sys [2009-07-14 12288]
S3 sffp_sd;SFF Storage Protocol Driver for SDBus; C:\Windows\system32\DRIVERS\sffp_sd.sys [2009-07-14 12800]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 SiSRaid2;SiSRaid2; C:\Windows\system32\DRIVERS\SiSRaid2.sys [2009-07-14 40016]
S3 SiSRaid4;SiSRaid4; C:\Windows\system32\DRIVERS\sisraid4.sys [2009-07-14 77888]
S3 Smb;@%SystemRoot%\system32\tcpipcfg.dll,-50005; C:\Windows\system32\DRIVERS\smb.sys [2009-07-14 71168]
S3 stexstor;stexstor; C:\Windows\system32\DRIVERS\stexstor.sys [2009-07-14 21072]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 TCPIP6;Microsoft IPv6 Protocol Driver; C:\Windows\system32\DRIVERS\tcpip.sys [2010-02-25 1285712]
S3 tssecsrv;@%SystemRoot%\System32\DRIVERS\tssecsrv.sys,-101; C:\Windows\System32\DRIVERS\tssecsrv.sys [2009-07-14 30208]
S3 uagp35;Microsoft AGPv3.5 Filter; C:\Windows\system32\DRIVERS\uagp35.sys [2009-07-14 55888]
S3 uliagpkx;Uli AGP Bus Filter; C:\Windows\system32\DRIVERS\uliagpkx.sys [2009-07-14 57424]
S3 UmPass;Microsoft UMPass Driver; C:\Windows\system32\DRIVERS\umpass.sys [2009-07-14 8192]
S3 usbaudio;USB Audio Driver (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-07-14 80640]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\Windows\system32\DRIVERS\usbccgp.sys [2009-07-14 75264]
S3 usbcir;eHome Infrared Receiver (USBCIR); C:\Windows\system32\DRIVERS\usbcir.sys [2009-07-14 86016]
S3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\Windows\system32\DRIVERS\usbohci.sys [2009-07-14 20480]
S3 usbprint;Microsoft USB PRINTER Class; C:\Windows\system32\DRIVERS\usbprint.sys [2009-07-14 19968]
S3 USBSTOR;USB Mass Storage Driver; C:\Windows\system32\DRIVERS\USBSTOR.SYS [2009-07-14 74752]
S3 vga;vga; C:\Windows\system32\DRIVERS\vgapnp.sys [2009-07-14 26112]
S3 vhdmp;vhdmp; C:\Windows\system32\DRIVERS\vhdmp.sys [2009-07-14 159824]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
S3 vsmraid;vsmraid; C:\Windows\system32\DRIVERS\vsmraid.sys [2009-07-14 141904]
S3 vwifibus;@%SystemRoot%\System32\drivers\vwifibus.sys,-257; C:\Windows\System32\drivers\vwifibus.sys [2009-07-14 19968]
S3 WacomPen;Wacom Serial Pen HID Driver; C:\Windows\system32\DRIVERS\wacompen.sys [2009-07-14 21632]
S3 Wd;Wd; C:\Windows\system32\DRIVERS\wd.sys [2009-07-14 19024]
S3 WIMMount;WIMMount; C:\Windows\system32\drivers\wimmount.sys [2009-07-14 19008]
S3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2009-07-14 11264]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2009-07-14 132224]
S4 crcdisk;Crcdisk Filter Driver; C:\Windows\system32\DRIVERS\crcdisk.sys [2009-07-14 22096]
S4 ws2ifsl;@%systemroot%\System32\drivers\ws2ifsl.sys,-1000; C:\Windows\system32\drivers\ws2ifsl.sys [2009-07-14 16384]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-08-18 176128]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672]
R2 AudioEndpointBuilder;@%SystemRoot%\system32\audiosrv.dll,-204; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 BFE;@%SystemRoot%\system32\bfe.dll,-1001; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 DPS;@%systemroot%\system32\dps.dll,-500; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 gpsvc;@gpapi.dll,-112; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 iphlpsvc;@%SystemRoot%\system32\iphlpsvc.dll,-500; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 MpsSvc;@%SystemRoot%\system32\FirewallAPI.dll,-23090; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 NlaSvc;@%SystemRoot%\System32\nlasvc.dll,-1; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 nsi;@%SystemRoot%\system32\nsisvc.dll,-200; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 Power;@%SystemRoot%\system32\umpo.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 ProfSvc;@%systemroot%\system32\profsvc.dll,-300; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 RpcEptMapper;@%windir%\system32\RpcEpMap.dll,-1001; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 SysMain;@%SystemRoot%\system32\sysmain.dll,-1000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 UxSms;@%SystemRoot%\system32\dwm.exe,-2000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 WinDefend;@%ProgramFiles%\Windows Defender\MsMpRes.dll,-103; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 WSearch;@%systemroot%\system32\SearchIndexer.exe,-103; C:\Windows\system32\SearchIndexer.exe [2009-07-14 428032]
R2 wudfsvc;@%SystemRoot%\system32\wudfsvc.dll,-1000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 AeLookupSvc;@%SystemRoot%\system32\aelupsvc.dll,-1; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2010-02-15 545576]
R3 netprofm;@%SystemRoot%\system32\netprofm.dll,-202; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 PcaSvc;@%SystemRoot%\system32\pcasvc.dll,-1; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 WdiServiceHost;@%systemroot%\system32\wdi.dll,-502; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 WdiSystemHost;@%systemroot%\system32\wdi.dll,-500; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 WinHttpAutoProxySvc;@%SystemRoot%\system32\winhttp.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-02-11 40384]
S2 MMCSS;@%systemroot%\system32\mmcss.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S2 sppsvc;@%SystemRoot%\system32\sppsvc.exe,-101; C:\Windows\system32\sppsvc.exe [2009-07-14 3179520]
S3 AppIDSvc;@%systemroot%\system32\appidsvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 Appinfo;@%systemroot%\system32\appinfo.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-02-11 40384]
S3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-02-11 40384]
S3 AxInstSV;@%SystemRoot%\system32\AxInstSV.dll,-103; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 BDESVC;@%SystemRoot%\system32\bdesvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 bthserv;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 CertPropSvc;@%SystemRoot%\System32\certprop.dll,-11; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 clr_optimization_v2.0.50727_32;Microsoft .NET Framework NGEN v2.0.50727_X86; C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2009-06-10 66384]
S3 defragsvc;@%SystemRoot%\system32\defragsvc.dll,-101; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 EFS;@%SystemRoot%\system32\efssvc.dll,-100; C:\Windows\System32\lsass.exe [2009-07-14 22528]
S3 ehRecvr;@%SystemRoot%\ehome\ehrecvr.exe,-101; C:\Windows\ehome\ehRecvr.exe [2009-07-14 557056]
S3 ehSched;@%SystemRoot%\ehome\ehsched.exe,-101; C:\Windows\ehome\ehsched.exe [2009-07-14 94720]
S3 Fax;@%systemroot%\system32\fxsresm.dll,-118; C:\Windows\system32\fxssvc.exe [2009-07-14 522752]
S3 fdPHost;@%systemroot%\system32\fdPHost.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 FDResPub;@%systemroot%\system32\fdrespub.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2009-06-10 42856]
S3 HomeGroupListener;@%SystemRoot%\System32\ListSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 HomeGroupProvider;@%SystemRoot%\System32\provsvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 idsvc;@%systemroot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8193; C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2009-06-10 878416]
S3 IKEEXT;@%SystemRoot%\system32\ikeext.dll,-501; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 IPBusEnum;@%systemroot%\system32\IPBusEnum.dll,-102; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 KeyIso;@keyiso.dll,-100; C:\Windows\system32\lsass.exe [2009-07-14 22528]
S3 KtmRm;@comres.dll,-2946; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 lltdsvc;@%SystemRoot%\system32\lltdres.dll,-1; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 MSiSCSI;@%SystemRoot%\system32\iscsidsc.dll,-5000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 p2pimsvc;@%SystemRoot%\system32\pnrpsvc.dll,-8004; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 p2psvc;@%SystemRoot%\system32\p2psvc.dll,-8006; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 pla;@%systemroot%\system32\pla.dll,-500; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 PNRPAutoReg;@%SystemRoot%\system32\pnrpauto.dll,-8002; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 PNRPsvc;@%SystemRoot%\system32\pnrpsvc.dll,-8000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 QWAVE;@%SystemRoot%\system32\qwave.dll,-1; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 SCPolicySvc;@%SystemRoot%\System32\certprop.dll,-13; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 SDRSVC;@%SystemRoot%\system32\sdrsvc.dll,-107; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 SensrSvc;@%SystemRoot%\System32\sensrsvc.dll,-1000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 SessionEnv;@%SystemRoot%\System32\SessEnv.dll,-1026; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 SNMPTRAP;@%SystemRoot%\system32\snmptrap.exe,-3; C:\Windows\System32\snmptrap.exe [2009-07-14 12800]
S3 sppuinotify;@%SystemRoot%\system32\sppuinotify.dll,-103; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 SstpSvc;@%SystemRoot%\system32\sstpsvc.dll,-200; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 TabletInputService;@%SystemRoot%\system32\TabSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 TBS;@%SystemRoot%\system32\tbssvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 THREADORDER;@%systemroot%\system32\mmcss.dll,-102; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 TrustedInstaller;@%SystemRoot%\servicing\TrustedInstaller.exe,-100; C:\Windows\servicing\TrustedInstaller.exe [2009-07-14 204800]
S3 UI0Detect;@%SystemRoot%\system32\ui0detect.exe,-101; C:\Windows\system32\UI0Detect.exe [2009-07-14 35840]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 VaultSvc;@%SystemRoot%\system32\vaultsvc.dll,-1003; C:\Windows\system32\lsass.exe [2009-07-14 22528]
S3 vds;@%SystemRoot%\system32\vds.exe,-100; C:\Windows\System32\vds.exe [2009-07-14 452608]
S3 wbengine;@%systemroot%\system32\wbengine.exe,-104; C:\Windows\system32\wbengine.exe [2009-07-14 1202688]
S3 WbioSrvc;@%systemroot%\system32\wbiosrvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 wcncsvc;@%SystemRoot%\system32\wcncsvc.dll,-3; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WcsPlugInService;@%SystemRoot%\system32\WcsPlugInService.dll,-200; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 Wecsvc;@%SystemRoot%\system32\wecsvc.dll,-200; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 wercplsupport;@%SystemRoot%\System32\wercplsupport.dll,-101; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WerSvc;@%SystemRoot%\System32\wersvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WinRM;@%Systemroot%\system32\wsmsvc.dll,-101; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 Wlansvc;@%SystemRoot%\System32\wlansvc.dll,-257; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 WMPNetworkSvc;@%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101; C:\Program Files\Windows Media Player\wmpnetwk.exe [2009-07-14 1121280]
S3 WPCSvc;@%SystemRoot%\system32\wpcsvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 WPDBusEnum;@%SystemRoot%\system32\wpdbusenum.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 WwanSvc;@%SystemRoot%\System32\wwansvc.dll,-257; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S4 Mcx2Svc;@%SystemRoot%\ehome\ehres.dll,-15501; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S4 NetTcpPortSharing;@%systemroot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8201; C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2009-06-10 128848]

Ďakujem za Vašu ochotu a pomoc pri riešení mojích problémov.

S pozdravom Execute.


 [ Príspevkov: 15 ] 


Win32/Delf.NFB worm



Podobné témy

 Témy  Odpovede  Zobrazenia  Posledný príspevok 
V tomto fóre nie sú ďalšie neprečítané témy.

Win32 /Delf.NFB - neviem to odstranit..

v Antivíry a antispywary

6

701

24.12.2008 19:43

dr.etker

V tomto fóre nie sú ďalšie neprečítané témy.

Email-Worm.Win32.Warezov.lk

v Antivíry a antispywary

1

793

23.02.2007 14:53

xyz

Táto téma je zamknutá, nemôžete posielať nové príspevky alebo odpovedať na staršie.

P: dac/amp Audio-gd NFB-11.32 alebo NFB-12

v Predám

1

160

04.05.2016 15:05

Andre

V tomto fóre nie sú ďalšie neprečítané témy.

WORM,TROJAN...ALEBO CO TO JE?

v Antivíry a antispywary

11

765

14.05.2007 20:44

tairikuokami

V tomto fóre nie sú ďalšie neprečítané témy.

IM worm chatuje s užívateľmi - naozaj zaujímavé :)

v Novinky

4

1078

08.12.2005 18:26

ScorpionSX

V tomto fóre nie sú ďalšie neprečítané témy.

Trojan.Win32/ agent Trojan.Win32/Wundo

[ Choď na stránku:Choď na stránku: 1, 2 ]

v Antivíry a antispywary

47

930

28.12.2012 21:55

personal compuper

V tomto fóre nie sú ďalšie neprečítané témy.

error win32

v Antivíry a antispywary

4

339

15.02.2009 10:47

Kallaf

V tomto fóre nie sú ďalšie neprečítané témy.

win32/adware

v Bezpečnosť a firewally

13

1536

02.03.2008 16:04

yaJohny

V tomto fóre nie sú ďalšie neprečítané témy.

Win32/Conficker

v Operačné systémy Microsoft

1

244

24.01.2009 15:30

tlacitko Enter

V tomto fóre nie sú ďalšie neprečítané témy.

chyba win32

v Operačné systémy Microsoft

4

686

24.09.2008 20:09

FERDA23

V tomto fóre nie sú ďalšie neprečítané témy.

Problem Win32

v Operačné systémy Microsoft

8

304

04.06.2009 9:24

walther

V tomto fóre nie sú ďalšie neprečítané témy.

Backdoor.Win32.IRCBot

v Antivíry a antispywary

3

198

23.06.2012 19:17

personal compuper

V tomto fóre nie sú ďalšie neprečítané témy.

Win32/Nuwar červ

v Antivíry a antispywary

6

740

22.11.2008 23:58

uUsErR

V tomto fóre nie sú ďalšie neprečítané témy.

win32-hidrag.A

v Antivíry a antispywary

5

496

08.07.2007 10:13

Rbot

V tomto fóre nie sú ďalšie neprečítané témy.

Win32/Finloski.AA

v Antivíry a antispywary

3

261

29.07.2012 10:59

personal compuper

V tomto fóre nie sú ďalšie neprečítané témy.

WIN32/Alman.NAD

v Antivíry a antispywary

22

1665

31.05.2008 0:25

yaJohny



© 2005 - 2017 PCforum, edited by JanoF