-
HiJackThis/Log :Оптимизация/Анализ/Ревю
Вече е добре.Благодаря за помоща.
-
HiJackThis/Log :Оптимизация/Анализ/Ревю
Eто го лога ComboFix 09-05-26.05 - User 05.2009 г. 21:39.3 - NTFSx86 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1251.359.1033.18.3068.1918 [GMT 3:00] Running from: c:\users\User\Desktop\ComboFix.exe Command switches used :: c:\users\User\Desktop\CFScript.txt SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} FILE :: "c:\windows\TEMP\TMP0000003ACB352524BF27BC51.tmp" . ((((((((((((((((((((((((( Files Created from 2009-04-27 to 2009-05-27 ))))))))))))))))))))))))))))))) . 2009-05-27 18:41 . 2009-05-27 18:44 -------- d-----w c:\users\User\AppData\Local\temp 2009-05-27 18:41 . 2009-05-27 18:41 -------- d-----w c:\users\rosen\AppData\Local\temp 2009-05-27 18:41 . 2009-05-27 18:41 -------- d-----w c:\users\Rosen.User-PC\AppData\Local\temp 2009-05-27 18:41 . 2009-05-27 18:41 -------- d-----w c:\users\Guest\AppData\Local\temp 2009-05-27 18:41 . 2009-05-27 18:41 -------- d-----w c:\users\all\AppData\Local\temp 2009-05-27 17:35 . 2009-05-06 18:06 4784464 ----a-w c:\programdata\Microsoft\Windows Defender\Definition Updates\{9FDD36AC-9325-4431-9F05-E9EE3D4F9A3C}\mpengine.dll 2009-05-27 15:22 . 2009-05-27 15:22 -------- d-----w c:\users\User\AppData\Roaming\Malwarebytes 2009-05-27 15:22 . 2009-05-26 10:20 40160 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys 2009-05-27 15:22 . 2009-05-27 17:03 -------- d-----w c:\program files\Malwarebytes' Anti-Malware 2009-05-27 15:22 . 2009-05-27 15:22 -------- d-----w c:\programdata\Malwarebytes 2009-05-27 15:22 . 2009-05-26 10:19 19096 ----a-w c:\windows\system32\drivers\mbam.sys 2009-05-27 14:35 . 2009-05-27 14:35 680 ----a-w c:\users\User\AppData\Local\d3d9caps.dat 2009-05-27 13:07 . 2009-05-27 13:13 -------- d-----w c:\programdata\Norton 2009-05-27 13:04 . 2009-05-27 13:05 -------- d-----w c:\programdata\NortonInstaller 2009-05-27 12:46 . 2009-05-27 12:46 -------- d-----w c:\program files\Trend Micro 2009-05-26 05:17 . 2009-05-26 05:17 -------- d-----w c:\users\Rosen.User-PC\AppData\Roaming\Ubisoft 2009-05-26 05:11 . 2009-05-26 05:16 -------- d-----w c:\users\Rosen.User-PC\AppData\Local\Microsoft Games 2009-05-25 16:15 . 2009-05-25 16:15 7592 ----a-w c:\users\Rosen.User-PC\AppData\Local\d3d9caps.dat 2009-05-25 15:57 . 2009-05-25 15:57 -------- d-----w c:\users\Rosen.User-PC\Bluetooth Software 2009-05-25 15:04 . 2009-05-25 15:57 -------- d-----w c:\users\Rosen.User-PC\AppData\Roaming\DAEMON Tools 2009-05-25 13:17 . 2009-05-28 01:14 -------- d-----w c:\users\Rosen.User-PC\AppData\Roaming\Winamp 2009-05-25 10:56 . 2009-05-25 10:56 -------- d-----w c:\users\Rosen.User-PC\AppData\Roaming\skypePM 2009-05-25 10:55 . 2009-05-25 11:25 -------- d-----w c:\users\Rosen.User-PC\AppData\Roaming\Skype 2009-05-25 10:53 . 2009-05-25 10:53 410984 ----a-w c:\windows\system32\deploytk.dll 2009-05-25 10:46 . 2009-05-25 10:46 103472 ----a-w c:\users\Rosen.User-PC\AppData\Local\GDIPFONTCACHEV1.DAT 2009-05-25 10:46 . 2009-05-25 10:46 -------- d-----w c:\users\Rosen.User-PC\AppData\Roaming\Nero 2009-05-25 10:46 . 2009-05-28 01:14 -------- d-----w c:\users\Rosen.User-PC\AppData\Local\QuickPlay 2009-05-25 10:29 . 2009-05-25 10:29 -------- d-----w c:\users\Guest\AppData\Roaming\Skype 2009-05-25 10:23 . 2009-05-25 10:23 -------- d-----w c:\users\Guest\AppData\Roaming\Nero 2009-05-25 09:19 . 2009-05-27 17:04 -------- d-sh--r C:\RESTORE 2009-05-24 16:10 . 2009-05-24 16:10 -------- d-----w c:\programdata\WindowsSearch 2009-05-24 14:48 . 2009-05-24 14:48 -------- d-----w c:\users\rosen\AppData\Roaming\Nero 2009-05-24 13:46 . 2009-05-24 13:46 -------- d-----w c:\users\User\AppData\Local\Ahead 2009-05-24 08:23 . 2009-05-24 08:23 -------- d-----w c:\users\Public\CyberLink 2009-05-21 08:41 . 2009-05-21 08:41 -------- d-----w c:\users\all\AppData\Local\Rockstar Games 2009-05-18 18:06 . 2009-05-18 18:08 -------- d-----w c:\users\User\AppData\Local\Rockstar Games 2009-05-18 18:02 . 2009-05-18 18:02 -------- d--h--r c:\users\User\AppData\Roaming\SecuROM 2009-05-18 18:01 . 2009-05-18 18:45 -------- d-----w c:\program files\Microsoft Games for Windows - LIVE 2009-05-18 18:01 . 2009-05-18 18:01 -------- d-----w c:\windows\system32\xlive 2009-05-18 17:12 . 2009-05-18 18:02 107888 ----a-w c:\windows\system32\CmdLineExt.dll 2009-05-18 13:18 . 2009-05-18 13:18 -------- d-----w c:\users\User\AppData\Roaming\Activision 2009-05-18 09:19 . 2009-05-23 08:54 -------- d-----w c:\users\all\AppData\Roaming\skypePM 2009-05-17 12:43 . 2009-05-27 18:23 -------- d-----w c:\users\User\AppData\Roaming\Skype 2009-05-17 12:43 . 2009-05-17 12:43 -------- d-----w c:\program files\Skype 2009-05-17 12:43 . 2009-05-17 12:43 -------- d-----w c:\program files\Common Files\Skype 2009-05-17 12:16 . 2009-05-17 12:16 -------- d-----w c:\users\all\AppData\Local\VirtualStore 2009-05-15 19:13 . 2009-05-16 09:26 -------- d-----w c:\program files\SpeedFan 2009-05-15 17:20 . 2009-05-15 17:20 -------- d-----w c:\program files\EasyBits For Kids 2009-05-15 17:00 . 2009-05-15 17:00 -------- d-----w c:\users\User\AppData\Roaming\Leadertech 2009-05-15 16:44 . 2009-05-15 16:44 -------- d-----w c:\program files\EA Games 2009-05-15 15:42 . 2009-05-15 15:42 -------- d-----w c:\program files\AGEIA Technologies 2009-05-15 15:42 . 2009-05-15 15:42 -------- d-----w c:\windows\system32\AGEIA 2009-05-15 15:42 . 2009-05-15 15:42 -------- d-----w c:\program files\Common Files\Wise Installation Wizard 2009-05-15 14:43 . 2009-05-18 17:07 -------- d-----w c:\program files\Activision 2009-05-15 14:42 . 2009-05-15 14:42 -------- d-sh--w c:\windows\ftpcache 2009-05-15 14:40 . 2009-05-15 14:41 -------- d-----w c:\users\User\AppData\Local\ACD Systems 2009-05-15 14:40 . 2009-05-15 14:40 -------- d-----w c:\users\User\AppData\Roaming\ACD Systems 2009-05-15 14:40 . 2009-05-15 14:40 -------- d-----w c:\programdata\ACD Systems 2009-05-15 14:40 . 2009-05-15 14:40 -------- d-----w c:\program files\Common Files\ACD Systems 2009-05-15 14:40 . 2009-05-15 14:40 -------- d-----w c:\program files\ACD Systems 2009-05-15 14:39 . 2009-05-15 14:39 10368 ----a-w c:\windows\system32\drivers\pfc.sys 2009-05-15 12:01 . 2009-05-20 00:40 -------- d-----w c:\users\all\AppData\Local\Microsoft Games 2009-05-15 11:53 . 2009-05-15 11:53 -------- d-----w c:\users\all\Bluetooth Software 2009-05-15 11:51 . 2009-05-23 09:52 -------- d-----w c:\users\all\AppData\Roaming\Skype 2009-05-14 03:56 . 2009-05-14 03:56 -------- d-----w c:\users\User\AppData\Roaming\InstallShield 2009-05-12 11:00 . 2009-05-12 11:00 -------- d-----w c:\users\Guest\Bluetooth Software 2009-05-11 17:45 . 2009-05-11 17:45 -------- d-----w c:\users\User\AppData\Local\Hewlett-Packard 2009-05-11 13:01 . 2009-05-24 18:36 -------- d-----w c:\users\User\AppData\Local\Google 2009-05-11 12:17 . 2009-05-11 15:47 -------- d-----w c:\users\rosen\AppData\Local\Google 2009-05-11 12:13 . 2009-05-12 17:48 -------- d-----w c:\program files\Google 2009-05-11 11:52 . 2009-05-11 11:52 -------- d-----w c:\program files\Common Files\Adobe AIR 2009-05-11 11:51 . 2009-05-11 11:51 -------- d-----w c:\program files\Common Files\Adobe 2009-05-11 07:39 . 2009-05-11 07:39 -------- d-----w c:\program files\Valve 2009-05-10 17:46 . 2009-05-10 17:46 -------- d-----w c:\program files\Microsoft.NET 2009-05-10 17:44 . 2009-05-10 17:44 -------- d-----w c:\program files\Microsoft Visual Studio 8 2009-05-10 17:43 . 2009-05-10 17:43 -------- d-----w c:\users\User\AppData\Local\Microsoft Help 2009-05-10 17:42 . 2009-05-10 17:42 -------- d--h--r C:\MSOCache 2009-05-10 17:02 . 2009-05-10 17:02 -------- d-----w C:\NVIDIA 2009-05-10 14:37 . 2009-05-24 18:33 -------- d-----w c:\users\User\AppData\Local\Nero 2009-05-10 14:15 . 2009-05-10 14:47 -------- d-----w c:\program files\Left 4 Dead 2009-05-10 14:15 . 2009-05-10 14:15 -------- d-----w c:\windows\Left 4 Dead 2009-05-10 13:14 . 2008-01-21 02:24 638976 ----a-w c:\windows\system32\win_utilman.exe 2009-05-10 13:14 . 2009-05-10 13:14 56 ---ha-w c:\windows\system32\ezsidmv.dat 2009-05-10 13:14 . 2009-05-10 13:14 91136 ----a-w c:\windows\system32\ezUninst.exe 2009-05-10 13:14 . 2009-05-10 13:14 49152 ----a-w c:\windows\system32\ezUPBHook.dll 2009-05-10 13:14 . 2009-05-10 13:14 268288 ----a-w c:\windows\system32\ezSetup.exe 2009-05-10 13:14 . 2009-05-10 13:14 15872 ----a-w c:\windows\system32\ezMAPIHelper.exe 2009-05-10 13:14 . 2009-05-10 13:14 111104 ----a-w c:\windows\system32\ezShellStart.exe 2009-05-10 10:38 . 1999-11-29 17:33 7440 ----a-w c:\windows\system32\kbdlk41j.Dll 2009-05-10 10:38 . 1999-12-07 06:00 6416 ----a-w c:\windows\system32\kbdbp.Dll 2009-05-10 10:38 . 1999-11-18 02:04 7440 ----a-w c:\windows\system32\Kbddll.dll 2009-05-10 10:38 . 1999-11-11 10:47 6928 ----a-w c:\windows\system32\kbdhebx.Dll 2009-05-10 10:38 . 2002-04-22 21:17 45056 ----a-w c:\windows\system32\newdll.dll 2009-05-10 10:38 . 2009-05-10 10:38 -------- d-----w c:\program files\Datecs 2009-05-10 00:05 . 2008-06-20 01:14 97800 ----a-w c:\windows\system32\infocardapi.dll 2009-05-10 00:05 . 2008-06-20 01:14 43544 ----a-w c:\windows\system32\PresentationHostProxy.dll 2009-05-10 00:05 . 2008-06-20 01:14 105016 ----a-w c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll 2009-05-10 00:05 . 2008-06-20 01:14 11264 ----a-w c:\windows\system32\icardres.dll 2009-05-10 00:05 . 2008-06-20 01:14 622080 ----a-w c:\windows\system32\icardagt.exe 2009-05-10 00:05 . 2008-06-20 01:14 781344 ----a-w c:\windows\system32\PresentationNative_v0300.dll 2009-05-10 00:05 . 2008-06-20 01:14 326160 ----a-w c:\windows\system32\PresentationHost.exe 2009-05-10 00:02 . 2008-07-27 18:03 96760 ----a-w c:\windows\system32\dfshim.dll 2009-05-10 00:02 . 2008-07-27 18:03 41984 ----a-w c:\windows\system32\netfxperf.dll 2009-05-10 00:02 . 2008-07-27 18:03 282112 ----a-w c:\windows\system32\mscoree.dll 2009-05-10 00:01 . 2008-07-27 18:03 158720 ----a-w c:\windows\system32\mscorier.dll 2009-05-10 00:01 . 2008-07-27 18:03 83968 ----a-w c:\windows\system32\mscories.dll 2009-05-10 00:01 . 2009-05-10 00:01 -------- d-----w c:\program files\MSXML 4.0 2009-05-09 21:01 . 1999-03-23 07:12 299520 ----a-w c:\windows\uninst.exe 2009-05-09 20:41 . 2009-05-09 20:41 -------- d-----w c:\program files\Lavalys 2009-05-09 20:00 . 2009-05-09 20:00 -------- d-----w c:\users\User\AppData\Roaming\Ubisoft 2009-05-09 20:00 . 2009-05-09 20:00 -------- d-----w c:\programdata\Ubisoft 2009-05-09 19:42 . 2009-05-14 03:56 -------- d-----w c:\program files\Ubisoft 2009-05-09 19:21 . 2009-05-24 07:44 -------- d-----w c:\program files\The KMPlayer 2009-05-09 19:13 . 2009-05-09 19:13 -------- d-----w c:\windows\Driver Cache 2009-05-09 19:13 . 2009-05-09 19:13 -------- d-----w c:\program files\AVerMedia 2009-05-09 18:57 . 2009-05-09 18:57 -------- d-----w c:\users\User\AppData\Roaming\NeroDCTemplates 2009-05-09 18:54 . 2009-05-24 13:44 -------- d-----w c:\users\User\AppData\Roaming\Nero 2009-05-09 18:19 . 2009-05-24 13:41 -------- d-----w c:\program files\Nero 2009-05-09 18:18 . 2009-05-24 13:43 -------- d-----w c:\program files\Common Files\Nero 2009-05-09 18:18 . 2009-05-24 13:41 -------- d-----w c:\programdata\Nero 2009-05-09 18:18 . 2009-05-09 18:18 -------- d-----w c:\program files\Common Files\LightScribe 2009-05-09 17:53 . 2009-05-11 09:43 -------- d-----w c:\programdata\LightScribe 2009-05-09 16:39 . 2009-05-09 16:51 -------- d-----w c:\users\rosen\AppData\Roaming\DAEMON Tools 2009-05-09 16:02 . 2009-05-09 16:02 -------- d-----w c:\users\rosen\AppData\Roaming\GRETECH 2009-05-09 16:02 . 2009-05-09 16:02 -------- d-----w c:\program files\GRETECH . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-05-28 01:14 . 2009-05-09 14:58 -------- d-----w c:\users\User\AppData\Roaming\DAEMON Tools 2009-05-27 18:41 . 2008-09-27 08:11 12 ----a-w c:\windows\bthservsdp.dat 2009-05-27 17:31 . 2008-09-27 08:44 113440 ----a-w c:\programdata\nvModes.dat 2009-05-27 13:08 . 2008-07-02 17:07 -------- d-----w c:\program files\Common Files\Symantec Shared 2009-05-27 13:07 . 2008-07-02 17:07 -------- d-----w c:\programdata\Symantec 2009-05-25 10:53 . 2008-07-02 18:31 -------- d-----w c:\program files\Java 2009-05-18 17:37 . 2008-07-02 17:05 -------- d--h--w c:\program files\InstallShield Installation Information 2009-05-16 14:32 . 2006-11-02 11:18 -------- d-----w c:\program files\Windows Mail 2009-05-15 11:49 . 2009-05-15 11:49 103472 ----a-w c:\users\all\AppData\Local\GDIPFONTCACHEV1.DAT 2009-05-11 17:22 . 2009-05-11 17:22 103472 ----a-w c:\users\Guest\AppData\Local\GDIPFONTCACHEV1.DAT 2009-05-10 17:55 . 2009-05-09 11:20 103472 ----a-w c:\users\rosen\AppData\Local\GDIPFONTCACHEV1.DAT 2009-05-10 17:53 . 2008-07-02 18:09 -------- d-----w c:\programdata\Microsoft Help 2009-05-10 17:47 . 2006-11-02 12:37 -------- d-----w c:\program files\MSBuild 2009-05-10 17:37 . 2008-09-27 08:50 -------- d-----w c:\programdata\NVIDIA 2009-05-10 13:14 . 2008-07-02 18:21 8292 ----a-w c:\windows\system32\ezdigsgn.dat 2009-05-10 00:30 . 2006-11-02 10:25 665600 ----a-w c:\windows\inf\drvindex.dat 2009-05-09 11:20 . 2009-05-09 11:20 -------- d-----w c:\users\rosen\AppData\Roaming\Symantec 2009-05-09 10:38 . 2009-05-09 10:38 0 ---ha-w c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf 2009-05-09 10:03 . 2008-09-27 08:49 -------- d-----w c:\programdata\CyberLink 2009-05-09 09:42 . 2008-07-02 17:42 -------- d-----w c:\programdata\WildTangent 2009-05-09 09:40 . 2009-05-09 09:40 32 ----a-w c:\programdata\ezsid.dat 2009-05-09 05:46 . 2009-05-09 05:46 0 --sha-r c:\windows\system32\drivers\103C_HP_cNB_Pavilion dv5 Notebook PC_Y5335KV_0U_QCNF84514NW_E465478-024_4A_I3603_SQuanta_V02.20_F.0C_T080918_WV3-1_L409_M3069_J320_7Intel_8676_92.00_#090509_N10EC8168;80864237_(FW699EA#ABB)_XMO BILE_CN10_Z_2F.0C.MRK 2009-04-21 21:20 . 2009-04-21 21:20 14311680 ----a-w c:\windows\system32\xlive.dll 2009-04-21 21:20 . 2009-04-21 21:20 13642496 ----a-w c:\windows\system32\xlivefnt.dll 2009-04-17 06:48 . 2009-04-17 06:48 114528 ----a-w c:\windows\system32\drivers\jmcr.sys 2009-03-08 11:34 . 2009-05-09 14:58 914944 ----a-w c:\windows\system32\wininet.dll 2009-03-08 11:34 . 2009-05-09 14:58 43008 ----a-w c:\windows\system32\licmgr10.dll 2009-03-08 11:33 . 2009-05-09 14:58 18944 ----a-w c:\windows\system32\corpol.dll 2009-03-08 11:33 . 2009-05-09 14:58 109056 ----a-w c:\windows\system32\iesysprep.dll 2009-03-08 11:33 . 2009-05-09 14:58 109568 ----a-w c:\windows\system32\PDMSetup.exe 2009-03-08 11:33 . 2009-05-09 14:58 132608 ----a-w c:\windows\system32\ieUnatt.exe 2009-03-08 11:33 . 2009-05-09 14:58 107520 ----a-w c:\windows\system32\RegisterIEPKEYs.exe 2009-03-08 11:33 . 2009-05-09 14:58 107008 ----a-w c:\windows\system32\SetIEInstalledDate.exe 2009-03-08 11:33 . 2009-05-09 14:58 103936 ----a-w c:\windows\system32\SetDepNx.exe 2009-03-08 11:33 . 2009-05-09 14:58 420352 ----a-w c:\windows\system32\vbscript.dll 2009-03-08 11:32 . 2009-05-09 14:58 72704 ----a-w c:\windows\system32\admparse.dll 2009-03-08 11:32 . 2009-05-09 14:58 71680 ----a-w c:\windows\system32\iesetup.dll 2009-03-08 11:32 . 2009-05-09 14:58 66560 ----a-w c:\windows\system32\wextract.exe 2009-03-08 11:32 . 2009-05-09 14:58 169472 ----a-w c:\windows\system32\iexpress.exe 2009-03-08 11:31 . 2009-05-09 14:58 34816 ----a-w c:\windows\system32\imgutil.dll 2009-03-08 11:31 . 2009-05-09 14:58 48128 ----a-w c:\windows\system32\mshtmler.dll 2009-03-08 11:31 . 2009-05-09 14:58 45568 ----a-w c:\windows\system32\mshta.exe 2009-03-08 11:22 . 2009-05-09 14:58 156160 ----a-w c:\windows\system32\msls31.dll 2009-03-06 06:06 . 2009-03-06 06:06 140800 ----a-w c:\windows\system32\drivers\Rtlh86.sys 2009-03-05 03:54 . 2009-03-05 03:54 73728 ----a-w c:\windows\system32\RtNicProp32.dll 2008-07-02 15:47 . 2008-07-02 15:47 8192 --sha-w c:\windows\Users\Default\NTUSER.DAT . ((((((((((((((((((((((((((((( SnapShot@2009-05-27_17.47.25 ))))))))))))))))))))))))))))))))))))))))) . + 2008-01-21 01:58 . 2009-05-27 18:20 41698 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin + 2008-09-27 08:11 . 2009-05-27 18:42 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2008-09-27 08:11 . 2009-05-27 17:30 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2008-09-27 08:11 . 2009-05-27 18:42 98304 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2008-09-27 08:11 . 2009-05-27 17:30 98304 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2008-09-27 08:11 . 2009-05-27 18:42 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2008-09-27 08:11 . 2009-05-27 17:30 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2009-05-10 05:40 . 2009-05-25 12:53 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-05-10 05:40 . 2009-05-27 18:07 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-05-10 05:40 . 2009-05-27 18:07 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-05-10 05:40 . 2009-05-25 12:53 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-05-10 05:40 . 2009-05-25 12:53 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-05-10 05:40 . 2009-05-27 18:07 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-05-09 05:47 . 2009-05-27 18:20 5456 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2514056171-1166224141-2149493090-1000_UserData.bin + 2009-05-27 18:42 . 2009-05-27 18:42 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2009-05-27 15:20 . 2009-05-27 17:30 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2009-05-27 18:42 . 2009-05-27 18:42 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2009-05-27 15:20 . 2009-05-27 17:30 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2006-11-02 13:05 . 2009-05-27 18:20 102914 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin + 2009-05-12 17:47 . 2009-05-27 18:41 1043152 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-07 21633320] "RGSC"="f:\rockstar games\Rockstar Games Social Club\RGSCLauncher.exe" [2009-05-18 306088] "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-27 1045800] "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-16 178712] "UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504] "QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-04-24 468264] "QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-03-14 202032] "OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-11-02 554288] "HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-04-15 70912] "HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840] "hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-11-20 488752] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-25 148888] "SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-06-27 442467] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-30 13605408] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-01-30 92704] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-1-17 727592] FlexType 2K.lnk - c:\program files\Datecs\FlexType 2K\FType2K.exe [2009-5-10 95232] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) "HideFastUserSwitching"= 0 (0x0) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="" [HKEY_LOCAL_MACHINE\software\microsoft\security center] "UacDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{D1A19267-720D-45C7-BA29-21A2A647EF5B}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play "{B9AC649E-0A78-4DCC-9DAF-B51D71EE0A38}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program "{4802C87A-702A-4431-876A-5D11193D65B1}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector "{B12F35B4-F422-4B67-BB9F-3CA110ADF1A6}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone) "{0FC4DF7C-9FEC-442B-9468-5CA6B3C5DC9D}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In) "{5D406AE4-F07F-4153-9036-38CFF4942937}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In) "{9C70456F-ECFC-4FCE-9E00-06EDA40B50AE}"= UDP:17804:BitComet 17804 TCP "{A819E5D7-E9B1-41FF-ADB2-EB52591E6058}"= TCP:17804:BitComet 17804 UDP "TCP Query User{52BF79F6-7F65-49C8-9D5B-D3CEBA256D75}c:\\program files\\skype\\phone\\skype.exe"= UDP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath "UDP Query User{4D84D741-171B-4776-A5C5-9B7768D7E5ED}c:\\program files\\skype\\phone\\skype.exe"= TCP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath "{5BF83EF4-0DCE-47A4-9564-DB1105D16549}"= UDP:f:\prince of persia\Prince of Persia.exe:Prince of Persia Dx "{6E701431-BE56-48BD-813B-365AC08536F3}"= TCP:f:\prince of persia\Prince of Persia.exe:Prince of Persia Dx "{41366894-C565-4431-A345-D3B14D33F172}"= UDP:f:\prince of persia\PrinceOfPersia_Launcher.exe:Prince of Persia Update "{306C325E-6A01-4C49-BF66-6946136434F6}"= TCP:f:\prince of persia\PrinceOfPersia_Launcher.exe:Prince of Persia Update "TCP Query User{18B1FEFC-7956-4E81-960F-B3968E4EC522}f:\\counter-strike\\hl.exe"= UDP:f:\counter-strike\hl.exe:Half-Life Launcher "UDP Query User{09F01335-6BF9-4CB5-BE3D-8F0F84B159F6}f:\\counter-strike\\hl.exe"= TCP:f:\counter-strike\hl.exe:Half-Life Launcher "{EDCEBA08-3A90-4B0E-A84B-0E026327559B}"= UDP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9 "{8033D948-9891-4C4E-B6EE-12419A7B5E3C}"= TCP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9 "{4D75C391-1523-4D78-A4CF-026C8CEE3A8B}"= UDP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10 "{1FD4DDBD-A9C3-4920-94B5-C8FE1EFE6A33}"= TCP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10 "{17DF0F66-7ADC-44A1-AC1C-204CDAB14A10}"= UDP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update "{4F210143-C5CD-4B46-920F-0824F3A31496}"= TCP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update "TCP Query User{0F5523D7-6BA8-419B-9A34-760FB9EAB3ED}c:\\program files\\left 4 dead\\left4dead.exe"= UDP:c:\program files\left 4 dead\left4dead.exe:left4dead "UDP Query User{5FF2D015-FD7C-47C3-8385-F005AB5C71D4}c:\\program files\\left 4 dead\\left4dead.exe"= TCP:c:\program files\left 4 dead\left4dead.exe:left4dead "{B658BB4C-29EC-4A5D-9E3F-ECC98E5304E5}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook "{0FACA8F0-6BB6-4460-943C-7F643A60CE3F}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove "{D296CA6A-DB3F-4F18-914D-B554FBA9AD62}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove "{4CD86C2B-C1DE-4652-AF60-7FD94581DB94}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{38A34AFC-5B7D-4B1B-905C-F0CFB609272F}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "TCP Query User{87156E94-9DEF-4FB5-866A-D19A08B04DCE}f:\\half life\\hl2\\hl2.exe"= UDP:f:\half life\hl2\hl2.exe:hl2 "UDP Query User{07D91094-95B3-4CCE-A1F8-BCCF642AFC8C}f:\\half life\\hl2\\hl2.exe"= TCP:f:\half life\hl2\hl2.exe:hl2 "{BE0BD50B-800C-4199-AE63-74F501E0494E}"= UDP:c:\program files\Lavalys\EVEREST Ultimate Edition\everest.exe:EVEREST Ultimate Edition "{F9A2C16C-737E-409A-982D-CD293CF8837F}"= TCP:c:\program files\Lavalys\EVEREST Ultimate Edition\everest.exe:EVEREST Ultimate Edition "TCP Query User{C8352A4C-A496-4FCC-89D7-9F5178B0A72A}c:\\program files\\bitcomet\\bitcomet.exe"= UDP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client "UDP Query User{1160E15F-F4FE-477E-B6B3-2B26F97A6841}c:\\program files\\bitcomet\\bitcomet.exe"= TCP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client "TCP Query User{9F2A8CF4-8203-4F01-8B79-E5278EB8AE14}c:\\windows\\explorer.exe"= UDP:c:\windows\explorer.exe:Windows Explorer "UDP Query User{9BAD5322-E370-448A-A36F-6EEAF637E101}c:\\windows\\explorer.exe"= TCP:c:\windows\explorer.exe:Windows Explorer "{9946B689-4843-494C-A639-0F5202DAF3D0}"= UDP:17804:BitComet 17804 TCP "{8E93DEDD-8DAE-4B26-84CE-F4BF73EAE93F}"= TCP:17804:BitComet 17804 UDP "{94C90566-97C0-4D31-A77F-0574EA643D6E}"= UDP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9 "{5275B171-726F-425F-8052-8F41EE77F9F8}"= TCP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9 "{9E89D40F-7D6A-4FEC-A8DB-D13A5C6E2525}"= UDP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10 "{A82881B4-3C35-45BC-8017-D4E8FC9AD9B0}"= TCP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10 "{958B2B9E-523D-4D43-99BC-5D0578F62E23}"= UDP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update "{C3A949CF-031F-4F56-8756-4589F6BDE6A4}"= TCP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update "TCP Query User{FD86E422-D391-4D53-80C3-F0EC34BE7825}f:\\half life\\hl2\\hl2.exe"= UDP:f:\half life\hl2\hl2.exe:hl2 "UDP Query User{9AE0D4EA-DDEE-4886-8253-14A2BBF25F86}f:\\half life\\hl2\\hl2.exe"= TCP:f:\half life\hl2\hl2.exe:hl2 "{05092115-0D67-4CC8-BFBB-E04D74704BF3}"= UDP:c:\program files\Activision\X-Men Origins - Wolverine\Binaries\Wolverine.exe:X-Men Origins - Wolverine "{BC261CFE-CF5F-4236-A990-7B8139DFBA2B}"= TCP:c:\program files\Activision\X-Men Origins - Wolverine\Binaries\Wolverine.exe:X-Men Origins - Wolverine "{3F142349-23D7-45BA-9533-8167D9C46CB4}"= c:\program files\Skype\Phone\Skype.exe:Skype "{5CD145D9-D607-45CA-AC40-5EAB00A3A0A9}"= UDP:f:\rockstar games\Rockstar Games Social Club\RGSCLauncher.exe:Rockstar Games Social Club "{920D8BF9-403A-4277-9818-684822C6A675}"= TCP:f:\rockstar games\Rockstar Games Social Club\RGSCLauncher.exe:Rockstar Games Social Club "{74632C98-0192-4C53-A345-4C9FFAE08664}"= UDP:f:\rockstar games\Grand Theft Auto IV\LaunchGTAIV.exe:Grand Theft Auto IV "{171565A4-B6F6-496D-B33B-01216524ECD7}"= TCP:f:\rockstar games\Grand Theft Auto IV\LaunchGTAIV.exe:Grand Theft Auto IV "TCP Query User{612159B0-E64D-4111-90C4-8E5E8078091B}f:\\rockstar games\\grand theft auto iv\\gtaiv.exe"= UDP:f:\rockstar games\grand theft auto iv\gtaiv.exe:Grand Theft Auto IV "UDP Query User{9FA4F7DC-3DFF-4535-8526-ABE944199B6B}f:\\rockstar games\\grand theft auto iv\\gtaiv.exe"= TCP:f:\rockstar games\grand theft auto iv\gtaiv.exe:Grand Theft Auto IV "TCP Query User{30DC198A-9802-46EA-AF57-2F90A4C8A8AA}c:\\program files\\common files\\nero\\nero web\\setupx.exe"= UDP:c:\program files\common files\nero\nero web\setupx.exe:Nero Installer "UDP Query User{7CEE600E-2A67-4E29-BA2A-71EDB8261D5A}c:\\program files\\common files\\nero\\nero web\\setupx.exe"= TCP:c:\program files\common files\nero\nero web\setupx.exe:Nero Installer "TCP Query User{2FA6753E-7D33-4558-84E0-F0A1897A653B}c:\\users\\user\\appdata\\local\\temp\\onlineupdate8\\setupxu.exe"= UDP:c:\users\user\appdata\local\temp\onlineupdate8\setupxu.exe:setupxu.exe "UDP Query User{0C8A11A1-DD20-494C-8CA6-0EE97FEB0B9E}c:\\users\\user\\appdata\\local\\temp\\onlineupdate8\\setupxu.exe"= TCP:c:\users\user\appdata\local\temp\onlineupdate8\setupxu.exe:setupxu.exe R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\AEstSrv.exe [27.9.2008 і. 11:18 73728] R2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe -k netsvcs [21.1.2008 і. 05:23 21504] R2 hpsrv;HP Service;c:\windows\System32\hpservice.exe [19.3.2008 і. 02:24 19456] R2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\SMINST\BLService.exe [2.7.2008 і. 21:26 341328] R3 enecir;ENE CIR Receiver;c:\windows\System32\drivers\enecir.sys [24.1.2008 і. 16:23 52736] R3 JMCR;JMCR;c:\windows\System32\drivers\jmcr.sys [17.4.2009 і. 09:48 114528] R3 NETw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\System32\drivers\NETw5v32.sys [17.11.2008 і. 15:40 3668480] R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\System32\drivers\nvhda32v.sys [23.5.2008 і. 06:29 43552] S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2.7.2008 і. 20:29 193840] S3 EverestDriver;Lavalys EVEREST Kernel Driver;f:\downloads\Everest Ultimate Engineer Edition 5.00.1692 (multi)\Everest Ultimate Engineer Edition 5.00.1692 (Multilanguage)\kerneld.wnt [16.5.2009 і. 12:14 26224] --- Other Services/Drivers In Memory --- *Deregistered* - sptd [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs REG_MULTI_SZ BthServ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs ezSharedSvc [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] "c:\program files\Common Files\LightScribe\LSRunOnce.exe" . Contents of the 'Scheduled Tasks' folder 2009-05-27 c:\windows\Tasks\User_Feed_Synchronization-{A1953874-5815-44FF-9509-2C81765588EE}.job - c:\windows\system32\msfeedssync.exe [2009-05-09 11:31] 2009-05-27 c:\windows\Tasks\User_Feed_Synchronization-{DD313412-8BC6-47F1-9C0C-AFFFC1E7DD33}.job - c:\windows\system32\msfeedssync.exe [2009-05-09 11:31] . . ------- Supplementary Scan ------- . uStart Page = hxxp://######/ IE: &AOL Toolbar Search - c:\programdata\AOL\ieToolbar\resources\en-GB\local\search.html IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-05-27 21:44 Windows 6.0.6001 Service Pack 1 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\EverestDriver] "ImagePath"="\??\f:\downloads\Everest Ultimate Engineer Edition 5.00.1692 (multi)\Everest Ultimate Engineer Edition 5.00.1692 (Multilanguage)\kerneld.wnt" . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-2514056171-1166224141-2149493090-1000\Software\SecuROM\License information*] "datasecu"=hex:21,01,9b,3c,56,e4,6d,1b,00,1f,54,9b,b7,77,fa,fe,aa,5e,96,90,29, 05,f4,09,c4,ab,3f,16,c6,63,28,1b,9f,99,bc,70,e7,ed,74,c8,a7,d8,72,dc,ab,f3,\ "rkeysecu"=hex:c1,7f,15,d2,4b,40,f2,1f,fb,ab,85,2a,cf,91,ec,eb . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'Explorer.exe'(6108) c:\windows\system32\newdll.dll c:\windows\system32\btmmhook.dll c:\windows\system32\btncopy.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\System32\nvvsvc.exe c:\windows\System32\DriverStore\FileRepository\stwrt.inf_a7e996cd\stacsv.exe c:\windows\System32\audiodg.exe c:\windows\System32\rundll32.exe c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe c:\program files\Common Files\LightScribe\LSSrvc.exe c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe c:\windows\System32\IoctlSvc.exe c:\program files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe c:\program files\HP\QuickPlay\Kernel\TV\QPSched.exe c:\program files\CyberLink\Shared Files\RichVideo.exe c:\windows\System32\rundll32.exe c:\windows\System32\wbem\unsecapp.exe c:\windows\ehome\ehmsas.exe c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe f:\rockstar games\Rockstar Games Social Club\1_1_3_0\RGSC.exe c:\program files\Synaptics\SynTP\SynTPHelper.exe c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe c:\program files\Common Files\Nero\Lib\NMIndexingService.exe c:\program files\Hewlett-Packard\Shared\HpqToaster.exe c:\program files\Skype\Plugin Manager\skypePM.exe c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe . ************************************************************************** . Completion time: 2009-05-27 21:47 - machine was rebooted ComboFix-quarantined-files.txt 2009-05-27 18:47 ComboFix2.txt 2009-05-27 18:23 ComboFix3.txt 2009-05-27 17:48 Pre-Run: 65 513 766 912 bytes free Post-Run: 65 228 931 072 bytes free 410 --- E O F --- 2009-05-27 17:42
-
HiJackThis/Log :Оптимизация/Анализ/Ревю
Ето го лога ComboFix 09-05-26.05 - User 05.2009 г. 21:13.2 - NTFSx86 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1251.359.1033.18.3068.1965 [GMT 3:00] Running from: c:\users\User\Desktop\ComboFix.exe Command switches used :: c:\users\User\Desktop\CFScript.txt SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} FILE :: "c:\windows\system32\02358.tmp" "c:\windows\system32\032B3.tmp" "c:\windows\system32\0E1D6.tmp" . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\02358.tmp c:\windows\system32\032B3.tmp c:\windows\system32\0E1D6.tmp . ((((((((((((((((((((((((( Files Created from 2009-04-27 to 2009-05-27 ))))))))))))))))))))))))))))))) . 2009-05-27 18:15 . 2009-05-27 18:18 -------- d-----w c:\users\User\AppData\Local\temp 2009-05-27 18:15 . 2009-05-27 18:15 -------- d-----w c:\users\rosen\AppData\Local\temp 2009-05-27 18:15 . 2009-05-27 18:15 -------- d-----w c:\users\Rosen.User-PC\AppData\Local\temp 2009-05-27 18:15 . 2009-05-27 18:15 -------- d-----w c:\users\Guest\AppData\Local\temp 2009-05-27 18:15 . 2009-05-27 18:15 -------- d-----w c:\users\all\AppData\Local\temp 2009-05-27 17:35 . 2009-05-06 18:06 4784464 ----a-w c:\programdata\Microsoft\Windows Defender\Definition Updates\{9FDD36AC-9325-4431-9F05-E9EE3D4F9A3C}\mpengine.dll 2009-05-27 15:22 . 2009-05-27 15:22 -------- d-----w c:\users\User\AppData\Roaming\Malwarebytes 2009-05-27 15:22 . 2009-05-26 10:20 40160 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys 2009-05-27 15:22 . 2009-05-27 17:03 -------- d-----w c:\program files\Malwarebytes' Anti-Malware 2009-05-27 15:22 . 2009-05-27 15:22 -------- d-----w c:\programdata\Malwarebytes 2009-05-27 15:22 . 2009-05-26 10:19 19096 ----a-w c:\windows\system32\drivers\mbam.sys 2009-05-27 14:35 . 2009-05-27 14:35 680 ----a-w c:\users\User\AppData\Local\d3d9caps.dat 2009-05-27 13:07 . 2009-05-27 13:13 -------- d-----w c:\programdata\Norton 2009-05-27 13:04 . 2009-05-27 13:05 -------- d-----w c:\programdata\NortonInstaller 2009-05-27 12:46 . 2009-05-27 12:46 -------- d-----w c:\program files\Trend Micro 2009-05-26 05:17 . 2009-05-26 05:17 -------- d-----w c:\users\Rosen.User-PC\AppData\Roaming\Ubisoft 2009-05-26 05:11 . 2009-05-26 05:16 -------- d-----w c:\users\Rosen.User-PC\AppData\Local\Microsoft Games 2009-05-25 16:15 . 2009-05-25 16:15 7592 ----a-w c:\users\Rosen.User-PC\AppData\Local\d3d9caps.dat 2009-05-25 15:57 . 2009-05-25 15:57 -------- d-----w c:\users\Rosen.User-PC\Bluetooth Software 2009-05-25 15:04 . 2009-05-25 15:57 -------- d-----w c:\users\Rosen.User-PC\AppData\Roaming\DAEMON Tools 2009-05-25 13:17 . 2009-05-28 01:14 -------- d-----w c:\users\Rosen.User-PC\AppData\Roaming\Winamp 2009-05-25 10:56 . 2009-05-25 10:56 -------- d-----w c:\users\Rosen.User-PC\AppData\Roaming\skypePM 2009-05-25 10:55 . 2009-05-25 11:25 -------- d-----w c:\users\Rosen.User-PC\AppData\Roaming\Skype 2009-05-25 10:53 . 2009-05-25 10:53 410984 ----a-w c:\windows\system32\deploytk.dll 2009-05-25 10:46 . 2009-05-25 10:46 103472 ----a-w c:\users\Rosen.User-PC\AppData\Local\GDIPFONTCACHEV1.DAT 2009-05-25 10:46 . 2009-05-25 10:46 -------- d-----w c:\users\Rosen.User-PC\AppData\Roaming\Nero 2009-05-25 10:46 . 2009-05-28 01:14 -------- d-----w c:\users\Rosen.User-PC\AppData\Local\QuickPlay 2009-05-25 10:29 . 2009-05-25 10:29 -------- d-----w c:\users\Guest\AppData\Roaming\Skype 2009-05-25 10:23 . 2009-05-25 10:23 -------- d-----w c:\users\Guest\AppData\Roaming\Nero 2009-05-25 09:19 . 2009-05-27 17:04 -------- d-sh--r C:\RESTORE 2009-05-24 16:10 . 2009-05-24 16:10 -------- d-----w c:\programdata\WindowsSearch 2009-05-24 14:48 . 2009-05-24 14:48 -------- d-----w c:\users\rosen\AppData\Roaming\Nero 2009-05-24 13:46 . 2009-05-24 13:46 -------- d-----w c:\users\User\AppData\Local\Ahead 2009-05-24 08:23 . 2009-05-24 08:23 -------- d-----w c:\users\Public\CyberLink 2009-05-21 08:41 . 2009-05-21 08:41 -------- d-----w c:\users\all\AppData\Local\Rockstar Games 2009-05-18 18:06 . 2009-05-18 18:08 -------- d-----w c:\users\User\AppData\Local\Rockstar Games 2009-05-18 18:02 . 2009-05-18 18:02 -------- d--h--r c:\users\User\AppData\Roaming\SecuROM 2009-05-18 18:01 . 2009-05-18 18:45 -------- d-----w c:\program files\Microsoft Games for Windows - LIVE 2009-05-18 18:01 . 2009-05-18 18:01 -------- d-----w c:\windows\system32\xlive 2009-05-18 17:12 . 2009-05-18 18:02 107888 ----a-w c:\windows\system32\CmdLineExt.dll 2009-05-18 13:18 . 2009-05-18 13:18 -------- d-----w c:\users\User\AppData\Roaming\Activision 2009-05-18 09:19 . 2009-05-23 08:54 -------- d-----w c:\users\all\AppData\Roaming\skypePM 2009-05-17 12:43 . 2009-05-27 18:08 -------- d-----w c:\users\User\AppData\Roaming\Skype 2009-05-17 12:43 . 2009-05-17 12:43 -------- d-----w c:\program files\Skype 2009-05-17 12:43 . 2009-05-17 12:43 -------- d-----w c:\program files\Common Files\Skype 2009-05-17 12:16 . 2009-05-17 12:16 -------- d-----w c:\users\all\AppData\Local\VirtualStore 2009-05-15 19:13 . 2009-05-16 09:26 -------- d-----w c:\program files\SpeedFan 2009-05-15 17:20 . 2009-05-15 17:20 -------- d-----w c:\program files\EasyBits For Kids 2009-05-15 17:00 . 2009-05-15 17:00 -------- d-----w c:\users\User\AppData\Roaming\Leadertech 2009-05-15 16:44 . 2009-05-15 16:44 -------- d-----w c:\program files\EA Games 2009-05-15 15:42 . 2009-05-15 15:42 -------- d-----w c:\program files\AGEIA Technologies 2009-05-15 15:42 . 2009-05-15 15:42 -------- d-----w c:\windows\system32\AGEIA 2009-05-15 15:42 . 2009-05-15 15:42 -------- d-----w c:\program files\Common Files\Wise Installation Wizard 2009-05-15 14:43 . 2009-05-18 17:07 -------- d-----w c:\program files\Activision 2009-05-15 14:42 . 2009-05-15 14:42 -------- d-sh--w c:\windows\ftpcache 2009-05-15 14:40 . 2009-05-15 14:41 -------- d-----w c:\users\User\AppData\Local\ACD Systems 2009-05-15 14:40 . 2009-05-15 14:40 -------- d-----w c:\users\User\AppData\Roaming\ACD Systems 2009-05-15 14:40 . 2009-05-15 14:40 -------- d-----w c:\programdata\ACD Systems 2009-05-15 14:40 . 2009-05-15 14:40 -------- d-----w c:\program files\Common Files\ACD Systems 2009-05-15 14:40 . 2009-05-15 14:40 -------- d-----w c:\program files\ACD Systems 2009-05-15 14:39 . 2009-05-15 14:39 10368 ----a-w c:\windows\system32\drivers\pfc.sys 2009-05-15 12:01 . 2009-05-20 00:40 -------- d-----w c:\users\all\AppData\Local\Microsoft Games 2009-05-15 11:53 . 2009-05-15 11:53 -------- d-----w c:\users\all\Bluetooth Software 2009-05-15 11:51 . 2009-05-23 09:52 -------- d-----w c:\users\all\AppData\Roaming\Skype 2009-05-14 03:56 . 2009-05-14 03:56 -------- d-----w c:\users\User\AppData\Roaming\InstallShield 2009-05-12 11:00 . 2009-05-12 11:00 -------- d-----w c:\users\Guest\Bluetooth Software 2009-05-11 17:45 . 2009-05-11 17:45 -------- d-----w c:\users\User\AppData\Local\Hewlett-Packard 2009-05-11 13:01 . 2009-05-24 18:36 -------- d-----w c:\users\User\AppData\Local\Google 2009-05-11 12:17 . 2009-05-11 15:47 -------- d-----w c:\users\rosen\AppData\Local\Google 2009-05-11 12:13 . 2009-05-12 17:48 -------- d-----w c:\program files\Google 2009-05-11 11:52 . 2009-05-11 11:52 -------- d-----w c:\program files\Common Files\Adobe AIR 2009-05-11 11:51 . 2009-05-11 11:51 -------- d-----w c:\program files\Common Files\Adobe 2009-05-11 07:39 . 2009-05-11 07:39 -------- d-----w c:\program files\Valve 2009-05-10 17:46 . 2009-05-10 17:46 -------- d-----w c:\program files\Microsoft.NET 2009-05-10 17:44 . 2009-05-10 17:44 -------- d-----w c:\program files\Microsoft Visual Studio 8 2009-05-10 17:43 . 2009-05-10 17:43 -------- d-----w c:\users\User\AppData\Local\Microsoft Help 2009-05-10 17:42 . 2009-05-10 17:42 -------- d--h--r C:\MSOCache 2009-05-10 17:02 . 2009-05-10 17:02 -------- d-----w C:\NVIDIA 2009-05-10 14:37 . 2009-05-24 18:33 -------- d-----w c:\users\User\AppData\Local\Nero 2009-05-10 14:15 . 2009-05-10 14:47 -------- d-----w c:\program files\Left 4 Dead 2009-05-10 14:15 . 2009-05-10 14:15 -------- d-----w c:\windows\Left 4 Dead 2009-05-10 13:14 . 2008-01-21 02:24 638976 ----a-w c:\windows\system32\win_utilman.exe 2009-05-10 13:14 . 2009-05-10 13:14 56 ---ha-w c:\windows\system32\ezsidmv.dat 2009-05-10 13:14 . 2009-05-10 13:14 91136 ----a-w c:\windows\system32\ezUninst.exe 2009-05-10 13:14 . 2009-05-10 13:14 49152 ----a-w c:\windows\system32\ezUPBHook.dll 2009-05-10 13:14 . 2009-05-10 13:14 268288 ----a-w c:\windows\system32\ezSetup.exe 2009-05-10 13:14 . 2009-05-10 13:14 15872 ----a-w c:\windows\system32\ezMAPIHelper.exe 2009-05-10 13:14 . 2009-05-10 13:14 111104 ----a-w c:\windows\system32\ezShellStart.exe 2009-05-10 10:38 . 1999-11-29 17:33 7440 ----a-w c:\windows\system32\kbdlk41j.Dll 2009-05-10 10:38 . 1999-12-07 06:00 6416 ----a-w c:\windows\system32\kbdbp.Dll 2009-05-10 10:38 . 1999-11-18 02:04 7440 ----a-w c:\windows\system32\Kbddll.dll 2009-05-10 10:38 . 1999-11-11 10:47 6928 ----a-w c:\windows\system32\kbdhebx.Dll 2009-05-10 10:38 . 2002-04-22 21:17 45056 ----a-w c:\windows\system32\newdll.dll 2009-05-10 10:38 . 2009-05-10 10:38 -------- d-----w c:\program files\Datecs 2009-05-10 00:05 . 2008-06-20 01:14 97800 ----a-w c:\windows\system32\infocardapi.dll 2009-05-10 00:05 . 2008-06-20 01:14 43544 ----a-w c:\windows\system32\PresentationHostProxy.dll 2009-05-10 00:05 . 2008-06-20 01:14 105016 ----a-w c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll 2009-05-10 00:05 . 2008-06-20 01:14 11264 ----a-w c:\windows\system32\icardres.dll 2009-05-10 00:05 . 2008-06-20 01:14 622080 ----a-w c:\windows\system32\icardagt.exe 2009-05-10 00:05 . 2008-06-20 01:14 781344 ----a-w c:\windows\system32\PresentationNative_v0300.dll 2009-05-10 00:05 . 2008-06-20 01:14 326160 ----a-w c:\windows\system32\PresentationHost.exe 2009-05-10 00:02 . 2008-07-27 18:03 96760 ----a-w c:\windows\system32\dfshim.dll 2009-05-10 00:02 . 2008-07-27 18:03 41984 ----a-w c:\windows\system32\netfxperf.dll 2009-05-10 00:02 . 2008-07-27 18:03 282112 ----a-w c:\windows\system32\mscoree.dll 2009-05-10 00:01 . 2008-07-27 18:03 158720 ----a-w c:\windows\system32\mscorier.dll 2009-05-10 00:01 . 2008-07-27 18:03 83968 ----a-w c:\windows\system32\mscories.dll 2009-05-10 00:01 . 2009-05-10 00:01 -------- d-----w c:\program files\MSXML 4.0 2009-05-09 21:01 . 1999-03-23 07:12 299520 ----a-w c:\windows\uninst.exe 2009-05-09 20:41 . 2009-05-09 20:41 -------- d-----w c:\program files\Lavalys 2009-05-09 20:00 . 2009-05-09 20:00 -------- d-----w c:\users\User\AppData\Roaming\Ubisoft 2009-05-09 20:00 . 2009-05-09 20:00 -------- d-----w c:\programdata\Ubisoft 2009-05-09 19:42 . 2009-05-14 03:56 -------- d-----w c:\program files\Ubisoft 2009-05-09 19:21 . 2009-05-24 07:44 -------- d-----w c:\program files\The KMPlayer 2009-05-09 19:13 . 2009-05-09 19:13 -------- d-----w c:\windows\Driver Cache 2009-05-09 19:13 . 2009-05-09 19:13 -------- d-----w c:\program files\AVerMedia 2009-05-09 18:57 . 2009-05-09 18:57 -------- d-----w c:\users\User\AppData\Roaming\NeroDCTemplates 2009-05-09 18:54 . 2009-05-24 13:44 -------- d-----w c:\users\User\AppData\Roaming\Nero 2009-05-09 18:19 . 2009-05-24 13:41 -------- d-----w c:\program files\Nero 2009-05-09 18:18 . 2009-05-24 13:43 -------- d-----w c:\program files\Common Files\Nero 2009-05-09 18:18 . 2009-05-24 13:41 -------- d-----w c:\programdata\Nero 2009-05-09 18:18 . 2009-05-09 18:18 -------- d-----w c:\program files\Common Files\LightScribe 2009-05-09 17:53 . 2009-05-11 09:43 -------- d-----w c:\programdata\LightScribe 2009-05-09 16:39 . 2009-05-09 16:51 -------- d-----w c:\users\rosen\AppData\Roaming\DAEMON Tools 2009-05-09 16:02 . 2009-05-09 16:02 -------- d-----w c:\users\rosen\AppData\Roaming\GRETECH 2009-05-09 16:02 . 2009-05-09 16:02 -------- d-----w c:\program files\GRETECH . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-05-28 01:14 . 2009-05-09 14:58 -------- d-----w c:\users\User\AppData\Roaming\DAEMON Tools 2009-05-27 18:16 . 2008-09-27 08:11 12 ----a-w c:\windows\bthservsdp.dat 2009-05-27 17:31 . 2008-09-27 08:44 113440 ----a-w c:\programdata\nvModes.dat 2009-05-27 13:08 . 2008-07-02 17:07 -------- d-----w c:\program files\Common Files\Symantec Shared 2009-05-27 13:07 . 2008-07-02 17:07 -------- d-----w c:\programdata\Symantec 2009-05-25 10:53 . 2008-07-02 18:31 -------- d-----w c:\program files\Java 2009-05-18 17:37 . 2008-07-02 17:05 -------- d--h--w c:\program files\InstallShield Installation Information 2009-05-16 14:32 . 2006-11-02 11:18 -------- d-----w c:\program files\Windows Mail 2009-05-15 11:49 . 2009-05-15 11:49 103472 ----a-w c:\users\all\AppData\Local\GDIPFONTCACHEV1.DAT 2009-05-11 17:22 . 2009-05-11 17:22 103472 ----a-w c:\users\Guest\AppData\Local\GDIPFONTCACHEV1.DAT 2009-05-10 17:55 . 2009-05-09 11:20 103472 ----a-w c:\users\rosen\AppData\Local\GDIPFONTCACHEV1.DAT 2009-05-10 17:53 . 2008-07-02 18:09 -------- d-----w c:\programdata\Microsoft Help 2009-05-10 17:47 . 2006-11-02 12:37 -------- d-----w c:\program files\MSBuild 2009-05-10 17:37 . 2008-09-27 08:50 -------- d-----w c:\programdata\NVIDIA 2009-05-10 13:14 . 2008-07-02 18:21 8292 ----a-w c:\windows\system32\ezdigsgn.dat 2009-05-10 00:30 . 2006-11-02 10:25 665600 ----a-w c:\windows\inf\drvindex.dat 2009-05-09 11:20 . 2009-05-09 11:20 -------- d-----w c:\users\rosen\AppData\Roaming\Symantec 2009-05-09 10:38 . 2009-05-09 10:38 0 ---ha-w c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf 2009-05-09 10:03 . 2008-09-27 08:49 -------- d-----w c:\programdata\CyberLink 2009-05-09 09:42 . 2008-07-02 17:42 -------- d-----w c:\programdata\WildTangent 2009-05-09 09:40 . 2009-05-09 09:40 32 ----a-w c:\programdata\ezsid.dat 2009-05-09 05:46 . 2009-05-09 05:46 0 --sha-r c:\windows\system32\drivers\103C_HP_cNB_Pavilion dv5 Notebook PC_Y5335KV_0U_QCNF84514NW_E465478-024_4A_I3603_SQuanta_V02.20_F.0C_T080918_WV3-1_L409_M3069_J320_7Intel_8676_92.00_#090509_N10EC8168;80864237_(FW699EA#ABB)_XMO BILE_CN10_Z_2F.0C.MRK 2009-04-21 21:20 . 2009-04-21 21:20 14311680 ----a-w c:\windows\system32\xlive.dll 2009-04-21 21:20 . 2009-04-21 21:20 13642496 ----a-w c:\windows\system32\xlivefnt.dll 2009-04-17 06:48 . 2009-04-17 06:48 114528 ----a-w c:\windows\system32\drivers\jmcr.sys 2009-03-08 11:34 . 2009-05-09 14:58 914944 ----a-w c:\windows\system32\wininet.dll 2009-03-08 11:34 . 2009-05-09 14:58 43008 ----a-w c:\windows\system32\licmgr10.dll 2009-03-08 11:33 . 2009-05-09 14:58 18944 ----a-w c:\windows\system32\corpol.dll 2009-03-08 11:33 . 2009-05-09 14:58 109056 ----a-w c:\windows\system32\iesysprep.dll 2009-03-08 11:33 . 2009-05-09 14:58 109568 ----a-w c:\windows\system32\PDMSetup.exe 2009-03-08 11:33 . 2009-05-09 14:58 132608 ----a-w c:\windows\system32\ieUnatt.exe 2009-03-08 11:33 . 2009-05-09 14:58 107520 ----a-w c:\windows\system32\RegisterIEPKEYs.exe 2009-03-08 11:33 . 2009-05-09 14:58 107008 ----a-w c:\windows\system32\SetIEInstalledDate.exe 2009-03-08 11:33 . 2009-05-09 14:58 103936 ----a-w c:\windows\system32\SetDepNx.exe 2009-03-08 11:33 . 2009-05-09 14:58 420352 ----a-w c:\windows\system32\vbscript.dll 2009-03-08 11:32 . 2009-05-09 14:58 72704 ----a-w c:\windows\system32\admparse.dll 2009-03-08 11:32 . 2009-05-09 14:58 71680 ----a-w c:\windows\system32\iesetup.dll 2009-03-08 11:32 . 2009-05-09 14:58 66560 ----a-w c:\windows\system32\wextract.exe 2009-03-08 11:32 . 2009-05-09 14:58 169472 ----a-w c:\windows\system32\iexpress.exe 2009-03-08 11:31 . 2009-05-09 14:58 34816 ----a-w c:\windows\system32\imgutil.dll 2009-03-08 11:31 . 2009-05-09 14:58 48128 ----a-w c:\windows\system32\mshtmler.dll 2009-03-08 11:31 . 2009-05-09 14:58 45568 ----a-w c:\windows\system32\mshta.exe 2009-03-08 11:22 . 2009-05-09 14:58 156160 ----a-w c:\windows\system32\msls31.dll 2009-03-06 06:06 . 2009-03-06 06:06 140800 ----a-w c:\windows\system32\drivers\Rtlh86.sys 2009-03-05 03:54 . 2009-03-05 03:54 73728 ----a-w c:\windows\system32\RtNicProp32.dll 2008-07-02 15:47 . 2008-07-02 15:47 8192 --sha-w c:\windows\Users\Default\NTUSER.DAT . ((((((((((((((((((((((((((((( SnapShot@2009-05-27_17.47.25 ))))))))))))))))))))))))))))))))))))))))) . + 2008-09-27 08:11 . 2009-05-27 18:16 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2008-09-27 08:11 . 2009-05-27 17:30 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2008-09-27 08:11 . 2009-05-27 18:16 98304 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2008-09-27 08:11 . 2009-05-27 17:30 98304 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2008-09-27 08:11 . 2009-05-27 17:30 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2008-09-27 08:11 . 2009-05-27 18:16 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-05-10 05:40 . 2009-05-27 18:07 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-05-10 05:40 . 2009-05-25 12:53 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-05-10 05:40 . 2009-05-25 12:53 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-05-10 05:40 . 2009-05-27 18:07 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-05-10 05:40 . 2009-05-27 18:07 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2009-05-10 05:40 . 2009-05-25 12:53 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-05-09 05:47 . 2009-05-27 18:06 5216 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2514056171-1166224141-2149493090-1000_UserData.bin - 2009-05-27 15:20 . 2009-05-27 17:30 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2009-05-27 18:16 . 2009-05-27 18:16 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2009-05-27 15:20 . 2009-05-27 17:30 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2009-05-27 18:16 . 2009-05-27 18:16 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2006-11-02 13:05 . 2009-05-27 18:06 102828 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin + 2009-05-12 17:47 . 2009-05-27 18:16 1043072 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-07 21633320] "RGSC"="f:\rockstar games\Rockstar Games Social Club\RGSCLauncher.exe" [2009-05-18 306088] "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-27 1045800] "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-16 178712] "UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504] "QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-04-24 468264] "QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-03-14 202032] "OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-11-02 554288] "HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-04-15 70912] "HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840] "hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-11-20 488752] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-25 148888] "SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-06-27 442467] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-30 13605408] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-01-30 92704] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-1-17 727592] FlexType 2K.lnk - c:\program files\Datecs\FlexType 2K\FType2K.exe [2009-5-10 95232] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) "HideFastUserSwitching"= 0 (0x0) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="" [HKEY_LOCAL_MACHINE\software\microsoft\security center] "UacDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{D1A19267-720D-45C7-BA29-21A2A647EF5B}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play "{B9AC649E-0A78-4DCC-9DAF-B51D71EE0A38}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program "{4802C87A-702A-4431-876A-5D11193D65B1}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector "{B12F35B4-F422-4B67-BB9F-3CA110ADF1A6}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone) "{0FC4DF7C-9FEC-442B-9468-5CA6B3C5DC9D}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In) "{5D406AE4-F07F-4153-9036-38CFF4942937}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In) "{9C70456F-ECFC-4FCE-9E00-06EDA40B50AE}"= UDP:17804:BitComet 17804 TCP "{A819E5D7-E9B1-41FF-ADB2-EB52591E6058}"= TCP:17804:BitComet 17804 UDP "TCP Query User{52BF79F6-7F65-49C8-9D5B-D3CEBA256D75}c:\\program files\\skype\\phone\\skype.exe"= UDP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath "UDP Query User{4D84D741-171B-4776-A5C5-9B7768D7E5ED}c:\\program files\\skype\\phone\\skype.exe"= TCP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath "{5BF83EF4-0DCE-47A4-9564-DB1105D16549}"= UDP:f:\prince of persia\Prince of Persia.exe:Prince of Persia Dx "{6E701431-BE56-48BD-813B-365AC08536F3}"= TCP:f:\prince of persia\Prince of Persia.exe:Prince of Persia Dx "{41366894-C565-4431-A345-D3B14D33F172}"= UDP:f:\prince of persia\PrinceOfPersia_Launcher.exe:Prince of Persia Update "{306C325E-6A01-4C49-BF66-6946136434F6}"= TCP:f:\prince of persia\PrinceOfPersia_Launcher.exe:Prince of Persia Update "TCP Query User{18B1FEFC-7956-4E81-960F-B3968E4EC522}f:\\counter-strike\\hl.exe"= UDP:f:\counter-strike\hl.exe:Half-Life Launcher "UDP Query User{09F01335-6BF9-4CB5-BE3D-8F0F84B159F6}f:\\counter-strike\\hl.exe"= TCP:f:\counter-strike\hl.exe:Half-Life Launcher "{EDCEBA08-3A90-4B0E-A84B-0E026327559B}"= UDP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9 "{8033D948-9891-4C4E-B6EE-12419A7B5E3C}"= TCP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9 "{4D75C391-1523-4D78-A4CF-026C8CEE3A8B}"= UDP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10 "{1FD4DDBD-A9C3-4920-94B5-C8FE1EFE6A33}"= TCP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10 "{17DF0F66-7ADC-44A1-AC1C-204CDAB14A10}"= UDP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update "{4F210143-C5CD-4B46-920F-0824F3A31496}"= TCP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update "TCP Query User{0F5523D7-6BA8-419B-9A34-760FB9EAB3ED}c:\\program files\\left 4 dead\\left4dead.exe"= UDP:c:\program files\left 4 dead\left4dead.exe:left4dead "UDP Query User{5FF2D015-FD7C-47C3-8385-F005AB5C71D4}c:\\program files\\left 4 dead\\left4dead.exe"= TCP:c:\program files\left 4 dead\left4dead.exe:left4dead "{B658BB4C-29EC-4A5D-9E3F-ECC98E5304E5}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook "{0FACA8F0-6BB6-4460-943C-7F643A60CE3F}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove "{D296CA6A-DB3F-4F18-914D-B554FBA9AD62}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove "{4CD86C2B-C1DE-4652-AF60-7FD94581DB94}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{38A34AFC-5B7D-4B1B-905C-F0CFB609272F}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "TCP Query User{87156E94-9DEF-4FB5-866A-D19A08B04DCE}f:\\half life\\hl2\\hl2.exe"= UDP:f:\half life\hl2\hl2.exe:hl2 "UDP Query User{07D91094-95B3-4CCE-A1F8-BCCF642AFC8C}f:\\half life\\hl2\\hl2.exe"= TCP:f:\half life\hl2\hl2.exe:hl2 "{BE0BD50B-800C-4199-AE63-74F501E0494E}"= UDP:c:\program files\Lavalys\EVEREST Ultimate Edition\everest.exe:EVEREST Ultimate Edition "{F9A2C16C-737E-409A-982D-CD293CF8837F}"= TCP:c:\program files\Lavalys\EVEREST Ultimate Edition\everest.exe:EVEREST Ultimate Edition "TCP Query User{C8352A4C-A496-4FCC-89D7-9F5178B0A72A}c:\\program files\\bitcomet\\bitcomet.exe"= UDP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client "UDP Query User{1160E15F-F4FE-477E-B6B3-2B26F97A6841}c:\\program files\\bitcomet\\bitcomet.exe"= TCP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client "TCP Query User{9F2A8CF4-8203-4F01-8B79-E5278EB8AE14}c:\\windows\\explorer.exe"= UDP:c:\windows\explorer.exe:Windows Explorer "UDP Query User{9BAD5322-E370-448A-A36F-6EEAF637E101}c:\\windows\\explorer.exe"= TCP:c:\windows\explorer.exe:Windows Explorer "{9946B689-4843-494C-A639-0F5202DAF3D0}"= UDP:17804:BitComet 17804 TCP "{8E93DEDD-8DAE-4B26-84CE-F4BF73EAE93F}"= TCP:17804:BitComet 17804 UDP "{94C90566-97C0-4D31-A77F-0574EA643D6E}"= UDP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9 "{5275B171-726F-425F-8052-8F41EE77F9F8}"= TCP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9 "{9E89D40F-7D6A-4FEC-A8DB-D13A5C6E2525}"= UDP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10 "{A82881B4-3C35-45BC-8017-D4E8FC9AD9B0}"= TCP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10 "{958B2B9E-523D-4D43-99BC-5D0578F62E23}"= UDP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update "{C3A949CF-031F-4F56-8756-4589F6BDE6A4}"= TCP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update "TCP Query User{FD86E422-D391-4D53-80C3-F0EC34BE7825}f:\\half life\\hl2\\hl2.exe"= UDP:f:\half life\hl2\hl2.exe:hl2 "UDP Query User{9AE0D4EA-DDEE-4886-8253-14A2BBF25F86}f:\\half life\\hl2\\hl2.exe"= TCP:f:\half life\hl2\hl2.exe:hl2 "{05092115-0D67-4CC8-BFBB-E04D74704BF3}"= UDP:c:\program files\Activision\X-Men Origins - Wolverine\Binaries\Wolverine.exe:X-Men Origins - Wolverine "{BC261CFE-CF5F-4236-A990-7B8139DFBA2B}"= TCP:c:\program files\Activision\X-Men Origins - Wolverine\Binaries\Wolverine.exe:X-Men Origins - Wolverine "{3F142349-23D7-45BA-9533-8167D9C46CB4}"= c:\program files\Skype\Phone\Skype.exe:Skype "{5CD145D9-D607-45CA-AC40-5EAB00A3A0A9}"= UDP:f:\rockstar games\Rockstar Games Social Club\RGSCLauncher.exe:Rockstar Games Social Club "{920D8BF9-403A-4277-9818-684822C6A675}"= TCP:f:\rockstar games\Rockstar Games Social Club\RGSCLauncher.exe:Rockstar Games Social Club "{74632C98-0192-4C53-A345-4C9FFAE08664}"= UDP:f:\rockstar games\Grand Theft Auto IV\LaunchGTAIV.exe:Grand Theft Auto IV "{171565A4-B6F6-496D-B33B-01216524ECD7}"= TCP:f:\rockstar games\Grand Theft Auto IV\LaunchGTAIV.exe:Grand Theft Auto IV "TCP Query User{612159B0-E64D-4111-90C4-8E5E8078091B}f:\\rockstar games\\grand theft auto iv\\gtaiv.exe"= UDP:f:\rockstar games\grand theft auto iv\gtaiv.exe:Grand Theft Auto IV "UDP Query User{9FA4F7DC-3DFF-4535-8526-ABE944199B6B}f:\\rockstar games\\grand theft auto iv\\gtaiv.exe"= TCP:f:\rockstar games\grand theft auto iv\gtaiv.exe:Grand Theft Auto IV "TCP Query User{30DC198A-9802-46EA-AF57-2F90A4C8A8AA}c:\\program files\\common files\\nero\\nero web\\setupx.exe"= UDP:c:\program files\common files\nero\nero web\setupx.exe:Nero Installer "UDP Query User{7CEE600E-2A67-4E29-BA2A-71EDB8261D5A}c:\\program files\\common files\\nero\\nero web\\setupx.exe"= TCP:c:\program files\common files\nero\nero web\setupx.exe:Nero Installer "TCP Query User{2FA6753E-7D33-4558-84E0-F0A1897A653B}c:\\users\\user\\appdata\\local\\temp\\onlineupdate8\\setupxu.exe"= UDP:c:\users\user\appdata\local\temp\onlineupdate8\setupxu.exe:setupxu.exe "UDP Query User{0C8A11A1-DD20-494C-8CA6-0EE97FEB0B9E}c:\\users\\user\\appdata\\local\\temp\\onlineupdate8\\setupxu.exe"= TCP:c:\users\user\appdata\local\temp\onlineupdate8\setupxu.exe:setupxu.exe R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\AEstSrv.exe [27.9.2008 і. 11:18 73728] R2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe -k netsvcs [21.1.2008 і. 05:23 21504] R2 hpsrv;HP Service;c:\windows\System32\hpservice.exe [19.3.2008 і. 02:24 19456] R2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\SMINST\BLService.exe [2.7.2008 і. 21:26 341328] R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2.7.2008 і. 20:29 193840] R3 enecir;ENE CIR Receiver;c:\windows\System32\drivers\enecir.sys [24.1.2008 і. 16:23 52736] R3 JMCR;JMCR;c:\windows\System32\drivers\jmcr.sys [17.4.2009 і. 09:48 114528] R3 NETw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\System32\drivers\NETw5v32.sys [17.11.2008 і. 15:40 3668480] R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\System32\drivers\nvhda32v.sys [23.5.2008 і. 06:29 43552] S3 EverestDriver;Lavalys EVEREST Kernel Driver;f:\downloads\Everest Ultimate Engineer Edition 5.00.1692 (multi)\Everest Ultimate Engineer Edition 5.00.1692 (Multilanguage)\kerneld.wnt [16.5.2009 і. 12:14 26224] --- Other Services/Drivers In Memory --- *Deregistered* - sptd [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs REG_MULTI_SZ BthServ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs ezSharedSvc [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] "c:\program files\Common Files\LightScribe\LSRunOnce.exe" . Contents of the 'Scheduled Tasks' folder 2009-05-27 c:\windows\Tasks\User_Feed_Synchronization-{A1953874-5815-44FF-9509-2C81765588EE}.job - c:\windows\system32\msfeedssync.exe [2009-05-09 11:31] 2009-05-27 c:\windows\Tasks\User_Feed_Synchronization-{DD313412-8BC6-47F1-9C0C-AFFFC1E7DD33}.job - c:\windows\system32\msfeedssync.exe [2009-05-09 11:31] . . ------- Supplementary Scan ------- . uStart Page = hxxp://######/ IE: &AOL Toolbar Search - c:\programdata\AOL\ieToolbar\resources\en-GB\local\search.html IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-05-27 21:18 Windows 6.0.6001 Service Pack 1 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... c:\windows\TEMP\TMP0000003ACB352524BF27BC51 524288 bytes executable scan completed successfully hidden files: 1 ************************************************************************** [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\EverestDriver] "ImagePath"="\??\f:\downloads\Everest Ultimate Engineer Edition 5.00.1692 (multi)\Everest Ultimate Engineer Edition 5.00.1692 (Multilanguage)\kerneld.wnt" . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-2514056171-1166224141-2149493090-1000\Software\SecuROM\License information*] "datasecu"=hex:21,01,9b,3c,56,e4,6d,1b,00,1f,54,9b,b7,77,fa,fe,aa,5e,96,90,29, 05,f4,09,c4,ab,3f,16,c6,63,28,1b,9f,99,bc,70,e7,ed,74,c8,a7,d8,72,dc,ab,f3,\ "rkeysecu"=hex:c1,7f,15,d2,4b,40,f2,1f,fb,ab,85,2a,cf,91,ec,eb . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'Explorer.exe'(5284) c:\windows\system32\newdll.dll c:\windows\system32\btmmhook.dll c:\windows\system32\btncopy.dll c:\windows\system32\BtwNamespaceExt.dll c:\windows\system32\BtwNeLib.dll c:\windows\system32\btwapi.dll c:\windows\system32\btosif.dll c:\windows\system32\btwpimif.dll c:\program files\Common Files\Nero\Lib\MediaLibraryNSE.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\System32\nvvsvc.exe c:\windows\System32\DriverStore\FileRepository\stwrt.inf_a7e996cd\stacsv.exe c:\windows\System32\audiodg.exe c:\windows\System32\rundll32.exe c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe c:\program files\Common Files\LightScribe\LSSrvc.exe c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe c:\windows\System32\IoctlSvc.exe c:\program files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe c:\program files\HP\QuickPlay\Kernel\TV\QPSched.exe c:\program files\CyberLink\Shared Files\RichVideo.exe c:\windows\System32\rundll32.exe c:\windows\System32\wbem\unsecapp.exe c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe c:\windows\ehome\ehmsas.exe c:\program files\Synaptics\SynTP\SynTPHelper.exe c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe c:\program files\Hewlett-Packard\Shared\HpqToaster.exe c:\program files\Common Files\Nero\Lib\NMIndexingService.exe c:\program files\Skype\Plugin Manager\skypePM.exe c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe c:\windows\servicing\TrustedInstaller.exe c:\windows\System32\vdsldr.exe c:\windows\System32\vds.exe . ************************************************************************** . Completion time: 2009-05-27 21:23 - machine was rebooted ComboFix-quarantined-files.txt 2009-05-27 18:23 ComboFix2.txt 2009-05-27 17:48 Pre-Run: 65 607 000 064 bytes free Post-Run: 65 436 565 504 bytes free 425 --- E O F --- 2009-05-27 17:42
-
HiJackThis/Log :Оптимизация/Анализ/Ревю
Излезе този лог,но не се рестартира. ComboFix 09-05-26.05 - User 05.2009 г. 20:43.1 - NTFSx86 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1251.359.1033.18.3068.1819 [GMT 3:00] Running from: c:\users\User\Desktop\ComboFix.exe SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\kbdbds.Dll c:\windows\system32\KBDBPH.dLL c:\windows\system32\kbdbphz.dLL D:\Desktop.ini . ((((((((((((((((((((((((( Files Created from 2009-04-27 to 2009-05-27 ))))))))))))))))))))))))))))))) . 2009-05-27 17:47 . 2009-05-27 17:47 -------- d-----w c:\users\rosen\AppData\Local\temp 2009-05-27 17:35 . 2009-05-06 18:06 4784464 ----a-w c:\programdata\Microsoft\Windows Defender\Definition Updates\{9FDD36AC-9325-4431-9F05-E9EE3D4F9A3C}\mpengine.dll 2009-05-27 15:22 . 2009-05-27 15:22 -------- d-----w c:\users\User\AppData\Roaming\Malwarebytes 2009-05-27 15:22 . 2009-05-26 10:20 40160 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys 2009-05-27 15:22 . 2009-05-27 17:03 -------- d-----w c:\program files\Malwarebytes' Anti-Malware 2009-05-27 15:22 . 2009-05-27 15:22 -------- d-----w c:\programdata\Malwarebytes 2009-05-27 15:22 . 2009-05-26 10:19 19096 ----a-w c:\windows\system32\drivers\mbam.sys 2009-05-27 14:35 . 2009-05-27 14:35 680 ----a-w c:\users\User\AppData\Local\d3d9caps.dat 2009-05-27 13:07 . 2009-05-27 13:13 -------- d-----w c:\programdata\Norton 2009-05-27 13:04 . 2009-05-27 13:05 -------- d-----w c:\programdata\NortonInstaller 2009-05-27 12:46 . 2009-05-27 12:46 -------- d-----w c:\program files\Trend Micro 2009-05-26 05:17 . 2009-05-26 05:17 -------- d-----w c:\users\Rosen.User-PC\AppData\Roaming\Ubisoft 2009-05-26 05:11 . 2009-05-26 05:16 -------- d-----w c:\users\Rosen.User-PC\AppData\Local\Microsoft Games 2009-05-25 16:15 . 2009-05-25 16:15 7592 ----a-w c:\users\Rosen.User-PC\AppData\Local\d3d9caps.dat 2009-05-25 15:57 . 2009-05-25 15:57 -------- d-----w c:\users\Rosen.User-PC\Bluetooth Software 2009-05-25 15:04 . 2009-05-25 15:57 -------- d-----w c:\users\Rosen.User-PC\AppData\Roaming\DAEMON Tools 2009-05-25 13:17 . 2009-05-28 01:14 -------- d-----w c:\users\Rosen.User-PC\AppData\Roaming\Winamp 2009-05-25 10:56 . 2009-05-25 10:56 -------- d-----w c:\users\Rosen.User-PC\AppData\Roaming\skypePM 2009-05-25 10:55 . 2009-05-25 11:25 -------- d-----w c:\users\Rosen.User-PC\AppData\Roaming\Skype 2009-05-25 10:53 . 2009-05-25 10:53 410984 ----a-w c:\windows\system32\deploytk.dll 2009-05-25 10:46 . 2009-05-25 10:46 103472 ----a-w c:\users\Rosen.User-PC\AppData\Local\GDIPFONTCACHEV1.DAT 2009-05-25 10:46 . 2009-05-25 10:46 -------- d-----w c:\users\Rosen.User-PC\AppData\Roaming\Nero 2009-05-25 10:46 . 2009-05-28 01:14 -------- d-----w c:\users\Rosen.User-PC\AppData\Local\QuickPlay 2009-05-25 10:29 . 2009-05-25 10:29 -------- d-----w c:\users\Guest\AppData\Roaming\Skype 2009-05-25 10:23 . 2009-05-25 10:23 -------- d-----w c:\users\Guest\AppData\Roaming\Nero 2009-05-25 09:19 . 2009-05-27 17:04 -------- d-sh--r C:\RESTORE 2009-05-24 16:10 . 2009-05-24 16:10 -------- d-----w c:\programdata\WindowsSearch 2009-05-24 14:48 . 2009-05-24 14:48 -------- d-----w c:\users\rosen\AppData\Roaming\Nero 2009-05-24 13:46 . 2009-05-24 13:46 -------- d-----w c:\users\User\AppData\Local\Ahead 2009-05-24 08:23 . 2009-05-24 08:23 -------- d-----w c:\users\Public\CyberLink 2009-05-21 08:41 . 2009-05-21 08:41 -------- d-----w c:\users\all\AppData\Local\Rockstar Games 2009-05-18 18:06 . 2009-05-18 18:08 -------- d-----w c:\users\User\AppData\Local\Rockstar Games 2009-05-18 18:02 . 2009-05-18 18:02 -------- d--h--r c:\users\User\AppData\Roaming\SecuROM 2009-05-18 18:01 . 2009-05-18 18:45 -------- d-----w c:\program files\Microsoft Games for Windows - LIVE 2009-05-18 18:01 . 2009-05-18 18:01 -------- d-----w c:\windows\system32\xlive 2009-05-18 17:12 . 2009-05-18 18:02 107888 ----a-w c:\windows\system32\CmdLineExt.dll 2009-05-18 13:18 . 2009-05-18 13:18 -------- d-----w c:\users\User\AppData\Roaming\Activision 2009-05-18 09:19 . 2009-05-23 08:54 -------- d-----w c:\users\all\AppData\Roaming\skypePM 2009-05-17 12:43 . 2009-05-27 17:32 -------- d-----w c:\users\User\AppData\Roaming\Skype 2009-05-17 12:43 . 2009-05-17 12:43 -------- d-----w c:\program files\Skype 2009-05-17 12:43 . 2009-05-17 12:43 -------- d-----w c:\program files\Common Files\Skype 2009-05-17 12:16 . 2009-05-17 12:16 -------- d-----w c:\users\all\AppData\Local\VirtualStore 2009-05-15 19:13 . 2009-05-16 09:26 -------- d-----w c:\program files\SpeedFan 2009-05-15 17:20 . 2009-05-15 17:20 -------- d-----w c:\program files\EasyBits For Kids 2009-05-15 17:00 . 2009-05-15 17:00 -------- d-----w c:\users\User\AppData\Roaming\Leadertech 2009-05-15 16:44 . 2009-05-15 16:44 -------- d-----w c:\program files\EA Games 2009-05-15 15:42 . 2009-05-15 15:42 -------- d-----w c:\program files\AGEIA Technologies 2009-05-15 15:42 . 2009-05-15 15:42 -------- d-----w c:\windows\system32\AGEIA 2009-05-15 15:42 . 2009-05-15 15:42 -------- d-----w c:\program files\Common Files\Wise Installation Wizard 2009-05-15 14:43 . 2009-05-18 17:07 -------- d-----w c:\program files\Activision 2009-05-15 14:42 . 2009-05-15 14:42 -------- d-sh--w c:\windows\ftpcache 2009-05-15 14:40 . 2009-05-15 14:41 -------- d-----w c:\users\User\AppData\Local\ACD Systems 2009-05-15 14:40 . 2009-05-15 14:40 -------- d-----w c:\users\User\AppData\Roaming\ACD Systems 2009-05-15 14:40 . 2009-05-15 14:40 -------- d-----w c:\programdata\ACD Systems 2009-05-15 14:40 . 2009-05-15 14:40 -------- d-----w c:\program files\Common Files\ACD Systems 2009-05-15 14:40 . 2009-05-15 14:40 -------- d-----w c:\program files\ACD Systems 2009-05-15 14:39 . 2009-05-15 14:39 10368 ----a-w c:\windows\system32\drivers\pfc.sys 2009-05-15 12:01 . 2009-05-20 00:40 -------- d-----w c:\users\all\AppData\Local\Microsoft Games 2009-05-15 11:53 . 2009-05-15 11:53 -------- d-----w c:\users\all\Bluetooth Software 2009-05-15 11:51 . 2009-05-23 09:52 -------- d-----w c:\users\all\AppData\Roaming\Skype 2009-05-14 03:56 . 2009-05-14 03:56 -------- d-----w c:\users\User\AppData\Roaming\InstallShield 2009-05-12 11:00 . 2009-05-12 11:00 -------- d-----w c:\users\Guest\Bluetooth Software 2009-05-11 17:45 . 2009-05-11 17:45 -------- d-----w c:\users\User\AppData\Local\Hewlett-Packard 2009-05-11 13:01 . 2009-05-24 18:36 -------- d-----w c:\users\User\AppData\Local\Google 2009-05-11 12:17 . 2009-05-11 15:47 -------- d-----w c:\users\rosen\AppData\Local\Google 2009-05-11 12:13 . 2009-05-12 17:48 -------- d-----w c:\program files\Google 2009-05-11 11:52 . 2009-05-11 11:52 -------- d-----w c:\program files\Common Files\Adobe AIR 2009-05-11 11:51 . 2009-05-11 11:51 -------- d-----w c:\program files\Common Files\Adobe 2009-05-11 07:39 . 2009-05-11 07:39 -------- d-----w c:\program files\Valve 2009-05-10 17:46 . 2009-05-10 17:46 -------- d-----w c:\program files\Microsoft.NET 2009-05-10 17:44 . 2009-05-10 17:44 -------- d-----w c:\program files\Microsoft Visual Studio 8 2009-05-10 17:43 . 2009-05-10 17:43 -------- d-----w c:\users\User\AppData\Local\Microsoft Help 2009-05-10 17:42 . 2009-05-10 17:42 -------- d--h--r C:\MSOCache 2009-05-10 17:02 . 2009-05-10 17:02 -------- d-----w C:\NVIDIA 2009-05-10 14:37 . 2009-05-24 18:33 -------- d-----w c:\users\User\AppData\Local\Nero 2009-05-10 14:15 . 2009-05-10 14:47 -------- d-----w c:\program files\Left 4 Dead 2009-05-10 14:15 . 2009-05-10 14:15 -------- d-----w c:\windows\Left 4 Dead 2009-05-10 13:14 . 2008-01-21 02:24 638976 ----a-w c:\windows\system32\win_utilman.exe 2009-05-10 13:14 . 2009-05-10 13:14 56 ---ha-w c:\windows\system32\ezsidmv.dat 2009-05-10 13:14 . 2009-05-10 13:14 91136 ----a-w c:\windows\system32\ezUninst.exe 2009-05-10 13:14 . 2009-05-10 13:14 49152 ----a-w c:\windows\system32\ezUPBHook.dll 2009-05-10 13:14 . 2009-05-10 13:14 268288 ----a-w c:\windows\system32\ezSetup.exe 2009-05-10 13:14 . 2009-05-10 13:14 15872 ----a-w c:\windows\system32\ezMAPIHelper.exe 2009-05-10 13:14 . 2009-05-10 13:14 111104 ----a-w c:\windows\system32\ezShellStart.exe 2009-05-10 10:38 . 1999-11-29 17:33 7440 ----a-w c:\windows\system32\kbdlk41j.Dll 2009-05-10 10:38 . 1999-12-07 06:00 6416 ----a-w c:\windows\system32\kbdbp.Dll 2009-05-10 10:38 . 1999-11-18 02:04 7440 ----a-w c:\windows\system32\Kbddll.dll 2009-05-10 10:38 . 1999-11-11 10:47 6928 ----a-w c:\windows\system32\kbdhebx.Dll 2009-05-10 10:38 . 2002-04-22 21:17 45056 ----a-w c:\windows\system32\newdll.dll 2009-05-10 10:38 . 2009-05-10 10:38 -------- d-----w c:\program files\Datecs 2009-05-10 00:05 . 2008-06-20 01:14 97800 ----a-w c:\windows\system32\infocardapi.dll 2009-05-10 00:05 . 2008-06-20 01:14 43544 ----a-w c:\windows\system32\PresentationHostProxy.dll 2009-05-10 00:05 . 2008-06-20 01:14 105016 ----a-w c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll 2009-05-10 00:05 . 2008-06-20 01:14 11264 ----a-w c:\windows\system32\icardres.dll 2009-05-10 00:05 . 2008-06-20 01:14 622080 ----a-w c:\windows\system32\icardagt.exe 2009-05-10 00:05 . 2008-06-20 01:14 781344 ----a-w c:\windows\system32\PresentationNative_v0300.dll 2009-05-10 00:05 . 2008-06-20 01:14 326160 ----a-w c:\windows\system32\PresentationHost.exe 2009-05-10 00:02 . 2008-07-27 18:03 96760 ----a-w c:\windows\system32\dfshim.dll 2009-05-10 00:02 . 2008-07-27 18:03 41984 ----a-w c:\windows\system32\netfxperf.dll 2009-05-10 00:02 . 2008-07-27 18:03 282112 ----a-w c:\windows\system32\mscoree.dll 2009-05-10 00:01 . 2008-07-27 18:03 158720 ----a-w c:\windows\system32\mscorier.dll 2009-05-10 00:01 . 2008-07-27 18:03 83968 ----a-w c:\windows\system32\mscories.dll 2009-05-10 00:01 . 2009-05-10 00:01 -------- d-----w c:\program files\MSXML 4.0 2009-05-09 21:01 . 1999-03-23 07:12 299520 ----a-w c:\windows\uninst.exe 2009-05-09 20:41 . 2009-05-09 20:41 -------- d-----w c:\program files\Lavalys 2009-05-09 20:00 . 2009-05-09 20:00 -------- d-----w c:\users\User\AppData\Roaming\Ubisoft 2009-05-09 20:00 . 2009-05-09 20:00 -------- d-----w c:\programdata\Ubisoft 2009-05-09 19:42 . 2009-05-14 03:56 -------- d-----w c:\program files\Ubisoft 2009-05-09 19:21 . 2009-05-24 07:44 -------- d-----w c:\program files\The KMPlayer 2009-05-09 19:13 . 2009-05-09 19:13 -------- d-----w c:\windows\Driver Cache 2009-05-09 19:13 . 2009-05-09 19:13 -------- d-----w c:\program files\AVerMedia 2009-05-09 18:57 . 2009-05-09 18:57 -------- d-----w c:\users\User\AppData\Roaming\NeroDCTemplates 2009-05-09 18:54 . 2009-05-24 13:44 -------- d-----w c:\users\User\AppData\Roaming\Nero 2009-05-09 18:19 . 2009-05-24 13:41 -------- d-----w c:\program files\Nero 2009-05-09 18:18 . 2009-05-24 13:43 -------- d-----w c:\program files\Common Files\Nero 2009-05-09 18:18 . 2009-05-24 13:41 -------- d-----w c:\programdata\Nero 2009-05-09 18:18 . 2009-05-09 18:18 -------- d-----w c:\program files\Common Files\LightScribe 2009-05-09 17:53 . 2009-05-11 09:43 -------- d-----w c:\programdata\LightScribe 2009-05-09 16:39 . 2009-05-09 16:51 -------- d-----w c:\users\rosen\AppData\Roaming\DAEMON Tools 2009-05-09 16:02 . 2009-05-09 16:02 -------- d-----w c:\users\rosen\AppData\Roaming\GRETECH 2009-05-09 16:02 . 2009-05-09 16:02 -------- d-----w c:\program files\GRETECH 2009-05-09 15:59 . 2009-05-09 15:59 -------- d-----w c:\users\rosen\AppData\Local\Adobe 2009-05-09 15:46 . 2009-05-09 15:46 -------- d-----w c:\users\rosen\AppData\Roaming\HP 2009-05-09 15:46 . 2009-05-09 15:46 -------- d-----w c:\programdata\HP 2009-05-09 15:44 . 2009-05-09 16:25 -------- d-----w c:\users\rosen\AppData\Roaming\CyberLink . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-05-28 01:14 . 2009-05-09 14:58 -------- d-----w c:\users\User\AppData\Roaming\DAEMON Tools 2009-05-27 17:31 . 2008-09-27 08:44 113440 ----a-w c:\programdata\nvModes.dat 2009-05-27 17:05 . 2008-09-27 08:11 12 ----a-w c:\windows\bthservsdp.dat 2009-05-27 13:08 . 2008-07-02 17:07 -------- d-----w c:\program files\Common Files\Symantec Shared 2009-05-27 13:07 . 2008-07-02 17:07 -------- d-----w c:\programdata\Symantec 2009-05-25 10:53 . 2008-07-02 18:31 -------- d-----w c:\program files\Java 2009-05-18 17:37 . 2008-07-02 17:05 -------- d--h--w c:\program files\InstallShield Installation Information 2009-05-16 14:32 . 2006-11-02 11:18 -------- d-----w c:\program files\Windows Mail 2009-05-15 11:49 . 2009-05-15 11:49 103472 ----a-w c:\users\all\AppData\Local\GDIPFONTCACHEV1.DAT 2009-05-13 17:44 . 2009-05-13 17:44 4096 ----a-w c:\windows\system32\02358.tmp 2009-05-13 13:13 . 2009-05-13 13:13 4096 ----a-w c:\windows\system32\032B3.tmp 2009-05-13 11:11 . 2009-05-13 11:11 4096 ----a-w c:\windows\system32\0E1D6.tmp 2009-05-11 17:22 . 2009-05-11 17:22 103472 ----a-w c:\users\Guest\AppData\Local\GDIPFONTCACHEV1.DAT 2009-05-10 17:55 . 2009-05-09 11:20 103472 ----a-w c:\users\rosen\AppData\Local\GDIPFONTCACHEV1.DAT 2009-05-10 17:53 . 2008-07-02 18:09 -------- d-----w c:\programdata\Microsoft Help 2009-05-10 17:47 . 2006-11-02 12:37 -------- d-----w c:\program files\MSBuild 2009-05-10 17:37 . 2008-09-27 08:50 -------- d-----w c:\programdata\NVIDIA 2009-05-10 13:14 . 2008-07-02 18:21 8292 ----a-w c:\windows\system32\ezdigsgn.dat 2009-05-10 00:30 . 2006-11-02 10:25 665600 ----a-w c:\windows\inf\drvindex.dat 2009-05-09 11:20 . 2009-05-09 11:20 -------- d-----w c:\users\rosen\AppData\Roaming\Symantec 2009-05-09 10:38 . 2009-05-09 10:38 0 ---ha-w c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf 2009-05-09 10:03 . 2008-09-27 08:49 -------- d-----w c:\programdata\CyberLink 2009-05-09 09:42 . 2008-07-02 17:42 -------- d-----w c:\programdata\WildTangent 2009-05-09 09:40 . 2009-05-09 09:40 32 ----a-w c:\programdata\ezsid.dat 2009-05-09 05:46 . 2009-05-09 05:46 0 --sha-r c:\windows\system32\drivers\103C_HP_cNB_Pavilion dv5 Notebook PC_Y5335KV_0U_QCNF84514NW_E465478-024_4A_I3603_SQuanta_V02.20_F.0C_T080918_WV3-1_L409_M3069_J320_7Intel_8676_92.00_#090509_N10EC8168;80864237_(FW699EA#ABB)_XMO BILE_CN10_Z_2F.0C.MRK 2009-04-21 21:20 . 2009-04-21 21:20 14311680 ----a-w c:\windows\system32\xlive.dll 2009-04-21 21:20 . 2009-04-21 21:20 13642496 ----a-w c:\windows\system32\xlivefnt.dll 2009-04-17 06:48 . 2009-04-17 06:48 114528 ----a-w c:\windows\system32\drivers\jmcr.sys 2009-03-08 11:34 . 2009-05-09 14:58 914944 ----a-w c:\windows\system32\wininet.dll 2009-03-08 11:34 . 2009-05-09 14:58 43008 ----a-w c:\windows\system32\licmgr10.dll 2009-03-08 11:33 . 2009-05-09 14:58 18944 ----a-w c:\windows\system32\corpol.dll 2009-03-08 11:33 . 2009-05-09 14:58 109056 ----a-w c:\windows\system32\iesysprep.dll 2009-03-08 11:33 . 2009-05-09 14:58 109568 ----a-w c:\windows\system32\PDMSetup.exe 2009-03-08 11:33 . 2009-05-09 14:58 132608 ----a-w c:\windows\system32\ieUnatt.exe 2009-03-08 11:33 . 2009-05-09 14:58 107520 ----a-w c:\windows\system32\RegisterIEPKEYs.exe 2009-03-08 11:33 . 2009-05-09 14:58 107008 ----a-w c:\windows\system32\SetIEInstalledDate.exe 2009-03-08 11:33 . 2009-05-09 14:58 103936 ----a-w c:\windows\system32\SetDepNx.exe 2009-03-08 11:33 . 2009-05-09 14:58 420352 ----a-w c:\windows\system32\vbscript.dll 2009-03-08 11:32 . 2009-05-09 14:58 72704 ----a-w c:\windows\system32\admparse.dll 2009-03-08 11:32 . 2009-05-09 14:58 71680 ----a-w c:\windows\system32\iesetup.dll 2009-03-08 11:32 . 2009-05-09 14:58 66560 ----a-w c:\windows\system32\wextract.exe 2009-03-08 11:32 . 2009-05-09 14:58 169472 ----a-w c:\windows\system32\iexpress.exe 2009-03-08 11:31 . 2009-05-09 14:58 34816 ----a-w c:\windows\system32\imgutil.dll 2009-03-08 11:31 . 2009-05-09 14:58 48128 ----a-w c:\windows\system32\mshtmler.dll 2009-03-08 11:31 . 2009-05-09 14:58 45568 ----a-w c:\windows\system32\mshta.exe 2009-03-08 11:22 . 2009-05-09 14:58 156160 ----a-w c:\windows\system32\msls31.dll 2009-03-06 06:06 . 2009-03-06 06:06 140800 ----a-w c:\windows\system32\drivers\Rtlh86.sys 2009-03-05 03:54 . 2009-03-05 03:54 73728 ----a-w c:\windows\system32\RtNicProp32.dll 2008-07-02 15:47 . 2008-07-02 15:47 8192 --sha-w c:\windows\Users\Default\NTUSER.DAT . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-07 21633320] "RGSC"="f:\rockstar games\Rockstar Games Social Club\RGSCLauncher.exe" [2009-05-18 306088] "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-27 1045800] "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-16 178712] "UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504] "QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-04-24 468264] "QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-03-14 202032] "OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-11-02 554288] "HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-04-15 70912] "HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840] "hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-11-20 488752] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-25 148888] "SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-06-27 442467] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-30 13605408] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-01-30 92704] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-1-17 727592] FlexType 2K.lnk - c:\program files\Datecs\FlexType 2K\FType2K.exe [2009-5-10 95232] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) "HideFastUserSwitching"= 0 (0x0) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center] "UacDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{D1A19267-720D-45C7-BA29-21A2A647EF5B}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play "{B9AC649E-0A78-4DCC-9DAF-B51D71EE0A38}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program "{4802C87A-702A-4431-876A-5D11193D65B1}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector "{B12F35B4-F422-4B67-BB9F-3CA110ADF1A6}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone) "{0FC4DF7C-9FEC-442B-9468-5CA6B3C5DC9D}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In) "{5D406AE4-F07F-4153-9036-38CFF4942937}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In) "{9C70456F-ECFC-4FCE-9E00-06EDA40B50AE}"= UDP:17804:BitComet 17804 TCP "{A819E5D7-E9B1-41FF-ADB2-EB52591E6058}"= TCP:17804:BitComet 17804 UDP "TCP Query User{52BF79F6-7F65-49C8-9D5B-D3CEBA256D75}c:\\program files\\skype\\phone\\skype.exe"= UDP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath "UDP Query User{4D84D741-171B-4776-A5C5-9B7768D7E5ED}c:\\program files\\skype\\phone\\skype.exe"= TCP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath "{5BF83EF4-0DCE-47A4-9564-DB1105D16549}"= UDP:f:\prince of persia\Prince of Persia.exe:Prince of Persia Dx "{6E701431-BE56-48BD-813B-365AC08536F3}"= TCP:f:\prince of persia\Prince of Persia.exe:Prince of Persia Dx "{41366894-C565-4431-A345-D3B14D33F172}"= UDP:f:\prince of persia\PrinceOfPersia_Launcher.exe:Prince of Persia Update "{306C325E-6A01-4C49-BF66-6946136434F6}"= TCP:f:\prince of persia\PrinceOfPersia_Launcher.exe:Prince of Persia Update "TCP Query User{18B1FEFC-7956-4E81-960F-B3968E4EC522}f:\\counter-strike\\hl.exe"= UDP:f:\counter-strike\hl.exe:Half-Life Launcher "UDP Query User{09F01335-6BF9-4CB5-BE3D-8F0F84B159F6}f:\\counter-strike\\hl.exe"= TCP:f:\counter-strike\hl.exe:Half-Life Launcher "{EDCEBA08-3A90-4B0E-A84B-0E026327559B}"= UDP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9 "{8033D948-9891-4C4E-B6EE-12419A7B5E3C}"= TCP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9 "{4D75C391-1523-4D78-A4CF-026C8CEE3A8B}"= UDP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10 "{1FD4DDBD-A9C3-4920-94B5-C8FE1EFE6A33}"= TCP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10 "{17DF0F66-7ADC-44A1-AC1C-204CDAB14A10}"= UDP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update "{4F210143-C5CD-4B46-920F-0824F3A31496}"= TCP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update "TCP Query User{0F5523D7-6BA8-419B-9A34-760FB9EAB3ED}c:\\program files\\left 4 dead\\left4dead.exe"= UDP:c:\program files\left 4 dead\left4dead.exe:left4dead "UDP Query User{5FF2D015-FD7C-47C3-8385-F005AB5C71D4}c:\\program files\\left 4 dead\\left4dead.exe"= TCP:c:\program files\left 4 dead\left4dead.exe:left4dead "{B658BB4C-29EC-4A5D-9E3F-ECC98E5304E5}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook "{0FACA8F0-6BB6-4460-943C-7F643A60CE3F}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove "{D296CA6A-DB3F-4F18-914D-B554FBA9AD62}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove "{4CD86C2B-C1DE-4652-AF60-7FD94581DB94}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{38A34AFC-5B7D-4B1B-905C-F0CFB609272F}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "TCP Query User{87156E94-9DEF-4FB5-866A-D19A08B04DCE}f:\\half life\\hl2\\hl2.exe"= UDP:f:\half life\hl2\hl2.exe:hl2 "UDP Query User{07D91094-95B3-4CCE-A1F8-BCCF642AFC8C}f:\\half life\\hl2\\hl2.exe"= TCP:f:\half life\hl2\hl2.exe:hl2 "{BE0BD50B-800C-4199-AE63-74F501E0494E}"= UDP:c:\program files\Lavalys\EVEREST Ultimate Edition\everest.exe:EVEREST Ultimate Edition "{F9A2C16C-737E-409A-982D-CD293CF8837F}"= TCP:c:\program files\Lavalys\EVEREST Ultimate Edition\everest.exe:EVEREST Ultimate Edition "TCP Query User{C8352A4C-A496-4FCC-89D7-9F5178B0A72A}c:\\program files\\bitcomet\\bitcomet.exe"= UDP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client "UDP Query User{1160E15F-F4FE-477E-B6B3-2B26F97A6841}c:\\program files\\bitcomet\\bitcomet.exe"= TCP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client "TCP Query User{9F2A8CF4-8203-4F01-8B79-E5278EB8AE14}c:\\windows\\explorer.exe"= UDP:c:\windows\explorer.exe:Windows Explorer "UDP Query User{9BAD5322-E370-448A-A36F-6EEAF637E101}c:\\windows\\explorer.exe"= TCP:c:\windows\explorer.exe:Windows Explorer "{9946B689-4843-494C-A639-0F5202DAF3D0}"= UDP:17804:BitComet 17804 TCP "{8E93DEDD-8DAE-4B26-84CE-F4BF73EAE93F}"= TCP:17804:BitComet 17804 UDP "{94C90566-97C0-4D31-A77F-0574EA643D6E}"= UDP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9 "{5275B171-726F-425F-8052-8F41EE77F9F8}"= TCP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9 "{9E89D40F-7D6A-4FEC-A8DB-D13A5C6E2525}"= UDP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10 "{A82881B4-3C35-45BC-8017-D4E8FC9AD9B0}"= TCP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10 "{958B2B9E-523D-4D43-99BC-5D0578F62E23}"= UDP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update "{C3A949CF-031F-4F56-8756-4589F6BDE6A4}"= TCP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update "TCP Query User{FD86E422-D391-4D53-80C3-F0EC34BE7825}f:\\half life\\hl2\\hl2.exe"= UDP:f:\half life\hl2\hl2.exe:hl2 "UDP Query User{9AE0D4EA-DDEE-4886-8253-14A2BBF25F86}f:\\half life\\hl2\\hl2.exe"= TCP:f:\half life\hl2\hl2.exe:hl2 "{05092115-0D67-4CC8-BFBB-E04D74704BF3}"= UDP:c:\program files\Activision\X-Men Origins - Wolverine\Binaries\Wolverine.exe:X-Men Origins - Wolverine "{BC261CFE-CF5F-4236-A990-7B8139DFBA2B}"= TCP:c:\program files\Activision\X-Men Origins - Wolverine\Binaries\Wolverine.exe:X-Men Origins - Wolverine "{3F142349-23D7-45BA-9533-8167D9C46CB4}"= c:\program files\Skype\Phone\Skype.exe:Skype "{5CD145D9-D607-45CA-AC40-5EAB00A3A0A9}"= UDP:f:\rockstar games\Rockstar Games Social Club\RGSCLauncher.exe:Rockstar Games Social Club "{920D8BF9-403A-4277-9818-684822C6A675}"= TCP:f:\rockstar games\Rockstar Games Social Club\RGSCLauncher.exe:Rockstar Games Social Club "{74632C98-0192-4C53-A345-4C9FFAE08664}"= UDP:f:\rockstar games\Grand Theft Auto IV\LaunchGTAIV.exe:Grand Theft Auto IV "{171565A4-B6F6-496D-B33B-01216524ECD7}"= TCP:f:\rockstar games\Grand Theft Auto IV\LaunchGTAIV.exe:Grand Theft Auto IV "TCP Query User{612159B0-E64D-4111-90C4-8E5E8078091B}f:\\rockstar games\\grand theft auto iv\\gtaiv.exe"= UDP:f:\rockstar games\grand theft auto iv\gtaiv.exe:Grand Theft Auto IV "UDP Query User{9FA4F7DC-3DFF-4535-8526-ABE944199B6B}f:\\rockstar games\\grand theft auto iv\\gtaiv.exe"= TCP:f:\rockstar games\grand theft auto iv\gtaiv.exe:Grand Theft Auto IV "TCP Query User{30DC198A-9802-46EA-AF57-2F90A4C8A8AA}c:\\program files\\common files\\nero\\nero web\\setupx.exe"= UDP:c:\program files\common files\nero\nero web\setupx.exe:Nero Installer "UDP Query User{7CEE600E-2A67-4E29-BA2A-71EDB8261D5A}c:\\program files\\common files\\nero\\nero web\\setupx.exe"= TCP:c:\program files\common files\nero\nero web\setupx.exe:Nero Installer "TCP Query User{2FA6753E-7D33-4558-84E0-F0A1897A653B}c:\\users\\user\\appdata\\local\\temp\\onlineupdate8\\setupxu.exe"= UDP:c:\users\user\appdata\local\temp\onlineupdate8\setupxu.exe:setupxu.exe "UDP Query User{0C8A11A1-DD20-494C-8CA6-0EE97FEB0B9E}c:\\users\\user\\appdata\\local\\temp\\onlineupdate8\\setupxu.exe"= TCP:c:\users\user\appdata\local\temp\onlineupdate8\setupxu.exe:setupxu.exe R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\AEstSrv.exe [27.9.2008 і. 11:18 73728] R2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe -k netsvcs [21.1.2008 і. 05:23 21504] R2 hpsrv;HP Service;c:\windows\System32\hpservice.exe [19.3.2008 і. 02:24 19456] R2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\SMINST\BLService.exe [2.7.2008 і. 21:26 341328] R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2.7.2008 і. 20:29 193840] R3 enecir;ENE CIR Receiver;c:\windows\System32\drivers\enecir.sys [24.1.2008 і. 16:23 52736] R3 JMCR;JMCR;c:\windows\System32\drivers\jmcr.sys [17.4.2009 і. 09:48 114528] R3 NETw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\System32\drivers\NETw5v32.sys [17.11.2008 і. 15:40 3668480] R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\System32\drivers\nvhda32v.sys [23.5.2008 і. 06:29 43552] S3 EverestDriver;Lavalys EVEREST Kernel Driver;f:\downloads\Everest Ultimate Engineer Edition 5.00.1692 (multi)\Everest Ultimate Engineer Edition 5.00.1692 (Multilanguage)\kerneld.wnt [16.5.2009 і. 12:14 26224] --- Other Services/Drivers In Memory --- *Deregistered* - sptd [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs REG_MULTI_SZ BthServ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs ezSharedSvc [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] "c:\program files\Common Files\LightScribe\LSRunOnce.exe" . Contents of the 'Scheduled Tasks' folder 2009-05-27 c:\windows\Tasks\User_Feed_Synchronization-{A1953874-5815-44FF-9509-2C81765588EE}.job - c:\windows\system32\msfeedssync.exe [2009-05-09 11:31] 2009-05-27 c:\windows\Tasks\User_Feed_Synchronization-{DD313412-8BC6-47F1-9C0C-AFFFC1E7DD33}.job - c:\windows\system32\msfeedssync.exe [2009-05-09 11:31] . - - - - ORPHANS REMOVED - - - - SafeBoot-procexp90.Sys . ------- Supplementary Scan ------- . uStart Page = hxxp://######/ IE: &AOL Toolbar Search - c:\programdata\AOL\ieToolbar\resources\en-GB\local\search.html IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-05-27 20:47 Windows 6.0.6001 Service Pack 1 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\EverestDriver] "ImagePath"="\??\f:\downloads\Everest Ultimate Engineer Edition 5.00.1692 (multi)\Everest Ultimate Engineer Edition 5.00.1692 (Multilanguage)\kerneld.wnt" . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-2514056171-1166224141-2149493090-1000\Software\SecuROM\License information*] "datasecu"=hex:21,01,9b,3c,56,e4,6d,1b,00,1f,54,9b,b7,77,fa,fe,aa,5e,96,90,29, 05,f4,09,c4,ab,3f,16,c6,63,28,1b,9f,99,bc,70,e7,ed,74,c8,a7,d8,72,dc,ab,f3,\ "rkeysecu"=hex:c1,7f,15,d2,4b,40,f2,1f,fb,ab,85,2a,cf,91,ec,eb . Completion time: 2009-05-27 20:48 ComboFix-quarantined-files.txt 2009-05-27 17:48 Pre-Run: 59 703 152 640 bytes free Post-Run: 65 630 097 408 bytes free 362 --- E O F --- 2009-05-27 17:42
-
HiJackThis/Log :Оптимизация/Анализ/Ревю
Това е лога на hijack Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 20:13 ч., on 27.5.2009 г. Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files\HP\QuickPlay\QPService.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\IDT\WDM\sttray.exe C:\Windows\System32\rundll32.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\ehome\ehtray.exe C:\Program Files\DAEMON Tools Lite\daemon.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\Datecs\FlexType 2K\FType2K.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe C:\Program Files\Skype\Plugin Manager\skypePM.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Nero\Nero8\Nero StartSmart\NeroStartSmart.exe C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe C:\Windows\system32\wuauclt.exe C:\Program Files\Common Files\Nero\Nero Web\SetupX.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\User\Desktop\HiJackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://######/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe O1 - Hosts: ::1 localhost O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [iAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe O4 - HKLM\..\Run: [uCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0" O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe" O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [batteryBar] c:\program files\batterybar\batterybar.exe O4 - HKLM\..\Run: [sysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [RGSC] F:\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent O4 - HKCU\..\Run: [indxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020 O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE') O4 - Global Startup: Bluetooth.lnk = ? O4 - Global Startup: FlexType 2K.lnk = C:\Program Files\Datecs\FlexType 2K\FType2K.exe O8 - Extra context menu item: &AOL Toolbar Search - C:\ProgramData\AOL\ieToolbar\resources\en-GB\local\search.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O13 - Gopher Prefix: O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\aestsrv.exe O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe O23 - Service: HP Service (hpsrv) - Hewlett-Packard Corporation - C:\Windows\system32\Hpservice.exe O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_a7e996cd\STacSV.exe -- End of file - 10139 bytes А това е от malwarebytes Malwarebytes' Anti-Malware 1.37 Database version: 2185 Windows 6.0.6001 Service Pack 1 27.5.2009 г. 20:04:23 mbam-log-2009-05-27 (20-04-23).txt Scan type: Full Scan (C:\|D:\|E:\|F:\|G:\|H:\|I:\|) Objects scanned: 375662 Time elapsed: 1 hour(s), 39 minute(s), 15 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 1 Registry Data Items Infected: 0 Folders Infected: 1 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\internet security service (Backdoor.IRCBot) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013 (Backdoor.IRCBot) -> Quarantined and deleted successfully. Files Infected: c:\RESTORE\s-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini (Backdoor.IRCBot) -> Quarantined and deleted successfully. c:\RESTORE\s-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe (Backdoor.IRCBot) -> Quarantined and deleted successfully. Благодаря за помоща
-
HiJackThis/Log :Оптимизация/Анализ/Ревю
това е от скан с hijackthis имам проблеми с ise32.exe постоянно ми забива компа и ми блокира task managera.бихте ли ми казали какво да направя за го изчистя. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 15:52 ч., on 27.5.2009 г. Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files\HP\QuickPlay\QPService.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\IDT\WDM\sttray.exe C:\Windows\System32\rundll32.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\ehome\ehtray.exe C:\Program Files\DAEMON Tools Lite\daemon.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\Datecs\FlexType 2K\FType2K.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Skype\Plugin Manager\skypePM.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\taskmgr.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\SearchFilterHost.exe C:\Program Files\Trend Micro\HijackThis\post.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...ion&pf=cnnb R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://######/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...ion&pf=cnnb R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...ion&pf=cnnb R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe O1 - Hosts: ::1 localhost O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [iAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe O4 - HKLM\..\Run: [uCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0" O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe" O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [batteryBar] c:\program files\batterybar\batterybar.exe O4 - HKLM\..\Run: [sysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [RGSC] F:\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent O4 - HKCU\..\Run: [indxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020 O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE') O4 - Global Startup: Bluetooth.lnk = ? O4 - Global Startup: FlexType 2K.lnk = C:\Program Files\Datecs\FlexType 2K\FType2K.exe O8 - Extra context menu item: &AOL Toolbar Search - C:\ProgramData\AOL\ieToolbar\resources\en-GB\local\search.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll O13 - Gopher Prefix: O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://cache.systemrequirementslab.com/htd...sreqlab_srl.cab O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\aestsrv.exe O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe O23 - Service: HP Service (hpsrv) - Hewlett-Packard Corporation - C:\Windows\system32\Hpservice.exe O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_a7e996cd\STacSV.exe -- End of file - 11626 bytes
-
Въпроси за избор на лаптоп
Здравейте,кой от тези процесори е по-добър и голяма ли е разликата в производителността Intel Pentium Dual-Core T3400 (2.16GHz, 667MHz FSB, 1MB L2 Cache) и Intel Core 2 Duo T5800 (2.0GHz, 2MB L2 Cache, 800 MHz FSB)? Става въпрос за тези два лаптопа: http://laptop.bg/#/details/ACER/7/1916 и http://laptop.bg/#/details/ACER/7/1917
Разглеждащи това в момента 0
- Няма регистрирани потребители разглеждащи тази страница.