Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

poslushen

Потребител
  • Регистрация

  • Последно онлайн

  1. изпълних инструкциите ето лога: прикачвам файла защото: Коментарът ви е прекалено дълъг. Моля върнете се и го съкратете log.txt
  2. да, и натоварването от svhost на процесора изчезна, ето лога: ComboFix 10-02-26.01 - Adrian 02.2010 г. 6:24.2.1 - x86 Microsoft Windows XP Professional 5.1.2600.2.1251.359.1033.18.447.200 [GMT 2:00] Running from: c:\documents and settings\Adrian\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Adrian\Desktop\CFScript.txt AV: ESET NOD32 antivirus system 2.70 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} * Resident AV is active file zipped: c:\documents and settings\LocalService\Application Data\rbuwzv.dat file zipped: c:\documents and settings\NetworkService\Application Data\rbuwzv.dat file zipped: c:\windows\popcinfo.dat file zipped: c:\windows\system.tmp file zipped: c:\windows\system32\config\systemprofile\Application Data\rbuwzv.dat . The following files were disabled during the run: c:\progra~1\SPYWAR~1\Tools\swpg.dat ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\LocalService\Application Data\rbuwzv.dat c:\documents and settings\NetworkService\Application Data\rbuwzv.dat c:\windows\popcinfo.dat c:\windows\system.tmp c:\windows\system32\config\systemprofile\Application Data\rbuwzv.dat . ((((((((((((((((((((((((( Files Created from 2010-01-27 to 2010-02-27 ))))))))))))))))))))))))))))))) . 2010-02-27 03:21 . 2010-02-27 03:22 -------- d-----w- C:\HJT 2010-02-27 02:38 . 2010-02-27 02:38 -------- d-----w- c:\documents and settings\Adrian\Application Data\Malwarebytes 2010-02-27 02:38 . 2010-01-07 14:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-02-27 02:38 . 2010-02-27 02:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2010-02-27 02:38 . 2010-01-07 14:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-02-27 02:38 . 2010-02-27 02:38 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2010-02-27 00:09 . 2005-12-13 13:18 50048 ----a-w- c:\windows\system32\drivers\ikhlayer.sys 2010-02-27 00:08 . 2010-02-27 01:16 -------- d-----w- c:\program files\Spyware Doctor 2010-02-27 00:08 . 2010-02-27 00:08 -------- d-----w- c:\documents and settings\Adrian\Application Data\PC Tools 2010-02-26 21:55 . 2010-02-26 23:51 -------- d-----w- c:\windows\BDOSCAN8 2010-02-26 16:15 . 2010-02-26 16:15 -------- d-sh--w- c:\documents and settings\Adrian\PrivacIE 2010-02-26 16:15 . 2010-02-26 16:15 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache 2010-02-26 16:14 . 2010-02-26 16:14 -------- d-sh--w- c:\documents and settings\Adrian\IETldCache 2010-02-26 16:05 . 2010-02-26 16:05 -------- dc-h--w- c:\windows\ie8 2010-02-26 04:22 . 2004-08-03 21:00 8192 -c--a-w- c:\windows\system32\dllcache\i2omgmt.sys 2010-02-26 04:22 . 2004-08-03 21:00 8192 ----a-w- c:\windows\system32\drivers\i2omgmt.sys 2010-02-26 04:22 . 2004-08-03 20:59 34688 -c--a-w- c:\windows\system32\dllcache\lbrtfdc.sys 2010-02-26 04:22 . 2004-08-03 20:59 34688 ----a-w- c:\windows\system32\drivers\lbrtfdc.sys 2010-02-26 04:22 . 2004-08-03 21:00 8192 -c--a-w- c:\windows\system32\dllcache\changer.sys 2010-02-26 04:22 . 2004-08-03 21:00 8192 ----a-w- c:\windows\system32\drivers\Changer.sys 2010-02-26 03:09 . 2010-02-26 03:10 5515984 ----a-w- c:\documents and settings\Adrian\Application Data\TVU Networks\AutoUpgrade\TVUPlayer2.5.2.1.exe 2010-02-26 02:46 . 2010-02-26 02:46 -------- d-----w- c:\program files\Photodex 2010-02-26 02:46 . 2010-02-26 02:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Photodex 2010-02-26 02:46 . 2010-02-26 02:46 -------- d-----w- c:\documents and settings\Adrian\Application Data\Photodex 2010-02-11 19:25 . 2010-02-26 22:29 -------- d-----w- c:\program files\PokerStars 2010-02-07 12:56 . 2010-02-27 01:55 -------- d-----w- c:\program files\Common Files\Symantec Shared 2010-02-05 20:22 . 2008-03-05 14:03 479752 ----a-w- c:\windows\system32\XAudio2_0.dll 2010-02-05 20:22 . 2008-03-05 14:03 238088 ----a-w- c:\windows\system32\xactengine3_0.dll 2010-02-05 20:22 . 2008-03-05 14:00 25608 ----a-w- c:\windows\system32\X3DAudio1_3.dll 2010-02-05 20:22 . 2008-03-05 13:56 1420824 ----a-w- c:\windows\system32\D3DCompiler_37.dll 2010-02-05 20:22 . 2008-02-05 21:07 462864 ----a-w- c:\windows\system32\d3dx10_37.dll 2010-02-05 20:22 . 2008-03-05 13:56 3786760 ----a-w- c:\windows\system32\D3DX9_37.dll 2010-01-30 17:21 . 2010-02-27 01:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton 2010-01-30 17:21 . 2010-01-30 17:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec 2010-01-30 17:21 . 2010-01-30 17:21 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller 2010-01-30 14:20 . 2010-01-30 14:24 -------- d-----w- c:\windows\system32\Adobe 2010-01-29 17:06 . 2010-02-06 23:35 -------- d-----w- c:\program files\Videos 2010-01-29 16:37 . 2010-01-29 16:37 -------- d-----w- c:\documents and settings\Adrian\Application Data\FastStone 2010-01-29 16:37 . 2010-01-29 16:37 -------- d-----w- c:\program files\FastStone Capture . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-02-27 04:31 . 2010-02-27 04:31 827 ----a-w- c:\windows\system.tmp 2010-02-27 02:22 . 2009-02-07 00:35 -------- d-----w- c:\program files\Pazera_Free_FLV_to_AVI_Converter 2010-02-27 01:23 . 2009-07-03 06:47 -------- d-----w- c:\documents and settings\Adrian\Application Data\FileZilla 2010-02-25 21:52 . 2008-05-23 16:55 -------- d-----w- c:\documents and settings\Adrian\Application Data\skypePM 2010-02-23 16:51 . 2008-05-23 16:55 -------- d-----w- c:\documents and settings\Adrian\Application Data\Skype 2010-02-11 19:23 . 2010-01-21 22:10 -------- d-----w- c:\program files\PokerStars.NET 2010-01-21 19:01 . 2008-05-23 16:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype 2010-01-18 13:42 . 2010-01-18 13:42 -------- d-----w- c:\documents and settings\Adrian\Application Data\Media Player Classic 2010-01-18 13:42 . 2010-01-18 13:42 -------- d-----w- c:\program files\K-Lite Codec Pack 2010-01-18 13:41 . 2010-01-18 13:00 -------- d-----w- c:\program files\ACE Mega CoDecS Pack 2010-01-18 12:51 . 2010-01-18 12:07 -------- d-----w- c:\program files\BSR Screen Recorder 4 2010-01-18 12:13 . 2010-01-18 12:07 2048 ----a-w- c:\windows\system32\Tr_sttool.dat 2009-12-29 06:38 . 2009-12-29 06:33 -------- d-----w- c:\program files\TGIANT 2009-12-22 14:56 . 2008-05-23 14:46 38664 ----a-w- c:\documents and settings\Adrian\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-10-02 19:40 . 2009-10-02 19:33 120566929 ----a-w- c:\program files\Championship Manager 01-02.rar 2008-07-31 16:59 . 2008-06-03 20:20 61038 ----a-w- c:\program files\mozilla firefox\components\jar50.dll 2008-07-31 16:59 . 2008-06-03 20:20 49256 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll 2008-07-31 16:59 . 2008-06-03 20:20 166000 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll 2005-05-13 15:12 . 2005-05-13 15:12 217073 --sha-r- c:\windows\meta4.exe 2005-10-24 09:13 . 2005-10-24 09:13 66560 --sha-r- c:\windows\MOTA113.exe 2005-10-13 19:27 . 2005-10-13 19:27 422400 --sha-r- c:\windows\x2.64.exe 2005-10-07 17:14 . 2005-10-07 17:14 308224 --sha-r- c:\windows\system32\avisynth.dll 2005-07-14 10:31 . 2005-07-14 10:31 27648 --sha-r- c:\windows\system32\AVSredirect.dll 2005-06-26 13:32 . 2005-06-26 13:32 616448 --sha-r- c:\windows\system32\cygwin1.dll 2005-06-21 20:37 . 2005-06-21 20:37 45568 --sha-r- c:\windows\system32\cygz.dll 2004-01-24 22:00 . 2004-01-24 22:00 70656 --sha-r- c:\windows\system32\i420vfw.dll 2006-04-27 08:24 . 2006-04-27 08:24 2945024 --sha-r- c:\windows\system32\Smab.dll 2005-02-28 11:16 . 2005-02-28 11:16 240128 --sha-r- c:\windows\system32\x.264.exe 2004-01-24 22:00 . 2004-01-24 22:00 217088 --sha-r- c:\windows\system32\yv12vfw.dll . (((((((((((((((((((((((((((((((((((((((((( SR_Search )))))))))))))))))))))))))))))))))))))))))))))))))))))))) . ------- Sigcheck ------- [-] 2008-05-22 . 6E266AAF4168B3569A330C61AB01F6B4 . 1580544 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll . ((((((((((((((((((((((((((((((((((((((( System Restore ))))))))))))))))))))))))))))))))))))))))))))))))))) . c:\12c762eb1b4771c079de44\admparse.dll 08.03.2009 г. 04:32 72704 \RP2\A0000097.dll c:\12c762eb1b4771c079de44\advpack.dll 08.03.2009 г. 04:32 128512 \RP2\A0000096.dll c:\12c762eb1b4771c079de44\browseui.dll 07.01.2009 г. 18:20 1022976 \RP2\A0000095.dll c:\12c762eb1b4771c079de44\corpol.dll 08.03.2009 г. 04:33 18944 \RP2\A0000094.dll c:\12c762eb1b4771c079de44\dxtmsft.dll 08.03.2009 г. 04:31 348160 \RP2\A0000093.dll c:\12c762eb1b4771c079de44\dxtrans.dll 08.03.2009 г. 04:31 216064 \RP2\A0000092.dll c:\12c762eb1b4771c079de44\extexport.exe 08.03.2009 г. 04:35 144384 \RP2\A0000043.exe c:\12c762eb1b4771c079de44\hmmapi.dll 08.03.2009 г. 04:24 68608 \RP2\A0000091.dll c:\12c762eb1b4771c079de44\icardie.dll 08.03.2009 г. 04:31 59904 \RP2\A0000090.dll c:\12c762eb1b4771c079de44\ie4uinit.exe 08.03.2009 г. 04:32 173056 \RP2\A0000042.exe c:\12c762eb1b4771c079de44\ieakeng.dll 08.03.2009 г. 04:33 125952 \RP2\A0000089.dll c:\12c762eb1b4771c079de44\ieaksie.dll 08.03.2009 г. 04:33 229376 \RP2\A0000088.dll c:\12c762eb1b4771c079de44\ieakui.dll 08.03.2009 г. 04:32 163840 \RP2\A0000087.dll c:\12c762eb1b4771c079de44\ieapfltr.dll 08.03.2009 г. 04:11 445952 \RP2\A0000086.dll c:\12c762eb1b4771c079de44\iecompat.dll 08.03.2009 г. 04:35 2048 \RP2\A0000085.dll c:\12c762eb1b4771c079de44\iedkcs32.dll 08.03.2009 г. 14:09 391536 \RP2\A0000084.dll c:\12c762eb1b4771c079de44\iedvtool.dll 08.03.2009 г. 04:35 742912 \RP2\A0000083.dll c:\12c762eb1b4771c079de44\ieframe.dll 08.03.2009 г. 04:39 11063808 \RP2\A0000082.dll c:\12c762eb1b4771c079de44\iepeers.dll 08.03.2009 г. 04:31 183808 \RP2\A0000081.dll c:\12c762eb1b4771c079de44\ieproxy.dll 08.03.2009 г. 04:33 246784 \RP2\A0000080.dll c:\12c762eb1b4771c079de44\iernonce.dll 08.03.2009 г. 04:32 55808 \RP2\A0000079.dll c:\12c762eb1b4771c079de44\iertutil.dll 08.03.2009 г. 04:32 1985024 \RP2\A0000078.dll c:\12c762eb1b4771c079de44\iesetup.dll 08.03.2009 г. 04:32 71680 \RP2\A0000077.dll c:\12c762eb1b4771c079de44\ieudinit.exe 08.03.2009 г. 04:32 36864 \RP2\A0000041.exe c:\12c762eb1b4771c079de44\ieui.dll 08.03.2009 г. 04:22 164352 \RP2\A0000076.dll c:\12c762eb1b4771c079de44\iexplore.exe 08.03.2009 г. 14:09 638816 \RP2\A0000040.exe c:\12c762eb1b4771c079de44\imgutil.dll 08.03.2009 г. 04:31 34816 \RP2\A0000075.dll c:\12c762eb1b4771c079de44\inseng.dll 08.03.2009 г. 04:32 94720 \RP2\A0000074.dll c:\12c762eb1b4771c079de44\jscript.dll 08.03.2009 г. 04:33 726528 \RP2\A0000073.dll c:\12c762eb1b4771c079de44\jsdbgui.dll 08.03.2009 г. 04:35 521216 \RP2\A0000072.dll c:\12c762eb1b4771c079de44\jsdebuggeride.dll 08.03.2009 г. 04:35 121344 \RP2\A0000071.dll c:\12c762eb1b4771c079de44\jsprofilercore.dll 08.03.2009 г. 04:35 118272 \RP2\A0000070.dll c:\12c762eb1b4771c079de44\jsprofilerui.dll 08.03.2009 г. 04:35 233984 \RP2\A0000069.dll c:\12c762eb1b4771c079de44\jsproxy.dll 08.03.2009 г. 04:33 25600 \RP2\A0000068.dll c:\12c762eb1b4771c079de44\licmgr10.dll 08.03.2009 г. 04:34 43008 \RP2\A0000067.dll c:\12c762eb1b4771c079de44\msdbg2.dll 07.01.2009 г. 18:20 265720 \RP2\A0000066.dll c:\12c762eb1b4771c079de44\msfeeds.dll 08.03.2009 г. 04:32 594432 \RP2\A0000065.dll c:\12c762eb1b4771c079de44\msfeedsbs.dll 08.03.2009 г. 04:31 55296 \RP2\A0000064.dll c:\12c762eb1b4771c079de44\msfeedssync.exe 08.03.2009 г. 04:31 13312 \RP2\A0000039.exe c:\12c762eb1b4771c079de44\mshta.exe 08.03.2009 г. 04:31 45568 \RP2\A0000038.exe c:\12c762eb1b4771c079de44\mshtml.dll 08.03.2009 г. 04:41 5937152 \RP2\A0000063.dll c:\12c762eb1b4771c079de44\mshtmled.dll 08.03.2009 г. 04:31 66560 \RP2\A0000062.dll c:\12c762eb1b4771c079de44\mshtmler.dll 08.03.2009 г. 04:31 48128 \RP2\A0000061.dll c:\12c762eb1b4771c079de44\msls31.dll 08.03.2009 г. 04:22 156160 \RP2\A0000060.dll c:\12c762eb1b4771c079de44\msrating.dll 08.03.2009 г. 04:34 193536 \RP2\A0000059.dll c:\12c762eb1b4771c079de44\mstime.dll 08.03.2009 г. 04:32 611840 \RP2\A0000058.dll c:\12c762eb1b4771c079de44\occache.dll 08.03.2009 г. 04:34 109568 \RP2\A0000057.dll c:\12c762eb1b4771c079de44\pdm.dll 07.01.2009 г. 18:20 355832 \RP2\A0000056.dll c:\12c762eb1b4771c079de44\pngfilt.dll 08.03.2009 г. 04:31 46592 \RP2\A0000055.dll c:\12c762eb1b4771c079de44\shdocvw.dll 07.01.2009 г. 18:20 1497088 \RP2\A0000054.dll c:\12c762eb1b4771c079de44\shlwapi.dll 07.01.2009 г. 18:20 474112 \RP2\A0000053.dll c:\12c762eb1b4771c079de44\spmsg.dll 07.01.2009 г. 18:20 16928 \RP2\A0000052.dll c:\12c762eb1b4771c079de44\spuninst.exe 07.01.2009 г. 18:20 231456 \RP2\A0000037.exe c:\12c762eb1b4771c079de44\spupdsvc.exe 07.01.2009 г. 18:21 26144 \RP2\A0000036.exe c:\12c762eb1b4771c079de44\sqmapi.dll 07.01.2009 г. 18:20 134144 \RP2\A0000051.dll c:\12c762eb1b4771c079de44\support\idndl.dll 07.01.2009 г. 18:20 26112 \RP2\A0000024.dll c:\12c762eb1b4771c079de44\support\nlsdl.dll 07.01.2009 г. 18:20 24576 \RP2\A0000023.dll c:\12c762eb1b4771c079de44\support\normaliz.dll 07.01.2009 г. 18:20 23552 \RP2\A0000022.dll c:\12c762eb1b4771c079de44\support\xmllite.dll 07.01.2009 г. 18:21 121856 \RP2\A0000021.dll c:\12c762eb1b4771c079de44\update\iecustom.dll 08.03.2009 г. 14:23 58464 \RP2\A0000019.dll c:\12c762eb1b4771c079de44\update\iesetup.exe 08.03.2009 г. 14:23 1113696 \RP2\A0000016.exe c:\12c762eb1b4771c079de44\update\sqmapi.dll 08.03.2009 г. 14:23 141408 \RP2\A0000018.dll c:\12c762eb1b4771c079de44\update\update.exe 07.01.2009 г. 18:21 755744 \RP2\A0000015.exe c:\12c762eb1b4771c079de44\update\updspapi.dll 07.01.2009 г. 18:21 382496 \RP2\A0000017.dll c:\12c762eb1b4771c079de44\url.dll 08.03.2009 г. 04:34 105984 \RP2\A0000050.dll c:\12c762eb1b4771c079de44\urlmon.dll 08.03.2009 г. 04:34 1206784 \RP2\A0000049.dll c:\12c762eb1b4771c079de44\vbscript.dll 08.03.2009 г. 04:33 420352 \RP2\A0000048.dll c:\12c762eb1b4771c079de44\vgx.dll 08.03.2009 г. 04:33 759296 \RP2\A0000047.dll c:\12c762eb1b4771c079de44\webcheck.dll 08.03.2009 г. 04:34 236544 \RP2\A0000046.dll c:\12c762eb1b4771c079de44\winfxdocobj.exe 08.03.2009 г. 04:34 208384 \RP2\A0000035.exe c:\12c762eb1b4771c079de44\wininet.dll 08.03.2009 г. 04:34 914944 \RP2\A0000045.dll c:\12c762eb1b4771c079de44\xpshims.dll 08.03.2009 г. 04:33 12288 \RP2\A0000044.dll c:\32788r22fwjfw\SF.exe 10.06.2006 г. 14:42 49152 \RP3\A0000785.exe c:\avenger\winesm32.exe 04.08.2004 г. 00:56 29184 \RP3\A0000776.exe c:\documents and settings\Adrian\Application Data\Sun\Java\jre1.6.0_10\lzma.dll 19.11.2008 г. 00:42 152576 \RP2\A0000218.dll C:\ie4uinit.exe 13.08.2007 г. 17:39 54784 \RP2\A0000107.exe c:\program files\Ahead\CoverDesigner\CoverDes.exe 01.02.2005 г. 12:31 2412544 \RP3\A0000434.exe c:\program files\Ahead\ImageDrive\idriveinst.dll 02.03.2004 г. 15:37 90112 \RP3\A0000521.dll c:\program files\Ahead\ImageDrive\ImageDrive.exe 30.11.2004 г. 11:31 893016 \RP3\A0000523.exe c:\program files\Ahead\ImageDrive\imagedrv.dll 02.03.2004 г. 15:37 118784 \RP3\A0000524.dll c:\program files\Ahead\Nero BackItUp\BackItUp.exe 10.02.2005 г. 17:36 5734400 \RP3\A0000435.exe c:\program files\Ahead\Nero BackItUp\NBJ.exe 10.02.2005 г. 16:00 1937408 \RP3\A0000436.exe c:\program files\Ahead\Nero BackItUp\NBR.exe 10.02.2005 г. 16:01 1159168 \RP3\A0000437.exe c:\program files\Ahead\Nero SoundTrax\SoundTrax.exe 01.02.2005 г. 12:54 1830999 \RP3\A0000519.exe c:\program files\Ahead\Nero StartSmart\NeroStartSmart.exe 21.01.2005 г. 18:12 4714582 \RP3\A0000438.exe c:\program files\Ahead\Nero Toolkit\CDSpeed.exe 09.02.2005 г. 22:25 1220608 \RP3\A0000509.exe c:\program files\Ahead\Nero Toolkit\DriveSpeed.exe 18.12.2004 г. 22:01 593920 \RP3\A0000510.exe c:\program files\Ahead\Nero Toolkit\hwinfo.exe 10.03.2003 г. 11:10 11568 \RP3\A0000512.exe c:\program files\Ahead\Nero Toolkit\InfoTool.exe 19.01.2005 г. 16:01 524288 \RP3\A0000511.exe c:\program files\Ahead\Nero Wave Editor\DXEnum.exe 01.02.2005 г. 12:49 122980 \RP3\A0000513.exe c:\program files\Ahead\Nero Wave Editor\waveedit.dll 01.02.2005 г. 12:53 1802332 \RP3\A0000514.dll c:\program files\Ahead\Nero Wave Editor\WaveEdit.exe 01.02.2005 г. 12:49 118877 \RP3\A0000515.exe c:\program files\Ahead\Nero\AudioPluginMgr.dll 01.02.2005 г. 10:53 106578 \RP3\A0000452.dll c:\program files\Ahead\Nero\CDCopy.dll 11.03.2005 г. 14:52 208967 \RP3\A0000453.dll c:\program files\Ahead\Nero\cdr100.dll 11.03.2005 г. 14:48 233546 \RP3\A0000454.dll c:\program files\Ahead\Nero\cdr50s.dll 11.03.2005 г. 14:48 245831 \RP3\A0000455.dll c:\program files\Ahead\Nero\CDROM.dll 11.03.2005 г. 14:48 258118 \RP3\A0000456.dll c:\program files\Ahead\Nero\cdu920.dll 11.03.2005 г. 14:48 278599 \RP3\A0000457.dll c:\program files\Ahead\Nero\cr2200cs.dll 11.03.2005 г. 14:48 237641 \RP3\A0000458.dll c:\program files\Ahead\Nero\Drweb32.dll 01.10.2003 г. 13:02 627200 \RP3\A0000460.dll c:\program files\Ahead\Nero\DVDREALLOC.dll 01.10.2003 г. 13:02 102400 \RP3\A0000461.dll c:\program files\Ahead\Nero\Dws114x.dll 11.03.2005 г. 14:48 229448 \RP3\A0000462.dll c:\program files\Ahead\Nero\em2v.dll 16.02.2005 г. 09:55 176128 \RP3\A0000459.dll c:\program files\Ahead\Nero\Equalize.dll 11.03.2005 г. 14:52 110671 \RP3\A0000463.dll c:\program files\Ahead\Nero\FATImporter.dll 11.03.2005 г. 15:18 184396 \RP3\A0000464.dll c:\program files\Ahead\Nero\GENCUSH.dll 11.03.2005 г. 14:53 77896 \RP3\A0000465.dll c:\program files\Ahead\Nero\Generatr.dll 11.03.2005 г. 14:50 77903 \RP3\A0000466.dll c:\program files\Ahead\Nero\GenFAT.dll 11.03.2005 г. 14:57 176202 \RP3\A0000467.dll c:\program files\Ahead\Nero\geniso.dll 11.03.2005 г. 14:50 225354 \RP3\A0000468.dll c:\program files\Ahead\Nero\GenPCHy.dll 11.03.2005 г. 14:51 233544 \RP3\A0000469.dll c:\program files\Ahead\Nero\GenUDF.dll 11.03.2005 г. 14:51 311370 \RP3\A0000470.dll c:\program files\Ahead\Nero\image.dll 11.03.2005 г. 14:48 135238 \RP3\A0000471.dll c:\program files\Ahead\Nero\ImageGen.dll 11.03.2005 г. 14:50 106569 \RP3\A0000472.dll c:\program files\Ahead\Nero\ims.dll 11.03.2005 г. 14:49 241732 \RP3\A0000473.dll c:\program files\Ahead\Nero\ISOFS.dll 11.03.2005 г. 14:49 196678 \RP3\A0000474.dll c:\program files\Ahead\Nero\KARAOKE.dll 01.10.2003 г. 13:02 28160 \RP3\A0000475.dll c:\program files\Ahead\Nero\mfc42.DLL 23.08.2001 г. 12:00 995383 \RP3\A0000446.DLL c:\program files\Ahead\Nero\MMC.dll 11.03.2005 г. 14:49 696388 \RP3\A0000476.dll c:\program files\Ahead\Nero\MPGEnc.dll 01.10.2003 г. 13:02 139264 \RP3\A0000477.dll c:\program files\Ahead\Nero\msvcrt.dll 04.05.2001 г. 10:05 290869 \RP3\A0000447.dll c:\program files\Ahead\Nero\NeEm2a.dll 16.02.2005 г. 09:55 274432 \RP3\A0000486.dll c:\program files\Ahead\Nero\NeHDBlkAccess.dll 11.03.2005 г. 15:01 102492 \RP3\A0000478.dll c:\program files\Ahead\Nero\NeMP3Dmo.dll 11.03.2005 г. 15:18 471113 \RP3\A0000479.dll c:\program files\Ahead\Nero\NeMP3Hlp.dll 11.03.2005 г. 14:52 81998 \RP3\A0000480.dll c:\program files\Ahead\Nero\nero.exe 11.03.2005 г. 15:18 15376454 \RP3\A0000448.exe c:\program files\Ahead\Nero\neroAPI.dll 11.03.2005 г. 15:23 3211340 \RP3\A0000481.dll c:\program files\Ahead\Nero\NeroCmd.exe 29.10.2004 г. 08:11 151552 \RP3\A0000449.exe c:\program files\Ahead\Nero\NeroCom.dll 19.10.2004 г. 15:06 372736 \RP3\A0000482.dll c:\program files\Ahead\Nero\neroDB.dll 11.03.2005 г. 14:52 249930 \RP3\A0000483.dll c:\program files\Ahead\Nero\neroErr.dll 11.03.2005 г. 14:46 282696 \RP3\A0000484.dll c:\program files\Ahead\Nero\NeroMediaCon.dll 16.02.2005 г. 09:55 630784 \RP3\A0000485.dll c:\program files\Ahead\Nero\NeroNet.dll 01.09.2004 г. 16:17 323584 \RP3\A0000487.dll c:\program files\Ahead\Nero\neroscsi.dll 11.03.2005 г. 14:47 159817 \RP3\A0000488.dll c:\program files\Ahead\Nero\neRSDB.dll 11.03.2005 г. 14:53 102478 \RP3\A0000489.dll c:\program files\Ahead\Nero\NetRecorder.dll 11.03.2005 г. 14:57 200788 \RP3\A0000490.dll c:\program files\Ahead\Nero\NeVCDEngine.dll 11.03.2005 г. 14:52 159826 \RP3\A0000491.dll c:\program files\Ahead\Nero\newtrf.dll 11.03.2005 г. 14:47 270407 \RP3\A0000492.dll c:\program files\Ahead\Nero\NRESTORE.EXE 14.05.2004 г. 13:56 257820 \RP3\A0000451.EXE c:\program files\Ahead\Nero\READHD16.dll 01.10.2003 г. 13:02 5120 \RP3\A0000493.dll c:\program files\Ahead\Nero\ReadHD32.dll 01.10.2003 г. 13:02 23040 \RP3\A0000494.dll c:\program files\Ahead\Nero\ro1420c.dll 11.03.2005 г. 14:49 237640 \RP3\A0000495.dll c:\program files\Ahead\Nero\SHORTCUT.DLL 16.02.2005 г. 15:16 725062 \RP3\A0000536.DLL c:\program files\Ahead\Nero\TMPVImporter.dll 11.03.2005 г. 15:19 90202 \RP3\A0000496.dll c:\program files\Ahead\Nero\UDFImporter.dll 11.03.2005 г. 15:00 491604 \RP3\A0000497.dll c:\program files\Ahead\Nero\Uninstall\UNNero.exe 17.02.2005 г. 11:21 2682880 \RP3\A0000507.exe c:\program files\Ahead\Nero\VCDMenu.dll 11.03.2005 г. 14:54 155724 \RP3\A0000498.dll c:\program files\Ahead\Nero\VMPEGEnc.dll 11.03.2005 г. 15:01 155726 \RP3\A0000499.dll c:\program files\Ahead\Nero\VMPEGEncNDX.dll 01.10.2003 г. 13:02 364544 \RP3\A0000500.dll c:\program files\Ahead\Nero\WNASPI32.DLL 26.10.2004 г. 16:35 164112 \RP3\A0000506.DLL c:\program files\Ahead\WMPBurn\NeroBurnPlugin.dll 08.01.2004 г. 15:17 331776 \RP3\A0000440.dll c:\program files\Ahead\WMPBurn\WMPBurn.exe 08.01.2004 г. 15:19 1265664 \RP3\A0000439.exe c:\program files\BitComet\Downloads\Photodex.ProShow.Gold.v4.1.2711.Incl.Keymaker-CORE\Keygen\CORE10k.EXE 26.02.2010 г. 04:44 137728 \RP2\A0000211.EXE c:\program files\BitComet\Downloads\Photodex.ProShow.Gold.v4.1.2711.Incl.Keymaker-CORE\Keygen\keygen.exe 26.02.2010 г. 04:44 126464 \RP2\A0000212.exe c:\program files\BitComet\Downloads\Photodex.ProShow.Gold.v4.1.2711.Incl.Keymaker-CORE\psgold_41_2711.exe 26.02.2010 г. 04:44 19644248 \RP2\A0000213.exe c:\program files\Common Files\Ahead\AudioPlugins\Aac.dll 26.01.2005 г. 10:38 1990656 \RP3\A0000424.dll c:\program files\Common Files\Ahead\AudioPlugins\aacenc32.dll 16.02.2005 г. 09:51 978944 \RP3\A0000425.dll c:\program files\Common Files\Ahead\AudioPlugins\Aiff.dll 01.02.2005 г. 10:51 73813 \RP3\A0000404.dll c:\program files\Common Files\Ahead\AudioPlugins\DefConvertor.dll 01.02.2005 г. 10:51 57445 \RP3\A0000405.dll c:\program files\Common Files\Ahead\AudioPlugins\lame_enc.dll 17.02.2004 г. 10:20 208896 \RP3\A0000445.dll c:\program files\Common Files\Ahead\AudioPlugins\mp3PP.dll 01.02.2005 г. 10:51 536664 \RP3\A0000441.dll c:\program files\Common Files\Ahead\AudioPlugins\mp3PRO.dll 01.02.2005 г. 10:52 1433689 \RP3\A0000442.dll c:\program files\Common Files\Ahead\AudioPlugins\mp3PRO_dmo.dll 01.02.2005 г. 10:52 94305 \RP3\A0000443.dll c:\program files\Common Files\Ahead\AudioPlugins\mp3PRO_hlp.dll 01.02.2005 г. 10:52 86118 \RP3\A0000444.dll c:\program files\Common Files\Ahead\AudioPlugins\msa.dll 01.02.2005 г. 10:51 234496 \RP3\A0000406.dll c:\program files\Common Files\Ahead\AudioPlugins\ogg.dll 01.02.2005 г. 10:52 1589336 \RP3\A0000431.dll c:\program files\Common Files\Ahead\AudioPlugins\Vqf.dll 01.02.2005 г. 10:51 82003 \RP3\A0000407.dll c:\program files\Common Files\Ahead\AudioPlugins\VqfDecLib.dll 01.02.2005 г. 10:51 667648 \RP3\A0000408.dll c:\program files\Common Files\Ahead\AudioPlugins\VqfEncLib.dll 01.02.2005 г. 10:51 827392 \RP3\A0000409.dll c:\program files\Common Files\Ahead\AudioPlugins\VqfEncLib1.dll 01.02.2005 г. 10:51 221184 \RP3\A0000410.dll c:\program files\Common Files\Ahead\AudioPlugins\wav.dll 01.02.2005 г. 10:53 98387 \RP3\A0000411.dll c:\program files\Common Files\Ahead\DSFilter\aacplus.dll 16.02.2005 г. 09:54 303104 \RP3\A0000428.dll c:\program files\Common Files\Ahead\DSFilter\NeAMR.dll 16.02.2005 г. 09:54 372736 \RP3\A0000422.dll c:\program files\Common Files\Ahead\Lib\AdvrCntr.dll 11.03.2005 г. 15:28 1454158 \RP3\A0000429.dll c:\program files\Common Files\Ahead\Lib\apreg.dll 21.01.2005 г. 18:12 528461 \RP3\A0000420.dll c:\program files\Common Files\Ahead\Lib\DriveLocker.dll 08.12.2004 г. 19:58 139264 \RP3\A0000412.dll c:\program files\Common Files\Ahead\Lib\NeroCBUI.dll 24.08.2004 г. 06:58 1097728 \RP3\A0000413.dll c:\program files\Common Files\Ahead\Lib\NeroIPP.dll 16.02.2005 г. 09:55 1097728 \RP3\A0000430.dll 08.03.2009 г. 04:33 759296 c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll 13.08.2007 г. 17:54 765952 \RP2\A0000143.dll c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20100223.004\CCERASER.DLL 18.01.2010 г. 18:22 2747440 \RP3\A0000537.DLL c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20100223.004\ECMSVR32.DLL 18.01.2010 г. 18:22 259440 \RP3\A0000538.DLL c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20100223.004\EECTRL.SYS 18.01.2010 г. 18:22 371248 \RP3\A0000539.SYS c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20100223.004\ERASER.SYS 18.01.2010 г. 18:22 102448 \RP3\A0000541.SYS c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20100223.004\NAVENG.SYS 16.02.2010 г. 11:00 84912 \RP3\A0000542.SYS c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20100223.004\NAVENG32.DLL 18.01.2010 г. 18:22 177520 \RP3\A0000543.DLL c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20100223.004\NAVEX15.SYS 16.02.2010 г. 11:00 1324720 \RP3\A0000544.SYS c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20100223.004\NAVEX32A.DLL 18.01.2010 г. 18:22 1647984 \RP3\A0000545.DLL c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\cceraser.dll 18.01.2010 г. 18:22 2747440 \RP3\A0000551.dll c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\ecmsvr32.dll 18.01.2010 г. 18:22 259440 \RP3\A0000552.dll c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\eeCtrl.sys 18.01.2010 г. 18:22 371248 \RP3\A0000553.sys c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\ERASER.sys 18.01.2010 г. 18:22 102448 \RP3\A0000555.sys c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\NAVENG.SYS 16.02.2010 г. 11:00 84912 \RP3\A0000556.SYS c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\naveng32.dll 18.01.2010 г. 18:22 177520 \RP3\A0000557.dll c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\NAVEX15.SYS 16.02.2010 г. 11:00 1324720 \RP3\A0000558.SYS c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\navex32a.dll 18.01.2010 г. 18:22 1647984 \RP3\A0000559.dll c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp3062.tmp\CCERASER.DLL 18.01.2010 г. 18:22 2747440 \RP3\A0000565.DLL c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp3062.tmp\ECMSVR32.DLL 18.01.2010 г. 18:22 259440 \RP3\A0000566.DLL c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp3062.tmp\EECTRL.SYS 18.01.2010 г. 18:22 371248 \RP3\A0000567.SYS c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp3062.tmp\ERASER.SYS 18.01.2010 г. 18:22 102448 \RP3\A0000569.SYS c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp3062.tmp\hub.scr 18.01.2010 г. 18:22 750 \RP3\A0000570.scr c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp3062.tmp\NAVENG.SYS 18.01.2010 г. 18:22 84912 \RP3\A0000571.SYS c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp3062.tmp\NAVENG32.DLL 18.01.2010 г. 18:22 177520 \RP3\A0000572.DLL c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp3062.tmp\NAVEX15.SYS 18.01.2010 г. 18:22 1323568 \RP3\A0000573.SYS c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp3062.tmp\NAVEX32A.DLL 18.01.2010 г. 18:22 1647984 \RP3\A0000574.DLL c:\program files\Conduit\Community Alerts\Alert.dll 29.12.2009 г. 15:32 520728 \RP3\A0000676.dll c:\program files\Forklift Truck Simulator 2009\CEGUIBase.dll 10.12.2008 г. 17:18 1683456 \RP2\A0000262.dll c:\program files\Forklift Truck Simulator 2009\CEGUIExpatParser.dll 10.12.2008 г. 17:25 114688 \RP2\A0000261.dll c:\program files\Forklift Truck Simulator 2009\CEGUIFalagardWRBase.dll 10.12.2008 г. 17:28 131072 \RP2\A0000260.dll c:\program files\Forklift Truck Simulator 2009\dbghelp.dll 04.12.2007 г. 00:50 986112 \RP2\A0000259.dll c:\program files\Forklift Truck Simulator 2009\DirectX9GUIRenderer.dll 10.12.2008 г. 17:25 253952 \RP2\A0000258.dll c:\program files\Forklift Truck Simulator 2009\Forklift Truck Simulator 2009.exe 01.05.2009 г. 17:52 1175552 \RP2\A0000257.exe c:\program files\Forklift Truck Simulator 2009\Microsoft DirectX\dxwebsetup.exe 16.03.2009 г. 22:23 301384 \RP2\A0000254.exe c:\program files\Forklift Truck Simulator 2009\msvcp71.dll 18.03.2003 г. 23:14 499712 \RP2\A0000256.dll c:\program files\Forklift Truck Simulator 2009\msvcr71.dll 21.02.2003 г. 05:42 348160 \RP2\A0000255.dll 08.03.2009 г. 04:24 68608 c:\program files\Internet Explorer\hmmapi.dll 13.08.2007 г. 17:18 60416 \RP2\A0000139.dll 08.03.2009 г. 04:33 246784 c:\program files\Internet Explorer\ieproxy.dll 13.08.2007 г. 17:54 287744 \RP2\A0000140.dll 08.03.2009 г. 14:09 638816 c:\program files\Internet Explorer\iexplore.exe 13.08.2007 г. 17:43 622080 \RP2\A0000141.exe c:\program files\Java\jre6\bin\msvcr71.dll 19.11.2008 г. 00:43 348160 \RP3\A0000269.dll c:\program files\MillBar\MillBarToolbarHelper.exe 02.06.2009 г. 10:12 38424 \RP3\A0000391.exe c:\program files\MillBar\tbMill.dll 31.12.2009 г. 11:53 2349080 \RP3\A0000393.dll c:\program files\MillBar\UNWISE.EXE 26.07.2002 г. 17:02 153088 \RP3\A0000394.EXE c:\program files\Norton Security Scan\Engine\2.7.0.52\BilBDRes.dll 01.02.2010 г. 11:54 578936 \RP3\A0000582.dll c:\program files\Norton Security Scan\Engine\2.7.0.52\ccL80U.dll 30.01.2010 г. 19:21 522088 \RP3\A0000583.dll c:\program files\Norton Security Scan\Engine\2.7.0.52\ccScanw.dll 30.01.2010 г. 19:21 328552 \RP3\A0000584.dll c:\program files\Norton Security Scan\Engine\2.7.0.52\ccVrTrst.dll 30.01.2010 г. 19:21 80744 \RP3\A0000585.dll c:\program files\Norton Security Scan\Engine\2.7.0.52\dec_abi.dll 30.01.2010 г. 19:21 2102624 \RP3\A0000586.dll c:\program files\Norton Security Scan\Engine\2.7.0.52\DefUtDCD.dll 30.01.2010 г. 19:21 677240 \RP3\A0000587.dll c:\program files\Norton Security Scan\Engine\2.7.0.52\diLueCbk.dll 30.01.2010 г. 19:21 65904 \RP3\A0000588.dll c:\program files\Norton Security Scan\Engine\2.7.0.52\ecmldr32.dll 30.01.2010 г. 19:21 54640 \RP3\A0000589.dll c:\program files\Norton Security Scan\Engine\2.7.0.52\HeartBt.dll 30.01.2010 г. 19:21 95608 \RP3\A0000590.dll c:\program files\Norton Security Scan\Engine\2.7.0.52\msl.dll 30.01.2010 г. 19:21 321152 \RP3\A0000592.dll c:\program files\Norton Security Scan\Engine\2.7.0.52\msvcp80.dll 30.01.2010 г. 19:21 548864 \RP3\A0000593.dll c:\program files\Norton Security Scan\Engine\2.7.0.52\msvcr80.dll 30.01.2010 г. 19:21 626688 \RP3\A0000594.dll c:\program files\Norton Security Scan\Engine\2.7.0.52\Nss.exe 23.02.2010 г. 13:12 606072 \RP3\A0000595.exe c:\program files\Norton Security Scan\Engine\2.7.0.52\patch25d.dll 30.01.2010 г. 19:21 40320 \RP3\A0000596.dll c:\program files\Norton Security Scan\Engine\2.7.0.52\PrdDtRes.dll 23.02.2010 г. 13:12 35704 \RP3\A0000597.dll c:\program files\Norton Security Scan\Engine\2.7.0.52\RptCdRes.dll 22.02.2010 г. 22:22 128376 \RP3\A0000598.dll c:\program files\Norton Security Scan\Engine\2.7.0.52\SAUpdt.dll 30.01.2010 г. 19:21 898424 \RP3\A0000599.dll c:\program files\Norton Security Scan\Engine\2.7.0.52\ScanCore.dll 23.02.2010 г. 13:12 1098616 \RP3\A0000600.dll c:\program files\Norton Security Scan\Engine\2.7.0.52\ScanRes.dll 22.02.2010 г. 22:10 932216 \RP3\A0000601.dll c:\program files\Norton Security Scan\Engine\2.7.0.52\ScanText.dll 22.02.2010 г. 22:10 31096 \RP3\A0000602.dll c:\program files\Norton Security Scan\Engine\2.7.0.52\SKUCfg.dll 23.02.2010 г. 18:31 12664 \RP3\A0000603.dll c:\program files\Norton Security Scan\Engine\2.7.0.52\SKURes.dll 23.02.2010 г. 18:31 451960 \RP3\A0000604.dll c:\program files\Norton Security Scan\Engine\2.7.0.52\symbos.exe 22.02.2010 г. 22:22 382328 \RP3\A0000605.exe c:\program files\Norton Security Scan\Engine\2.7.0.52\SymHTML.dll 30.01.2010 г. 19:21 1657688 \RP3\A0000606.dll c:\program files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\2.7.0.52\ccL80U.dll 30.01.2010 г. 19:21 523624 \RP3\A0000610.dll c:\program files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\2.7.0.52\ccSet.dll 30.01.2010 г. 19:21 254824 \RP3\A0000611.dll c:\program files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\2.7.0.52\Engine.dll 30.01.2010 г. 19:21 1328160 \RP3\A0000612.dll c:\program files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\2.7.0.52\InstStub.exe 30.01.2010 г. 19:21 634760 \RP3\A0000613.exe c:\program files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\2.7.0.52\InstUI.dll 30.01.2010 г. 19:21 2261536 \RP3\A0000614.dll c:\program files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\2.7.0.52\Lue.dll 30.01.2010 г. 19:21 935776 \RP3\A0000615.dll c:\program files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\2.7.0.52\Microsoft.VC80.CRT\msvcm80.dll 30.01.2010 г. 19:21 479232 \RP3\A0000617.dll c:\program files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\2.7.0.52\Microsoft.VC80.CRT\msvcp80.dll 30.01.2010 г. 19:21 548864 \RP3\A0000618.dll c:\program files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\2.7.0.52\Microsoft.VC80.CRT\msvcr80.dll 30.01.2010 г. 19:21 626688 \RP3\A0000619.dll c:\program files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\2.7.0.52\ProdCbk.dll 30.01.2010 г. 19:21 189816 \RP3\A0000620.dll c:\program files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\2.7.0.52\SKUCfg.dll 30.01.2010 г. 19:21 12152 \RP3\A0000621.dll c:\program files\SMAC\SMAC.exe 24.03.2004 г. 21:16 258048 \RP3\A0000622.exe c:\program files\SMAC\UNWISE.EXE 26.07.2002 г. 17:02 153088 \RP3\A0000627.EXE 27.02.2010 г. 02:11 1281712 c:\program files\Spyware Doctor\update.exe 09.01.2006 г. 09:19 1281784 \RP2\A0000235.exe c:\program files\Webcam and Screen Recorder\mfc42.dll 04.08.2004 г. 00:56 1028096 \RP3\A0000670.dll c:\program files\Webcam and Screen Recorder\MFC71.dll 19.03.2003 г. 12:19 1060864 \RP3\A0000671.dll c:\program files\Webcam and Screen Recorder\msvcp71.dll 27.08.2003 г. 14:43 499712 \RP3\A0000672.dll c:\program files\Webcam and Screen Recorder\msvcr71.dll 21.02.2003 г. 19:42 348160 \RP3\A0000673.dll c:\program files\Webcam and Screen Recorder\msvcrt.dll 04.08.2004 г. 00:56 343040 \RP3\A0000674.dll c:\program files\Wisdom-soft AutoScreenRecorder 3 Free\AskInstallChecker.exe 18.12.2008 г. 13:22 54664 \RP3\A0000675.exe c:\program files\Wisdom-soft AutoScreenRecorder 3 Free\askSBarSetup-4.1.0.5.exe 23.12.2008 г. 11:48 867544 \RP3\A0000638.exe c:\program files\Wisdom-soft AutoScreenRecorder 3 Free\asr30.dll 01.12.2009 г. 17:54 231424 \RP3\A0000636.dll c:\program files\Wisdom-soft AutoScreenRecorder 3 Free\AutoScreenRecorder.exe 01.12.2009 г. 18:00 4656640 \RP3\A0000637.exe c:\program files\Wisdom-soft AutoScreenRecorder 3 Free\gdiplus.dll 15.04.2008 г. 10:47 1724416 \RP3\A0000635.dll c:\program files\Wisdom-soft AutoScreenRecorder 3 Free\KillAutoScreenRecorder.exe 18.06.2009 г. 17:38 110978 \RP3\A0000633.exe c:\program files\Wisdom-soft AutoScreenRecorder 3 Free\Remove AutoScreenRecorder 3 Free from Startup.reg 23.02.2009 г. 17:22 115 \RP3\A0000634.reg c:\program files\Wisdom-soft AutoScreenRecorder 3 Free\UNWISE.EXE 28.09.2001 г. 16:00 164864 \RP3\A0000643.EXE c:\sportskeeping\SportsKeeping.exe 26.07.2009 г. 22:11 8650752 \RP3\A0000628.exe c:\sportskeeping\Uninstal.exe 22.08.2009 г. 20:45 50037 \RP3\A0000632.exe c:\windows\_001232_.tmp.dll 08.03.2009 г. 14:23 47422 \RP2\A0000004.dll c:\windows\ie7\spuninst\_001237_.tmp.dll 06.09.2006 г. 16:43 213216 \RP2\A0000006.dll c:\windows\system32\_001231_.tmp.dll 16.10.2006 г. 15:10 14640 \RP2\A0000002.dll c:\windows\system32\_001238_.tmp.dll 13.08.2007 г. 17:45 78336 \RP2\A0000007.dll 08.03.2009 г. 04:32 72704 c:\windows\system32\admparse.dll 13.08.2007 г. 17:39 71680 \RP2\A0000144.dll 08.03.2009 г. 04:32 128512 c:\windows\system32\advpack.dll 13.08.2007 г. 17:39 123904 \RP2\A0000145.dll 08.03.2009 г. 04:33 18944 c:\windows\system32\corpol.dll 13.08.2007 г. 17:42 17408 \RP2\A0000146.dll c:\windows\system32\dllcache\_001233_.tmp.dll 13.08.2007 г. 17:45 78336 \RP2\A0000005.dll 08.03.2009 г. 04:32 72704 c:\windows\system32\dllcache\admparse.dll 13.08.2007 г. 17:39 71680 \RP2\A0000101.dll 08.03.2009 г. 04:32 128512 c:\windows\system32\dllcache\advpack.dll 13.08.2007 г. 17:39 123904 \RP2\A0000102.dll 03.08.2004 г. 21:39 142464 c:\windows\system32\dllcache\aec.sys 03.08.2004 г. 21:39 142464 \RP3\A0000695.sys 03.08.2004 г. 23:05 14336 c:\windows\system32\dllcache\asyncmac.sys 03.08.2004 г. 23:05 14336 \RP3\A0000698.sys 03.08.2004 г. 22:58 59904 c:\windows\system32\dllcache\atmarpc.sys 03.08.2004 г. 22:58 59904 \RP3\A0000699.sys 03.08.2004 г. 22:10 17024 c:\windows\system32\dllcache\ccdecode.sys 03.08.2004 г. 22:10 17024 \RP3\A0000701.sys 23.08.2001 г. 14:00 18688 c:\windows\system32\dllcache\cdaudio.sys 23.08.2001 г. 14:00 18688 \RP3\A0000703.sys 03.08.2004 г. 23:00 8192 c:\windows\system32\dllcache\changer.sys 03.08.2004 г. 23:00 8192 \RP3\A0000707.sys 08.03.2009 г. 04:33 18944 c:\windows\system32\dllcache\corpol.dll 13.08.2007 г. 17:42 17408 \RP2\A0000103.dll 03.08.2004 г. 22:07 52864 c:\windows\system32\dllcache\dmusic.sys 03.08.2004 г. 22:07 52864 \RP3\A0000709.sys 03.08.2004 г. 22:07 2944 c:\windows\system32\dllcache\drmkaud.sys 03.08.2004 г. 22:07 2944 \RP3\A0000710.sys 08.03.2009 г. 04:31 348160 c:\windows\system32\dllcache\dxtmsft.dll 13.08.2007 г. 17:35 346624 \RP2\A0000104.dll 08.03.2009 г. 04:31 216064 c:\windows\system32\dllcache\dxtrans.dll 13.08.2007 г. 17:35 214528 \RP2\A0000105.dll 03.08.2004 г. 22:59 20480 c:\windows\system32\dllcache\flpydisk.sys 03.08.2004 г. 22:59 20480 \RP3\A0000712.sys 08.03.2009 г. 04:24 68608 c:\windows\system32\dllcache\hmmapi.dll 13.08.2007 г. 17:18 60416 \RP2\A0000106.dll 03.08.2004 г. 23:14 52736 c:\windows\system32\dllcache\i8042prt.sys 03.08.2004 г. 23:14 52736 \RP3\A0000713.sys 08.03.2009 г. 04:32 173056 c:\windows\system32\dllcache\ie4uinit.exe 13.08.2007 г. 17:39 54784 \RP2\A0000107.exe 08.03.2009 г. 04:33 125952 c:\windows\system32\dllcache\ieakeng.dll 13.08.2007 г. 17:39 152064 \RP2\A0000108.dll 08.03.2009 г. 04:33 229376 c:\windows\system32\dllcache\ieaksie.dll 13.08.2007 г. 17:39 229376 \RP2\A0000109.dll 08.03.2009 г. 04:32 163840 c:\windows\system32\dllcache\ieakui.dll 13.08.2007 г. 16:56 161792 \RP2\A0000110.dll 08.03.2009 г. 14:09 391536 c:\windows\system32\dllcache\iedkcs32.dll 13.08.2007 г. 17:39 382976 \RP2\A0000111.dll 08.03.2009 г. 04:31 183808 c:\windows\system32\dllcache\iepeers.dll 13.08.2007 г. 17:54 191488 \RP2\A0000112.dll 08.03.2009 г. 04:32 55808 c:\windows\system32\dllcache\iernonce.dll 13.08.2007 г. 17:39 43008 \RP2\A0000113.dll 08.03.2009 г. 04:32 71680 c:\windows\system32\dllcache\iesetup.dll 13.08.2007 г. 17:39 55296 \RP2\A0000114.dll 08.03.2009 г. 14:09 638816 c:\windows\system32\dllcache\iexplore.exe 13.08.2007 г. 17:43 622080 \RP2\A0000115.exe 03.08.2004 г. 23:00 41856 c:\windows\system32\dllcache\imapi.sys 03.08.2004 г. 23:00 41856 \RP3\A0000715.sys 08.03.2009 г. 04:31 34816 c:\windows\system32\dllcache\imgutil.dll 13.08.2007 г. 17:36 36352 \RP2\A0000116.dll 08.03.2009 г. 04:32 94720 c:\windows\system32\dllcache\inseng.dll 13.08.2007 г. 17:39 92672 \RP2\A0000118.dll 03.08.2004 г. 23:00 29056 c:\windows\system32\dllcache\ip6fw.sys 03.08.2004 г. 23:00 29056 \RP3\A0000716.sys 23.08.2001 г. 14:00 32896 c:\windows\system32\dllcache\ipfltdrv.sys 23.08.2001 г. 14:00 32896 \RP3\A0000718.sys 03.08.2004 г. 23:04 20992 c:\windows\system32\dllcache\ipinip.sys 03.08.2004 г. 23:04 20992 \RP3\A0000719.sys 03.08.2004 г. 23:00 11264 c:\windows\system32\dllcache\irenum.sys 03.08.2004 г. 23:00 11264 \RP3\A0000722.sys 08.03.2009 г. 04:33 726528 c:\windows\system32\dllcache\jscript.dll 17.05.2006 г. 10:43 465864 \RP2\A0000119.dll 08.03.2009 г. 04:33 25600 c:\windows\system32\dllcache\jsproxy.dll 13.08.2007 г. 17:54 27136 \RP2\A0000120.dll 03.08.2004 г. 22:59 34688 c:\windows\system32\dllcache\lbrtfdc.sys 03.08.2004 г. 22:59 34688 \RP3\A0000724.sys 08.03.2009 г. 04:34 43008 c:\windows\system32\dllcache\licmgr10.dll 13.08.2007 г. 17:44 40960 \RP2\A0000121.dll 04.08.2004 г. 01:05 30080 c:\windows\system32\dllcache\modem.sys 04.08.2004 г. 01:05 30080 \RP3\A0000726.sys 08.03.2009 г. 04:31 45568 c:\windows\system32\dllcache\mshta.exe 13.08.2007 г. 17:32 45568 \RP2\A0000122.exe 08.03.2009 г. 04:41 5937152 c:\windows\system32\dllcache\mshtml.dll 13.08.2007 г. 17:54 3578368 \RP2\A0000123.dll 08.03.2009 г. 04:31 66560 c:\windows\system32\dllcache\mshtmled.dll 13.08.2007 г. 17:54 475648 \RP2\A0000125.dll 08.03.2009 г. 04:31 48128 c:\windows\system32\dllcache\mshtmler.dll 13.08.2007 г. 17:01 48128 \RP2\A0000126.dll 03.08.2004 г. 21:58 7552 c:\windows\system32\dllcache\mskssrv.sys 03.08.2004 г. 21:58 7552 \RP3\A0000728.sys 08.03.2009 г. 04:22 156160 c:\windows\system32\dllcache\msls31.dll 13.08.2007 г. 17:54 156160 \RP2\A0000127.dll 03.08.2004 г. 21:58 5376 c:\windows\system32\dllcache\mspclock.sys 03.08.2004 г. 21:58 5376 \RP3\A0000734.sys 03.08.2004 г. 21:58 4992 c:\windows\system32\dllcache\mspqm.sys 03.08.2004 г. 21:58 4992 \RP3\A0000736.sys 08.03.2009 г. 04:34 193536 c:\windows\system32\dllcache\msrating.dll 13.08.2007 г. 17:44 192000 \RP2\A0000128.dll 03.08.2004 г. 21:58 5504 c:\windows\system32\dllcache\mstee.sys 03.08.2004 г. 21:58 5504 \RP3\A0000738.sys 08.03.2009 г. 04:32 611840 c:\windows\system32\dllcache\mstime.dll 13.08.2007 г. 17:54 670720 \RP2\A0000129.dll 03.08.2004 г. 22:10 85376 c:\windows\system32\dllcache\nabtsfec.sys 03.08.2004 г. 22:10 85376 \RP3\A0000739.sys 03.08.2004 г. 22:10 10880 c:\windows\system32\dllcache\ndisip.sys 03.08.2004 г. 22:10 10880 \RP3\A0000740.sys 03.08.2004 г. 22:59 40320 c:\windows\system32\dllcache\nmnt.sys 03.08.2004 г. 22:59 40320 \RP3\A0000741.sys 23.08.2001 г. 14:00 12416 c:\windows\system32\dllcache\nwlnkflt.sys 23.08.2001 г. 14:00 12416 \RP3\A0000743.sys 23.08.2001 г. 14:00 32512 c:\windows\system32\dllcache\nwlnkfwd.sys 23.08.2001 г. 14:00 32512 \RP3\A0000745.sys 08.03.2009 г. 04:34 109568 c:\windows\system32\dllcache\occache.dll 13.08.2007 г. 17:44 101376 \RP2\A0000130.dll 08.03.2009 г. 04:31 46592 c:\windows\system32\dllcache\pngfilt.dll 13.08.2007 г. 17:36 44544 \RP2\A0000131.dll 04.08.2004 г. 01:01 139400 c:\windows\system32\dllcache\rdpwd.sys 04.08.2004 г. 01:01 139400 \RP3\A0000755.sys 03.08.2004 г. 22:59 11392 c:\windows\system32\dllcache\sfloppy.sys 03.08.2004 г. 22:59 11392 \RP3\A0000756.sys 03.08.2004 г. 22:10 11136 c:\windows\system32\dllcache\slip.sys 03.08.2004 г. 22:10 11136 \RP3\A0000758.sys 03.08.2004 г. 22:07 6400 c:\windows\system32\dllcache\splitter.sys 03.08.2004 г. 22:07 6400 \RP3\A0000760.sys 03.08.2004 г. 22:10 15360 c:\windows\system32\dllcache\streamip.sys 03.08.2004 г. 22:10 15360 \RP3\A0000761.sys 17.08.2001 г. 13:00 54272 c:\windows\system32\dllcache\swmidi.sys 17.08.2001 г. 13:00 54272 \RP3\A0000763.sys 04.08.2004 г. 01:01 12040 c:\windows\system32\dllcache\tdpipe.sys 04.08.2004 г. 01:01 12040 \RP3\A0000764.sys 04.08.2004 г. 01:01 21896 c:\windows\system32\dllcache\tdtcp.sys 04.08.2004 г. 01:01 21896 \RP3\A0000765.sys 08.03.2009 г. 04:34 105984 c:\windows\system32\dllcache\url.dll 13.08.2007 г. 17:44 105984 \RP2\A0000133.dll 08.03.2009 г. 04:34 1206784 c:\windows\system32\dllcache\urlmon.dll 13.08.2007 г. 17:54 1162240 \RP2\A0000134.dll 03.08.2004 г. 22:07 59264 c:\windows\system32\dllcache\usbaudio.sys 03.08.2004 г. 22:07 59264 \RP3\A0000768.sys 03.08.2004 г. 22:08 25600 c:\windows\system32\dllcache\usbser.sys 03.08.2004 г. 22:08 25600 \RP3\A0000769.sys 03.08.2004 г. 22:08 26496 c:\windows\system32\dllcache\usbstor.sys 03.08.2004 г. 22:08 26496 \RP3\A0000771.sys 08.03.2009 г. 04:33 420352 c:\windows\system32\dllcache\vbscript.dll 09.08.2004 г. 20:27 438272 \RP2\A0000135.dll 08.03.2009 г. 04:33 759296 c:\windows\system32\dllcache\VGX.dll 13.08.2007 г. 17:54 765952 \RP2\A0000136.dll 08.03.2009 г. 04:34 236544 c:\windows\system32\dllcache\webcheck.dll 13.08.2007 г. 17:54 231424 \RP2\A0000137.dll 08.03.2009 г. 04:34 914944 c:\windows\system32\dllcache\wininet.dll 13.08.2007 г. 17:54 818688 \RP2\A0000138.dll 03.08.2004 г. 22:10 19328 c:\windows\system32\dllcache\wstcodec.sys 03.08.2004 г. 22:10 19328 \RP3\A0000772.sys 03.08.2004 г. 21:39 142464 c:\windows\system32\drivers\aec.sys 03.08.2004 г. 21:39 142464 \RP3\A0000687.sys 03.08.2004 г. 23:05 14336 c:\windows\system32\drivers\asyncmac.sys 03.08.2004 г. 23:05 14336 \RP3\A0000688.sys 03.08.2004 г. 22:58 59904 c:\windows\system32\drivers\atmarpc.sys 03.08.2004 г. 22:58 59904 \RP3\A0000689.sys 07.05.2008 г. 06:38 17536 c:\windows\system32\drivers\ccdcmb.sys 07.05.2008 г. 06:38 17536 \RP3\A0000729.sys 07.05.2008 г. 06:38 20864 c:\windows\system32\drivers\ccdcmbo.sys 07.05.2008 г. 06:38 20864 \RP3\A0000730.sys 03.08.2004 г. 22:10 17024 c:\windows\system32\drivers\ccdecode.sys 03.08.2004 г. 22:10 17024 \RP3\A0000690.sys 23.08.2001 г. 14:00 18688 c:\windows\system32\drivers\Cdaudio.sys 23.08.2001 г. 14:00 18688 \RP3\A0000691.sys 03.08.2004 г. 23:00 8192 c:\windows\system32\drivers\Changer.sys 03.08.2004 г. 23:00 8192 \RP3\A0000692.sys 03.08.2004 г. 22:07 52864 c:\windows\system32\drivers\dmusic.sys 03.08.2004 г. 22:07 52864 \RP3\A0000693.sys 03.08.2004 г. 22:07 2944 c:\windows\system32\drivers\drmkaud.sys 03.08.2004 г. 22:07 2944 \RP3\A0000694.sys 03.08.2004 г. 22:59 20480 c:\windows\system32\drivers\Flpydisk.sys 03.08.2004 г. 22:59 20480 \RP3\A0000696.sys 03.08.2004 г. 23:14 52736 c:\windows\system32\drivers\i8042prt.sys 03.08.2004 г. 23:14 52736 \RP3\A0000697.sys c:\windows\system32\drivers\imagedrv.sys 02.03.2004 г. 15:37 5504 \RP3\A0000525.sys c:\windows\system32\drivers\imagesrv.sys 02.03.2004 г. 15:37 125184 \RP3\A0000526.sys 03.08.2004 г. 23:00 41856 c:\windows\system32\drivers\imapi.sys 03.08.2004 г. 23:00 41856 \RP3\A0000700.sys 03.08.2004 г. 23:00 29056 c:\windows\system32\drivers\ip6fw.sys 03.08.2004 г. 23:00 29056 \RP3\A0000702.sys 23.08.2001 г. 14:00 32896 c:\windows\system32\drivers\ipfltdrv.sys 23.08.2001 г. 14:00 32896 \RP3\A0000704.sys 03.08.2004 г. 23:04 20992 c:\windows\system32\drivers\ipinip.sys 03.08.2004 г. 23:04 20992 \RP3\A0000705.sys 03.08.2004 г. 23:00 11264 c:\windows\system32\drivers\irenum.sys 03.08.2004 г. 23:00 11264 \RP3\A0000706.sys 03.08.2004 г. 22:59 34688 c:\windows\system32\drivers\lbrtfdc.sys 03.08.2004 г. 22:59 34688 \RP3\A0000708.sys 04.08.2004 г. 01:05 30080 c:\windows\system32\drivers\Modem.sys 04.08.2004 г. 01:05 30080 \RP3\A0000711.sys 03.08.2004 г. 21:58 7552 c:\windows\system32\drivers\mskssrv.sys 03.08.2004 г. 21:58 7552 \RP3\A0000714.sys 03.08.2004 г. 21:58 5376 c:\windows\system32\drivers\mspclock.sys 03.08.2004 г. 21:58 5376 \RP3\A0000717.sys 03.08.2004 г. 21:58 4992 c:\windows\system32\drivers\mspqm.sys 03.08.2004 г. 21:58 4992 \RP3\A0000720.sys 03.08.2004 г. 21:58 5504 c:\windows\system32\drivers\mstee.sys 03.08.2004 г. 21:58 5504 \RP3\A0000721.sys 03.08.2004 г. 22:10 85376 c:\windows\system32\drivers\nabtsfec.sys 03.08.2004 г. 22:10 85376 \RP3\A0000723.sys 03.08.2004 г. 22:10 10880 c:\windows\system32\drivers\ndisip.sys 03.08.2004 г. 22:10 10880 \RP3\A0000725.sys 03.08.2004 г. 22:59 40320 c:\windows\system32\drivers\nmnt.sys 03.08.2004 г. 22:59 40320 \RP3\A0000727.sys 06.11.2007 г. 22:22 34064 c:\windows\system32\drivers\npf.sys 06.11.2007 г. 22:22 34064 \RP3\A0000731.sys 27.11.2006 г. 15:33 58368 c:\windows\system32\drivers\nvenetfd.sys 27.11.2006 г. 15:33 58368 \RP3\A0000732.sys 23.08.2001 г. 14:00 12416 c:\windows\system32\drivers\nwlnkflt.sys 23.08.2001 г. 14:00 12416 \RP3\A0000733.sys 23.08.2001 г. 14:00 32512 c:\windows\system32\drivers\nwlnkfwd.sys 23.08.2001 г. 14:00 32512 \RP3\A0000735.sys 17.09.2007 г. 14:53 21632 c:\windows\system32\drivers\pccsmcfd.sys 17.09.2007 г. 14:53 21632 \RP3\A0000737.sys 04.08.2004 г. 01:01 139400 c:\windows\system32\drivers\RDPWD.sys 04.08.2004 г. 01:01 139400 \RP3\A0000742.sys 03.08.2004 г. 22:59 11392 c:\windows\system32\drivers\Sfloppy.sys 03.08.2004 г. 22:59 11392 \RP3\A0000744.sys 03.08.2004 г. 22:10 11136 c:\windows\system32\drivers\slip.sys 03.08.2004 г. 22:10 11136 \RP3\A0000746.sys 03.08.2004 г. 22:07 6400 c:\windows\system32\drivers\splitter.sys 03.08.2004 г. 22:07 6400 \RP3\A0000747.sys 03.08.2004 г. 22:10 15360 c:\windows\system32\drivers\streamip.sys 03.08.2004 г. 22:10 15360 \RP3\A0000748.sys 17.08.2001 г. 13:00 54272 c:\windows\system32\drivers\swmidi.sys 17.08.2001 г. 13:00 54272 \RP3\A0000749.sys 04.08.2004 г. 01:01 12040 c:\windows\system32\drivers\TDPIPE.sys 04.08.2004 г. 01:01 12040 \RP3\A0000750.sys 04.08.2004 г. 01:01 21896 c:\windows\system32\drivers\TDTCP.sys 04.08.2004 г. 01:01 21896 \RP3\A0000751.sys 03.08.2004 г. 22:07 59264 c:\windows\system32\drivers\usbaudio.sys 03.08.2004 г. 22:07 59264 \RP3\A0000753.sys 03.08.2004 г. 22:08 25600 c:\windows\system32\drivers\usbser.sys 03.08.2004 г. 22:08 25600 \RP3\A0000754.sys 06.06.2008 г. 08:24 8064 c:\windows\system32\drivers\usbser_lowerflt.sys 06.06.2008 г. 08:24 8064 \RP3\A0000752.sys 07.05.2008 г. 06:38 8064 c:\windows\system32\drivers\usbser_lowerfltj.sys 07.05.2008 г. 06:38 8064 \RP3\A0000757.sys 03.08.2004 г. 22:08 26496 c:\windows\system32\drivers\usbstor.sys 03.08.2004 г. 22:08 26496 \RP3\A0000759.sys 06.12.2006 г. 01:39 1963680 c:\windows\system32\drivers\vx1000.sys 06.12.2006 г. 01:39 1963680 \RP3\A0000762.sys 02.11.2006 г. 06:22 492000 c:\windows\system32\drivers\wdf01000.sys 02.11.2006 г. 06:22 492000 \RP3\A0000766.sys 03.08.2004 г. 22:10 19328 c:\windows\system32\drivers\wstcodec.sys 03.08.2004 г. 22:10 19328 \RP3\A0000767.sys 15.09.2006 г. 21:30 82688 c:\windows\system32\drivers\wudfrd.sys 15.09.2006 г. 21:30 82688 \RP3\A0000770.sys c:\windows\system32\drivers\xcybys.sys 27.02.2010 г. 05:15 54016 \RP3\A0000775.sys 08.03.2009 г. 04:31 348160 c:\windows\system32\dxtmsft.dll 13.08.2007 г. 17:35 346624 \RP2\A0000147.dll 08.03.2009 г. 04:31 216064 c:\windows\system32\dxtrans.dll 13.08.2007 г. 17:35 214528 \RP2\A0000148.dll 08.03.2009 г. 04:31 59904 c:\windows\system32\icardie.dll 13.08.2007 г. 17:36 61952 \RP2\A0000149.dll 08.03.2009 г. 04:32 173056 c:\windows\system32\ie4uinit.exe 13.08.2007 г. 17:39 54784 \RP2\A0000150.exe 08.03.2009 г. 04:33 125952 c:\windows\system32\ieakeng.dll 13.08.2007 г. 17:39 152064 \RP2\A0000151.dll 08.03.2009 г. 04:33 229376 c:\windows\system32\ieaksie.dll 13.08.2007 г. 17:39 229376 \RP2\A0000152.dll 08.03.2009 г. 04:32 163840 c:\windows\system32\ieakui.dll 13.08.2007 г. 16:56 161792 \RP2\A0000153.dll 08.03.2009 г. 04:11 445952 c:\windows\system32\ieapfltr.dll 11.07.2007 г. 11:27 383488 \RP2\A0000154.dll 08.03.2009 г. 14:09 391536 c:\windows\system32\iedkcs32.dll 13.08.2007 г. 17:39 382976 \RP2\A0000155.dll 08.03.2009 г. 04:39 11063808 c:\windows\system32\ieframe.dll 13.08.2007 г. 17:54 6049280 \RP2\A0000156.dll 08.03.2009 г. 04:31 183808 c:\windows\system32\iepeers.dll 13.08.2007 г. 17:54 191488 \RP2\A0000157.dll 08.03.2009 г. 04:32 55808 c:\windows\system32\iernonce.dll 13.08.2007 г. 17:39 43008 \RP2\A0000158.dll 08.03.2009 г. 04:32 1985024 c:\windows\system32\iertutil.dll 13.08.2007 г. 17:34 266752 \RP2\A0000159.dll 08.03.2009 г. 04:32 71680 c:\windows\system32\iesetup.dll 13.08.2007 г. 17:39 55296 \RP2\A0000160.dll 08.03.2009 г. 04:22 164352 c:\windows\system32\ieui.dll 13.08.2007 г. 17:54 180736 \RP2\A0000161.dll c:\windows\system32\ImagX7.dll 26.07.2004 г. 15:16 1568768 \RP3\A0000416.dll c:\windows\system32\ImagXpr7.dll 26.07.2004 г. 15:16 476320 \RP3\A0000417.dll c:\windows\system32\ImagXR7.dll 26.07.2004 г. 15:16 262144 \RP3\A0000418.dll c:\windows\system32\ImagXRA7.dll 26.07.2004 г. 15:16 471040 \RP3\A0000419.dll 08.03.2009 г. 04:31 34816 c:\windows\system32\imgutil.dll 13.08.2007 г. 17:36 36352 \RP2\A0000163.dll 08.03.2009 г. 04:32 94720 c:\windows\system32\inseng.dll 13.08.2007 г. 17:39 92672 \RP2\A0000165.dll c:\windows\system32\java.exe 19.11.2008 г. 00:43 144792 \RP3\A0000265.exe c:\windows\system32\javaw.exe 19.11.2008 г. 00:43 144792 \RP3\A0000266.exe c:\windows\system32\javaws.exe 19.11.2008 г. 00:43 148888 \RP3\A0000267.exe 08.03.2009 г. 04:33 726528 c:\windows\system32\jscript.dll 17.05.2006 г. 10:43 465864 \RP2\A0000166.dll 08.03.2009 г. 04:33 25600 c:\windows\system32\jsproxy.dll 13.08.2007 г. 17:54 27136 \RP2\A0000167.dll 08.03.2009 г. 04:34 43008 c:\windows\system32\licmgr10.dll 13.08.2007 г. 17:44 40960 \RP2\A0000168.dll 08.03.2009 г. 04:32 594432 c:\windows\system32\msfeeds.dll 13.08.2007 г. 17:54 458752 \RP2\A0000169.dll 08.03.2009 г. 04:31 55296 c:\windows\system32\msfeedsbs.dll 13.08.2007 г. 17:54 50688 \RP2\A0000170.dll 08.03.2009 г. 04:31 13312 c:\windows\system32\msfeedssync.exe 13.08.2007 г. 17:36 12288 \RP2\A0000171.exe 08.03.2009 г. 04:31 45568 c:\windows\system32\mshta.exe 13.08.2007 г. 17:32 45568 \RP2\A0000172.exe 08.03.2009 г. 04:41 5937152 c:\windows\system32\mshtml.dll 13.08.2007 г. 17:54 3578368 \RP2\A0000173.dll 08.03.2009 г. 04:31 66560 c:\windows\system32\mshtmled.dll 13.08.2007 г. 17:54 475648 \RP2\A0000175.dll 08.03.2009 г. 04:31 48128 c:\windows\system32\mshtmler.dll 13.08.2007 г. 17:01 48128 \RP2\A0000176.dll 08.03.2009 г. 04:22 156160 c:\windows\system32\msls31.dll 13.08.2007 г. 17:54 156160 \RP2\A0000177.dll 08.03.2009 г. 04:34 193536 c:\windows\system32\msrating.dll 13.08.2007 г. 17:44 192000 \RP2\A0000178.dll 08.03.2009 г. 04:32 611840 c:\windows\system32\mstime.dll 13.08.2007 г. 17:54 670720 \RP2\A0000179.dll c:\windows\system32\NeroCheck.exe 09.07.2001 г. 09:50 155648 \RP3\A0000403.exe 07.01.2009 г. 18:20 23552 c:\windows\system32\normaliz.dll 29.06.2006 г. 07:05 23552 \RP2\A0000100.dll 08.03.2009 г. 04:34 109568 c:\windows\system32\occache.dll 13.08.2007 г. 17:44 101376 \RP2\A0000180.dll 08.03.2009 г. 04:31 46592 c:\windows\system32\pngfilt.dll 13.08.2007 г. 17:36 44544 \RP2\A0000181.dll c:\windows\system32\TwnLib20.dll 26.06.2000 г. 09:45 106496 \RP3\A0000433.dll 08.03.2009 г. 04:34 105984 c:\windows\system32\url.dll 13.08.2007 г. 17:44 105984 \RP2\A0000183.dll 08.03.2009 г. 04:34 1206784 c:\windows\system32\urlmon.dll 13.08.2007 г. 17:54 1162240 \RP2\A0000184.dll 08.03.2009 г. 04:33 420352 c:\windows\system32\vbscript.dll \RP2\A0000185." 09.08.2004 г. 20:27 438272 \RP2\A0000185.dll 08.03.2009 г. 04:34 236544 c:\windows\system32\webcheck.dll 13.08.2007 г. 17:54 231424 \RP2\A0000186.dll 08.03.2009 г. 04:34 208384 c:\windows\system32\WinFXDocObj.exe 13.08.2007 г. 17:45 206336 \RP2\A0000187.exe 08.03.2009 г. 04:34 914944 c:\windows\system32\wininet.dll 13.08.2007 г. 17:54 818688 \RP2\A0000188.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Spyware Doctor"="c:\progra~1\SPYWAR~1\swdoctor.exe" [2005-12-13 1976544] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDCPL"="RTHDCPL.EXE" [2008-02-13 16857600] "nod32kui"="c:\program files\Eset\nod32kui.exe" [2008-05-24 950664] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480] "nwiz"="nwiz.exe" [2006-10-22 1622016] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360] "Spyware Doctor"="c:\program files\Spyware Doctor\swdoctor.exe" [2005-12-13 1976544] c:\documents and settings\Adrian\Start Menu\Programs\Startup\ Rainlendar.lnk - c:\program files\Rainlendar\Rainlendar.exe [2008-5-23 118784] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-10-6 113664] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" "VX1000"=c:\windows\vVX1000.exe [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"= "c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "21362:TCP"= 21362:TCP:BitComet 21362 TCP "21362:UDP"= 21362:UDP:BitComet 21362 UDP R2 XAMPP;XAMPP Service;c:\xampp\service.exe [x] R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-06 34064] S0 d346bus;d346bus;c:\windows\system32\DRIVERS\d346bus.sys [2004-03-12 156800] S0 d346prt;d346prt;c:\windows\System32\Drivers\d346prt.sys [2004-03-12 5248] S1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2008-05-24 15424] --- Other Services/Drivers In Memory --- *Deregistered* - mchInjDrv HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . Contents of the 'Scheduled Tasks' folder 2010-02-26 c:\windows\Tasks\1-Click Maintenance.job - c:\program files\TuneUp Utilities 2007en\SystemOptimizer.exe [2007-04-26 19:51] . . ------- Supplementary Scan ------- . uStart Page = about:blank IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 IE: {{FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\PokerStars.NET\PokerStarsUpdate.exe LSP: c:\windows\system32\imon.dll DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://193.68.31.137/activex/AMC.cab DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} - hxxps://plugins.valueactive.eu/flashax/iefax.cab . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-02-27 06:32 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv] "ImagePath"="\??\c:\docume~1\Adrian\LOCALS~1\Temp\mc22.tmp" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(588) c:\progra~1\SPYWAR~1\Tools\swpg.dat - - - - - - - > 'lsass.exe'(644) c:\progra~1\SPYWAR~1\Tools\swpg.dat c:\windows\system32\imon.dll - - - - - - - > 'explorer.exe'(1280) c:\progra~1\SPYWAR~1\Tools\swpg.dat c:\windows\system32\msi.dll c:\windows\system32\webcheck.dll c:\windows\system32\IEFRAME.dll c:\windows\system32\WPDShServiceObj.dll c:\program files\Nokia\Nokia PC Suite 7\phonebrowser.dll c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_eng.nlr c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll - - - - - - - > 'csrss.exe'(564) c:\progra~1\SPYWAR~1\Tools\swpg.dat . ------------------------ Other Running Processes ------------------------ . c:\windows\RTHDCPL.EXE c:\program files\Common Files\InterVideo\DeviceService\DevSvc.exe c:\program files\Microsoft LifeCam\MSCamS32.exe c:\program files\Eset\nod32krn.exe c:\windows\system32\nvsvc32.exe c:\program files\Photodex\ProShowGold\ScsiAccess.exe c:\program files\Spyware Doctor\sdhelp.exe c:\windows\system32\wscntfy.exe . ************************************************************************** . Completion time: 2010-02-27 06:35:48 - machine was rebooted ComboFix-quarantined-files.txt 2010-02-27 04:35 ComboFix2.txt 2010-02-27 03:57 Pre-Run: 4 683 071 488 bytes free Post-Run: 4 652 834 816 bytes free - - End Of File - - 4F5983E2BFF186A3376514FFA4F258C7
  3. ComboFix 10-02-26.01 - Adrian 02.2010 г. 5:43.1.1 - x86 Microsoft Windows XP Professional 5.1.2600.2.1251.359.1033.18.447.165 [GMT 2:00] Running from: c:\documents and settings\Adrian\Desktop\ComboFix.exe AV: ESET NOD32 antivirus system 2.70 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} . ((((((((((((((((((((((((( Files Created from 2010-01-27 to 2010-02-27 ))))))))))))))))))))))))))))))) . 2010-02-27 03:21 . 2010-02-27 03:22 -------- d-----w- C:\HJT 2010-02-27 02:38 . 2010-02-27 02:38 -------- d-----w- c:\documents and settings\Adrian\Application Data\Malwarebytes 2010-02-27 02:38 . 2010-01-07 14:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-02-27 02:38 . 2010-02-27 02:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2010-02-27 02:38 . 2010-01-07 14:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-02-27 02:38 . 2010-02-27 02:38 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2010-02-27 00:09 . 2005-12-13 13:18 50048 ----a-w- c:\windows\system32\drivers\ikhlayer.sys 2010-02-27 00:08 . 2010-02-27 01:16 -------- d-----w- c:\program files\Spyware Doctor 2010-02-27 00:08 . 2010-02-27 00:08 -------- d-----w- c:\documents and settings\Adrian\Application Data\PC Tools 2010-02-26 21:55 . 2010-02-26 23:51 -------- d-----w- c:\windows\BDOSCAN8 2010-02-26 16:15 . 2010-02-26 16:15 -------- d-sh--w- c:\documents and settings\Adrian\PrivacIE 2010-02-26 16:15 . 2010-02-26 16:15 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache 2010-02-26 16:14 . 2010-02-26 16:14 -------- d-sh--w- c:\documents and settings\Adrian\IETldCache 2010-02-26 16:05 . 2010-02-26 16:05 -------- dc-h--w- c:\windows\ie8 2010-02-26 04:22 . 2004-08-03 21:00 8192 -c--a-w- c:\windows\system32\dllcache\i2omgmt.sys 2010-02-26 04:22 . 2004-08-03 21:00 8192 ----a-w- c:\windows\system32\drivers\i2omgmt.sys 2010-02-26 04:22 . 2004-08-03 20:59 34688 -c--a-w- c:\windows\system32\dllcache\lbrtfdc.sys 2010-02-26 04:22 . 2004-08-03 20:59 34688 ----a-w- c:\windows\system32\drivers\lbrtfdc.sys 2010-02-26 04:22 . 2004-08-03 21:00 8192 -c--a-w- c:\windows\system32\dllcache\changer.sys 2010-02-26 04:22 . 2004-08-03 21:00 8192 ----a-w- c:\windows\system32\drivers\Changer.sys 2010-02-26 03:09 . 2010-02-26 03:10 5515984 ----a-w- c:\documents and settings\Adrian\Application Data\TVU Networks\AutoUpgrade\TVUPlayer2.5.2.1.exe 2010-02-26 02:46 . 2010-02-26 02:46 -------- d-----w- c:\program files\Photodex 2010-02-26 02:46 . 2010-02-26 02:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Photodex 2010-02-26 02:46 . 2010-02-26 02:46 -------- d-----w- c:\documents and settings\Adrian\Application Data\Photodex 2010-02-11 19:25 . 2010-02-26 22:29 -------- d-----w- c:\program files\PokerStars 2010-02-07 12:56 . 2010-02-27 01:55 -------- d-----w- c:\program files\Common Files\Symantec Shared 2010-02-05 20:22 . 2008-03-05 14:03 479752 ----a-w- c:\windows\system32\XAudio2_0.dll 2010-02-05 20:22 . 2008-03-05 14:03 238088 ----a-w- c:\windows\system32\xactengine3_0.dll 2010-02-05 20:22 . 2008-03-05 14:00 25608 ----a-w- c:\windows\system32\X3DAudio1_3.dll 2010-02-05 20:22 . 2008-03-05 13:56 1420824 ----a-w- c:\windows\system32\D3DCompiler_37.dll 2010-02-05 20:22 . 2008-02-05 21:07 462864 ----a-w- c:\windows\system32\d3dx10_37.dll 2010-02-05 20:22 . 2008-03-05 13:56 3786760 ----a-w- c:\windows\system32\D3DX9_37.dll 2010-01-30 17:21 . 2010-02-27 01:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton 2010-01-30 17:21 . 2010-01-30 17:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec 2010-01-30 17:21 . 2010-01-30 17:21 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller 2010-01-30 14:20 . 2010-01-30 14:24 -------- d-----w- c:\windows\system32\Adobe 2010-01-29 17:06 . 2010-02-06 23:35 -------- d-----w- c:\program files\Videos 2010-01-29 16:37 . 2010-01-29 16:37 -------- d-----w- c:\documents and settings\Adrian\Application Data\FastStone 2010-01-29 16:37 . 2010-01-29 16:37 -------- d-----w- c:\program files\FastStone Capture . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-02-27 02:26 . 2010-02-27 02:26 16 ----a-w- c:\windows\system32\config\systemprofile\Application Data\rbuwzv.dat 2010-02-27 02:22 . 2009-02-07 00:35 -------- d-----w- c:\program files\Pazera_Free_FLV_to_AVI_Converter 2010-02-27 01:23 . 2009-07-03 06:47 -------- d-----w- c:\documents and settings\Adrian\Application Data\FileZilla 2010-02-26 16:01 . 2010-02-26 16:01 8 ----a-w- c:\documents and settings\NetworkService\Application Data\rbuwzv.dat 2010-02-26 12:40 . 2008-10-29 18:30 14 ----a-w- c:\windows\popcinfo.dat 2010-02-26 04:20 . 2010-02-26 04:20 12 ----a-w- c:\documents and settings\LocalService\Application Data\rbuwzv.dat 2010-02-25 21:52 . 2008-05-23 16:55 -------- d-----w- c:\documents and settings\Adrian\Application Data\skypePM 2010-02-23 16:51 . 2008-05-23 16:55 -------- d-----w- c:\documents and settings\Adrian\Application Data\Skype 2010-02-11 19:23 . 2010-01-21 22:10 -------- d-----w- c:\program files\PokerStars.NET 2010-01-21 19:01 . 2008-05-23 16:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype 2010-01-18 13:42 . 2010-01-18 13:42 -------- d-----w- c:\documents and settings\Adrian\Application Data\Media Player Classic 2010-01-18 13:42 . 2010-01-18 13:42 -------- d-----w- c:\program files\K-Lite Codec Pack 2010-01-18 13:41 . 2010-01-18 13:00 -------- d-----w- c:\program files\ACE Mega CoDecS Pack 2010-01-18 13:41 . 2010-02-27 01:12 831 ----a-w- c:\windows\system.tmp 2010-01-18 12:51 . 2010-01-18 12:07 -------- d-----w- c:\program files\BSR Screen Recorder 4 2010-01-18 12:13 . 2010-01-18 12:07 2048 ----a-w- c:\windows\system32\Tr_sttool.dat 2009-12-29 06:38 . 2009-12-29 06:33 -------- d-----w- c:\program files\TGIANT 2009-12-22 14:56 . 2008-05-23 14:46 38664 ----a-w- c:\documents and settings\Adrian\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-10-02 19:40 . 2009-10-02 19:33 120566929 ----a-w- c:\program files\Championship Manager 01-02.rar 2008-07-31 16:59 . 2008-06-03 20:20 61038 ----a-w- c:\program files\mozilla firefox\components\jar50.dll 2008-07-31 16:59 . 2008-06-03 20:20 49256 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll 2008-07-31 16:59 . 2008-06-03 20:20 166000 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll 2005-05-13 15:12 . 2005-05-13 15:12 217073 --sha-r- c:\windows\meta4.exe 2005-10-24 09:13 . 2005-10-24 09:13 66560 --sha-r- c:\windows\MOTA113.exe 2005-10-13 19:27 . 2005-10-13 19:27 422400 --sha-r- c:\windows\x2.64.exe 2005-10-07 17:14 . 2005-10-07 17:14 308224 --sha-r- c:\windows\system32\avisynth.dll 2005-07-14 10:31 . 2005-07-14 10:31 27648 --sha-r- c:\windows\system32\AVSredirect.dll 2005-06-26 13:32 . 2005-06-26 13:32 616448 --sha-r- c:\windows\system32\cygwin1.dll 2005-06-21 20:37 . 2005-06-21 20:37 45568 --sha-r- c:\windows\system32\cygz.dll 2004-01-24 22:00 . 2004-01-24 22:00 70656 --sha-r- c:\windows\system32\i420vfw.dll 2006-04-27 08:24 . 2006-04-27 08:24 2945024 --sha-r- c:\windows\system32\Smab.dll 2005-02-28 11:16 . 2005-02-28 11:16 240128 --sha-r- c:\windows\system32\x.264.exe 2004-01-24 22:00 . 2004-01-24 22:00 217088 --sha-r- c:\windows\system32\yv12vfw.dll . ------- Sigcheck ------- [-] 2008-05-22 . 6E266AAF4168B3569A330C61AB01F6B4 . 1580544 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Spyware Doctor"="c:\program files\Spyware Doctor\swdoctor.exe" [2005-12-13 1976544] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDCPL"="RTHDCPL.EXE" [2008-02-13 16857600] "nod32kui"="c:\program files\Eset\nod32kui.exe" [2008-05-24 950664] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480] "nwiz"="nwiz.exe" [2006-10-22 1622016] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360] "Spyware Doctor"="c:\program files\Spyware Doctor\swdoctor.exe" [2005-12-13 1976544] c:\documents and settings\Adrian\Start Menu\Programs\Startup\ Rainlendar.lnk - c:\program files\Rainlendar\Rainlendar.exe [2008-5-23 118784] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-10-6 113664] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" "VX1000"=c:\windows\vVX1000.exe [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"= "c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "21362:TCP"= 21362:TCP:BitComet 21362 TCP "21362:UDP"= 21362:UDP:BitComet 21362 UDP R2 XAMPP;XAMPP Service;c:\xampp\service.exe [x] R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-06 34064] S0 d346bus;d346bus;c:\windows\system32\DRIVERS\d346bus.sys [2004-03-12 156800] S0 d346prt;d346prt;c:\windows\System32\Drivers\d346prt.sys [2004-03-12 5248] S1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2008-05-24 15424] --- Other Services/Drivers In Memory --- *Deregistered* - mchInjDrv HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . Contents of the 'Scheduled Tasks' folder 2010-02-26 c:\windows\Tasks\1-Click Maintenance.job - c:\program files\TuneUp Utilities 2007en\SystemOptimizer.exe [2007-04-26 19:51] . . ------- Supplementary Scan ------- . uStart Page = about:blank IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 IE: {{FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\PokerStars.NET\PokerStarsUpdate.exe LSP: c:\windows\system32\imon.dll TCP: {C969EE38-2110-4871-8507-43738E67EC08} = 212.25.58.229 212.25.58.2 DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://193.68.31.137/activex/AMC.cab DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} - hxxps://plugins.valueactive.eu/flashax/iefax.cab . - - - - ORPHANS REMOVED - - - - WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) AddRemove-HijackThis - c:\hjt\HijackThis.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-02-27 05:54 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv] "ImagePath"="\??\c:\docume~1\Adrian\LOCALS~1\Temp\mc21.tmp" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'lsass.exe'(648) c:\windows\system32\imon.dll - - - - - - - > 'explorer.exe'(1788) c:\windows\system32\msi.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . Completion time: 2010-02-27 05:57:22 ComboFix-quarantined-files.txt 2010-02-27 03:57 Pre-Run: 2 827 997 184 bytes free Post-Run: 4 655 624 192 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect - - End Of File - - D5E4C859C16C4D0DACB57E4F3ED1B4B9
  4. Логовете от Malwarebytes и HijackThis: Malwarebytes' Anti-Malware 1.44 Database version: 3799 Windows 5.1.2600 Service Pack 2 Internet Explorer 8.0.6001.18702 27.2.2010 г. 05:14:07 mbam-log-2010-02-27 (05-14-07).txt Scan type: Full Scan (C:\|D:\|) Objects scanned: 203241 Time elapsed: 33 minute(s), 15 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 3 Folders Infected: 0 Files Infected: 4 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: C:\Documents and Settings\Adrian\Start Menu\Programs\Startup\winesm32.exe (Worm.KoobFace) -> Delete on reboot. C:\Documents and Settings\Adrian\Favorites\Free Porn Sex Porno - a group of young one have a sex party.url (Rogue.Link) -> Quarantined and deleted successfully. C:\Documents and Settings\Adrian\Favorites\Free Porn Sex Porno - Cute girl with Rodney Moore does anal and receives facial.url (Rogue.Link) -> Quarantined and deleted successfully. C:\Documents and Settings\Adrian\Application Data\avdrn.dat (Malware.Trace) -> Quarantined and deleted successfully. -------------------------------------------------------------------------------------------------------------------- Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 05:22:58, on 27.2.2010 г. Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\RTHDCPL.EXE C:\Program Files\Eset\nod32kui.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Spyware Doctor\swdoctor.exe C:\Program Files\Rainlendar\Rainlendar.exe C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe C:\Program Files\Microsoft LifeCam\MSCamS32.exe C:\Program Files\Eset\nod32krn.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe C:\Program Files\Spyware Doctor\sdhelp.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\HJT\kaldata.exe C:\WINDOWS\system32\wbem\wmiprvse.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R3 - URLSearchHook: (no name) - - (no file) O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: Rainlendar.lnk = C:\Program Files\Rainlendar\Rainlendar.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1211800259437 O16 - DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} (ContactExtractor Class) - http://www.facebook.com/controls/contactx.dll O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://193.68.31.137/activex/AMC.cab O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O16 - DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} (Flash Casino Helper Control) - https://plugins.valueactive.eu/flashax/iefax.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{C969EE38-2110-4871-8507-43738E67EC08}: NameServer = 212.25.58.229 212.25.58.2 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe O23 - Service: XAMPP Service (XAMPP) - Unknown owner - c:\xampp\service.exe (file missing) -- End of file - 6638 bytes ---------------------------------------------------------------------------------------------------------------- От инструкциите не разбрах дали да избера FIX CHEKED на HijackThis затова извличам само лог-а. Ако е нужно ще повторя сканирането и ще поправя грешките които дава.
  5. Здравейте, четвъртък вечерта ( 25 02 2010 ) антивирусната ми (nod32) алармира за наличието на троянски кон. алармира за около 10 файла със съобщение че ги вкарва под карантина. няколко часа по късно установих че вируса е изпратил моите юзернаме и парола за фтп достъп към сайт който подържам и беше инсталирал кодове в source на някои файлове на сървъра. оправих това сканирах отново този път не излезе нищо, инсталирах и spyware doctor който откри около 20 проблема и ги поправи. преди малко обаче антивирусната отново сигнализира за наличието на win32 rootkit.kryptik.af trojan във файлове в директория system32. системата работи тромаво, при процесите имам един svhost който заема на 100% процесора. това мога да дам като информация, логовете ще пусна във следващия си пост

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.