Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Проблем с Personal Security [РЕШЕН]

Featured Replies

здравейте!

имам един проблем,активира ми се personal security и security center които ми прецакват нещо системата

изчезват ми иконите от desktop-а и заявяват че системата ми има 42 вируса които мога да премахна като им заплатя лиценз

ако някой може да помогне моля нека да пише

Редактирано от nologo
Корекция на заглавието на темата (преглед на промените)

здравейте!

имам един проблем,активира ми се personal security и security center които ми прецакват нещо системата

изчезват ми иконите от desktop-а и заявяват че системата ми има 42 вируса които мога да премахна като им заплатя лиценз

ако някой може да помогне моля нека да пише

Изтегли Malwarebytes от http://Malwarebytes.net/ обнови и пусни фул-скан.

  • Автор

Изтегли Malwarebytes от http://Malwarebytes.net/ обнови и пусни фул-скан.

свалих free версията кликвам на фаила дава ми "run"кликвам и нищо

доста съм "босичък" в тези работи има ли значение къде свалям фаила C\или D\

Редактирано от kokko (преглед на промените)

свалих free версията кликвам на фаила дава ми "run"кликвам и нищо

доста съм "босичък" в тези работи има ли значение къде свалям фаила C\или D\

В такъв случай,трябва да смениш,разширението на файла от .exe на .com

Тогава ще се стартира успех.

Няма значение,къде си свалил файла,преименувай го на MBARMY.com и го стартирай.

Редактирано от M_Polyce (преглед на промените)

  • Автор

В такъв случай,трябва да смениш,разширението на файла от .exe на .com

Тогава ще се стартира успех.

Няма значение,къде си свалил файла,преименувай го на MBARMY.com и го стартирай.

пак не иска изкача ми"windows няма достъп до указаното устроиство,път или фаил.Може да нямате подходящите права за достъп до елемента"

  • Изтеглете Win32kDiag от някой от следните линкове и го запазете на вашия десктоп.

  • Кликнете два пъти върху Win32kDiag.exe, за да стартирате Win32kDiag , след което я изчакайте да приключи работата си.
  • Когато изпише "Finished! Press any key to exit...", натиснете произволен бутон от вашата клавиатура, за да се затвори прозореца.
  • Кликнете два пъти върху Win32kDiag.txt, който се намира на вашия десктоп и поставете цялото съдържание на лог файла в следващия Ви коментар в тази тема.

  • Автор
' date='09 март 2010 - 22:54 ' timestamp='1268168092' post='1653569']

  • Изтеглете Win32kDiag от някой от следните линкове и го запазете на вашия десктоп.

  • Кликнете два пъти върху Win32kDiag.exe, за да стартирате Win32kDiag , след което я изчакайте да приключи работата си.
  • Когато изпише "Finished! Press any key to exit...", натиснете произволен бутон от вашата клавиатура, за да се затвори прозореца.
  • Кликнете два пъти върху Win32kDiag.txt, който се намира на вашия десктоп и поставете цялото съдържание на лог файла в следващия Ви коментар в тази тема.

Running from: C:\Documents and Settings\User-PC\Desktop\Win32kDiag.exe

Log file at : C:\Documents and Settings\User-PC\Desktop\Win32kDiag.txt

WARNING: Could not get backup privileges!

Searching 'C:\WINDOWS'...

Finished!

незнам дали е важно но като стартирам комп-а и се появят тези security...иконите от десктопа изчезват и се налага да кликам бързичко на нещо ако искам да го отворя и после нов рестарт за да отворя друго (за това се и бавя)

СТЪПКА 1

Изтеглете и инсталирайте инструмента RKill (от Grinler) чрез някои от следните линкове и го запазете на вашия десктоп.

Линк 1

Линк 2

Линк 3

Линк 4

  • Изключете вашата антивирусна програма, обикновено това става чрез натискане на десния бутон на мишката върху иконата на програма в системния трей.

  • Стартирайте изтегления инструмент

  • Ако използвате операционна система Windows Vista или Windows 7 ще е необходимо да стартирате файла, като кликнете с десния бутон на мишката върху него и изберете Run As Administrator

Ако програмата успешно успява да свърши своята работа, то ще се появи черен прозорец, който ще е признак за това. В противен случай, изтрийте това копие на RKill и изтеглете ново от друг линк и продължете така, докато някой от вариантите проработи.

СТЪПКА 2

*. Изтеглете Combofix.

*. Запазете го на на декстопа.

*. Стартирайте инструмента с двукратен клик на мишката.

*. По време на сканиране от страна на ComboFix не стартирайте никакви други приложения, не натискайте клавиши от клавиатурата и не местете мишката !

*. Публикувайте лог файла, който ще се създаде след рестарта на компютъра в следващия си пост.

  • Автор
' date='09 март 2010 - 23:20 ' timestamp='1268169645' post='1653595']

СТЪПКА 1

Изтеглете и инсталирайте инструмента RKill (от Grinler) чрез някои от следните линкове и го запазете на вашия десктоп.

Линк 1

Линк 2

Линк 3

Линк 4

  • Изключете вашата антивирусна програма, обикновено това става чрез натискане на десния бутон на мишката върху иконата на програма в системния трей.

  • Стартирайте изтегления инструмент

  • Ако използвате операционна система Windows Vista или Windows 7 ще е необходимо да стартирате файла, като кликнете с десния бутон на мишката върху него и изберете Run As Administrator

Ако програмата успешно успява да свърши своята работа, то ще се появи черен прозорец, който ще е признак за това. В противен случай, изтрийте това копие на RKill и изтеглете ново от друг линк и продължете така, докато някой от вариантите проработи.

СТЪПКА 2

*. Изтеглете Combofix.

*. Запазете го на на декстопа.

*. Стартирайте инструмента с двукратен клик на мишката.

*. По време на сканиране от страна на ComboFix не стартирайте никакви други приложения, не натискайте клавиши от клавиатурата и не местете мишката !

*. Публикувайте лог файла, който ще се създаде след рестарта на компютъра в следващия си пост.

стартирах RKILL от 1-вия линк пак не ставаше нищо но натиснах "излез"от старт менюто,след което влезнах и пак тъка ,докато се виждаха иконите го стартирах.

Сега вече се виждат

Това е log fail-a:This log file is located at C:\rkill.log.

Please post this only if requested to by the person helping you.

Otherwise you can close this log when you wish.

Ran as User-PC on 03.2010 Ј. at 23:29:20.

Processes terminated by Rkill or while it was running:

C:\WINDOWS\system32\nvsvc32.exe

C:\DOCUME~1\User-PC\LOCALS~1\Temp\Jst.exe

C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe

C:\Documents and Settings\User-PC\Desktop\rkill.pif

Rkill completed on 03.2010 Ј. at 23:29:21.

M,foc.gdld; u; ijcmud 2

  • Автор
' date='09 март 2010 - 23:43 ' timestamp='1268171001' post='1653606']

Продължете със стъпка 2.

ComboFix 10-03-09.04 - User-PC 03.2010 г. 23:52:17.1.2 - x86

Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.1983.1582 [GMT 2:00]

Running from: c:\documents and settings\User-PC\Desktop\ComboFix.exe

AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}

FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}

* Created a new restore point

* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\program files\PersSecurity

c:\program files\PersSecurity\psecurity.exe

c:\windows\system32\ammppg.dll

c:\windows\system32\sshnas21.dll

c:\windows\system32\win32extension.dll

c:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job

c:\windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

-------\Legacy_SSHNAS

-------\Service_SSHNAS

((((((((((((((((((((((((( Files Created from 2010-02-09 to 2010-03-09 )))))))))))))))))))))))))))))))

.

2010-03-08 22:08 . 2009-08-06 17:23 274288 ----a-w- c:\windows\system32\mucltui.dll

2010-03-08 22:08 . 2009-08-06 17:23 215920 ----a-w- c:\windows\system32\muweb.dll

2010-03-08 21:54 . 2010-03-08 21:39 164864 ----a-w- c:\windows\Jlujeb.exe

2010-03-08 21:36 . 2010-03-08 21:36 -------- d-----w- c:\program files\Common Files\PersSecurityUninstall

2010-03-08 21:34 . 2010-03-08 21:34 164864 ----a-w- c:\windows\Jlujea.exe

2010-03-08 20:27 . 2010-03-08 20:27 152576 ----a-w- c:\documents and settings\User-PC\Application Data\Sun\Java\jre1.6.0_17\lzma.dll

2010-03-06 14:20 . 2010-03-08 21:52 -------- d-----w- c:\documents and settings\User-PC\Application Data\######

2010-03-05 19:49 . 2010-03-05 19:49 -------- d-----w- c:\documents and settings\User-PC\Application Data\ImTOO Software Studio

2010-02-25 09:30 . 2010-02-25 09:50 -------- d-----w- c:\program files\Common Files\Real

2010-02-20 18:32 . 2010-02-20 18:32 -------- d-----w- c:\windows\solcache

2010-02-19 20:55 . 2010-02-19 20:55 -------- d-----w- c:\documents and settings\User-PC\Local Settings\Application Data\WMTools Downloaded Files

2010-02-18 08:49 . 2010-03-05 11:01 -------- d-----w- c:\documents and settings\User-PC\Application Data\f2fPreIntermediate

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-03-08 21:53 . 2009-06-10 16:39 -------- d-----w- c:\documents and settings\User-PC\Application Data\Skype

2010-03-08 20:26 . 2010-01-08 19:35 79488 ----a-w- c:\documents and settings\User-PC\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll

2010-03-08 18:53 . 2008-12-19 17:01 -------- d-----w- c:\documents and settings\User-PC\Application Data\skypePM

2010-03-07 22:33 . 2008-06-04 08:38 -------- d-----w- c:\documents and settings\User-PC\Application Data\uTorrent

2010-03-06 13:42 . 2009-12-04 15:21 -------- d-----w- c:\documents and settings\User-PC\Application Data\Winamp

2010-03-01 20:00 . 2009-04-26 07:30 -------- d-----w- c:\program files\Microsoft Silverlight

2010-02-26 09:24 . 2008-06-04 08:38 -------- d-----w- c:\program files\uTorrent

2010-02-21 13:53 . 2008-06-04 08:37 -------- d-----w- c:\program files\Common Files\Adobe

2010-02-20 17:07 . 2009-01-10 23:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Codemasters

2010-02-20 15:16 . 2008-06-04 08:24 -------- d--h--w- c:\program files\InstallShield Installation Information

2010-02-17 17:20 . 2008-12-26 00:30 107888 ----a-w- c:\windows\system32\CmdLineExt.dll

2010-02-12 11:58 . 2010-01-19 18:52 -------- d-----w- c:\documents and settings\User-PC\Application Data\f2fElementary

2010-02-04 22:41 . 2008-06-04 07:48 -------- d-----w- c:\program files\System

2010-02-04 22:40 . 2008-06-04 07:51 -------- d-----w- c:\program files\Windows Media Connect 2

2010-02-04 22:36 . 2008-12-29 15:09 -------- d-----w- c:\program files\Google

2010-02-03 20:00 . 2009-04-15 15:11 139128 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys

2010-02-03 20:00 . 2009-04-15 15:11 215128 ----a-w- c:\windows\system32\PnkBstrB.exe

2010-02-03 19:18 . 2008-12-22 23:04 138056 ----a-w- c:\documents and settings\User-PC\Application Data\PnkBstrK.sys

2010-02-03 19:18 . 2008-12-22 23:04 138056 ----a-w- c:\documents and settings\User-PC\Application Data\PnkBstrK.sys

2010-02-03 19:18 . 2009-04-15 15:10 75064 ----a-w- c:\windows\system32\PnkBstrA.exe

2010-02-03 19:18 . 2010-02-03 19:18 2434856 ----a-w- c:\windows\system32\pbsvc_bc2.exe

2010-01-31 22:23 . 2009-04-18 19:19 2250024 ----a-w- c:\windows\system32\pbsvc.exe

2010-01-19 19:38 . 2008-06-04 08:14 19192 ----a-w- c:\documents and settings\User-PC\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2009-12-12 12:29 . 2008-06-04 07:48 445016 ----a-w- c:\windows\system32\wrap_oal.dll

2009-12-12 12:29 . 2008-06-04 07:48 109144 ----a-w- c:\windows\system32\OpenAL32.dll

.

------- Sigcheck -------

[-] 2008-04-24 . C951DB3D9B6EF3CF4B82454D30A8BF59 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"DAEMON Tools Lite"="d:\games\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2007-12-21 1443072]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-11 13574144]

"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2006-11-23 487424]

"BigDog303"="c:\windows\VM303_STI.EXE" [2005-10-25 61440]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]

"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-07-01 37888]

"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2009-12-18 40368]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"nltide_2"="shell32" [X]

c:\documents and settings\User-PC\Start Menu\Programs\Startup\

######.lnk - d:\programi\fiestaBar\######.exe [2009-12-4 829440]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]

2009-12-18 06:58 40368 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]

2005-05-03 10:43 69632 ------r- c:\windows\Alcmtr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]

2008-04-13 18:42 15360 ------w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]

2006-05-18 08:29 49152 ----a-w- c:\program files\CyberLink\PowerDVD\Language\Language.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

2006-01-12 12:40 155648 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]

2008-09-11 09:13 13574144 ----a-w- c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]

2008-09-11 09:13 86016 ----a-w- c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]

2008-09-11 09:13 1657376 ----a-w- c:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]

2005-12-07 19:57 30208 ------w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]

2007-08-20 07:38 16384512 ------r- c:\windows\RTHDCPL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]

2009-10-09 11:11 25623336 ----a-r- c:\program files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TBPanel]

2008-09-05 16:24 2154496 ----a-w- c:\program files\Vtune\TBPANEL.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\uTorrent\\uTorrent.exe"=

"c:\\WINDOWS\\system32\\PnkBstrA.exe"=

"c:\\WINDOWS\\system32\\PnkBstrB.exe"=

"d:\\GAMES\\Race.Driver.GRID.RePack\\GRID\\GRID.exe"=

"d:\\GAMES\\FlatOut 2\\flatout2.exe"=

"d:\\GAMES\\Tom.Clancys.H.A.W.X-SKIDROW\\sr-tch\\HAWX.exe"=

"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=

"d:\\GAMES\\Dirt.2-RELOADED\\dirt2_game.exe"=

"d:\\GAMES\\Operation.Flashpoint.Dragon.Rising-RELOADED\\OFDR.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [19.12.2008 і. 19:34 721904]

R2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [21.12.2007 і. 07:21 468224]

R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [11.10.2009 і. 23:28 222968]

S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [04.2.2010 і. 23:11 135664]

S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys --> d:\NTGLM7X.sys [?]

.

Contents of the 'Scheduled Tasks' folder

2010-03-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-04 21:11]

2010-03-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-04 21:11]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.msn.com

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

FF - ProfilePath - c:\documents and settings\User-PC\Application Data\Mozilla\Firefox\Profiles\5jsf1ael.default\

FF - prefs.js: browser.search.selectedEngine - Google

FF - prefs.js: browser.startup.homepage - hxxp://www.data.bg/

FF - component: c:\documents and settings\User-PC\Application Data\Mozilla\Firefox\Profiles\5jsf1ael.default\extensions\[email protected]\components\DTToolbarFF.dll

FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll

FF - plugin: c:\program files\Google\Update\1.2.183.17\npGoogleOneClick8.dll

.

- - - - ORPHANS REMOVED - - - -

WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)

HKCU-Run-PersSecurity - c:\program files\PersSecurity\psecurity.exe

AddRemove-PersSecurity - c:\program files\PersSecurity\psecurity.exe

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-03-09 23:56

Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

BigDog303 = c:\windows\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)????????????????0?????????@??????????????

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully

user: MBR read successfully

called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spun.sys >>UNKNOWN [0x8A31E938]<<

kernel: MBR read successfully

detected MBR rootkit hooks:

\Driver\Disk -> CLASSPNP.SYS @ 0xf763bf28

\Driver\ACPI -> ACPI.sys @ 0xf7495cb8

\Driver\atapi -> atapi.sys @ 0xf7978b40

IoDeviceObjectType -> ParseProcedure -> ntoskrnl.exe @ 0x8057b6b1

\Device\Harddisk0\DR0 -> ParseProcedure -> ntoskrnl.exe @ 0x8057b6b1

NDIS: NVIDIA nForce Networking Controller -> SendCompleteHandler -> NDIS.sys @ 0xf7b3abb0

PacketIndicateHandler -> NDIS.sys @ 0xf7b47a21

SendHandler -> NDIS.sys @ 0xf7b2587b

user & kernel MBR OK

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1202660629-790525478-682003330-1003\Software\Microsoft\SystemCertificates\AddressBook*]

@Allowed: (Read) (RestrictedCode)

@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-1202660629-790525478-682003330-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]

"??"=hex:e1,3f,08,00,2b,5f,ad,57,b1,23,9c,44,6d,9c,a3,e4,c9,4c,b4,d2,fd,92,7d,

5a,2d,18,71,55,d2,e4,29,24,85,ef,1e,bf,3a,76,7d,36,21,16,fe,21,e9,40,d0,6e,\

"??"=hex:b6,3c,a3,f5,1b,49,13,25,4e,a7,4b,c6,d1,2b,df,ea

[HKEY_USERS\S-1-5-21-1202660629-790525478-682003330-1003\Software\SecuROM\License information*]

"datasecu"=hex:a1,f9,4f,3d,9c,7c,8e,21,d4,6f,9d,d9,c7,bf,01,69,76,49,aa,6a,7a,

26,52,2b,24,70,cd,93,1a,7f,a5,17,d9,f2,4d,ea,ca,ee,f5,4e,56,a3,5f,68,00,d8,\

"rkeysecu"=hex:87,15,77,a3,da,f3,9b,39,49,4c,dd,d3,a6,ff,ac,ec

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(4064)

c:\windows\system32\msi.dll

c:\windows\system32\ieframe.dll

c:\windows\system32\OneX.DLL

c:\windows\system32\eappprxy.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\WPDShServiceObj.dll

c:\windows\system32\PortableDeviceTypes.dll

c:\windows\system32\PortableDeviceApi.dll

.

------------------------ Other Running Processes ------------------------

.

c:\windows\system32\nvsvc32.exe

c:\windows\system32\PnkBstrA.exe

c:\windows\system32\PnkBstrB.exe

c:\program files\Internet Explorer\IEXPLORE.EXE

c:\program files\CyberLink\Shared files\RichVideo.exe

c:\program files\Common Files\Teleca Shared\Generic.exe

c:\program files\Internet Explorer\IEXPLORE.EXE

c:\program files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe

.

**************************************************************************

.

Completion time: 2010-03-09 23:58:34 - machine was rebooted

ComboFix-quarantined-files.txt 2010-03-09 21:58

Pre-Run: 6 884 372 480 bytes free

Post-Run: 9 897 594 880 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer

- - End Of File - - 0D6DA0C46742F038981DC4581E52F36F

' date='09 март 2010 - 23:43 ' timestamp='1268171001' post='1653606']

Продължете със стъпка 2.

нещо друго трябва ли да правя

автоматичните ъпдейтвания на "security center"трябва ли да ги изключа

от тези програми има ли ненужна:"Win32kDiag";"rkill"

"ComboFIx" предполагам ,че ще ми трябва

СТЪПКА 1

Отворете Control Panel => Add or remove programs => намерете от списъка и деинсталирайте Daemon Tools.

След това изтеглете този файл и го стартирайте.

Изберете Uninstall (ако това меню е активно).

Затворете приложението.

Ако се наложи рестартирайте компютъра.

СТЪПКА 2

*. Отворете notepad.exe и с copy/paste въведете следната информация:


http://www.kaldata.com/forums/index.php?showtopic=151217


KILLALL::

Driver::

SetupNTGLM7X

Collect::

c:\windows\Jlujea.exe

c:\documents and settings\User-PC\LOCAL SETTINGS\TEMP\Jst.exe

d:\ntglm7x.sys

DirLook::

c:\documents and settings\User-PC\Application Data\######

d:\programi\fiestaBar

Запазете файла с име CFScript и го провлачете и пуснете в Combofix (както е показано на картинката отдолу).

cfscript10uc2.gif

*. По време на сканиране от страна на ComboFix не стартирайте никакви други приложения, не натискайте клавиши от клавиатурата и не местете мишката !

*. Публикувайте лог файла, който ще се създаде след рестарта на компютъра в следващия си пост.

  • Автор

стъпка1:

daemon tools го премахнах уж,обаче долу вдясно иконката си остана

след това изтеглих фаила,стартирах го и ми изписва:

C:\Document and Settings\User-PC\desktop\SPTDinst-v162-n86.exe isnot a valid Win32 application.

Сега я премахнах.Кликнах с десният бутон на мишката,след това "Exit" и изчезна.

стъпка1:

daemon tools го премахнах уж,обаче долу вдясно иконката си остана

след това изтеглих фаила,стартирах го и ми изписва:

C:\Document and Settings\User-PC\desktop\SPTDinst-v162-n86.exe isnot a valid Win32 application.

Сега я премахнах.Кликнах с десният бутон на мишката,след това "Exit" и изчезна.

Едва ли сте я премахнали така. С exit само я затваряте, което на нас не ни върши работа.

Би трябвало като изберете Add or Remove programs - Uninstall, процеса на деинсталация да убие активния процес на Daemon Tools и след това да я деинсталира.

Както и да е. Продължете със стъпка 2.

  • Автор
' date='10 март 2010 - 15:04 ' timestamp='1268226245' post='1653973']

Едва ли сте я премахнали така. С exit само я затваряте, което на нас не ни върши работа.

Би трябвало като изберете Add or Remove programs - Uninstall, процеса на деинсталация да убие активния процес на Daemon Tools и след това да я деинсталира.

Както и да е. Продължете със стъпка 2.

Мисля ,че я премахнах,защото като пусна търсачката на компютъра не намира "daemon tools"фаил

Обаче не намирам и "Notepad.exe"

Редактирано от kokko (преглед на промените)

Изтеглете прикачения файл и го провлачете и пуснете в Combofix (както е показано на картинката отдолу).

cfscript10uc2.gif

*. По време на сканиране от страна на ComboFix не стартирайте никакви други приложения, не натискайте клавиши от клавиатурата и не местете мишката !

*. Публикувайте лог файла, който ще се създаде след рестарта на компютъра в следващия си пост.

CFScript.txt

  • Автор
' date='10 март 2010 - 21:24 ' timestamp='1268249059' post='1654396']

Изтеглете прикачения файл и го провлачете и пуснете в Combofix (както е показано на картинката отдолу).

cfscript10uc2.gif

*. По време на сканиране от страна на ComboFix не стартирайте никакви други приложения, не натискайте клавиши от клавиатурата и не местете мишката !

*. Публикувайте лог файла, който ще се създаде след рестарта на компютъра в следващия си пост.

ComboFix 10-03-10.02 - User-PC 03.2010 г. 21:41:11.2.2 - x86

Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.1983.1476 [GMT 2:00]

Running from: c:\documents and settings\User-PC\Desktop\ComboFix.exe

Command switches used :: c:\documents and settings\User-PC\Desktop\CFScript.txt

AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}

FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}

* Resident AV is active

file zipped: c:\windows\Jlujea.exe

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\windows\Jlujea.exe

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

-------\Legacy_SETUPNTGLM7X

-------\Service_SetupNTGLM7X

((((((((((((((((((((((((( Files Created from 2010-02-10 to 2010-03-10 )))))))))))))))))))))))))))))))

.

2010-03-10 12:09 . 2010-03-10 12:09 -------- d-----w- c:\program files\MSXML 4.0

2010-03-10 07:42 . 2009-12-21 19:14 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll

2010-03-10 07:42 . 2009-12-21 19:14 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll

2010-03-08 22:08 . 2009-08-06 17:23 274288 ----a-w- c:\windows\system32\mucltui.dll

2010-03-08 22:08 . 2009-08-06 17:23 215920 ----a-w- c:\windows\system32\muweb.dll

2010-03-08 21:54 . 2010-03-08 21:39 164864 ----a-w- c:\windows\Jlujeb.exe

2010-03-08 21:36 . 2010-03-08 21:36 -------- d-----w- c:\program files\Common Files\PersSecurityUninstall

2010-03-08 20:27 . 2010-03-08 20:27 152576 ----a-w- c:\documents and settings\User-PC\Application Data\Sun\Java\jre1.6.0_17\lzma.dll

2010-03-06 14:20 . 2010-03-10 07:38 -------- d-----w- c:\documents and settings\User-PC\Application Data\######

2010-03-05 19:49 . 2010-03-05 19:49 -------- d-----w- c:\documents and settings\User-PC\Application Data\ImTOO Software Studio

2010-02-25 09:30 . 2010-02-25 09:50 -------- d-----w- c:\program files\Common Files\Real

2010-02-20 18:32 . 2010-02-20 18:32 -------- d-----w- c:\windows\solcache

2010-02-19 20:55 . 2010-02-19 20:55 -------- d-----w- c:\documents and settings\User-PC\Local Settings\Application Data\WMTools Downloaded Files

2010-02-18 08:49 . 2010-03-05 11:01 -------- d-----w- c:\documents and settings\User-PC\Application Data\f2fPreIntermediate

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-03-10 12:08 . 2008-06-04 08:38 -------- d-----w- c:\documents and settings\User-PC\Application Data\uTorrent

2010-03-08 21:53 . 2009-06-10 16:39 -------- d-----w- c:\documents and settings\User-PC\Application Data\Skype

2010-03-08 20:26 . 2010-01-08 19:35 79488 ----a-w- c:\documents and settings\User-PC\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll

2010-03-08 18:53 . 2008-12-19 17:01 -------- d-----w- c:\documents and settings\User-PC\Application Data\skypePM

2010-03-06 13:42 . 2009-12-04 15:21 -------- d-----w- c:\documents and settings\User-PC\Application Data\Winamp

2010-03-01 20:00 . 2009-04-26 07:30 -------- d-----w- c:\program files\Microsoft Silverlight

2010-02-26 09:24 . 2008-06-04 08:38 -------- d-----w- c:\program files\uTorrent

2010-02-21 13:53 . 2008-06-04 08:37 -------- d-----w- c:\program files\Common Files\Adobe

2010-02-20 17:07 . 2009-01-10 23:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Codemasters

2010-02-20 15:16 . 2008-06-04 08:24 -------- d--h--w- c:\program files\InstallShield Installation Information

2010-02-17 17:20 . 2008-12-26 00:30 107888 ----a-w- c:\windows\system32\CmdLineExt.dll

2010-02-12 11:58 . 2010-01-19 18:52 -------- d-----w- c:\documents and settings\User-PC\Application Data\f2fElementary

2010-02-04 22:41 . 2008-06-04 07:48 -------- d-----w- c:\program files\System

2010-02-04 22:40 . 2008-06-04 07:51 -------- d-----w- c:\program files\Windows Media Connect 2

2010-02-04 22:36 . 2008-12-29 15:09 -------- d-----w- c:\program files\Google

2010-02-03 20:00 . 2009-04-15 15:11 139128 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys

2010-02-03 20:00 . 2009-04-15 15:11 215128 ----a-w- c:\windows\system32\PnkBstrB.exe

2010-02-03 19:18 . 2008-12-22 23:04 138056 ----a-w- c:\documents and settings\User-PC\Application Data\PnkBstrK.sys

2010-02-03 19:18 . 2008-12-22 23:04 138056 ----a-w- c:\documents and settings\User-PC\Application Data\PnkBstrK.sys

2010-02-03 19:18 . 2009-04-15 15:10 75064 ----a-w- c:\windows\system32\PnkBstrA.exe

2010-02-03 19:18 . 2010-02-03 19:18 2434856 ----a-w- c:\windows\system32\pbsvc_bc2.exe

2010-01-31 22:23 . 2009-04-18 19:19 2250024 ----a-w- c:\windows\system32\pbsvc.exe

2010-01-19 19:38 . 2008-06-04 08:14 19192 ----a-w- c:\documents and settings\User-PC\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2009-12-31 16:50 . 2008-04-13 13:45 353792 ----a-w- c:\windows\system32\drivers\srv.sys

2009-12-21 19:14 . 2008-04-24 02:24 916480 ----a-w- c:\windows\system32\wininet.dll

2009-12-16 18:43 . 2008-06-04 07:47 343040 ----a-w- c:\windows\system32\mspaint.exe

2009-12-14 07:08 . 2008-04-13 18:41 33280 ----a-w- c:\windows\system32\csrsrv.dll

2009-12-12 12:29 . 2008-06-04 07:48 445016 ----a-w- c:\windows\system32\wrap_oal.dll

2009-12-12 12:29 . 2008-06-04 07:48 109144 ----a-w- c:\windows\system32\OpenAL32.dll

.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))

.

---- Directory of c:\documents and settings\User-PC\Application Data\###### ----

---- Directory of d:\programi\fiestaBar ----

2010-03-08 18:51 . 2010-03-09 08:55 597 ----a-w- d:\programi\fiestaBar\Diag.log

2010-03-06 14:20 . 2010-03-06 14:20 396 ----a-w- d:\programi\fiestaBar\base_m.swf

2010-03-06 14:19 . 2010-03-06 14:19 94512 ----a-w- d:\programi\fiestaBar\Uninstall.exe

2009-12-04 14:51 . 2009-12-04 14:51 829440 ----a-w- d:\programi\fiestaBar\######.exe

2009-12-04 14:42 . 2009-12-04 14:42 183296 ----a-w- d:\programi\fiestaBar\CFFilter.dll

2009-12-02 14:03 . 2009-12-02 14:03 76800 ----a-w- d:\programi\fiestaBar\default.cfx

2009-08-06 14:00 . 2009-08-06 14:00 80896 ----a-w- d:\programi\fiestaBar\silver.cfx

2009-08-06 13:59 . 2009-08-06 13:59 87040 ----a-w- d:\programi\fiestaBar\cherry.cfx

------- Sigcheck -------

[-] 2008-04-24 . C951DB3D9B6EF3CF4B82454D30A8BF59 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll

.

((((((((((((((((((((((((((((( SnapShot@2010-03-09_21.56.18 )))))))))))))))))))))))))))))))))))))))))

.

+ 2008-04-13 18:42 . 2009-06-25 08:25 54272 c:\windows\system32\wdigest.dll

+ 2008-04-13 18:42 . 2010-01-23 08:11 46080 c:\windows\system32\tzchange.exe

+ 2008-04-13 18:42 . 2009-06-12 12:31 80896 c:\windows\system32\tlntsess.exe

+ 2008-04-13 18:42 . 2009-06-12 12:31 76288 c:\windows\system32\telnet.exe

+ 2008-04-13 18:42 . 2009-06-25 08:25 56832 c:\windows\system32\secur32.dll

- 2008-04-13 18:42 . 2009-02-03 19:59 56832 c:\windows\system32\secur32.dll

+ 2008-04-13 18:42 . 2009-10-12 13:38 79872 c:\windows\system32\raschap.dll

- 2008-04-13 18:42 . 2008-04-13 18:42 79872 c:\windows\system32\raschap.dll

+ 2001-08-23 11:00 . 2010-03-10 19:40 72544 c:\windows\system32\perfc009.dat

- 2001-08-23 11:00 . 2010-03-09 21:53 72544 c:\windows\system32\perfc009.dat

+ 2008-04-14 05:42 . 2009-11-27 17:11 17920 c:\windows\system32\msyuv.dll

+ 2001-08-23 11:00 . 2009-11-27 16:07 28672 c:\windows\system32\msvidc32.dll

- 2008-04-13 18:42 . 2008-04-13 18:42 11264 c:\windows\system32\msrle32.dll

+ 2008-04-13 18:42 . 2009-11-27 16:07 11264 c:\windows\system32\msrle32.dll

- 2008-04-24 02:23 . 2009-03-08 01:31 55296 c:\windows\system32\msfeedsbs.dll

+ 2008-04-24 02:23 . 2009-12-21 19:14 55296 c:\windows\system32\msfeedsbs.dll

+ 2008-04-13 18:42 . 2009-09-04 21:03 58880 c:\windows\system32\msasn1.dll

+ 2008-04-24 02:23 . 2009-12-21 19:14 25600 c:\windows\system32\jsproxy.dll

- 2008-04-24 02:23 . 2009-03-08 01:33 25600 c:\windows\system32\jsproxy.dll

+ 2008-04-14 05:41 . 2009-11-27 16:07 48128 c:\windows\system32\iyuv_32.dll

+ 2008-04-13 18:41 . 2009-10-15 16:28 81920 c:\windows\system32\fontsub.dll

+ 2008-04-13 13:01 . 2009-06-24 11:18 92928 c:\windows\system32\drivers\ksecdd.sys

+ 2008-04-13 18:42 . 2009-06-25 08:25 54272 c:\windows\system32\dllcache\wdigest.dll

+ 2008-04-13 18:42 . 2009-06-12 12:31 80896 c:\windows\system32\dllcache\tlntsess.exe

+ 2008-04-13 18:42 . 2009-06-12 12:31 76288 c:\windows\system32\dllcache\telnet.exe

- 2008-04-13 18:42 . 2009-02-03 19:59 56832 c:\windows\system32\dllcache\secur32.dll

+ 2008-04-13 18:42 . 2009-06-25 08:25 56832 c:\windows\system32\dllcache\secur32.dll

- 2008-04-13 18:42 . 2008-04-13 18:42 79872 c:\windows\system32\dllcache\raschap.dll

+ 2008-04-13 18:42 . 2009-10-12 13:38 79872 c:\windows\system32\dllcache\raschap.dll

+ 2009-11-27 17:11 . 2009-11-27 17:11 17920 c:\windows\system32\dllcache\msyuv.dll

+ 2001-08-23 11:00 . 2009-11-27 16:07 28672 c:\windows\system32\dllcache\msvidc32.dll

+ 2008-04-13 18:42 . 2009-11-27 16:07 11264 c:\windows\system32\dllcache\msrle32.dll

- 2008-04-13 18:42 . 2008-04-13 18:42 11264 c:\windows\system32\dllcache\msrle32.dll

+ 2009-02-20 18:09 . 2009-12-21 19:14 55296 c:\windows\system32\dllcache\msfeedsbs.dll

- 2009-02-20 18:09 . 2009-03-08 01:31 55296 c:\windows\system32\dllcache\msfeedsbs.dll

+ 2008-04-13 18:42 . 2009-09-04 21:03 58880 c:\windows\system32\dllcache\msasn1.dll

+ 2008-04-13 13:01 . 2009-06-24 11:18 92928 c:\windows\system32\dllcache\ksecdd.sys

- 2008-04-24 02:23 . 2009-03-08 01:33 25600 c:\windows\system32\dllcache\jsproxy.dll

+ 2008-04-24 02:23 . 2009-12-21 19:14 25600 c:\windows\system32\dllcache\jsproxy.dll

+ 2009-11-27 16:07 . 2009-11-27 16:07 48128 c:\windows\system32\dllcache\iyuv_32.dll

+ 2008-04-13 18:41 . 2009-10-15 16:28 81920 c:\windows\system32\dllcache\fontsub.dll

+ 2008-04-13 18:41 . 2009-12-14 07:08 33280 c:\windows\system32\dllcache\csrsrv.dll

- 2008-04-13 18:41 . 2008-04-13 18:41 84992 c:\windows\system32\dllcache\avifil32.dll

+ 2008-04-13 18:41 . 2009-11-27 16:07 84992 c:\windows\system32\dllcache\avifil32.dll

- 2008-04-13 18:41 . 2008-04-13 18:41 58880 c:\windows\system32\dllcache\atl.dll

+ 2008-04-13 18:41 . 2009-07-17 19:01 58880 c:\windows\system32\dllcache\atl.dll

- 2008-04-13 18:41 . 2008-04-13 18:41 84992 c:\windows\system32\avifil32.dll

+ 2008-04-13 18:41 . 2009-11-27 16:07 84992 c:\windows\system32\avifil32.dll

+ 2008-04-13 18:41 . 2009-07-17 19:01 58880 c:\windows\system32\atl.dll

- 2008-04-13 18:41 . 2008-04-13 18:41 58880 c:\windows\system32\atl.dll

+ 2009-06-24 17:56 . 2009-06-24 17:56 73728 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe

+ 2008-05-27 22:49 . 2008-05-27 22:49 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll

- 2007-04-13 18:58 . 2007-04-13 18:58 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll

+ 2008-05-27 22:49 . 2008-05-27 22:49 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll

- 2007-04-13 18:57 . 2007-04-13 18:57 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll

+ 2008-05-27 22:49 . 2008-05-27 22:49 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll

- 2007-04-13 18:57 . 2007-04-13 18:57 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll

- 2007-04-13 19:30 . 2007-04-13 19:30 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe

+ 2008-05-27 23:30 . 2008-05-27 23:30 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe

+ 2010-03-10 12:09 . 2010-03-10 12:09 32768 c:\windows\Installer\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}\icon.exe

- 2008-06-04 08:30 . 2008-06-04 08:30 23040 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe

+ 2008-06-04 08:30 . 2010-03-10 12:20 23040 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe

+ 2008-06-04 08:30 . 2010-03-10 12:20 61440 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe

- 2008-06-04 08:30 . 2008-06-04 08:30 61440 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe

+ 2008-06-04 08:30 . 2010-03-10 12:20 27136 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe

- 2008-06-04 08:30 . 2008-06-04 08:30 27136 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe

- 2008-06-04 08:30 . 2008-06-04 08:30 11264 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe

+ 2008-06-04 08:30 . 2010-03-10 12:20 11264 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe

- 2008-06-04 08:30 . 2008-06-04 08:30 86016 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe

+ 2008-06-04 08:30 . 2010-03-10 12:20 86016 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe

- 2008-06-04 08:30 . 2008-06-04 08:30 12288 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe

+ 2008-06-04 08:30 . 2010-03-10 12:20 12288 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe

+ 1999-12-09 21:21 . 1999-12-09 21:21 32768 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.7969\XLCALL32.DLL

+ 2005-03-17 14:32 . 2005-03-17 14:32 74944 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.7969\RM.DLL

+ 2003-07-14 22:42 . 2003-07-14 22:42 37432 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.7969\RECALL.DLL

+ 2005-03-31 13:21 . 2005-03-31 13:21 64200 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.7969\OUTLRPC.DLL

+ 2005-04-25 13:29 . 2005-04-25 13:29 92360 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.7969\OUTLMIME.DLL

+ 2005-03-17 14:09 . 2005-03-17 14:09 25288 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.7969\OUTLACCT.DLL

+ 2005-03-17 14:32 . 2005-03-17 14:32 77000 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.7969\DLGSETP.DLL

+ 2005-03-17 14:32 . 2005-03-17 14:32 88264 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.7969\ADDRPARS.DLL

+ 2010-03-10 12:19 . 2009-03-08 01:33 12288 c:\windows\ie8updates\KB978207-IE8\xpshims.dll

+ 2010-03-10 12:19 . 2009-03-08 01:31 55296 c:\windows\ie8updates\KB978207-IE8\msfeedsbs.dll

+ 2010-03-10 12:19 . 2009-03-08 01:33 25600 c:\windows\ie8updates\KB978207-IE8\jsproxy.dll

+ 2008-12-21 11:44 . 2009-11-27 17:11 17920 c:\windows\Driver Cache\i386\msyuv.dll

+ 2009-11-27 16:07 . 2009-11-27 16:07 48128 c:\windows\Driver Cache\i386\iyuv_32.dll

+ 2010-03-10 12:11 . 2010-03-10 12:11 90112 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_c28549a3\System.Drawing.Design.dll

+ 2010-03-10 12:11 . 2010-03-10 12:11 61440 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_689cb644\CustomMarshalers.dll

+ 2010-03-10 18:37 . 2010-03-10 18:37 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\fd23e35a951d31ea22e802cb811ec8d4\UIAutomationProvider.ni.dll

+ 2010-03-10 12:19 . 2010-03-10 12:19 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\e32bbe37990199c04777207187e32148\PresentationFontCache.ni.exe

+ 2010-03-10 12:19 . 2010-03-10 12:19 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\7d2c7c871a7bfb3a7b511dc0656555d8\PresentationCFFRasterizer.ni.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll

+ 2001-08-17 22:36 . 2009-11-27 16:07 8704 c:\windows\system32\tsbyuv.dll

+ 2009-11-27 16:07 . 2009-11-27 16:07 8704 c:\windows\system32\dllcache\tsbyuv.dll

+ 2008-06-04 08:30 . 2010-03-10 12:20 4096 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe

- 2008-06-04 08:30 . 2008-06-04 08:30 4096 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe

+ 2009-11-27 16:07 . 2009-11-27 16:07 8704 c:\windows\Driver Cache\i386\tsbyuv.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll

- 2009-12-12 12:33 . 2009-12-12 12:33 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll

- 2009-12-12 12:33 . 2009-12-12 12:33 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll

+ 2006-10-18 10:47 . 2009-04-01 21:02 604160 c:\windows\system32\wmspdmod.dll

+ 2006-10-18 10:47 . 2009-07-13 21:43 286208 c:\windows\system32\wmpdxm.dll

+ 2008-04-13 18:42 . 2009-06-10 06:14 132096 c:\windows\system32\wkssvc.dll

- 2008-04-13 18:42 . 2008-04-13 18:42 132096 c:\windows\system32\wkssvc.dll

+ 2008-04-13 18:42 . 2009-10-15 16:28 119808 c:\windows\system32\t2embed.dll

- 2008-04-13 18:42 . 2008-10-03 10:02 247326 c:\windows\system32\strmdll.dll

+ 2008-04-13 18:42 . 2009-08-26 08:00 247326 c:\windows\system32\strmdll.dll

- 2008-04-13 18:42 . 2008-04-13 18:42 474112 c:\windows\system32\shlwapi.dll

+ 2008-04-13 18:42 . 2009-12-08 09:23 474112 c:\windows\system32\shlwapi.dll

+ 2008-04-13 18:42 . 2009-06-25 08:25 147456 c:\windows\system32\schannel.dll

+ 2008-04-13 18:42 . 2009-04-15 14:51 585216 c:\windows\system32\rpcrt4.dll

+ 2008-04-13 18:42 . 2009-10-12 13:38 149504 c:\windows\system32\rastls.dll

- 2001-08-23 11:00 . 2010-03-09 21:53 445052 c:\windows\system32\perfh009.dat

+ 2001-08-23 11:00 . 2010-03-10 19:40 445052 c:\windows\system32\perfh009.dat

+ 2008-04-24 02:24 . 2009-12-21 19:14 206848 c:\windows\system32\occache.dll

- 2008-04-13 18:42 . 2008-04-13 18:42 270336 c:\windows\system32\oakley.dll

+ 2008-04-13 18:42 . 2009-10-13 10:30 270336 c:\windows\system32\oakley.dll

+ 2008-04-13 18:42 . 2009-08-05 09:01 204800 c:\windows\system32\mswebdvd.dll

+ 2008-04-13 18:42 . 2009-09-11 14:18 136192 c:\windows\system32\msv1_0.dll

- 2008-04-24 02:23 . 2009-03-08 01:32 594432 c:\windows\system32\msfeeds.dll

+ 2008-04-24 02:23 . 2009-12-21 19:14 594432 c:\windows\system32\msfeeds.dll

+ 2008-04-13 18:41 . 2009-06-25 08:25 730112 c:\windows\system32\lsasrv.dll

+ 2008-04-13 18:41 . 2009-05-07 15:32 345600 c:\windows\system32\localspl.dll

+ 2008-04-13 18:41 . 2009-06-25 08:25 301568 c:\windows\system32\kerberos.dll

+ 2008-04-13 18:41 . 2009-12-09 05:53 726528 c:\windows\system32\jscript.dll

- 2008-04-13 18:41 . 2009-03-08 01:33 726528 c:\windows\system32\jscript.dll

+ 2008-04-24 02:23 . 2009-12-21 19:14 184320 c:\windows\system32\iepeers.dll

+ 2008-04-24 02:22 . 2009-12-21 19:14 387584 c:\windows\system32\iedkcs32.dll

- 2008-04-24 02:22 . 2009-03-08 01:32 173056 c:\windows\system32\ie4uinit.exe

+ 2008-04-24 02:22 . 2009-12-21 13:19 173056 c:\windows\system32\ie4uinit.exe

- 2008-06-04 10:41 . 2010-01-11 16:13 118152 c:\windows\system32\FNTCACHE.DAT

+ 2008-06-04 10:41 . 2010-03-10 18:35 118152 c:\windows\system32\FNTCACHE.DAT

+ 2008-04-13 13:47 . 2009-12-04 18:22 455424 c:\windows\system32\drivers\mrxsmb.sys

+ 2006-10-18 10:47 . 2009-04-01 21:02 604160 c:\windows\system32\dllcache\wmspdmod.dll

+ 2006-10-18 10:47 . 2009-07-13 21:43 286208 c:\windows\system32\dllcache\wmpdxm.dll

+ 2008-04-13 18:42 . 2009-06-10 06:14 132096 c:\windows\system32\dllcache\wkssvc.dll

- 2008-04-13 18:42 . 2008-04-13 18:42 132096 c:\windows\system32\dllcache\wkssvc.dll

+ 2008-04-24 02:24 . 2009-12-21 19:14 916480 c:\windows\system32\dllcache\wininet.dll

- 2008-06-04 07:49 . 2008-04-13 18:42 153088 c:\windows\system32\dllcache\triedit.dll

+ 2008-06-04 07:49 . 2009-06-21 21:44 153088 c:\windows\system32\dllcache\triedit.dll

+ 2008-04-13 18:42 . 2009-10-15 16:28 119808 c:\windows\system32\dllcache\t2embed.dll

+ 2008-04-13 18:42 . 2009-08-26 08:00 247326 c:\windows\system32\dllcache\strmdll.dll

- 2008-04-13 18:42 . 2008-10-03 10:02 247326 c:\windows\system32\dllcache\strmdll.dll

+ 2008-04-13 13:45 . 2009-12-31 16:50 353792 c:\windows\system32\dllcache\srv.sys

- 2008-04-13 18:42 . 2008-04-13 18:42 474112 c:\windows\system32\dllcache\shlwapi.dll

+ 2008-04-13 18:42 . 2009-12-08 09:23 474112 c:\windows\system32\dllcache\shlwapi.dll

+ 2008-04-13 18:42 . 2009-06-25 08:25 147456 c:\windows\system32\dllcache\schannel.dll

+ 2008-04-13 18:42 . 2009-04-15 14:51 585216 c:\windows\system32\dllcache\rpcrt4.dll

+ 2008-04-13 18:42 . 2009-10-12 13:38 149504 c:\windows\system32\dllcache\rastls.dll

+ 2008-04-24 02:24 . 2009-12-21 19:14 206848 c:\windows\system32\dllcache\occache.dll

- 2008-04-13 18:42 . 2008-04-13 18:42 270336 c:\windows\system32\dllcache\oakley.dll

+ 2008-04-13 18:42 . 2009-10-13 10:30 270336 c:\windows\system32\dllcache\oakley.dll

+ 2008-04-13 18:42 . 2009-08-05 09:01 204800 c:\windows\system32\dllcache\mswebdvd.dll

+ 2008-04-13 18:42 . 2009-09-11 14:18 136192 c:\windows\system32\dllcache\msv1_0.dll

+ 2008-06-04 07:47 . 2009-12-16 18:43 343040 c:\windows\system32\dllcache\mspaint.exe

- 2008-06-04 07:47 . 2008-04-13 18:42 343040 c:\windows\system32\dllcache\mspaint.exe

- 2009-02-20 18:09 . 2009-03-08 01:32 594432 c:\windows\system32\dllcache\msfeeds.dll

+ 2009-02-20 18:09 . 2009-12-21 19:14 594432 c:\windows\system32\dllcache\msfeeds.dll

+ 2008-12-29 14:53 . 2009-12-04 18:22 455424 c:\windows\system32\dllcache\mrxsmb.sys

+ 2008-04-13 18:41 . 2009-06-25 08:25 730112 c:\windows\system32\dllcache\lsasrv.dll

+ 2008-04-13 18:41 . 2009-05-07 15:32 345600 c:\windows\system32\dllcache\localspl.dll

+ 2008-04-13 18:41 . 2009-06-25 08:25 301568 c:\windows\system32\dllcache\kerberos.dll

+ 2008-04-13 18:41 . 2009-12-09 05:53 726528 c:\windows\system32\dllcache\jscript.dll

- 2008-04-13 18:41 . 2009-03-08 01:33 726528 c:\windows\system32\dllcache\jscript.dll

+ 2008-04-24 02:23 . 2009-12-21 19:14 184320 c:\windows\system32\dllcache\iepeers.dll

+ 2008-04-24 02:22 . 2009-12-21 19:14 387584 c:\windows\system32\dllcache\iedkcs32.dll

+ 2008-04-24 02:22 . 2009-12-21 13:19 173056 c:\windows\system32\dllcache\ie4uinit.exe

- 2008-04-24 02:22 . 2009-03-08 01:32 173056 c:\windows\system32\dllcache\ie4uinit.exe

+ 2008-04-13 18:41 . 2009-11-21 15:51 471552 c:\windows\system32\dllcache\aclayers.dll

+ 2009-08-07 21:51 . 2009-08-07 21:51 989016 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll

+ 2008-05-27 22:49 . 2008-05-27 22:49 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll

- 2007-04-13 18:58 . 2007-04-13 18:58 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll

+ 2008-05-27 22:48 . 2008-05-27 22:48 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll

- 2007-04-13 18:56 . 2007-04-13 18:56 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll

- 2007-04-13 19:30 . 2007-04-13 19:30 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll

+ 2008-05-27 23:30 . 2008-05-27 23:30 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll

+ 2008-06-11 12:02 . 2008-06-11 12:02 830464 c:\windows\Installer\fabf32.msp

+ 2008-07-28 12:59 . 2008-07-28 12:59 180736 c:\windows\Installer\fabf01.msp

+ 2010-03-10 12:09 . 2010-03-10 12:09 429568 c:\windows\Installer\fabec4.msi

- 2008-06-04 08:29 . 2008-06-04 08:29 409600 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe

+ 2008-06-04 08:29 . 2010-03-10 12:20 409600 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe

+ 2008-06-04 08:29 . 2010-03-10 12:20 286720 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe

- 2008-06-04 08:29 . 2008-06-04 08:29 286720 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe

+ 2008-06-04 08:30 . 2010-03-10 12:20 249856 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe

- 2008-06-04 08:30 . 2008-06-04 08:30 249856 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe

+ 2008-06-04 08:30 . 2010-03-10 12:20 794624 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe

- 2008-06-04 08:30 . 2008-06-04 08:30 794624 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe

- 2008-06-04 08:30 . 2008-06-04 08:30 135168 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe

+ 2008-06-04 08:30 . 2010-03-10 12:20 135168 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe

- 2008-06-04 08:30 . 2008-06-04 08:30 593920 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe

+ 2008-06-04 08:30 . 2010-03-10 12:20 593920 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe

+ 2003-04-02 11:21 . 2003-04-02 11:21 111632 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.7969\WAVTOASF.EXE

+ 2005-05-27 01:27 . 2005-05-27 01:27 100552 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.7969\TRANSMGR.DLL

+ 2003-07-21 11:46 . 2003-07-21 11:46 390712 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.7969\RTFHTML.DLL

+ 2005-03-17 14:32 . 2005-03-17 14:32 141000 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.7969\OUTLPH.DLL

+ 2005-07-05 12:14 . 2005-07-05 12:14 196296 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.7969\OUTLOOK.EXE

+ 2005-06-24 12:32 . 2005-06-24 12:32 307424 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.7969\OUTLFLTR.DLL

+ 2003-07-14 22:46 . 2003-07-14 22:46 176696 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.7969\MIMEDIR.DLL

+ 2005-03-17 14:32 . 2005-03-17 14:32 122056 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.7969\IMPMAIL.DLL

+ 2005-03-17 14:36 . 2005-03-17 14:36 161984 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.7969\IETAG.DLL

+ 2005-03-25 16:27 . 2005-03-25 16:27 132296 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.7969\ENVELOPE.DLL

+ 2010-03-10 12:19 . 2009-03-08 01:34 914944 c:\windows\ie8updates\KB978207-IE8\wininet.dll

+ 2010-03-10 12:19 . 2009-05-26 11:40 382840 c:\windows\ie8updates\KB978207-IE8\spuninst\updspapi.dll

+ 2010-03-10 12:19 . 2008-07-08 13:02 231288 c:\windows\ie8updates\KB978207-IE8\spuninst\spuninst.exe

+ 2010-03-10 12:19 . 2009-03-08 01:34 109568 c:\windows\ie8updates\KB978207-IE8\occache.dll

+ 2010-03-10 12:19 . 2009-03-08 01:32 594432 c:\windows\ie8updates\KB978207-IE8\msfeeds.dll

+ 2010-03-10 12:19 . 2009-03-08 01:33 246784 c:\windows\ie8updates\KB978207-IE8\ieproxy.dll

+ 2010-03-10 12:19 . 2009-03-08 01:31 183808 c:\windows\ie8updates\KB978207-IE8\iepeers.dll

+ 2010-03-10 12:19 . 2009-03-08 11:09 391536 c:\windows\ie8updates\KB978207-IE8\iedkcs32.dll

+ 2010-03-10 12:19 . 2009-03-08 01:32 173056 c:\windows\ie8updates\KB978207-IE8\ie4uinit.exe

+ 2010-03-10 12:17 . 2008-07-08 13:02 382840 c:\windows\ie8updates\KB976662-IE8\spuninst\updspapi.dll

+ 2010-03-10 12:17 . 2008-07-08 13:02 231288 c:\windows\ie8updates\KB976662-IE8\spuninst\spuninst.exe

+ 2010-03-10 12:17 . 2009-06-22 06:44 726528 c:\windows\ie8updates\KB976662-IE8\jscript.dll

+ 2010-03-10 12:09 . 2008-07-08 13:02 382840 c:\windows\ie8updates\KB971961-IE8\spuninst\updspapi.dll

+ 2010-03-10 12:09 . 2008-07-08 13:02 231288 c:\windows\ie8updates\KB971961-IE8\spuninst\spuninst.exe

+ 2010-03-10 12:09 . 2009-03-08 01:33 726528 c:\windows\ie8updates\KB971961-IE8\jscript.dll

+ 2008-12-29 14:53 . 2009-12-04 18:22 455424 c:\windows\Driver Cache\i386\mrxsmb.sys

+ 2010-03-10 12:11 . 2010-03-10 12:11 835584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_2fe5904f\System.Drawing.dll

+ 2010-03-10 12:11 . 2010-03-10 12:11 192512 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_dfc1c70b\System.Drawing.Design.dll

+ 2010-03-10 12:11 . 2010-03-10 12:11 118784 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_b241f053\CustomMarshalers.dll

+ 2010-03-10 18:37 . 2010-03-10 18:37 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\b3da65983c80cac308599cbb88a53e6d\WindowsFormsIntegration.ni.dll

+ 2010-03-10 18:37 . 2010-03-10 18:37 187904 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\d3636894f6b04b5abf405f2505f2ee07\UIAutomationTypes.ni.dll

+ 2010-03-10 18:37 . 2010-03-10 18:37 447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\7db8f36114d5f0d885ef34ffde39140d\UIAutomationClient.ni.dll

+ 2010-03-10 18:37 . 2010-03-10 18:37 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\e79cacbe1259ef88b1fa03a01b6fc6bf\System.Drawing.Design.ni.dll

+ 2010-03-10 18:36 . 2010-03-10 18:36 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\cdce2437c0a2820bd1a7465792a1c433\PresentationFramework.Royale.ni.dll

+ 2010-03-10 18:36 . 2010-03-10 18:36 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\7fa8ee532e6629cb90d65e486b922691\PresentationFramework.Aero.ni.dll

+ 2010-03-10 18:36 . 2010-03-10 18:36 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\70ac14c28100d0ca7ed1170597fbc172\PresentationFramework.Luna.ni.dll

+ 2010-03-10 18:36 . 2010-03-10 18:36 224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\203c63d75c419ded87c657a05d8ae7b8\PresentationFramework.Classic.ni.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll

+ 2010-03-10 12:19 . 2010-03-10 12:19 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll

+ 2010-03-10 12:19 . 2010-03-10 12:19 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll

+ 2008-04-13 18:41 . 2009-11-21 15:51 471552 c:\windows\AppPatch\aclayers.dll

+ 2010-03-10 07:42 . 2009-08-13 13:55 1748992 c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6001.22319_x-ww_f0b4c2df\GdiPlus.dll

+ 2009-07-20 22:03 . 2009-07-20 22:03 1348432 c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9876.0_x-ww_a621d1d5\msxml4.dll

+ 2006-10-18 10:47 . 2009-05-20 02:56 2458112 c:\windows\system32\WMVCore.dll

- 2006-10-18 10:47 . 2008-06-18 03:03 2458112 c:\windows\system32\WMVCore.dll

+ 2008-04-13 14:00 . 2009-08-14 13:21 1850624 c:\windows\system32\win32k.sys

+ 2008-04-24 02:24 . 2009-12-21 19:14 1208832 c:\windows\system32\urlmon.dll

- 2008-04-13 18:42 . 2008-04-13 18:42 1435648 c:\windows\system32\query.dll

+ 2008-04-13 18:42 . 2009-07-17 16:22 1435648 c:\windows\system32\query.dll

+ 2008-04-13 18:42 . 2009-11-27 17:11 1291776 c:\windows\system32\quartz.dll

+ 2008-04-13 13:54 . 2009-12-08 19:26 2145280 c:\windows\system32\ntoskrnl.exe

- 2008-04-13 13:54 . 2009-02-06 11:06 2145280 c:\windows\system32\ntoskrnl.exe

+ 2008-04-14 00:01 . 2009-12-08 18:43 2023936 c:\windows\system32\ntkrnlpa.exe

- 2008-04-14 00:01 . 2009-02-06 10:32 2023936 c:\windows\system32\ntkrnlpa.exe

+ 2008-04-13 18:42 . 2009-07-31 08:05 1372672 c:\windows\system32\msxml6.dll

+ 2009-07-20 22:05 . 2009-07-20 22:05 1348432 c:\windows\system32\msxml4.dll

+ 2008-04-13 18:42 . 2009-07-31 04:35 1172480 c:\windows\system32\msxml3.dll

+ 2008-06-04 07:47 . 2009-06-10 07:19 2066432 c:\windows\system32\mstscax.dll

+ 2008-04-24 02:24 . 2009-12-21 19:14 5942784 c:\windows\system32\mshtml.dll

+ 2008-04-24 02:23 . 2009-12-21 19:14 1985536 c:\windows\system32\iertutil.dll

+ 2006-10-18 10:47 . 2009-05-20 02:56 2458112 c:\windows\system32\dllcache\WMVCore.dll

- 2006-10-18 10:47 . 2008-06-18 03:03 2458112 c:\windows\system32\dllcache\WMVCore.dll

+ 2008-04-13 14:00 . 2009-08-14 13:21 1850624 c:\windows\system32\dllcache\win32k.sys

+ 2008-04-24 02:24 . 2009-12-21 19:14 1208832 c:\windows\system32\dllcache\urlmon.dll

- 2008-04-13 18:42 . 2008-04-13 18:42 1435648 c:\windows\system32\dllcache\query.dll

+ 2008-04-13 18:42 . 2009-07-17 16:22 1435648 c:\windows\system32\dllcache\query.dll

+ 2008-04-13 18:42 . 2009-11-27 17:11 1291776 c:\windows\system32\dllcache\quartz.dll

+ 2008-12-29 14:55 . 2009-12-08 19:27 2189184 c:\windows\system32\dllcache\ntoskrnl.exe

+ 2008-12-29 14:55 . 2009-12-08 18:43 2023936 c:\windows\system32\dllcache\ntkrpamp.exe

- 2008-12-29 14:55 . 2009-02-06 10:32 2023936 c:\windows\system32\dllcache\ntkrpamp.exe

- 2008-12-29 14:55 . 2009-02-07 16:02 2066048 c:\windows\system32\dllcache\ntkrnlpa.exe

+ 2008-12-29 14:55 . 2009-12-08 18:43 2066048 c:\windows\system32\dllcache\ntkrnlpa.exe

+ 2008-12-29 14:55 . 2009-12-08 19:26 2145280 c:\windows\system32\dllcache\ntkrnlmp.exe

- 2008-12-29 14:55 . 2009-02-06 11:06 2145280 c:\windows\system32\dllcache\ntkrnlmp.exe

+ 2008-04-13 18:42 . 2009-07-31 08:05 1372672 c:\windows\system32\dllcache\msxml6.dll

+ 2008-04-13 18:42 . 2009-07-31 04:35 1172480 c:\windows\system32\dllcache\msxml3.dll

+ 2009-06-10 07:19 . 2009-06-10 07:19 2066432 c:\windows\system32\dllcache\mstscax.dll

+ 2008-06-04 07:49 . 2009-07-10 13:27 1315328 c:\windows\system32\dllcache\msoe.dll

+ 2008-04-24 02:24 . 2009-12-21 19:14 5942784 c:\windows\system32\dllcache\mshtml.dll

- 2008-06-04 07:49 . 2008-04-13 18:42 3558912 c:\windows\system32\dllcache\moviemk.exe

+ 2008-06-04 07:49 . 2009-10-23 15:28 3558912 c:\windows\system32\dllcache\moviemk.exe

+ 2009-02-20 18:09 . 2009-12-21 19:14 1985536 c:\windows\system32\dllcache\iertutil.dll

+ 2009-08-07 21:51 . 2009-08-07 21:51 5812560 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll

+ 2009-08-07 21:51 . 2009-08-07 21:51 4546560 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll

- 2008-07-25 09:17 . 2008-07-25 09:17 4546560 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll

- 2007-04-13 19:35 . 2007-04-13 19:35 1265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll

+ 2008-05-27 23:35 . 2008-05-27 23:35 1265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll

+ 2008-05-27 23:35 . 2008-05-27 23:35 1232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll

- 2007-04-13 19:35 . 2007-04-13 19:35 1232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll

+ 2008-05-27 22:48 . 2008-05-27 22:48 2514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll

- 2007-04-13 18:57 . 2007-04-13 18:57 2514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll

- 2007-04-13 18:57 . 2007-04-13 18:57 2523136 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll

+ 2008-05-27 22:48 . 2008-05-27 22:48 2523136 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll

+ 2008-05-27 22:43 . 2008-05-27 22:43 2142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll

- 2007-04-13 18:50 . 2007-04-13 18:50 2142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll

+ 2008-06-11 13:05 . 2008-06-11 13:05 9994240 c:\windows\Installer\fac081.msp

+ 2005-10-26 12:59 . 2005-10-26 12:59 2883072 c:\windows\Installer\fac05c.msp

+ 2010-02-04 16:11 . 2010-02-04 16:11 5526528 c:\windows\Installer\fac046.msp

+ 2008-04-01 12:33 . 2008-04-01 12:33 5479936 c:\windows\Installer\fabfe9.msp

+ 2008-01-31 08:30 . 2008-01-31 08:30 9947648 c:\windows\Installer\fabfbb.msp

+ 2008-01-14 14:53 . 2008-01-14 14:53 5213696 c:\windows\Installer\fabf90.msp

+ 2009-12-16 20:58 . 2009-12-16 20:58 5382144 c:\windows\Installer\fabf7a.msp

+ 2008-07-08 09:27 . 2008-07-08 09:27 8436736 c:\windows\Installer\fabf49.msp

+ 2007-11-08 09:42 . 2007-11-08 09:42 4158464 c:\windows\Installer\fabeeb.msp

+ 2004-05-24 19:45 . 2004-05-24 19:45 2482176 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.7969\VBE6.DLL

+ 2005-06-28 19:15 . 2005-06-28 19:15 6146760 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.7969\POWERPNT.EXE

+ 2005-07-22 17:27 . 2005-07-22 17:27 7605960 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.7969\OUTLLIB.DLL

+ 2005-10-28 16:33 . 2005-10-28 16:33 3685616 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.7969\OUTLFLTR.DAT

+ 2010-03-10 12:19 . 2009-03-08 01:34 1206784 c:\windows\ie8updates\KB978207-IE8\urlmon.dll

+ 2010-03-10 12:19 . 2009-03-08 01:41 5937152 c:\windows\ie8updates\KB978207-IE8\mshtml.dll

+ 2010-03-10 12:19 . 2009-03-08 01:32 1985024 c:\windows\ie8updates\KB978207-IE8\iertutil.dll

+ 2008-12-29 14:55 . 2009-12-08 19:27 2189184 c:\windows\Driver Cache\i386\ntoskrnl.exe

+ 2008-12-29 14:55 . 2009-12-08 18:43 2023936 c:\windows\Driver Cache\i386\ntkrpamp.exe

- 2008-12-29 14:55 . 2009-02-06 10:32 2023936 c:\windows\Driver Cache\i386\ntkrpamp.exe

- 2008-12-29 14:55 . 2009-02-07 16:02 2066048 c:\windows\Driver Cache\i386\ntkrnlpa.exe

+ 2008-12-29 14:55 . 2009-12-08 18:43 2066048 c:\windows\Driver Cache\i386\ntkrnlpa.exe

- 2008-12-29 14:55 . 2009-02-06 11:06 2145280 c:\windows\Driver Cache\i386\ntkrnlmp.exe

+ 2008-12-29 14:55 . 2009-12-08 19:26 2145280 c:\windows\Driver Cache\i386\ntkrnlmp.exe

+ 2010-03-10 12:11 . 2010-03-10 12:11 4792320 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_cdee2b41\System.dll

+ 2010-03-10 12:11 . 2010-03-10 12:11 1966080 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_b3a46399\System.dll

+ 2010-03-10 12:11 . 2010-03-10 12:11 5513216 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_d9c6c39d\System.Xml.dll

+ 2010-03-10 12:11 . 2010-03-10 12:11 2088960 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_6663712f\System.Xml.dll

+ 2010-03-10 12:11 . 2010-03-10 12:11 3018752 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_b3c97961\System.Windows.Forms.dll

+ 2010-03-10 12:11 . 2010-03-10 12:11 7884800 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_61c707ff\System.Windows.Forms.dll

+ 2010-03-10 12:11 . 2010-03-10 12:11 2244608 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_0e607993\System.Drawing.dll

+ 2010-03-10 12:11 . 2010-03-10 12:11 3395584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_8aad3af5\System.Design.dll

+ 2010-03-10 12:11 . 2010-03-10 12:11 1470464 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_217f8c6e\System.Design.dll

+ 2010-03-10 12:11 . 2010-03-10 12:11 8908800 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_d0755350\mscorlib.dll

+ 2010-03-10 12:11 . 2010-03-10 12:11 3391488 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_bfe9129b\mscorlib.dll

+ 2010-03-10 12:19 . 2010-03-10 12:19 3312128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\c770cdb4fc7f26c9b5fe858d4147ae57\WindowsBase.ni.dll

+ 2010-03-10 18:37 . 2010-03-10 18:37 1049600 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\fd463597ccb0d17afb9ed0491bfb996a\UIAutomationClientsideProviders.ni.dll

+ 2010-03-10 12:19 . 2010-03-10 12:19 7868416 c:\windows\assembly\NativeImages_v2.0.50727_32\System\2e356db128ec7354bd70a3ecc84b1f87\System.ni.dll

+ 2010-03-10 18:37 . 2010-03-10 18:37 5450240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\28cee07c1277b35abcb83560cd8c677c\System.Xml.ni.dll

+ 2010-03-10 18:37 . 2010-03-10 18:37 1035264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\571e33db0f70fd1184e3ba25dea0dc0b\System.Printing.ni.dll

+ 2010-03-10 18:37 . 2010-03-10 18:37 1587200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\f9c517646d0706b9c61a41af685ff6b7\System.Drawing.ni.dll

+ 2010-03-10 18:36 . 2010-03-10 18:36 6615040 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\288044f77c184ff68e0200f762c395f4\System.Data.ni.dll

+ 2010-03-10 18:37 . 2010-03-10 18:37 2510848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\c8fe4e187a8f4b17a0448268fa3e0b6b\System.Data.Linq.ni.dll

+ 2010-03-10 18:36 . 2010-03-10 18:36 2295296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\349efab7d4325e3cf4bc57b8a1b0f605\System.Core.ni.dll

+ 2010-03-10 18:36 . 2010-03-10 18:36 2126336 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\3b35e47f4876f2eed2e86b2829da0fbf\ReachFramework.ni.dll

+ 2010-03-10 18:36 . 2010-03-10 18:36 1657344 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\f256e6ef01b68fbc8d60628b5479185b\PresentationUI.ni.dll

+ 2010-03-10 12:19 . 2010-03-10 12:19 1451008 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\647e0b340467d8b9ef7c6474ed5bde64\PresentationBuildTasks.ni.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 3149824 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 3149824 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 5238784 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 5238784 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll

+ 2010-03-10 12:18 . 2010-03-10 12:18 4546560 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll

- 2009-12-12 12:33 . 2009-12-12 12:33 4546560 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll

- 2008-12-29 16:34 . 2008-12-29 16:34 1232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll

+ 2010-03-10 12:10 . 2010-03-10 12:10 1232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll

- 2008-12-29 16:34 . 2008-12-29 16:34 1265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll

+ 2010-03-10 12:10 . 2010-03-10 12:10 1265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll

+ 2006-10-18 10:47 . 2009-07-13 21:43 10841088 c:\windows\system32\wmp.dll

+ 2009-01-01 23:18 . 2010-03-01 19:30 31648712 c:\windows\system32\MRT.exe

+ 2008-04-24 02:23 . 2009-12-21 19:14 11070464 c:\windows\system32\ieframe.dll

+ 2006-10-18 10:47 . 2009-07-13 21:43 10841088 c:\windows\system32\dllcache\wmp.dll

+ 2009-02-20 18:09 . 2009-12-21 19:14 11070464 c:\windows\system32\dllcache\ieframe.dll

+ 2009-08-10 19:08 . 2009-08-10 19:08 11315712 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M953297\M953297Uninstall.msp

+ 2009-08-14 18:32 . 2009-08-14 18:32 11110912 c:\windows\Installer\fac066.msp

+ 2008-08-13 12:49 . 2008-08-13 12:49 11816960 c:\windows\Installer\fac02e.msp

+ 2008-07-30 06:50 . 2008-07-30 06:50 12506112 c:\windows\Installer\fac017.msp

+ 2008-07-08 08:09 . 2008-07-08 08:09 11887616 c:\windows\Installer\fac000.msp

+ 2008-06-04 11:29 . 2008-06-04 11:29 16905728 c:\windows\Installer\fabfd3.msp

+ 2008-01-14 13:24 . 2008-01-14 13:24 10721280 c:\windows\Installer\fabf60.msp

+ 2009-08-10 12:09 . 2009-08-10 12:09 17254912 c:\windows\Installer\fabf19.msp

+ 2005-07-22 17:21 . 2005-07-22 17:21 12061896 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.7969\WINWORD.EXE

+ 2005-07-22 17:47 . 2005-07-22 17:47 12242624 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.7969\MSO.DLL

+ 2005-05-27 01:06 . 2005-05-27 01:06 10095808 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.7969\EXCEL.EXE

+ 2010-03-10 12:19 . 2009-03-08 01:39 11063808 c:\windows\ie8updates\KB978207-IE8\ieframe.dll

+ 2010-03-10 18:37 . 2010-03-10 18:37 12430848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\1d1239cae67610d8659752751abc7856\System.Windows.Forms.ni.dll

+ 2010-03-10 18:37 . 2010-03-10 18:37 10682368 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\5f5f201fb2705a1523212fcaf593bf5e\System.Design.ni.dll

+ 2010-03-10 18:36 . 2010-03-10 18:36 14322688 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\e3d4d240794478ea8067ceed63bbad1e\PresentationFramework.ni.dll

+ 2010-03-10 18:36 . 2010-03-10 18:36 12215296 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\4619e16b34a37586c8dbae5f71359156\PresentationCore.ni.dll

+ 2010-03-10 12:19 . 2010-03-10 12:19 11485184 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\4b10d8196bb368996ec5d24fca777456\mscorlib.ni.dll

.

-- Snapshot reset to current date --

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2007-12-21 1443072]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-11 13574144]

"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2006-11-23 487424]

"BigDog303"="c:\windows\VM303_STI.EXE" [2005-10-25 61440]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]

"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-07-01 37888]

"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2009-12-18 40368]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"nltide_2"="shell32" [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]

2009-12-18 06:58 40368 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]

2005-05-03 10:43 69632 ------r- c:\windows\Alcmtr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]

2008-04-13 18:42 15360 ------w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]

2006-05-18 08:29 49152 ----a-w- c:\program files\CyberLink\PowerDVD\Language\Language.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

2006-01-12 12:40 155648 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]

2008-09-11 09:13 13574144 ----a-w- c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]

2008-09-11 09:13 86016 ----a-w- c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]

2008-09-11 09:13 1657376 ----a-w- c:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]

2005-12-07 19:57 30208 ------w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]

2007-08-20 07:38 16384512 ------r- c:\windows\RTHDCPL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]

2009-10-09 11:11 25623336 ----a-r- c:\program files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TBPanel]

2008-09-05 16:24 2154496 ----a-w- c:\program files\Vtune\TBPANEL.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\uTorrent\\uTorrent.exe"=

"c:\\WINDOWS\\system32\\PnkBstrA.exe"=

"c:\\WINDOWS\\system32\\PnkBstrB.exe"=

"d:\\GAMES\\Race.Driver.GRID.RePack\\GRID\\GRID.exe"=

"d:\\GAMES\\FlatOut 2\\flatout2.exe"=

"d:\\GAMES\\Tom.Clancys.H.A.W.X-SKIDROW\\sr-tch\\HAWX.exe"=

"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=

"d:\\GAMES\\Dirt.2-RELOADED\\dirt2_game.exe"=

"d:\\GAMES\\Operation.Flashpoint.Dragon.Rising-RELOADED\\OFDR.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [19.12.2008 і. 19:34 721904]

R2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [21.12.2007 і. 07:21 468224]

R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [11.10.2009 і. 23:28 222968]

S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [04.2.2010 і. 23:11 135664]

.

Contents of the 'Scheduled Tasks' folder

2010-03-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-04 21:11]

2010-03-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-04 21:11]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.msn.com

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

FF - ProfilePath - c:\documents and settings\User-PC\Application Data\Mozilla\Firefox\Profiles\5jsf1ael.default\

FF - prefs.js: browser.search.selectedEngine - Google

FF - prefs.js: browser.startup.homepage - hxxp://www.data.bg/

FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll

FF - plugin: c:\program files\Google\Update\1.2.183.17\npGoogleOneClick8.dll

.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-03-10 21:45

Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

BigDog303 = c:\windows\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)????????????????0?????????@??????????????

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully

user: MBR read successfully

called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spyy.sys >>UNKNOWN [0x8A31E938]<<

kernel: MBR read successfully

detected MBR rootkit hooks:

\Driver\Disk -> CLASSPNP.SYS @ 0xf763bf28

\Driver\ACPI -> ACPI.sys @ 0xf7495cb8

\Driver\atapi -> atapi.sys @ 0xf7978b40

IoDeviceObjectType -> ParseProcedure -> ntoskrnl.exe @ 0x8057b6b1

\Device\Harddisk0\DR0 -> ParseProcedure -> ntoskrnl.exe @ 0x8057b6b1

NDIS: NVIDIA nForce Networking Controller -> SendCompleteHandler -> NDIS.sys @ 0xf7b3abb0

PacketIndicateHandler -> NDIS.sys @ 0xf7b47a21

SendHandler -> NDIS.sys @ 0xf7b2587b

user & kernel MBR OK

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1202660629-790525478-682003330-1003\Software\Microsoft\SystemCertificates\AddressBook*]

@Allowed: (Read) (RestrictedCode)

@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-1202660629-790525478-682003330-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]

"??"=hex:e1,3f,08,00,2b,5f,ad,57,b1,23,9c,44,6d,9c,a3,e4,c9,4c,b4,d2,fd,92,7d,

5a,2d,18,71,55,d2,e4,29,24,85,ef,1e,bf,3a,76,7d,36,21,16,fe,21,e9,40,d0,6e,\

"??"=hex:b6,3c,a3,f5,1b,49,13,25,4e,a7,4b,c6,d1,2b,df,ea

[HKEY_USERS\S-1-5-21-1202660629-790525478-682003330-1003\Software\SecuROM\License information*]

"datasecu"=hex:a1,f9,4f,3d,9c,7c,8e,21,d4,6f,9d,d9,c7,bf,01,69,76,49,aa,6a,7a,

26,52,2b,24,70,cd,93,1a,7f,a5,17,d9,f2,4d,ea,ca,ee,f5,4e,56,a3,5f,68,00,d8,\

"rkeysecu"=hex:87,15,77,a3,da,f3,9b,39,49,4c,dd,d3,a6,ff,ac,ec

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(232)

c:\windows\system32\WININET.dll

c:\windows\system32\msi.dll

c:\windows\system32\ieframe.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\WPDShServiceObj.dll

c:\windows\system32\PortableDeviceTypes.dll

c:\windows\system32\PortableDeviceApi.dll

.

------------------------ Other Running Processes ------------------------

.

c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe

c:\windows\system32\nvsvc32.exe

c:\windows\system32\PnkBstrA.exe

c:\windows\system32\PnkBstrB.exe

c:\program files\CyberLink\Shared files\RichVideo.exe

c:\program files\Common Files\Teleca Shared\Generic.exe

c:\program files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe

.

**************************************************************************

.

Completion time: 2010-03-10 21:48:01 - machine was rebooted

ComboFix-quarantined-files.txt 2010-03-10 19:47

ComboFix2.txt 2010-03-09 21:58

Pre-Run: 9 031 610 368 bytes free

Post-Run: 9 052 975 104 bytes free

- - End Of File - - 45824B3BAC516EBB167A9123DD4404E5

Ще се наложи да повторим процедурата с нов скрипт...

Изтеглете прикачения файл и го провлачете и пуснете в Combofix (както е показано на картинката отдолу).

cfscript10uc2.gif

*. По време на сканиране от страна на ComboFix не стартирайте никакви други приложения, не натискайте клавиши от клавиатурата и не местете мишката !

*. Публикувайте лог файла, който ще се създаде след рестарта на компютъра в следващия си пост.

CFScript.txt

  • Автор

ComboFix 10-03-10.02 - User-PC 03.2010 г. 22:12:09.3.2 - x86

Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.1983.1618 [GMT 2:00]

Running from: c:\documents and settings\User-PC\Desktop\ComboFix.exe

Command switches used :: c:\documents and settings\User-PC\Desktop\CFScript.txt

AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}

FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}

* Resident AV is active

FILE ::

"c:\windows\Jlujeb.exe"

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\windows\Jlujeb.exe

d:\programi\fiestaBar

d:\programi\fiestaBar\base_m.swf

d:\programi\fiestaBar\######.exe

d:\programi\fiestaBar\CFFilter.dll

d:\programi\fiestaBar\cherry.cfx

d:\programi\fiestaBar\default.cfx

d:\programi\fiestaBar\Diag.log

d:\programi\fiestaBar\silver.cfx

d:\programi\fiestaBar\Uninstall.exe

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

-------\Legacy_SPTD

-------\Service_sptd

((((((((((((((((((((((((( Files Created from 2010-02-10 to 2010-03-10 )))))))))))))))))))))))))))))))

.

2010-03-10 12:09 . 2010-03-10 12:09 -------- d-----w- c:\program files\MSXML 4.0

2010-03-10 07:42 . 2009-12-21 19:14 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll

2010-03-10 07:42 . 2009-12-21 19:14 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll

2010-03-08 22:08 . 2009-08-06 17:23 274288 ----a-w- c:\windows\system32\mucltui.dll

2010-03-08 22:08 . 2009-08-06 17:23 215920 ----a-w- c:\windows\system32\muweb.dll

2010-03-08 21:36 . 2010-03-08 21:36 -------- d-----w- c:\program files\Common Files\PersSecurityUninstall

2010-03-08 20:27 . 2010-03-08 20:27 152576 ----a-w- c:\documents and settings\User-PC\Application Data\Sun\Java\jre1.6.0_17\lzma.dll

2010-03-06 14:20 . 2010-03-10 07:38 -------- d-----w- c:\documents and settings\User-PC\Application Data\######

2010-03-05 19:49 . 2010-03-05 19:49 -------- d-----w- c:\documents and settings\User-PC\Application Data\ImTOO Software Studio

2010-02-25 09:30 . 2010-02-25 09:50 -------- d-----w- c:\program files\Common Files\Real

2010-02-20 18:32 . 2010-02-20 18:32 -------- d-----w- c:\windows\solcache

2010-02-19 20:55 . 2010-02-19 20:55 -------- d-----w- c:\documents and settings\User-PC\Local Settings\Application Data\WMTools Downloaded Files

2010-02-18 08:49 . 2010-03-05 11:01 -------- d-----w- c:\documents and settings\User-PC\Application Data\f2fPreIntermediate

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-03-10 12:08 . 2008-06-04 08:38 -------- d-----w- c:\documents and settings\User-PC\Application Data\uTorrent

2010-03-08 21:53 . 2009-06-10 16:39 -------- d-----w- c:\documents and settings\User-PC\Application Data\Skype

2010-03-08 20:26 . 2010-01-08 19:35 79488 ----a-w- c:\documents and settings\User-PC\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll

2010-03-08 18:53 . 2008-12-19 17:01 -------- d-----w- c:\documents and settings\User-PC\Application Data\skypePM

2010-03-06 13:42 . 2009-12-04 15:21 -------- d-----w- c:\documents and settings\User-PC\Application Data\Winamp

2010-03-01 20:00 . 2009-04-26 07:30 -------- d-----w- c:\program files\Microsoft Silverlight

2010-02-26 09:24 . 2008-06-04 08:38 -------- d-----w- c:\program files\uTorrent

2010-02-21 13:53 . 2008-06-04 08:37 -------- d-----w- c:\program files\Common Files\Adobe

2010-02-20 17:07 . 2009-01-10 23:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Codemasters

2010-02-20 15:16 . 2008-06-04 08:24 -------- d--h--w- c:\program files\InstallShield Installation Information

2010-02-17 17:20 . 2008-12-26 00:30 107888 ----a-w- c:\windows\system32\CmdLineExt.dll

2010-02-12 11:58 . 2010-01-19 18:52 -------- d-----w- c:\documents and settings\User-PC\Application Data\f2fElementary

2010-02-04 22:41 . 2008-06-04 07:48 -------- d-----w- c:\program files\System

2010-02-04 22:40 . 2008-06-04 07:51 -------- d-----w- c:\program files\Windows Media Connect 2

2010-02-04 22:36 . 2008-12-29 15:09 -------- d-----w- c:\program files\Google

2010-02-03 20:00 . 2009-04-15 15:11 139128 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys

2010-02-03 20:00 . 2009-04-15 15:11 215128 ----a-w- c:\windows\system32\PnkBstrB.exe

2010-02-03 19:18 . 2008-12-22 23:04 138056 ----a-w- c:\documents and settings\User-PC\Application Data\PnkBstrK.sys

2010-02-03 19:18 . 2008-12-22 23:04 138056 ----a-w- c:\documents and settings\User-PC\Application Data\PnkBstrK.sys

2010-02-03 19:18 . 2009-04-15 15:10 75064 ----a-w- c:\windows\system32\PnkBstrA.exe

2010-02-03 19:18 . 2010-02-03 19:18 2434856 ----a-w- c:\windows\system32\pbsvc_bc2.exe

2010-01-31 22:23 . 2009-04-18 19:19 2250024 ----a-w- c:\windows\system32\pbsvc.exe

2010-01-19 19:38 . 2008-06-04 08:14 19192 ----a-w- c:\documents and settings\User-PC\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2009-12-31 16:50 . 2008-04-13 13:45 353792 ----a-w- c:\windows\system32\drivers\srv.sys

2009-12-21 19:14 . 2008-04-24 02:24 916480 ------w- c:\windows\system32\wininet.dll

2009-12-16 18:43 . 2008-06-04 07:47 343040 ----a-w- c:\windows\system32\mspaint.exe

2009-12-14 07:08 . 2008-04-13 18:41 33280 ----a-w- c:\windows\system32\csrsrv.dll

2009-12-12 12:29 . 2008-06-04 07:48 445016 ----a-w- c:\windows\system32\wrap_oal.dll

2009-12-12 12:29 . 2008-06-04 07:48 109144 ----a-w- c:\windows\system32\OpenAL32.dll

.

------- Sigcheck -------

[-] 2008-04-24 . C951DB3D9B6EF3CF4B82454D30A8BF59 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll

.

((((((((((((((((((((((((((((( SnapShot_2010-03-10_19.45.39 )))))))))))))))))))))))))))))))))))))))))

.

- 2001-08-23 11:00 . 2010-03-10 19:40 72544 c:\windows\system32\perfc009.dat

+ 2001-08-23 11:00 . 2010-03-10 19:49 72544 c:\windows\system32\perfc009.dat

+ 2001-08-23 11:00 . 2010-03-10 19:49 445052 c:\windows\system32\perfh009.dat

- 2001-08-23 11:00 . 2010-03-10 19:40 445052 c:\windows\system32\perfh009.dat

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2007-12-21 1443072]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-11 13574144]

"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2006-11-23 487424]

"BigDog303"="c:\windows\VM303_STI.EXE" [2005-10-25 61440]

"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-07-01 37888]

"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"nltide_2"="shell32" [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]

2009-12-18 06:58 40368 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]

2005-05-03 10:43 69632 ------r- c:\windows\Alcmtr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]

2008-04-13 18:42 15360 ------w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]

2006-05-18 08:29 49152 ----a-w- c:\program files\CyberLink\PowerDVD\Language\Language.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

2006-01-12 12:40 155648 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]

2008-09-11 09:13 13574144 ----a-w- c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]

2008-09-11 09:13 86016 ----a-w- c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]

2008-09-11 09:13 1657376 ----a-w- c:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]

2005-12-07 19:57 30208 ------w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]

2007-08-20 07:38 16384512 ------r- c:\windows\RTHDCPL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]

2009-10-09 11:11 25623336 ----a-r- c:\program files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TBPanel]

2008-09-05 16:24 2154496 ----a-w- c:\program files\Vtune\TBPANEL.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\uTorrent\\uTorrent.exe"=

"c:\\WINDOWS\\system32\\PnkBstrA.exe"=

"c:\\WINDOWS\\system32\\PnkBstrB.exe"=

"d:\\GAMES\\Race.Driver.GRID.RePack\\GRID\\GRID.exe"=

"d:\\GAMES\\FlatOut 2\\flatout2.exe"=

"d:\\GAMES\\Tom.Clancys.H.A.W.X-SKIDROW\\sr-tch\\HAWX.exe"=

"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=

"d:\\GAMES\\Dirt.2-RELOADED\\dirt2_game.exe"=

"d:\\GAMES\\Operation.Flashpoint.Dragon.Rising-RELOADED\\OFDR.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [21.12.2007 і. 07:21 468224]

R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [11.10.2009 і. 23:28 222968]

S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [04.2.2010 і. 23:11 135664]

.

Contents of the 'Scheduled Tasks' folder

2010-03-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-04 21:11]

2010-03-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-04 21:11]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.msn.com

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

FF - ProfilePath - c:\documents and settings\User-PC\Application Data\Mozilla\Firefox\Profiles\5jsf1ael.default\

FF - prefs.js: browser.search.selectedEngine - Google

FF - prefs.js: browser.startup.homepage - hxxp://www.data.bg/

FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll

FF - plugin: c:\program files\Google\Update\1.2.183.17\npGoogleOneClick8.dll

.

- - - - ORPHANS REMOVED - - - -

AddRemove-FiestaBar - d:\programi\fiestaBar\Uninstall.exe

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-03-10 22:16

Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

BigDog303 = c:\windows\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)????????????????0?????????@??????????????

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1202660629-790525478-682003330-1003\Software\Microsoft\SystemCertificates\AddressBook*]

@Allowed: (Read) (RestrictedCode)

@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-1202660629-790525478-682003330-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]

"??"=hex:e1,3f,08,00,2b,5f,ad,57,b1,23,9c,44,6d,9c,a3,e4,c9,4c,b4,d2,fd,92,7d,

5a,2d,18,71,55,d2,e4,29,24,85,ef,1e,bf,3a,76,7d,36,21,16,fe,21,e9,40,d0,6e,\

"??"=hex:b6,3c,a3,f5,1b,49,13,25,4e,a7,4b,c6,d1,2b,df,ea

[HKEY_USERS\S-1-5-21-1202660629-790525478-682003330-1003\Software\SecuROM\License information*]

"datasecu"=hex:a1,f9,4f,3d,9c,7c,8e,21,d4,6f,9d,d9,c7,bf,01,69,76,49,aa,6a,7a,

26,52,2b,24,70,cd,93,1a,7f,a5,17,d9,f2,4d,ea,ca,ee,f5,4e,56,a3,5f,68,00,d8,\

"rkeysecu"=hex:87,15,77,a3,da,f3,9b,39,49,4c,dd,d3,a6,ff,ac,ec

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(172)

c:\windows\system32\WININET.dll

c:\windows\system32\msi.dll

c:\windows\system32\ieframe.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\WPDShServiceObj.dll

c:\windows\system32\PortableDeviceTypes.dll

c:\windows\system32\PortableDeviceApi.dll

.

------------------------ Other Running Processes ------------------------

.

c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe

c:\windows\system32\nvsvc32.exe

c:\windows\system32\PnkBstrA.exe

c:\windows\system32\PnkBstrB.exe

c:\program files\CyberLink\Shared files\RichVideo.exe

c:\program files\Common Files\Teleca Shared\Generic.exe

c:\program files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe

c:\program files\Common Files\Teleca Shared\CapabilityManager.exe

.

**************************************************************************

.

Completion time: 2010-03-10 22:18:30 - machine was rebooted

ComboFix-quarantined-files.txt 2010-03-10 20:18

ComboFix2.txt 2010-03-10 19:48

ComboFix3.txt 2010-03-09 21:58

Pre-Run: 9 059 201 024 bytes free

Post-Run: 9 021 607 936 bytes free

- - End Of File - - CB8D7316BD3F7AA00763D9F2FFFA8F1D

Така е по-добре.

СТЪПКА 1

Моля архивирайте папката C:\Qoobox и я качете на този адрес: http://www.skatafka.com/

Публикувайте линк за да я изтеглим.

След това деинсталирайте Combofix.

Start => Run => въведете Combofix /Uninstall => (има празно място между Combofix и /Uninstall) => Enter => това ще стартира и ще деинсталира Combofix. Ще затрие и файловете асоциирани с този инструмент, както и папката C:\Qoobox - карантината на Combofix.

Забравил съм да премахна един остатък от паразита, но за него ще се погрижи Malwarebytes' Anti-Malware:

2010-03-08 21:36 . 2010-03-08 21:36 -------- d-----w- c:\program files\Common Files\PersSecurityUninstall

СТЪПКА 2

Изтеглете Malwarebytes' Anti-Malware от тук

Кликнете два пъти върху mbam-setup.exe за да инсталирате програмата.

  • * Уверете се, че има отметки на Update Malwarebytes' Anti-Malware и Launch Malwarebytes' Anti-Malware, след това кликнете на Finish.
    * Ако има намерени по-нови обновления, тя ще ги изтегли и инсталира.
    * Стартирайте програмата и изберете "Perform Full Scan", след това кликнете на Scan.
    * Сканирането ще отнеме малко време, затова моля бъдете търпеливи.
    * Когато сканирането завърши, кликнете на OK, след това Show Results, за да видите резултата.
    * Уверете се, че на всички редове има отметки, и кликнете Remove Selected.
    * Когато всичко бъде премахнато, логът ще бъде отворен в Notepad. Копирайте лога и го публикувайте в следващия си коментар в темата.

Бележка: Ако MalwareBytes' Anti-Malware се затрудни в премахването на откритите вируси/заплахи, той ще поиска да рестартира компютъра Ви и по време на рестартирането да премахне проблемните вируси/заплахи. Ако бъдете попитани, потвърдете че желаете вашия компютър да бъде рестартиран.

  • Автор

незнам дали правилно съм архивирал папката

пак ще се повторя,че съм доста "босичък"в тези работи

получих файл тип WinRAR archive

натискам browse избирам фаила,натискам качи,след което уж започва да се качва и след малко ми изписва "не сте избрали файл,които да качите"

Благодаря ! :whist:

Сега продължете с останалите стъпки по деинсталирането на Combofix и сканирането с Malwarebytes.

Не забравяйте да изтриете и архива, който създадохте ! ;)

Добавете отговор

Можете да публикувате отговор сега и да се регистрирате по-късно. Ако имате регистрация, влезте в профила си за да публикувате от него.
Бележка: Вашата публикация изисква одобрение от модератор, преди да стане видима за всички.

Гост
Публикацията ви съдържа термини, които не допускаме! Моля, редактирайте съдържанието си и премахнете подчертаните думи по-долу. Ако замените букви от думата със звездички или друго, за да заобиколите това предупреждение, профилът ви ще бъде блокиран и наказан!
Напишете отговор в тази тема...

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    25%
    Дарени 252.69 EUR от нужните 1,000.00 EUR

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.