ComboFix 10-04-01.02 - Konrad 2009-12-31 9:21.1.2 - x86 Microsoft Windows XP Professional 5.1.2600.2.1250.48.1045.18.3327.2703 [GMT 1:00] Uruchomiony z: c:\documents and settings\Konrad\Pulpit\ComboFix.exe AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} . ((((((((((((((((((((((((((((((((((((((( Usunięto ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\recycled\Recycled c:\windows\system32\ieuinit.inf c:\windows\system32\msvcsv60.dll . ((((((((((((((((((((((((( Pliki utworzone od 2009-11-28 do 2009-12-31 ))))))))))))))))))))))))))))))) . 2010-03-02 07:41 . 2010-03-02 07:41 237320 ----a-w- c:\windows\system32\PDBoot.exe 2010-01-16 22:02 . 2010-01-16 22:04 -------- d-----w- c:\program files\Pianissimo 2009-12-30 17:11 . 2009-12-30 17:11 -------- d-----w- c:\documents and settings\Konrad\Dane aplikacji\Malwarebytes 2009-12-30 17:11 . 2010-03-29 23:46 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-12-30 17:11 . 2010-03-29 23:45 20824 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-12-30 17:11 . 2009-12-30 17:11 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Malwarebytes 2009-12-30 11:51 . 2009-12-30 11:51 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Raxco 2009-12-29 18:57 . 2009-12-29 18:58 -------- d-----w- c:\windows\system32\NtmsData 2009-12-27 16:35 . 2010-03-09 11:08 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2009-12-27 16:35 . 2010-03-09 11:12 162640 ----a-w- c:\windows\system32\drivers\aswSP.sys 2009-12-27 16:35 . 2010-03-09 11:09 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys 2009-12-27 16:35 . 2010-03-09 11:12 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2009-12-27 16:35 . 2010-03-09 11:08 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys 2009-12-27 16:35 . 2010-03-09 11:08 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys 2009-12-27 16:35 . 2010-03-09 11:08 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys 2009-12-27 16:35 . 2010-03-09 11:24 38848 ----a-w- c:\windows\system32\avastSS.scr 2009-12-27 16:35 . 2010-03-09 11:24 153184 ----a-w- c:\windows\system32\aswBoot.exe 2009-12-25 19:58 . 2009-12-30 11:32 -------- d-----w- c:\documents and settings\Konrad\Dane aplikacji\Mumble 2009-12-25 11:06 . 2009-12-27 16:34 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Alwil Software 2009-12-25 11:06 . 2009-12-25 11:06 -------- d-----w- c:\program files\Alwil Software 2009-12-23 20:00 . 2009-12-23 20:00 -------- d-----w- c:\program files\CCleaner 2009-12-22 10:33 . 2009-12-22 10:33 135184 ----a-w- c:\windows\system32\drivers\DefragFs.sys 2009-12-16 18:50 . 2009-12-16 18:50 -------- d-----w- c:\program files\Ontrack 2009-12-16 17:40 . 2009-12-16 18:49 -------- d---a-w- c:\documents and settings\All Users\Dane aplikacji\TEMP 2009-12-14 17:41 . 2009-12-14 17:41 -------- d-----w- c:\program files\Common Files\PACE Anti-Piracy 2009-12-14 17:41 . 2009-12-14 17:41 -------- d-----w- c:\documents and settings\Konrad\Ustawienia lokalne\Dane aplikacji\PACE Anti-Piracy 2009-12-14 17:41 . 2009-12-14 17:41 -------- d-----w- c:\documents and settings\Konrad\Dane aplikacji\PACE Anti-Piracy 2009-12-14 17:41 . 2009-12-14 17:41 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\PACE Anti-Piracy 2009-12-14 17:41 . 2009-12-14 17:41 -------- d-----w- c:\documents and settings\Konrad\Dane aplikacji\Waves Audio 2009-12-14 17:37 . 2009-12-14 17:37 634880 ------w- c:\windows\system32\ilinet.dll 2009-12-14 17:37 . 2009-12-14 17:37 27328 ----a-w- c:\windows\system32\drivers\iLokDrvr.sys 2009-12-14 17:37 . 2005-12-15 19:30 1060864 ------w- c:\windows\system32\MFC71.dll 2009-12-14 17:37 . 2009-12-14 17:37 785 ------w- c:\windows\Tpkdboot.reg 2009-12-14 17:37 . 2009-12-14 17:37 72032 ----a-w- c:\windows\system32\drivers\TPkd.sys 2009-12-13 20:55 . 2009-12-26 06:08 -------- d-----w- c:\documents and settings\Konrad\Dane aplikacji\Steinberg 2009-12-13 20:53 . 2007-12-08 23:32 344064 ----a-w- c:\windows\system32\msvcr70.dll 2009-12-12 11:02 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe 2009-12-06 14:37 . 2009-12-06 14:37 -------- d-s---w- c:\documents and settings\Administrator\UserData 2009-12-06 14:34 . 2009-12-06 14:34 -------- d-----w- c:\documents and settings\Administrator\Dane aplikacji\PC Suite . (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-02-26 06:14 . 2004-08-03 23:44 664576 ----a-w- c:\windows\system32\wininet.dll 2010-02-26 06:13 . 2004-08-03 23:44 81920 ----a-w- c:\windows\system32\ieencode.dll 2009-12-31 16:14 . 2004-08-03 22:14 352640 ----a-w- c:\windows\system32\drivers\srv.sys 2009-12-31 06:49 . 2001-10-26 16:15 88838 ----a-w- c:\windows\system32\perfc015.dat 2009-12-31 06:49 . 2001-10-26 16:15 500302 ----a-w- c:\windows\system32\perfh015.dat 2009-12-30 20:43 . 2009-03-17 20:39 48 ----a-w- c:\windows\msocreg32.dat 2009-12-29 17:34 . 2009-07-15 08:51 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Skype 2009-12-29 17:26 . 2009-04-04 15:18 -------- d-----w- c:\program files\Google 2009-12-27 19:48 . 2009-03-17 20:39 -------- d-----w- c:\program files\IK Multimedia 2009-12-27 19:48 . 2008-12-23 16:23 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-12-26 06:03 . 2008-12-25 03:41 -------- d-----w- c:\program files\Syncrosoft 2009-12-17 08:00 . 2008-12-23 16:00 345088 ----a-w- c:\windows\system32\mspaint.exe 2009-12-14 17:41 . 2009-01-07 10:21 -------- d-----w- c:\program files\Waves 2009-12-14 07:37 . 2004-08-03 23:43 33280 ----a-w- c:\windows\system32\csrsrv.dll 2009-12-11 13:03 . 2009-06-09 14:52 -------- d-----w- c:\program files\Common Files\PCSuite 2009-12-09 10:28 . 2004-08-03 23:38 2137600 ----a-w- c:\windows\system32\ntoskrnl.exe 2009-12-09 10:28 . 2004-08-04 00:39 2017280 ----a-w- c:\windows\system32\ntkrnlpa.exe 2009-12-04 14:41 . 2004-08-03 22:15 453760 ----a-w- c:\windows\system32\drivers\mrxsmb.sys 2009-11-27 17:35 . 2004-08-04 00:44 17920 ----a-w- c:\windows\system32\msyuv.dll 2009-11-27 17:35 . 2004-08-03 23:44 1294848 ----a-w- c:\windows\system32\quartz.dll 2009-11-27 16:40 . 2004-08-04 00:44 48128 ----a-w- c:\windows\system32\iyuv_32.dll 2009-11-27 16:40 . 2004-08-03 23:44 11264 ----a-w- c:\windows\system32\msrle32.dll 2009-11-27 16:40 . 2004-08-03 23:43 84992 ----a-w- c:\windows\system32\avifil32.dll 2009-11-27 16:40 . 2001-10-26 17:29 8704 ----a-w- c:\windows\system32\tsbyuv.dll 2009-11-27 16:40 . 2001-10-26 17:29 28672 ----a-w- c:\windows\system32\msvidc32.dll 2009-11-21 21:15 . 2009-11-21 21:15 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Funcom 2009-11-21 16:47 . 2010-01-06 18:17 1196000 ----a-w- c:\windows\AppPatch\SET70.tmp 2009-11-21 16:46 . 2010-01-06 18:17 470528 ----a-w- c:\windows\AppPatch\SET71.tmp 2009-11-21 16:46 . 2004-08-03 23:43 470528 ----a-w- c:\windows\AppPatch\aclayers.dll 2009-11-17 14:45 . 2009-08-21 19:45 691696 ----a-w- c:\windows\system32\drivers\sptd.sys 2009-11-09 21:18 . 2009-06-09 14:53 -------- d-----w- c:\documents and settings\Konrad\Dane aplikacji\PC Suite 2009-11-09 21:18 . 2009-11-09 21:18 -------- d-----w- c:\documents and settings\Konrad\Dane aplikacji\Nokia Multimedia Player 2009-11-09 21:17 . 2009-11-09 21:17 -------- d-----w- c:\program files\Common Files\Nokia 2009-11-09 21:17 . 2008-12-23 16:24 -------- d-----w- c:\program files\Common Files\InstallShield 2009-10-30 18:22 . 2009-01-05 19:28 36176 ----a-w- c:\documents and settings\Konrad\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT 2009-10-21 06:03 . 2004-08-03 23:44 75776 ----a-w- c:\windows\system32\strmfilt.dll 2009-10-21 06:03 . 2004-08-03 23:44 25088 ----a-w- c:\windows\system32\httpapi.dll 2009-10-20 14:58 . 2004-08-03 22:00 263552 ----a-w- c:\windows\system32\drivers\http.sys 2009-10-15 21:52 . 2004-08-03 23:44 119808 ----a-w- c:\windows\system32\t2embed.dll 2009-10-15 17:22 . 2001-10-26 17:29 82432 ----a-w- c:\windows\system32\fontsub.dll 2009-10-13 10:53 . 2004-08-03 23:44 267776 ----a-w- c:\windows\system32\oakley.dll 2009-10-12 13:54 . 2004-08-03 23:44 69632 ----a-w- c:\windows\system32\raschap.dll 2009-10-12 13:54 . 2004-08-03 23:44 112640 ----a-w- c:\windows\system32\rastls.dll . ------- Sigcheck ------- [-] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\atapi.sys [-] 2004-08-03 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\atapi.sys [-] 2004-08-03 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\drivers\atapi.sys [-] 2004-08-03 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\drivers\system32\DRIVERS\atapi.sys [-] 2004-08-03 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys [-] 2004-08-03 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\ReinstallBackups\0007\DriverFiles\i386\atapi.sys [-] 2008-04-13 . B153AFFAC761E7F5FCFA822B9C4E97BC . 14336 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\asyncmac.sys [-] 2004-08-03 . 02000ABF34AF4C218C35D257024807D6 . 14336 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\asyncmac.sys [-] 2004-08-03 . 02000ABF34AF4C218C35D257024807D6 . 14336 . . [5.1.2600.2180] . . c:\windows\system32\drivers\asyncmac.sys [-] 2001-08-17 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . [5.1.2600.0] . . c:\windows\system32\dllcache\beep.sys [-] 2001-08-17 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . [5.1.2600.0] . . c:\windows\system32\drivers\beep.sys [-] 2008-04-14 . 2AECA45D4AEAACBDCB77AD11184E4601 . 24960 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\kbdclass.sys [-] 2004-08-03 . CC13DB862F929AE33F64C3BEDC01CD31 . 24960 . . [5.1.2600.2180] . . c:\windows\system32\drivers\kbdclass.sys [-] 2008-04-13 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\ndis.sys [-] 2004-08-03 . 558635D3AF1C7546D26067D5D9B6959E . 182912 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\ndis.sys [-] 2004-08-03 . 558635D3AF1C7546D26067D5D9B6959E . 182912 . . [5.1.2600.2180] . . c:\windows\system32\drivers\ndis.sys [-] 2008-04-13 . 78A08DD6A8D65E697C18E1DB01C5CDCA . 574976 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\ntfs.sys [-] 2004-08-03 . B78BE402C3F63DD55521F73876951CDD . 574592 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\ntfs.sys [-] 2004-08-03 . B78BE402C3F63DD55521F73876951CDD . 574592 . . [5.1.2600.2180] . . c:\windows\system32\drivers\ntfs.sys [-] 2001-08-17 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . [5.1.2600.0] . . c:\windows\system32\dllcache\null.sys [-] 2001-08-17 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . [5.1.2600.0] . . c:\windows\system32\drivers\null.sys [-] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys [-] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys [-] 2008-06-20 . 2A5554FC5B1E04E131230E3CE035C3F9 . 360320 . . [5.1.2600.3394] . . c:\windows\system32\dllcache\tcpip.sys [-] 2008-06-20 . 2A5554FC5B1E04E131230E3CE035C3F9 . 360320 . . [5.1.2600.3394] . . c:\windows\system32\drivers\tcpip.sys [-] 2008-06-20 . 744E57C99232201AE98C49168B918F48 . 360960 . . [5.1.2600.3394] . . c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys [-] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\tcpip.sys [-] 2004-08-03 . 9F4B36614A0FC234525BA224957DE55C . 359040 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB951748$\tcpip.sys [-] 2008-04-14 . B98ED6D85339A66A73F32FB569EB6C01 . 77824 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\browser.dll [-] 2004-08-03 . 210830D2497FEF78694076179AF8C795 . 77312 . . [5.1.2600.2180] . . c:\windows\system32\browser.dll [-] 2004-08-03 . 210830D2497FEF78694076179AF8C795 . 77312 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\browser.dll [-] 2008-04-14 . 88296F7943F30A1EE3AF735440B92268 . 13312 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\lsass.exe [-] 2004-08-03 . F485FEFC8CC4FD29243D800BE5D275D1 . 13312 . . [5.1.2600.2180] . . c:\windows\system32\lsass.exe [-] 2004-08-03 . F485FEFC8CC4FD29243D800BE5D275D1 . 13312 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\lsass.exe [-] 2008-04-14 . 4FE97D0B1B182DF2A9BDD4C02155EF5E . 198144 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\netman.dll [-] 2004-08-03 . 3E7B6583269BC118720D0020B03CC71E . 198144 . . [5.1.2600.2180] . . c:\windows\system32\netman.dll [-] 2004-08-03 . 3E7B6583269BC118720D0020B03CC71E . 198144 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\netman.dll [-] 2008-04-14 . 78200FAA6FD9C69394134C238C87FB7F . 409088 . . [6.7.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\qmgr.dll [-] 2004-08-03 . A6BFD910074B02C8794FC65F39CC6B28 . 382464 . . [6.6.2600.2180] . . c:\windows\system32\qmgr.dll [-] 2004-08-03 . A6BFD910074B02C8794FC65F39CC6B28 . 382464 . . [6.6.2600.2180] . . c:\windows\system32\dllcache\qmgr.dll [-] 2009-02-09 . C9E5AC78D9A00B1DE8CE2AD1BDDE7E42 . 401408 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\rpcss.dll [-] 2009-02-09 . A37311D9D628C1042A2836731787F0F3 . 401408 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3GDR\rpcss.dll [-] 2009-02-09 . B5D78596EFFBEB82F3B86D9A002538E1 . 399360 . . [5.1.2600.3520] . . c:\windows\system32\rpcss.dll [-] 2009-02-09 . B5D78596EFFBEB82F3B86D9A002538E1 . 399360 . . [5.1.2600.3520] . . c:\windows\system32\dllcache\rpcss.dll [-] 2009-02-09 . 3256C32654CC35DFCFEF42B0C5E4AB89 . 401408 . . [5.1.2600.3520] . . c:\windows\$hf_mig$\KB956572\SP2QFE\rpcss.dll [-] 2008-04-14 . 02396DAB9DD407B06539981F477F3FEC . 399360 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\rpcss.dll [-] 2004-08-03 . 346E5B19FC986FE7185A0C2C43593722 . 395776 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB956572$\rpcss.dll [-] 2009-02-09 . 02A467E27AF55F7064C5B251E587315F . 111104 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3GDR\services.exe [-] 2009-02-09 . 8816E60BF654353E8E0D35ED98875445 . 111104 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\services.exe [-] 2009-02-09 . ED4E5391100287B9EABF8F2CF4B42235 . 111104 . . [5.1.2600.3520] . . c:\windows\system32\services.exe [-] 2009-02-09 . ED4E5391100287B9EABF8F2CF4B42235 . 111104 . . [5.1.2600.3520] . . c:\windows\system32\dllcache\services.exe [-] 2009-02-09 . 245A46964D7F534E1D20563ACF215E80 . 111104 . . [5.1.2600.3520] . . c:\windows\$hf_mig$\KB956572\SP2QFE\services.exe [-] 2008-04-14 . 3E3AE424E27C4CEFE4CAB368C7B570EA . 109056 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\services.exe [-] 2004-08-03 . 3DA8D964D2CC12EF8E8C342471A37917 . 108544 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB956572$\services.exe [-] 2008-04-14 . DD69EC597AB942C39B950D9C3CE1375D . 57856 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\spoolsv.exe [-] 2004-08-03 . BEBE8A85954FF460374FD5A0CD21E19B . 57856 . . [5.1.2600.2180] . . c:\windows\system32\spoolsv.exe [-] 2004-08-03 . BEBE8A85954FF460374FD5A0CD21E19B . 57856 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\spoolsv.exe [-] 2008-04-14 . 51FD2E13D723857B9CA239AE77150F48 . 510464 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\winlogon.exe [-] 2004-08-03 . 0344407089B08548D4FEBA62BB0F32D0 . 504832 . . [5.1.2600.2180] . . c:\windows\system32\winlogon.exe [-] 2004-08-03 . 0344407089B08548D4FEBA62BB0F32D0 . 504832 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\winlogon.exe [-] 2008-04-14 . 0BE00656B7CAEDE754AEE4D7AD13B687 . 617472 . . [5.82] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\comctl32.dll [-] 2008-04-14 . 737739FACEAD60683AA8D7FF7602FD14 . 1054208 . . [6.0] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\asms\60\msft\windows\common\controls\comctl32.dll [-] 2004-08-03 . D38C710AAC3A0D16AF7DF6770C9F6CBB . 611328 . . [5.82] . . c:\windows\system32\comctl32.dll [-] 2004-08-03 . D38C710AAC3A0D16AF7DF6770C9F6CBB . 611328 . . [5.82] . . c:\windows\system32\dllcache\comctl32.dll [-] 2008-04-14 . 6B105FE95F2E9F0B6346044BA59D41C9 . 62464 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\cryptsvc.dll [-] 2004-08-03 . 91723CD7C96C5854149F9CAE820A90DD . 60416 . . [5.1.2600.2180] . . c:\windows\system32\cryptsvc.dll [-] 2004-08-03 . 91723CD7C96C5854149F9CAE820A90DD . 60416 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\cryptsvc.dll [-] 2008-07-07 20:33 . 878FA7B8FFBCFFDAEB05F0484A99562D . 253952 . . [2001.12.4414.320] . . c:\windows\system32\es.dll [-] 2008-07-07 20:33 . 878FA7B8FFBCFFDAEB05F0484A99562D . 253952 . . [2001.12.4414.320] . . c:\windows\system32\dllcache\es.dll [-] 2008-07-07 20:29 . 6AFF804839C85859E0247164FBE5F5BB . 253952 . . [2001.12.4414.706] . . c:\windows\$hf_mig$\KB950974\SP3GDR\es.dll [-] 2008-07-07 20:25 . 5BB3E442E43C7BB0F38203F23C920D3C . 253952 . . [2001.12.4414.706] . . c:\windows\$hf_mig$\KB950974\SP3QFE\es.dll [-] 2008-07-07 20:19 . 266EE073842AFF70B1A1460EE0CBBD49 . 253952 . . [2001.12.4414.320] . . c:\windows\$hf_mig$\KB950974\SP2QFE\es.dll [-] 2008-04-14 17:20 . BE1B1412A3D488C50B8F67F792196108 . 246272 . . [2001.12.4414.701] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\es.dll [-] 2004-08-03 23:43 . DC54CC79E1FAEFA480A8117C9BF105E1 . 243200 . . [2001.12.4414.258] . . c:\windows\$NtUninstallKB950974$\es.dll [-] 2008-04-14 . 2E9A03268E609917B83921EE16FD9CFB . 110080 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\imm32.dll [-] 2004-08-03 . BDB679C04273B19BF46BD0D591FDEEC3 . 110080 . . [5.1.2600.2180] . . c:\windows\system32\imm32.dll [-] 2004-08-03 . BDB679C04273B19BF46BD0D591FDEEC3 . 110080 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\imm32.dll [-] 2009-03-21 . C57B35FBBB25E8314E022F8D13BE5A57 . 1014784 . . [5.1.2600.3541] . . c:\windows\system32\kernel32.dll [-] 2009-03-21 . C57B35FBBB25E8314E022F8D13BE5A57 . 1014784 . . [5.1.2600.3541] . . c:\windows\system32\dllcache\kernel32.dll [-] 2009-03-21 . 77C951B64413E80EEC0359426DCA938B . 1018368 . . [5.1.2600.5781] . . c:\windows\$hf_mig$\KB959426\SP3GDR\kernel32.dll [-] 2009-03-21 . 6CFFFD4A53F08D1BE0222D859BF93B29 . 1020416 . . [5.1.2600.5781] . . c:\windows\$hf_mig$\KB959426\SP3QFE\kernel32.dll [-] 2009-03-21 . 6B29B8F00F7CDE46C69BDED5253B96B9 . 1017856 . . [5.1.2600.3541] . . c:\windows\$hf_mig$\KB959426\SP2QFE\kernel32.dll [-] 2008-04-14 . FCE4ECC34A36EDACF03DBE8DE5E28910 . 1018368 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\kernel32.dll [-] 2004-08-03 . 578BB2F44597CB53451DED99013573F3 . 1012224 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB959426$\kernel32.dll [-] 2008-04-14 . EA8DF0AF49E2616F55BF327549E44368 . 19968 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\linkinfo.dll [-] 2004-08-03 . 7068F13DEFF03488E1A1E27E4BC004E8 . 18944 . . [5.1.2600.2180] . . c:\windows\system32\linkinfo.dll [-] 2004-08-03 . 7068F13DEFF03488E1A1E27E4BC004E8 . 18944 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\linkinfo.dll [-] 2008-04-14 . A9C89DBAD5EFF7A06B58302778674507 . 22016 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\lpk.dll [-] 2004-08-03 . 261DB4366ECB4220EA960F0CA78CABAC . 22016 . . [5.1.2600.2180] . . c:\windows\system32\lpk.dll [-] 2004-08-03 . 261DB4366ECB4220EA960F0CA78CABAC . 22016 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\lpk.dll [-] 2008-04-14 . 411864012AC39F2B57319AEF64D336DF . 343040 . . [7.0.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\msvcrt.dll [-] 2008-04-14 . 11F8B9042B6F4320B6D4E528664AD693 . 343040 . . [7.0.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\asms\70\msft\windows\mswincrt\msvcrt.dll [-] 2004-08-03 . 9AFE931CBC9244A5EB0B9E9D5FA74F44 . 343040 . . [7.0.2600.2180] . . c:\windows\system32\msvcrt.dll [-] 2004-08-03 . 9AFE931CBC9244A5EB0B9E9D5FA74F44 . 343040 . . [7.0.2600.2180] . . c:\windows\system32\dllcache\msvcrt.dll [-] 2008-06-20 . 300BCC512DE4038F1494230941DB2C2A . 246784 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3GDR\mswsock.dll [-] 2008-06-20 . BF80D884E1C60DED1C7CEA3EC6F9DC28 . 246784 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\mswsock.dll [-] 2008-06-20 . D4ABFCD86AF9533EF94F291A1BB3E9A2 . 246784 . . [5.1.2600.3394] . . c:\windows\system32\mswsock.dll [-] 2008-06-20 . D4ABFCD86AF9533EF94F291A1BB3E9A2 . 246784 . . [5.1.2600.3394] . . c:\windows\system32\dllcache\mswsock.dll [-] 2008-06-20 . F1590C9B2294DB9ACE3B081ABD596174 . 246784 . . [5.1.2600.3394] . . c:\windows\$hf_mig$\KB951748\SP2QFE\mswsock.dll [-] 2008-04-14 . 612E31FCAC1040EDD78ECAC81C9F859F . 246784 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\mswsock.dll [-] 2004-08-03 . 83387067B25E000E64B178A62E5DCD24 . 246784 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB951748$\mswsock.dll [-] 2009-02-06 . B771DCBE0449C9F0F290092DEC48E698 . 408064 . . [5.1.2600.3520] . . c:\windows\$hf_mig$\KB968389\SP2QFE\netlogon.dll [-] 2009-02-06 . B771DCBE0449C9F0F290092DEC48E698 . 408064 . . [5.1.2600.3520] . . c:\windows\$hf_mig$\KB975467\SP2QFE\netlogon.dll [-] 2008-04-14 . 9858AD0A3FCD83C3B100EDD5852DE540 . 407040 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\netlogon.dll [-] 2004-08-03 . 8BE1BEBB1447EFFAF5F2135DC098431E . 407040 . . [5.1.2600.2180] . . c:\windows\system32\netlogon.dll [-] 2004-08-03 . 8BE1BEBB1447EFFAF5F2135DC098431E . 407040 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\netlogon.dll [-] 2008-04-14 . 414C17A2958AEDAC700BBAAFBF999F94 . 17408 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\powrprof.dll [-] 2004-08-03 . B20BB2A65349EF132FA7F2EB51A29E5C . 17408 . . [6.00.2900.2180] . . c:\windows\system32\powrprof.dll [-] 2004-08-03 . B20BB2A65349EF132FA7F2EB51A29E5C . 17408 . . [6.00.2900.2180] . . c:\windows\system32\dllcache\powrprof.dll [-] 2008-04-14 . 3F74B6B4E2721272A117D25990141F73 . 186368 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\scecli.dll [-] 2004-08-03 . 3609496AE18FF399920C494270C526F9 . 185344 . . [5.1.2600.2180] . . c:\windows\system32\scecli.dll [-] 2004-08-03 . 3609496AE18FF399920C494270C526F9 . 185344 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\scecli.dll [-] 2008-04-14 . 71C6AB6EB8CF1190BAC7075F82BD8F05 . 5120 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\sfc.dll [-] 2004-08-03 . 3F342B984E9E1ABD58347DA859CD44C6 . 5120 . . [5.1.2600.2180] . . c:\windows\system32\sfc.dll [-] 2004-08-03 . 3F342B984E9E1ABD58347DA859CD44C6 . 5120 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\sfc.dll [-] 2008-04-14 . 8607D35D92528E2DF386F19A960D23CE . 14336 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\svchost.exe [-] 2004-08-03 . BA98327E90022DBD6EE76490E0622E2E . 14336 . . [5.1.2600.2180] . . c:\windows\system32\svchost.exe [-] 2004-08-03 . BA98327E90022DBD6EE76490E0622E2E . 14336 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\svchost.exe [-] 2008-04-14 . 2340E6977548038C88E39A9ECBB3FADC . 249856 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\tapisrv.dll [-] 2004-08-03 . 0A695B77564D8E9333E846B526F95AB2 . 246272 . . [5.1.2600.2180] . . c:\windows\system32\tapisrv.dll [-] 2004-08-03 . 0A695B77564D8E9333E846B526F95AB2 . 246272 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\tapisrv.dll [-] 2008-04-14 . A435C5C069AFD901751AC323AD238793 . 580096 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\user32.dll [-] 2004-08-03 . 0C81764F50F32D376E6E4B9E9F4B01A0 . 578560 . . [5.1.2600.2180] . . c:\windows\system32\user32.dll [-] 2004-08-03 . 0C81764F50F32D376E6E4B9E9F4B01A0 . 578560 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\user32.dll [-] 2008-04-14 . 2A5B37D520508BE6570A3EA79695F5B5 . 26624 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\userinit.exe [-] 2004-08-03 . BD768099B4C44AA631728CB74EB54396 . 25088 . . [5.1.2600.2180] . . c:\windows\system32\userinit.exe [-] 2004-08-03 . BD768099B4C44AA631728CB74EB54396 . 25088 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\userinit.exe [-] 2008-04-14 . C0AA2AB856680C44739B41E01F5BD4E9 . 82432 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\ws2_32.dll [-] 2004-08-03 . AB82237486B727DD7DAB36A76F38A3A2 . 82944 . . [5.1.2600.2180] . . c:\windows\system32\ws2_32.dll [-] 2004-08-03 . AB82237486B727DD7DAB36A76F38A3A2 . 82944 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\ws2_32.dll [-] 2008-04-14 . C791ED9EAC5E76D9525E157B1D7A599A . 1035264 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\explorer.exe [-] 2004-08-03 . 379098A96E6C165B659DE7E4328010EA . 1033728 . . [6.00.2900.2180] . . c:\windows\explorer.exe [-] 2004-08-03 . 379098A96E6C165B659DE7E4328010EA . 1033728 . . [6.00.2900.2180] . . c:\windows\system32\dllcache\explorer.exe [-] 2008-04-14 . 316D0E66074AE4CDE641C50D3A1C5148 . 171520 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\srsvc.dll [-] 2004-08-03 . F309D9894FCA821E3C2F557A8032D47A . 171008 . . [5.1.2600.2180] . . c:\windows\system32\srsvc.dll [-] 2004-08-03 . F309D9894FCA821E3C2F557A8032D47A . 171008 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\srsvc.dll [-] 2008-04-14 . CC07DA5A1CB214ADDFA50B2FA6935F18 . 13824 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\wscntfy.exe [-] 2004-08-03 . 1905812AB06A70FF21907FAA10C927D6 . 13824 . . [5.1.2600.2180] . . c:\windows\system32\wscntfy.exe [-] 2004-08-03 . 1905812AB06A70FF21907FAA10C927D6 . 13824 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\wscntfy.exe [-] 2008-04-14 . 24ED6935771359A5AEF1FE8BF0C56F39 . 129024 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\xmlprov.dll [-] 2004-08-03 . E3C9EF5BCC9EB171BD81051CD19BDED7 . 129536 . . [5.1.2600.2180] . . c:\windows\system32\xmlprov.dll [-] 2004-08-03 . E3C9EF5BCC9EB171BD81051CD19BDED7 . 129536 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\xmlprov.dll [-] 2008-04-14 . 35FCCFD093582FA9098762E6F84EE119 . 56320 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\eventlog.dll [-] 2004-08-03 . 05684DE2DA55A04C8AAAB5911AFE7643 . 55808 . . [5.1.2600.2180] . . c:\windows\system32\eventlog.dll [-] 2004-08-03 . 05684DE2DA55A04C8AAAB5911AFE7643 . 55808 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\eventlog.dll [-] 2008-04-14 . A9ED600F08A92143253C10EDB5651ECF . 1571840 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\sfcfiles.dll [-] 2004-08-03 . F044A12CFFB8E58BC044A2605283A636 . 1548288 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll [-] 2004-08-03 . F044A12CFFB8E58BC044A2605283A636 . 1548288 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\sfcfiles.dll [-] 2008-04-14 . 1BD41EDA5B869AFC99895C39A8DE36E1 . 15360 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\ctfmon.exe [-] 2004-08-03 . CBFA30492D70CE3938D8A7783D0C0436 . 15360 . . [5.1.2600.2180] . . c:\windows\system32\ctfmon.exe [-] 2004-08-03 . CBFA30492D70CE3938D8A7783D0C0436 . 15360 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\ctfmon.exe [-] 2008-04-14 . 8AD90ED829B8404D962545ED3EFB1129 . 135680 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\shsvcs.dll [-] 2004-08-03 . 7C8E934687C496EDC69FDBBD2C277E63 . 135168 . . [6.00.2900.2180] . . c:\windows\system32\shsvcs.dll [-] 2004-08-03 . 7C8E934687C496EDC69FDBBD2C277E63 . 135168 . . [6.00.2900.2180] . . c:\windows\system32\dllcache\shsvcs.dll [-] 2008-04-14 . B472B59EF98469C91651B751D3442CB8 . 59904 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\regsvc.dll [-] 2004-08-03 . A19BFED61736127DB5B8B815AFB35190 . 59904 . . [5.1.2600.2180] . . c:\windows\system32\regsvc.dll [-] 2004-08-03 . A19BFED61736127DB5B8B815AFB35190 . 59904 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\regsvc.dll [-] 2008-04-14 . DD73C11A5C4D14945846384B90A61A4B . 193536 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\schedsvc.dll [-] 2004-08-03 . E5F1C9EAD4C6617ACD40CA90882CC7D4 . 192000 . . [5.1.2600.2180] . . c:\windows\system32\schedsvc.dll [-] 2004-08-03 . E5F1C9EAD4C6617ACD40CA90882CC7D4 . 192000 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\schedsvc.dll [-] 2008-04-14 . 2C0B1224AA36B4CA1753302BAA855882 . 71680 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\ssdpsrv.dll [-] 2004-08-03 . BB754C4BE0B18F0FAF01A7EBDE7025C4 . 71680 . . [5.1.2600.2180] . . c:\windows\system32\ssdpsrv.dll [-] 2004-08-03 . BB754C4BE0B18F0FAF01A7EBDE7025C4 . 71680 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\ssdpsrv.dll [-] 2008-04-14 . 52E0505408EDD4AB5CCC7F83B67B4299 . 296448 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\termsrv.dll [-] 2004-08-03 . 2C28157229925280916B3041CCC5FE4B . 296448 . . [5.1.2600.2180] . . c:\windows\system32\termsrv.dll [-] 2004-08-03 . 2C28157229925280916B3041CCC5FE4B . 296448 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\termsrv.dll [-] 2008-04-14 . 1561430DA2F2AB81CC0CE71AF95A778D . 172032 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\appmgmts.dll [-] 2004-08-03 . 8D60B308D061DA209CC271D9B480468C . 172032 . . [5.1.2600.2180] . . c:\windows\system32\appmgmts.dll [-] 2004-08-03 . 8D60B308D061DA209CC271D9B480468C . 172032 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\appmgmts.dll [-] 2001-10-26 . 66A42B7DB194E24B973BBCCE840A0F3F . 12032 . . [5.1.2600.0] . . c:\windows\system32\drivers\acpiec.sys [-] 2008-04-13 16:39 . 8BED39E3C35D6A489438B8141717A557 . 142592 . . [5.1.2601.3142] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\aec.sys [-] 2004-08-03 21:39 . 841F385C6CFAF66B58FBD898722BB4F0 . 142464 . . [5.1.2601.2078] . . c:\windows\system32\dllcache\aec.sys [-] 2004-08-03 21:39 . 841F385C6CFAF66B58FBD898722BB4F0 . 142464 . . [5.1.2601.2078] . . c:\windows\system32\drivers\aec.sys [-] 2008-04-13 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\ip6fw.sys [-] 2004-08-03 . 4448006B6BC60E6C027932CFC38D6855 . 29056 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\ip6fw.sys [-] 2004-08-03 . 4448006B6BC60E6C027932CFC38D6855 . 29056 . . [5.1.2600.2180] . . c:\windows\system32\drivers\ip6fw.sys [-] 2008-04-14 17:20 . E43B998C777D43FB8624741B4567BCD9 . 927504 . . [4.1.0.61] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\mfc40u.dll [-] 2001-10-26 17:29 . CFA664EFA06EEE2B02721C1384F51123 . 924432 . . [4.1.6140] . . c:\windows\system32\mfc40u.dll [-] 2001-10-26 17:29 . CFA664EFA06EEE2B02721C1384F51123 . 924432 . . [4.1.6140] . . c:\windows\system32\dllcache\mfc40u.dll [-] 2008-04-14 . 36F3AB18B1BE303DA51DE90A67DE3942 . 33792 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\msgsvc.dll [-] 2004-08-03 . 1D0EBF9EDAE8A61CBF56ED1FF8489FAC . 33792 . . [5.1.2600.2180] . . c:\windows\system32\msgsvc.dll [-] 2004-08-03 . 1D0EBF9EDAE8A61CBF56ED1FF8489FAC . 33792 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\msgsvc.dll [-] 2004-08-11 00:45 . A477391B7A8B0A0DAABADB17CF533A4B . 25088 . . [10.0.3790.3646] . . c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\MsPMSNSv.dll [-] 2004-08-11 00:45 . A477391B7A8B0A0DAABADB17CF533A4B . 25088 . . [10.0.3790.3646] . . c:\windows\system32\MsPMSNSv.dll [-] 2004-08-11 00:45 . A477391B7A8B0A0DAABADB17CF533A4B . 25088 . . [10.0.3790.3646] . . c:\windows\system32\dllcache\mspmsnsv.dll [-] 2004-08-03 23:44 . FA83DF4EE3B86E5CE53A5EA425F3F472 . 52736 . . [9.0.1.56] . . c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\MsPMSNSv.dll [-] 2008-04-14 17:20 . 3FB5399DBB7001A80D58EDAD64C98225 . 435712 . . [5.1.2400.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\ntmssvc.dll [-] 2004-08-03 23:44 . C8CE1566B0537C3F5F7AE1CA458A6697 . 435712 . . [5.1.2400.2180] . . c:\windows\system32\ntmssvc.dll [-] 2004-08-03 23:44 . C8CE1566B0537C3F5F7AE1CA458A6697 . 435712 . . [5.1.2400.2180] . . c:\windows\system32\dllcache\ntmssvc.dll [-] 2008-04-14 . E96A6BAEE0B2A14A38B45830D6E30697 . 186880 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\upnphost.dll [-] 2004-08-03 . 387D2A06C8E7CCCEA8E9A350C8FE6781 . 185856 . . [5.1.2600.2180] . . c:\windows\system32\upnphost.dll [-] 2004-08-03 . 387D2A06C8E7CCCEA8E9A350C8FE6781 . 185856 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\upnphost.dll . ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "GAINWARD"="c:\program files\EXPERTool\TBPanel.exe" [2008-10-21 2177576] "LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-12-06 2387968] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Six Engine"="c:\program files\ASUS\EPU-4 Engine\FourEngine.exe" [2008-06-25 5625344] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-21 13574144] "nwiz"="nwiz.exe" [2008-10-21 1630208] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-21 86016] "CTHelper"="CTHELPER.EXE" [2008-06-27 19456] "NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136] "SecurDisc"="c:\program files\Nero\Nero 7\InCD\NBHGui.exe" [2007-11-26 1629480] "InCD"="c:\program files\Nero\Nero 7\InCD\InCD.exe" [2007-11-26 1057064] "H2O"="c:\program files\SyncroSoft\Pos\H2O\cledx.exe" [2007-12-11 307200] "avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-03-09 2769336] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "wave9"=Echo24Wrap.dll [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk * [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"= "f:\\Program Files\\Nowe Gadu-Gadu\\gg.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "9101:TCP"= 9101:TCP:BitComet 9101 TCP "9101:UDP"= 9101:UDP:BitComet 9101 UDP "26517:TCP"= 26517:TCP:BitComet 26517 TCP "26517:UDP"= 26517:UDP:BitComet 26517 UDP "13844:TCP"= 13844:TCP:BitComet 13844 TCP "13844:UDP"= 13844:UDP:BitComet 13844 UDP R1 Asapi;Asapi;c:\windows\system32\drivers\asapi.sys [2009-01-07 11264] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2009-12-27 162640] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-12-27 19024] R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\drivers\cledx.sys [2008-12-25 33792] R3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [2008-06-27 99352] R3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [2008-06-27 555032] R3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [2008-06-27 566296] R3 echo24;Echo24 Service;c:\windows\system32\drivers\echo24.sys [2008-12-25 557056] S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2009-08-21 691696] S2 gupdate;Usługa Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2009-11-07 135664] S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [2008-06-27 99352] S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [2008-06-27 555032] S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [2008-06-27 100888] S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [2008-06-27 100888] S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [2008-06-27 566296] S3 Droppix Service;Droppix Service;c:\program files\Common Files\Droppix\DxService.exe [2009-01-07 135168] S3 nmwcdsa;Samsung USB Phone Parent;c:\windows\system32\drivers\nmwcdsa.sys [2009-06-09 135680] S3 nmwcdsac;Samsung USB Generic;c:\windows\system32\drivers\nmwcdsac.sys [2009-06-09 8320] S3 nmwcdsacj;Samsung USB Port;c:\windows\system32\drivers\nmwcdsacj.sys [2009-06-09 12288] S3 nmwcdsacm;Samsung USB Modem;c:\windows\system32\drivers\nmwcdsacm.sys [2009-06-09 12288] S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] 2008-12-06 22:18 451872 -c--a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe . Zawartość folderu 'Zaplanowane zadania' 2009-12-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-11-07 20:43] 2009-12-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-11-07 20:43] . . ------- Skan uzupełniający ------- . IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html . - - - - USUNIĘTO PUSTE WPISY - - - - HKCU-Run-ares - f:\program files\Ares\Ares.exe AddRemove-Addictive Drums - c:\windows\unvise32.exe AddRemove-Antares Autotune DX v4.3.1 - c:\progra~1\ANTARE~1\AUTO-T~1\Tutorial\UNWISE.EXE AddRemove-Ares - f:\program files\Ares\uninstall.exe AddRemove-ArtsAcoustic Reverb VST v1.1.0.1 - c:\progra~1\STEINB~1\VSTPLU~1\ARTSAC~1\Reverb\UNINST~1\UNWISE.EXE AddRemove-Arturia Minimoog V v1.0 - c:\progra~1\Arturia\MINIMO~1\UNWISE.EXE AddRemove-Audiorealism Bassline Pro v1.0.1 - c:\progra~1\STEINB~1\VSTPLU~1\AUDIOR~1\BASSLI~1\UNINST~1\UNWISE.EXE AddRemove-Dash Signature theAbstractGuitar VSTi v1.26 - c:\progra~1\STEINB~1\VSTPLU~1\THEABS~1\THEABS~1\UNWISE.EXE AddRemove-Elemental Audio Neodynium VST RTAS - c:\progra~1\ELEMEN~1\NEODYN~1\UNWISE.EXE AddRemove-Guitar Pro 5_is1 - f:\program files\Guitar Pro 5\unins000.exe AddRemove-KORG Legacy Collection - DIGITAL EDITION v1.0.0 - c:\progra~1\KORG\KORGLE~1\UNWISE.EXE AddRemove-Linplug daOrgan v2.1.1 - c:\progra~1\STEINB~1\VSTPLU~1\LINPLU~1\DAORGA~1\UNWISE.EXE AddRemove-NomadFactory Rock Amp Legends RTAS v1.01 - c:\progra~1\NOMADF~1\ROCKAM~1\ROCKAM~1\UNWISE.EXE AddRemove-NomadFactory Rock Amp Legends VST v1.01 - c:\progra~1\STEINB~1\VSTPLU~1\RALv101\UNWISE.EXE AddRemove-Novation Bass-Station for Cubase SX3 VSTi v1.41 - c:\progra~1\STEINB~1\VSTPLU~1\NOVATI~1\BASSUN~1\UNWISE.EXE AddRemove-Polarity GX Stack Guitar Amplifier System VST v1.0.4.1 - c:\progra~1\STEINB~1\VSTPLU~1\POLARI~1\UNWISE.EXE AddRemove-Rgc Audio z3ta+ VSTi DXi - c:\progra~1\STEINB~1\VSTPLU~1\Z3TA_~1\UNINST~1\UNWISE.EXE AddRemove-Rocktave Fact 2 VSTi v1.0 - c:\progra~1\STEINB~1\VSTPLU~1\ROCKTA~2\UNWISE.EXE AddRemove-Rocktave Universal Fx VST v1.0 - c:\progra~1\STEINB~1\VSTPLU~1\ROCKTA~1\UNWISE.EXE AddRemove-SCARBEE Vintage Keyboard FX v1.2.1 - c:\progra~1\STEINB~1\VSTPLU~1\SCARBEE\VKFXUS~1\UNWISE.EXE AddRemove-SpinAudio 3DChorus VST DX v1.2 Build 250 - c:\progra~1\SPINAU~1\3DChorus\UNWISE.EXE AddRemove-SRS Circle Surround VST Pro 1.0.2 - c:\progra~1\STEINB~1\VSTPLU~1\CSVSTP~1\UNWISE.EXE AddRemove-Steinberg WaveLab 5.01a - c:\progra~1\STEINB~1\WaveLab\UNWISE.EXE AddRemove-Voxengo PHA-979 VST v1.2 - c:\progra~1\STEINB~1\VSTPLU~1\VOXENG~1\UNWISE.EXE AddRemove-Warhammer Online - Age of Reckoning_is1 - f:\program files\kk\Warhammer Online\unins000.exe AddRemove-WaveMachine Labs Drumagog VST RTAS v4.02 - c:\progra~1\DRUMAG~1\UNWISE.EXE AddRemove-Waves Diamond Bundle v5.0 - c:\progra~1\Waves\UNINST~1\UNWISE.EXE AddRemove-Waves Diamond Bundle v5.2 - c:\progra~1\Waves\DIAMON~1\UNWISE.EXE ************************************************************************** skanowanie ukrytych procesów ... skanowanie ukrytych wpisów autostartu ... HKLM\Software\Microsoft\Windows\CurrentVersion\Run CTHelper = CTHELPER.EXE? skanowanie ukrytych plików ... skanowanie pomyślnie ukończone ukryte pliki: ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . --------------------- ZABLOKOWANE KLUCZE REJESTRU --------------------- [HKEY_USERS\S-1-5-21-1957994488-606747145-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:33,2f,b9,66,f5,7a,9d,c5,c4,eb,d3,b3,65,d3,2d,7d,57,4c,fb,58,48,f5,9a, 95,4d,2b,1e,72,35,e2,37,26,47,ba,d3,40,7f,54,1a,c2,63,55,fd,e6,83,6b,cb,ff,\ "??"=hex:5d,2e,bc,00,9b,07,bc,9c,34,34,87,88,c9,ab,ca,0d . Czas ukończenia: 2009-12-31 09:25:45 ComboFix-quarantined-files.txt 2009-12-31 08:25 Przed: 18 630 098 944 bajtów wolnych Po: 19 126 583 296 bajtów wolnych WindowsXP-KB310994-SP2-Pro-BootDisk-PLK.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect - - End Of File - - 481EC823C397D78E8736713814896CC7