========== Chrome ========== CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Kiss Bal\u00E1zs\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Kiss Bal\u00E1zs\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Kiss Bal\u00E1zs\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: vShare.tv plug-in (Enabled) = C:\Documents and Settings\Kiss Bal\u00E1zs\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0\chvsharetvplg.dll
CHR - plugin: vShare.tv plug-in (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npvsharetvplg.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Kiss Bal\u00E1zs\Local Settings\Application Data\Google\Update\1.2.183.39\npGoogleOneClick8.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
O1 HOSTS File: ([2011.11.29 18:35:38 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-725345543-1715567821-682003330-1003\..\Toolbar\WebBrowser: (uTorrentBar Toolbar) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - C:\Program Files\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-21-725345543-1715567821-682003330-1003..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - HKU\.DEFAULT..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 File not found
O4 - HKU\S-1-5-18..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-725345543-1715567821-682003330-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-725345543-1715567821-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-725345543-1715567821-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-725345543-1715567821-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microso ... 2640710843 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 213.46.246.53 213.46.246.54
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DD9CAC21-4195-4433-91C0-2E256D522B85}: DhcpNameServer = 213.46.246.53 213.46.246.54
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (Jelenlegi saját honlap) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Kiss Balázs\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Kiss Balázs\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011.08.05 22:57:37 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2001.09.25 12:08:44 | 001,572,864 | R--- | M] () - F:\Autorun.exe -- [ CDFS ]
O32 - AutoRun File - [2001.09.25 12:08:44 | 000,000,135 | R--- | M] () - F:\Autorun.inf -- [ CDFS ]
O32 - AutoRun File - [2004.02.23 10:44:06 | 000,000,046 | R--- | M] () - G:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.divxa32 - C:\WINDOWS\System32\divxa32.acm (Kristal StudioDFileDescription)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.imc - C:\WINDOWS\System32\IMC32.acm (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3fhg - C:\WINDOWS\System32\mp3fhg.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (
http://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.vorbis - C:\WINDOWS\System32\vorbis.acm (HMS
http://hp.vector.co.jp/authors/VA012897/)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.DIVX - C:\WINDOWS\System32\divx.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: VIDC.HFYU - C:\WINDOWS\System32\huffyuv.dll (Disappearing Inc.)
Drivers32: vidc.i263 - C:\WINDOWS\System32\I263_32.drv (Intel Corporation)
Drivers32: vidc.I420 - C:\WINDOWS\System32\i420vfw.dll (
www.helixcommunity.org)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.VP60 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP61 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP62 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP70 - C:\WINDOWS\System32\vp7vfw.dll (On2.com)
Drivers32: VIDC.wmv3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)
Drivers32: VIDC.X264 - C:\WINDOWS\System32\x264vfw.dll ()
Drivers32: VIDC.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\yv12vfw.dll (
www.helixcommunity.org)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin
========== Files/Folders - Created Within 30 Days ========== [2011.11.29 18:35:41 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011.11.29 18:35:35 | 000,000,000 | ---D | C] -- C:\_OTL
[2011.11.29 18:31:11 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Kiss Balázs\Asztal\OTL.exe
[2011.11.29 18:11:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2011.11.29 18:03:24 | 000,000,000 | ---D | C] -- C:\ComboFix
[2011.11.29 16:57:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\xircom
[2011.11.29 16:57:23 | 000,000,000 | ---D | C] -- C:\Program Files\xerox
[2011.11.29 16:57:23 | 000,000,000 | ---D | C] -- C:\Program Files\microsoft frontpage
[2011.11.29 14:18:46 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Kiss Balázs\ComboFix
[2011.11.29 13:41:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2011.11.29 13:34:30 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011.11.29 13:31:59 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011.11.29 13:31:32 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Kiss Balázs\Start Menu\Programs\Felügyeleti eszközök
[2011.11.29 13:12:23 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2011.11.29 10:08:02 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2011.11.29 10:08:01 | 000,000,000 | ---D | C] -- C:\rsit
[2011.11.27 21:18:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kiss Balázs\Application Data\AVG
[2011.11.27 17:55:26 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2011.11.27 17:55:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2011.11.27 17:48:17 | 000,380,928 | R--- | C] (Simon Fell) -- C:\WINDOWS\System32\pSOAP32.dll
[2011.11.27 17:48:17 | 000,188,416 | R--- | C] (Simon Fell) -- C:\WINDOWS\System32\pocketHTTP.dll
[2011.11.27 17:48:17 | 000,110,676 | R--- | C] (pocketsoap.com) -- C:\WINDOWS\System32\psDime.dll
[2011.11.27 17:48:17 | 000,073,728 | R--- | C] (
www.pocketsoap.com) -- C:\WINDOWS\System32\psProxy.dll
[2011.11.26 20:39:35 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Kiss Balázs\Recent
[2011.11.24 16:16:13 | 000,000,000 | -H-D | C] -- C:\WINDOWS\PIF
[2011.11.05 19:39:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kiss Balázs\Start Menu\Programs\Rome - Total War
[2011.11.05 11:45:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Ashampoo
[2011.11.05 11:44:26 | 000,000,000 | ---D | C] -- C:\Program Files\Ashampoo
[2011.11.04 18:46:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kiss Balázs\Local Settings\Application Data\My Games
[2011.11.04 18:46:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kiss Balázs\Dokumentumok\My Games
[2011.11.04 18:40:00 | 000,107,888 | ---- | C] (Sony DADC Austria AG.) -- C:\WINDOWS\System32\CmdLineExt.dll
[2011.11.04 18:39:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Firaxis Games
[2011.11.04 18:36:16 | 000,000,000 | ---D | C] -- C:\Program Files\2K Games
[2011.11.04 18:36:14 | 001,124,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DCompiler_34.dll
[2011.11.04 18:36:14 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx10_34.dll
[2011.11.04 18:36:14 | 000,266,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_8.dll
[2011.11.04 18:36:14 | 000,018,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\x3daudio1_2.dll
[2011.11.04 18:36:13 | 003,497,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_34.dll
[2011.11.04 18:36:12 | 000,261,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_7.dll
[2011.11.04 18:36:11 | 001,123,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DCompiler_33.dll
[2011.11.04 18:36:11 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx10_33.dll
[2011.11.04 18:36:08 | 003,495,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_33.dll
[2011.11.04 18:36:08 | 000,255,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_6.dll
[2011.11.04 09:06:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kiss Balázs\Application Data\Ashampoo
[2011.11.04 09:06:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kiss Balázs\Local Settings\Application Data\ConduitEngine
[2011.11.04 09:05:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kiss Balázs\Local Settings\Application Data\ashampoo
[2011.11.04 09:05:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ashampoo
[2011.11.04 08:34:24 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}
[2011.11.04 08:34:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kiss Balázs\Local Settings\Application Data\PackageAware
[2011.11.03 17:57:39 | 000,000,000 | ---D | C] -- C:\tmp
[2011.11.03 17:57:39 | 000,000,000 | ---D | C] -- C:\output
[2011.11.03 14:05:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kiss Balázs\Application Data\12Ghosts
[2011.11.03 14:05:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\12Ghosts
[2011.11.03 14:04:19 | 000,000,000 | ---D | C] -- C:\Program Files\12Ghosts
[2011.11.03 13:58:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kiss Balázs\Application Data\STGU
[2011.11.03 13:58:27 | 000,152,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\Comdlg32.ocx
[2011.11.03 12:54:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kiss Balázs\Start Menu\Programs\Google Chrome
========== Files - Modified Within 30 Days ========== [2011.11.29 19:46:51 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2011.11.29 18:53:25 | 000,471,344 | ---- | M] () -- C:\WINDOWS\System32\perfh00E.dat
[2011.11.29 18:53:25 | 000,443,588 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011.11.29 18:53:25 | 000,110,290 | ---- | M] () -- C:\WINDOWS\System32\perfc00E.dat
[2011.11.29 18:53:25 | 000,071,846 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011.11.29 18:49:33 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011.11.29 18:49:04 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011.11.29 18:35:38 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts
[2011.11.29 18:31:21 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Kiss Balázs\Asztal\OTL.exe
[2011.11.29 16:19:19 | 000,190,464 | ---- | M] () -- C:\Documents and Settings\Kiss Balázs\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.11.29 13:34:34 | 000,000,336 | RHS- | M] () -- C:\boot.ini
[2011.11.06 09:38:55 | 000,000,702 | ---- | M] () -- C:\Documents and Settings\Kiss Balázs\Asztal\DLOGO.lnk
[2011.11.05 19:42:11 | 000,000,697 | ---- | M] () -- C:\Documents and Settings\Kiss Balázs\Asztal\Parancsikon - RomeTW.lnk
[2011.11.05 19:39:42 | 000,000,240 | ---- | M] () -- C:\WINDOWS\RomeTW.ini
[2011.11.05 11:45:05 | 000,000,864 | ---- | M] () -- C:\Documents and Settings\Kiss Balázs\Application Data\Microsoft\Internet Explorer\Quick Launch\Ashampoo Burning Studio 10.lnk
[2011.11.05 11:45:05 | 000,000,846 | ---- | M] () -- C:\Documents and Settings\All Users\Asztal\Ashampoo Burning Studio 10.lnk
[2011.11.04 18:47:49 | 000,001,009 | ---- | M] () -- C:\Documents and Settings\Kiss Balázs\Asztal\Parancsikon - Colonization.lnk
[2011.11.04 18:40:00 | 000,107,888 | ---- | M] (Sony DADC Austria AG.) -- C:\WINDOWS\System32\CmdLineExt.dll
[2011.11.03 12:54:49 | 000,002,308 | ---- | M] () -- C:\Documents and Settings\Kiss Balázs\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011.11.01 08:37:44 | 000,000,085 | ---- | M] () -- C:\WINDOWS\FinalAlert2.ini
========== Files Created - No Company Name ========== [2011.11.29 19:46:51 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2011.11.29 13:34:34 | 000,000,220 | ---- | C] () -- C:\Boot.bak
[2011.11.29 13:34:32 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2011.11.06 09:38:55 | 000,000,702 | ---- | C] () -- C:\Documents and Settings\Kiss Balázs\Asztal\DLOGO.lnk
[2011.11.05 19:42:12 | 000,000,697 | ---- | C] () -- C:\Documents and Settings\Kiss Balázs\Asztal\Parancsikon - RomeTW.lnk
[2011.11.05 19:39:42 | 000,000,240 | ---- | C] () -- C:\WINDOWS\RomeTW.ini
[2011.11.05 11:45:05 | 000,000,864 | ---- | C] () -- C:\Documents and Settings\Kiss Balázs\Application Data\Microsoft\Internet Explorer\Quick Launch\Ashampoo Burning Studio 10.lnk
[2011.11.05 11:45:05 | 000,000,846 | ---- | C] () -- C:\Documents and Settings\All Users\Asztal\Ashampoo Burning Studio 10.lnk
[2011.11.04 18:47:49 | 000,001,009 | ---- | C] () -- C:\Documents and Settings\Kiss Balázs\Asztal\Parancsikon - Colonization.lnk
[2011.11.03 12:54:49 | 000,002,308 | ---- | C] () -- C:\Documents and Settings\Kiss Balázs\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011.10.23 14:03:37 | 000,000,085 | ---- | C] () -- C:\WINDOWS\FinalAlert2.ini
[2011.08.25 14:28:23 | 000,222,800 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011.08.25 10:05:59 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDevice.Dll
[2011.08.25 10:05:59 | 000,036,640 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDisk.Sys
[2011.08.25 10:05:51 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\Kiss Balázs\Application Data\$_hpcst$.hpc
[2011.08.07 11:03:05 | 000,223,128 | ---- | C] () -- C:\WINDOWS\System32\drivers\dtscsi.sys
[2011.08.07 11:01:26 | 000,096,384 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd1965.sys
[2011.08.06 12:26:03 | 000,190,464 | ---- | C] () -- C:\Documents and Settings\Kiss Balázs\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.08.06 12:05:15 | 000,000,134 | ---- | C] () -- C:\Documents and Settings\Kiss Balázs\Local Settings\Application Data\fusioncache.dat
[2011.08.06 10:31:26 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2011.08.06 09:27:33 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2011.08.06 09:27:33 | 000,765,952 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2011.08.06 09:27:33 | 000,558,592 | ---- | C] () -- C:\WINDOWS\System32\x264vfw.dll
[2011.08.06 09:27:33 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2011.08.06 09:27:32 | 000,010,752 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2011.08.06 09:19:13 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2011.08.06 09:17:25 | 000,593,920 | ---- | C] () -- C:\WINDOWS\System32\ati2sgag.exe
[2011.08.06 00:49:18 | 000,004,249 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2011.08.06 00:46:27 | 000,269,392 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011.08.05 23:02:58 | 000,001,732 | R--- | C] () -- C:\WINDOWS\System32\drivers\nvphy.bin
[2011.08.05 23:02:04 | 000,004,445 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2011.08.05 23:02:01 | 000,010,288 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2011.08.05 22:58:24 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2011.08.05 22:54:33 | 000,021,948 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2010.02.11 05:12:00 | 003,107,788 | ---- | C] () -- C:\WINDOWS\System32\ativva5x.dat
[2010.02.11 05:12:00 | 000,887,724 | ---- | C] () -- C:\WINDOWS\System32\ativva6x.dat
[2009.11.09 03:08:10 | 000,974,848 | ---- | C] () -- C:\WINDOWS\System32\cis-2.4.dll
[2009.11.09 03:08:10 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\issacapi_bs-2.3.dll
[2009.11.09 03:08:10 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\issacapi_pe-2.3.dll
[2009.11.09 03:08:10 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\issacapi_se-2.3.dll
[2009.04.23 23:29:16 | 000,189,051 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2008.05.26 21:22:42 | 000,016,288 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2008.05.26 21:22:40 | 000,023,334 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2008.05.26 21:22:38 | 000,015,770 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2008.05.26 20:59:42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008.05.26 20:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
[2008.04.14 04:45:40 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2006.12.30 14:57:08 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004.08.18 12:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2004.08.18 12:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004.08.18 12:00:00 | 000,471,344 | ---- | C] () -- C:\WINDOWS\System32\perfh00E.dat
[2004.08.18 12:00:00 | 000,443,588 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004.08.18 12:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004.08.18 12:00:00 | 000,264,338 | ---- | C] () -- C:\WINDOWS\System32\perfi00E.dat
[2004.08.18 12:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004.08.18 12:00:00 | 000,110,290 | ---- | C] () -- C:\WINDOWS\System32\perfc00E.dat
[2004.08.18 12:00:00 | 000,071,846 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004.08.18 12:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004.08.18 12:00:00 | 000,043,990 | ---- | C] () -- C:\WINDOWS\System32\perfd00E.dat
[2004.08.18 12:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004.08.18 12:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004.08.18 12:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
========== LOP Check ========== [2011.11.03 14:05:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\12Ghosts
[2011.11.04 09:05:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ashampoo
[2011.11.27 17:55:26 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2011.08.06 10:43:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET
[2011.11.29 13:16:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2011.08.25 10:10:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2011.08.25 10:06:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Samsung
[2011.08.08 13:22:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TreeCardGames
[2011.11.04 08:34:24 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}
[2011.11.03 14:05:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kiss Balázs\Application Data\12Ghosts
[2011.11.04 09:06:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kiss Balázs\Application Data\Ashampoo
[2011.11.27 21:19:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kiss Balázs\Application Data\AVG
[2011.08.06 09:32:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kiss Balázs\Application Data\HEXelon
[2011.08.08 13:07:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kiss Balázs\Application Data\iWin
[2011.10.01 19:15:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kiss Balázs\Application Data\JaiboGames
[2011.10.14 22:32:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kiss Balázs\Application Data\MaaTec
[2011.11.01 19:32:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kiss Balázs\Application Data\MahJong Suite
[2011.08.25 10:10:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kiss Balázs\Application Data\PC Suite
[2011.08.25 10:02:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kiss Balázs\Application Data\Samsung
[2011.11.03 14:03:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kiss Balázs\Application Data\STGU
[2011.11.29 19:47:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kiss Balázs\Application Data\uTorrent
[2011.08.06 11:58:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kiss Balázs\Application Data\Windows Desktop Search
[2011.08.07 19:08:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kiss Balázs\Application Data\Windows Search
[2011.08.06 13:10:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kiss Balázs\Application Data\Xilisoft Corporation
========== Purity Check ========== ========== Custom Scans ========== < HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >"uTorrent" = "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED -- [2011.11.29 08:46:20 | 000,730,488 | ---- | M] (BitTorrent, Inc.)
"msnmsgr" = "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background -- [2010.04.16 21:11:38 | 003,872,080 | ---- | M] (Microsoft Corporation)
"ctfmon.exe" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 04:32:14 | 000,015,360 | ---- | M] (Microsoft Corporation)
< > < MD5 for: ACPI.SYS >[2008.04.14 04:43:16 | 020,107,774 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:acpi.sys
[2008.04.14 04:03:26 | 000,188,032 | ---- | M] (Microsoft Corporation) MD5=5482FF197E59B4CA97CCB1B4740A2949 -- C:\WINDOWS\system32\drivers\acpi.sys
< MD5 for: AGP440.SYS >[2008.04.14 04:43:16 | 020,107,774 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
< MD5 for: ATAPI.SYS >[2008.04.14 04:43:16 | 020,107,774 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008.04.13 12:40:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2008.04.13 12:40:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
< MD5 for: AUTOCHK.EXE >[2008.04.14 04:32:10 | 000,605,184 | ---- | M] (Microsoft Corporation) MD5=73D5C3AA8CD7A8FEDC05A6AD6BCFE684 -- C:\cmdcons\autochk.exe
[2008.04.14 04:32:10 | 000,605,184 | ---- | M] (Microsoft Corporation) MD5=73D5C3AA8CD7A8FEDC05A6AD6BCFE684 -- C:\WINDOWS\system32\autochk.exe
< MD5 for: CDROM.SYS >[2008.04.14 04:43:16 | 020,107,774 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2008.04.13 07:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys
< MD5 for: CHANGER.SYS >[2008.04.14 04:43:16 | 020,107,774 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:Changer.sys
< MD5 for: CMD.EXE >[2008.04.14 04:32:12 | 000,393,216 | ---- | M] (Microsoft Corporation) MD5=1F3AB749140C35172A6710976C596FC2 -- C:\WINDOWS\system32\cmd.exe
< MD5 for: CRYPTSVC.DLL >[2008.04.14 04:31:50 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=13CB7FC794D005D60712FDD9F1362235 -- C:\WINDOWS\ERDNT\cache\cryptsvc.dll
[2008.04.14 04:31:50 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=13CB7FC794D005D60712FDD9F1362235 -- C:\WINDOWS\system32\cryptsvc.dll
< MD5 for: CSRSS.EXE >[2008.04.14 04:32:14 | 000,006,144 | ---- | M] (Microsoft Corporation) MD5=7A2DFF483095773CC201420FAD11862F -- C:\WINDOWS\system32\csrss.exe
< MD5 for: EVENTLOG.DLL >[2008.04.14 04:31:52 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=4BFA2DC223A814CCD1D07C6A0E26C72B -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008.04.14 04:31:52 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=4BFA2DC223A814CCD1D07C6A0E26C72B -- C:\WINDOWS\system32\eventlog.dll
< MD5 for: EXPLORER.EXE >[2008.04.14 04:32:18 | 001,035,776 | ---- | M] (Microsoft Corporation) MD5=AD3A8A9E8914439852A98CE48015E237 -- C:\WINDOWS\ERDNT\cache\explorer.exe
[2008.04.14 04:32:18 | 001,035,776 | ---- | M] (Microsoft Corporation) MD5=AD3A8A9E8914439852A98CE48015E237 -- C:\WINDOWS\explorer.exe
< MD5 for: FASTFAT.SYS >[2008.04.13 07:44:30 | 000,143,744 | ---- | M] (Microsoft Corporation) MD5=38D332A6D56AF32635675F132548343E -- C:\WINDOWS\system32\drivers\fastfat.sys
< MD5 for: HAL.DLL >[2008.04.14 04:43:16 | 020,107,774 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2008.04.13 07:01:30 | 000,131,840 | ---- | M] (Microsoft Corporation) MD5=6F61D3287A6A15A08A9433222C09D17F -- C:\WINDOWS\system32\hal.dll
< MD5 for: I8042PRT.SYS >[2008.04.14 04:43:16 | 020,107,774 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:i8042prt.sys
[2008.04.14 04:08:16 | 000,052,736 | ---- | M] (Microsoft Corporation) MD5=D7947ECF17544CED478BD969939DB349 -- C:\WINDOWS\system32\drivers\i8042prt.sys
< MD5 for: IASTOR.SYS >[2008.05.20 11:17:58 | 000,304,920 | ---- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 -- C:\WINDOWS\NLDRV\001\iastor.sys
< MD5 for: ISAPNP.SYS >[2008.04.14 04:43:16 | 020,107,774 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:isapnp.sys
[2008.04.14 04:10:22 | 000,037,504 | ---- | M] (Microsoft Corporation) MD5=3685529CAA2B14C9632E85E265BA293B -- C:\WINDOWS\system32\drivers\isapnp.sys
< MD5 for: KBDCLASS.SYS >[2008.04.14 04:43:16 | 020,107,774 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:kbdclass.sys
[2008.04.14 04:10:52 | 000,024,960 | ---- | M] (Microsoft Corporation) MD5=51D3342D1A0C19605095405352BB009B -- C:\WINDOWS\ERDNT\cache\kbdclass.sys
[2008.04.14 04:10:52 | 000,024,960 | ---- | M] (Microsoft Corporation) MD5=51D3342D1A0C19605095405352BB009B -- C:\WINDOWS\system32\drivers\kbdclass.sys
< MD5 for: LSASS.EXE >[2008.04.14 04:32:22 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=21844F6DA13ECE4737D0B7524EDEB6EC -- C:\WINDOWS\ERDNT\cache\lsass.exe
[2008.04.14 04:32:22 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=21844F6DA13ECE4737D0B7524EDEB6EC -- C:\WINDOWS\system32\lsass.exe
< MD5 for: NDIS.SYS >[2008.04.13 07:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ERDNT\cache\ndis.sys
[2008.04.13 07:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys
< MD5 for: NETLOGON.DLL >[2008.04.14 04:31:58 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=A792F49B07A36D7F64D236C45BAC4A50 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008.04.14 04:31:58 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=A792F49B07A36D7F64D236C45BAC4A50 -- C:\WINDOWS\system32\netlogon.dll
< MD5 for: NTFS.SYS >[2008.04.13 07:45:54 | 000,574,976 | ---- | M] (Microsoft Corporation) MD5=78A08DD6A8D65E697C18E1DB01C5CDCA -- C:\WINDOWS\ERDNT\cache\ntfs.sys
[2008.04.13 07:45:54 | 000,574,976 | ---- | M] (Microsoft Corporation) MD5=78A08DD6A8D65E697C18E1DB01C5CDCA -- C:\WINDOWS\system32\drivers\ntfs.sys
[2004.08.03 23:15:10 | 000,574,592 | ---- | M] (Microsoft Corporation) MD5=B78BE402C3F63DD55521F73876951CDD -- C:\cmdcons\NTFS.SYS
< MD5 for: REGEDIT.EXE >[2008.04.14 04:32:28 | 000,152,576 | ---- | M] (Microsoft Corporation) MD5=C4470EF73D046D41E64077ED2237B876 -- C:\WINDOWS\ERDNT\cache\regedit.exe
[2008.04.14 04:32:28 | 000,152,576 | ---- | M] (Microsoft Corporation) MD5=C4470EF73D046D41E64077ED2237B876 -- C:\WINDOWS\regedit.exe
< MD5 for: SCECLI.DLL >[2008.04.14 04:32:00 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=4F6A0B812BD286E97E26DF3E225ABCFB -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2008.04.14 04:32:00 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=4F6A0B812BD286E97E26DF3E225ABCFB -- C:\WINDOWS\system32\scecli.dll
< MD5 for: SERVICES.EXE >[2009.02.09 12:26:58 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=9CEDBFBE08BC1C4F35F74B8F96E0289A -- C:\WINDOWS\ERDNT\cache\services.exe
[2009.02.09 12:26:58 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=9CEDBFBE08BC1C4F35F74B8F96E0289A -- C:\WINDOWS\system32\dllcache\services.exe
[2009.02.09 12:26:58 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=9CEDBFBE08BC1C4F35F74B8F96E0289A -- C:\WINDOWS\system32\services.exe
[2009.02.09 12:19:03 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=BDEB2B3B235C8488BC7BAE94143415EF -- C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
< MD5 for: SMSS.EXE >[2008.04.14 04:32:30 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=A03C3BF7E45ECC9775D3CE653086FAA1 -- C:\WINDOWS\system32\smss.exe
[2004.08.04 00:56:58 | 000,152,576 | ---- | M] (Microsoft Corporation) MD5=DA5CF1C368B33D75602FD6B3A7F5E0C6 -- C:\cmdcons\SYSTEM32\SMSS.EXE
< MD5 for: SPOOLSV.EXE >[2010.08.17 14:19:36 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=258DD5D4283FD9F9A7166BE9AE45CE73 -- C:\WINDOWS\$hf_mig$\KB2347290\SP3QFE\spoolsv.exe
[2010.08.17 14:17:06 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=60784F891563FB1B767F70117FC2428F -- C:\WINDOWS\ERDNT\cache\spoolsv.exe
[2010.08.17 14:17:06 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=60784F891563FB1B767F70117FC2428F -- C:\WINDOWS\system32\dllcache\spoolsv.exe
[2010.08.17 14:17:06 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=60784F891563FB1B767F70117FC2428F -- C:\WINDOWS\system32\spoolsv.exe
< MD5 for: SVCHOST.EXE >[2008.04.14 04:32:32 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=05194D8A92CF7E559C1A38FC134C966A -- C:\WINDOWS\ERDNT\cache\svchost.exe
[2008.04.14 04:32:32 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=05194D8A92CF7E559C1A38FC134C966A -- C:\WINDOWS\system32\svchost.exe
< MD5 for: TCPIP.SYS >[2008.06.20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\ERDNT\cache\tcpip.sys
[2008.06.20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\drivers\tcpip.sys
[2008.06.20 12:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
< MD5 for: USER32.DLL >[2008.04.14 04:32:06 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=D6CAE3824EA12A356065C9EF10FC0EB3 -- C:\WINDOWS\ERDNT\cache\user32.dll
[2008.04.14 04:32:06 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=D6CAE3824EA12A356065C9EF10FC0EB3 -- C:\WINDOWS\system32\user32.dll
< MD5 for: USERINIT.EXE >[2008.04.14 04:32:32 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=B0DDDFC8361952B956EF9475244F40BD -- C:\WINDOWS\ERDNT\cache\userinit.exe
[2008.04.14 04:32:32 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=B0DDDFC8361952B956EF9475244F40BD -- C:\WINDOWS\system32\userinit.exe
< MD5 for: WIN32K.SYS >[2011.09.06 15:08:43 | 001,867,904 | ---- | M] (Microsoft Corporation) MD5=A04F561CF9147A8FA1AD7EAD6385EFF8 -- C:\WINDOWS\$hf_mig$\KB2567053\SP3QFE\win32k.sys
[2011.09.06 15:10:12 | 001,858,944 | ---- | M] (Microsoft Corporation) MD5=B367DCEDC10A4566184EAD0A7DE4F44C -- C:\WINDOWS\system32\dllcache\win32k.sys
[2011.09.06 15:10:12 | 001,858,944 | ---- | M] (Microsoft Corporation) MD5=B367DCEDC10A4566184EAD0A7DE4F44C -- C:\WINDOWS\system32\win32k.sys
[2011.06.06 12:36:17 | 001,867,904 | ---- | M] (Microsoft Corporation) MD5=B37B9056094E166D8B2B9138914851F8 -- C:\WINDOWS\$hf_mig$\KB2555917\SP3QFE\win32k.sys
< MD5 for: WINLOGON.EXE >[2008.04.14 04:32:34 | 000,509,952 | ---- | M] (Microsoft Corporation) MD5=15D1D956D9F01E51E6623EDB31EA43B6 -- C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008.04.14 04:32:34 | 000,509,952 | ---- | M] (Microsoft Corporation) MD5=15D1D956D9F01E51E6623EDB31EA43B6 -- C:\WINDOWS\system32\winlogon.exe
< MD5 for: WINSRV.DLL >[2011.04.26 12:02:48 | 000,293,888 | ---- | M] (Microsoft Corporation) MD5=36C76C72D61B92AA9E7AA130EE65A9B7 -- C:\WINDOWS\$hf_mig$\KB2507938\SP3QFE\winsrv.dll
[2011.06.20 18:44:52 | 000,293,888 | ---- | M] (Microsoft Corporation) MD5=86C91430E9D33D91D3150CEE2CDFDC80 -- C:\WINDOWS\system32\dllcache\winsrv.dll
[2011.06.20 18:44:52 | 000,293,888 | ---- | M] (Microsoft Corporation) MD5=86C91430E9D33D91D3150CEE2CDFDC80 -- C:\WINDOWS\system32\winsrv.dll
[2011.06.20 18:43:23 | 000,293,888 | ---- | M] (Microsoft Corporation) MD5=EC3DCEEE4ADD1FAA673365B2307EB0BE -- C:\WINDOWS\$hf_mig$\KB2567680\SP3QFE\winsrv.dll
< MD5 for: WS2_32.DLL >[2008.04.14 04:32:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=EA551E1AB5BA99DA3397517BDD278E94 -- C:\WINDOWS\ERDNT\cache\ws2_32.dll
[2008.04.14 04:32:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=EA551E1AB5BA99DA3397517BDD278E94 -- C:\WINDOWS\system32\ws2_32.dll
< > < C:\windows\system32\spool\prtprocs|dll;true;true;true /FP >[2008.07.06 13:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008.07.06 13:06:10 | 000,147,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\x64\filterpipelineprintproc.dll
< %systemroot%\system32\Spool\prtprocs\*.* /s >[2008.07.06 13:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008.07.06 11:50:03 | 000,597,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
[2008.07.06 13:06:10 | 000,147,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Spool\prtprocs\x64\filterpipelineprintproc.dll
< %systemroot%\system32\drivers\*.sys /10 > < %systemroot%\system32\drivers\*.sys /X >[2010.02.11 05:19:08 | 000,053,248 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\drivers\ati2erec.dll
[2004.08.18 12:00:00 | 003,440,660 | ---- | M] () -- C:\WINDOWS\system32\drivers\gm.dls
[2004.08.18 12:00:00 | 000,000,646 | ---- | M] () -- C:\WINDOWS\system32\drivers\gmreadme.txt
[2007.01.03 05:20:24 | 000,001,732 | R--- | M] () -- C:\WINDOWS\system32\drivers\nvphy.bin
< %systemroot%\system32\drivers\*.sys /lockedfiles >[2011.08.07 11:03:05 | 000,223,128 | ---- | M] ()
Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\dtscsi.sys
[2011.08.07 11:01:26 | 000,664,064 | ---- | M] ()
Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\sptd.sys
[2011.08.07 11:01:26 | 000,096,384 | ---- | M] ()
Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\sptd1965.sys
< %systemroot%\system32\*.* /10 >[2011.11.29 18:53:25 | 000,071,846 | ---- | M] () -- C:\WINDOWS\system32\perfc009.dat
[2011.11.29 18:53:25 | 000,110,290 | ---- | M] () -- C:\WINDOWS\system32\perfc00E.dat
[2011.11.29 18:53:25 | 000,443,588 | ---- | M] () -- C:\WINDOWS\system32\perfh009.dat
[2011.11.29 18:53:25 | 000,471,344 | ---- | M] () -- C:\WINDOWS\system32\perfh00E.dat
[2011.11.29 18:53:24 | 001,113,238 | ---- | M] () -- C:\WINDOWS\system32\PerfStringBackup.INI
[2011.11.29 18:49:33 | 000,002,206 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
< %systemroot%\system32\*.dll /lockedfiles > < %systemroot%\system32\config\*.sav >[2011.08.06 00:45:44 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2011.08.06 00:45:44 | 001,089,536 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2011.08.06 00:45:44 | 000,458,752 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\Tasks\*.job > < %systemroot%\*.* /U /s >[13 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[1 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\AuthCabs\7971f918-a847-4430-9279-4a52d1efe18d\*.tmp files -> C:\WINDOWS\SoftwareDistribution\AuthCabs\7971f918-a847-4430-9279-4a52d1efe18d\*.tmp -> ]
< %systemroot%\*. /rp /s > < %ALLUSERSPROFILE%\Data Aplikací\*.* > < %ALLUSERSPROFILE%\Data Aplikací\*.exe /s > < %ALLUSERSPROFILE%\Application Data\*. >[2011.11.03 14:05:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\12Ghosts
[2011.11.04 09:05:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ashampoo
[2011.08.06 10:46:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ATI
[2011.11.27 17:55:26 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2011.08.06 10:43:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET
[2011.08.06 12:11:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\McAfee
[2011.11.29 13:16:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2011.09.02 15:48:22 | 000,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2011.10.15 15:30:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2011.08.25 10:10:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2011.08.25 10:06:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Samsung
[2011.08.06 09:29:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sun
[2011.08.08 13:22:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TreeCardGames
[2011.08.08 13:12:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Trymedia
[2011.08.06 09:55:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2011.08.06 12:59:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WLInstaller
[2011.11.04 08:34:24 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >[2011.08.05 22:57:42 | 000,000,311 | -HS- | M] () -- C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %APPDATA%\*.* >[2011.08.25 10:05:51 | 000,002,528 | ---- | M] () -- C:\Documents and Settings\Kiss Balázs\Application Data\$_hpcst$.hpc
[2011.08.06 00:48:44 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\Kiss Balázs\Application Data\desktop.ini
< %APPDATA%\*.exe /s >[2011.10.14 22:32:33 | 000,011,694 | R--- | M] () -- C:\Documents and Settings\Kiss Balázs\Application Data\Microsoft\Installer\{07010016-0001-2010-0110-4D6161546563}\_53303AAEEB4CF964B0F9D9.exe
[2011.10.14 22:32:33 | 000,292,022 | R--- | M] () -- C:\Documents and Settings\Kiss Balázs\Application Data\Microsoft\Installer\{07010016-0001-2010-0110-4D6161546563}\_6FEFF9B68218417F98F549.exe
[2011.10.14 22:32:33 | 000,292,022 | R--- | M] () -- C:\Documents and Settings\Kiss Balázs\Application Data\Microsoft\Installer\{07010016-0001-2010-0110-4D6161546563}\_7F3A875A26B7D945CF730D.exe
[2011.09.02 15:48:21 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Kiss Balázs\Application Data\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
[2011.01.27 14:43:34 | 000,266,552 | ---- | M] (ml) -- C:\Documents and Settings\Kiss Balázs\Application Data\Samsung\Kies\UpdateTemp\MCS.Thunder.Update.exe
< %SYSTEMDRIVE%\*.exe >[2011.08.06 09:14:31 | 079,313,640 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\10-2_legacy_xp32-64_dd_ccc.exe
[2011.08.06 12:11:01 | 000,731,424 | ---- | M] (Solid State Networks) -- C:\install_flashplayer10_mssa_aih.exe
[2011.08.06 10:34:43 | 025,001,480 | ---- | M] (Microsoft Corporation) -- C:\NetFx20SP2_x86.exe
< %systemroot%\system32|bak;true;false;false /fp > < %PROGRAMFILES%|bak;true;false;false /fp > < reg query "HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager" /v BootExecute /c >No captured output from command...
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager" /v "PendingFileRenameOperations" /c >No captured output from command...
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========[C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790 -> Junction
[C:\WINDOWS\assembly\GAC_MSIL\CCC\2.0.0.0__90ba9c70f846762e] -> C:\WINDOWS\WinSxS\MSIL_CCC_90ba9c70f846762e_2.0.0.0_x-ww_c7ed2bb0 -> Junction
[C:\WINDOWS\assembly\GAC_MSIL\CLI\2.0.0.0__90ba9c70f846762e] -> C:\WINDOWS\WinSxS\MSIL_CLI_90ba9c70f846762e_2.0.0.0_x-ww_42656733 -> Junction
[C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e -> Junction
[C:\WINDOWS\assembly\GAC_MSIL\LOG\2.0.3693.42530__90ba9c70f846762e] -> C:\WINDOWS\WinSxS\MSIL_LOG_90ba9c70f846762e_2.0.3693.42530_x-ww_47e32df4 -> Junction
[C:\WINDOWS\assembly\GAC_MSIL\MOM\2.0.0.0__90ba9c70f846762e] -> C:\WINDOWS\WinSxS\MSIL_MOM_90ba9c70f846762e_2.0.0.0_x-ww_a60193a8 -> Junction
< End of report >