Nie moge usunac wirusa win32-FakeSydel-AP)Trj


(Carla01) #1

Mam niebieska strone pulpitu z ostzerzeniem o wirusach .Skanowalam komputer -mam zainstalowany program antywirusowy Alvast wykryl mi dwa wirusy -Win32-FakeSydef-AP Trj.

Win32.Crypt-IHZ Trj.Przenioslam zarazone pliki do kwaratany lecz nadal mam ostzerzenie na niebieskim tle pulpit komuptera co mam zrobic jak go usunac .Komputer moj posiada orginalna wersje windows 7.Prosze o pomoc


(Spandau) #2

Pobierz Malwarebytes http://www.dobreprogramy.pl/Malwarebyte ... 13117.html Wykonaj pełne skanowanie Usuń co znajdzie podaj log na forum

Następnie podaj logi OTL instrukcja otl-gmer-rsit-dss-inne-instrukcje-t370405.html


(Carla01) #3

Malwarebytes' Anti-Malware 1.50.1.1100

Wersja bazy: 5639

Windows 6.1.7600

Internet Explorer 8.0.7600.16385

30-1-2011 14:45:06

mbam-log-2011-01-30 (14-45-06).txt

Typ skanowania: Pe³ne skanowanie (C:\|)

Przeskanowano obiektów: 250629

Up³ynê³o: 14 minut(y), 13 sekund(y)

Zainfekowanych procesów w pamiêci: 0

Zainfekowanych modu³ów w pamiêci: 0

Zainfekowanych kluczy rejestru: 0

Zainfekowanych wartoœci rejestru: 1

Zainfekowane informacje rejestru systemowego: 0

Zainfekowanych folderów: 0

Zainfekowanych plików: 0

Zainfekowanych procesów w pamiêci:

(Nie znaleziono zagro¿eñ)

Zainfekowanych modu³ów w pamiêci:

(Nie znaleziono zagro¿eñ)

Zainfekowanych kluczy rejestru:

(Nie znaleziono zagro¿eñ)

Zainfekowanych wartoœci rejestru:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\hAmMfLg01804 (Rogue.SystemTool.M) -> Value: hAmMfLg01804 -> Quarantined and deleted successfully.

Zainfekowane informacje rejestru systemowego:

(Nie znaleziono zagro¿eñ)

Zainfekowanych folderów:

(Nie znaleziono zagro¿eñ)

Zainfekowanych plików:

(Nie znaleziono zagro¿eñ)


(Spandau) #4

Czekamy na logi OTL


(Carla01) #5

OTL logfile created on: 1/30/2011 2:49:19 PM - Run 1

OTL by OldTimer - Version 3.2.20.6 Folder = C:\Users\Serge\Downloads

64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.7600.16385)

Locale: 00000409 | Country: Nederland | Language: NLD | Date Format: d-M-yyyy

3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 42.00% Memory free

6.00 Gb Paging File | 4.00 Gb Available in Paging File | 70.00% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

Drive C: | 451.66 Gb Total Space | 422.29 Gb Free Space | 93.50% Space Free | Partition Type: NTFS

Computer Name: SERGE-PC | User Name: Serge | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/01/30 14:47:38 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Users\Serge\Downloads\OTL.exe

PRC - [2011/01/13 09:47:34 | 003,396,624 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe

PRC - [2011/01/13 09:47:33 | 000,040,384 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe

PRC - [2011/01/06 21:22:14 | 000,304,304 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe

PRC - [2010/12/20 18:08:46 | 000,963,976 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe

PRC - [2010/08/19 04:25:22 | 000,039,408 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

PRC - [2010/01/29 00:27:36 | 000,243,232 | ---- | M] (Acer Group) -- C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe

PRC - [2009/08/28 10:38:58 | 001,150,496 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\eMachines\Registration\GregHSRW.exe

PRC - [2009/07/18 04:12:12 | 000,257,440 | R--- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10c.exe

========== Modules (SafeList) ==========

MOD - [2011/01/30 14:47:38 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Users\Serge\Downloads\OTL.exe

MOD - [2011/01/28 16:58:06 | 000,189,728 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\snxhk.dll

MOD - [2010/08/21 06:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll

========== Win32 Services (SafeList) ==========

SRV: 64bit: - [2011/01/13 09:47:33 | 000,040,384 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)

SRV: 64bit: - [2010/01/29 00:27:36 | 000,243,232 | ---- | M] (Acer Group) [Auto | Running] -- C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe -- (Updater Service)

SRV: 64bit: - [2009/07/14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)

SRV - [2010/04/04 00:01:24 | 000,246,520 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\eMachines Games\eMachines Game Console\GameConsoleService.exe -- (GameConsoleService)

SRV - [2010/01/15 22:08:38 | 000,935,208 | ---- | M] (Nero AG) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)

SRV - [2009/08/28 10:38:58 | 001,150,496 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\eMachines\Registration\GregHSRW.exe -- (Greg_Service)

SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)

========== Driver Services (SafeList) ==========

DRV: 64bit: - [2011/01/13 09:37:23 | 000,062,032 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)

DRV: 64bit: - [2009/09/23 05:23:02 | 006,180,832 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)

DRV: 64bit: - [2009/07/14 02:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)

DRV: 64bit: - [2009/07/14 02:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)

DRV: 64bit: - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)

DRV: 64bit: - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)

DRV: 64bit: - [2009/07/14 02:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)

DRV: 64bit: - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)

DRV: 64bit: - 2009/06/10 21:38:56 | 000,000,308 | ---- | M [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)

DRV: 64bit: - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)

DRV: 64bit: - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)

DRV: 64bit: - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)

DRV: 64bit: - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)

DRV: 64bit: - 2009/05/22 15:52:30 | 000,215,040 | ---- | M [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE: 64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx? ... 5r47j1t38n

IE: 64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.emachines.com/rdr.aspx? ... 5r47j1t38n

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx? ... 5r47j1t38n

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.emachines.com/rdr.aspx? ... 5r47j1t38n

IE - HKLM..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - File not found

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx? ... 5r47j1t38n

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.emachines.com/rdr.aspx? ... 5r47j1t38n

IE - HKCU..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - File not found

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

O1 HOSTS File: ([2009/06/10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts

O2: 64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)

O2: 64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg64.dll (Google Inc.)

O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - File not found

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.

O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)

O3: 64bit: - HKLM..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)

O3: 64bit: - HKLM..\Toolbar: (no name) - Locked - No CLSID value found.

O3 - HKLM..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O3 - HKLM..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - File not found

O3 - HKLM..\Toolbar: (no name) - Locked - No CLSID value found.

O3: 64bit: - HKCU..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)

O3 - HKCU..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O3 - HKCU..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - File not found

O4: 64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)

O4: 64bit: - HKLM..\Run: [igfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)

O4: 64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)

O4: 64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)

O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)

O4 - HKLM..\Run: [Hotkey Utility] C:\Program Files (x86)\eMachines\Hotkey Utility\HotkeyUtility.exe ()

O4 - HKLM..\Run: [WinampAgent] C:\Program Files (x86)\Winamp\winampa.exe (Nullsoft, Inc.)

O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)

O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3

O8: 64bit: - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()

O8: 64bit: - Extra context menu item: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll (Google Inc.)

O8 - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()

O8 - Extra context menu item: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll (Google Inc.)

O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O13 - gopher Prefix: missing

O13 - gopher Prefix: missing

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1

O18: 64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found

O18: 64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found

O18: 64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found

O18: 64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found

O18: 64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found

O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)

O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O20: 64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)

O20: 64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)

O20: 64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found

O20: 64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)

O21: 64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.

O32 - HKLM CDRom: AutoRun - 1

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35: 64bit: - HKLM..comfile [open] -- "%1" %*

O35: 64bit: - HKLM..exefile [open] -- "%1" %*

O35 - HKLM..comfile [open] -- "%1" %*

O35 - HKLM..exefile [open] -- "%1" %*

O37: 64bit: - HKLM...com [@ = comfile] -- "%1" %*

O37: 64bit: - HKLM...exe [@ = exefile] -- "%1" %*

O37 - HKLM...com [@ = comfile] -- "%1" %*

O37 - HKLM...exe [@ = exefile] -- "%1" %*

SafeBootMin: 64bit: AppMgmt - Service

SafeBootMin: 64bit: Base - Driver Group

SafeBootMin: 64bit: Boot Bus Extender - Driver Group

SafeBootMin: 64bit: Boot file system - Driver Group

SafeBootMin: 64bit: File system - Driver Group

SafeBootMin: 64bit: Filter - Driver Group

SafeBootMin: 64bit: HelpSvc - Service

SafeBootMin: 64bit: PCI Configuration - Driver Group

SafeBootMin: 64bit: PNP Filter - Driver Group

SafeBootMin: 64bit: Primary disk - Driver Group

SafeBootMin: 64bit: sacsvr - Service

SafeBootMin: 64bit: SCSI Class - Driver Group

SafeBootMin: 64bit: System Bus Extender - Driver Group

SafeBootMin: 64bit: vmms - Service

SafeBootMin: 64bit: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)

SafeBootMin: 64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers

SafeBootMin: 64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive

SafeBootMin: 64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive

SafeBootMin: 64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller

SafeBootMin: 64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc

SafeBootMin: 64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard

SafeBootMin: 64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse

SafeBootMin: 64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters

SafeBootMin: 64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter

SafeBootMin: 64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System

SafeBootMin: 64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive

SafeBootMin: 64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy

SafeBootMin: 64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers

SafeBootMin: 64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume

SafeBootMin: 64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

SafeBootMin: 64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices

SafeBootMin: 64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

SafeBootMin: AppMgmt - Service

SafeBootMin: Base - Driver Group

SafeBootMin: Boot Bus Extender - Driver Group

SafeBootMin: Boot file system - Driver Group

SafeBootMin: File system - Driver Group

SafeBootMin: Filter - Driver Group

SafeBootMin: HelpSvc - Service

SafeBootMin: PCI Configuration - Driver Group

SafeBootMin: PNP Filter - Driver Group

SafeBootMin: Primary disk - Driver Group

SafeBootMin: sacsvr - Service

SafeBootMin: SCSI Class - Driver Group

SafeBootMin: System Bus Extender - Driver Group

SafeBootMin: vmms - Service

SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers

SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive

SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive

SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller

SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc

SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard

SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse

SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters

SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter

SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System

SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive

SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy

SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers

SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume

SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices

SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

SafeBootNet: 64bit: AppMgmt - Service

SafeBootNet: 64bit: Base - Driver Group

SafeBootNet: 64bit: Boot Bus Extender - Driver Group

SafeBootNet: 64bit: Boot file system - Driver Group

SafeBootNet: 64bit: File system - Driver Group

SafeBootNet: 64bit: Filter - Driver Group

SafeBootNet: 64bit: HelpSvc - Service

SafeBootNet: 64bit: Messenger - Service

SafeBootNet: 64bit: NDIS Wrapper - Driver Group

SafeBootNet: 64bit: NetBIOSGroup - Driver Group

SafeBootNet: 64bit: NetDDEGroup - Driver Group

SafeBootNet: 64bit: Network - Driver Group

SafeBootNet: 64bit: NetworkProvider - Driver Group

SafeBootNet: 64bit: PCI Configuration - Driver Group

SafeBootNet: 64bit: PNP Filter - Driver Group

SafeBootNet: 64bit: PNP_TDI - Driver Group

SafeBootNet: 64bit: Primary disk - Driver Group

SafeBootNet: 64bit: rdsessmgr - Service

SafeBootNet: 64bit: sacsvr - Service

SafeBootNet: 64bit: SCSI Class - Driver Group

SafeBootNet: 64bit: Streams Drivers - Driver Group

SafeBootNet: 64bit: System Bus Extender - Driver Group

SafeBootNet: 64bit: TDI - Driver Group

SafeBootNet: 64bit: vmms - Service

SafeBootNet: 64bit: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)

SafeBootNet: 64bit: WudfUsbccidDriver - Driver

SafeBootNet: 64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers

SafeBootNet: 64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive

SafeBootNet: 64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive

SafeBootNet: 64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller

SafeBootNet: 64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc

SafeBootNet: 64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard

SafeBootNet: 64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse

SafeBootNet: 64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net

SafeBootNet: 64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient

SafeBootNet: 64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService

SafeBootNet: 64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans

SafeBootNet: 64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters

SafeBootNet: 64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter

SafeBootNet: 64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System

SafeBootNet: 64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive

SafeBootNet: 64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers

SafeBootNet: 64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy

SafeBootNet: 64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers

SafeBootNet: 64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume

SafeBootNet: 64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

SafeBootNet: 64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices

SafeBootNet: 64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

SafeBootNet: AppMgmt - Service

SafeBootNet: Base - Driver Group

SafeBootNet: Boot Bus Extender - Driver Group

SafeBootNet: Boot file system - Driver Group

SafeBootNet: File system - Driver Group

SafeBootNet: Filter - Driver Group

SafeBootNet: HelpSvc - Service

SafeBootNet: Messenger - Service

SafeBootNet: NDIS Wrapper - Driver Group

SafeBootNet: NetBIOSGroup - Driver Group

SafeBootNet: NetDDEGroup - Driver Group

SafeBootNet: Network - Driver Group

SafeBootNet: NetworkProvider - Driver Group

SafeBootNet: PCI Configuration - Driver Group

SafeBootNet: PNP Filter - Driver Group

SafeBootNet: PNP_TDI - Driver Group

SafeBootNet: Primary disk - Driver Group

SafeBootNet: rdsessmgr - Service

SafeBootNet: sacsvr - Service

SafeBootNet: SCSI Class - Driver Group

SafeBootNet: Streams Drivers - Driver Group

SafeBootNet: System Bus Extender - Driver Group

SafeBootNet: TDI - Driver Group

SafeBootNet: vmms - Service

SafeBootNet: WudfUsbccidDriver - Driver

SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers

SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive

SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive

SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller

SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc

SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard

SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse

SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net

SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient

SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService

SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans

SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters

SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter

SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System

SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive

SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers

SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy

SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers

SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume

SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices

SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

========== Files/Folders - Created Within 30 Days ==========

[2011/01/30 14:11:11 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Roaming\Malwarebytes

[2011/01/30 14:11:06 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys

[2011/01/30 14:11:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware

[2011/01/30 14:11:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes

[2011/01/30 14:11:03 | 000,024,152 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys

[2011/01/30 14:11:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware

[2011/01/30 13:25:46 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Local\Adobe

[2011/01/30 13:01:41 | 037,403,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MRT.exe

[2011/01/28 16:08:05 | 000,000,000 | ---D | C] -- C:\ProgramData\hAmMfLg01804

[2011/01/13 17:32:50 | 004,068,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mf.dll

[2011/01/13 17:32:50 | 001,888,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVDECOD.DLL

[2011/01/13 17:32:50 | 001,837,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10warp.dll

[2011/01/13 17:32:50 | 001,540,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll

[2011/01/13 17:32:50 | 001,170,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d10warp.dll

[2011/01/13 17:32:50 | 000,902,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d2d1.dll

[2011/01/13 17:32:50 | 000,739,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d2d1.dll

[2011/01/13 17:32:49 | 003,181,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mf.dll

[2011/01/13 17:32:49 | 001,863,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ExplorerFrame.dll

[2011/01/13 17:32:49 | 001,074,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DWrite.dll

[2011/01/13 17:32:49 | 000,662,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsPrint.dll

[2011/01/13 17:32:49 | 000,470,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsGdiConverter.dll

[2011/01/13 17:32:49 | 000,442,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsPrint.dll

[2011/01/13 17:32:49 | 000,320,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1core.dll

[2011/01/13 17:32:49 | 000,283,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsGdiConverter.dll

[2011/01/13 17:32:48 | 001,619,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVDECOD.DLL

[2011/01/13 17:32:48 | 001,495,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ExplorerFrame.dll

[2011/01/13 17:32:48 | 000,258,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dxgmms1.sys

[2011/01/13 17:32:48 | 000,257,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfreadwrite.dll

[2011/01/13 17:32:48 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsRasterService.dll

[2011/01/13 17:32:48 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d10_1core.dll

[2011/01/13 17:32:48 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfps.dll

[2011/01/13 17:32:48 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1.dll

[2011/01/13 17:32:48 | 000,196,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfreadwrite.dll

[2011/01/13 17:32:48 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d10_1.dll

[2011/01/13 17:32:48 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdd.dll

[2011/01/13 17:32:48 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsRasterService.dll

[2011/01/13 17:32:44 | 000,720,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbc32.dll

[2011/01/13 17:32:44 | 000,573,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbc32.dll

[2011/01/11 15:47:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner

[2011/01/11 15:47:30 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner

[2011/01/11 15:44:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VS Revo Group

[2011/01/11 15:44:24 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller

[2011/01/11 15:39:30 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Local\Winamp Toolbar

[2011/01/11 15:39:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winamp

[2011/01/11 15:39:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Winamp Toolbar

[2011/01/11 15:39:10 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Roaming\Winamp

[2011/01/10 20:03:01 | 000,000,000 | ---D | C] -- C:\ProgramData\eDoCl01804

[2011/01/08 15:02:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0

[2011/01/08 14:57:13 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Wat

[2011/01/08 14:57:13 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Wat

[2011/01/07 21:14:37 | 001,942,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dfshim.dll

[2011/01/07 21:14:37 | 001,130,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dfshim.dll

[2011/01/07 21:14:37 | 000,320,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PresentationHost.exe

[2011/01/07 21:14:37 | 000,295,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PresentationHost.exe

[2011/01/07 21:14:37 | 000,109,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PresentationHostProxy.dll

[2011/01/07 21:14:37 | 000,099,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PresentationHostProxy.dll

[2011/01/07 21:14:37 | 000,049,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netfxperf.dll

[2011/01/07 21:14:37 | 000,048,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netfxperf.dll

[2011/01/07 21:14:26 | 000,294,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\browserchoice.exe

[2011/01/07 21:13:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight

[2011/01/07 16:40:22 | 000,148,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\t2embed.dll

[2011/01/07 16:40:22 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\t2embed.dll

[2011/01/07 16:40:21 | 001,736,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll

[2011/01/07 16:40:18 | 002,085,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ole32.dll

[2011/01/07 16:40:17 | 001,169,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\taskschd.dll

[2011/01/07 16:40:17 | 000,524,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmicmiplugin.dll

[2011/01/07 16:40:17 | 000,496,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\taskschd.dll

[2011/01/07 16:40:17 | 000,473,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\taskcomp.dll

[2011/01/07 16:40:17 | 000,464,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\taskeng.exe

[2011/01/07 16:40:17 | 000,305,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\taskcomp.dll

[2011/01/07 16:40:17 | 000,285,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\schtasks.exe

[2011/01/07 16:40:17 | 000,179,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\schtasks.exe

[2011/01/07 16:40:16 | 000,483,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\StructuredQuery.dll

[2011/01/07 16:40:15 | 000,367,104 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysNative\atmfd.dll

[2011/01/07 16:40:15 | 000,294,400 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\atmfd.dll

[2011/01/07 16:40:15 | 000,046,080 | ---- | C] (Adobe Systems) -- C:\Windows\SysNative\atmlib.dll

[2011/01/07 16:40:15 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\SysWow64\atmlib.dll

[2011/01/07 16:40:06 | 000,961,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CPFilters.dll

[2011/01/07 16:40:06 | 000,641,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CPFilters.dll

[2011/01/07 16:40:05 | 000,552,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdri.dll

[2011/01/07 16:40:05 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSNP.ax

[2011/01/07 16:40:05 | 000,258,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mpg2splt.ax

[2011/01/07 16:40:05 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSNP.ax

[2011/01/07 16:40:05 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mpg2splt.ax

[2011/01/07 16:40:02 | 000,633,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\comctl32.dll

[2011/01/07 16:39:58 | 000,861,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleaut32.dll

[2011/01/07 16:39:57 | 005,507,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe

[2011/01/07 16:39:57 | 003,955,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe

[2011/01/07 16:39:56 | 003,899,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe

[2011/01/07 16:39:54 | 000,052,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rtutils.dll

[2011/01/07 16:39:54 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rtutils.dll

[2011/01/07 16:39:50 | 000,395,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\webio.dll

[2011/01/07 16:39:50 | 000,314,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\webio.dll

[2011/01/07 16:39:49 | 000,082,944 | ---- | C] (Radius Inc.) -- C:\Windows\SysWow64\iccvid.dll

[2011/01/07 16:39:44 | 001,024,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmpmde.dll

[2011/01/07 16:39:44 | 000,738,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmpmde.dll

[2011/01/07 16:39:37 | 000,027,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\Diskdump.sys

[2011/01/07 16:39:36 | 000,954,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfc40.dll

[2011/01/07 16:39:36 | 000,954,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfc40u.dll

[2011/01/07 16:39:35 | 014,627,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmp.dll

[2011/01/07 16:39:34 | 011,406,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmp.dll

[2011/01/07 16:39:33 | 012,625,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmploc.DLL

[2011/01/07 16:39:33 | 012,625,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmploc.DLL

[2011/01/07 16:39:32 | 000,112,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\consent.exe

[2011/01/07 16:39:31 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sscore.dll

[2011/01/07 16:39:27 | 000,703,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll

[2011/01/07 16:39:26 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeeds.dll

[2011/01/07 16:39:26 | 000,256,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll

[2011/01/07 16:39:26 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll

[2011/01/07 16:39:26 | 000,097,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll

[2011/01/07 16:39:26 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll

[2011/01/07 16:39:26 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll

[2011/01/07 16:39:25 | 000,482,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec

[2011/01/07 16:39:25 | 000,386,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec

[2011/01/07 16:39:25 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll

[2011/01/07 16:39:25 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll

[2011/01/07 16:39:25 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll

[2011/01/07 16:39:25 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe

[2011/01/07 16:39:25 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe

[2011/01/06 22:33:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Winamp

[2011/01/06 21:44:35 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Roaming\skypePM

[2011/01/06 21:43:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype

[2011/01/06 21:43:05 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype

[2011/01/06 21:43:01 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Roaming\Skype

[2011/01/06 21:42:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype

[2011/01/06 20:43:53 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Local\Diagnostics

[2011/01/06 20:41:56 | 000,273,488 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys

[2011/01/06 20:41:56 | 000,020,560 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys

[2011/01/06 20:41:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus

[2011/01/06 20:41:54 | 000,051,792 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys

[2011/01/06 20:41:54 | 000,029,264 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr.sys

[2011/01/06 20:41:53 | 000,062,032 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys

[2011/01/06 20:41:52 | 000,237,168 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe

[2011/01/06 20:41:41 | 000,038,848 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr

[2011/01/06 20:41:40 | 000,188,216 | ---- | C] (AVAST Software) -- C:\Windows\SysWow64\aswBoot.exe

[2011/01/06 20:41:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Alwil Software

[2011/01/06 20:41:38 | 000,000,000 | ---D | C] -- C:\Program Files\Alwil Software

[2011/01/06 20:27:37 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Roaming\Adobe

[2011/01/06 20:27:34 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Roaming\Google

[2011/01/06 20:27:34 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Local\Google

[2011/01/06 20:23:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eMachines Documentation

[2011/01/06 20:23:45 | 000,000,000 | ---D | C] -- C:\book

[2011/01/06 20:22:40 | 004,398,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_32.dll

[2011/01/06 20:22:40 | 003,426,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_32.dll

[2011/01/06 20:22:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition

[2011/01/06 20:21:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft

[2011/01/06 20:21:27 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\microsoft

[2011/01/06 20:21:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Live SkyDrive

[2011/01/06 20:21:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live

[2011/01/06 20:20:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Live

[2011/01/06 20:20:34 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH

[2011/01/06 20:18:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Windows Live

[2011/01/06 20:18:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office

[2011/01/06 20:14:06 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Roaming\OEM

[2011/01/06 20:14:04 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Roaming\Macromedia

[2011/01/06 20:13:57 | 000,000,000 | R--D | C] -- C:\Users\Serge\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

[2011/01/06 20:13:57 | 000,000,000 | R--D | C] -- C:\Users\Serge\Searches

[2011/01/06 20:13:57 | 000,000,000 | R--D | C] -- C:\Users\Serge\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools

[2011/01/06 20:13:57 | 000,000,000 | -H-D | C] -- C:\Users\Serge\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned

[2011/01/06 20:13:49 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Roaming\Identities

[2011/01/06 20:13:48 | 000,000,000 | R--D | C] -- C:\Users\Serge\Contacts

[2011/01/06 20:13:46 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Local\VirtualStore

[2011/01/06 20:07:19 | 000,000,000 | ---D | C] -- C:\Program Files\eMachines Accessory Store

[2011/01/06 20:07:04 | 000,000,000 | --SD | C] -- C:\Users\Serge\AppData\Roaming\Microsoft

[2011/01/06 20:07:04 | 000,000,000 | R--D | C] -- C:\Users\Serge\Videos

[2011/01/06 20:07:04 | 000,000,000 | R--D | C] -- C:\Users\Serge\Saved Games

[2011/01/06 20:07:04 | 000,000,000 | R--D | C] -- C:\Users\Serge\Pictures

[2011/01/06 20:07:04 | 000,000,000 | R--D | C] -- C:\Users\Serge\Music

[2011/01/06 20:07:04 | 000,000,000 | R--D | C] -- C:\Users\Serge\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance

[2011/01/06 20:07:04 | 000,000,000 | R--D | C] -- C:\Users\Serge\Links

[2011/01/06 20:07:04 | 000,000,000 | R--D | C] -- C:\Users\Serge\Favorites

[2011/01/06 20:07:04 | 000,000,000 | R--D | C] -- C:\Users\Serge\Downloads

[2011/01/06 20:07:04 | 000,000,000 | R--D | C] -- C:\Users\Serge\Documents

[2011/01/06 20:07:04 | 000,000,000 | R--D | C] -- C:\Users\Serge\Desktop

[2011/01/06 20:07:04 | 000,000,000 | R--D | C] -- C:\Users\Serge\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories

[2011/01/06 20:07:04 | 000,000,000 | -HSD | C] -- C:\Users\Serge\AppData\Local\Temporary Internet Files

[2011/01/06 20:07:04 | 000,000,000 | -HSD | C] -- C:\Users\Serge\Sjablonen

[2011/01/06 20:07:04 | 000,000,000 | -HSD | C] -- C:\Users\Serge\SendTo

[2011/01/06 20:07:04 | 000,000,000 | -HSD | C] -- C:\Users\Serge\Recent

[2011/01/06 20:07:04 | 000,000,000 | -HSD | C] -- C:\Users\Serge\Netwerkprinteromgeving

[2011/01/06 20:07:04 | 000,000,000 | -HSD | C] -- C:\Users\Serge\NetHood

[2011/01/06 20:07:04 | 000,000,000 | -HSD | C] -- C:\Users\Serge\Documents\Mijn video's

[2011/01/06 20:07:04 | 000,000,000 | -HSD | C] -- C:\Users\Serge\Documents\Mijn muziek

[2011/01/06 20:07:04 | 000,000,000 | -HSD | C] -- C:\Users\Serge\Mijn documenten

[2011/01/06 20:07:04 | 000,000,000 | -HSD | C] -- C:\Users\Serge\Documents\Mijn afbeeldingen

[2011/01/06 20:07:04 | 000,000,000 | -HSD | C] -- C:\Users\Serge\Menu Start

[2011/01/06 20:07:04 | 000,000,000 | -HSD | C] -- C:\Users\Serge\Local Settings

[2011/01/06 20:07:04 | 000,000,000 | -HSD | C] -- C:\Users\Serge\AppData\Local\Geschiedenis

[2011/01/06 20:07:04 | 000,000,000 | -HSD | C] -- C:\Users\Serge\Cookies

[2011/01/06 20:07:04 | 000,000,000 | -HSD | C] -- C:\Users\Serge\Application Data

[2011/01/06 20:07:04 | 000,000,000 | -HSD | C] -- C:\Users\Serge\AppData\Local\Application Data

[2011/01/06 20:07:04 | 000,000,000 | -H-D | C] -- C:\Users\Serge\AppData

[2011/01/06 20:07:04 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Local\Temp

[2011/01/06 20:07:04 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Local\Microsoft

[2011/01/06 20:07:04 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Roaming\Media Center Programs

[2011/01/06 20:05:21 | 000,000,000 | -HSD | C] -- C:\Recovery

========== Files - Modified Within 30 Days ==========

2011/01/30 14:47:00 | 000,001,052 | ---- | M -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

2011/01/30 14:11:06 | 000,001,122 | ---- | M -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk

2011/01/30 12:01:11 | 000,009,696 | -H-- | M -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

2011/01/30 12:01:11 | 000,009,696 | -H-- | M -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

2011/01/30 11:58:46 | 001,523,502 | ---- | M -- C:\Windows\SysNative\PerfStringBackup.INI

2011/01/30 11:58:46 | 000,691,490 | ---- | M -- C:\Windows\SysNative\perfh013.dat

2011/01/30 11:58:46 | 000,606,992 | ---- | M -- C:\Windows\SysNative\perfh009.dat

2011/01/30 11:58:46 | 000,130,026 | ---- | M -- C:\Windows\SysNative\perfc013.dat

2011/01/30 11:58:46 | 000,103,370 | ---- | M -- C:\Windows\SysNative\perfc009.dat

2011/01/30 11:54:12 | 000,001,048 | ---- | M -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job

2011/01/30 11:53:28 | 000,067,584 | --S- | M -- C:\Windows\bootstat.dat

2011/01/30 11:53:22 | 2408,243,200 | -HS- | M -- C:\hiberfil.sys

2011/01/28 16:28:56 | 000,000,000 | ---- | M -- C:\Windows\SysWow64\config.nt

[2011/01/13 09:47:32 | 000,188,216 | ---- | M] (AVAST Software) -- C:\Windows\SysWow64\aswBoot.exe

[2011/01/13 09:47:23 | 000,237,168 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe

[2011/01/13 09:41:44 | 000,273,488 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys

[2011/01/13 09:40:20 | 000,051,792 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys

[2011/01/13 09:37:34 | 000,029,264 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr.sys

[2011/01/13 09:37:23 | 000,062,032 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys

[2011/01/13 09:37:12 | 000,020,560 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys

2011/01/11 15:47:31 | 000,000,831 | ---- | M -- C:\Users\Public\Desktop\CCleaner.lnk

2011/01/11 15:44:24 | 000,001,277 | ---- | M -- C:\Users\Serge\Desktop\Revo Uninstaller.lnk

2011/01/11 15:39:23 | 000,001,016 | ---- | M -- C:\Users\Serge\Application Data\Microsoft\Internet Explorer\Quick Launch\Winamp.lnk

2011/01/11 15:24:18 | 000,000,223 | ---- | M -- C:\Users\Serge\Desktop\Home - Windows Live.url

2011/01/11 15:13:57 | 000,000,911 | ---- | M -- C:\Users\Serge\Desktop\Contactpersonen - Snelkoppeling.lnk

2011/01/11 15:13:38 | 000,000,918 | ---- | M -- C:\Users\Serge\Desktop\Mijn documenten - Snelkoppeling.lnk

2011/01/08 14:59:19 | 000,001,763 | ---- | M -- C:\Users\Public\Desktop\Internetbrowser selecteren.lnk

2011/01/08 14:58:27 | 000,274,552 | ---- | M -- C:\Windows\SysNative\FNTCACHE.DAT

2011/01/06 22:27:28 | 000,000,189 | ---- | M -- C:\Users\Serge\Desktop\Marktplaats - De plek om Nieuwe en Tweedehands spullen te kopen en verkopen.url

2011/01/06 22:10:22 | 000,000,190 | ---- | M -- C:\Users\Serge\Desktop\iGoogle.url

2011/01/06 21:44:51 | 000,000,056 | -H-- | M -- C:\ProgramData\ezsidmv.dat

2011/01/06 21:44:29 | 000,002,252 | ---- | M -- C:\Users\Serge\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk

2011/01/06 21:43:07 | 000,002,517 | ---- | M -- C:\Users\Public\Desktop\Skype.lnk

2011/01/06 20:41:56 | 000,001,861 | ---- | M -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk

2011/01/06 20:37:37 | 000,000,163 | ---- | M -- C:\Users\Serge\Desktop\Onet.pl - Polski Portal Internetowy.url

2011/01/06 20:36:52 | 000,000,168 | ---- | M -- C:\Users\Serge\Desktop\Portal INTERIA.PL - więcej niż się spodziewasz!.url

2011/01/06 20:27:29 | 000,001,462 | ---- | M -- C:\Users\Serge\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk

2011/01/06 20:22:24 | 000,000,020 | ---- | M -- C:\Windows\Tú­

2011/01/06 20:07:19 | 000,002,042 | ---- | M -- C:\Users\Public\Desktop\eMachines Accessoires.lnk

2011/01/06 20:02:50 | 000,046,406 | ---- | M -- C:\Windows\SysWow64\license.rtf

2011/01/06 20:02:50 | 000,046,406 | ---- | M -- C:\Windows\SysNative\license.rtf

[2011/01/04 17:20:14 | 037,403,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\MRT.exe

[2010/12/31 21:06:36 | 000,038,848 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr

========== Files Created - No Company Name ==========

2011/01/30 14:11:06 | 000,001,122 | ---- | C -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk

2011/01/11 15:47:31 | 000,000,831 | ---- | C -- C:\Users\Public\Desktop\CCleaner.lnk

2011/01/11 15:44:24 | 000,001,277 | ---- | C -- C:\Users\Serge\Desktop\Revo Uninstaller.lnk

2011/01/11 15:39:23 | 000,001,016 | ---- | C -- C:\Users\Serge\Application Data\Microsoft\Internet Explorer\Quick Launch\Winamp.lnk

2011/01/11 15:24:18 | 000,000,223 | ---- | C -- C:\Users\Serge\Desktop\Home - Windows Live.url

2011/01/11 15:13:57 | 000,000,911 | ---- | C -- C:\Users\Serge\Desktop\Contactpersonen - Snelkoppeling.lnk

2011/01/11 15:13:38 | 000,000,918 | ---- | C -- C:\Users\Serge\Desktop\Mijn documenten - Snelkoppeling.lnk

2011/01/08 14:59:19 | 000,001,763 | ---- | C -- C:\Users\Public\Desktop\Internetbrowser selecteren.lnk

2011/01/06 22:27:28 | 000,000,189 | ---- | C -- C:\Users\Serge\Desktop\Marktplaats - De plek om Nieuwe en Tweedehands spullen te kopen en verkopen.url

2011/01/06 22:10:22 | 000,000,190 | ---- | C -- C:\Users\Serge\Desktop\iGoogle.url

2011/01/06 21:44:51 | 000,000,056 | -H-- | C -- C:\ProgramData\ezsidmv.dat

2011/01/06 21:44:29 | 000,002,252 | ---- | C -- C:\Users\Serge\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk

2011/01/06 21:43:07 | 000,002,517 | ---- | C -- C:\Users\Public\Desktop\Skype.lnk

2011/01/06 20:42:56 | 000,001,052 | ---- | C -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

2011/01/06 20:42:56 | 000,001,048 | ---- | C -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job

2011/01/06 20:41:56 | 000,001,861 | ---- | C -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk

2011/01/06 20:41:52 | 000,000,000 | ---- | C -- C:\Windows\SysWow64\config.nt

2011/01/06 20:37:37 | 000,000,163 | ---- | C -- C:\Users\Serge\Desktop\Onet.pl - Polski Portal Internetowy.url

2011/01/06 20:36:52 | 000,000,168 | ---- | C -- C:\Users\Serge\Desktop\Portal INTERIA.PL - więcej niż się spodziewasz!.url

2011/01/06 20:27:29 | 000,001,462 | ---- | C -- C:\Users\Serge\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk

2011/01/06 20:22:24 | 000,000,020 | ---- | C -- C:\Windows\Tú­

2011/01/06 20:18:05 | 000,002,435 | ---- | C -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2010.lnk

2011/01/06 20:14:01 | 000,001,434 | ---- | C -- C:\Users\Serge\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk

2011/01/06 20:13:57 | 000,001,468 | ---- | C -- C:\Users\Serge\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk

2011/01/06 20:07:19 | 000,002,042 | ---- | C -- C:\Users\Public\Desktop\eMachines Accessoires.lnk

2011/01/06 20:07:04 | 000,000,290 | ---- | C -- C:\Users\Serge\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk

2011/01/06 20:07:04 | 000,000,272 | ---- | C -- C:\Users\Serge\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk

2009/07/14 00:42:10 | 000,064,000 | ---- | C -- C:\Windows\SysWow64\BWContextHandler.dll

2009/07/13 22:03:59 | 000,364,544 | ---- | C -- C:\Windows\SysWow64\msjetoledb40.dll

========== Custom Scans ==========

< %systemdrive%*.* >

2010/08/19 05:00:36 | 000,008,192 | RHS- | M -- C:\BOOTSECT.BAK

2011/01/30 11:53:22 | 2408,243,200 | -HS- | M -- C:\hiberfil.sys

2011/01/30 11:53:25 | 3210,993,664 | -HS- | M -- C:\pagefile.sys

2010/08/19 04:13:19 | 000,002,188 | ---- | M -- C:\RHDSetup.log

2011/01/30 13:28:53 | 000,057,404 | ---- | M -- C:\TDSSKiller.2.4.15.0_30.01.2011_13.28.22_log.txt

< MD5 for: AGP440.SYS >

[2009/07/14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys

[2009/07/14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys

[2009/07/14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys

< MD5 for: ATAPI.SYS >

[2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys

[2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys

[2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys

< MD5 for: BEEP.SYS >

[2009/07/14 01:00:13 | 000,006,656 | ---- | M] (Microsoft Corporation) MD5=16A47CE2DECC9B099349A5F840654746 -- C:\Windows\SysNative\drivers\beep.sys

[2009/07/14 01:00:13 | 000,006,656 | ---- | M] (Microsoft Corporation) MD5=16A47CE2DECC9B099349A5F840654746 -- C:\Windows\winsxs\amd64_microsoft-windows-beepsys_31bf3856ad364e35_6.1.7600.16385_none_201592fa214e4f02\beep.sys

< MD5 for: CDROM.SYS >

[2009/07/14 00:19:54 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=83D2D75E1EFB81B3450C18131443F7DB -- C:\Windows\SysNative\drivers\cdrom.sys

[2009/07/14 00:19:54 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=83D2D75E1EFB81B3450C18131443F7DB -- C:\Windows\SysNative\DriverStore\FileRepository\cdrom.inf_amd64_neutral_8363d00ecae4322d\cdrom.sys

[2009/07/14 00:19:54 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=83D2D75E1EFB81B3450C18131443F7DB -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7600.16385_none_bb9e4d89bd7870f1\cdrom.sys

< MD5 for: NDIS.SYS >

[2009/07/14 02:48:27 | 000,947,776 | ---- | M] (Microsoft Corporation) MD5=CAD515DBD07D082BB317D9928CE8962C -- C:\Windows\SysNative\drivers\ndis.sys

[2009/07/14 02:48:27 | 000,947,776 | ---- | M] (Microsoft Corporation) MD5=CAD515DBD07D082BB317D9928CE8962C -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.1.7600.16385_none_03bc1d6e35c013bf\ndis.sys

< MD5 for: USERINIT.EXE >

[2009/07/14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\SysWOW64\userinit.exe

[2009/07/14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe

[2009/07/14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\SysNative\userinit.exe

[2009/07/14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe

< MD5 for: WINLOGON.EXE >

[2009/07/14 02:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe

[2010/07/17 20:26:04 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe

[2010/07/17 20:26:04 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\SysNative\winlogon.exe

[2010/07/17 20:26:04 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< >

< >

< End of report >

-- Dodane 30.01.2011 (N) 17:17 --

Co mam dalej zrobic


(Spandau) #6

W okno Własne opcje skanowania / skrypt w OTL wklej:

Klikasz na Wykonaj skrypt. Zgadzasz się na restart komputera. Log z usuwania na forum

Następnie ponownie uruchamiasz OTL klikasz raz jeszcze Skanuj i dajesz nowy log na forum Czyli dwa logi jeden z usuwania drugi z nowego skanowania po usuwaniu.

Logi wklej na www.wklej.org a w poście podaj linka


(Carla01) #7

Ponownie wlaczylam komputer i :o i pulpit mam juz normalny wykonalam szybkie skanowanie i nie wykzalo mi zadnego wirusa .Czy mam w dalszym ciagu zalecane przez Ciebie polecenia wykonac .Dziekuje bardzo mi Pomogles . =D>

to kopia mojego skanu

Malwarebytes' Anti-Malware 1.50.1.1100

www.malwarebytes.org

Wersja bazy: 5639

Windows 6.1.7600

Internet Explorer 8.0.7600.16385

30-1-2011 19:36:09

mbam-log-2011-01-30 (19-36-09).txt

Typ skanowania: Szybkie skanowanie

Przeskanowano obiektów: 153720

Up³ynê³o: 1 minut(y), 4 sekund(y)

Zainfekowanych procesów w pamiêci: 0

Zainfekowanych modu³ów w pamiêci: 0

Zainfekowanych kluczy rejestru: 0

Zainfekowanych wartoœci rejestru: 0

Zainfekowane informacje rejestru systemowego: 0

Zainfekowanych folderów: 0

Zainfekowanych plików: 0

Zainfekowanych procesów w pamiêci:

(Nie znaleziono zagro¿eñ)

Zainfekowanych modu³ów w pamiêci:

(Nie znaleziono zagro¿eñ)

Zainfekowanych kluczy rejestru:

(Nie znaleziono zagro¿eñ)

Zainfekowanych wartoœci rejestru:

(Nie znaleziono zagro¿eñ)

Zainfekowane informacje rejestru systemowego:

(Nie znaleziono zagro¿eñ)

Zainfekowanych folderów:

(Nie znaleziono zagro¿eñ)

Zainfekowanych plików:

(Nie znaleziono zagro¿eñ)


(Spandau) #8

Folder który dałem do usuwania to pozostałość po infekcji Dlatego powinnaś przeprowadzić usuwanie Ewentualnie usuń ten folder ręcznie C:\ProgramData\ hAmMfLg01804