witam,mam problem z rootkit-gen.
Przeskanowalem w sdfix i mam taki o to raport;co robic?
b]SDFix: Version 1.240
Run by pawcio on 2009-03-21 at 12:04
Microsoft Windows XP [Wersja 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
Checking Files :
Trojan Files Found:
C:\autorun.inf - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP77.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP1C.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP10.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP1E.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP20.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPE.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPC.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP8.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP22.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP14.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP9.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP19.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP1A.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPD.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPF.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP13.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP12.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP11.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPA.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPB.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP15.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP16.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP1B.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP17.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP3D.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP18.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP1F.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPD5.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP24.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP21.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP37.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP28.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP23.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPD7.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP27.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP25.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP26.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP1D.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPD4.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP2A.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP31.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPCC.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPCE.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP34.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP2B.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP2D.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP29.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPDD.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPD3.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP2C.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPD6.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPD9.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP2F.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP30.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP46.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP5A.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP33.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP32.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP35.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP57.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP2E.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP36.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP7A.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP7C.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPE2.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP39.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP3A.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP38.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPC8.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP3F.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP3B.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP54.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP55.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP3C.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP3E.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP5D.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP41.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP42.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP40.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP43.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP45.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP59.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP44.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP49.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP47.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP68.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP9F.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP4B.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP51.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP48.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP4A.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP4E.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP4D.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP4C.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP50.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP52.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP4F.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP56.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP5B.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP53.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP5C.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP5E.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP60.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP58.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP63.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP66.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP61.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP5F.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP9B.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP65.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP6F.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP75.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP64.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP62.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP67.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP8B.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP7D.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP6A.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP69.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP6B.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP6E.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP8D.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP6D.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP70.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP71.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP72.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP73.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP8E.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP90.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP74.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP98.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP9A.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPA1.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP7F.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP76.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP6C.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP78.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP84.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP86.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP80.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP81.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP7B.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPA0.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP7E.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPA3.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP82.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP89.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP83.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP87.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP85.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP88.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP8C.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP8A.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP94.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP91.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP8F.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP97.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP92.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP93.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP95.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP96.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP99.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP9C.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP9D.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP9E.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPA9.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPA7.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPA2.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPA4.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPA5.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP79.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPAA.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPA8.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPAC.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPA6.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPAD.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPAE.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPDC.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPAF.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMP7.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPAB.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPB0.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPDF.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPDA.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPB1.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPB2.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPB7.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPB4.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPB5.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPB6.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPB8.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPB3.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPBB.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPBA.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPB9.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPCF.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPBD.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPBC.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPBE.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPBF.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPC0.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPC1.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPC2.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPC5.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPC4.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPDB.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPE1.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPE3.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPC7.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPC6.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPDE.tmp - Deleted
C:\DOCUME~1\pawcio\USTAWI~1\Temp\TMPC3.tmp - Deleted
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-21 12:08:56
Windows 5.1.2600 Dodatek Service Pack 2 FAT NTAPI
scanning hidden processes …
scanning hidden services …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
“%windir%\system32\sessmgr.exe”="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
“C:\Program Files\Gadu-Gadu\gg.exe”=“C:\Program Files\Gadu-Gadu\gg.exe:*:Enabled:Gadu-Gadu - program g˘wny”
“C:\Program Files\Tlen.pl\tlen.exe”=“C:\Program Files\Tlen.pl\tlen.exe:*:Enabled:Komunikator Tlen.pl”
“C:\PROGRA~1\RINGZS~1\STORMC~1\Stormser.exe”=“C:\PROGRA~1\RINGZS~1\STORMC~1\Stormser.exe:*:Enabled:@xpsp2res.dll,-22008”
“C:\Program Files\IncrediMail\bin\ImApp.exe”=“C:\Program Files\IncrediMail\bin\ImApp.exe:*:Enabled:IncrediMail”
“C:\Program Files\IncrediMail\bin\IncMail.exe”=“C:\Program Files\IncrediMail\bin\IncMail.exe:*:Enabled:IncrediMail”
“C:\Program Files\IncrediMail\bin\ImpCnt.exe”=“C:\Program Files\IncrediMail\bin\ImpCnt.exe:*:Enabled:IncrediMail”
“C:\Program Files\Skype\Phone\Skype.exe”="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
“%windir%\system32\sessmgr.exe”="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
Remaining Files :
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes :
Sat 21 Mar 2009 100,864 …SHR — “C:\WINDOWS\system32\nmdfgds0.dll”
Fri 20 Mar 2009 100,864 …SHR — “C:\WINDOWS\system32\nmdfgds1.dll”
Fri 20 Mar 2009 110,776 …SHR — “C:\WINDOWS\system32\olhrwef.exe”
Mon 9 Feb 2009 9,934,392 A…H. — “C:\Program Files\Google\Picasa3\setup.exe”
Mon 27 Oct 2008 6,108,728 A…H. — “C:\System Volume Information_restore{F67BB49C-E621-4AF0-878C-35BB9CEFF5F7}\RP110\A0076395.exe”
Finished!