problem trojan
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
problem trojan
mam spomaleny nb bo som asi chytil trojana tu je log:
Logfile of random's system information tool 1.08 (written by random/random)
Run by ARES at 2011-03-06 19:02:03
Microsoft Windows 7 Home Premium
System drive C: has 22 GB (29%) free of 76 GB
Total RAM: 4094 MB (50% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:02:23, on 6. 3. 2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe
C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\uTorrent\uTorrent.exe
C:\Program Files (x86)\Valve\Steam\Steam.exe
C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe
C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo Wi-Fi.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\SysWOW64\explorer.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\PROGRA~2\Java\jre6\bin\jp2launcher.exe
C:\Program Files (x86)\Java\jre6\bin\java.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\ARES.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT1750559
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Wisdom-soft toolbar - {6dfc55bb-bfff-485a-9709-90c3fdf6db58} - C:\Program Files (x86)\Wisdom-soft\tbWisd.dll
R3 - URLSearchHook: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll
R3 - URLSearchHook: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files (x86)\BS_Player\tbBS_P.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
O2 - BHO: Wisdom-soft toolbar - {6dfc55bb-bfff-485a-9709-90c3fdf6db58} - C:\Program Files (x86)\Wisdom-soft\tbWisd.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Pomocník pri prihlasovaní v sieti Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O2 - BHO: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files (x86)\BS_Player\tbBS_P.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: Wisdom-soft toolbar - {6dfc55bb-bfff-485a-9709-90c3fdf6db58} - C:\Program Files (x86)\Wisdom-soft\tbWisd.dll
O3 - Toolbar: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
O3 - Toolbar: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files (x86)\BS_Player\tbBS_P.dll
O4 - HKLM\..\Run: [RemoteControl9] "C:\Program Files (x86)\Cyberlink\PowerDVD9\PDVD9Serv.exe"
O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Cyberlink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [Boingo Wi-Fi] "C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [ESL Wire] "C:\Program Files\EslWire\wire.exe" --tray
O4 - HKCU\..\Run: [HKCU] C:\Users\ARES\AppData\Roaming\spynet\Win18.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Valve\Steam\steam.exe" -silent
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: FancyStart daemon.lnk = ?
O4 - Global Startup: SRS Premium Sound.lnk = ?
O9 - Extra button: Pridať do blogu - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Pridať do blogu v programe Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 6 (TeamViewer6) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 13901 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
winlogon.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files (x86)\ASUS\SmartLogon\smartlogon.exe" -switch-3be2f036c43042cdb03588591c9325c3
"C:\Windows\system32\FBAgent.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
C:\Windows\System32\spoolsv.exe
taskeng.exe {3902614A-FA46-4855-A6F8-D674835AD014}
"C:\Windows\system32\Dwm.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe"
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
"C:\Program Files (x86)\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe" -sSONY_MEDIAMGR
taskeng.exe {79BA0B08-A588-423C-BF22-C241C370E2B2}
"C:\Program Files (x86)\Google\Update\1.2.183.39\GoogleCrashHandler.exe" /crashhandler
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
"C:\Program Files\P4G\BatteryLife.exe"
"C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe"
"C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe" avshadowcontrol0_00000778
\??\C:\Windows\system32\conhost.exe
"C:\Program Files (x86)\ASUS\ASUS CopyProtect\aspg.exe"
"C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe"
"C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe"
"C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe"
"C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe"
"C:\Windows\SysWOW64\ACEngSvr.exe" -Embedding
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
"C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe"
"C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe"
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe"
"C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe"
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files (x86)\uTorrent\uTorrent.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Valve\Steam\Steam.exe" -silent
"C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel_64.exe" /f=srs_premium_sound_nopreset.zip /h
"C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe"
"C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo Wi-Fi.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe"
ATKOSD.exe
"C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
WDC.exe
explorer.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\servicing\TrustedInstaller.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe" /SILENT
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files\Trend Micro\Internet Security\TmProxy.exe"
"C:\Program Files\Trend Micro\BM\TMBMSRV.exe" /service
C:\Windows\system32\sppsvc.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtest="CacheSize/CacheSizeGroup_4/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_4 concurrent_prefetch/DnsParallelism/parallel_7/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchEnabled/ProxyConnectionImpact/proxy_connections_32/SpdyImpact/npn_with_spdy/" --channel=6492.070EA300.1373770357 /prefetch:3
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Program Files (x86)\Google\Chrome\Application\9.0.597.107\gcswf32.dll" --lang=sk --plugin-data-dir="C:\Users\ARES\AppData\Local\Google\Chrome\User Data\Default" --channel=6492.070C8A4C.1868517250 /prefetch:4
C:\Windows\system32\rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll" --lang=sk --plugin-data-dir="C:\Users\ARES\AppData\Local\Google\Chrome\User Data\Default" --channel=6492.07F8544C.1442341537 /prefetch:4
"C:\Windows\system32\SearchFilterHost.exe" 0 504 508 516 65536 512
C:\PROGRA~2\Java\jre6\bin\jp2launcher.exe "C:\Program Files (x86)\Java\jre6" -D__jvm_launched=279155709 -Xbootclasspath/a:C:\PROGRA~2\Java\jre6\lib\deploy.jar;C:\PROGRA~2\Java\jre6\lib\javaws.jar;C:\PROGRA~2\Java\jre6\lib\plugin.jar -Djava.class.path=C:\PROGRA~2\Java\jre6\classes -Dsun.awt.warmup=true --- -- -Xmx134m -Dsun.java2d.noddraw=true sun.plugin2.main.client.PluginMain write_pipe_name=jpi2_pid6176_pipe2,read_pipe_name=jpi2_pid6176_pipe1
"C:\Program Files (x86)\Java\jre6\bin\java.exe" -D__jvm_launched=279155709 "-Xbootclasspath/a:C:\\PROGRA~2\\Java\\jre6\\lib\\deploy.jar;C:\\PROGRA~2\\Java\\jre6\\lib\\javaws.jar;C:\\PROGRA~2\\Java\\jre6\\lib\\plugin.jar" "-Djava.class.path=C:\\PROGRA~2\\Java\\jre6\\classes" -Dsun.awt.warmup=true -Xmx134m -Dsun.java2d.noddraw=true "-Dsun.plugin2.jvm.args=-D__jvm_launched=279155709 \"-Xbootclasspath/a:C:\\\\PROGRA~2\\\\Java\\\\jre6\\\\lib\\\\deploy.jar;C:\\\\PROGRA~2\\\\Java\\\\jre6\\\\lib\\\\javaws.jar;C:\\\\PROGRA~2\\\\Java\\\\jre6\\\\lib\\\\plugin.jar\" \"-Djava.class.path=C:\\\\PROGRA~2\\\\Java\\\\jre6\\\\classes\" -Dsun.awt.warmup=true --- -- -Xmx134m -Dsun.java2d.noddraw=true" sun.plugin2.main.client.PluginMain write_pipe_name=jpi2_pid6176_pipe2,read_pipe_name=jpi2_pid6176_pipe1
wmiadap.exe /F /T /R
\??\C:\Windows\system32\conhost.exe
"C:\Windows\system32\wuauclt.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtest="CacheSize/CacheSizeGroup_4/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_4 concurrent_prefetch/DnsParallelism/parallel_7/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchEnabled/ProxyConnectionImpact/proxy_connections_32/SpdyImpact/npn_with_spdy/" --channel=6492.07121300.286379253 /prefetch:3
"C:\Users\ARES\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4f3ed5cd-0726-42a9-87f5-d13f3d2976ac}]
Windows Live Family Safety Browser Helper Class - C:\Program Files\Windows Live\Family Safety\fssbho.dll [2008-12-08 68960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2010-08-12 346736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg64.dll [2010-08-12 318960]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll [2010-12-09 3911776]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6dfc55bb-bfff-485a-9709-90c3fdf6db58}]
Wisdom-soft toolbar - C:\Program Files (x86)\Wisdom-soft\tbWisd.dll [2007-07-17 1379352]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2008-12-04 92504]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pri prihlasovaní v sieti Windows Live - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2010-08-12 256112]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-11-22 1242504]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll [2010-08-12 761840]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
uTorrentBar Toolbar - C:\Program Files (x86)\uTorrentBar\tbuTor.dll [2010-12-09 3911776]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [2010-08-12 458736]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-02-03 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll [2008-12-08 1067352]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
BS Player Toolbar - C:\Program Files (x86)\BS_Player\tbBS_P.dll [2010-11-29 3908192]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2010-08-12 346736]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll [2010-03-25 1548096]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2010-08-12 256112]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll [2008-12-08 1067352]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll [2010-03-25 968000]
{6dfc55bb-bfff-485a-9709-90c3fdf6db58} - Wisdom-soft toolbar - C:\Program Files (x86)\Wisdom-soft\tbWisd.dll [2007-07-17 1379352]
{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - uTorrentBar Toolbar - C:\Program Files (x86)\uTorrentBar\tbuTor.dll [2010-12-09 3911776]
{30F9B915-B755-4826-820B-08FBA6BD249D} - Conduit Engine - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll [2010-12-09 3911776]
{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - BS Player Toolbar - C:\Program Files (x86)\BS_Player\tbBS_P.dll [2010-11-29 3908192]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ETDWare"=C:\Program Files\Elantech\ETDCtrl.exe [2009-09-30 621440]
"ASUS WebStorage"=C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe [2010-03-16 1754448]
"UfSeAgnt.exe"=C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe [2010-02-23 1022904]
"AmIcoSinglun64"=C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [2010-01-18 324608]
"Setwallpaper"=c:\programdata\SetWallpaper.cmd []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2010-12-03 14944136]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1475072]
"uTorrent"=C:\Program Files (x86)\uTorrent\uTorrent.exe [2011-01-30 395640]
"ESL Wire"=C:\Program Files\EslWire\wire.exe --tray []
"HKCU"=C:\Users\ARES\AppData\Roaming\spynet\Win18.exe [2005-06-21 373314]
"Steam"=C:\Program Files (x86)\Valve\Steam\steam.exe [2011-03-06 1242448]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-28 35696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
C:\Windows\AsScrPro.exe [2010-08-12 3058304]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer]
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [2009-11-02 103720]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-05-04 10804256]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl9"=C:\Program Files (x86)\Cyberlink\PowerDVD9\PDVD9Serv.exe [2009-07-06 87336]
"UpdatePSTShortCut"=C:\Program Files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe [2010-06-24 210216]
"UpdateLBPShortCut"=C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [2009-05-20 222504]
"UpdateP2GoShortCut"=C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [2009-05-20 222504]
"Boingo Wi-Fi"=C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk [2010-08-12 2429]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-03-31 102400]
"ATKOSD2"=C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2010-02-04 7350912]
"ATKMEDIA"=C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [2010-05-03 170624]
"HControlUser"=C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [2009-06-19 105016]
"Wireless Console 3"=C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2010-04-26 1597440]
"avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2010-12-13 281768]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
FancyStart daemon.lnk - C:\Windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe
SRS Premium Sound.lnk - C:\Windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2011-03-06 19:02:03 ----D---- C:\rsit
2011-03-06 15:53:49 ----D---- C:\Users\ARES\AppData\Roaming\Avira
2011-03-06 13:14:22 ----D---- C:\Program Files (x86)\Valve
2011-03-05 20:41:49 ----D---- C:\DSPK
2011-03-05 14:04:59 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2011-03-05 14:04:59 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2011-03-05 14:04:59 ----A---- C:\Windows\system32\d3dcsx_42.dll
2011-03-05 14:04:59 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2011-03-05 14:04:58 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2011-03-05 14:04:58 ----A---- C:\Windows\system32\d3dx11_42.dll
2011-03-05 14:04:57 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2011-03-05 14:04:57 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2011-03-05 14:04:57 ----A---- C:\Windows\system32\D3DX9_42.dll
2011-03-05 14:04:57 ----A---- C:\Windows\system32\d3dx10_42.dll
2011-03-04 14:55:37 ----D---- C:\newhpvpcache
2011-02-28 21:00:57 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-02-27 16:39:42 ----D---- C:\Program Files (x86)\BS_Player
2011-02-27 16:39:36 ----D---- C:\Users\ARES\AppData\Roaming\BSplayer Pro
2011-02-27 16:39:36 ----D---- C:\Users\ARES\AppData\Roaming\BSplayer
2011-02-27 16:39:35 ----D---- C:\Program Files (x86)\Webteh
2011-02-25 17:40:47 ----D---- C:\ProgramData\VirtualizedApplications
2011-02-25 11:55:56 ----D---- C:\Users\ARES\AppData\Roaming\SoftGrid Client
2011-02-25 11:54:53 ----D---- C:\Program Files\Microsoft Office
2011-02-25 11:54:52 ----D---- C:\Program Files (x86)\Microsoft Application Virtualization Client
2011-02-25 11:54:34 ----D---- C:\Users\ARES\AppData\Roaming\TP
2011-02-25 11:51:48 ----A---- C:\Windows\SYSWOW64\wcncsvc.dll
2011-02-25 11:51:48 ----A---- C:\Windows\system32\wcncsvc.dll
2011-02-22 22:24:17 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2011-02-22 22:24:17 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2011-02-22 22:24:17 ----A---- C:\Windows\system32\XpsPrint.dll
2011-02-22 22:24:17 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2011-02-21 15:17:40 ----D---- C:\Users\ARES\AppData\Roaming\Leadertech
2011-02-21 15:12:55 ----D---- C:\Program Files (x86)\EA Sports
2011-02-21 15:12:54 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2011-02-21 15:12:54 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2011-02-21 15:12:54 ----A---- C:\Windows\system32\d3dx10_41.dll
2011-02-21 15:12:54 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2011-02-21 15:12:53 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2011-02-21 15:12:53 ----A---- C:\Windows\system32\D3DX9_41.dll
2011-02-21 15:12:51 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2011-02-21 15:12:51 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2011-02-21 15:12:51 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2011-02-21 15:12:51 ----A---- C:\Windows\system32\XAudio2_4.dll
2011-02-21 15:12:51 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2011-02-21 15:12:51 ----A---- C:\Windows\system32\xactengine3_4.dll
2011-02-21 15:12:50 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2011-02-21 15:12:50 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2011-02-21 15:12:49 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2011-02-21 15:12:49 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2011-02-21 15:12:49 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2011-02-21 15:12:49 ----A---- C:\Windows\system32\D3DX9_40.dll
2011-02-21 15:12:49 ----A---- C:\Windows\system32\d3dx10_40.dll
2011-02-21 15:12:49 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2011-02-21 15:12:48 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2011-02-21 15:12:48 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2011-02-21 15:12:48 ----A---- C:\Windows\system32\XAudio2_3.dll
2011-02-21 15:12:48 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2011-02-21 15:12:47 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2011-02-21 15:12:47 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2011-02-21 15:12:47 ----A---- C:\Windows\system32\xactengine3_3.dll
2011-02-21 15:12:47 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2011-02-21 15:12:45 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2011-02-21 15:12:45 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2011-02-21 15:12:45 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2011-02-21 15:12:45 ----A---- C:\Windows\system32\XAudio2_2.dll
2011-02-21 15:12:45 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2011-02-21 15:12:45 ----A---- C:\Windows\system32\xactengine3_2.dll
2011-02-21 15:12:44 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2011-02-21 15:12:44 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2011-02-21 15:12:44 ----A---- C:\Windows\system32\d3dx10_39.dll
2011-02-21 15:12:44 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2011-02-21 15:12:43 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2011-02-21 15:12:43 ----A---- C:\Windows\system32\D3DX9_39.dll
2011-02-21 15:12:42 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2011-02-21 15:12:42 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2011-02-21 15:12:42 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2011-02-21 15:12:42 ----A---- C:\Windows\system32\XAudio2_1.dll
2011-02-21 15:12:42 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2011-02-21 15:12:42 ----A---- C:\Windows\system32\xactengine3_1.dll
2011-02-21 15:12:41 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2011-02-21 15:12:41 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2011-02-21 15:12:41 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2011-02-21 15:12:41 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2011-02-21 15:12:41 ----A---- C:\Windows\system32\d3dx10_38.dll
2011-02-21 15:12:41 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2011-02-21 15:12:39 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2011-02-21 15:12:39 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2011-02-21 15:12:39 ----A---- C:\Windows\system32\XAudio2_0.dll
2011-02-21 15:12:39 ----A---- C:\Windows\system32\D3DX9_38.dll
2011-02-21 15:12:38 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2011-02-21 15:12:38 ----A---- C:\Windows\system32\xactengine3_0.dll
2011-02-21 15:12:37 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2011-02-21 15:12:37 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2011-02-21 15:12:37 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2011-02-21 15:12:37 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2011-02-21 15:12:37 ----A---- C:\Windows\system32\d3dx10_37.dll
2011-02-21 15:12:37 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2011-02-21 15:12:36 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2011-02-21 15:12:36 ----A---- C:\Windows\system32\D3DX9_37.dll
2011-02-21 15:12:35 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2011-02-21 15:12:35 ----A---- C:\Windows\system32\xactengine2_10.dll
2011-02-21 15:12:34 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2011-02-21 15:12:34 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2011-02-21 15:12:34 ----A---- C:\Windows\system32\d3dx10_36.dll
2011-02-21 15:12:34 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2011-02-21 15:12:33 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2011-02-21 15:12:33 ----A---- C:\Windows\system32\d3dx9_36.dll
2011-02-21 15:12:32 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2011-02-21 15:12:32 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2011-02-21 15:12:32 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2011-02-21 15:12:32 ----A---- C:\Windows\system32\xactengine2_9.dll
2011-02-21 15:12:32 ----A---- C:\Windows\system32\d3dx10_35.dll
2011-02-21 15:12:32 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2011-02-21 15:12:31 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2011-02-21 15:12:31 ----A---- C:\Windows\system32\d3dx9_35.dll
2011-02-21 15:12:29 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2011-02-21 15:12:29 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2011-02-21 15:12:29 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2011-02-21 15:12:29 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2011-02-21 15:12:29 ----A---- C:\Windows\system32\xactengine2_8.dll
2011-02-21 15:12:29 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2011-02-21 15:12:29 ----A---- C:\Windows\system32\d3dx10_34.dll
2011-02-21 15:12:29 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2011-02-21 15:12:28 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2011-02-21 15:12:28 ----A---- C:\Windows\system32\d3dx9_34.dll
2011-02-21 15:12:27 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2011-02-21 15:12:27 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2011-02-21 15:12:27 ----A---- C:\Windows\system32\xinput1_3.dll
2011-02-21 15:12:27 ----A---- C:\Windows\system32\xactengine2_7.dll
2011-02-21 15:12:26 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2011-02-21 15:12:26 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2011-02-21 15:12:26 ----A---- C:\Windows\system32\d3dx10_33.dll
2011-02-21 15:12:26 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2011-02-21 15:12:25 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2011-02-21 15:12:25 ----A---- C:\Windows\system32\d3dx9_33.dll
2011-02-21 15:12:24 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2011-02-21 15:12:24 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2011-02-21 15:12:24 ----A---- C:\Windows\system32\xactengine2_6.dll
2011-02-21 15:12:24 ----A---- C:\Windows\system32\xactengine2_5.dll
2011-02-21 15:12:23 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2011-02-21 15:12:23 ----A---- C:\Windows\system32\d3dx10.dll
2011-02-21 15:12:21 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2011-02-21 15:12:21 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2011-02-21 15:12:21 ----A---- C:\Windows\system32\xactengine2_4.dll
2011-02-21 15:12:21 ----A---- C:\Windows\system32\x3daudio1_1.dll
2011-02-21 15:12:20 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2011-02-21 15:12:20 ----A---- C:\Windows\system32\d3dx9_31.dll
2011-02-21 15:12:19 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2011-02-21 15:12:19 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2011-02-21 15:12:19 ----A---- C:\Windows\system32\xinput1_2.dll
2011-02-21 15:12:19 ----A---- C:\Windows\system32\xactengine2_3.dll
2011-02-21 15:12:18 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2011-02-21 15:12:18 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2011-02-21 15:12:18 ----A---- C:\Windows\system32\xinput1_1.dll
2011-02-21 15:12:18 ----A---- C:\Windows\system32\xactengine2_2.dll
2011-02-21 15:12:17 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2011-02-21 15:12:17 ----A---- C:\Windows\system32\xactengine2_1.dll
2011-02-21 15:12:10 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2011-02-21 15:12:10 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2011-02-21 15:12:10 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2011-02-21 15:12:10 ----A---- C:\Windows\system32\xactengine2_0.dll
2011-02-21 15:12:10 ----A---- C:\Windows\system32\x3daudio1_0.dll
2011-02-21 15:12:10 ----A---- C:\Windows\system32\d3dx9_30.dll
2011-02-21 15:12:09 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2011-02-21 15:12:09 ----A---- C:\Windows\system32\d3dx9_29.dll
2011-02-21 15:12:08 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2011-02-21 15:12:08 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2011-02-21 15:12:08 ----A---- C:\Windows\system32\d3dx9_28.dll
2011-02-21 15:12:08 ----A---- C:\Windows\system32\d3dx9_27.dll
2011-02-21 15:12:07 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2011-02-21 15:12:07 ----A---- C:\Windows\system32\d3dx9_26.dll
2011-02-21 15:12:06 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2011-02-21 15:12:06 ----A---- C:\Windows\system32\d3dx9_25.dll
2011-02-21 15:12:05 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2011-02-21 15:12:05 ----A---- C:\Windows\system32\d3dx9_24.dll
2011-02-19 18:39:37 ----D---- C:\Program Files (x86)\EslWire
2011-02-19 17:44:31 ----D---- C:\ProgramData\ESL Wire
2011-02-19 17:30:01 ----A---- C:\Windows\system32\drivers\ESLWireACD.sys
2011-02-19 17:29:45 ----A---- C:\Windows\system32\drivers\ESLvnic.sys
2011-02-09 20:05:06 ----A---- C:\Windows\system32\mshtml.dll
2011-02-09 20:05:05 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-02-09 20:05:01 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2011-02-09 20:05:00 ----A---- C:\Windows\SYSWOW64\mstime.dll
2011-02-09 20:05:00 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-02-09 20:05:00 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-02-09 20:05:00 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2011-02-09 20:05:00 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2011-02-09 20:05:00 ----A---- C:\Windows\system32\mstime.dll
2011-02-09 20:05:00 ----A---- C:\Windows\system32\mshtmled.dll
2011-02-09 20:05:00 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-02-09 20:05:00 ----A---- C:\Windows\system32\msfeeds.dll
2011-02-09 20:05:00 ----A---- C:\Windows\system32\iertutil.dll
2011-02-09 20:05:00 ----A---- C:\Windows\system32\iepeers.dll
2011-02-09 20:05:00 ----A---- C:\Windows\system32\iedkcs32.dll
2011-02-09 20:04:59 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2011-02-09 20:04:59 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2011-02-09 20:04:59 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2011-02-09 20:04:59 ----A---- C:\Windows\system32\msfeedssync.exe
2011-02-09 20:04:59 ----A---- C:\Windows\system32\licmgr10.dll
2011-02-09 20:04:43 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2011-02-09 20:04:43 ----A---- C:\Windows\system32\kerberos.dll
2011-02-09 20:04:41 ----A---- C:\Windows\system32\win32k.sys
2011-02-09 20:04:37 ----A---- C:\Windows\system32\msxml6.dll
2011-02-09 20:04:36 ----A---- C:\Windows\SYSWOW64\upnp.dll
2011-02-09 20:04:36 ----A---- C:\Windows\system32\urlmon.dll
2011-02-09 20:04:36 ----A---- C:\Windows\system32\upnp.dll
2011-02-09 20:04:36 ----A---- C:\Windows\system32\msxml3.dll
2011-02-09 20:04:35 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-02-09 20:04:34 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-02-09 20:04:34 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2011-02-09 20:04:34 ----A---- C:\Windows\system32\wininet.dll
2011-02-09 20:04:34 ----A---- C:\Windows\system32\winhttp.dll
2011-02-09 20:04:33 ----A---- C:\Windows\SYSWOW64\winhttp.dll
2011-02-09 20:04:33 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2011-02-09 20:04:33 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2011-02-09 20:04:33 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-02-09 20:04:33 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2011-02-09 20:04:33 ----A---- C:\Windows\system32\wscapi.dll
2011-02-09 20:04:33 ----A---- C:\Windows\system32\WebClnt.dll
2011-02-09 20:04:33 ----A---- C:\Windows\system32\ieframe.dll
2011-02-09 20:04:33 ----A---- C:\Windows\system32\davclnt.dll
2011-02-09 20:04:32 ----A---- C:\Windows\SYSWOW64\wscapi.dll
2011-02-09 20:04:32 ----A---- C:\Windows\SYSWOW64\slwga.dll
2011-02-09 20:04:32 ----A---- C:\Windows\system32\wscsvc.dll
2011-02-09 20:04:32 ----A---- C:\Windows\system32\slwga.dll
2011-02-09 20:04:29 ----A---- C:\Windows\system32\winsrv.dll
2011-02-09 20:04:27 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2011-02-09 20:04:27 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-02-09 20:04:27 ----A---- C:\Windows\system32\cdd.dll
2011-02-09 20:04:23 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2011-02-09 20:04:23 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-02-09 20:04:23 ----A---- C:\Windows\system32\vbscript.dll
2011-02-09 20:04:23 ----A---- C:\Windows\system32\jscript.dll
2011-02-09 20:04:20 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2011-02-09 20:04:20 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-02-09 20:04:20 ----A---- C:\Windows\system32\ntdll.dll
2011-02-09 20:04:19 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2011-02-09 20:04:19 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2011-02-09 20:04:17 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2011-02-09 20:04:17 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2011-02-09 20:04:17 ----A---- C:\Windows\system32\atmlib.dll
2011-02-09 20:04:17 ----A---- C:\Windows\system32\atmfd.dll
2011-02-09 16:19:32 ----D---- C:\Program Files (x86)\Microsoft.NET
======List of files/folders modified in the last 1 months======
2011-03-06 19:02:28 ----D---- C:\Windows\system32\drivers\etc
2011-03-06 19:02:24 ----D---- C:\Windows\Temp
2011-03-06 19:02:23 ----D---- C:\Program Files\Trend Micro
2011-03-06 19:02:19 ----D---- C:\Windows\Prefetch
2011-03-06 19:01:35 ----SHD---- C:\System Volume Information
2011-03-06 18:58:25 ----D---- C:\Users\ARES\AppData\Roaming\Skype
2011-03-06 18:57:17 ----D---- C:\Windows\system32\config
2011-03-06 18:56:47 ----D---- C:\Windows\system32\Tasks
2011-03-06 18:56:36 ----D---- C:\Users\ARES\AppData\Roaming\uTorrent
2011-03-06 18:52:33 ----RD---- C:\Program Files
2011-03-06 18:17:26 ----D---- C:\Windows\System32
2011-03-06 18:17:26 ----D---- C:\Windows\inf
2011-03-06 18:17:26 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-03-06 18:11:35 ----D---- C:\Users\ARES\AppData\Roaming\skypePM
2011-03-06 13:19:23 ----SHD---- C:\Windows\Installer
2011-03-06 13:19:23 ----D---- C:\Windows
2011-03-06 13:19:16 ----SD---- C:\Users\ARES\AppData\Roaming\Microsoft
2011-03-06 13:14:22 ----RD---- C:\Program Files (x86)
2011-03-06 13:13:21 ----D---- C:\Windows\SysWOW64
2011-03-04 22:46:31 ----A---- C:\Windows\system32\AutoRunFilter.ini
2011-03-04 13:56:15 ----D---- C:\Windows\system32\NDF
2011-02-26 20:47:40 ----D---- C:\Windows\system32\catroot2
2011-02-25 17:40:47 ----HD---- C:\ProgramData
2011-02-25 11:55:38 ----SD---- C:\ProgramData\Microsoft
2011-02-25 11:55:14 ----D---- C:\Windows\system32\drivers
2011-02-25 11:55:09 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2011-02-25 11:54:54 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-02-25 11:54:54 ----D---- C:\Program Files (x86)\Microsoft Office
2011-02-25 11:54:53 ----D---- C:\Program Files (x86)\Common Files
2011-02-25 11:51:51 ----D---- C:\Windows\system32\catroot
2011-02-25 11:51:50 ----D---- C:\Windows\winsxs
2011-02-21 15:12:17 ----RSD---- C:\Windows\assembly
2011-02-21 15:12:12 ----D---- C:\Windows\Microsoft.NET
2011-02-19 17:53:56 ----D---- C:\Windows\Logs
2011-02-19 17:30:35 ----D---- C:\Windows\system32\DriverStore
2011-02-11 14:18:48 ----D---- C:\Program Files\Internet Explorer
2011-02-11 14:18:48 ----D---- C:\Program Files (x86)\Internet Explorer
2011-02-09 22:04:11 ----A---- C:\Windows\system32\MRT.exe
2011-02-09 16:19:33 ----D---- C:\Windows\SYSWOW64\en-US
2011-02-09 16:19:33 ----D---- C:\Windows\system32\en-US
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 16440]
R0 lullaby;lullaby; C:\Windows\system32\DRIVERS\lullaby.sys [2009-06-18 15928]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-08-12 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-12-26 834544]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2010-12-13 116568]
R1 tmtdi;Trend Micro TDI Driver; C:\Windows\system32\DRIVERS\tmtdi.sys [2010-02-23 107536]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2010-12-13 83120]
R2 ESLWireAC;ESLWireAC; \??\C:\Windows\system32\drivers\ESLWireACD.sys [2010-12-08 169656]
R2 tmpreflt;tmpreflt; C:\Windows\system32\DRIVERS\tmpreflt.sys [2010-07-30 42576]
R2 tmxpflt;tmxpflt; C:\Windows\system32\DRIVERS\tmxpflt.sys [2010-07-30 309840]
R2 vsapint;vsapint; C:\Windows\system32\DRIVERS\vsapint.sys [2010-07-30 1988176]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-03-30 6657536]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-03-30 195584]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2010-03-02 1594368]
R3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2010-04-08 124944]
R3 BthEnum;Bluetooth Request Block Driver; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 79360]
R3 btusbflt;Bluetooth USB Filter; C:\Windows\system32\drivers\btusbflt.sys [2009-12-14 53800]
R3 ESLvnic1;ESLvnic Virtual Network 64 Bit; C:\Windows\system32\DRIVERS\ESLvnic.sys [2010-12-08 25528]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2009-10-15 117760]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-05-04 2363936]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2009-07-20 15416]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2010-03-04 75816]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATK64AMD.sys [2009-05-13 15928]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 Sftfs;Sftfs; C:\Windows\system32\DRIVERS\Sftfslh.sys [2009-12-02 721768]
R3 Sftplay;Sftplay; C:\Windows\system32\DRIVERS\Sftplaylh.sys [2009-12-02 269672]
R3 Sftredir;Sftredir; C:\Windows\system32\DRIVERS\Sftredirlh.sys [2009-12-02 25960]
R3 Sftvol;Sftvol; C:\Windows\system32\DRIVERS\Sftvollh.sys [2009-12-02 22376]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2009-08-20 1800192]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2009-12-22 38456]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 a8ogr9gy;a8ogr9gy; C:\Windows\system32\drivers\a8ogr9gy.sys []
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 551936]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys []
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys []
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys []
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys []
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2008-12-08 61792]
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver; C:\Windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
S3 WimFltr;WimFltr; C:\Windows\system32\DRIVERS\wimfltr.sys [2008-05-24 154168]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
Logfile of random's system information tool 1.08 (written by random/random)
Run by ARES at 2011-03-06 19:02:03
Microsoft Windows 7 Home Premium
System drive C: has 22 GB (29%) free of 76 GB
Total RAM: 4094 MB (50% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:02:23, on 6. 3. 2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe
C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\uTorrent\uTorrent.exe
C:\Program Files (x86)\Valve\Steam\Steam.exe
C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe
C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo Wi-Fi.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\SysWOW64\explorer.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\PROGRA~2\Java\jre6\bin\jp2launcher.exe
C:\Program Files (x86)\Java\jre6\bin\java.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\ARES.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT1750559
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Wisdom-soft toolbar - {6dfc55bb-bfff-485a-9709-90c3fdf6db58} - C:\Program Files (x86)\Wisdom-soft\tbWisd.dll
R3 - URLSearchHook: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll
R3 - URLSearchHook: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files (x86)\BS_Player\tbBS_P.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
O2 - BHO: Wisdom-soft toolbar - {6dfc55bb-bfff-485a-9709-90c3fdf6db58} - C:\Program Files (x86)\Wisdom-soft\tbWisd.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Pomocník pri prihlasovaní v sieti Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O2 - BHO: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files (x86)\BS_Player\tbBS_P.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: Wisdom-soft toolbar - {6dfc55bb-bfff-485a-9709-90c3fdf6db58} - C:\Program Files (x86)\Wisdom-soft\tbWisd.dll
O3 - Toolbar: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
O3 - Toolbar: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files (x86)\BS_Player\tbBS_P.dll
O4 - HKLM\..\Run: [RemoteControl9] "C:\Program Files (x86)\Cyberlink\PowerDVD9\PDVD9Serv.exe"
O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Cyberlink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [Boingo Wi-Fi] "C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [ESL Wire] "C:\Program Files\EslWire\wire.exe" --tray
O4 - HKCU\..\Run: [HKCU] C:\Users\ARES\AppData\Roaming\spynet\Win18.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Valve\Steam\steam.exe" -silent
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: FancyStart daemon.lnk = ?
O4 - Global Startup: SRS Premium Sound.lnk = ?
O9 - Extra button: Pridať do blogu - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Pridať do blogu v programe Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 6 (TeamViewer6) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 13901 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
winlogon.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files (x86)\ASUS\SmartLogon\smartlogon.exe" -switch-3be2f036c43042cdb03588591c9325c3
"C:\Windows\system32\FBAgent.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
C:\Windows\System32\spoolsv.exe
taskeng.exe {3902614A-FA46-4855-A6F8-D674835AD014}
"C:\Windows\system32\Dwm.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe"
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
"C:\Program Files (x86)\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe" -sSONY_MEDIAMGR
taskeng.exe {79BA0B08-A588-423C-BF22-C241C370E2B2}
"C:\Program Files (x86)\Google\Update\1.2.183.39\GoogleCrashHandler.exe" /crashhandler
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
"C:\Program Files\P4G\BatteryLife.exe"
"C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe"
"C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe" avshadowcontrol0_00000778
\??\C:\Windows\system32\conhost.exe
"C:\Program Files (x86)\ASUS\ASUS CopyProtect\aspg.exe"
"C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe"
"C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe"
"C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe"
"C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe"
"C:\Windows\SysWOW64\ACEngSvr.exe" -Embedding
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
"C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe"
"C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe"
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe"
"C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe"
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files (x86)\uTorrent\uTorrent.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Valve\Steam\Steam.exe" -silent
"C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel_64.exe" /f=srs_premium_sound_nopreset.zip /h
"C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe"
"C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo Wi-Fi.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe"
ATKOSD.exe
"C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
WDC.exe
explorer.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\servicing\TrustedInstaller.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe" /SILENT
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files\Trend Micro\Internet Security\TmProxy.exe"
"C:\Program Files\Trend Micro\BM\TMBMSRV.exe" /service
C:\Windows\system32\sppsvc.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtest="CacheSize/CacheSizeGroup_4/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_4 concurrent_prefetch/DnsParallelism/parallel_7/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchEnabled/ProxyConnectionImpact/proxy_connections_32/SpdyImpact/npn_with_spdy/" --channel=6492.070EA300.1373770357 /prefetch:3
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Program Files (x86)\Google\Chrome\Application\9.0.597.107\gcswf32.dll" --lang=sk --plugin-data-dir="C:\Users\ARES\AppData\Local\Google\Chrome\User Data\Default" --channel=6492.070C8A4C.1868517250 /prefetch:4
C:\Windows\system32\rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll" --lang=sk --plugin-data-dir="C:\Users\ARES\AppData\Local\Google\Chrome\User Data\Default" --channel=6492.07F8544C.1442341537 /prefetch:4
"C:\Windows\system32\SearchFilterHost.exe" 0 504 508 516 65536 512
C:\PROGRA~2\Java\jre6\bin\jp2launcher.exe "C:\Program Files (x86)\Java\jre6" -D__jvm_launched=279155709 -Xbootclasspath/a:C:\PROGRA~2\Java\jre6\lib\deploy.jar;C:\PROGRA~2\Java\jre6\lib\javaws.jar;C:\PROGRA~2\Java\jre6\lib\plugin.jar -Djava.class.path=C:\PROGRA~2\Java\jre6\classes -Dsun.awt.warmup=true --- -- -Xmx134m -Dsun.java2d.noddraw=true sun.plugin2.main.client.PluginMain write_pipe_name=jpi2_pid6176_pipe2,read_pipe_name=jpi2_pid6176_pipe1
"C:\Program Files (x86)\Java\jre6\bin\java.exe" -D__jvm_launched=279155709 "-Xbootclasspath/a:C:\\PROGRA~2\\Java\\jre6\\lib\\deploy.jar;C:\\PROGRA~2\\Java\\jre6\\lib\\javaws.jar;C:\\PROGRA~2\\Java\\jre6\\lib\\plugin.jar" "-Djava.class.path=C:\\PROGRA~2\\Java\\jre6\\classes" -Dsun.awt.warmup=true -Xmx134m -Dsun.java2d.noddraw=true "-Dsun.plugin2.jvm.args=-D__jvm_launched=279155709 \"-Xbootclasspath/a:C:\\\\PROGRA~2\\\\Java\\\\jre6\\\\lib\\\\deploy.jar;C:\\\\PROGRA~2\\\\Java\\\\jre6\\\\lib\\\\javaws.jar;C:\\\\PROGRA~2\\\\Java\\\\jre6\\\\lib\\\\plugin.jar\" \"-Djava.class.path=C:\\\\PROGRA~2\\\\Java\\\\jre6\\\\classes\" -Dsun.awt.warmup=true --- -- -Xmx134m -Dsun.java2d.noddraw=true" sun.plugin2.main.client.PluginMain write_pipe_name=jpi2_pid6176_pipe2,read_pipe_name=jpi2_pid6176_pipe1
wmiadap.exe /F /T /R
\??\C:\Windows\system32\conhost.exe
"C:\Windows\system32\wuauclt.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtest="CacheSize/CacheSizeGroup_4/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_4 concurrent_prefetch/DnsParallelism/parallel_7/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchEnabled/ProxyConnectionImpact/proxy_connections_32/SpdyImpact/npn_with_spdy/" --channel=6492.07121300.286379253 /prefetch:3
"C:\Users\ARES\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4f3ed5cd-0726-42a9-87f5-d13f3d2976ac}]
Windows Live Family Safety Browser Helper Class - C:\Program Files\Windows Live\Family Safety\fssbho.dll [2008-12-08 68960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2010-08-12 346736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg64.dll [2010-08-12 318960]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll [2010-12-09 3911776]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6dfc55bb-bfff-485a-9709-90c3fdf6db58}]
Wisdom-soft toolbar - C:\Program Files (x86)\Wisdom-soft\tbWisd.dll [2007-07-17 1379352]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2008-12-04 92504]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pri prihlasovaní v sieti Windows Live - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2010-08-12 256112]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-11-22 1242504]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll [2010-08-12 761840]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
uTorrentBar Toolbar - C:\Program Files (x86)\uTorrentBar\tbuTor.dll [2010-12-09 3911776]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [2010-08-12 458736]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-02-03 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll [2008-12-08 1067352]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
BS Player Toolbar - C:\Program Files (x86)\BS_Player\tbBS_P.dll [2010-11-29 3908192]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2010-08-12 346736]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll [2010-03-25 1548096]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2010-08-12 256112]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll [2008-12-08 1067352]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll [2010-03-25 968000]
{6dfc55bb-bfff-485a-9709-90c3fdf6db58} - Wisdom-soft toolbar - C:\Program Files (x86)\Wisdom-soft\tbWisd.dll [2007-07-17 1379352]
{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - uTorrentBar Toolbar - C:\Program Files (x86)\uTorrentBar\tbuTor.dll [2010-12-09 3911776]
{30F9B915-B755-4826-820B-08FBA6BD249D} - Conduit Engine - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll [2010-12-09 3911776]
{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - BS Player Toolbar - C:\Program Files (x86)\BS_Player\tbBS_P.dll [2010-11-29 3908192]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ETDWare"=C:\Program Files\Elantech\ETDCtrl.exe [2009-09-30 621440]
"ASUS WebStorage"=C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe [2010-03-16 1754448]
"UfSeAgnt.exe"=C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe [2010-02-23 1022904]
"AmIcoSinglun64"=C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [2010-01-18 324608]
"Setwallpaper"=c:\programdata\SetWallpaper.cmd []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2010-12-03 14944136]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1475072]
"uTorrent"=C:\Program Files (x86)\uTorrent\uTorrent.exe [2011-01-30 395640]
"ESL Wire"=C:\Program Files\EslWire\wire.exe --tray []
"HKCU"=C:\Users\ARES\AppData\Roaming\spynet\Win18.exe [2005-06-21 373314]
"Steam"=C:\Program Files (x86)\Valve\Steam\steam.exe [2011-03-06 1242448]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-28 35696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
C:\Windows\AsScrPro.exe [2010-08-12 3058304]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer]
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [2009-11-02 103720]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-05-04 10804256]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl9"=C:\Program Files (x86)\Cyberlink\PowerDVD9\PDVD9Serv.exe [2009-07-06 87336]
"UpdatePSTShortCut"=C:\Program Files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe [2010-06-24 210216]
"UpdateLBPShortCut"=C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [2009-05-20 222504]
"UpdateP2GoShortCut"=C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [2009-05-20 222504]
"Boingo Wi-Fi"=C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk [2010-08-12 2429]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-03-31 102400]
"ATKOSD2"=C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2010-02-04 7350912]
"ATKMEDIA"=C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [2010-05-03 170624]
"HControlUser"=C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [2009-06-19 105016]
"Wireless Console 3"=C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2010-04-26 1597440]
"avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2010-12-13 281768]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
FancyStart daemon.lnk - C:\Windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe
SRS Premium Sound.lnk - C:\Windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2011-03-06 19:02:03 ----D---- C:\rsit
2011-03-06 15:53:49 ----D---- C:\Users\ARES\AppData\Roaming\Avira
2011-03-06 13:14:22 ----D---- C:\Program Files (x86)\Valve
2011-03-05 20:41:49 ----D---- C:\DSPK
2011-03-05 14:04:59 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2011-03-05 14:04:59 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2011-03-05 14:04:59 ----A---- C:\Windows\system32\d3dcsx_42.dll
2011-03-05 14:04:59 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2011-03-05 14:04:58 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2011-03-05 14:04:58 ----A---- C:\Windows\system32\d3dx11_42.dll
2011-03-05 14:04:57 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2011-03-05 14:04:57 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2011-03-05 14:04:57 ----A---- C:\Windows\system32\D3DX9_42.dll
2011-03-05 14:04:57 ----A---- C:\Windows\system32\d3dx10_42.dll
2011-03-04 14:55:37 ----D---- C:\newhpvpcache
2011-02-28 21:00:57 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-02-27 16:39:42 ----D---- C:\Program Files (x86)\BS_Player
2011-02-27 16:39:36 ----D---- C:\Users\ARES\AppData\Roaming\BSplayer Pro
2011-02-27 16:39:36 ----D---- C:\Users\ARES\AppData\Roaming\BSplayer
2011-02-27 16:39:35 ----D---- C:\Program Files (x86)\Webteh
2011-02-25 17:40:47 ----D---- C:\ProgramData\VirtualizedApplications
2011-02-25 11:55:56 ----D---- C:\Users\ARES\AppData\Roaming\SoftGrid Client
2011-02-25 11:54:53 ----D---- C:\Program Files\Microsoft Office
2011-02-25 11:54:52 ----D---- C:\Program Files (x86)\Microsoft Application Virtualization Client
2011-02-25 11:54:34 ----D---- C:\Users\ARES\AppData\Roaming\TP
2011-02-25 11:51:48 ----A---- C:\Windows\SYSWOW64\wcncsvc.dll
2011-02-25 11:51:48 ----A---- C:\Windows\system32\wcncsvc.dll
2011-02-22 22:24:17 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2011-02-22 22:24:17 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2011-02-22 22:24:17 ----A---- C:\Windows\system32\XpsPrint.dll
2011-02-22 22:24:17 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2011-02-21 15:17:40 ----D---- C:\Users\ARES\AppData\Roaming\Leadertech
2011-02-21 15:12:55 ----D---- C:\Program Files (x86)\EA Sports
2011-02-21 15:12:54 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2011-02-21 15:12:54 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2011-02-21 15:12:54 ----A---- C:\Windows\system32\d3dx10_41.dll
2011-02-21 15:12:54 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2011-02-21 15:12:53 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2011-02-21 15:12:53 ----A---- C:\Windows\system32\D3DX9_41.dll
2011-02-21 15:12:51 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2011-02-21 15:12:51 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2011-02-21 15:12:51 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2011-02-21 15:12:51 ----A---- C:\Windows\system32\XAudio2_4.dll
2011-02-21 15:12:51 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2011-02-21 15:12:51 ----A---- C:\Windows\system32\xactengine3_4.dll
2011-02-21 15:12:50 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2011-02-21 15:12:50 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2011-02-21 15:12:49 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2011-02-21 15:12:49 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2011-02-21 15:12:49 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2011-02-21 15:12:49 ----A---- C:\Windows\system32\D3DX9_40.dll
2011-02-21 15:12:49 ----A---- C:\Windows\system32\d3dx10_40.dll
2011-02-21 15:12:49 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2011-02-21 15:12:48 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2011-02-21 15:12:48 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2011-02-21 15:12:48 ----A---- C:\Windows\system32\XAudio2_3.dll
2011-02-21 15:12:48 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2011-02-21 15:12:47 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2011-02-21 15:12:47 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2011-02-21 15:12:47 ----A---- C:\Windows\system32\xactengine3_3.dll
2011-02-21 15:12:47 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2011-02-21 15:12:45 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2011-02-21 15:12:45 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2011-02-21 15:12:45 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2011-02-21 15:12:45 ----A---- C:\Windows\system32\XAudio2_2.dll
2011-02-21 15:12:45 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2011-02-21 15:12:45 ----A---- C:\Windows\system32\xactengine3_2.dll
2011-02-21 15:12:44 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2011-02-21 15:12:44 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2011-02-21 15:12:44 ----A---- C:\Windows\system32\d3dx10_39.dll
2011-02-21 15:12:44 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2011-02-21 15:12:43 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2011-02-21 15:12:43 ----A---- C:\Windows\system32\D3DX9_39.dll
2011-02-21 15:12:42 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2011-02-21 15:12:42 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2011-02-21 15:12:42 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2011-02-21 15:12:42 ----A---- C:\Windows\system32\XAudio2_1.dll
2011-02-21 15:12:42 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2011-02-21 15:12:42 ----A---- C:\Windows\system32\xactengine3_1.dll
2011-02-21 15:12:41 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2011-02-21 15:12:41 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2011-02-21 15:12:41 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2011-02-21 15:12:41 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2011-02-21 15:12:41 ----A---- C:\Windows\system32\d3dx10_38.dll
2011-02-21 15:12:41 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2011-02-21 15:12:39 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2011-02-21 15:12:39 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2011-02-21 15:12:39 ----A---- C:\Windows\system32\XAudio2_0.dll
2011-02-21 15:12:39 ----A---- C:\Windows\system32\D3DX9_38.dll
2011-02-21 15:12:38 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2011-02-21 15:12:38 ----A---- C:\Windows\system32\xactengine3_0.dll
2011-02-21 15:12:37 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2011-02-21 15:12:37 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2011-02-21 15:12:37 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2011-02-21 15:12:37 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2011-02-21 15:12:37 ----A---- C:\Windows\system32\d3dx10_37.dll
2011-02-21 15:12:37 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2011-02-21 15:12:36 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2011-02-21 15:12:36 ----A---- C:\Windows\system32\D3DX9_37.dll
2011-02-21 15:12:35 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2011-02-21 15:12:35 ----A---- C:\Windows\system32\xactengine2_10.dll
2011-02-21 15:12:34 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2011-02-21 15:12:34 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2011-02-21 15:12:34 ----A---- C:\Windows\system32\d3dx10_36.dll
2011-02-21 15:12:34 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2011-02-21 15:12:33 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2011-02-21 15:12:33 ----A---- C:\Windows\system32\d3dx9_36.dll
2011-02-21 15:12:32 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2011-02-21 15:12:32 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2011-02-21 15:12:32 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2011-02-21 15:12:32 ----A---- C:\Windows\system32\xactengine2_9.dll
2011-02-21 15:12:32 ----A---- C:\Windows\system32\d3dx10_35.dll
2011-02-21 15:12:32 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2011-02-21 15:12:31 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2011-02-21 15:12:31 ----A---- C:\Windows\system32\d3dx9_35.dll
2011-02-21 15:12:29 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2011-02-21 15:12:29 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2011-02-21 15:12:29 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2011-02-21 15:12:29 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2011-02-21 15:12:29 ----A---- C:\Windows\system32\xactengine2_8.dll
2011-02-21 15:12:29 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2011-02-21 15:12:29 ----A---- C:\Windows\system32\d3dx10_34.dll
2011-02-21 15:12:29 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2011-02-21 15:12:28 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2011-02-21 15:12:28 ----A---- C:\Windows\system32\d3dx9_34.dll
2011-02-21 15:12:27 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2011-02-21 15:12:27 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2011-02-21 15:12:27 ----A---- C:\Windows\system32\xinput1_3.dll
2011-02-21 15:12:27 ----A---- C:\Windows\system32\xactengine2_7.dll
2011-02-21 15:12:26 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2011-02-21 15:12:26 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2011-02-21 15:12:26 ----A---- C:\Windows\system32\d3dx10_33.dll
2011-02-21 15:12:26 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2011-02-21 15:12:25 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2011-02-21 15:12:25 ----A---- C:\Windows\system32\d3dx9_33.dll
2011-02-21 15:12:24 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2011-02-21 15:12:24 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2011-02-21 15:12:24 ----A---- C:\Windows\system32\xactengine2_6.dll
2011-02-21 15:12:24 ----A---- C:\Windows\system32\xactengine2_5.dll
2011-02-21 15:12:23 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2011-02-21 15:12:23 ----A---- C:\Windows\system32\d3dx10.dll
2011-02-21 15:12:21 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2011-02-21 15:12:21 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2011-02-21 15:12:21 ----A---- C:\Windows\system32\xactengine2_4.dll
2011-02-21 15:12:21 ----A---- C:\Windows\system32\x3daudio1_1.dll
2011-02-21 15:12:20 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2011-02-21 15:12:20 ----A---- C:\Windows\system32\d3dx9_31.dll
2011-02-21 15:12:19 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2011-02-21 15:12:19 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2011-02-21 15:12:19 ----A---- C:\Windows\system32\xinput1_2.dll
2011-02-21 15:12:19 ----A---- C:\Windows\system32\xactengine2_3.dll
2011-02-21 15:12:18 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2011-02-21 15:12:18 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2011-02-21 15:12:18 ----A---- C:\Windows\system32\xinput1_1.dll
2011-02-21 15:12:18 ----A---- C:\Windows\system32\xactengine2_2.dll
2011-02-21 15:12:17 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2011-02-21 15:12:17 ----A---- C:\Windows\system32\xactengine2_1.dll
2011-02-21 15:12:10 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2011-02-21 15:12:10 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2011-02-21 15:12:10 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2011-02-21 15:12:10 ----A---- C:\Windows\system32\xactengine2_0.dll
2011-02-21 15:12:10 ----A---- C:\Windows\system32\x3daudio1_0.dll
2011-02-21 15:12:10 ----A---- C:\Windows\system32\d3dx9_30.dll
2011-02-21 15:12:09 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2011-02-21 15:12:09 ----A---- C:\Windows\system32\d3dx9_29.dll
2011-02-21 15:12:08 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2011-02-21 15:12:08 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2011-02-21 15:12:08 ----A---- C:\Windows\system32\d3dx9_28.dll
2011-02-21 15:12:08 ----A---- C:\Windows\system32\d3dx9_27.dll
2011-02-21 15:12:07 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2011-02-21 15:12:07 ----A---- C:\Windows\system32\d3dx9_26.dll
2011-02-21 15:12:06 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2011-02-21 15:12:06 ----A---- C:\Windows\system32\d3dx9_25.dll
2011-02-21 15:12:05 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2011-02-21 15:12:05 ----A---- C:\Windows\system32\d3dx9_24.dll
2011-02-19 18:39:37 ----D---- C:\Program Files (x86)\EslWire
2011-02-19 17:44:31 ----D---- C:\ProgramData\ESL Wire
2011-02-19 17:30:01 ----A---- C:\Windows\system32\drivers\ESLWireACD.sys
2011-02-19 17:29:45 ----A---- C:\Windows\system32\drivers\ESLvnic.sys
2011-02-09 20:05:06 ----A---- C:\Windows\system32\mshtml.dll
2011-02-09 20:05:05 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-02-09 20:05:01 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2011-02-09 20:05:00 ----A---- C:\Windows\SYSWOW64\mstime.dll
2011-02-09 20:05:00 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-02-09 20:05:00 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-02-09 20:05:00 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2011-02-09 20:05:00 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2011-02-09 20:05:00 ----A---- C:\Windows\system32\mstime.dll
2011-02-09 20:05:00 ----A---- C:\Windows\system32\mshtmled.dll
2011-02-09 20:05:00 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-02-09 20:05:00 ----A---- C:\Windows\system32\msfeeds.dll
2011-02-09 20:05:00 ----A---- C:\Windows\system32\iertutil.dll
2011-02-09 20:05:00 ----A---- C:\Windows\system32\iepeers.dll
2011-02-09 20:05:00 ----A---- C:\Windows\system32\iedkcs32.dll
2011-02-09 20:04:59 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2011-02-09 20:04:59 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2011-02-09 20:04:59 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2011-02-09 20:04:59 ----A---- C:\Windows\system32\msfeedssync.exe
2011-02-09 20:04:59 ----A---- C:\Windows\system32\licmgr10.dll
2011-02-09 20:04:43 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2011-02-09 20:04:43 ----A---- C:\Windows\system32\kerberos.dll
2011-02-09 20:04:41 ----A---- C:\Windows\system32\win32k.sys
2011-02-09 20:04:37 ----A---- C:\Windows\system32\msxml6.dll
2011-02-09 20:04:36 ----A---- C:\Windows\SYSWOW64\upnp.dll
2011-02-09 20:04:36 ----A---- C:\Windows\system32\urlmon.dll
2011-02-09 20:04:36 ----A---- C:\Windows\system32\upnp.dll
2011-02-09 20:04:36 ----A---- C:\Windows\system32\msxml3.dll
2011-02-09 20:04:35 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-02-09 20:04:34 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-02-09 20:04:34 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2011-02-09 20:04:34 ----A---- C:\Windows\system32\wininet.dll
2011-02-09 20:04:34 ----A---- C:\Windows\system32\winhttp.dll
2011-02-09 20:04:33 ----A---- C:\Windows\SYSWOW64\winhttp.dll
2011-02-09 20:04:33 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2011-02-09 20:04:33 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2011-02-09 20:04:33 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-02-09 20:04:33 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2011-02-09 20:04:33 ----A---- C:\Windows\system32\wscapi.dll
2011-02-09 20:04:33 ----A---- C:\Windows\system32\WebClnt.dll
2011-02-09 20:04:33 ----A---- C:\Windows\system32\ieframe.dll
2011-02-09 20:04:33 ----A---- C:\Windows\system32\davclnt.dll
2011-02-09 20:04:32 ----A---- C:\Windows\SYSWOW64\wscapi.dll
2011-02-09 20:04:32 ----A---- C:\Windows\SYSWOW64\slwga.dll
2011-02-09 20:04:32 ----A---- C:\Windows\system32\wscsvc.dll
2011-02-09 20:04:32 ----A---- C:\Windows\system32\slwga.dll
2011-02-09 20:04:29 ----A---- C:\Windows\system32\winsrv.dll
2011-02-09 20:04:27 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2011-02-09 20:04:27 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-02-09 20:04:27 ----A---- C:\Windows\system32\cdd.dll
2011-02-09 20:04:23 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2011-02-09 20:04:23 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-02-09 20:04:23 ----A---- C:\Windows\system32\vbscript.dll
2011-02-09 20:04:23 ----A---- C:\Windows\system32\jscript.dll
2011-02-09 20:04:20 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2011-02-09 20:04:20 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-02-09 20:04:20 ----A---- C:\Windows\system32\ntdll.dll
2011-02-09 20:04:19 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2011-02-09 20:04:19 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2011-02-09 20:04:17 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2011-02-09 20:04:17 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2011-02-09 20:04:17 ----A---- C:\Windows\system32\atmlib.dll
2011-02-09 20:04:17 ----A---- C:\Windows\system32\atmfd.dll
2011-02-09 16:19:32 ----D---- C:\Program Files (x86)\Microsoft.NET
======List of files/folders modified in the last 1 months======
2011-03-06 19:02:28 ----D---- C:\Windows\system32\drivers\etc
2011-03-06 19:02:24 ----D---- C:\Windows\Temp
2011-03-06 19:02:23 ----D---- C:\Program Files\Trend Micro
2011-03-06 19:02:19 ----D---- C:\Windows\Prefetch
2011-03-06 19:01:35 ----SHD---- C:\System Volume Information
2011-03-06 18:58:25 ----D---- C:\Users\ARES\AppData\Roaming\Skype
2011-03-06 18:57:17 ----D---- C:\Windows\system32\config
2011-03-06 18:56:47 ----D---- C:\Windows\system32\Tasks
2011-03-06 18:56:36 ----D---- C:\Users\ARES\AppData\Roaming\uTorrent
2011-03-06 18:52:33 ----RD---- C:\Program Files
2011-03-06 18:17:26 ----D---- C:\Windows\System32
2011-03-06 18:17:26 ----D---- C:\Windows\inf
2011-03-06 18:17:26 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-03-06 18:11:35 ----D---- C:\Users\ARES\AppData\Roaming\skypePM
2011-03-06 13:19:23 ----SHD---- C:\Windows\Installer
2011-03-06 13:19:23 ----D---- C:\Windows
2011-03-06 13:19:16 ----SD---- C:\Users\ARES\AppData\Roaming\Microsoft
2011-03-06 13:14:22 ----RD---- C:\Program Files (x86)
2011-03-06 13:13:21 ----D---- C:\Windows\SysWOW64
2011-03-04 22:46:31 ----A---- C:\Windows\system32\AutoRunFilter.ini
2011-03-04 13:56:15 ----D---- C:\Windows\system32\NDF
2011-02-26 20:47:40 ----D---- C:\Windows\system32\catroot2
2011-02-25 17:40:47 ----HD---- C:\ProgramData
2011-02-25 11:55:38 ----SD---- C:\ProgramData\Microsoft
2011-02-25 11:55:14 ----D---- C:\Windows\system32\drivers
2011-02-25 11:55:09 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2011-02-25 11:54:54 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-02-25 11:54:54 ----D---- C:\Program Files (x86)\Microsoft Office
2011-02-25 11:54:53 ----D---- C:\Program Files (x86)\Common Files
2011-02-25 11:51:51 ----D---- C:\Windows\system32\catroot
2011-02-25 11:51:50 ----D---- C:\Windows\winsxs
2011-02-21 15:12:17 ----RSD---- C:\Windows\assembly
2011-02-21 15:12:12 ----D---- C:\Windows\Microsoft.NET
2011-02-19 17:53:56 ----D---- C:\Windows\Logs
2011-02-19 17:30:35 ----D---- C:\Windows\system32\DriverStore
2011-02-11 14:18:48 ----D---- C:\Program Files\Internet Explorer
2011-02-11 14:18:48 ----D---- C:\Program Files (x86)\Internet Explorer
2011-02-09 22:04:11 ----A---- C:\Windows\system32\MRT.exe
2011-02-09 16:19:33 ----D---- C:\Windows\SYSWOW64\en-US
2011-02-09 16:19:33 ----D---- C:\Windows\system32\en-US
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 16440]
R0 lullaby;lullaby; C:\Windows\system32\DRIVERS\lullaby.sys [2009-06-18 15928]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-08-12 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-12-26 834544]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2010-12-13 116568]
R1 tmtdi;Trend Micro TDI Driver; C:\Windows\system32\DRIVERS\tmtdi.sys [2010-02-23 107536]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2010-12-13 83120]
R2 ESLWireAC;ESLWireAC; \??\C:\Windows\system32\drivers\ESLWireACD.sys [2010-12-08 169656]
R2 tmpreflt;tmpreflt; C:\Windows\system32\DRIVERS\tmpreflt.sys [2010-07-30 42576]
R2 tmxpflt;tmxpflt; C:\Windows\system32\DRIVERS\tmxpflt.sys [2010-07-30 309840]
R2 vsapint;vsapint; C:\Windows\system32\DRIVERS\vsapint.sys [2010-07-30 1988176]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-03-30 6657536]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-03-30 195584]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2010-03-02 1594368]
R3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2010-04-08 124944]
R3 BthEnum;Bluetooth Request Block Driver; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 79360]
R3 btusbflt;Bluetooth USB Filter; C:\Windows\system32\drivers\btusbflt.sys [2009-12-14 53800]
R3 ESLvnic1;ESLvnic Virtual Network 64 Bit; C:\Windows\system32\DRIVERS\ESLvnic.sys [2010-12-08 25528]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2009-10-15 117760]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-05-04 2363936]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2009-07-20 15416]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2010-03-04 75816]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATK64AMD.sys [2009-05-13 15928]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 Sftfs;Sftfs; C:\Windows\system32\DRIVERS\Sftfslh.sys [2009-12-02 721768]
R3 Sftplay;Sftplay; C:\Windows\system32\DRIVERS\Sftplaylh.sys [2009-12-02 269672]
R3 Sftredir;Sftredir; C:\Windows\system32\DRIVERS\Sftredirlh.sys [2009-12-02 25960]
R3 Sftvol;Sftvol; C:\Windows\system32\DRIVERS\Sftvollh.sys [2009-12-02 22376]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2009-08-20 1800192]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2009-12-22 38456]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 a8ogr9gy;a8ogr9gy; C:\Windows\system32\drivers\a8ogr9gy.sys []
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 551936]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys []
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys []
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys []
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys []
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2008-12-08 61792]
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver; C:\Windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
S3 WimFltr;WimFltr; C:\Windows\system32\DRIVERS\wimfltr.sys [2008-05-24 154168]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
Re: problem trojan
R2 AFBAgent;AFBAgent; C:\Windows\system32\FBAgent.exe [2009-12-08 379520]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-03-30 202752]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2010-12-13 267944]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2010-12-13 135336]
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2009-06-16 84536]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2009-12-15 96896]
R2 cvhsvc;Client Virtualization Handler; C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
R2 MSSQL$SONY_MEDIAMGR;MSSQL$SONY_MEDIAMGR; C:\Program Files (x86)\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe [2002-12-17 7520337]
R2 SeaPort;SeaPort; C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2008-12-04 226640]
R2 SfCtlCom;Trend Micro Central Control Component; C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe [2010-10-09 859712]
R2 sftlist;Application Virtualization Client; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
R2 TeamViewer6;TeamViewer 6; C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2010-12-07 2228008]
R3 sftvsa;Application Virtualization Service Agent; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2011-03-06 407336]
R3 TMBMServer;Trend Micro Unauthorized Change Prevention Service; C:\Program Files\Trend Micro\BM\TMBMSRV.exe [2010-02-23 570632]
R3 TmProxy;Trend Micro Proxy Service; C:\Program Files\Trend Micro\Internet Security\TmProxy.exe [2010-02-23 917768]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Google Update Service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-08-12 135664]
S3 fsssvc;Bezpečnosť rodiny v službe Windows Live; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2008-12-08 533344]
S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-08-12 182768]
S3 MSSQLServerADHelper;MSSQLServerADHelper; C:\Program Files (x86)\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe [2002-12-17 66112]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [2010-04-06 244904]
S3 SQLAgent$SONY_MEDIAMGR;SQLAgent$SONY_MEDIAMGR; C:\Program Files (x86)\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE [2002-12-17 311872]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-12-26 1255736]
-----------------EOF-----------------
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-03-30 202752]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2010-12-13 267944]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2010-12-13 135336]
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2009-06-16 84536]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2009-12-15 96896]
R2 cvhsvc;Client Virtualization Handler; C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
R2 MSSQL$SONY_MEDIAMGR;MSSQL$SONY_MEDIAMGR; C:\Program Files (x86)\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe [2002-12-17 7520337]
R2 SeaPort;SeaPort; C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2008-12-04 226640]
R2 SfCtlCom;Trend Micro Central Control Component; C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe [2010-10-09 859712]
R2 sftlist;Application Virtualization Client; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
R2 TeamViewer6;TeamViewer 6; C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2010-12-07 2228008]
R3 sftvsa;Application Virtualization Service Agent; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2011-03-06 407336]
R3 TMBMServer;Trend Micro Unauthorized Change Prevention Service; C:\Program Files\Trend Micro\BM\TMBMSRV.exe [2010-02-23 570632]
R3 TmProxy;Trend Micro Proxy Service; C:\Program Files\Trend Micro\Internet Security\TmProxy.exe [2010-02-23 917768]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Google Update Service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-08-12 135664]
S3 fsssvc;Bezpečnosť rodiny v službe Windows Live; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2008-12-08 533344]
S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-08-12 182768]
S3 MSSQLServerADHelper;MSSQLServerADHelper; C:\Program Files (x86)\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe [2002-12-17 66112]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [2010-04-06 244904]
S3 SQLAgent$SONY_MEDIAMGR;SQLAgent$SONY_MEDIAMGR; C:\Program Files (x86)\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE [2002-12-17 311872]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-12-26 1255736]
-----------------EOF-----------------
Re: problem trojan
Dobrý večer
Stahněte MBAM z mého podpisu
-Nainstalujte,dejte úplný sken
NIC NEMAZAT
-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.
-Nainstalujte,dejte úplný sken
NIC NEMAZAT
-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: problem trojan
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Verzia databázy: 5975
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
6. 3. 2011 23:25:07
mbam-log-2011-03-06 (23-24-45).txt
Typ kontroly: Úplná kontrola (C:\|D:\|Q:\|)
Objektov kontrolovaných: 313561
Uplynutý čas: 1 hod, 57 min, 4 sek
Infikované služby pamäte: 0
Infikované moduly pamäte: 0
Infikované registračné kľúče: 0
Infikované registračné hodnoty: 0
Infikované položky registračných dát: 0
Infikované priečinky: 0
Infikované súbory: 5
Infikované služby pamäte:
(Škodlivé položky neboli zistené)
Infikované moduly pamäte:
(Škodlivé položky neboli zistené)
Infikované registračné kľúče:
(Škodlivé položky neboli zistené)
Infikované registračné hodnoty:
(Škodlivé položky neboli zistené)
Infikované položky registračných dát:
(Škodlivé položky neboli zistené)
Infikované priečinky:
(Škodlivé položky neboli zistené)
Infikované súbory:
c:\Users\ARES\downloads\runescapetools.exe (Malware.Gen) -> No action taken.
c:\Users\ARES\AppData\Roaming\logs.dat (Bifrose.Trace) -> No action taken.
c:\Users\ARES\AppData\Local\Temp\IELOGIN.abc (Malware.Trace) -> No action taken.
c:\Users\ARES\AppData\Local\Temp\UuU.uUu (Malware.Trace) -> No action taken.
c:\Users\ARES\AppData\Local\Temp\XxX.xXx (Malware.Trace) -> No action taken.
www.malwarebytes.org
Verzia databázy: 5975
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
6. 3. 2011 23:25:07
mbam-log-2011-03-06 (23-24-45).txt
Typ kontroly: Úplná kontrola (C:\|D:\|Q:\|)
Objektov kontrolovaných: 313561
Uplynutý čas: 1 hod, 57 min, 4 sek
Infikované služby pamäte: 0
Infikované moduly pamäte: 0
Infikované registračné kľúče: 0
Infikované registračné hodnoty: 0
Infikované položky registračných dát: 0
Infikované priečinky: 0
Infikované súbory: 5
Infikované služby pamäte:
(Škodlivé položky neboli zistené)
Infikované moduly pamäte:
(Škodlivé položky neboli zistené)
Infikované registračné kľúče:
(Škodlivé položky neboli zistené)
Infikované registračné hodnoty:
(Škodlivé položky neboli zistené)
Infikované položky registračných dát:
(Škodlivé položky neboli zistené)
Infikované priečinky:
(Škodlivé položky neboli zistené)
Infikované súbory:
c:\Users\ARES\downloads\runescapetools.exe (Malware.Gen) -> No action taken.
c:\Users\ARES\AppData\Roaming\logs.dat (Bifrose.Trace) -> No action taken.
c:\Users\ARES\AppData\Local\Temp\IELOGIN.abc (Malware.Trace) -> No action taken.
c:\Users\ARES\AppData\Local\Temp\UuU.uUu (Malware.Trace) -> No action taken.
c:\Users\ARES\AppData\Local\Temp\XxX.xXx (Malware.Trace) -> No action taken.
Re: problem trojan
V mbamu vše smažte.
Spusťte combofix podle tohoto návodu
http://www.bleepingcomputer.com/combofi ... t-combofix
http://www.bleepingcomputer.com/combofi ... t-combofix
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: problem trojan
ComboFix 11-03-06.05 - ARES . 03. 2011 15:47:01.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.421.1051.18.4094.2672 [GMT 1:00]
Running from: c:\users\ARES\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Outdated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
AV: Trend Micro Internet Security *Enabled/Outdated* {68F968AC-2AA0-091D-848C-803E83E35902}
SP: AntiVir Desktop *Disabled/Outdated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Trend Micro Internet Security *Enabled/Outdated* {D3988948-0C9A-0693-BE3C-BB4CF86413BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\esupport\eDriver\Software\ASUS\MultiFrame\XP32_Vista32_Vista64_Win7_32_Win7_64_1.0.0021\Desktop_.ini
c:\programdata\FullRemove.exe
c:\windows\system32\service
.
.
((((((((((((((((((((((((( Files Created from 2011-02-07 to 2011-03-07 )))))))))))))))))))))))))))))))
.
.
2011-03-07 15:04 . 2011-03-07 15:04 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-03-06 20:25 . 2011-03-06 20:25 -------- d-----w- c:\users\ARES\AppData\Roaming\Malwarebytes
2011-03-06 20:24 . 2010-12-20 17:09 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-03-06 20:24 . 2011-03-06 20:24 -------- d-----w- c:\programdata\Malwarebytes
2011-03-06 20:24 . 2010-12-20 17:08 24152 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-03-06 20:24 . 2011-03-06 20:24 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-03-06 18:02 . 2011-03-06 18:02 -------- d-----w- C:\rsit
2011-03-06 14:53 . 2011-03-06 14:53 -------- d-----w- c:\users\ARES\AppData\Roaming\Avira
2011-03-06 12:14 . 2011-03-06 12:14 -------- d-----w- c:\program files (x86)\Valve
2011-03-05 19:41 . 2011-03-05 19:50 -------- d-----w- C:\DSPK
2011-03-05 13:04 . 2009-09-04 16:29 5501792 ----a-w- c:\windows\SysWow64\d3dcsx_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 1974616 ----a-w- c:\windows\SysWow64\D3DCompiler_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 5554512 ----a-w- c:\windows\system32\d3dcsx_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 2582888 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 235344 ----a-w- c:\windows\SysWow64\d3dx11_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 285024 ----a-w- c:\windows\system32\d3dx11_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 453456 ----a-w- c:\windows\SysWow64\d3dx10_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 1892184 ----a-w- c:\windows\SysWow64\D3DX9_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 523088 ----a-w- c:\windows\system32\d3dx10_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 2475352 ----a-w- c:\windows\system32\D3DX9_42.dll
2011-03-04 13:55 . 2011-03-04 13:55 -------- d-----w- C:\newhpvpcache
2011-03-03 07:24 . 2011-03-07 15:04 824 ----a-w- c:\windows\system32\drivers\etc\tmvsthfud.bin
2011-02-27 15:39 . 2011-02-27 15:39 -------- d-----w- c:\program files (x86)\BS_Player
2011-02-27 15:39 . 2011-02-27 17:11 -------- d-----w- c:\users\ARES\AppData\Roaming\BSplayer
2011-02-27 15:39 . 2011-02-27 15:39 -------- d-----w- c:\users\ARES\AppData\Roaming\BSplayer Pro
2011-02-27 15:39 . 2011-02-27 15:39 -------- d-----w- c:\program files (x86)\Webteh
2011-02-25 16:40 . 2011-02-28 15:25 -------- d-----w- c:\programdata\VirtualizedApplications
2011-02-25 13:57 . 2011-02-27 10:34 -------- d-----w- c:\users\ARES\AppData\Local\Microsoft Games
2011-02-25 10:55 . 2011-02-25 10:55 -------- d-----w- c:\users\ARES\AppData\Local\SoftGrid Client
2011-02-25 10:55 . 2011-03-01 09:02 -------- d-----w- c:\users\ARES\AppData\Roaming\SoftGrid Client
2011-02-25 10:54 . 2011-02-25 10:54 -------- d-----w- c:\program files (x86)\Microsoft Application Virtualization Client
2011-02-25 10:54 . 2011-02-25 10:56 -------- d-----w- c:\users\ARES\AppData\Roaming\TP
2011-02-25 10:51 . 2010-09-14 06:45 367104 ----a-w- c:\windows\system32\wcncsvc.dll
2011-02-25 10:51 . 2010-09-14 06:07 276992 ----a-w- c:\windows\SysWow64\wcncsvc.dll
2011-02-22 21:24 . 2011-01-07 08:07 662528 ----a-w- c:\windows\system32\XpsPrint.dll
2011-02-22 21:24 . 2011-01-07 08:07 475648 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-02-22 21:24 . 2011-01-07 07:31 442880 ----a-w- c:\windows\SysWow64\XpsPrint.dll
2011-02-22 21:24 . 2011-01-07 07:31 288256 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2011-02-21 14:17 . 2011-02-21 14:17 -------- d-----w- c:\users\ARES\AppData\Roaming\Leadertech
2011-02-19 17:39 . 2011-02-19 17:39 -------- d-----w- c:\program files (x86)\EslWire
2011-02-19 16:44 . 2011-02-19 16:44 -------- d-----w- c:\programdata\ESL Wire
2011-02-19 16:30 . 2010-12-08 10:53 169656 ----a-w- c:\windows\system32\drivers\ESLWireACD.sys
2011-02-19 16:29 . 2010-12-08 10:53 25528 ----a-w- c:\windows\system32\drivers\ESLvnic.sys
2011-02-09 19:04 . 2010-12-18 06:11 57856 ----a-w- c:\windows\system32\licmgr10.dll
2011-02-09 15:19 . 2011-02-09 15:19 -------- d-----w- c:\program files (x86)\Microsoft.NET
2011-02-06 18:39 . 2011-02-06 18:39 -------- d-----w- C:\zee_store
2011-02-06 16:50 . 2011-02-06 16:50 -------- d-----w- c:\users\ARES\.jagex_cache_32
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-03 19:52 . 2011-02-03 19:52 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-01-08 22:34 . 2011-01-08 22:34 20480 ----a-w- c:\windows\SysWow64\cliconfg.728
2010-12-26 12:20 . 2010-12-26 12:20 2829 ----a-w- c:\windows\War3Unin.pif
2010-12-26 12:20 . 2010-12-26 12:20 126976 ----a-w- c:\windows\War3Unin.exe
2010-12-17 06:56 . 2011-01-06 20:28 545 ----a-w- c:\windows\UC.PIF
2010-12-17 06:56 . 2011-01-06 20:28 545 ----a-w- c:\windows\RAR.PIF
2010-12-17 06:56 . 2011-01-06 20:28 545 ----a-w- c:\windows\PKZIP.PIF
2010-12-17 06:56 . 2011-01-06 20:28 545 ----a-w- c:\windows\PKUNZIP.PIF
2010-12-17 06:56 . 2011-01-06 20:28 545 ----a-w- c:\windows\NOCLOSE.PIF
2010-12-17 06:56 . 2011-01-06 20:28 545 ----a-w- c:\windows\LHA.PIF
2010-12-17 06:56 . 2011-01-06 20:28 545 ----a-w- c:\windows\ARJ.PIF
2010-12-13 07:40 . 2010-12-26 11:16 83120 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-12-13 07:40 . 2010-12-26 11:16 116568 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-04-08 17:31 . 2009-04-08 17:31 106496 ----a-w- c:\program files (x86)\Common Files\CPInstallAction.dll
2008-08-12 04:45 . 2008-08-12 04:45 155648 ----a-w- c:\program files (x86)\Common Files\MSIactionall.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{6dfc55bb-bfff-485a-9709-90c3fdf6db58}"= "c:\program files (x86)\Wisdom-soft\tbWisd.dll" [2007-07-17 1379352]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\tbuTor.dll" [2010-12-09 3911776]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files (x86)\BS_Player\tbBS_P.dll" [2010-11-29 3908192]
.
[HKEY_CLASSES_ROOT\clsid\{6dfc55bb-bfff-485a-9709-90c3fdf6db58}]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-12-09 11:51 3911776 ----a-w- c:\program files (x86)\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{6dfc55bb-bfff-485a-9709-90c3fdf6db58}]
2007-07-17 14:59 1379352 ----a-w- c:\program files (x86)\Wisdom-soft\tbWisd.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
2010-12-09 11:51 3911776 ----a-w- c:\program files (x86)\uTorrentBar\tbuTor.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
2010-11-29 14:26 3908192 ----a-w- c:\program files (x86)\BS_Player\tbBS_P.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{6dfc55bb-bfff-485a-9709-90c3fdf6db58}"= "c:\program files (x86)\Wisdom-soft\tbWisd.dll" [2007-07-17 1379352]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\tbuTor.dll" [2010-12-09 3911776]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files (x86)\ConduitEngine\ConduitEngine.dll" [2010-12-09 3911776]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files (x86)\BS_Player\tbBS_P.dll" [2010-11-29 3908192]
.
[HKEY_CLASSES_ROOT\clsid\{6dfc55bb-bfff-485a-9709-90c3fdf6db58}]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2010-12-03 14944136]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"uTorrent"="c:\program files (x86)\uTorrent\uTorrent.exe" [2011-01-30 395640]
"Steam"="c:\program files (x86)\Valve\Steam\steam.exe" [2011-03-06 1242448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl9"="c:\program files (x86)\Cyberlink\PowerDVD9\PDVD9Serv.exe" [2009-07-06 87336]
"UpdatePSTShortCut"="c:\program files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2010-06-24 210216]
"UpdateLBPShortCut"="c:\program files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"UpdateP2GoShortCut"="c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"Boingo Wi-Fi"="c:\program files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk" [2010-08-12 2429]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-03-31 102400]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-02-04 7350912]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-05-03 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"Wireless Console 3"="c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe" [2010-04-26 1597440]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2010-12-13 281768]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
FancyStart daemon.lnk - c:\windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe [2010-8-12 12862]
SRS Premium Sound.lnk - c:\windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe [2010-8-12 156952]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-12 135664]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2010-12-26 1255736]
S0 lullaby;lullaby;c:\windows\system32\DRIVERS\lullaby.sys [2009-06-18 15928]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-12-26 834544]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [2009-12-07 379520]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-03-30 202752]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2010-12-13 135336]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
S2 ESLWireAC;ESLWireAC;c:\windows\system32\drivers\ESLWireACD.sys [2010-12-08 169656]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2010-12-07 2228008]
S2 tmpreflt;tmpreflt;c:\windows\system32\DRIVERS\tmpreflt.sys [2010-07-30 42576]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2010-03-30 6657536]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-03-30 195584]
S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2009-12-14 53800]
S3 ESLvnic1;ESLvnic Virtual Network 64 Bit;c:\windows\system32\DRIVERS\ESLvnic.sys [2010-12-08 25528]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2009-10-15 117760]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [2010-03-04 75816]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2009-12-02 721768]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2009-12-02 269672]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2009-12-02 25960]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2009-12-02 22376]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
S3 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [2010-02-23 917768]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2009-12-22 38456]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-12 19:42]
.
2011-03-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-12 19:42]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2009-09-30 621440]
"ASUS WebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe" [2010-03-16 1754448]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2010-02-23 1022904]
"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2010-01-18 324608]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT1750559
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
FF - ProfilePath - c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - BS Player Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT1750559&SearchSource=13
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: DAEMON Tools Toolbar: DTToolbar@toolbarnet.com - %profile%\extensions\DTToolbar@toolbarnet.com
FF - Ext: Conduit Engine : engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - Ext: uTorrentBar Community Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - %profile%\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
FF - Ext: BS Player Community Toolbar: {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - %profile%\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKCU-Run-ESL Wire - c:\program files\EslWire\wire.exe
Toolbar-Locked - (no file)
WebBrowser-{6DFC55BB-BFFF-485A-9709-90C3FDF6DB58} - (no file)
WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file)
WebBrowser-{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5} - (no file)
HKLM-Run-Setwallpaper - c:\programdata\SetWallpaper.cmd
AddRemove-ASUS_Screensaver - c:\windows\system32\ASUS_Screensaver.scr
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10d.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10d.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-03-07 16:09:46
ComboFix-quarantined-files.txt 2011-03-07 15:09
.
Pre-Run: 23 378 313 216 bytes free
Post-Run: 25 041 240 064 bytes free
.
- - End Of File - - CB63EEEC53658081D00E502FE4E1D895
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.421.1051.18.4094.2672 [GMT 1:00]
Running from: c:\users\ARES\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Outdated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
AV: Trend Micro Internet Security *Enabled/Outdated* {68F968AC-2AA0-091D-848C-803E83E35902}
SP: AntiVir Desktop *Disabled/Outdated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Trend Micro Internet Security *Enabled/Outdated* {D3988948-0C9A-0693-BE3C-BB4CF86413BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\esupport\eDriver\Software\ASUS\MultiFrame\XP32_Vista32_Vista64_Win7_32_Win7_64_1.0.0021\Desktop_.ini
c:\programdata\FullRemove.exe
c:\windows\system32\service
.
.
((((((((((((((((((((((((( Files Created from 2011-02-07 to 2011-03-07 )))))))))))))))))))))))))))))))
.
.
2011-03-07 15:04 . 2011-03-07 15:04 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-03-06 20:25 . 2011-03-06 20:25 -------- d-----w- c:\users\ARES\AppData\Roaming\Malwarebytes
2011-03-06 20:24 . 2010-12-20 17:09 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-03-06 20:24 . 2011-03-06 20:24 -------- d-----w- c:\programdata\Malwarebytes
2011-03-06 20:24 . 2010-12-20 17:08 24152 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-03-06 20:24 . 2011-03-06 20:24 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-03-06 18:02 . 2011-03-06 18:02 -------- d-----w- C:\rsit
2011-03-06 14:53 . 2011-03-06 14:53 -------- d-----w- c:\users\ARES\AppData\Roaming\Avira
2011-03-06 12:14 . 2011-03-06 12:14 -------- d-----w- c:\program files (x86)\Valve
2011-03-05 19:41 . 2011-03-05 19:50 -------- d-----w- C:\DSPK
2011-03-05 13:04 . 2009-09-04 16:29 5501792 ----a-w- c:\windows\SysWow64\d3dcsx_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 1974616 ----a-w- c:\windows\SysWow64\D3DCompiler_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 5554512 ----a-w- c:\windows\system32\d3dcsx_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 2582888 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 235344 ----a-w- c:\windows\SysWow64\d3dx11_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 285024 ----a-w- c:\windows\system32\d3dx11_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 453456 ----a-w- c:\windows\SysWow64\d3dx10_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 1892184 ----a-w- c:\windows\SysWow64\D3DX9_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 523088 ----a-w- c:\windows\system32\d3dx10_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 2475352 ----a-w- c:\windows\system32\D3DX9_42.dll
2011-03-04 13:55 . 2011-03-04 13:55 -------- d-----w- C:\newhpvpcache
2011-03-03 07:24 . 2011-03-07 15:04 824 ----a-w- c:\windows\system32\drivers\etc\tmvsthfud.bin
2011-02-27 15:39 . 2011-02-27 15:39 -------- d-----w- c:\program files (x86)\BS_Player
2011-02-27 15:39 . 2011-02-27 17:11 -------- d-----w- c:\users\ARES\AppData\Roaming\BSplayer
2011-02-27 15:39 . 2011-02-27 15:39 -------- d-----w- c:\users\ARES\AppData\Roaming\BSplayer Pro
2011-02-27 15:39 . 2011-02-27 15:39 -------- d-----w- c:\program files (x86)\Webteh
2011-02-25 16:40 . 2011-02-28 15:25 -------- d-----w- c:\programdata\VirtualizedApplications
2011-02-25 13:57 . 2011-02-27 10:34 -------- d-----w- c:\users\ARES\AppData\Local\Microsoft Games
2011-02-25 10:55 . 2011-02-25 10:55 -------- d-----w- c:\users\ARES\AppData\Local\SoftGrid Client
2011-02-25 10:55 . 2011-03-01 09:02 -------- d-----w- c:\users\ARES\AppData\Roaming\SoftGrid Client
2011-02-25 10:54 . 2011-02-25 10:54 -------- d-----w- c:\program files (x86)\Microsoft Application Virtualization Client
2011-02-25 10:54 . 2011-02-25 10:56 -------- d-----w- c:\users\ARES\AppData\Roaming\TP
2011-02-25 10:51 . 2010-09-14 06:45 367104 ----a-w- c:\windows\system32\wcncsvc.dll
2011-02-25 10:51 . 2010-09-14 06:07 276992 ----a-w- c:\windows\SysWow64\wcncsvc.dll
2011-02-22 21:24 . 2011-01-07 08:07 662528 ----a-w- c:\windows\system32\XpsPrint.dll
2011-02-22 21:24 . 2011-01-07 08:07 475648 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-02-22 21:24 . 2011-01-07 07:31 442880 ----a-w- c:\windows\SysWow64\XpsPrint.dll
2011-02-22 21:24 . 2011-01-07 07:31 288256 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2011-02-21 14:17 . 2011-02-21 14:17 -------- d-----w- c:\users\ARES\AppData\Roaming\Leadertech
2011-02-19 17:39 . 2011-02-19 17:39 -------- d-----w- c:\program files (x86)\EslWire
2011-02-19 16:44 . 2011-02-19 16:44 -------- d-----w- c:\programdata\ESL Wire
2011-02-19 16:30 . 2010-12-08 10:53 169656 ----a-w- c:\windows\system32\drivers\ESLWireACD.sys
2011-02-19 16:29 . 2010-12-08 10:53 25528 ----a-w- c:\windows\system32\drivers\ESLvnic.sys
2011-02-09 19:04 . 2010-12-18 06:11 57856 ----a-w- c:\windows\system32\licmgr10.dll
2011-02-09 15:19 . 2011-02-09 15:19 -------- d-----w- c:\program files (x86)\Microsoft.NET
2011-02-06 18:39 . 2011-02-06 18:39 -------- d-----w- C:\zee_store
2011-02-06 16:50 . 2011-02-06 16:50 -------- d-----w- c:\users\ARES\.jagex_cache_32
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-03 19:52 . 2011-02-03 19:52 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-01-08 22:34 . 2011-01-08 22:34 20480 ----a-w- c:\windows\SysWow64\cliconfg.728
2010-12-26 12:20 . 2010-12-26 12:20 2829 ----a-w- c:\windows\War3Unin.pif
2010-12-26 12:20 . 2010-12-26 12:20 126976 ----a-w- c:\windows\War3Unin.exe
2010-12-17 06:56 . 2011-01-06 20:28 545 ----a-w- c:\windows\UC.PIF
2010-12-17 06:56 . 2011-01-06 20:28 545 ----a-w- c:\windows\RAR.PIF
2010-12-17 06:56 . 2011-01-06 20:28 545 ----a-w- c:\windows\PKZIP.PIF
2010-12-17 06:56 . 2011-01-06 20:28 545 ----a-w- c:\windows\PKUNZIP.PIF
2010-12-17 06:56 . 2011-01-06 20:28 545 ----a-w- c:\windows\NOCLOSE.PIF
2010-12-17 06:56 . 2011-01-06 20:28 545 ----a-w- c:\windows\LHA.PIF
2010-12-17 06:56 . 2011-01-06 20:28 545 ----a-w- c:\windows\ARJ.PIF
2010-12-13 07:40 . 2010-12-26 11:16 83120 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-12-13 07:40 . 2010-12-26 11:16 116568 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-04-08 17:31 . 2009-04-08 17:31 106496 ----a-w- c:\program files (x86)\Common Files\CPInstallAction.dll
2008-08-12 04:45 . 2008-08-12 04:45 155648 ----a-w- c:\program files (x86)\Common Files\MSIactionall.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{6dfc55bb-bfff-485a-9709-90c3fdf6db58}"= "c:\program files (x86)\Wisdom-soft\tbWisd.dll" [2007-07-17 1379352]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\tbuTor.dll" [2010-12-09 3911776]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files (x86)\BS_Player\tbBS_P.dll" [2010-11-29 3908192]
.
[HKEY_CLASSES_ROOT\clsid\{6dfc55bb-bfff-485a-9709-90c3fdf6db58}]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-12-09 11:51 3911776 ----a-w- c:\program files (x86)\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{6dfc55bb-bfff-485a-9709-90c3fdf6db58}]
2007-07-17 14:59 1379352 ----a-w- c:\program files (x86)\Wisdom-soft\tbWisd.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
2010-12-09 11:51 3911776 ----a-w- c:\program files (x86)\uTorrentBar\tbuTor.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
2010-11-29 14:26 3908192 ----a-w- c:\program files (x86)\BS_Player\tbBS_P.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{6dfc55bb-bfff-485a-9709-90c3fdf6db58}"= "c:\program files (x86)\Wisdom-soft\tbWisd.dll" [2007-07-17 1379352]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\tbuTor.dll" [2010-12-09 3911776]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files (x86)\ConduitEngine\ConduitEngine.dll" [2010-12-09 3911776]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files (x86)\BS_Player\tbBS_P.dll" [2010-11-29 3908192]
.
[HKEY_CLASSES_ROOT\clsid\{6dfc55bb-bfff-485a-9709-90c3fdf6db58}]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2010-12-03 14944136]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"uTorrent"="c:\program files (x86)\uTorrent\uTorrent.exe" [2011-01-30 395640]
"Steam"="c:\program files (x86)\Valve\Steam\steam.exe" [2011-03-06 1242448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl9"="c:\program files (x86)\Cyberlink\PowerDVD9\PDVD9Serv.exe" [2009-07-06 87336]
"UpdatePSTShortCut"="c:\program files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2010-06-24 210216]
"UpdateLBPShortCut"="c:\program files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"UpdateP2GoShortCut"="c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"Boingo Wi-Fi"="c:\program files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk" [2010-08-12 2429]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-03-31 102400]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-02-04 7350912]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-05-03 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"Wireless Console 3"="c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe" [2010-04-26 1597440]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2010-12-13 281768]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
FancyStart daemon.lnk - c:\windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe [2010-8-12 12862]
SRS Premium Sound.lnk - c:\windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe [2010-8-12 156952]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-12 135664]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2010-12-26 1255736]
S0 lullaby;lullaby;c:\windows\system32\DRIVERS\lullaby.sys [2009-06-18 15928]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-12-26 834544]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [2009-12-07 379520]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-03-30 202752]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2010-12-13 135336]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
S2 ESLWireAC;ESLWireAC;c:\windows\system32\drivers\ESLWireACD.sys [2010-12-08 169656]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2010-12-07 2228008]
S2 tmpreflt;tmpreflt;c:\windows\system32\DRIVERS\tmpreflt.sys [2010-07-30 42576]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2010-03-30 6657536]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-03-30 195584]
S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2009-12-14 53800]
S3 ESLvnic1;ESLvnic Virtual Network 64 Bit;c:\windows\system32\DRIVERS\ESLvnic.sys [2010-12-08 25528]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2009-10-15 117760]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [2010-03-04 75816]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2009-12-02 721768]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2009-12-02 269672]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2009-12-02 25960]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2009-12-02 22376]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
S3 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [2010-02-23 917768]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2009-12-22 38456]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-12 19:42]
.
2011-03-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-12 19:42]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2009-09-30 621440]
"ASUS WebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe" [2010-03-16 1754448]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2010-02-23 1022904]
"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2010-01-18 324608]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT1750559
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
FF - ProfilePath - c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - BS Player Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT1750559&SearchSource=13
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: DAEMON Tools Toolbar: DTToolbar@toolbarnet.com - %profile%\extensions\DTToolbar@toolbarnet.com
FF - Ext: Conduit Engine : engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - Ext: uTorrentBar Community Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - %profile%\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
FF - Ext: BS Player Community Toolbar: {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - %profile%\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKCU-Run-ESL Wire - c:\program files\EslWire\wire.exe
Toolbar-Locked - (no file)
WebBrowser-{6DFC55BB-BFFF-485A-9709-90C3FDF6DB58} - (no file)
WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file)
WebBrowser-{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5} - (no file)
HKLM-Run-Setwallpaper - c:\programdata\SetWallpaper.cmd
AddRemove-ASUS_Screensaver - c:\windows\system32\ASUS_Screensaver.scr
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10d.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10d.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-03-07 16:09:46
ComboFix-quarantined-files.txt 2011-03-07 15:09
.
Pre-Run: 23 378 313 216 bytes free
Post-Run: 25 041 240 064 bytes free
.
- - End Of File - - CB63EEEC53658081D00E502FE4E1D895
Re: problem trojan
C:\DSPK
C:\newhpvpcache
c:\windows\system32\drivers\etc\tmvsthfud.bin
-Do okénka zkopírujte cestu k souboru , pokud napíše, že soubor byl už testován, dejte otestovat znovu.
-Sem vložte link s výsledky.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: problem trojan
tie súbory neviem čo sú zač ... ale c:\windows\system32\drivers\etc\tmvsthfud.bin neviem to tam nájsť viem sa dostať len po c:\windows\system32\drivers\ a tam som už nenašiel etc
Re: problem trojan
Do složek se podívejte.
Ten soubor - na virustotalu dejte procházet, a do spodního okénka nakopírujte celou cestu k souboru a dejte odeslat.
Ten soubor - na virustotalu dejte procházet, a do spodního okénka nakopírujte celou cestu k souboru a dejte odeslat.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: problem trojan
A můžete mrknout do ětch složek, jestli Vám to něco říká?
C:\DSPK
C:\newhpvpcache
C:\DSPK
C:\newhpvpcache
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: problem trojan
jo .. už viem malo to byť z jednej hry
Re: problem trojan
-otevřete si Poznámkový blok
-Do něj zkopírujte text z tohoto okénka
Kód: Vybrat vše
DDS::
uStart Page = hxxp://search.conduit.com?SearchSource= ... =CT1750559
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
Firefox::
FF - ProfilePath - c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.as ... ource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - BS Player Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT17505 ... hSource=13
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: DAEMON Tools Toolbar: DTToolbar@toolbarnet.com - %profile%\extensions\DTToolbar@toolbarnet.com
FF - Ext: Conduit Engine : engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - Ext: uTorrentBar Community Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - %profile%\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
FF - Ext: BS Player Community Toolbar: {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - %profile%\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}
Registry::
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{6dfc55bb-bfff-485a-9709-90c3fdf6db58}"=-
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"=-
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"=-
[-HKEY_CLASSES_ROOT\clsid\{6dfc55bb-bfff-485a-9709-90c3fdf6db58}]
[-HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
[-HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
[-HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
[-KEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{6dfc55bb-bfff-485a-9709-90c3fdf6db58}]
[-KEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
[-HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{6dfc55bb-bfff-485a-9709-90c3fdf6db58}"=-
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"=-
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= -
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"=-
.[-HKEY_CLASSES_ROOT\clsid\{6dfc55bb-bfff-485a-9709-90c3fdf6db58}]
[-HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
[-HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
[-HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
-po uložení uchopte vámi vytvořený skript levým myšítkem a -přesuňte ho nad ikonu Combofixu, kde ho upustíte:

-po aplikaci na Vás vypadne další log,vložte ho sem
Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou, v tom případě znovu restartujte a přitom mačkejte F8, pak zvolte Poslední známou funkční konfiguraci
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: problem trojan
ComboFix 11-03-07.06 - ARES . 03. 2011 18:33:32.2.2 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.421.1051.18.4094.2605 [GMT 1:00]
Running from: c:\users\ARES\Desktop\ComboFix.exe
Command switches used :: c:\users\ARES\Desktop\CFScript.txt.txt
AV: AntiVir Desktop *Enabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Enabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\icon.png
c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\install.rdf
c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\preview.png
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\ConduitAutoCompleteSearch.js
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\ConduitAutoCompleteSearch.xpt
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\ConduitToolbar.idl
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\ConduitToolbar.js
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\ConduitToolbar.xpt
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCore.dll
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCore.xpt
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCoreGecko19.dll
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults\alertSettingsComponent.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults\appContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults\engineContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults\engineSettings.json
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults\fbAlert.js
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults\getAppsContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults\postAppsContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults\toolbarContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults\unsharedAppsContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\chrome.manifest
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\chrome\utorrentbar.jar
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\install.rdf
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\lib\xpcom.js
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\META-INF\manifest.mf
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\META-INF\zigbert.rsa
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\META-INF\zigbert.sf
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\searchplugin\conduit.gif
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\searchplugin\conduit.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\searchplugin\conduit.PNG
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\searchplugin\conduit.src
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\searchplugin\conduit.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\setup.ini
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\version.txt
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\ConduitAutoCompleteSearch.js
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\ConduitAutoCompleteSearch.xpt
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\ConduitToolbar.idl
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\ConduitToolbar.js
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\ConduitToolbar.xpt
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\RadioWMPCore.dll
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\RadioWMPCore.xpt
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\RadioWMPCoreGecko19.dll
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\defaults\alertSettingsComponent.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\defaults\appContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\defaults\engineContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\defaults\engineSettings.json
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\defaults\fbAlert.js
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\defaults\getAppsContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\defaults\postAppsContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\defaults\toolbarContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\defaults\unsharedAppsContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\chrome.manifest
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\chrome\bs_player.jar
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\install.rdf
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\lib\xpcom.js
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\META-INF\manifest.mf
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\META-INF\zigbert.rsa
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\META-INF\zigbert.sf
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\searchplugin\conduit.gif
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\searchplugin\conduit.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\searchplugin\conduit.PNG
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\searchplugin\conduit.src
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\searchplugin\conduit.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\setup.ini
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\version.txt
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.dll
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.xpt
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\about.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\AboutWindow.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\accept.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\AddRadioStation.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\as.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\as.png
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_buy.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_download.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_feedback.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_forum.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_home.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_lite.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astroburn_site.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astroLite_16.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\az.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\b1.png
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\burn_files.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\burn_image.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\burn_imgs.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\BurnImage.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\buy.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Config.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\d.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\d2.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\daemon.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\daemon_search.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\daemon_search_site.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dot_disabled.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dot_enabled.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dot_on_over.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\download.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ds.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dsearch.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt-home.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_about.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_buy.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_download.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_faq.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_feedback.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_forum.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_line.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_lite.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_manual.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_pro.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\DTPro.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dtt16.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dtt32.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Dwnl.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\emulation.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\faq.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\favicon.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\features.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\feedback.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\forum.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrix.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixCristals.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixDownload.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixPlayOnline.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixTop.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameS.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\games_search.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\games_search_SA.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameSA.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\gct16.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\gd.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\genre.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\globe.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GrabImage.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\hb.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\hb.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\help.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\hide.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\home.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\image_search.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\image_search_SA.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ImageS.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ImageSA.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ip.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\lang.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\lingvo.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\m.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_disable.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_down.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_m.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_under.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_disable.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_down.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_m.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_under.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\manual.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\map.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuRadioConfig.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuRadioStation.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuRSCur.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuTr.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mount.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mount_n_drive.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next_down.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next_m.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next_under.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\none.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\none_m.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\op.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play_down.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play_m.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play_under.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\pragma.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev_down.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev_m.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev_under.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prod.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Radio.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioBg.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioBg.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioBgMask.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDisp.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDisp_m.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown_down.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown_m.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown_under.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioE.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioG.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioL.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLDotMask.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLeft.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLeftMask.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLM.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioM.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioN.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioR.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioR.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioRM.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioRU.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume_down.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume_m.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume_under.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioW.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rbcheck.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rbtxt.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh_down.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh_m.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh_under.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Rss.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Rss1.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RssA.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RssA1.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rssClose.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rssL.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rssOpen.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RssRefresh.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\s2.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\show.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size_lr.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size_m.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size_rl.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\skins.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\soft24.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\soft24_SA.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\spt.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop_down.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop_m.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop_under.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\style.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\SupportRequest.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\timer.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\TitleIcon.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\toolbar.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\trans.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_disable.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_down.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_m.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_under.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\u.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\unmount-all.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_back.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_dott.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_dott_m.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_down.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_m.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_mute.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_mute_check.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_under.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose_down.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose_m.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose_under.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText_down.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText_m.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText_under.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\web_resources.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\web_search.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\web_search_SA.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\WebS.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\WebSa.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi0.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi1.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi10.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi11.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi12.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi13.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi14.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi2.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi3.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi4.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi5.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi6.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi7.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi8.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi9.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\chrome.manifest
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\chrome\dttoolbar.jar
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\install.rdf
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\components\ConduitAutoCompleteSearch.js
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\components\ConduitAutoCompleteSearch.xpt
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\components\ConduitToolbar.idl
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\components\ConduitToolbar.js
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\components\ConduitToolbar.xpt
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\components\RadioWMPCore.dll
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\components\RadioWMPCore.xpt
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\components\RadioWMPCoreGecko19.dll
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\defaults\alertSettingsComponent.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\defaults\appContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\defaults\engineContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\defaults\engineSettings.json
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\defaults\fbAlert.js
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\defaults\getAppsContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\defaults\postAppsContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\defaults\toolbarContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\defaults\unsharedAppsContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\DualPackage\install.rdf
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\chrome.manifest
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\chrome\conduitengine.jar
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\install.rdf
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\lib\xpcom.js
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\META-INF\manifest.mf
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\META-INF\zigbert.rsa
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\META-INF\zigbert.sf
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\searchplugin\conduit.gif
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\searchplugin\conduit.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\searchplugin\conduit.PNG
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\searchplugin\conduit.src
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\searchplugin\conduit.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\setup.ini
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\version.txt
.
.
((((((((((((((((((((((((( Files Created from 2011-02-08 to 2011-03-08 )))))))))))))))))))))))))))))))
.
.
2011-03-08 18:46 . 2011-03-08 18:46 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-03-06 20:25 . 2011-03-06 20:25 -------- d-----w- c:\users\ARES\AppData\Roaming\Malwarebytes
2011-03-06 20:24 . 2010-12-20 17:09 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-03-06 20:24 . 2011-03-06 20:24 -------- d-----w- c:\programdata\Malwarebytes
2011-03-06 20:24 . 2010-12-20 17:08 24152 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-03-06 20:24 . 2011-03-06 20:24 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-03-06 18:02 . 2011-03-06 18:02 -------- d-----w- C:\rsit
2011-03-06 14:53 . 2011-03-06 14:53 -------- d-----w- c:\users\ARES\AppData\Roaming\Avira
2011-03-06 12:14 . 2011-03-06 12:14 -------- d-----w- c:\program files (x86)\Valve
2011-03-05 19:41 . 2011-03-05 19:50 -------- d-----w- C:\DSPK
2011-03-05 13:04 . 2009-09-04 16:29 5501792 ----a-w- c:\windows\SysWow64\d3dcsx_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 1974616 ----a-w- c:\windows\SysWow64\D3DCompiler_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 5554512 ----a-w- c:\windows\system32\d3dcsx_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 2582888 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 235344 ----a-w- c:\windows\SysWow64\d3dx11_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 285024 ----a-w- c:\windows\system32\d3dx11_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 453456 ----a-w- c:\windows\SysWow64\d3dx10_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 1892184 ----a-w- c:\windows\SysWow64\D3DX9_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 523088 ----a-w- c:\windows\system32\d3dx10_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 2475352 ----a-w- c:\windows\system32\D3DX9_42.dll
2011-03-04 13:55 . 2011-03-04 13:55 -------- d-----w- C:\newhpvpcache
2011-03-03 07:24 . 2011-03-07 15:04 824 ----a-w- c:\windows\system32\drivers\etc\tmvsthfud.bin
2011-02-27 15:39 . 2011-02-27 15:39 -------- d-----w- c:\program files (x86)\BS_Player
2011-02-27 15:39 . 2011-02-27 17:11 -------- d-----w- c:\users\ARES\AppData\Roaming\BSplayer
2011-02-27 15:39 . 2011-02-27 15:39 -------- d-----w- c:\users\ARES\AppData\Roaming\BSplayer Pro
2011-02-27 15:39 . 2011-02-27 15:39 -------- d-----w- c:\program files (x86)\Webteh
2011-02-25 16:40 . 2011-02-28 15:25 -------- d-----w- c:\programdata\VirtualizedApplications
2011-02-25 13:57 . 2011-02-27 10:34 -------- d-----w- c:\users\ARES\AppData\Local\Microsoft Games
2011-02-25 10:55 . 2011-02-25 10:55 -------- d-----w- c:\users\ARES\AppData\Local\SoftGrid Client
2011-02-25 10:55 . 2011-03-01 09:02 -------- d-----w- c:\users\ARES\AppData\Roaming\SoftGrid Client
2011-02-25 10:54 . 2011-02-25 10:54 -------- d-----w- c:\program files (x86)\Microsoft Application Virtualization Client
2011-02-25 10:54 . 2011-02-25 10:56 -------- d-----w- c:\users\ARES\AppData\Roaming\TP
2011-02-25 10:51 . 2010-09-14 06:45 367104 ----a-w- c:\windows\system32\wcncsvc.dll
2011-02-25 10:51 . 2010-09-14 06:07 276992 ----a-w- c:\windows\SysWow64\wcncsvc.dll
2011-02-22 21:24 . 2011-01-07 08:07 662528 ----a-w- c:\windows\system32\XpsPrint.dll
2011-02-22 21:24 . 2011-01-07 08:07 475648 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-02-22 21:24 . 2011-01-07 07:31 442880 ----a-w- c:\windows\SysWow64\XpsPrint.dll
2011-02-22 21:24 . 2011-01-07 07:31 288256 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2011-02-21 14:17 . 2011-02-21 14:17 -------- d-----w- c:\users\ARES\AppData\Roaming\Leadertech
2011-02-19 17:39 . 2011-02-19 17:39 -------- d-----w- c:\program files (x86)\EslWire
2011-02-19 16:44 . 2011-02-19 16:44 -------- d-----w- c:\programdata\ESL Wire
2011-02-19 16:30 . 2010-12-08 10:53 169656 ----a-w- c:\windows\system32\drivers\ESLWireACD.sys
2011-02-19 16:29 . 2010-12-08 10:53 25528 ----a-w- c:\windows\system32\drivers\ESLvnic.sys
2011-02-09 19:04 . 2010-12-18 06:11 57856 ----a-w- c:\windows\system32\licmgr10.dll
2011-02-09 15:19 . 2011-02-09 15:19 -------- d-----w- c:\program files (x86)\Microsoft.NET
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-03 19:52 . 2011-02-03 19:52 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-01-08 22:34 . 2011-01-08 22:34 20480 ----a-w- c:\windows\SysWow64\cliconfg.728
2010-12-26 12:20 . 2010-12-26 12:20 2829 ----a-w- c:\windows\War3Unin.pif
2010-12-26 12:20 . 2010-12-26 12:20 126976 ----a-w- c:\windows\War3Unin.exe
2010-12-17 06:56 . 2011-01-06 20:28 545 ----a-w- c:\windows\UC.PIF
2010-12-17 06:56 . 2011-01-06 20:28 545 ----a-w- c:\windows\RAR.PIF
2010-12-17 06:56 . 2011-01-06 20:28 545 ----a-w- c:\windows\PKZIP.PIF
2010-12-17 06:56 . 2011-01-06 20:28 545 ----a-w- c:\windows\PKUNZIP.PIF
2010-12-17 06:56 . 2011-01-06 20:28 545 ----a-w- c:\windows\NOCLOSE.PIF
2010-12-17 06:56 . 2011-01-06 20:28 545 ----a-w- c:\windows\LHA.PIF
2010-12-17 06:56 . 2011-01-06 20:28 545 ----a-w- c:\windows\ARJ.PIF
2010-12-13 07:40 . 2010-12-26 11:16 83120 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-12-13 07:40 . 2010-12-26 11:16 116568 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-04-08 17:31 . 2009-04-08 17:31 106496 ----a-w- c:\program files (x86)\Common Files\CPInstallAction.dll
2008-08-12 04:45 . 2008-08-12 04:45 155648 ----a-w- c:\program files (x86)\Common Files\MSIactionall.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-03-07_15.04.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-03-07 21:50 . 2011-03-07 21:50 13306 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat
- 2011-03-06 22:39 . 2011-03-06 22:39 13306 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat
+ 2009-07-14 04:54 . 2011-03-08 14:27 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2011-03-07 14:10 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2011-03-08 14:27 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-03-07 14:10 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-03-08 14:27 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2011-03-07 14:10 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-08-12 19:54 . 2011-03-08 14:29 45264 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
- 2009-07-14 05:10 . 2011-03-07 14:11 41850 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-03-08 14:29 41850 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2009-07-14 05:30 . 2011-02-19 17:40 86016 c:\windows\system32\DriverStore\infpub.dat
+ 2009-07-14 05:30 . 2011-03-07 19:34 86016 c:\windows\system32\DriverStore\infpub.dat
+ 2010-12-23 20:12 . 2011-03-08 14:27 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-12-23 20:12 . 2011-03-07 14:11 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-12-23 20:12 . 2011-03-07 14:11 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-12-23 20:12 . 2011-03-08 14:27 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-12-23 20:12 . 2011-03-08 14:27 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-12-23 20:12 . 2011-03-07 14:11 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-12-23 19:59 . 2011-03-07 15:03 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-12-23 19:59 . 2011-03-08 18:13 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-12-23 19:59 . 2011-03-07 15:03 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-12-23 19:59 . 2011-03-08 18:13 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-12-23 20:04 . 2011-03-08 14:29 5998 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3657261213-877462495-3954197453-1001_UserData.bin
- 2010-12-23 20:04 . 2011-03-07 14:11 5998 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3657261213-877462495-3954197453-1001_UserData.bin
- 2010-08-12 19:16 . 2011-03-06 22:39 1634 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Bluetooth\bthservsdp.dat
+ 2010-08-12 19:16 . 2011-03-07 21:50 1634 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Bluetooth\bthservsdp.dat
- 2011-03-07 14:09 . 2011-03-07 14:09 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-03-08 14:26 . 2011-03-08 14:26 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-03-07 14:09 . 2011-03-07 14:09 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-03-08 14:26 . 2011-03-08 14:26 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 02:36 . 2011-03-07 14:16 638424 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2011-03-08 14:32 638424 c:\windows\system32\perfh009.dat
- 2009-07-14 02:36 . 2011-03-07 14:16 116202 c:\windows\system32\perfc009.dat
+ 2009-07-14 02:36 . 2011-03-08 14:32 116202 c:\windows\system32\perfc009.dat
- 2009-07-14 05:30 . 2011-02-19 17:40 143360 c:\windows\system32\DriverStore\infstrng.dat
+ 2009-07-14 05:30 . 2011-03-07 19:34 143360 c:\windows\system32\DriverStore\infstrng.dat
+ 2009-07-14 05:30 . 2011-03-07 19:34 143360 c:\windows\system32\DriverStore\infstor.dat
- 2009-07-14 05:30 . 2011-02-19 16:30 143360 c:\windows\system32\DriverStore\infstor.dat
+ 2010-08-12 05:32 . 2011-03-07 21:50 394264 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2010-08-12 05:32 . 2011-03-06 22:39 394264 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2009-07-14 05:01 . 2011-03-07 21:50 232240 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2011-03-06 22:39 232240 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2010-12-26 11:31 . 2011-03-07 21:50 3326300 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3657261213-877462495-3954197453-1001-8192.dat
- 2010-12-26 11:31 . 2011-03-06 22:39 3326300 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3657261213-877462495-3954197453-1001-8192.dat
+ 2009-07-14 02:34 . 2011-03-08 14:40 10223616 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
- 2009-07-14 02:34 . 2011-03-07 14:23 10223616 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2010-12-03 14944136]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"uTorrent"="c:\program files (x86)\uTorrent\uTorrent.exe" [2011-01-30 395640]
"Steam"="c:\program files (x86)\Valve\Steam\steam.exe" [2011-03-06 1242448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl9"="c:\program files (x86)\Cyberlink\PowerDVD9\PDVD9Serv.exe" [2009-07-06 87336]
"UpdatePSTShortCut"="c:\program files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2010-06-24 210216]
"UpdateLBPShortCut"="c:\program files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"UpdateP2GoShortCut"="c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"Boingo Wi-Fi"="c:\program files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk" [2010-08-12 2429]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-03-31 102400]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-02-04 7350912]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-05-03 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"Wireless Console 3"="c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe" [2010-04-26 1597440]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2010-12-13 281768]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
FancyStart daemon.lnk - c:\windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe [2010-8-12 12862]
SRS Premium Sound.lnk - c:\windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe [2010-8-12 156952]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-12 135664]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2010-12-26 1255736]
S0 lullaby;lullaby;c:\windows\system32\DRIVERS\lullaby.sys [2009-06-18 15928]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-12-26 834544]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [2009-12-07 379520]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-03-30 202752]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2010-12-13 135336]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
S2 ESLWireAC;ESLWireAC;c:\windows\system32\drivers\ESLWireACD.sys [2010-12-08 169656]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2010-12-07 2228008]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2010-03-30 6657536]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-03-30 195584]
S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2009-12-14 53800]
S3 ESLvnic1;ESLvnic Virtual Network 64 Bit;c:\windows\system32\DRIVERS\ESLvnic.sys [2010-12-08 25528]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2009-10-15 117760]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [2010-03-04 75816]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2009-12-02 721768]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2009-12-02 269672]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2009-12-02 25960]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2009-12-02 22376]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2009-12-22 38456]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-12 19:42]
.
2011-03-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-12 19:42]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2009-09-30 621440]
"ASUS WebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe" [2010-03-16 1754448]
"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2010-01-18 324608]
"Setwallpaper"="c:\programdata\SetWallpaper.cmd" [BU]
.
------- Supplementary Scan -------
.
uLocal Page = %SystemRoot%\system32\blank.htm
mLocal Page = %SystemRoot%\system32\blank.htm
FF - ProfilePath - c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{6dfc55bb-bfff-485a-9709-90c3fdf6db58} - (no file)
BHO-{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)
Toolbar-Locked - (no file)
WebBrowser-{6DFC55BB-BFFF-485A-9709-90C3FDF6DB58} - (no file)
WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10d.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10d.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-03-08 19:51:37
ComboFix-quarantined-files.txt 2011-03-08 18:51
ComboFix2.txt 2011-03-07 15:09
.
Pre-Run: 25 782 685 696 bytes free
Post-Run: 26 010 345 472 bytes free
.
- - End Of File - - B5B15EBB131C85FC127B0D8F5DB43270
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.421.1051.18.4094.2605 [GMT 1:00]
Running from: c:\users\ARES\Desktop\ComboFix.exe
Command switches used :: c:\users\ARES\Desktop\CFScript.txt.txt
AV: AntiVir Desktop *Enabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Enabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\icon.png
c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\install.rdf
c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\preview.png
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\ConduitAutoCompleteSearch.js
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\ConduitAutoCompleteSearch.xpt
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\ConduitToolbar.idl
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\ConduitToolbar.js
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\ConduitToolbar.xpt
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCore.dll
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCore.xpt
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCoreGecko19.dll
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults\alertSettingsComponent.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults\appContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults\engineContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults\engineSettings.json
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults\fbAlert.js
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults\getAppsContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults\postAppsContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults\toolbarContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults\unsharedAppsContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\chrome.manifest
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\chrome\utorrentbar.jar
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\install.rdf
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\lib\xpcom.js
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\META-INF\manifest.mf
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\META-INF\zigbert.rsa
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\META-INF\zigbert.sf
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\searchplugin\conduit.gif
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\searchplugin\conduit.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\searchplugin\conduit.PNG
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\searchplugin\conduit.src
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\searchplugin\conduit.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\setup.ini
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\version.txt
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\ConduitAutoCompleteSearch.js
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\ConduitAutoCompleteSearch.xpt
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\ConduitToolbar.idl
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\ConduitToolbar.js
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\ConduitToolbar.xpt
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\RadioWMPCore.dll
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\RadioWMPCore.xpt
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\RadioWMPCoreGecko19.dll
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\defaults\alertSettingsComponent.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\defaults\appContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\defaults\engineContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\defaults\engineSettings.json
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\defaults\fbAlert.js
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\defaults\getAppsContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\defaults\postAppsContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\defaults\toolbarContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\defaults\unsharedAppsContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\chrome.manifest
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\chrome\bs_player.jar
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\install.rdf
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\lib\xpcom.js
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\META-INF\manifest.mf
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\META-INF\zigbert.rsa
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\META-INF\zigbert.sf
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\searchplugin\conduit.gif
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\searchplugin\conduit.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\searchplugin\conduit.PNG
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\searchplugin\conduit.src
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\searchplugin\conduit.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\setup.ini
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\version.txt
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.dll
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.xpt
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\about.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\AboutWindow.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\accept.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\AddRadioStation.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\as.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\as.png
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_buy.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_download.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_feedback.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_forum.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_home.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_lite.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astroburn_site.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astroLite_16.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\az.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\b1.png
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\burn_files.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\burn_image.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\burn_imgs.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\BurnImage.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\buy.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Config.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\d.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\d2.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\daemon.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\daemon_search.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\daemon_search_site.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dot_disabled.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dot_enabled.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dot_on_over.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\download.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ds.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dsearch.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt-home.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_about.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_buy.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_download.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_faq.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_feedback.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_forum.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_line.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_lite.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_manual.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_pro.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\DTPro.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dtt16.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dtt32.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Dwnl.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\emulation.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\faq.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\favicon.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\features.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\feedback.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\forum.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrix.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixCristals.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixDownload.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixPlayOnline.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixTop.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameS.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\games_search.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\games_search_SA.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameSA.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\gct16.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\gd.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\genre.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\globe.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GrabImage.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\hb.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\hb.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\help.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\hide.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\home.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\image_search.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\image_search_SA.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ImageS.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ImageSA.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ip.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\lang.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\lingvo.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\m.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_disable.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_down.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_m.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_under.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_disable.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_down.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_m.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_under.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\manual.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\map.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuRadioConfig.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuRadioStation.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuRSCur.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuTr.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mount.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mount_n_drive.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next_down.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next_m.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next_under.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\none.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\none_m.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\op.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play_down.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play_m.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play_under.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\pragma.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev_down.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev_m.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev_under.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prod.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Radio.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioBg.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioBg.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioBgMask.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDisp.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDisp_m.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown_down.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown_m.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown_under.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioE.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioG.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioL.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLDotMask.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLeft.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLeftMask.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLM.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioM.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioN.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioR.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioR.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioRM.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioRU.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume_down.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume_m.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume_under.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioW.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rbcheck.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rbtxt.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh_down.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh_m.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh_under.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Rss.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Rss1.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RssA.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RssA1.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rssClose.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rssL.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rssOpen.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RssRefresh.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\s2.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\show.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size_lr.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size_m.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size_rl.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\skins.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\soft24.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\soft24_SA.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\spt.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop_down.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop_m.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop_under.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\style.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\SupportRequest.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\timer.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\TitleIcon.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\toolbar.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\trans.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_disable.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_down.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_m.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_under.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\u.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\unmount-all.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_back.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_dott.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_dott_m.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_down.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_m.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_mute.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_mute_check.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_under.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose_down.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose_m.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose_under.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText_down.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText_m.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText_under.bmp
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\web_resources.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\web_search.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\web_search_SA.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\WebS.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\WebSa.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi0.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi1.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi10.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi11.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi12.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi13.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi14.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi2.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi3.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi4.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi5.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi6.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi7.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi8.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi9.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\chrome.manifest
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\chrome\dttoolbar.jar
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\DTToolbar@toolbarnet.com\install.rdf
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\components\ConduitAutoCompleteSearch.js
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\components\ConduitAutoCompleteSearch.xpt
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\components\ConduitToolbar.idl
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\components\ConduitToolbar.js
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\components\ConduitToolbar.xpt
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\components\RadioWMPCore.dll
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\components\RadioWMPCore.xpt
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\components\RadioWMPCoreGecko19.dll
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\defaults\alertSettingsComponent.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\defaults\appContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\defaults\engineContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\defaults\engineSettings.json
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\defaults\fbAlert.js
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\defaults\getAppsContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\defaults\postAppsContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\defaults\toolbarContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\defaults\unsharedAppsContextMenu.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\DualPackage\install.rdf
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\chrome.manifest
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\chrome\conduitengine.jar
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\install.rdf
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\lib\xpcom.js
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\META-INF\manifest.mf
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\META-INF\zigbert.rsa
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\META-INF\zigbert.sf
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\searchplugin\conduit.gif
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\searchplugin\conduit.ico
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\searchplugin\conduit.PNG
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\searchplugin\conduit.src
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\searchplugin\conduit.xml
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\setup.ini
c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\extensions\engine@conduit.com\version.txt
.
.
((((((((((((((((((((((((( Files Created from 2011-02-08 to 2011-03-08 )))))))))))))))))))))))))))))))
.
.
2011-03-08 18:46 . 2011-03-08 18:46 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-03-06 20:25 . 2011-03-06 20:25 -------- d-----w- c:\users\ARES\AppData\Roaming\Malwarebytes
2011-03-06 20:24 . 2010-12-20 17:09 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-03-06 20:24 . 2011-03-06 20:24 -------- d-----w- c:\programdata\Malwarebytes
2011-03-06 20:24 . 2010-12-20 17:08 24152 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-03-06 20:24 . 2011-03-06 20:24 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-03-06 18:02 . 2011-03-06 18:02 -------- d-----w- C:\rsit
2011-03-06 14:53 . 2011-03-06 14:53 -------- d-----w- c:\users\ARES\AppData\Roaming\Avira
2011-03-06 12:14 . 2011-03-06 12:14 -------- d-----w- c:\program files (x86)\Valve
2011-03-05 19:41 . 2011-03-05 19:50 -------- d-----w- C:\DSPK
2011-03-05 13:04 . 2009-09-04 16:29 5501792 ----a-w- c:\windows\SysWow64\d3dcsx_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 1974616 ----a-w- c:\windows\SysWow64\D3DCompiler_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 5554512 ----a-w- c:\windows\system32\d3dcsx_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 2582888 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 235344 ----a-w- c:\windows\SysWow64\d3dx11_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 285024 ----a-w- c:\windows\system32\d3dx11_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 453456 ----a-w- c:\windows\SysWow64\d3dx10_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 1892184 ----a-w- c:\windows\SysWow64\D3DX9_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 523088 ----a-w- c:\windows\system32\d3dx10_42.dll
2011-03-05 13:04 . 2009-09-04 16:29 2475352 ----a-w- c:\windows\system32\D3DX9_42.dll
2011-03-04 13:55 . 2011-03-04 13:55 -------- d-----w- C:\newhpvpcache
2011-03-03 07:24 . 2011-03-07 15:04 824 ----a-w- c:\windows\system32\drivers\etc\tmvsthfud.bin
2011-02-27 15:39 . 2011-02-27 15:39 -------- d-----w- c:\program files (x86)\BS_Player
2011-02-27 15:39 . 2011-02-27 17:11 -------- d-----w- c:\users\ARES\AppData\Roaming\BSplayer
2011-02-27 15:39 . 2011-02-27 15:39 -------- d-----w- c:\users\ARES\AppData\Roaming\BSplayer Pro
2011-02-27 15:39 . 2011-02-27 15:39 -------- d-----w- c:\program files (x86)\Webteh
2011-02-25 16:40 . 2011-02-28 15:25 -------- d-----w- c:\programdata\VirtualizedApplications
2011-02-25 13:57 . 2011-02-27 10:34 -------- d-----w- c:\users\ARES\AppData\Local\Microsoft Games
2011-02-25 10:55 . 2011-02-25 10:55 -------- d-----w- c:\users\ARES\AppData\Local\SoftGrid Client
2011-02-25 10:55 . 2011-03-01 09:02 -------- d-----w- c:\users\ARES\AppData\Roaming\SoftGrid Client
2011-02-25 10:54 . 2011-02-25 10:54 -------- d-----w- c:\program files (x86)\Microsoft Application Virtualization Client
2011-02-25 10:54 . 2011-02-25 10:56 -------- d-----w- c:\users\ARES\AppData\Roaming\TP
2011-02-25 10:51 . 2010-09-14 06:45 367104 ----a-w- c:\windows\system32\wcncsvc.dll
2011-02-25 10:51 . 2010-09-14 06:07 276992 ----a-w- c:\windows\SysWow64\wcncsvc.dll
2011-02-22 21:24 . 2011-01-07 08:07 662528 ----a-w- c:\windows\system32\XpsPrint.dll
2011-02-22 21:24 . 2011-01-07 08:07 475648 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-02-22 21:24 . 2011-01-07 07:31 442880 ----a-w- c:\windows\SysWow64\XpsPrint.dll
2011-02-22 21:24 . 2011-01-07 07:31 288256 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2011-02-21 14:17 . 2011-02-21 14:17 -------- d-----w- c:\users\ARES\AppData\Roaming\Leadertech
2011-02-19 17:39 . 2011-02-19 17:39 -------- d-----w- c:\program files (x86)\EslWire
2011-02-19 16:44 . 2011-02-19 16:44 -------- d-----w- c:\programdata\ESL Wire
2011-02-19 16:30 . 2010-12-08 10:53 169656 ----a-w- c:\windows\system32\drivers\ESLWireACD.sys
2011-02-19 16:29 . 2010-12-08 10:53 25528 ----a-w- c:\windows\system32\drivers\ESLvnic.sys
2011-02-09 19:04 . 2010-12-18 06:11 57856 ----a-w- c:\windows\system32\licmgr10.dll
2011-02-09 15:19 . 2011-02-09 15:19 -------- d-----w- c:\program files (x86)\Microsoft.NET
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-03 19:52 . 2011-02-03 19:52 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-01-08 22:34 . 2011-01-08 22:34 20480 ----a-w- c:\windows\SysWow64\cliconfg.728
2010-12-26 12:20 . 2010-12-26 12:20 2829 ----a-w- c:\windows\War3Unin.pif
2010-12-26 12:20 . 2010-12-26 12:20 126976 ----a-w- c:\windows\War3Unin.exe
2010-12-17 06:56 . 2011-01-06 20:28 545 ----a-w- c:\windows\UC.PIF
2010-12-17 06:56 . 2011-01-06 20:28 545 ----a-w- c:\windows\RAR.PIF
2010-12-17 06:56 . 2011-01-06 20:28 545 ----a-w- c:\windows\PKZIP.PIF
2010-12-17 06:56 . 2011-01-06 20:28 545 ----a-w- c:\windows\PKUNZIP.PIF
2010-12-17 06:56 . 2011-01-06 20:28 545 ----a-w- c:\windows\NOCLOSE.PIF
2010-12-17 06:56 . 2011-01-06 20:28 545 ----a-w- c:\windows\LHA.PIF
2010-12-17 06:56 . 2011-01-06 20:28 545 ----a-w- c:\windows\ARJ.PIF
2010-12-13 07:40 . 2010-12-26 11:16 83120 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-12-13 07:40 . 2010-12-26 11:16 116568 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-04-08 17:31 . 2009-04-08 17:31 106496 ----a-w- c:\program files (x86)\Common Files\CPInstallAction.dll
2008-08-12 04:45 . 2008-08-12 04:45 155648 ----a-w- c:\program files (x86)\Common Files\MSIactionall.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-03-07_15.04.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-03-07 21:50 . 2011-03-07 21:50 13306 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat
- 2011-03-06 22:39 . 2011-03-06 22:39 13306 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat
+ 2009-07-14 04:54 . 2011-03-08 14:27 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2011-03-07 14:10 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2011-03-08 14:27 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-03-07 14:10 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-03-08 14:27 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2011-03-07 14:10 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-08-12 19:54 . 2011-03-08 14:29 45264 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
- 2009-07-14 05:10 . 2011-03-07 14:11 41850 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-03-08 14:29 41850 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2009-07-14 05:30 . 2011-02-19 17:40 86016 c:\windows\system32\DriverStore\infpub.dat
+ 2009-07-14 05:30 . 2011-03-07 19:34 86016 c:\windows\system32\DriverStore\infpub.dat
+ 2010-12-23 20:12 . 2011-03-08 14:27 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-12-23 20:12 . 2011-03-07 14:11 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-12-23 20:12 . 2011-03-07 14:11 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-12-23 20:12 . 2011-03-08 14:27 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-12-23 20:12 . 2011-03-08 14:27 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-12-23 20:12 . 2011-03-07 14:11 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-12-23 19:59 . 2011-03-07 15:03 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-12-23 19:59 . 2011-03-08 18:13 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-12-23 19:59 . 2011-03-07 15:03 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-12-23 19:59 . 2011-03-08 18:13 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-12-23 20:04 . 2011-03-08 14:29 5998 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3657261213-877462495-3954197453-1001_UserData.bin
- 2010-12-23 20:04 . 2011-03-07 14:11 5998 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3657261213-877462495-3954197453-1001_UserData.bin
- 2010-08-12 19:16 . 2011-03-06 22:39 1634 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Bluetooth\bthservsdp.dat
+ 2010-08-12 19:16 . 2011-03-07 21:50 1634 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Bluetooth\bthservsdp.dat
- 2011-03-07 14:09 . 2011-03-07 14:09 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-03-08 14:26 . 2011-03-08 14:26 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-03-07 14:09 . 2011-03-07 14:09 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-03-08 14:26 . 2011-03-08 14:26 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 02:36 . 2011-03-07 14:16 638424 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2011-03-08 14:32 638424 c:\windows\system32\perfh009.dat
- 2009-07-14 02:36 . 2011-03-07 14:16 116202 c:\windows\system32\perfc009.dat
+ 2009-07-14 02:36 . 2011-03-08 14:32 116202 c:\windows\system32\perfc009.dat
- 2009-07-14 05:30 . 2011-02-19 17:40 143360 c:\windows\system32\DriverStore\infstrng.dat
+ 2009-07-14 05:30 . 2011-03-07 19:34 143360 c:\windows\system32\DriverStore\infstrng.dat
+ 2009-07-14 05:30 . 2011-03-07 19:34 143360 c:\windows\system32\DriverStore\infstor.dat
- 2009-07-14 05:30 . 2011-02-19 16:30 143360 c:\windows\system32\DriverStore\infstor.dat
+ 2010-08-12 05:32 . 2011-03-07 21:50 394264 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2010-08-12 05:32 . 2011-03-06 22:39 394264 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2009-07-14 05:01 . 2011-03-07 21:50 232240 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2011-03-06 22:39 232240 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2010-12-26 11:31 . 2011-03-07 21:50 3326300 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3657261213-877462495-3954197453-1001-8192.dat
- 2010-12-26 11:31 . 2011-03-06 22:39 3326300 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3657261213-877462495-3954197453-1001-8192.dat
+ 2009-07-14 02:34 . 2011-03-08 14:40 10223616 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
- 2009-07-14 02:34 . 2011-03-07 14:23 10223616 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2010-12-03 14944136]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"uTorrent"="c:\program files (x86)\uTorrent\uTorrent.exe" [2011-01-30 395640]
"Steam"="c:\program files (x86)\Valve\Steam\steam.exe" [2011-03-06 1242448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl9"="c:\program files (x86)\Cyberlink\PowerDVD9\PDVD9Serv.exe" [2009-07-06 87336]
"UpdatePSTShortCut"="c:\program files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2010-06-24 210216]
"UpdateLBPShortCut"="c:\program files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"UpdateP2GoShortCut"="c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"Boingo Wi-Fi"="c:\program files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk" [2010-08-12 2429]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-03-31 102400]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-02-04 7350912]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-05-03 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"Wireless Console 3"="c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe" [2010-04-26 1597440]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2010-12-13 281768]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
FancyStart daemon.lnk - c:\windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe [2010-8-12 12862]
SRS Premium Sound.lnk - c:\windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe [2010-8-12 156952]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-12 135664]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2010-12-26 1255736]
S0 lullaby;lullaby;c:\windows\system32\DRIVERS\lullaby.sys [2009-06-18 15928]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-12-26 834544]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [2009-12-07 379520]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-03-30 202752]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2010-12-13 135336]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
S2 ESLWireAC;ESLWireAC;c:\windows\system32\drivers\ESLWireACD.sys [2010-12-08 169656]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2010-12-07 2228008]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2010-03-30 6657536]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-03-30 195584]
S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2009-12-14 53800]
S3 ESLvnic1;ESLvnic Virtual Network 64 Bit;c:\windows\system32\DRIVERS\ESLvnic.sys [2010-12-08 25528]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2009-10-15 117760]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [2010-03-04 75816]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2009-12-02 721768]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2009-12-02 269672]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2009-12-02 25960]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2009-12-02 22376]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2009-12-22 38456]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-12 19:42]
.
2011-03-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-12 19:42]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2009-09-30 621440]
"ASUS WebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe" [2010-03-16 1754448]
"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2010-01-18 324608]
"Setwallpaper"="c:\programdata\SetWallpaper.cmd" [BU]
.
------- Supplementary Scan -------
.
uLocal Page = %SystemRoot%\system32\blank.htm
mLocal Page = %SystemRoot%\system32\blank.htm
FF - ProfilePath - c:\users\ARES\AppData\Roaming\Mozilla\Firefox\Profiles\frysom7n.default\
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{6dfc55bb-bfff-485a-9709-90c3fdf6db58} - (no file)
BHO-{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)
Toolbar-Locked - (no file)
WebBrowser-{6DFC55BB-BFFF-485A-9709-90C3FDF6DB58} - (no file)
WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10d.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10d.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-03-08 19:51:37
ComboFix-quarantined-files.txt 2011-03-08 18:51
ComboFix2.txt 2011-03-07 15:09
.
Pre-Run: 25 782 685 696 bytes free
Post-Run: 26 010 345 472 bytes free
.
- - End Of File - - B5B15EBB131C85FC127B0D8F5DB43270
Re: problem trojan
- zkopírujte do okénka:
ComboFix /Uninstall
-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.
***********
http://tharifas.sweb.cz/T-Cleaner.exe
-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir
***********
- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru
záložka čistič- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner
záložka Registry- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy
Záložka Nástroje- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.
Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.
***********
http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech
***********
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.


Přispějete na provoz fóra?