
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Preventívka..... -pre motji
Moderátor: Moderátoři
Pravidla fóra
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
-
- Vzorný návštěvník
- Příspěvky: 208
- Registrován: 07 čer 2010 17:54
- Bydliště: SK
- Kontaktovat uživatele:
Re: Preventívka..... -pre motji
.text C:\windows\Explorer.EXE[1328] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\windows\Explorer.EXE[1328] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\windows\Explorer.EXE[1328] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00150120
.text C:\windows\Explorer.EXE[1328] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0015006C
.text C:\windows\Explorer.EXE[1328] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001500E4
.text C:\windows\Explorer.EXE[1328] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00150030
.text C:\windows\Explorer.EXE[1328] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001500A8
.text C:\windows\system32\svchost.exe[1416] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 000A006C
.text C:\windows\system32\svchost.exe[1416] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 000A0030
.text C:\windows\system32\svchost.exe[1416] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00A10120
.text C:\windows\system32\svchost.exe[1416] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 00A1006C
.text C:\windows\system32\svchost.exe[1416] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 00A100E4
.text C:\windows\system32\svchost.exe[1416] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00A10030
.text C:\windows\system32\svchost.exe[1416] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 00A100A8
.text C:\windows\system32\Hpservice.exe[1488] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\windows\system32\Hpservice.exe[1488] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\windows\system32\Hpservice.exe[1488] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00090120
.text C:\windows\system32\Hpservice.exe[1488] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0009006C
.text C:\windows\system32\Hpservice.exe[1488] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 000900E4
.text C:\windows\system32\Hpservice.exe[1488] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00090030
.text C:\windows\system32\Hpservice.exe[1488] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 000900A8
.text C:\windows\system32\svchost.exe[1676] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\windows\system32\svchost.exe[1676] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\windows\system32\svchost.exe[1676] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00EE0120
.text C:\windows\system32\svchost.exe[1676] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 00EE006C
.text C:\windows\system32\svchost.exe[1676] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 00EE00E4
.text C:\windows\system32\svchost.exe[1676] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00EE0030
.text C:\windows\system32\svchost.exe[1676] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 00EE00A8
.text C:\Windows\System32\ZoneLabs\vsmon.exe[1732] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\Windows\System32\ZoneLabs\vsmon.exe[1732] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\Windows\System32\ZoneLabs\vsmon.exe[1732] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 000C0120
.text C:\Windows\System32\ZoneLabs\vsmon.exe[1732] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 000C006C
.text C:\Windows\System32\ZoneLabs\vsmon.exe[1732] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 000C00E4
.text C:\Windows\System32\ZoneLabs\vsmon.exe[1732] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 000C0030
.text C:\Windows\System32\ZoneLabs\vsmon.exe[1732] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 000C00A8
.text C:\windows\system32\DllHost.exe[1908] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0005006C
.text C:\windows\system32\DllHost.exe[1908] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00050030
.text C:\windows\system32\DllHost.exe[1908] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 000E0120
.text C:\windows\system32\DllHost.exe[1908] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 000E006C
.text C:\windows\system32\DllHost.exe[1908] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 000E00E4
.text C:\windows\system32\DllHost.exe[1908] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 000E0030
.text C:\windows\system32\DllHost.exe[1908] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 000E00A8
.text C:\windows\System32\spoolsv.exe[1968] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 000A006C
.text C:\windows\System32\spoolsv.exe[1968] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 000A0030
.text C:\windows\System32\spoolsv.exe[1968] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00240120
.text C:\windows\System32\spoolsv.exe[1968] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0024006C
.text C:\windows\System32\spoolsv.exe[1968] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 002400E4
.text C:\windows\System32\spoolsv.exe[1968] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00240030
.text C:\windows\System32\spoolsv.exe[1968] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 002400A8
.text D:\Program Files\Alwil Software\Avast5\AvastSvc.exe[2032] kernel32.dll!SetUnhandledExceptionFilter 76CA3D01 4 Bytes [C2, 04, 00, 90] {RET 0x4; NOP }
.text c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe[2044] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe[2044] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe[2044] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 001F0120
.text c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe[2044] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 001F006C
.text c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe[2044] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001F00E4
.text c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe[2044] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 001F0030
.text c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe[2044] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001F00A8
.text C:\windows\System32\svchost.exe[2116] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\windows\System32\svchost.exe[2116] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\windows\System32\svchost.exe[2116] user32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00470120
.text C:\windows\System32\svchost.exe[2116] user32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0047006C
.text C:\windows\System32\svchost.exe[2116] user32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 004700E4
.text C:\windows\System32\svchost.exe[2116] user32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00470030
.text C:\windows\System32\svchost.exe[2116] user32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 004700A8
.text C:\windows\system32\svchost.exe[2124] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 000A006C
.text C:\windows\system32\svchost.exe[2124] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 000A0030
.text C:\windows\system32\svchost.exe[2124] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00370120
.text C:\windows\system32\svchost.exe[2124] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0037006C
.text C:\windows\system32\svchost.exe[2124] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 003700E4
.text C:\windows\system32\svchost.exe[2124] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00370030
.text C:\windows\system32\svchost.exe[2124] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 003700A8
.text C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe[2136] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe[2136] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe[2136] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00310120
.text C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe[2136] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0031006C
.text C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe[2136] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 003100E4
.text C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe[2136] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00310030
.text C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe[2136] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 003100A8
.text C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9fc8b38ddee9fbba\aestsrv.exe[2204] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9fc8b38ddee9fbba\aestsrv.exe[2204] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe[2252] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe[2252] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe[2252] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00200120
.text C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe[2252] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0020006C
.text C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe[2252] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 002000E4
.text C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe[2252] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00200030
.text C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe[2252] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 002000A8
.text C:\windows\system32\svchost.exe[2280] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\windows\system32\svchost.exe[2280] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\windows\system32\svchost.exe[2280] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00520120
.text C:\windows\system32\svchost.exe[2280] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0052006C
.text C:\windows\system32\svchost.exe[2280] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 005200E4
.text C:\windows\system32\svchost.exe[2280] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00520030
.text C:\windows\system32\svchost.exe[2280] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 005200A8
.text D:\Program Files\Hercules\Audio\DJ Console Series\HerculesDJControlMP3.EXE[2332] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0005006C
.text D:\Program Files\Hercules\Audio\DJ Console Series\HerculesDJControlMP3.EXE[2332] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00050030
.text D:\Program Files\Hercules\Audio\DJ Console Series\HerculesDJControlMP3.EXE[2332] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00090120
.text D:\Program Files\Hercules\Audio\DJ Console Series\HerculesDJControlMP3.EXE[2332] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0009006C
.text D:\Program Files\Hercules\Audio\DJ Console Series\HerculesDJControlMP3.EXE[2332] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 000900E4
.text D:\Program Files\Hercules\Audio\DJ Console Series\HerculesDJControlMP3.EXE[2332] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00090030
.text D:\Program Files\Hercules\Audio\DJ Console Series\HerculesDJControlMP3.EXE[2332] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 000900A8
.text c:\Program Files\Hewlett-Packard\HP QuickLook\HPDayStarterService.exe[2392] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text c:\Program Files\Hewlett-Packard\HP QuickLook\HPDayStarterService.exe[2392] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text c:\Program Files\Hewlett-Packard\HP QuickLook\HPDayStarterService.exe[2392] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 001F0120
.text c:\Program Files\Hewlett-Packard\HP QuickLook\HPDayStarterService.exe[2392] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 001F006C
.text c:\Program Files\Hewlett-Packard\HP QuickLook\HPDayStarterService.exe[2392] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001F00E4
.text c:\Program Files\Hewlett-Packard\HP QuickLook\HPDayStarterService.exe[2392] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 001F0030
.text c:\Program Files\Hewlett-Packard\HP QuickLook\HPDayStarterService.exe[2392] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001F00A8
.text C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe[2428] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe[2428] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe[2428] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 000F0120
.text C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe[2428] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 000F006C
.text C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe[2428] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 000F00E4
.text C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe[2428] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 000F0030
.text C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe[2428] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 000F00A8
.text C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe[2464] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe[2464] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe[2464] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00200120
.text C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe[2464] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0020006C
.text C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe[2464] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 002000E4
.text C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe[2464] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00200030
.text C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe[2464] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 002000A8
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2492] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2492] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2492] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00220120
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2492] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0022006C
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2492] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 002200E4
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2492] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00220030
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2492] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 002200A8
.text C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2540] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2540] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2540] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00200120
.text C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2540] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0020006C
.text C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2540] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 002000E4
.text C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2540] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00200030
.text C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2540] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 002000A8
.text C:\Program Files\PDF Complete\pdfsvc.exe[2572] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text C:\Program Files\PDF Complete\pdfsvc.exe[2572] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text C:\Program Files\PDF Complete\pdfsvc.exe[2572] user32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 001F0120
.text C:\Program Files\PDF Complete\pdfsvc.exe[2572] user32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 001F006C
.text C:\Program Files\PDF Complete\pdfsvc.exe[2572] user32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001F00E4
.text C:\Program Files\PDF Complete\pdfsvc.exe[2572] user32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 001F0030
.text C:\Program Files\PDF Complete\pdfsvc.exe[2572] user32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001F00A8
.text c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[2636] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0015006C
.text c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[2636] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00150030
.text c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[2636] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 001F0120
.text c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[2636] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 001F006C
.text c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[2636] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001F00E4
.text c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[2636] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 001F0030
.text c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[2636] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001F00A8
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[2664] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[2664] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[2664] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00150120
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[2664] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0015006C
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[2664] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001500E4
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[2664] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00150030
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[2664] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001500A8
.text D:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe[2780] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text D:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe[2780] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text D:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe[2780] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 001F0120
.text D:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe[2780] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 001F006C
.text D:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe[2780] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001F00E4
.text D:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe[2780] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 001F0030
.text D:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe[2780] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001F00A8
.text C:\windows\system32\uArcCapture.exe[2808] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text C:\windows\system32\uArcCapture.exe[2808] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text C:\windows\system32\uArcCapture.exe[2808] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 001F0120
.text C:\windows\Explorer.EXE[1328] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\windows\Explorer.EXE[1328] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00150120
.text C:\windows\Explorer.EXE[1328] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0015006C
.text C:\windows\Explorer.EXE[1328] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001500E4
.text C:\windows\Explorer.EXE[1328] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00150030
.text C:\windows\Explorer.EXE[1328] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001500A8
.text C:\windows\system32\svchost.exe[1416] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 000A006C
.text C:\windows\system32\svchost.exe[1416] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 000A0030
.text C:\windows\system32\svchost.exe[1416] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00A10120
.text C:\windows\system32\svchost.exe[1416] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 00A1006C
.text C:\windows\system32\svchost.exe[1416] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 00A100E4
.text C:\windows\system32\svchost.exe[1416] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00A10030
.text C:\windows\system32\svchost.exe[1416] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 00A100A8
.text C:\windows\system32\Hpservice.exe[1488] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\windows\system32\Hpservice.exe[1488] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\windows\system32\Hpservice.exe[1488] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00090120
.text C:\windows\system32\Hpservice.exe[1488] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0009006C
.text C:\windows\system32\Hpservice.exe[1488] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 000900E4
.text C:\windows\system32\Hpservice.exe[1488] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00090030
.text C:\windows\system32\Hpservice.exe[1488] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 000900A8
.text C:\windows\system32\svchost.exe[1676] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\windows\system32\svchost.exe[1676] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\windows\system32\svchost.exe[1676] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00EE0120
.text C:\windows\system32\svchost.exe[1676] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 00EE006C
.text C:\windows\system32\svchost.exe[1676] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 00EE00E4
.text C:\windows\system32\svchost.exe[1676] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00EE0030
.text C:\windows\system32\svchost.exe[1676] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 00EE00A8
.text C:\Windows\System32\ZoneLabs\vsmon.exe[1732] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\Windows\System32\ZoneLabs\vsmon.exe[1732] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\Windows\System32\ZoneLabs\vsmon.exe[1732] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 000C0120
.text C:\Windows\System32\ZoneLabs\vsmon.exe[1732] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 000C006C
.text C:\Windows\System32\ZoneLabs\vsmon.exe[1732] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 000C00E4
.text C:\Windows\System32\ZoneLabs\vsmon.exe[1732] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 000C0030
.text C:\Windows\System32\ZoneLabs\vsmon.exe[1732] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 000C00A8
.text C:\windows\system32\DllHost.exe[1908] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0005006C
.text C:\windows\system32\DllHost.exe[1908] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00050030
.text C:\windows\system32\DllHost.exe[1908] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 000E0120
.text C:\windows\system32\DllHost.exe[1908] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 000E006C
.text C:\windows\system32\DllHost.exe[1908] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 000E00E4
.text C:\windows\system32\DllHost.exe[1908] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 000E0030
.text C:\windows\system32\DllHost.exe[1908] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 000E00A8
.text C:\windows\System32\spoolsv.exe[1968] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 000A006C
.text C:\windows\System32\spoolsv.exe[1968] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 000A0030
.text C:\windows\System32\spoolsv.exe[1968] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00240120
.text C:\windows\System32\spoolsv.exe[1968] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0024006C
.text C:\windows\System32\spoolsv.exe[1968] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 002400E4
.text C:\windows\System32\spoolsv.exe[1968] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00240030
.text C:\windows\System32\spoolsv.exe[1968] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 002400A8
.text D:\Program Files\Alwil Software\Avast5\AvastSvc.exe[2032] kernel32.dll!SetUnhandledExceptionFilter 76CA3D01 4 Bytes [C2, 04, 00, 90] {RET 0x4; NOP }
.text c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe[2044] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe[2044] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe[2044] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 001F0120
.text c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe[2044] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 001F006C
.text c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe[2044] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001F00E4
.text c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe[2044] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 001F0030
.text c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe[2044] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001F00A8
.text C:\windows\System32\svchost.exe[2116] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\windows\System32\svchost.exe[2116] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\windows\System32\svchost.exe[2116] user32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00470120
.text C:\windows\System32\svchost.exe[2116] user32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0047006C
.text C:\windows\System32\svchost.exe[2116] user32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 004700E4
.text C:\windows\System32\svchost.exe[2116] user32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00470030
.text C:\windows\System32\svchost.exe[2116] user32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 004700A8
.text C:\windows\system32\svchost.exe[2124] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 000A006C
.text C:\windows\system32\svchost.exe[2124] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 000A0030
.text C:\windows\system32\svchost.exe[2124] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00370120
.text C:\windows\system32\svchost.exe[2124] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0037006C
.text C:\windows\system32\svchost.exe[2124] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 003700E4
.text C:\windows\system32\svchost.exe[2124] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00370030
.text C:\windows\system32\svchost.exe[2124] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 003700A8
.text C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe[2136] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe[2136] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe[2136] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00310120
.text C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe[2136] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0031006C
.text C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe[2136] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 003100E4
.text C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe[2136] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00310030
.text C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe[2136] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 003100A8
.text C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9fc8b38ddee9fbba\aestsrv.exe[2204] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9fc8b38ddee9fbba\aestsrv.exe[2204] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe[2252] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe[2252] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe[2252] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00200120
.text C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe[2252] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0020006C
.text C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe[2252] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 002000E4
.text C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe[2252] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00200030
.text C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe[2252] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 002000A8
.text C:\windows\system32\svchost.exe[2280] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\windows\system32\svchost.exe[2280] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\windows\system32\svchost.exe[2280] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00520120
.text C:\windows\system32\svchost.exe[2280] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0052006C
.text C:\windows\system32\svchost.exe[2280] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 005200E4
.text C:\windows\system32\svchost.exe[2280] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00520030
.text C:\windows\system32\svchost.exe[2280] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 005200A8
.text D:\Program Files\Hercules\Audio\DJ Console Series\HerculesDJControlMP3.EXE[2332] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0005006C
.text D:\Program Files\Hercules\Audio\DJ Console Series\HerculesDJControlMP3.EXE[2332] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00050030
.text D:\Program Files\Hercules\Audio\DJ Console Series\HerculesDJControlMP3.EXE[2332] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00090120
.text D:\Program Files\Hercules\Audio\DJ Console Series\HerculesDJControlMP3.EXE[2332] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0009006C
.text D:\Program Files\Hercules\Audio\DJ Console Series\HerculesDJControlMP3.EXE[2332] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 000900E4
.text D:\Program Files\Hercules\Audio\DJ Console Series\HerculesDJControlMP3.EXE[2332] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00090030
.text D:\Program Files\Hercules\Audio\DJ Console Series\HerculesDJControlMP3.EXE[2332] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 000900A8
.text c:\Program Files\Hewlett-Packard\HP QuickLook\HPDayStarterService.exe[2392] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text c:\Program Files\Hewlett-Packard\HP QuickLook\HPDayStarterService.exe[2392] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text c:\Program Files\Hewlett-Packard\HP QuickLook\HPDayStarterService.exe[2392] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 001F0120
.text c:\Program Files\Hewlett-Packard\HP QuickLook\HPDayStarterService.exe[2392] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 001F006C
.text c:\Program Files\Hewlett-Packard\HP QuickLook\HPDayStarterService.exe[2392] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001F00E4
.text c:\Program Files\Hewlett-Packard\HP QuickLook\HPDayStarterService.exe[2392] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 001F0030
.text c:\Program Files\Hewlett-Packard\HP QuickLook\HPDayStarterService.exe[2392] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001F00A8
.text C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe[2428] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe[2428] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe[2428] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 000F0120
.text C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe[2428] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 000F006C
.text C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe[2428] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 000F00E4
.text C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe[2428] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 000F0030
.text C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe[2428] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 000F00A8
.text C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe[2464] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe[2464] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe[2464] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00200120
.text C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe[2464] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0020006C
.text C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe[2464] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 002000E4
.text C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe[2464] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00200030
.text C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe[2464] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 002000A8
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2492] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2492] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2492] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00220120
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2492] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0022006C
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2492] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 002200E4
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2492] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00220030
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2492] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 002200A8
.text C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2540] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2540] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2540] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00200120
.text C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2540] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0020006C
.text C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2540] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 002000E4
.text C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2540] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00200030
.text C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2540] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 002000A8
.text C:\Program Files\PDF Complete\pdfsvc.exe[2572] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text C:\Program Files\PDF Complete\pdfsvc.exe[2572] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text C:\Program Files\PDF Complete\pdfsvc.exe[2572] user32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 001F0120
.text C:\Program Files\PDF Complete\pdfsvc.exe[2572] user32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 001F006C
.text C:\Program Files\PDF Complete\pdfsvc.exe[2572] user32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001F00E4
.text C:\Program Files\PDF Complete\pdfsvc.exe[2572] user32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 001F0030
.text C:\Program Files\PDF Complete\pdfsvc.exe[2572] user32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001F00A8
.text c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[2636] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0015006C
.text c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[2636] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00150030
.text c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[2636] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 001F0120
.text c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[2636] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 001F006C
.text c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[2636] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001F00E4
.text c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[2636] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 001F0030
.text c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[2636] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001F00A8
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[2664] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[2664] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[2664] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00150120
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[2664] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0015006C
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[2664] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001500E4
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[2664] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00150030
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[2664] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001500A8
.text D:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe[2780] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text D:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe[2780] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text D:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe[2780] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 001F0120
.text D:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe[2780] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 001F006C
.text D:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe[2780] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001F00E4
.text D:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe[2780] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 001F0030
.text D:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe[2780] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001F00A8
.text C:\windows\system32\uArcCapture.exe[2808] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text C:\windows\system32\uArcCapture.exe[2808] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text C:\windows\system32\uArcCapture.exe[2808] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 001F0120
-
- Vzorný návštěvník
- Příspěvky: 208
- Registrován: 07 čer 2010 17:54
- Bydliště: SK
- Kontaktovat uživatele:
Re: Preventívka..... -pre motji
.text C:\windows\system32\uArcCapture.exe[2808] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 001F006C
.text C:\windows\system32\uArcCapture.exe[2808] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001F00E4
.text C:\windows\system32\uArcCapture.exe[2808] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 001F0030
.text C:\windows\system32\uArcCapture.exe[2808] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001F00A8
.text C:\windows\System32\svchost.exe[2828] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\windows\System32\svchost.exe[2828] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\windows\System32\svchost.exe[2828] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00180120
.text C:\windows\System32\svchost.exe[2828] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0018006C
.text C:\windows\System32\svchost.exe[2828] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001800E4
.text C:\windows\System32\svchost.exe[2828] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00180030
.text C:\windows\System32\svchost.exe[2828] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001800A8
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2860] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 000A006C
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2860] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 000A0030
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2860] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 000D0120
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2860] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 000D006C
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2860] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 000D00E4
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2860] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 000D0030
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2860] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 000D00A8
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[2948] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[2948] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[2948] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 001F0120
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[2948] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 001F006C
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[2948] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001F00E4
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[2948] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 001F0030
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[2948] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001F00A8
.text C:\Program Files\Syncrosoft\POS\H2O\cledx.exe[3156] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0015006C
.text C:\Program Files\Syncrosoft\POS\H2O\cledx.exe[3156] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00150030
.text C:\Program Files\Syncrosoft\POS\H2O\cledx.exe[3156] User32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00210120
.text C:\Program Files\Syncrosoft\POS\H2O\cledx.exe[3156] User32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0021006C
.text C:\Program Files\Syncrosoft\POS\H2O\cledx.exe[3156] User32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 002100E4
.text C:\Program Files\Syncrosoft\POS\H2O\cledx.exe[3156] User32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00210030
.text C:\Program Files\Syncrosoft\POS\H2O\cledx.exe[3156] User32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 002100A8
.text C:\Windows\System32\rundll32.exe[3168] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 000B006C
.text C:\Windows\System32\rundll32.exe[3168] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 000B0030
.text C:\Windows\System32\rundll32.exe[3168] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00140120
.text C:\Windows\System32\rundll32.exe[3168] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0014006C
.text C:\Windows\System32\rundll32.exe[3168] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001400E4
.text C:\Windows\System32\rundll32.exe[3168] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00140030
.text C:\Windows\System32\rundll32.exe[3168] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001400A8
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3172] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3172] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3172] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00140120
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3172] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0014006C
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3172] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001400E4
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3172] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00140030
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3172] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001400A8
.text C:\windows\system32\wbem\unsecapp.exe[3232] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\windows\system32\wbem\unsecapp.exe[3232] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\windows\system32\wbem\unsecapp.exe[3232] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00080120
.text C:\windows\system32\wbem\unsecapp.exe[3232] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0008006C
.text C:\windows\system32\wbem\unsecapp.exe[3232] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 000800E4
.text C:\windows\system32\wbem\unsecapp.exe[3232] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00080030
.text C:\windows\system32\wbem\unsecapp.exe[3232] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 000800A8
.text C:\windows\system32\wbem\wmiprvse.exe[3336] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 000A006C
.text C:\windows\system32\wbem\wmiprvse.exe[3336] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 000A0030
.text C:\windows\system32\wbem\wmiprvse.exe[3336] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00140120
.text C:\windows\system32\wbem\wmiprvse.exe[3336] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0014006C
.text C:\windows\system32\wbem\wmiprvse.exe[3336] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001400E4
.text C:\windows\system32\wbem\wmiprvse.exe[3336] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00140030
.text C:\windows\system32\wbem\wmiprvse.exe[3336] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001400A8
.text D:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe[3432] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text D:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe[3432] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text D:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe[3432] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00230120
.text D:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe[3432] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0023006C
.text D:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe[3432] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 002300E4
.text D:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe[3432] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00230030
.text D:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe[3432] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 002300A8
.text C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe[3436] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe[3436] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe[3436] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00300120
.text C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe[3436] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0030006C
.text C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe[3436] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 003000E4
.text C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe[3436] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00300030
.text C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe[3436] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 003000A8
.text C:\windows\system32\svchost.exe[3508] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\windows\system32\svchost.exe[3508] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\windows\system32\svchost.exe[3748] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\windows\system32\svchost.exe[3748] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\windows\system32\svchost.exe[3748] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00270120
.text C:\windows\system32\svchost.exe[3748] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0027006C
.text C:\windows\system32\svchost.exe[3748] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 002700E4
.text C:\windows\system32\svchost.exe[3748] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00270030
.text C:\windows\system32\svchost.exe[3748] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 002700A8
.text C:\Windows\WindowsMobile\wmdc.exe[4088] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\Windows\WindowsMobile\wmdc.exe[4088] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\Windows\WindowsMobile\wmdc.exe[4088] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00110120
.text C:\Windows\WindowsMobile\wmdc.exe[4088] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0011006C
.text C:\Windows\WindowsMobile\wmdc.exe[4088] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001100E4
.text C:\Windows\WindowsMobile\wmdc.exe[4088] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00110030
.text C:\Windows\WindowsMobile\wmdc.exe[4088] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001100A8
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[4128] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[4128] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[4128] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00580120
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[4128] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0058006C
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[4128] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 005800E4
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[4128] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00580030
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[4128] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 005800A8
.text C:\windows\system32\svchost.exe[4348] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\windows\system32\svchost.exe[4348] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\windows\system32\taskhost.exe[4524] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0005006C
.text C:\windows\system32\taskhost.exe[4524] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00050030
.text C:\windows\system32\taskhost.exe[4524] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 000E0120
.text C:\windows\system32\taskhost.exe[4524] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 000E006C
.text C:\windows\system32\taskhost.exe[4524] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 000E00E4
.text C:\windows\system32\taskhost.exe[4524] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 000E0030
.text C:\windows\system32\taskhost.exe[4524] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 000E00A8
.text C:\Program Files\IDT\WDM\sttray.exe[4532] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text C:\Program Files\IDT\WDM\sttray.exe[4532] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text C:\Program Files\IDT\WDM\sttray.exe[4532] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 001F0120
.text C:\Program Files\IDT\WDM\sttray.exe[4532] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 001F006C
.text C:\Program Files\IDT\WDM\sttray.exe[4532] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001F00E4
.text C:\Program Files\IDT\WDM\sttray.exe[4532] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 001F0030
.text C:\Program Files\IDT\WDM\sttray.exe[4532] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001F00A8
.text C:\windows\system32\atieclxx.exe[4760] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text C:\windows\system32\atieclxx.exe[4760] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text C:\windows\system32\atieclxx.exe[4760] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 001F0120
.text C:\windows\system32\atieclxx.exe[4760] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 001F006C
.text C:\windows\system32\atieclxx.exe[4760] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001F00E4
.text C:\windows\system32\atieclxx.exe[4760] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 001F0030
.text C:\windows\system32\atieclxx.exe[4760] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001F00A8
.text C:\windows\system32\SearchIndexer.exe[4768] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\windows\system32\SearchIndexer.exe[4768] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\windows\system32\SearchIndexer.exe[4768] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00100120
.text C:\windows\system32\SearchIndexer.exe[4768] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0010006C
.text C:\windows\system32\SearchIndexer.exe[4768] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001000E4
.text C:\windows\system32\SearchIndexer.exe[4768] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00100030
.text C:\windows\system32\SearchIndexer.exe[4768] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001000A8
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4904] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4904] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4904] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 002F0120
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4904] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 002F006C
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4904] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 002F00E4
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4904] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 002F0030
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4904] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 002F00A8
.text C:\windows\system32\taskeng.exe[4952] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\windows\system32\taskeng.exe[4952] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\windows\system32\taskeng.exe[4952] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 000F0120
.text C:\windows\system32\taskeng.exe[4952] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 000F006C
.text C:\windows\system32\taskeng.exe[4952] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 000F00E4
.text C:\windows\system32\taskeng.exe[4952] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 000F0030
.text C:\windows\system32\taskeng.exe[4952] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 000F00A8
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[4968] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[4968] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[4968] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00100120
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[4968] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0010006C
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[4968] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001000E4
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[4968] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00100030
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[4968] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001000A8
.text C:\windows\system32\wbem\wmiprvse.exe[5276] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\windows\system32\wbem\wmiprvse.exe[5276] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\windows\system32\wbem\wmiprvse.exe[5276] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00100120
.text C:\windows\system32\wbem\wmiprvse.exe[5276] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0010006C
.text C:\windows\system32\wbem\wmiprvse.exe[5276] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001000E4
.text C:\windows\system32\wbem\wmiprvse.exe[5276] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00100030
.text C:\windows\system32\wbem\wmiprvse.exe[5276] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001000A8
.text C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe[5488] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe[5488] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe[5488] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00240120
.text C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe[5488] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0024006C
.text C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe[5488] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 002400E4
.text C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe[5488] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00240030
.text C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe[5488] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 002400A8
.text C:\windows\system32\uArcCapture.exe[2808] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001F00E4
.text C:\windows\system32\uArcCapture.exe[2808] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 001F0030
.text C:\windows\system32\uArcCapture.exe[2808] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001F00A8
.text C:\windows\System32\svchost.exe[2828] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\windows\System32\svchost.exe[2828] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\windows\System32\svchost.exe[2828] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00180120
.text C:\windows\System32\svchost.exe[2828] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0018006C
.text C:\windows\System32\svchost.exe[2828] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001800E4
.text C:\windows\System32\svchost.exe[2828] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00180030
.text C:\windows\System32\svchost.exe[2828] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001800A8
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2860] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 000A006C
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2860] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 000A0030
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2860] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 000D0120
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2860] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 000D006C
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2860] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 000D00E4
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2860] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 000D0030
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2860] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 000D00A8
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[2948] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[2948] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[2948] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 001F0120
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[2948] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 001F006C
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[2948] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001F00E4
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[2948] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 001F0030
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[2948] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001F00A8
.text C:\Program Files\Syncrosoft\POS\H2O\cledx.exe[3156] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0015006C
.text C:\Program Files\Syncrosoft\POS\H2O\cledx.exe[3156] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00150030
.text C:\Program Files\Syncrosoft\POS\H2O\cledx.exe[3156] User32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00210120
.text C:\Program Files\Syncrosoft\POS\H2O\cledx.exe[3156] User32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0021006C
.text C:\Program Files\Syncrosoft\POS\H2O\cledx.exe[3156] User32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 002100E4
.text C:\Program Files\Syncrosoft\POS\H2O\cledx.exe[3156] User32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00210030
.text C:\Program Files\Syncrosoft\POS\H2O\cledx.exe[3156] User32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 002100A8
.text C:\Windows\System32\rundll32.exe[3168] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 000B006C
.text C:\Windows\System32\rundll32.exe[3168] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 000B0030
.text C:\Windows\System32\rundll32.exe[3168] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00140120
.text C:\Windows\System32\rundll32.exe[3168] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0014006C
.text C:\Windows\System32\rundll32.exe[3168] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001400E4
.text C:\Windows\System32\rundll32.exe[3168] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00140030
.text C:\Windows\System32\rundll32.exe[3168] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001400A8
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3172] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3172] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3172] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00140120
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3172] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0014006C
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3172] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001400E4
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3172] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00140030
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3172] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001400A8
.text C:\windows\system32\wbem\unsecapp.exe[3232] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\windows\system32\wbem\unsecapp.exe[3232] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\windows\system32\wbem\unsecapp.exe[3232] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00080120
.text C:\windows\system32\wbem\unsecapp.exe[3232] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0008006C
.text C:\windows\system32\wbem\unsecapp.exe[3232] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 000800E4
.text C:\windows\system32\wbem\unsecapp.exe[3232] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00080030
.text C:\windows\system32\wbem\unsecapp.exe[3232] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 000800A8
.text C:\windows\system32\wbem\wmiprvse.exe[3336] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 000A006C
.text C:\windows\system32\wbem\wmiprvse.exe[3336] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 000A0030
.text C:\windows\system32\wbem\wmiprvse.exe[3336] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00140120
.text C:\windows\system32\wbem\wmiprvse.exe[3336] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0014006C
.text C:\windows\system32\wbem\wmiprvse.exe[3336] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001400E4
.text C:\windows\system32\wbem\wmiprvse.exe[3336] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00140030
.text C:\windows\system32\wbem\wmiprvse.exe[3336] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001400A8
.text D:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe[3432] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text D:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe[3432] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text D:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe[3432] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00230120
.text D:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe[3432] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0023006C
.text D:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe[3432] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 002300E4
.text D:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe[3432] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00230030
.text D:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe[3432] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 002300A8
.text C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe[3436] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe[3436] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe[3436] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00300120
.text C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe[3436] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0030006C
.text C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe[3436] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 003000E4
.text C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe[3436] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00300030
.text C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe[3436] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 003000A8
.text C:\windows\system32\svchost.exe[3508] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\windows\system32\svchost.exe[3508] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\windows\system32\svchost.exe[3748] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\windows\system32\svchost.exe[3748] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\windows\system32\svchost.exe[3748] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00270120
.text C:\windows\system32\svchost.exe[3748] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0027006C
.text C:\windows\system32\svchost.exe[3748] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 002700E4
.text C:\windows\system32\svchost.exe[3748] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00270030
.text C:\windows\system32\svchost.exe[3748] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 002700A8
.text C:\Windows\WindowsMobile\wmdc.exe[4088] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\Windows\WindowsMobile\wmdc.exe[4088] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\Windows\WindowsMobile\wmdc.exe[4088] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00110120
.text C:\Windows\WindowsMobile\wmdc.exe[4088] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0011006C
.text C:\Windows\WindowsMobile\wmdc.exe[4088] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001100E4
.text C:\Windows\WindowsMobile\wmdc.exe[4088] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00110030
.text C:\Windows\WindowsMobile\wmdc.exe[4088] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001100A8
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[4128] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[4128] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[4128] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00580120
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[4128] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0058006C
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[4128] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 005800E4
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[4128] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00580030
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[4128] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 005800A8
.text C:\windows\system32\svchost.exe[4348] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\windows\system32\svchost.exe[4348] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\windows\system32\taskhost.exe[4524] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0005006C
.text C:\windows\system32\taskhost.exe[4524] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00050030
.text C:\windows\system32\taskhost.exe[4524] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 000E0120
.text C:\windows\system32\taskhost.exe[4524] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 000E006C
.text C:\windows\system32\taskhost.exe[4524] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 000E00E4
.text C:\windows\system32\taskhost.exe[4524] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 000E0030
.text C:\windows\system32\taskhost.exe[4524] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 000E00A8
.text C:\Program Files\IDT\WDM\sttray.exe[4532] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text C:\Program Files\IDT\WDM\sttray.exe[4532] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text C:\Program Files\IDT\WDM\sttray.exe[4532] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 001F0120
.text C:\Program Files\IDT\WDM\sttray.exe[4532] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 001F006C
.text C:\Program Files\IDT\WDM\sttray.exe[4532] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001F00E4
.text C:\Program Files\IDT\WDM\sttray.exe[4532] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 001F0030
.text C:\Program Files\IDT\WDM\sttray.exe[4532] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001F00A8
.text C:\windows\system32\atieclxx.exe[4760] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text C:\windows\system32\atieclxx.exe[4760] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text C:\windows\system32\atieclxx.exe[4760] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 001F0120
.text C:\windows\system32\atieclxx.exe[4760] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 001F006C
.text C:\windows\system32\atieclxx.exe[4760] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001F00E4
.text C:\windows\system32\atieclxx.exe[4760] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 001F0030
.text C:\windows\system32\atieclxx.exe[4760] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001F00A8
.text C:\windows\system32\SearchIndexer.exe[4768] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\windows\system32\SearchIndexer.exe[4768] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\windows\system32\SearchIndexer.exe[4768] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00100120
.text C:\windows\system32\SearchIndexer.exe[4768] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0010006C
.text C:\windows\system32\SearchIndexer.exe[4768] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001000E4
.text C:\windows\system32\SearchIndexer.exe[4768] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00100030
.text C:\windows\system32\SearchIndexer.exe[4768] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001000A8
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4904] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4904] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4904] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 002F0120
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4904] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 002F006C
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4904] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 002F00E4
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4904] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 002F0030
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4904] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 002F00A8
.text C:\windows\system32\taskeng.exe[4952] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\windows\system32\taskeng.exe[4952] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\windows\system32\taskeng.exe[4952] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 000F0120
.text C:\windows\system32\taskeng.exe[4952] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 000F006C
.text C:\windows\system32\taskeng.exe[4952] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 000F00E4
.text C:\windows\system32\taskeng.exe[4952] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 000F0030
.text C:\windows\system32\taskeng.exe[4952] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 000F00A8
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[4968] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[4968] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[4968] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00100120
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[4968] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0010006C
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[4968] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001000E4
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[4968] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00100030
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[4968] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001000A8
.text C:\windows\system32\wbem\wmiprvse.exe[5276] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\windows\system32\wbem\wmiprvse.exe[5276] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\windows\system32\wbem\wmiprvse.exe[5276] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00100120
.text C:\windows\system32\wbem\wmiprvse.exe[5276] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0010006C
.text C:\windows\system32\wbem\wmiprvse.exe[5276] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001000E4
.text C:\windows\system32\wbem\wmiprvse.exe[5276] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00100030
.text C:\windows\system32\wbem\wmiprvse.exe[5276] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001000A8
.text C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe[5488] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe[5488] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe[5488] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00240120
.text C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe[5488] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0024006C
.text C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe[5488] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 002400E4
.text C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe[5488] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00240030
.text C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe[5488] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 002400A8
-
- Vzorný návštěvník
- Příspěvky: 208
- Registrován: 07 čer 2010 17:54
- Bydliště: SK
- Kontaktovat uživatele:
Re: Preventívka..... -pre motji
.text C:\windows\system32\SearchProtocolHost.exe[5584] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0005006C
.text C:\windows\system32\SearchProtocolHost.exe[5584] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00050030
.text C:\windows\system32\SearchProtocolHost.exe[5584] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 000F0120
.text C:\windows\system32\SearchProtocolHost.exe[5584] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 000F006C
.text C:\windows\system32\SearchProtocolHost.exe[5584] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 000F00E4
.text C:\windows\system32\SearchProtocolHost.exe[5584] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 000F0030
.text C:\windows\system32\SearchProtocolHost.exe[5584] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 000F00A8
.text C:\Program Files\Hewlett-Packard\File Sanitizer\coreshredder.exe[5936] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text C:\Program Files\Hewlett-Packard\File Sanitizer\coreshredder.exe[5936] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text C:\Program Files\Hewlett-Packard\File Sanitizer\coreshredder.exe[5936] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 002F0120
.text C:\Program Files\Hewlett-Packard\File Sanitizer\coreshredder.exe[5936] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 002F006C
.text C:\Program Files\Hewlett-Packard\File Sanitizer\coreshredder.exe[5936] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 002F00E4
.text C:\Program Files\Hewlett-Packard\File Sanitizer\coreshredder.exe[5936] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 002F0030
.text C:\Program Files\Hewlett-Packard\File Sanitizer\coreshredder.exe[5936] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 002F00A8
.text C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[6760] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[6760] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[6760] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00240120
.text C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[6760] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0024006C
.text C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[6760] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 002400E4
.text C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[6760] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00240030
.text C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[6760] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 002400A8
.text C:\Users\Admin\Desktop\gmer.exe[6824] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text C:\Users\Admin\Desktop\gmer.exe[6824] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text C:\Users\Admin\Desktop\gmer.exe[6824] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00220120
.text C:\Users\Admin\Desktop\gmer.exe[6824] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0022006C
.text C:\Users\Admin\Desktop\gmer.exe[6824] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 002200E4
.text C:\Users\Admin\Desktop\gmer.exe[6824] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00220030
.text C:\Users\Admin\Desktop\gmer.exe[6824] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 002200A8
.text D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[7136] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[7136] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[7136] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00250120
.text D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[7136] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0025006C
.text D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[7136] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 002500E4
.text D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[7136] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00250030
.text D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[7136] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 002500A8
.text C:\windows\system32\Dwm.exe[7584] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\windows\system32\Dwm.exe[7584] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\windows\system32\Dwm.exe[7584] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00140120
.text C:\windows\system32\Dwm.exe[7584] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0014006C
.text C:\windows\system32\Dwm.exe[7584] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001400E4
.text C:\windows\system32\Dwm.exe[7584] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00140030
.text C:\windows\system32\Dwm.exe[7584] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001400A8
.text C:\windows\System32\svchost.exe[7612] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\windows\System32\svchost.exe[7612] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\windows\system32\winlogon.exe[8184] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0003006C
.text C:\windows\system32\winlogon.exe[8184] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00030030
.text C:\windows\system32\winlogon.exe[8184] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 000C0120
.text C:\windows\system32\winlogon.exe[8184] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 000C006C
.text C:\windows\system32\winlogon.exe[8184] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 000C00E4
.text C:\windows\system32\winlogon.exe[8184] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 000C0030
.text C:\windows\system32\winlogon.exe[8184] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 000C00A8
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \SystemRoot\system32\DRIVERS\VMNetSrv.sys[NDIS.SYS!NdisCloseAdapter] [90EAF100] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\VMNetSrv.sys[NDIS.SYS!NdisOpenAdapter] [90EAE90E] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\VMNetSrv.sys[NDIS.SYS!NdisDeregisterProtocol] [90EAD06C] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\VMNetSrv.sys[NDIS.SYS!NdisRegisterProtocol] [90EAEAB8] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisCloseAdapter] [90EAF100] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisOpenAdapter] [90EAE90E] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisDeregisterProtocol] [90EAD06C] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisRegisterProtocol] [90EAEAB8] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRegisterProtocol] [90EAEAB8] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisCloseAdapter] [90EAF100] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisOpenAdapter] [90EAE90E] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisDeregisterProtocol] [90EAD06C] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRegisterProtocol] [90EAEAB8] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisDeregisterProtocol] [90EAD06C] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisCloseAdapter] [90EAF100] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisOpenAdapter] [90EAE90E] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\windows\Explorer.EXE[1328] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [73F82437] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1328] @ C:\windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [73F65600] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1328] @ C:\windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [73F656BE] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1328] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipFree] [73F824B2] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1328] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [73F78514] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1328] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [73F74CC8] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1328] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [73F7506F] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1328] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [73F75144] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1328] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [73F76671] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1328] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [73F7826B] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1328] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [73F787BA] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1328] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [73F7901B] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1328] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [73F7E1BE] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1328] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [73F74BFA] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[3168] @ C:\windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [751CFFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[3168] @ C:\windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [751CFFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[3168] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [751CFFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[3168] @ C:\windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [751CFFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 869F11E8
Device \FileSystem\fastfat \FatCdrom 87AA41E8
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
Device \Driver\usbehci \Device\USBPDO-0 87AAD1E8
Device \Driver\usbehci \Device\USBPDO-1 87AAD1E8
Device \Driver\ACPI_HAL \Device\00000055 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\NetBT \Device\NetBT_Tcpip_{3F2991A9-E4CB-4840-A808-B1425092A4F7} 8784F1E8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\cdrom \Device\CdRom0 877231E8
Device \Driver\iaStor \Device\Ide\iaStor0 [8BB3F390] \SystemRoot\system32\DRIVERS\iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-0 [8BB3F390] \SystemRoot\system32\DRIVERS\iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-1 [8BB3F390] \SystemRoot\system32\DRIVERS\iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\NetBT \Device\NetBt_Wins_Export 8784F1E8
AttachedDevice \Driver\tdx \Device\Udp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
Device \Driver\BTHUSB \Device\00000089 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
Device \Driver\BTHUSB \Device\00000089 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
Device \Driver\usbehci \Device\USBFDO-0 87AAD1E8
Device \Driver\usbehci \Device\USBFDO-1 87AAD1E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{BAB71129-EF19-4438-A8D6-E234585981B2} 8784F1E8
Device \Driver\BTHUSB \Device\0000008b bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
Device \Driver\BTHUSB \Device\0000008b bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
Device \FileSystem\fastfat \Fat 87AA41E8
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet001\services\BTHPORT\Parameters\Keys\002713c6c2b3 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\ControlSet001\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet001\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x85 0xA6 0x5A 0x36 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\002713c6c2b3
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x85 0xA6 0x5A 0x36 ...
Reg HKLM\SYSTEM\ControlSet003\services\BTHPORT\Parameters\Keys\002713c6c2b3 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\ControlSet003\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet003\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x85 0xA6 0x5A 0x36 ...
Reg HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted@D:\torrentdownload\IZotope Ozone\x2122 v4.01 + Keygen [GLADRAG_MANHUNT] [H33T]\iZotope_Ozone_Setup_v4_01.exe 1
Reg HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted@C:\Users\Admin\Downloads\Amazing Hardstyle Kick .flp by DJ Frozen\Amazing Hardstyle Kick .flp by DJ Frozen\VST\xb4s Used\V-Station 1.20\Novation.V-Station.VSTi.v1.5.1.incl.Keygen-AiR\Novation.V-Station.VSTi.v1.5.1.incl.Keygen-AiR\Setup.exe 1
---- EOF - GMER 1.0.15 ----
Ak je tam niečo viackrát tak prepáč....
.text C:\windows\system32\SearchProtocolHost.exe[5584] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00050030
.text C:\windows\system32\SearchProtocolHost.exe[5584] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 000F0120
.text C:\windows\system32\SearchProtocolHost.exe[5584] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 000F006C
.text C:\windows\system32\SearchProtocolHost.exe[5584] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 000F00E4
.text C:\windows\system32\SearchProtocolHost.exe[5584] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 000F0030
.text C:\windows\system32\SearchProtocolHost.exe[5584] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 000F00A8
.text C:\Program Files\Hewlett-Packard\File Sanitizer\coreshredder.exe[5936] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text C:\Program Files\Hewlett-Packard\File Sanitizer\coreshredder.exe[5936] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text C:\Program Files\Hewlett-Packard\File Sanitizer\coreshredder.exe[5936] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 002F0120
.text C:\Program Files\Hewlett-Packard\File Sanitizer\coreshredder.exe[5936] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 002F006C
.text C:\Program Files\Hewlett-Packard\File Sanitizer\coreshredder.exe[5936] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 002F00E4
.text C:\Program Files\Hewlett-Packard\File Sanitizer\coreshredder.exe[5936] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 002F0030
.text C:\Program Files\Hewlett-Packard\File Sanitizer\coreshredder.exe[5936] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 002F00A8
.text C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[6760] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[6760] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[6760] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00240120
.text C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[6760] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0024006C
.text C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[6760] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 002400E4
.text C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[6760] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00240030
.text C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[6760] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 002400A8
.text C:\Users\Admin\Desktop\gmer.exe[6824] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0016006C
.text C:\Users\Admin\Desktop\gmer.exe[6824] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00160030
.text C:\Users\Admin\Desktop\gmer.exe[6824] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00220120
.text C:\Users\Admin\Desktop\gmer.exe[6824] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0022006C
.text C:\Users\Admin\Desktop\gmer.exe[6824] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 002200E4
.text C:\Users\Admin\Desktop\gmer.exe[6824] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00220030
.text C:\Users\Admin\Desktop\gmer.exe[6824] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 002200A8
.text D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[7136] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[7136] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[7136] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00250120
.text D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[7136] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0025006C
.text D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[7136] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 002500E4
.text D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[7136] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00250030
.text D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe[7136] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 002500A8
.text C:\windows\system32\Dwm.exe[7584] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\windows\system32\Dwm.exe[7584] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\windows\system32\Dwm.exe[7584] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 00140120
.text C:\windows\system32\Dwm.exe[7584] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 0014006C
.text C:\windows\system32\Dwm.exe[7584] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 001400E4
.text C:\windows\system32\Dwm.exe[7584] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 00140030
.text C:\windows\system32\Dwm.exe[7584] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 001400A8
.text C:\windows\System32\svchost.exe[7612] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0006006C
.text C:\windows\System32\svchost.exe[7612] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00060030
.text C:\windows\system32\winlogon.exe[8184] ntdll.dll!LdrUnloadDll 7719C8DE 5 Bytes JMP 0003006C
.text C:\windows\system32\winlogon.exe[8184] ntdll.dll!LdrLoadDll 771A22B8 5 Bytes JMP 00030030
.text C:\windows\system32\winlogon.exe[8184] USER32.dll!UnhookWindowsHookEx 76B5ADF9 5 Bytes JMP 000C0120
.text C:\windows\system32\winlogon.exe[8184] USER32.dll!UnhookWinEvent 76B5B750 5 Bytes JMP 000C006C
.text C:\windows\system32\winlogon.exe[8184] USER32.dll!SetWindowsHookExW 76B5E30C 5 Bytes JMP 000C00E4
.text C:\windows\system32\winlogon.exe[8184] USER32.dll!SetWinEventHook 76B624DC 5 Bytes JMP 000C0030
.text C:\windows\system32\winlogon.exe[8184] USER32.dll!SetWindowsHookExA 76B86D0C 5 Bytes JMP 000C00A8
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \SystemRoot\system32\DRIVERS\VMNetSrv.sys[NDIS.SYS!NdisCloseAdapter] [90EAF100] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\VMNetSrv.sys[NDIS.SYS!NdisOpenAdapter] [90EAE90E] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\VMNetSrv.sys[NDIS.SYS!NdisDeregisterProtocol] [90EAD06C] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\VMNetSrv.sys[NDIS.SYS!NdisRegisterProtocol] [90EAEAB8] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisCloseAdapter] [90EAF100] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisOpenAdapter] [90EAE90E] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisDeregisterProtocol] [90EAD06C] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisRegisterProtocol] [90EAEAB8] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRegisterProtocol] [90EAEAB8] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisCloseAdapter] [90EAF100] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisOpenAdapter] [90EAE90E] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisDeregisterProtocol] [90EAD06C] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRegisterProtocol] [90EAEAB8] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisDeregisterProtocol] [90EAD06C] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisCloseAdapter] [90EAF100] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisOpenAdapter] [90EAE90E] \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\windows\Explorer.EXE[1328] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [73F82437] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1328] @ C:\windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [73F65600] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1328] @ C:\windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [73F656BE] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1328] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipFree] [73F824B2] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1328] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [73F78514] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1328] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [73F74CC8] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1328] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [73F7506F] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1328] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [73F75144] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1328] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [73F76671] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1328] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [73F7826B] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1328] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [73F787BA] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1328] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [73F7901B] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1328] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [73F7E1BE] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1328] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [73F74BFA] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[3168] @ C:\windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [751CFFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[3168] @ C:\windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [751CFFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[3168] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [751CFFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[3168] @ C:\windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [751CFFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 869F11E8
Device \FileSystem\fastfat \FatCdrom 87AA41E8
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
Device \Driver\usbehci \Device\USBPDO-0 87AAD1E8
Device \Driver\usbehci \Device\USBPDO-1 87AAD1E8
Device \Driver\ACPI_HAL \Device\00000055 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\NetBT \Device\NetBT_Tcpip_{3F2991A9-E4CB-4840-A808-B1425092A4F7} 8784F1E8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\cdrom \Device\CdRom0 877231E8
Device \Driver\iaStor \Device\Ide\iaStor0 [8BB3F390] \SystemRoot\system32\DRIVERS\iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-0 [8BB3F390] \SystemRoot\system32\DRIVERS\iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-1 [8BB3F390] \SystemRoot\system32\DRIVERS\iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\NetBT \Device\NetBt_Wins_Export 8784F1E8
AttachedDevice \Driver\tdx \Device\Udp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
Device \Driver\BTHUSB \Device\00000089 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
Device \Driver\BTHUSB \Device\00000089 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
Device \Driver\usbehci \Device\USBFDO-0 87AAD1E8
Device \Driver\usbehci \Device\USBFDO-1 87AAD1E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{BAB71129-EF19-4438-A8D6-E234585981B2} 8784F1E8
Device \Driver\BTHUSB \Device\0000008b bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
Device \Driver\BTHUSB \Device\0000008b bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
Device \FileSystem\fastfat \Fat 87AA41E8
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet001\services\BTHPORT\Parameters\Keys\002713c6c2b3 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\ControlSet001\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet001\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x85 0xA6 0x5A 0x36 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\002713c6c2b3
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x85 0xA6 0x5A 0x36 ...
Reg HKLM\SYSTEM\ControlSet003\services\BTHPORT\Parameters\Keys\002713c6c2b3 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\ControlSet003\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet003\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x85 0xA6 0x5A 0x36 ...
Reg HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted@D:\torrentdownload\IZotope Ozone\x2122 v4.01 + Keygen [GLADRAG_MANHUNT] [H33T]\iZotope_Ozone_Setup_v4_01.exe 1
Reg HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted@C:\Users\Admin\Downloads\Amazing Hardstyle Kick .flp by DJ Frozen\Amazing Hardstyle Kick .flp by DJ Frozen\VST\xb4s Used\V-Station 1.20\Novation.V-Station.VSTi.v1.5.1.incl.Keygen-AiR\Novation.V-Station.VSTi.v1.5.1.incl.Keygen-AiR\Setup.exe 1
---- EOF - GMER 1.0.15 ----
Ak je tam niečo viackrát tak prepáč....
Re: Preventívka..... -pre motji
Docela vadí, ten driver od daemonu je tam pořád 

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
-
- Vzorný návštěvník
- Příspěvky: 208
- Registrován: 07 čer 2010 17:54
- Bydliště: SK
- Kontaktovat uživatele:
Re: Preventívka..... -pre motji
Po strašne dlhej dobe s5 (poviem Ti to úprimne, vôbec sa mi to nechcelo robiť, ale keď som sa nudil tak som si nato vzpomenul a dokončil to
)
Defogger:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 20:29 on 05/04/2011 (Admin)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
Unable to read SafeBoot.sys
SPTD -> Already disabled
-=E.O.F=-
Gmer (1.):
GMER 1.0.15.15570 - http://www.gmer.net
Rootkit quick scan 2011-04-05 20:36:05
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 TOSHIBA_ rev.LH00
Running: gmer.exe; Driver: C:\Users\Admin\AppData\Local\Temp\pgddapow.sys
---- System - GMER 1.0.15 ----
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwLoadDriver [0x91C1E83C]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\tdx \Device\Udp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----

Defogger:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 20:29 on 05/04/2011 (Admin)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
Unable to read SafeBoot.sys
SPTD -> Already disabled
-=E.O.F=-
Gmer (1.):
GMER 1.0.15.15570 - http://www.gmer.net
Rootkit quick scan 2011-04-05 20:36:05
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 TOSHIBA_ rev.LH00
Running: gmer.exe; Driver: C:\Users\Admin\AppData\Local\Temp\pgddapow.sys
---- System - GMER 1.0.15 ----
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwLoadDriver [0x91C1E83C]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\tdx \Device\Udp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
Re: Preventívka..... -pre motji
Ještě by to chtělo ten druhej log, ale jestli se Ti to už nechce, necháme to tak. Měl jsi tam divný hák na důležitý systémový soubor, chtěla jsem prověřit, zda je to od daemonu.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
-
- Vzorný návštěvník
- Příspěvky: 208
- Registrován: 07 čer 2010 17:54
- Bydliště: SK
- Kontaktovat uživatele:
Re: Preventívka..... -pre motji
2.log som upol, lebo sa mi ho nechcelo deliť (sry):
http://www.mediafire.com/?6arcs6n7asg0sv5
http://www.mediafire.com/?6arcs6n7asg0sv5
Re: Preventívka..... -pre motji
Je to v pořádku.
Odinstalujte combofix přes Start - Spustit
- zkopírujte do okénka:
ComboFix /Uninstall
-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.
***********
Stáhněte T-Cleaner
http://tharifas.sweb.cz/T-Cleaner.exe
-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir
***********
Z mého podpisu stahněte Ccleaner
- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru
záložka čistič
- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner
záložka Registry
- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy
ok
zavřít
Záložka Nástroje
- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.
Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.
***********
Stahněte OTC a použijte
http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech
***********

- zkopírujte do okénka:
ComboFix /Uninstall
-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.
***********

http://tharifas.sweb.cz/T-Cleaner.exe
-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir
***********

- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru

- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner

- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy



- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.
Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.
***********

http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech
***********
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
-
- Vzorný návštěvník
- Příspěvky: 208
- Registrován: 07 čer 2010 17:54
- Bydliště: SK
- Kontaktovat uživatele:
Re: Preventívka..... -pre motji
ešte dodávam log z MBR (použitý ten "script" alebo čo je to...):
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.1.7601 Disk: TOSHIBA_ rev.LH00 -> Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
device: opened successfully
user: MBR read successfully
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys hpdskflt.sys halmacpi.dll ACPI.sys iaStor.sys
C:\windows\system32\DRIVERS\hpdskflt.sys Hewlett-Packard Mobile Data Protection System
C:\windows\system32\DRIVERS\iaStor.sys Intel Corporation Intel Matrix Storage Manager driver
1 ntkrnlpa!IofCallDriver[0x8364C52F] -> \Device\Harddisk0\DR0[0x877A9030]
3 CLASSPNP[0x8C1CF59E] -> ntkrnlpa!IofCallDriver[0x8364C52F] -> [0x877A76D8]
5 hpdskflt[0x8C181090] -> ntkrnlpa!IofCallDriver[0x8364C52F] -> [0x86CEF868]
7 ACPI[0x8BABE3D4] -> ntkrnlpa!IofCallDriver[0x8364C52F] -> \Device\Ide\IAAStorageDevice-1[0x86C92028]
kernel: MBR read successfully
user & kernel MBR OK
a poprosil by som o prezretie tohto DMPu. je to Dump z posledného BSoDu, ktorý mi nabehol asi pred 5-timi minútami, hneď po prihlásení (asi 5 sekúnd po prihlásení a zobrazení plochy).
http://leteckaposta.cz/250289071
Ďakujem.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.1.7601 Disk: TOSHIBA_ rev.LH00 -> Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
device: opened successfully
user: MBR read successfully
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys hpdskflt.sys halmacpi.dll ACPI.sys iaStor.sys
C:\windows\system32\DRIVERS\hpdskflt.sys Hewlett-Packard Mobile Data Protection System
C:\windows\system32\DRIVERS\iaStor.sys Intel Corporation Intel Matrix Storage Manager driver
1 ntkrnlpa!IofCallDriver[0x8364C52F] -> \Device\Harddisk0\DR0[0x877A9030]
3 CLASSPNP[0x8C1CF59E] -> ntkrnlpa!IofCallDriver[0x8364C52F] -> [0x877A76D8]
5 hpdskflt[0x8C181090] -> ntkrnlpa!IofCallDriver[0x8364C52F] -> [0x86CEF868]
7 ACPI[0x8BABE3D4] -> ntkrnlpa!IofCallDriver[0x8364C52F] -> \Device\Ide\IAAStorageDevice-1[0x86C92028]
kernel: MBR read successfully
user & kernel MBR OK
a poprosil by som o prezretie tohto DMPu. je to Dump z posledného BSoDu, ktorý mi nabehol asi pred 5-timi minútami, hneď po prihlásení (asi 5 sekúnd po prihlásení a zobrazení plochy).
http://leteckaposta.cz/250289071
Ďakujem.

Re: Preventívka..... -pre motji
Driver od Gmeru může za Bsod. Poprosím o nový log ze rsitu.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
-
- Vzorný návštěvník
- Příspěvky: 208
- Registrován: 07 čer 2010 17:54
- Bydliště: SK
- Kontaktovat uživatele:
Re: Preventívka..... -pre motji
Logfile of random's system information tool 1.08 (written by random/random)
Run by Admin at 2011-04-07 13:31:19
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 21 GB (42%) free of 50 GB
Total RAM: 2991 MB (61% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:31:29, on 7. 4. 2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal
Running processes:
C:\windows\system32\taskhost.exe
C:\windows\system32\taskeng.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe
C:\Program Files\Hewlett-Packard\File Sanitizer\coreshredder.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
D:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Syncrosoft\POS\H2O\cledx.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\windows\explorer.exe
D:\RSIT.exe
D:\Program Files\Image-Line\FL 9.8 Beta\FL.exe
C:\Program Files\trend micro\Admin.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R3 - URLSearchHook: (no name) - - (no file)
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: BHO_Startup - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files\Hewlett-Packard\File Sanitizer\IEBHO.dll
O2 - BHO: HP ProtectTools Security Manager Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O4 - HKLM\..\Run: [QLBController] C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe
O4 - HKLM\..\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe /hidden
O4 - HKLM\..\Run: [File Sanitizer] C:\Program Files\Hewlett-Packard\File Sanitizer\CoreShredder.exe
O4 - HKLM\..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [DTRun] c:\Program Files\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Hercules DJ Series] D:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe /boot
O4 - HKLM\..\Run: [Creative SB Monitoring Utility] RunDll32 sbavmon.dll,SBAVMonitor
O4 - HKLM\..\Run: [HPPowerAssistant] C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe /hidden
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ICQ] "D:\Program Files\ICQ7.4\ICQ.exe" silent loginmode=4
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\windows\WindowsMobile\INetRepl.dll
O9 - Extra button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - D:\Program Files\ICQ7.4\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - D:\Program Files\ICQ7.4\ICQ.exe
O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - Winlogon Notify: DeviceNP - DeviceNP.dll (file missing)
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9fc8b38ddee9fbba\aestsrv.exe
O23 - Service: AMD External Events Utility - AMD - C:\windows\system32\atiesrxx.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Ltd - c:\Windows\system32\flcdlock.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Hercules DJ Control MP3 (HerculesDJControlMP3) - Unknown owner - D:\Program Files\Hercules\Audio\DJ Console Series\HerculesDJControlMP3.EXE
O23 - Service: HP Health Check Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP Power Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
O23 - Service: HP ProtectTools Service - Hewlett-Packard Development Company, L.P - c:\Program Files\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP DayStarter Service (HPDayStarterService) - Hewlett-Packard Company - c:\Program Files\Hewlett-Packard\HP QuickLook\HPDayStarterService.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: Drive Encryption Service (HpFkCryptService) - McAfee, Inc. - c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
O23 - Service: File Sanitizer for HP ProtectTools (HPFSService) - Hewlett-Packard - C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe
O23 - Service: HP Hotkey Monitor (hpHotkeyMonitor) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard - C:\windows\system32\Hpservice.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9fc8b38ddee9fbba\STacSV.exe
O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - D:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe
O23 - Service: ArcCapture (uArcCapture) - ArcSoft, Inc. - C:\windows\system32\uArcCapture.exe
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\windows\system32\vcsFPService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
--
End of file - 11917 bytes
======Scheduled tasks folder======
C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-3863125621-3407463611-2706026323-1005Core.job
C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-3863125621-3407463611-2706026323-1005UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3134413B-49B4-425C-98A5-893C1F195601}]
File Sanitizer for HP ProtectTools - C:\Program Files\Hewlett-Packard\File Sanitizer\IEBHO.dll [2009-12-12 117248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{395610AE-C624-4f58-B89E-23733EA00F9A}]
HP ProtectTools Security Manager Extension - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll [2009-12-03 1471752]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-09-22 191792]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2011-02-23 814160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files\Windows Live\Companion\companioncore.dll [2010-11-10 393600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2011-02-23 814160]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"QLBController"=C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe [2010-01-05 254520]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2009-08-25 186904]
"PDF Complete"=C:\Program Files\PDF Complete\pdfsty.exe [2009-10-23 563736]
"HPWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe [2009-12-17 8192]
"File Sanitizer"=C:\Program Files\Hewlett-Packard\File Sanitizer\CoreShredder.exe [2009-12-12 11265536]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray.exe [2009-12-03 495711]
"DTRun"=c:\Program Files\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe [2009-11-19 518656]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-06-25 98304]
"Hercules DJ Series"=D:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe [2009-07-09 505128]
"Creative SB Monitoring Utility"=RunDll32 sbavmon.dll,SBAVMonitor []
"HPPowerAssistant"=C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe [2010-08-23 1691192]
"Windows Mobile Device Center"=C:\windows\WindowsMobile\wmdc.exe [2007-05-31 648072]
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2011-02-23 3451496]
"ZoneAlarm Client"=D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe [2010-11-16 1043968]
"H2O"=C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe [2005-10-23 385024]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2009-06-17 2363392]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2010-11-10 4240760]
"ICQ"=D:\Program Files\ICQ7.4\ICQ.exe [2011-03-01 119608]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DeviceNP]
C:\windows\system32\DeviceNP.dll [2009-11-18 75320]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\windows\system32\webcheck.dll [2010-11-20 229376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 months======
2011-04-06 20:30:10 ----A---- C:\windows\system32\drivers\aswSnx.sys
2011-04-06 20:25:07 ----A---- C:\windows\system32\drivers\aswSP.sys
2011-04-06 20:25:07 ----A---- C:\windows\system32\drivers\aswRdr.sys
2011-04-06 20:25:07 ----A---- C:\windows\system32\drivers\aswFsBlk.sys
2011-04-06 20:25:06 ----A---- C:\windows\system32\drivers\aswTdi.sys
2011-04-06 20:25:06 ----A---- C:\windows\system32\drivers\aswMonFlt.sys
2011-04-06 20:24:55 ----A---- C:\windows\system32\aswBoot.exe
2011-04-06 20:24:52 ----D---- C:\Program Files\Alwil Software
2011-03-24 19:13:55 ----A---- C:\TDSSKiller.2.4.21.0_24.03.2011_18.13.55_log.txt
2011-03-22 21:37:11 ----D---- C:\windows\temp
2011-03-22 21:37:09 ----A---- C:\ComboFix.txt
2011-03-22 21:33:37 ----D---- C:\$RECYCLE.BIN
2011-03-22 21:23:02 ----A---- C:\windows\zip.exe
2011-03-22 21:23:02 ----A---- C:\windows\SWSC.exe
2011-03-22 21:23:02 ----A---- C:\windows\SWREG.exe
2011-03-22 21:23:02 ----A---- C:\windows\sed.exe
2011-03-22 21:23:02 ----A---- C:\windows\PEV.exe
2011-03-22 21:23:02 ----A---- C:\windows\NIRCMD.exe
2011-03-22 21:23:02 ----A---- C:\windows\MBR.exe
2011-03-22 21:23:02 ----A---- C:\windows\grep.exe
2011-03-22 21:22:46 ----D---- C:\Qoobox
2011-03-22 21:22:29 ----A---- C:\windows\SWXCACLS.exe
2011-03-22 21:22:26 ----D---- C:\32788R22FWJFW
2011-03-08 21:38:30 ----D---- C:\windows\system32\SPReview
2011-03-08 21:37:42 ----D---- C:\windows\system32\EventProviders
2011-03-08 21:35:02 ----A---- C:\windows\system32\dfshim.dll
2011-03-08 21:34:59 ----A---- C:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2011-03-08 21:34:59 ----A---- C:\windows\system32\drivers\TsUsbFlt.sys
2011-03-08 21:34:58 ----A---- C:\windows\system32\mstscax.dll
2011-03-08 21:34:56 ----A---- C:\windows\system32\mfc40.dll
2011-03-08 21:34:56 ----A---- C:\windows\system32\d3d10warp.dll
2011-03-08 21:34:55 ----A---- C:\windows\system32\sysmain.dll
2011-03-08 21:34:55 ----A---- C:\windows\system32\mfc40u.dll
2011-03-08 21:34:54 ----A---- C:\windows\system32\shell32.dll
2011-03-08 21:34:54 ----A---- C:\windows\system32\secproc_isv.dll
2011-03-08 21:34:53 ----A---- C:\windows\system32\secproc.dll
2011-03-08 21:34:53 ----A---- C:\windows\system32\RMActivate_isv.exe
2011-03-08 21:34:52 ----A---- C:\windows\system32\RMActivate.exe
2011-03-08 21:34:52 ----A---- C:\windows\system32\ieframe.dll
2011-03-08 21:34:51 ----A---- C:\windows\system32\spwizui.dll
2011-03-08 21:34:51 ----A---- C:\windows\system32\mscoree.dll
2011-03-08 21:34:50 ----A---- C:\windows\system32\ntkrnlpa.exe
2011-03-08 21:34:50 ----A---- C:\windows\system32\mf.dll
2011-03-08 21:34:50 ----A---- C:\windows\system32\mcupdate_GenuineIntel.dll
2011-03-08 21:34:49 ----A---- C:\windows\system32\mssrch.dll
2011-03-08 21:34:49 ----A---- C:\windows\system32\iertutil.dll
2011-03-08 21:34:49 ----A---- C:\windows\system32\CertEnroll.dll
2011-03-08 21:34:48 ----A---- C:\windows\system32\wmp.dll
2011-03-08 21:34:48 ----A---- C:\windows\system32\PresentationHostProxy.dll
2011-03-08 21:34:48 ----A---- C:\windows\system32\PresentationHost.exe
2011-03-08 21:34:48 ----A---- C:\windows\system32\esent.dll
2011-03-08 21:34:48 ----A---- C:\windows\system32\drivers\msiscsi.sys
2011-03-08 21:34:48 ----A---- C:\windows\system32\drivers\hwpolicy.sys
2011-03-08 21:34:47 ----A---- C:\windows\system32\tquery.dll
2011-03-08 21:34:47 ----A---- C:\windows\system32\schedsvc.dll
2011-03-08 21:34:47 ----A---- C:\windows\system32\ntoskrnl.exe
2011-03-08 21:34:46 ----A---- C:\windows\system32\RacEngn.dll
2011-03-08 21:34:46 ----A---- C:\windows\system32\ntdll.dll
2011-03-08 21:34:46 ----A---- C:\windows\system32\AuthFWSnapin.dll
2011-03-08 21:34:45 ----A---- C:\windows\system32\wininet.dll
2011-03-08 21:34:45 ----A---- C:\windows\system32\rdpdd.dll
2011-03-08 21:34:45 ----A---- C:\windows\system32\qmgr.dll
2011-03-08 21:34:45 ----A---- C:\windows\system32\ExplorerFrame.dll
2011-03-08 21:34:44 ----A---- C:\windows\system32\wevtsvc.dll
2011-03-08 21:34:44 ----A---- C:\windows\system32\vssapi.dll
2011-03-08 21:34:44 ----A---- C:\windows\system32\urlmon.dll
2011-03-08 21:34:44 ----A---- C:\windows\system32\ole32.dll
2011-03-08 21:34:44 ----A---- C:\windows\system32\drivers\tcpip.sys
2011-03-08 21:34:43 ----A---- C:\windows\system32\taskschd.dll
2011-03-08 21:34:43 ----A---- C:\windows\system32\SearchFolder.dll
2011-03-08 21:34:43 ----A---- C:\windows\system32\IKEEXT.DLL
2011-03-08 21:34:43 ----A---- C:\windows\system32\d3d9.dll
2011-03-08 21:34:43 ----A---- C:\windows\explorer.exe
2011-03-08 21:34:42 ----A---- C:\windows\system32\termsrv.dll
2011-03-08 21:34:42 ----A---- C:\windows\system32\spreview.exe
2011-03-08 21:34:42 ----A---- C:\windows\system32\spinstall.exe
2011-03-08 21:34:42 ----A---- C:\windows\system32\mstsc.exe
2011-03-08 21:34:42 ----A---- C:\windows\system32\kernel32.dll
2011-03-08 21:34:42 ----A---- C:\windows\system32\drivers\ntfs.sys
2011-03-08 21:34:42 ----A---- C:\windows\system32\crypt32.dll
2011-03-08 21:34:41 ----A---- C:\windows\system32\wer.dll
2011-03-08 21:34:41 ----A---- C:\windows\system32\rpcrt4.dll
2011-03-08 21:34:41 ----A---- C:\windows\system32\msxml6.dll
2011-03-08 21:34:41 ----A---- C:\windows\system32\lsasrv.dll
2011-03-08 21:34:41 ----A---- C:\windows\system32\gpsvc.dll
2011-03-08 21:34:41 ----A---- C:\windows\system32\dwmcore.dll
2011-03-08 21:34:41 ----A---- C:\windows\system32\certcli.dll
2011-03-08 21:34:40 ----A---- C:\windows\system32\WinSAT.exe
2011-03-08 21:34:40 ----A---- C:\windows\system32\wbengine.exe
2011-03-08 21:34:40 ----A---- C:\windows\system32\scavengeui.dll
2011-03-08 21:34:40 ----A---- C:\windows\system32\odbc32.dll
2011-03-08 21:34:40 ----A---- C:\windows\system32\mstime.dll
2011-03-08 21:34:40 ----A---- C:\windows\system32\MPSSVC.dll
2011-03-08 21:34:40 ----A---- C:\windows\system32\diagperf.dll
2011-03-08 21:34:39 ----A---- C:\windows\system32\winhttp.dll
2011-03-08 21:34:39 ----A---- C:\windows\system32\TSWorkspace.dll
2011-03-08 21:34:39 ----A---- C:\windows\system32\tsmf.dll
2011-03-08 21:34:39 ----A---- C:\windows\system32\quartz.dll
2011-03-08 21:34:39 ----A---- C:\windows\system32\msfeeds.dll
2011-03-08 21:34:39 ----A---- C:\windows\system32\localspl.dll
2011-03-08 21:34:39 ----A---- C:\windows\system32\iedkcs32.dll
2011-03-08 21:34:39 ----A---- C:\windows\system32\dot3api.dll
2011-03-08 21:34:38 ----A---- C:\windows\system32\VSSVC.exe
2011-03-08 21:34:38 ----A---- C:\windows\system32\setupapi.dll
2011-03-08 21:34:38 ----A---- C:\windows\system32\netlogon.dll
2011-03-08 21:34:38 ----A---- C:\windows\system32\MSVidCtl.dll
2011-03-08 21:34:38 ----A---- C:\windows\system32\drivers\nvstor.sys
2011-03-08 21:34:38 ----A---- C:\windows\system32\dbgeng.dll
2011-03-08 21:34:38 ----A---- C:\windows\system32\apphelp.dll
2011-03-08 21:34:37 ----A---- C:\windows\system32\WindowsCodecs.dll
2011-03-08 21:34:37 ----A---- C:\windows\system32\netcfgx.dll
2011-03-08 21:34:37 ----A---- C:\windows\system32\d3d11.dll
2011-03-08 21:34:36 ----A---- C:\windows\system32\WsmSvc.dll
2011-03-08 21:34:36 ----A---- C:\windows\system32\WMVDECOD.DLL
2011-03-08 21:34:36 ----A---- C:\windows\system32\winlogon.exe
2011-03-08 21:34:36 ----A---- C:\windows\system32\webio.dll
2011-03-08 21:34:36 ----A---- C:\windows\system32\user32.dll
2011-03-08 21:34:36 ----A---- C:\windows\system32\Query.dll
2011-03-08 21:34:36 ----A---- C:\windows\system32\drivers\srv.sys
2011-03-08 21:34:36 ----A---- C:\windows\system32\drivers\rdpwd.sys
2011-03-08 21:34:36 ----A---- C:\windows\system32\advapi32.dll
2011-03-08 21:34:35 ----A---- C:\windows\system32\upnp.dll
2011-03-08 21:34:35 ----A---- C:\windows\system32\schannel.dll
2011-03-08 21:34:35 ----A---- C:\windows\system32\netfxperf.dll
2011-03-08 21:34:35 ----A---- C:\windows\system32\mmcndmgr.dll
2011-03-08 21:34:35 ----A---- C:\windows\system32\DShowRdpFilter.dll
2011-03-08 21:34:35 ----A---- C:\windows\system32\drivers\srv2.sys
2011-03-08 21:34:35 ----A---- C:\windows\system32\drivers\nvraid.sys
2011-03-08 21:34:34 ----A---- C:\windows\system32\sppobjs.dll
2011-03-08 21:34:34 ----A---- C:\windows\system32\SessEnv.dll
2011-03-08 21:34:34 ----A---- C:\windows\system32\PortableDeviceApi.dll
2011-03-08 21:34:34 ----A---- C:\windows\system32\msv1_0.dll
2011-03-08 21:34:34 ----A---- C:\windows\system32\msdrm.dll
2011-03-08 21:34:34 ----A---- C:\windows\system32\lsm.exe
2011-03-08 21:34:34 ----A---- C:\windows\system32\imapi2fs.dll
2011-03-08 21:34:34 ----A---- C:\windows\system32\authui.dll
2011-03-08 21:34:33 ----A---- C:\windows\system32\winload.exe
2011-03-08 21:34:33 ----A---- C:\windows\system32\usp10.dll
2011-03-08 21:34:33 ----A---- C:\windows\system32\userenv.dll
2011-03-08 21:34:33 ----A---- C:\windows\system32\shlwapi.dll
2011-03-08 21:34:33 ----A---- C:\windows\system32\mcbuilder.exe
2011-03-08 21:34:33 ----A---- C:\windows\system32\KernelBase.dll
2011-03-08 21:34:33 ----A---- C:\windows\system32\d3d10_1core.dll
2011-03-08 21:34:33 ----A---- C:\windows\system32\certmgr.dll
2011-03-08 21:34:32 ----A---- C:\windows\system32\xpsservices.dll
2011-03-08 21:34:32 ----A---- C:\windows\system32\WebClnt.dll
2011-03-08 21:34:32 ----A---- C:\windows\system32\umpnpmgr.dll
2011-03-08 21:34:32 ----A---- C:\windows\system32\sppwinob.dll
2011-03-08 21:34:32 ----A---- C:\windows\system32\rpcss.dll
2011-03-08 21:34:32 ----A---- C:\windows\system32\iphlpsvc.dll
2011-03-08 21:34:32 ----A---- C:\windows\system32\comdlg32.dll
2011-03-08 21:34:32 ----A---- C:\windows\system32\cmd.exe
2011-03-08 21:34:32 ----A---- C:\windows\system32\audiosrv.dll
2011-03-08 21:34:31 ----A---- C:\windows\system32\Wldap32.dll
2011-03-08 21:34:31 ----A---- C:\windows\system32\win32spl.dll
2011-03-08 21:34:31 ----A---- C:\windows\system32\propsys.dll
2011-03-08 21:34:31 ----A---- C:\windows\system32\nlasvc.dll
2011-03-08 21:34:31 ----A---- C:\windows\system32\mfds.dll
2011-03-08 21:34:31 ----A---- C:\windows\system32\framedynos.dll
2011-03-08 21:34:31 ----A---- C:\windows\system32\drivers\volsnap.sys
2011-03-08 21:34:31 ----A---- C:\windows\system32\dnsapi.dll
2011-03-08 21:34:31 ----A---- C:\windows\system32\BFE.DLL
2011-03-08 21:34:30 ----A---- C:\windows\system32\wucltux.dll
2011-03-08 21:34:30 ----A---- C:\windows\system32\wuaueng.dll
2011-03-08 21:34:30 ----A---- C:\windows\system32\winresume.exe
2011-03-08 21:34:30 ----A---- C:\windows\system32\samsrv.dll
2011-03-08 21:34:30 ----A---- C:\windows\system32\profsvc.dll
2011-03-08 21:34:30 ----A---- C:\windows\system32\ncsi.dll
2011-03-08 21:34:30 ----A---- C:\windows\system32\drivers\netio.sys
2011-03-08 21:34:30 ----A---- C:\windows\system32\drivers\ndis.sys
2011-03-08 21:34:30 ----A---- C:\windows\system32\azroles.dll
2011-03-08 21:34:29 ----A---- C:\windows\system32\werconcpl.dll
2011-03-08 21:34:29 ----A---- C:\windows\system32\themeui.dll
2011-03-08 21:34:29 ----A---- C:\windows\system32\taskeng.exe
2011-03-08 21:34:29 ----A---- C:\windows\system32\spp.dll
2011-03-08 21:34:29 ----A---- C:\windows\system32\mswsock.dll
2011-03-08 21:34:29 ----A---- C:\windows\system32\drivers\storport.sys
2011-03-08 21:34:29 ----A---- C:\windows\system32\drivers\mrxsmb10.sys
2011-03-08 21:34:29 ----A---- C:\windows\system32\dhcpcore.dll
2011-03-08 21:34:29 ----A---- C:\windows\system32\credui.dll
2011-03-08 21:34:28 ----A---- C:\windows\system32\wintrust.dll
2011-03-08 21:34:28 ----A---- C:\windows\system32\taskcomp.dll
2011-03-08 21:34:28 ----A---- C:\windows\system32\NaturalLanguage6.dll
2011-03-08 21:34:28 ----A---- C:\windows\system32\msxml3.dll
2011-03-08 21:34:28 ----A---- C:\windows\system32\mfreadwrite.dll
2011-03-08 21:34:28 ----A---- C:\windows\system32\inetcomm.dll
2011-03-08 21:34:28 ----A---- C:\windows\system32\evr.dll
2011-03-08 21:34:28 ----A---- C:\windows\system32\dxgi.dll
2011-03-08 21:34:28 ----A---- C:\windows\system32\drivers\mrxdav.sys
2011-03-08 21:34:28 ----A---- C:\windows\system32\drivers\http.sys
2011-03-08 21:34:28 ----A---- C:\windows\system32\dbghelp.dll
2011-03-08 21:34:28 ----A---- C:\windows\system32\basecsp.dll
2011-03-08 21:34:27 ----A---- C:\windows\system32\WinSATAPI.dll
2011-03-08 21:34:27 ----A---- C:\windows\system32\vpnike.dll
2011-03-08 21:34:27 ----A---- C:\windows\system32\sqlsrv32.dll
2011-03-08 21:34:27 ----A---- C:\windows\system32\spoolsv.exe
2011-03-08 21:34:27 ----A---- C:\windows\system32\QAGENTRT.DLL
2011-03-08 21:34:27 ----A---- C:\windows\system32\gdi32.dll
2011-03-08 21:34:27 ----A---- C:\windows\system32\drivers\amdsata.sys
2011-03-08 21:34:27 ----A---- C:\windows\system32\drivers\1394ohci.sys
2011-03-08 21:34:27 ----A---- C:\windows\system32\calc.exe
2011-03-08 21:34:26 ----A---- C:\windows\system32\UIRibbon.dll
2011-03-08 21:34:26 ----A---- C:\windows\system32\sxs.dll
2011-03-08 21:34:26 ----A---- C:\windows\system32\srvsvc.dll
2011-03-08 21:34:26 ----A---- C:\windows\system32\lpksetup.exe
2011-03-08 21:34:26 ----A---- C:\windows\system32\ie4uinit.exe
2011-03-08 21:34:26 ----A---- C:\windows\system32\fveapi.dll
2011-03-08 21:34:26 ----A---- C:\windows\system32\drivers\fvevol.sys
2011-03-08 21:34:26 ----A---- C:\windows\system32\cryptsvc.dll
2011-03-08 21:34:25 ----A---- C:\windows\system32\ws2_32.dll
2011-03-08 21:34:25 ----A---- C:\windows\system32\stobject.dll
2011-03-08 21:34:25 ----A---- C:\windows\system32\prncache.dll
2011-03-08 21:34:25 ----A---- C:\windows\system32\printui.dll
2011-03-08 21:34:25 ----A---- C:\windows\system32\netshell.dll
2011-03-08 21:34:25 ----A---- C:\windows\system32\inetpp.dll
2011-03-08 21:34:25 ----A---- C:\windows\system32\hgprint.dll
2011-03-08 21:34:25 ----A---- C:\windows\system32\drivers\rdbss.sys
2011-03-08 21:34:25 ----A---- C:\windows\system32\drivers\msdsm.sys
2011-03-08 21:34:25 ----A---- C:\windows\system32\comctl32.dll
2011-03-08 21:34:24 ----A---- C:\windows\system32\WSDApi.dll
2011-03-08 21:34:24 ----A---- C:\windows\system32\wmpeffects.dll
2011-03-08 21:34:24 ----A---- C:\windows\system32\rpchttp.dll
2011-03-08 21:34:24 ----A---- C:\windows\system32\net1.exe
2011-03-08 21:34:24 ----A---- C:\windows\system32\msi.dll
2011-03-08 21:34:24 ----A---- C:\windows\system32\dps.dll
2011-03-08 21:34:24 ----A---- C:\windows\system32\dnsrslvr.dll
2011-03-08 21:34:24 ----A---- C:\windows\system32\ci.dll
2011-03-08 21:34:24 ----A---- C:\windows\system32\aitagent.exe
2011-03-08 21:34:24 ----A---- C:\windows\system32\aepdu.dll
2011-03-08 21:34:23 ----A---- C:\windows\system32\vds.exe
2011-03-08 21:34:23 ----A---- C:\windows\system32\scansetting.dll
2011-03-08 21:34:23 ----A---- C:\windows\system32\mfc42u.dll
2011-03-08 21:34:23 ----A---- C:\windows\system32\FXSSVC.exe
2011-03-08 21:34:23 ----A---- C:\windows\system32\drivers\pci.sys
2011-03-08 21:34:23 ----A---- C:\windows\system32\drivers\mrxsmb.sys
2011-03-08 21:34:22 ----A---- C:\windows\system32\WMVCORE.DLL
2011-03-08 21:34:22 ----A---- C:\windows\system32\wlangpui.dll
2011-03-08 21:34:22 ----A---- C:\windows\system32\QSHVHOST.DLL
2011-03-08 21:34:22 ----A---- C:\windows\system32\MMDevAPI.dll
2011-03-08 21:34:22 ----A---- C:\windows\system32\IPSECSVC.DLL
2011-03-08 21:34:22 ----A---- C:\windows\system32\drivers\usbport.sys
2011-03-08 21:34:22 ----A---- C:\windows\system32\drivers\mrxsmb20.sys
2011-03-08 21:34:22 ----A---- C:\windows\system32\davclnt.dll
2011-03-08 21:34:22 ----A---- C:\windows\system32\consent.exe
2011-03-08 21:34:22 ----A---- C:\windows\system32\aaclient.dll
2011-03-08 21:34:21 ----A---- C:\windows\system32\wpdshext.dll
2011-03-08 21:34:21 ----A---- C:\windows\system32\webservices.dll
2011-03-08 21:34:21 ----A---- C:\windows\system32\t2embed.dll
2011-03-08 21:34:21 ----A---- C:\windows\system32\pnidui.dll
2011-03-08 21:34:21 ----A---- C:\windows\system32\fde.dll
2011-03-08 21:34:21 ----A---- C:\windows\system32\drivers\termdd.sys
2011-03-08 21:34:20 ----A---- C:\windows\system32\wuapi.dll
2011-03-08 21:34:20 ----A---- C:\windows\system32\wscapi.dll
2011-03-08 21:34:20 ----A---- C:\windows\system32\TsUsbGDCoInstaller.dll
2011-03-08 21:34:20 ----A---- C:\windows\system32\SyncCenter.dll
2011-03-08 21:34:20 ----A---- C:\windows\system32\sdengin2.dll
2011-03-08 21:34:20 ----A---- C:\windows\system32\netdiagfx.dll
2011-03-08 21:34:20 ----A---- C:\windows\system32\drivers\sbp2port.sys
2011-03-08 21:34:20 ----A---- C:\windows\system32\drivers\amdxata.sys
2011-03-08 21:34:19 ----A---- C:\windows\system32\wisptis.exe
2011-03-08 21:34:19 ----A---- C:\windows\system32\WinSCard.dll
2011-03-08 21:34:19 ----A---- C:\windows\system32\WFS.exe
2011-03-08 21:34:19 ----A---- C:\windows\system32\pla.dll
2011-03-08 21:34:19 ----A---- C:\windows\system32\MSMPEG2ENC.DLL
2011-03-08 21:34:19 ----A---- C:\windows\system32\msasn1.dll
2011-03-08 21:34:19 ----A---- C:\windows\system32\mcmde.dll
2011-03-08 21:34:19 ----A---- C:\windows\system32\drivers\vhdmp.sys
2011-03-08 21:34:18 ----A---- C:\windows\system32\WUDFSvc.dll
2011-03-08 21:34:18 ----A---- C:\windows\system32\winsta.dll
2011-03-08 21:34:18 ----A---- C:\windows\system32\wiaservc.dll
2011-03-08 21:34:18 ----A---- C:\windows\system32\setupcl.exe
2011-03-08 21:34:18 ----A---- C:\windows\system32\rdpcore.dll
2011-03-08 21:34:18 ----A---- C:\windows\system32\ntshrui.dll
2011-03-08 21:34:18 ----A---- C:\windows\system32\imapi2.dll
2011-03-08 21:34:18 ----A---- C:\windows\system32\iepeers.dll
2011-03-08 21:34:18 ----A---- C:\windows\system32\DXPTaskRingtone.dll
2011-03-08 21:34:18 ----A---- C:\windows\system32\drivers\msahci.sys
2011-03-08 21:34:18 ----A---- C:\windows\system32\conhost.exe
2011-03-08 21:34:18 ----A---- C:\windows\system32\aeinv.dll
2011-03-08 21:34:17 ----A---- C:\windows\system32\gameux.dll
2011-03-08 21:34:17 ----A---- C:\windows\system32\dwmredir.dll
2011-03-08 21:34:17 ----A---- C:\windows\system32\drivers\Diskdump.sys
2011-03-08 21:34:16 ----A---- C:\windows\system32\WMPEncEn.dll
2011-03-08 21:34:16 ----A---- C:\windows\system32\winmm.dll
2011-03-08 21:34:16 ----A---- C:\windows\system32\vaultsvc.dll
2011-03-08 21:34:16 ----A---- C:\windows\system32\TabSvc.dll
2011-03-08 21:34:16 ----A---- C:\windows\system32\shsvcs.dll
2011-03-08 21:34:16 ----A---- C:\windows\system32\rasmans.dll
2011-03-08 21:34:16 ----A---- C:\windows\system32\onex.dll
2011-03-08 21:34:16 ----A---- C:\windows\system32\mssvp.dll
2011-03-08 21:34:16 ----A---- C:\windows\system32\hbaapi.dll
2011-03-08 21:34:16 ----A---- C:\windows\system32\drivers\udfs.sys
2011-03-08 21:34:16 ----A---- C:\windows\system32\drivers\acpi.sys
2011-03-08 21:34:16 ----A---- C:\windows\system32\autofmt.exe
2011-03-08 21:34:15 ----A---- C:\windows\system32\samcli.dll
2011-03-08 21:34:15 ----A---- C:\windows\system32\proquota.exe
2011-03-08 21:34:15 ----A---- C:\windows\system32\netiohlp.dll
2011-03-08 21:34:15 ----A---- C:\windows\system32\Narrator.exe
2011-03-08 21:34:15 ----A---- C:\windows\system32\msutb.dll
2011-03-08 21:34:15 ----A---- C:\windows\system32\IPHLPAPI.DLL
2011-03-08 21:34:15 ----A---- C:\windows\system32\halmacpi.dll
2011-03-08 21:34:15 ----A---- C:\windows\system32\hal.dll
2011-03-08 21:34:15 ----A---- C:\windows\system32\bootres.dll
2011-03-08 21:34:15 ----A---- C:\windows\system32\autochk.exe
2011-03-08 21:34:15 ----A---- C:\windows\system32\autoconv.exe
2011-03-08 21:34:15 ----A---- C:\windows\system32\AudioSes.dll
2011-03-08 21:34:15 ----A---- C:\windows\system32\audiodg.exe
2011-03-08 21:34:14 ----A---- C:\windows\system32\wcncsvc.dll
2011-03-08 21:34:14 ----A---- C:\windows\system32\thumbcache.dll
2011-03-08 21:34:14 ----A---- C:\windows\system32\tcpipcfg.dll
2011-03-08 21:34:14 ----A---- C:\windows\system32\srchadmin.dll
2011-03-08 21:34:14 ----A---- C:\windows\system32\schtasks.exe
2011-03-08 21:34:14 ----A---- C:\windows\system32\regapi.dll
2011-03-08 21:34:14 ----A---- C:\windows\system32\powercpl.dll
2011-03-08 21:34:14 ----A---- C:\windows\system32\msinfo32.exe
2011-03-08 21:34:14 ----A---- C:\windows\system32\msihnd.dll
2011-03-08 21:34:14 ----A---- C:\windows\system32\mimefilt.dll
2011-03-08 21:34:14 ----A---- C:\windows\system32\ipsmsnap.dll
2011-03-08 21:34:14 ----A---- C:\windows\system32\framedyn.dll
2011-03-08 21:34:14 ----A---- C:\windows\system32\eapphost.dll
2011-03-08 21:34:14 ----A---- C:\windows\system32\drivers\winusb.sys
2011-03-08 21:34:14 ----A---- C:\windows\system32\drivers\volmgr.sys
2011-03-08 21:34:14 ----A---- C:\windows\system32\drivers\srvnet.sys
2011-03-08 21:34:13 ----A---- C:\windows\system32\umpo.dll
2011-03-08 21:34:13 ----A---- C:\windows\system32\sspicli.dll
2011-03-08 21:34:13 ----A---- C:\windows\system32\QAGENT.DLL
2011-03-08 21:34:13 ----A---- C:\windows\system32\netid.dll
2011-03-08 21:34:13 ----A---- C:\windows\system32\mscorier.dll
2011-03-08 21:34:13 ----A---- C:\windows\system32\FXSCOVER.exe
2011-03-08 21:34:13 ----A---- C:\windows\system32\DXP.dll
2011-03-08 21:34:13 ----A---- C:\windows\system32\drivers\USBSTOR.SYS
2011-03-08 21:34:13 ----A---- C:\windows\system32\drivers\partmgr.sys
2011-03-08 21:34:13 ----A---- C:\windows\system32\drivers\netbt.sys
2011-03-08 21:34:13 ----A---- C:\windows\system32\AuxiliaryDisplayCpl.dll
2011-03-08 21:34:12 ----A---- C:\windows\system32\wdc.dll
2011-03-08 21:34:12 ----A---- C:\windows\system32\untfs.dll
2011-03-08 21:34:12 ----A---- C:\windows\system32\StructuredQuery.dll
2011-03-08 21:34:12 ----A---- C:\windows\system32\scesrv.dll
2011-03-08 21:34:12 ----A---- C:\windows\system32\rastls.dll
2011-03-08 21:34:12 ----A---- C:\windows\system32\oleaut32.dll
2011-03-08 21:34:12 ----A---- C:\windows\system32\drivers\ataport.sys
2011-03-08 21:34:12 ----A---- C:\windows\system32\actxprxy.dll
2011-03-08 21:34:11 ----A---- C:\windows\system32\WMNetMgr.dll
2011-03-08 21:34:11 ----A---- C:\windows\system32\wlanpref.dll
2011-03-08 21:34:11 ----A---- C:\windows\system32\Vault.dll
2011-03-08 21:34:11 ----A---- C:\windows\system32\sppsvc.exe
2011-03-08 21:34:11 ----A---- C:\windows\system32\sdclt.exe
2011-03-08 21:34:11 ----A---- C:\windows\system32\RpcRtRemote.dll
2011-03-08 21:34:11 ----A---- C:\windows\system32\Robocopy.exe
2011-03-08 21:34:11 ----A---- C:\windows\system32\nci.dll
2011-03-08 21:34:11 ----A---- C:\windows\system32\ListSvc.dll
2011-03-08 21:34:11 ----A---- C:\windows\system32\licmgr10.dll
2011-03-08 21:34:10 ----A---- C:\windows\system32\taskmgr.exe
2011-03-08 21:34:10 ----A---- C:\windows\system32\mtxclu.dll
2011-03-08 21:34:10 ----A---- C:\windows\system32\DxpTaskSync.dll
2011-03-08 21:34:10 ----A---- C:\windows\system32\drivers\FWPKCLNT.SYS
2011-03-08 21:34:10 ----A---- C:\windows\system32\Display.dll
2011-03-08 21:34:09 ----A---- C:\windows\system32\XpsRasterService.dll
2011-03-08 21:34:09 ----A---- C:\windows\system32\userinit.exe
2011-03-08 21:34:09 ----A---- C:\windows\system32\sharemediacpl.dll
2011-03-08 21:34:09 ----A---- C:\windows\system32\puiobj.dll
2011-03-08 21:34:09 ----A---- C:\windows\system32\mssphtb.dll
2011-03-08 21:34:09 ----A---- C:\windows\system32\msdri.dll
2011-03-08 21:34:09 ----A---- C:\windows\system32\drivers\usbvideo.sys
2011-03-08 21:34:09 ----A---- C:\windows\system32\drivers\mpio.sys
2011-03-08 21:34:09 ----A---- C:\windows\system32\drivers\mountmgr.sys
2011-03-08 21:34:09 ----A---- C:\windows\system32\drivers\iaStorV.sys
2011-03-08 21:34:08 ----A---- C:\windows\system32\termmgr.dll
2011-03-08 21:34:08 ----A---- C:\windows\system32\eudcedit.exe
2011-03-08 21:34:08 ----A---- C:\windows\system32\drivers\usbehci.sys
2011-03-08 21:34:08 ----A---- C:\windows\system32\drivers\scsiport.sys
2011-03-08 21:34:08 ----A---- C:\windows\system32\DiagCpl.dll
2011-03-08 21:34:07 ----A---- C:\windows\system32\wiadefui.dll
2011-03-08 21:34:07 ----A---- C:\windows\system32\sppcomapi.dll
2011-03-08 21:34:07 ----A---- C:\windows\system32\shsetup.dll
2011-03-08 21:34:07 ----A---- C:\windows\system32\rasppp.dll
2011-03-08 21:34:07 ----A---- C:\windows\system32\msdtctm.dll
2011-03-08 21:34:07 ----A---- C:\windows\system32\msconfig.exe
2011-03-08 21:34:07 ----A---- C:\windows\system32\logoncli.dll
2011-03-08 21:34:07 ----A---- C:\windows\system32\FirewallControlPanel.dll
2011-03-08 21:34:07 ----A---- C:\windows\system32\cabview.dll
2011-03-08 21:34:07 ----A---- C:\windows\system32\biocpl.dll
2011-03-08 21:34:06 ----A---- C:\windows\system32\wpccpl.dll
2011-03-08 21:34:06 ----A---- C:\windows\system32\themecpl.dll
2011-03-08 21:34:06 ----A---- C:\windows\system32\SensorsCpl.dll
2011-03-08 21:34:06 ----A---- C:\windows\system32\FWPUCLNT.DLL
2011-03-08 21:34:06 ----A---- C:\windows\system32\drivers\rdyboost.sys
2011-03-08 21:34:06 ----A---- C:\windows\system32\drivers\BTHUSB.SYS
2011-03-08 21:34:06 ----A---- C:\windows\system32\dnscmmc.dll
2011-03-08 21:34:05 ----A---- C:\windows\system32\winsrv.dll
2011-03-08 21:34:05 ----A---- C:\windows\system32\tapisrv.dll
2011-03-08 21:34:05 ----A---- C:\windows\system32\scecli.dll
2011-03-08 21:34:05 ----A---- C:\windows\system32\mscories.dll
2011-03-08 21:34:05 ----A---- C:\windows\system32\mscms.dll
2011-03-08 21:34:05 ----A---- C:\windows\system32\localsec.dll
2011-03-08 21:34:05 ----A---- C:\windows\system32\hgcpl.dll
2011-03-08 21:34:05 ----A---- C:\windows\system32\fontext.dll
2011-03-08 21:34:05 ----A---- C:\windows\system32\drivers\ksecdd.sys
2011-03-08 21:34:04 ----A---- C:\windows\system32\wlanui.dll
2011-03-08 21:34:04 ----A---- C:\windows\system32\wkssvc.dll
2011-03-08 21:34:04 ----A---- C:\windows\system32\VAN.dll
2011-03-08 21:34:04 ----A---- C:\windows\system32\usercpl.dll
2011-03-08 21:34:04 ----A---- C:\windows\system32\srcore.dll
2011-03-08 21:34:04 ----A---- C:\windows\system32\SndVolSSO.dll
2011-03-08 21:34:04 ----A---- C:\windows\system32\qedit.dll
2011-03-08 21:34:04 ----A---- C:\windows\system32\prntvpt.dll
2011-03-08 21:34:04 ----A---- C:\windows\system32\PerfCenterCPL.dll
2011-03-08 21:34:04 ----A---- C:\windows\system32\mprddm.dll
2011-03-08 21:34:04 ----A---- C:\windows\system32\KMSVC.DLL
2011-03-08 21:34:04 ----A---- C:\windows\system32\iasacct.dll
2011-03-08 21:34:04 ----A---- C:\windows\system32\drivers\usbhub.sys
2011-03-08 21:34:04 ----A---- C:\windows\system32\bcdsrv.dll
2011-03-08 21:34:04 ----A---- C:\windows\system32\batmeter.dll
2011-03-08 21:34:03 ----A---- C:\windows\system32\wpdbusenum.dll
2011-03-08 21:34:03 ----A---- C:\windows\system32\wksprt.exe
2011-03-08 21:34:03 ----A---- C:\windows\system32\w32tm.exe
2011-03-08 21:34:03 ----A---- C:\windows\system32\spwizeng.dll
2011-03-08 21:34:03 ----A---- C:\windows\system32\SndVol.exe
2011-03-08 21:34:03 ----A---- C:\windows\system32\qdvd.dll
2011-03-08 21:34:03 ----A---- C:\windows\system32\netcenter.dll
2011-03-08 21:34:03 ----A---- C:\windows\system32\mblctr.exe
2011-03-08 21:34:03 ----A---- C:\windows\system32\drivers\afd.sys
2011-03-08 21:34:03 ----A---- C:\windows\system32\azroleui.dll
2011-03-08 21:34:03 ----A---- C:\windows\system32\accessibilitycpl.dll
2011-03-08 21:34:02 ----A---- C:\windows\system32\zipfldr.dll
2011-03-08 21:34:02 ----A---- C:\windows\system32\networkmap.dll
2011-03-08 21:34:02 ----A---- C:\windows\system32\netjoin.dll
2011-03-08 21:34:02 ----A---- C:\windows\system32\MSAC3ENC.DLL
2011-03-08 21:34:02 ----A---- C:\windows\system32\fdeploy.dll
2011-03-08 21:34:02 ----A---- C:\windows\system32\drivers\ks.sys
2011-03-08 21:34:02 ----A---- C:\windows\system32\cryptui.dll
2011-03-08 21:34:02 ----A---- C:\windows\system32\adsldp.dll
2011-03-08 21:34:01 ----A---- C:\windows\system32\wusa.exe
2011-03-08 21:34:01 ----A---- C:\windows\system32\sud.dll
2011-03-08 21:34:01 ----A---- C:\windows\system32\prnfldr.dll
2011-03-08 21:34:01 ----A---- C:\windows\system32\photowiz.dll
2011-03-08 21:34:01 ----A---- C:\windows\system32\OnLineIDCpl.dll
2011-03-08 21:34:01 ----A---- C:\windows\system32\mspbda.dll
2011-03-08 21:34:01 ----A---- C:\windows\system32\msieftp.dll
2011-03-08 21:34:01 ----A---- C:\windows\system32\MCEWMDRMNDBootstrap.dll
2011-03-08 21:34:01 ----A---- C:\windows\system32\Faultrep.dll
2011-03-08 21:34:01 ----A---- C:\windows\system32\cfgmgr32.dll
2011-03-08 21:34:01 ----A---- C:\windows\system32\ActionCenter.dll
2011-03-08 21:34:00 ----A---- C:\windows\system32\taskhost.exe
2011-03-08 21:34:00 ----A---- C:\windows\system32\taskbarcpl.dll
2011-03-08 21:34:00 ----A---- C:\windows\system32\slui.exe
2011-03-08 21:34:00 ----A---- C:\windows\system32\rdpcorekmts.dll
2011-03-08 21:34:00 ----A---- C:\windows\system32\MediaMetadataHandler.dll
2011-03-08 21:34:00 ----A---- C:\windows\system32\iprtrmgr.dll
2011-03-08 21:34:00 ----A---- C:\windows\system32\iasrad.dll
2011-03-08 21:34:00 ----A---- C:\windows\system32\drivers\hidclass.sys
2011-03-08 21:34:00 ----A---- C:\windows\system32\dot3cfg.dll
2011-03-08 21:34:00 ----A---- C:\windows\system32\defaultlocationcpl.dll
2011-03-08 21:34:00 ----A---- C:\windows\system32\credssp.dll
2011-03-08 21:33:59 ----A---- C:\windows\system32\wpd_ci.dll
2011-03-08 21:33:59 ----A---- C:\windows\system32\sisbkup.dll
2011-03-08 21:33:59 ----A---- C:\windows\system32\shwebsvc.dll
2011-03-08 21:33:59 ----A---- C:\windows\system32\odbcjt32.dll
2011-03-08 21:33:59 ----A---- C:\windows\system32\ifsutil.dll
2011-03-08 21:33:59 ----A---- C:\windows\system32\ieUnatt.exe
2011-03-08 21:33:59 ----A---- C:\windows\system32\iesysprep.dll
2011-03-08 21:33:59 ----A---- C:\windows\system32\halacpi.dll
2011-03-08 21:33:59 ----A---- C:\windows\system32\ftp.exe
2011-03-08 21:33:59 ----A---- C:\windows\system32\efscore.dll
2011-03-08 21:33:58 ----A---- C:\windows\system32\syncui.dll
2011-03-08 21:33:58 ----A---- C:\windows\system32\sdcpl.dll
2011-03-08 21:33:58 ----A---- C:\windows\system32\recovery.dll
2011-03-08 21:33:58 ----A---- C:\windows\system32\rdpwsx.dll
2011-03-08 21:33:58 ----A---- C:\windows\system32\fsquirt.exe
2011-03-08 21:33:58 ----A---- C:\windows\system32\DeviceCenter.dll
2011-03-08 21:33:58 ----A---- C:\windows\system32\bcdedit.exe
2011-03-08 21:33:58 ----A---- C:\windows\system32\autoplay.dll
2011-03-08 21:33:58 ----A---- C:\windows\system32\ActionCenterCPL.dll
2011-03-08 21:33:57 ----A---- C:\windows\system32\wmpmde.dll
2011-03-08 21:33:57 ----A---- C:\windows\system32\vdsutil.dll
2011-03-08 21:33:57 ----A---- C:\windows\system32\systemcpl.dll
2011-03-08 21:33:57 ----A---- C:\windows\system32\sppnp.dll
2011-03-08 21:33:57 ----A---- C:\windows\system32\rtutils.dll
2011-03-08 21:33:57 ----A---- C:\windows\system32\recdisc.exe
2011-03-08 21:33:57 ----A---- C:\windows\system32\OobeFldr.dll
2011-03-08 21:33:57 ----A---- C:\windows\system32\ntprint.dll
2011-03-08 21:33:57 ----A---- C:\windows\system32\ntlanman.dll
2011-03-08 21:33:57 ----A---- C:\windows\system32\dskquoui.dll
2011-03-08 21:33:56 ----A---- C:\windows\system32\SmartcardCredentialProvider.dll
2011-03-08 21:33:56 ----A---- C:\windows\system32\sethc.exe
2011-03-08 21:33:56 ----A---- C:\windows\system32\rstrui.exe
2011-03-08 21:33:56 ----A---- C:\windows\system32\riched20.dll
2011-03-08 21:33:56 ----A---- C:\windows\system32\nshwfp.dll
2011-03-08 21:33:56 ----A---- C:\windows\system32\drivers\tdx.sys
2011-03-08 21:33:56 ----A---- C:\windows\system32\blackbox.dll
2011-03-08 21:33:56 ----A---- C:\windows\system32\bcdboot.exe
2011-03-08 21:33:56 ----A---- C:\windows\system32\AxInstSv.dll
2011-03-08 21:33:55 ----A---- C:\windows\system32\wmpsrcwp.dll
2011-03-08 21:33:55 ----A---- C:\windows\system32\netplwiz.dll
2011-03-08 21:33:55 ----A---- C:\windows\system32\NAPHLPR.DLL
2011-03-08 21:33:55 ----A---- C:\windows\system32\migisol.dll
2011-03-08 21:33:55 ----A---- C:\windows\system32\httpapi.dll
2011-03-08 21:33:55 ----A---- C:\windows\system32\fms.dll
2011-03-08 21:33:55 ----A---- C:\windows\system32\drivers\tssecsrv.sys
2011-03-08 21:33:55 ----A---- C:\windows\system32\dot3svc.dll
2011-03-08 21:33:55 ----A---- C:\windows\system32\cdosys.dll
2011-03-08 21:33:55 ----A---- C:\windows\system32\AuxiliaryDisplayServices.dll
2011-03-08 21:33:55 ----A---- C:\windows\system32\activeds.dll
2011-03-08 21:33:54 ----A---- C:\windows\system32\wsqmcons.exe
2011-03-08 21:33:54 ----A---- C:\windows\system32\wlanmsm.dll
2011-03-08 21:33:54 ----A---- C:\windows\system32\wavemsp.dll
2011-03-08 21:33:54 ----A---- C:\windows\system32\ReAgent.dll
2011-03-08 21:33:54 ----A---- C:\windows\system32\nshipsec.dll
2011-03-08 21:33:54 ----A---- C:\windows\system32\nlaapi.dll
2011-03-08 21:33:54 ----A---- C:\windows\system32\msftedit.dll
2011-03-08 21:33:54 ----A---- C:\windows\system32\isoburn.exe
2011-03-08 21:33:54 ----A---- C:\windows\system32\asycfilt.dll
2011-03-08 21:33:53 ----A---- C:\windows\system32\wvc.dll
2011-03-08 21:33:53 ----A---- C:\windows\system32\wuwebv.dll
2011-03-08 21:33:53 ----A---- C:\windows\system32\wtsapi32.dll
2011-03-08 21:33:53 ----A---- C:\windows\system32\tzutil.exe
2011-03-08 21:33:53 ----A---- C:\windows\system32\sysclass.dll
2011-03-08 21:33:53 ----A---- C:\windows\system32\provsvc.dll
2011-03-08 21:33:53 ----A---- C:\windows\system32\ocsetup.exe
2011-03-08 21:33:53 ----A---- C:\windows\system32\dsuiext.dll
2011-03-08 21:33:53 ----A---- C:\windows\system32\drivers\ndproxy.sys
2011-03-08 21:33:53 ----A---- C:\windows\system32\dot3ui.dll
2011-03-08 21:33:53 ----A---- C:\windows\system32\dfrgui.exe
2011-03-08 21:33:53 ----A---- C:\windows\system32\appinfo.dll
2011-03-08 21:33:52 ----A---- C:\windows\system32\wimgapi.dll
2011-03-08 21:33:52 ----A---- C:\windows\system32\webcheck.dll
2011-03-08 21:33:52 ----A---- C:\windows\system32\twext.dll
2011-03-08 21:33:52 ----A---- C:\windows\system32\shdocvw.dll
2011-03-08 21:33:52 ----A---- C:\windows\system32\mstask.dll
2011-03-08 21:33:52 ----A---- C:\windows\system32\certprop.dll
2011-03-08 21:33:51 ----A---- C:\windows\twain_32.dll
2011-03-08 21:33:51 ----A---- C:\windows\system32\uxlib.dll
2011-03-08 21:33:51 ----A---- C:\windows\system32\slwga.dll
2011-03-08 21:33:51 ----A---- C:\windows\system32\setupugc.exe
2011-03-08 21:33:51 ----A---- C:\windows\system32\qcap.dll
2011-03-08 21:33:51 ----A---- C:\windows\system32\qasf.dll
2011-03-08 21:33:51 ----A---- C:\windows\system32\occache.dll
2011-03-08 21:33:51 ----A---- C:\windows\system32\msrating.dll
2011-03-08 21:33:51 ----A---- C:\windows\system32\msfeedsbs.dll
2011-03-08 21:33:51 ----A---- C:\windows\system32\imm32.dll
2011-03-08 21:33:50 ----A---- C:\windows\system32\wwanconn.dll
2011-03-08 21:33:50 ----A---- C:\windows\system32\wmdrmsdk.dll
2011-03-08 21:33:50 ----A---- C:\windows\system32\srrstr.dll
2011-03-08 21:33:50 ----A---- C:\windows\system32\nslookup.exe
2011-03-08 21:33:50 ----A---- C:\windows\system32\msvfw32.dll
2011-03-08 21:33:50 ----A---- C:\windows\system32\mciavi32.dll
2011-03-08 21:33:50 ----A---- C:\windows\system32\imgutil.dll
2011-03-08 21:33:50 ----A---- C:\windows\system32\clusapi.dll
2011-03-08 21:33:50 ----A---- C:\windows\system32\audiodev.dll
2011-03-08 21:33:49 ----A---- C:\windows\system32\WPDShServiceObj.dll
2011-03-08 21:33:49 ----A---- C:\windows\system32\wimserv.exe
2011-03-08 21:33:49 ----A---- C:\windows\system32\TSpkg.dll
2011-03-08 21:33:49 ----A---- C:\windows\system32\msscp.dll
2011-03-08 21:33:49 ----A---- C:\windows\system32\diskraid.exe
2011-03-08 21:33:49 ----A---- C:\windows\system32\DevicePairingFolder.dll
2011-03-08 21:33:48 ----A---- C:\windows\system32\WindowsAnytimeUpgradeResults.exe
2011-03-08 21:33:48 ----A---- C:\windows\system32\sdrsvc.dll
2011-03-08 21:33:48 ----A---- C:\windows\system32\remotepg.dll
2011-03-08 21:33:48 ----A---- C:\windows\system32\rdpencom.dll
2011-03-08 21:33:48 ----A---- C:\windows\system32\raschap.dll
2011-03-08 21:33:48 ----A---- C:\windows\system32\QUTIL.DLL
2011-03-08 21:33:48 ----A---- C:\windows\system32\perfmon.exe
2011-03-08 21:33:48 ----A---- C:\windows\system32\odbccp32.dll
2011-03-08 21:33:48 ----A---- C:\windows\system32\networkexplorer.dll
2011-03-08 21:33:48 ----A---- C:\windows\system32\NAPCRYPT.DLL
2011-03-08 21:33:48 ----A---- C:\windows\system32\input.dll
2011-03-08 21:33:48 ----A---- C:\windows\system32\drmmgrtn.dll
2011-03-08 21:33:48 ----A---- C:\windows\system32\browser.dll
2011-03-08 21:33:48 ----A---- C:\windows\system32\acppage.dll
2011-03-08 21:33:47 ----A---- C:\windows\system32\wpdwcn.dll
2011-03-08 21:33:47 ----A---- C:\windows\system32\wmpdxm.dll
2011-03-08 21:33:47 ----A---- C:\windows\system32\vpnikeapi.dll
2011-03-08 21:33:47 ----A---- C:\windows\system32\vdsbas.dll
2011-03-08 21:33:47 ----A---- C:\windows\system32\UserAccountControlSettings.dll
2011-03-08 21:33:47 ----A---- C:\windows\system32\onexui.dll
2011-03-08 21:33:47 ----A---- C:\windows\system32\olepro32.dll
2011-03-08 21:33:47 ----A---- C:\windows\system32\ocsetapi.dll
2011-03-08 21:33:47 ----A---- C:\windows\system32\nltest.exe
2011-03-08 21:33:47 ----A---- C:\windows\system32\iTVData.dll
2011-03-08 21:33:47 ----A---- C:\windows\bfsvc.exe
2011-03-08 21:33:46 ----A---- C:\windows\system32\sspisrv.dll
2011-03-08 21:33:46 ----A---- C:\windows\system32\runonce.exe
2011-03-08 21:33:46 ----A---- C:\windows\system32\RegisterIEPKEYs.exe
2011-03-08 21:33:46 ----A---- C:\windows\system32\Mcx2Svc.dll
2011-03-08 21:33:46 ----A---- C:\windows\system32\logagent.exe
2011-03-08 21:33:46 ----A---- C:\windows\system32\inseng.dll
2011-03-08 21:33:46 ----A---- C:\windows\system32\dxdiagn.dll
2011-03-08 21:33:45 ----A---- C:\windows\system32\PnPUnattend.exe
2011-03-08 21:33:45 ----A---- C:\windows\system32\msvidc32.dll
2011-03-08 21:33:45 ----A---- C:\windows\system32\msiexec.exe
2011-03-08 21:33:45 ----A---- C:\windows\system32\MFPlay.dll
2011-03-08 21:33:45 ----A---- C:\windows\system32\eapp3hst.dll
2011-03-08 21:33:45 ----A---- C:\windows\system32\drivers\rmcast.sys
2011-03-08 21:33:45 ----A---- C:\windows\system32\d3d10level9.dll
2011-03-08 21:33:44 ----A---- C:\windows\system32\wudriver.dll
2011-03-08 21:33:44 ----A---- C:\windows\system32\wmpshell.dll
2011-03-08 21:33:44 ----A---- C:\windows\system32\wmdrmdev.dll
2011-03-08 21:33:44 ----A---- C:\windows\system32\unimdmat.dll
2011-03-08 21:33:44 ----A---- C:\windows\system32\tabcal.exe
2011-03-08 21:33:44 ----A---- C:\windows\system32\sqlcese30.dll
2011-03-08 21:33:44 ----A---- C:\windows\system32\shacct.dll
2011-03-08 21:33:44 ----A---- C:\windows\system32\rdpd3d.dll
2011-03-08 21:33:44 ----A---- C:\windows\system32\lsmproxy.dll
2011-03-08 21:33:44 ----A---- C:\windows\system32\iscsium.dll
2011-03-08 21:33:44 ----A---- C:\windows\system32\bitsadmin.exe
2011-03-08 21:33:43 ----A---- C:\windows\system32\WUDFPlatform.dll
2011-03-08 21:33:43 ----A---- C:\windows\system32\WPDSp.dll
2011-03-08 21:33:43 ----A---- C:\windows\system32\srvcli.dll
2011-03-08 21:33:43 ----A---- C:\windows\system32\PortableDeviceSyncProvider.dll
2011-03-08 21:33:43 ----A---- C:\windows\system32\pdh.dll
2011-03-08 21:33:43 ----A---- C:\windows\system32\OpcServices.dll
2011-03-08 21:33:43 ----A---- C:\windows\system32\olethk32.dll
2011-03-08 21:33:43 ----A---- C:\windows\system32\ncryptui.dll
2011-03-08 21:33:43 ----A---- C:\windows\system32\mprapi.dll
2011-03-08 21:33:43 ----A---- C:\windows\system32\MdSched.exe
2011-03-08 21:33:43 ----A---- C:\windows\system32\logman.exe
2011-03-08 21:33:43 ----A---- C:\windows\system32\djoin.exe
2011-03-08 21:33:43 ----A---- C:\windows\system32\cscapi.dll
2011-03-08 21:33:42 ----A---- C:\windows\system32\wwanprotdim.dll
2011-03-08 21:33:42 ----A---- C:\windows\system32\WMPhoto.dll
2011-03-08 21:33:42 ----A---- C:\windows\system32\utildll.dll
2011-03-08 21:33:42 ----A---- C:\windows\system32\tsgqec.dll
2011-03-08 21:33:42 ----A---- C:\windows\system32\QSVRMGMT.DLL
2011-03-08 21:33:42 ----A---- C:\windows\system32\PortableDeviceStatus.dll
2011-03-08 21:33:42 ----A---- C:\windows\system32\odbctrac.dll
2011-03-08 21:33:42 ----A---- C:\windows\system32\mshtmled.dll
2011-03-08 21:33:42 ----A---- C:\windows\system32\mapistub.dll
2011-03-08 21:33:42 ----A---- C:\windows\system32\mapi32.dll
2011-03-08 21:33:42 ----A---- C:\windows\system32\lpremove.exe
2011-03-08 21:33:42 ----A---- C:\windows\system32\ActionQueue.dll
2011-03-08 21:33:41 ----A---- C:\windows\system32\WMVSDECD.DLL
2011-03-08 21:33:41 ----A---- C:\windows\system32\wmdrmnet.dll
2011-03-08 21:33:41 ----A---- C:\windows\system32\WMADMOD.DLL
2011-03-08 21:33:41 ----A---- C:\windows\system32\WindowsAnytimeUpgrade.exe
2011-03-08 21:33:41 ----A---- C:\windows\system32\wiavideo.dll
2011-03-08 21:33:41 ----A---- C:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2011-03-08 21:33:41 ----A---- C:\windows\system32\takeown.exe
2011-03-08 21:33:41 ----A---- C:\windows\system32\sqmapi.dll
2011-03-08 21:33:41 ----A---- C:\windows\system32\iyuv_32.dll
2011-03-08 21:33:41 ----A---- C:\windows\system32\imagehlp.dll
2011-03-08 21:33:41 ----A---- C:\windows\system32\fphc.dll
2011-03-08 21:33:41 ----A---- C:\windows\system32\dot3msm.dll
2011-03-08 21:33:41 ----A---- C:\windows\system32\avifil32.dll
2011-03-08 21:33:40 ----A---- C:\windows\system32\unattend.dll
2011-03-08 21:33:40 ----A---- C:\windows\system32\sppinst.dll
2011-03-08 21:33:40 ----A---- C:\windows\system32\qdv.dll
2011-03-08 21:33:40 ----A---- C:\windows\system32\QCLIPROV.DLL
2011-03-08 21:33:40 ----A---- C:\windows\system32\msyuv.dll
2011-03-08 21:33:40 ----A---- C:\windows\system32\msrle32.dll
2011-03-08 21:33:40 ----A---- C:\windows\system32\msnetobj.dll
2011-03-08 21:33:40 ----A---- C:\windows\system32\EhStorAPI.dll
2011-03-08 21:33:40 ----A---- C:\windows\system32\cca.dll
2011-03-08 21:33:39 ----A---- C:\windows\system32\WUDFx.dll
2011-03-08 21:33:39 ----A---- C:\windows\system32\WUDFHost.exe
2011-03-08 21:33:39 ----A---- C:\windows\system32\wsnmp32.dll
2011-03-08 21:33:39 ----A---- C:\windows\system32\WMSPDMOD.DLL
2011-03-08 21:33:39 ----A---- C:\windows\system32\vfwwdm32.dll
2011-03-08 21:33:39 ----A---- C:\windows\system32\setupcln.dll
2011-03-08 21:33:39 ----A---- C:\windows\system32\RelPost.exe
2011-03-08 21:33:39 ----A---- C:\windows\system32\pdhui.dll
2011-03-08 21:33:39 ----A---- C:\windows\system32\MuiUnattend.exe
2011-03-08 21:33:39 ----A---- C:\windows\system32\drivers\bthport.sys
2011-03-08 21:33:39 ----A---- C:\windows\system32\cmstp.exe
2011-03-08 21:33:39 ----A---- C:\windows\system32\basesrv.dll
2011-03-08 21:33:38 ----A---- C:\windows\system32\wuauclt.exe
2011-03-08 21:33:38 ----A---- C:\windows\system32\umb.dll
2011-03-08 21:33:38 ----A---- C:\windows\system32\tsbyuv.dll
2011-03-08 21:33:38 ----A---- C:\windows\system32\relog.exe
2011-03-08 21:33:38 ----A---- C:\windows\system32\PrintIsolationProxy.dll
2011-03-08 21:33:38 ----A---- C:\windows\system32\msorcl32.dll
2011-03-08 21:33:38 ----A---- C:\windows\system32\iasrecst.dll
2011-03-08 21:33:38 ----A---- C:\windows\system32\drivers\tcpipreg.sys
2011-03-08 21:33:38 ----A---- C:\windows\system32\drivers\ndisuio.sys
2011-03-08 21:33:38 ----A---- C:\windows\system32\AzSqlExt.dll
2011-03-08 21:33:37 ----A---- C:\windows\system32\wkscli.dll
2011-03-08 21:33:37 ----A---- C:\windows\system32\WavDest.dll
2011-03-08 21:33:37 ----A---- C:\windows\system32\sppuinotify.dll
2011-03-08 21:33:37 ----A---- C:\windows\system32\spbcd.dll
2011-03-08 21:33:37 ----A---- C:\windows\system32\rastapi.dll
2011-03-08 21:33:37 ----A---- C:\windows\system32\netiougc.exe
2011-03-08 21:33:37 ----A---- C:\windows\system32\mydocs.dll
2011-03-08 21:33:37 ----A---- C:\windows\system32\iscsicli.exe
2011-03-08 21:33:37 ----A---- C:\windows\system32\diskpart.exe
2011-03-08 21:33:37 ----A---- C:\windows\system32\amstream.dll
2011-03-08 21:33:36 ----A---- C:\windows\system32\wmpps.dll
2011-03-08 21:33:36 ----A---- C:\windows\system32\syssetup.dll
2011-03-08 21:33:36 ----A---- C:\windows\system32\setbcdlocale.dll
2011-03-08 21:33:36 ----A---- C:\windows\system32\secproc_ssp_isv.dll
2011-03-08 21:33:36 ----A---- C:\windows\system32\secproc_ssp.dll
2011-03-08 21:33:36 ----A---- C:\windows\system32\resutils.dll
2011-03-08 21:33:36 ----A---- C:\windows\system32\nrpsrv.dll
2011-03-08 21:33:36 ----A---- C:\windows\system32\netbtugc.exe
2011-03-08 21:33:36 ----A---- C:\windows\system32\MultiDigiMon.exe
2011-03-08 21:33:36 ----A---- C:\windows\system32\itircl.dll
2011-03-08 21:33:36 ----A---- C:\windows\system32\CertPolEng.dll
2011-03-08 21:33:35 ----A---- C:\windows\system32\wuapp.exe
2011-03-08 21:33:35 ----A---- C:\windows\system32\WerFaultSecure.exe
2011-03-08 21:33:35 ----A---- C:\windows\system32\tlscsp.dll
2011-03-08 21:33:35 ----A---- C:\windows\system32\secur32.dll
2011-03-08 21:33:35 ----A---- C:\windows\system32\RMActivate_ssp_isv.exe
2011-03-08 21:33:35 ----A---- C:\windows\system32\ReAgentc.exe
2011-03-08 21:33:35 ----A---- C:\windows\system32\FXSTIFF.dll
2011-03-08 21:33:35 ----A---- C:\windows\system32\findstr.exe
2011-03-08 21:33:35 ----A---- C:\windows\system32\eappgnui.dll
2011-03-08 21:33:35 ----A---- C:\windows\system32\drivers\usbccgp.sys
2011-03-08 21:33:34 ----A---- C:\windows\system32\wiarpc.dll
2011-03-08 21:33:34 ----A---- C:\windows\system32\RMActivate_ssp.exe
2011-03-08 21:33:34 ----A---- C:\windows\system32\netutils.dll
2011-03-08 21:33:34 ----A---- C:\windows\system32\netapi32.dll
2011-03-08 21:33:34 ----A---- C:\windows\system32\muifontsetup.dll
2011-03-08 21:33:34 ----A---- C:\windows\system32\mobsync.exe
2011-03-08 21:33:34 ----A---- C:\windows\system32\mciqtz32.dll
2011-03-08 21:33:34 ----A---- C:\windows\system32\dnscacheugc.exe
2011-03-08 21:33:34 ----A---- C:\windows\system32\cabinet.dll
2011-03-08 21:33:33 ----A---- C:\windows\system32\sppc.dll
2011-03-08 21:33:33 ----A---- C:\windows\system32\spopk.dll
2011-03-08 21:33:33 ----A---- C:\windows\system32\shimgvw.dll
2011-03-08 21:33:33 ----A---- C:\windows\system32\prevhost.exe
2011-03-08 21:33:33 ----A---- C:\windows\system32\luainstall.dll
2011-03-08 21:33:33 ----A---- C:\windows\system32\iccvid.dll
2011-03-08 21:33:33 ----A---- C:\windows\system32\HotStartUserAgent.dll
2011-03-08 21:33:33 ----A---- C:\windows\system32\drivers\usbrpm.sys
2011-03-08 21:33:33 ----A---- C:\windows\system32\drivers\tdi.sys
2011-03-08 21:33:33 ----A---- C:\windows\system32\dosx.exe
2011-03-08 21:33:32 ----A---- C:\windows\system32\wdiasqmmodule.dll
2011-03-08 21:33:32 ----A---- C:\windows\system32\unlodctr.exe
2011-03-08 21:33:32 ----A---- C:\windows\system32\repair-bde.exe
2011-03-08 21:33:32 ----A---- C:\windows\system32\rdprefdrvapi.dll
2011-03-08 21:33:32 ----A---- C:\windows\system32\netcfg.exe
2011-03-08 21:33:32 ----A---- C:\windows\system32\msdmo.dll
2011-03-08 21:33:32 ----A---- C:\windows\system32\manage-bde.exe
2011-03-08 21:33:32 ----A---- C:\windows\system32\inetmib1.dll
2011-03-08 21:33:32 ----A---- C:\windows\system32\drivers\CompositeBus.sys
2011-03-08 21:33:31 ----A---- C:\windows\system32\WUDFCoinstaller.dll
2011-03-08 21:33:31 ----A---- C:\windows\system32\odbcconf.dll
2011-03-08 21:33:31 ----A---- C:\windows\system32\drivers\cdrom.sys
2011-03-08 21:33:30 ----A---- C:\windows\system32\wups.dll
2011-03-08 21:33:30 ----A---- C:\windows\system32\UIRibbonRes.dll
2011-03-08 21:33:30 ----A---- C:\windows\system32\profprov.dll
2011-03-08 21:33:30 ----A---- C:\windows\system32\perfts.dll
2011-03-08 21:33:30 ----A---- C:\windows\system32\browcli.dll
2011-03-08 21:33:29 ----A---- C:\windows\system32\TRAPI.dll
2011-03-08 21:33:29 ----A---- C:\windows\system32\RDPENCDD.dll
2011-03-08 21:33:29 ----A---- C:\windows\system32\msfeedssync.exe
2011-03-08 21:33:29 ----A---- C:\windows\system32\icaapi.dll
2011-03-08 21:33:29 ----A---- C:\windows\system32\FXSMON.dll
2011-03-08 21:33:29 ----A---- C:\windows\system32\elsTrans.dll
2011-03-08 21:33:29 ----A---- C:\windows\system32\drivers\tunnel.sys
2011-03-08 21:33:29 ----A---- C:\windows\system32\drivers\dfsc.sys
2011-03-08 21:33:28 ----A---- C:\windows\system32\wshbth.dll
2011-03-08 21:33:28 ----A---- C:\windows\system32\schedcli.dll
2011-03-08 21:33:28 ----A---- C:\windows\system32\napdsnap.dll
2011-03-08 21:33:28 ----A---- C:\windows\system32\LogonUI.exe
2011-03-08 21:33:28 ----A---- C:\windows\system32\dsauth.dll
2011-03-08 21:33:28 ----A---- C:\windows\system32\cscdll.dll
2011-03-08 21:33:28 ----A---- C:\windows\system32\bitsperf.dll
2011-03-08 21:33:27 ----A---- C:\windows\system32\sscore.dll
2011-03-08 21:33:27 ----A---- C:\windows\system32\drivers\acpipmi.sys
2011-03-08 21:33:26 ----A---- C:\windows\system32\wups2.dll
2011-03-08 21:33:26 ----A---- C:\windows\system32\wsdchngr.dll
2011-03-08 21:33:26 ----A---- C:\windows\system32\shgina.dll
2011-03-08 21:33:26 ----A---- C:\windows\system32\riched32.dll
2011-03-08 21:33:26 ----A---- C:\windows\system32\drivers\ndiswan.sys
2011-03-08 21:33:25 ----A---- C:\windows\system32\rdpcfgex.dll
2011-03-08 21:33:25 ----A---- C:\windows\system32\drivers\WUDFRd.sys
2011-03-08 21:33:25 ----A---- C:\windows\system32\drivers\hidusb.sys
2011-03-08 21:33:25 ----A---- C:\windows\system32\drivers\appid.sys
2011-03-08 21:33:24 ----A---- C:\windows\system32\wshirda.dll
2011-03-08 21:33:24 ----A---- C:\windows\system32\drivers\IPMIDrv.sys
2011-03-08 21:33:23 ----A---- C:\windows\system32\drivers\USBCAMD2.sys
2011-03-08 21:33:23 ----A---- C:\windows\system32\drivers\USBCAMD.sys
2011-03-08 21:33:23 ----A---- C:\windows\system32\drivers\kbdhid.sys
2011-03-08 21:33:22 ----A---- C:\windows\system32\spwmp.dll
2011-03-08 21:33:22 ----A---- C:\windows\system32\drivers\tdtcp.sys
2011-03-08 21:33:22 ----A---- C:\windows\system32\browseui.dll
2011-03-08 21:33:21 ----A---- C:\windows\system32\RDPREFDD.dll
2011-03-08 21:33:21 ----A---- C:\windows\system32\dxmasf.dll
2011-03-08 21:33:21 ----A---- C:\windows\system32\drivers\WUDFPf.sys
2011-03-08 21:33:21 ----A---- C:\windows\system32\drivers\wanarp.sys
2011-03-08 21:33:21 ----A---- C:\windows\system32\drivers\umbus.sys
2011-03-08 21:33:21 ----A---- C:\windows\system32\drivers\tdpipe.sys
2011-03-08 21:33:21 ----A---- C:\windows\system32\drivers\sffp_sd.sys
2011-03-08 21:33:21 ----A---- C:\windows\system32\drivers\scfilter.sys
2011-03-08 21:33:21 ----A---- C:\windows\system32\drivers\RDPCDD.sys
2011-03-08 21:33:21 ----A---- C:\windows\system32\drivers\HdAudio.sys
2011-03-08 21:33:21 ----A---- C:\windows\system32\drivers\hdaudbus.sys
2011-03-08 21:33:21 ----A---- C:\windows\system32\C_ISCII.DLL
2011-03-08 21:33:20 ----A---- C:\windows\system32\shunimpl.dll
2011-03-08 21:33:19 ----A---- C:\windows\system32\wmploc.DLL
2011-03-08 21:33:19 ----A---- C:\windows\system32\KBDUS.DLL
2011-03-08 21:33:19 ----A---- C:\windows\system32\KBDUGHR1.DLL
2011-03-08 21:33:19 ----A---- C:\windows\system32\KBDTURME.DLL
2011-03-08 21:33:19 ----A---- C:\windows\system32\KBDTAJIK.DLL
2011-03-08 21:33:19 ----A---- C:\windows\system32\KBDINTEL.DLL
2011-03-08 21:33:19 ----A---- C:\windows\system32\KBDINKAN.DLL
2011-03-08 21:33:18 ----A---- C:\windows\system32\KBDSF.DLL
2011-03-08 21:33:18 ----A---- C:\windows\system32\KBDNEPR.DLL
2011-03-08 21:33:18 ----A---- C:\windows\system32\KBDMON.DLL
2011-03-08 21:33:18 ----A---- C:\windows\system32\KBDMAORI.DLL
2011-03-08 21:33:18 ----A---- C:\windows\system32\KBDLT1.DLL
2011-03-08 21:33:18 ----A---- C:\windows\system32\kbdlk41a.dll
2011-03-08 21:33:18 ----A---- C:\windows\system32\KBDINTAM.DLL
2011-03-08 21:33:18 ----A---- C:\windows\system32\KBDINORI.DLL
2011-03-08 21:33:18 ----A---- C:\windows\system32\KBDINMAR.DLL
2011-03-08 21:33:18 ----A---- C:\windows\system32\KBDINHIN.DLL
2011-03-08 21:33:18 ----A---- C:\windows\system32\KBDGEO.DLL
2011-03-08 21:33:18 ----A---- C:\windows\system32\KBDBULG.DLL
2011-03-08 21:33:18 ----A---- C:\windows\system32\KBDBLR.DLL
2011-03-08 21:33:18 ----A---- C:\windows\system32\KBDBASH.DLL
2011-03-08 21:33:17 ----A---- C:\windows\system32\tzres.dll
2011-03-08 21:33:17 ----A---- C:\windows\system32\spwizres.dll
2011-03-08 21:33:17 ----A---- C:\windows\system32\pifmgr.dll
2011-03-08 21:33:17 ----A---- C:\windows\system32\nlsbres.dll
2011-03-08 21:33:17 ----A---- C:\windows\system32\KBDTUQ.DLL
2011-03-08 21:33:17 ----A---- C:\windows\system32\KBDTUF.DLL
2011-03-08 21:33:17 ----A---- C:\windows\system32\KBDSG.DLL
2011-03-08 21:33:17 ----A---- C:\windows\system32\KBDPO.DLL
2011-03-08 21:33:17 ----A---- C:\windows\system32\KBDINBEN.DLL
2011-03-08 21:33:17 ----A---- C:\windows\system32\KBDGR1.DLL
2011-03-08 21:33:17 ----A---- C:\windows\system32\KBDGKL.DLL
2011-03-08 21:33:17 ----A---- C:\windows\system32\KBDCZ1.DLL
2011-03-08 21:33:17 ----A---- C:\windows\system32\dpnaddr.dll
2011-03-08 21:33:17 ----A---- C:\windows\system32\BlbEvents.dll
2011-03-08 21:32:58 ----A---- C:\windows\system32\wmicmiplugin.dll
2011-03-08 21:32:58 ----A---- C:\windows\system32\wbemcomn.dll
2011-03-08 21:32:52 ----A---- C:\windows\system32\SmiEngine.dll
2011-03-08 21:32:48 ----A---- C:\windows\system32\wdscore.dll
2011-03-08 21:32:48 ----A---- C:\windows\system32\PkgMgr.exe
2011-03-08 21:32:30 ----A---- C:\windows\system32\drvstore.dll
2011-03-08 21:32:30 ----A---- C:\windows\system32\dpx.dll
2011-03-08 21:17:20 ----A---- C:\windows\system32\sbe.dll
2011-03-08 21:17:20 ----A---- C:\windows\system32\EncDec.dll
2011-03-08 21:17:20 ----A---- C:\windows\system32\CPFilters.dll
2011-03-08 21:17:19 ----A---- C:\windows\system32\DWrite.dll
2011-03-08 21:17:18 ----A---- C:\windows\system32\FntCache.dll
2011-03-08 21:17:18 ----A---- C:\windows\system32\d2d1.dll
2011-03-08 21:17:16 ----A---- C:\windows\system32\d3d10_1.dll
Run by Admin at 2011-04-07 13:31:19
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 21 GB (42%) free of 50 GB
Total RAM: 2991 MB (61% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:31:29, on 7. 4. 2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal
Running processes:
C:\windows\system32\taskhost.exe
C:\windows\system32\taskeng.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe
C:\Program Files\Hewlett-Packard\File Sanitizer\coreshredder.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
D:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Syncrosoft\POS\H2O\cledx.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\windows\explorer.exe
D:\RSIT.exe
D:\Program Files\Image-Line\FL 9.8 Beta\FL.exe
C:\Program Files\trend micro\Admin.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R3 - URLSearchHook: (no name) - - (no file)
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: BHO_Startup - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files\Hewlett-Packard\File Sanitizer\IEBHO.dll
O2 - BHO: HP ProtectTools Security Manager Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O4 - HKLM\..\Run: [QLBController] C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe
O4 - HKLM\..\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe /hidden
O4 - HKLM\..\Run: [File Sanitizer] C:\Program Files\Hewlett-Packard\File Sanitizer\CoreShredder.exe
O4 - HKLM\..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [DTRun] c:\Program Files\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Hercules DJ Series] D:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe /boot
O4 - HKLM\..\Run: [Creative SB Monitoring Utility] RunDll32 sbavmon.dll,SBAVMonitor
O4 - HKLM\..\Run: [HPPowerAssistant] C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe /hidden
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ICQ] "D:\Program Files\ICQ7.4\ICQ.exe" silent loginmode=4
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\windows\WindowsMobile\INetRepl.dll
O9 - Extra button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - D:\Program Files\ICQ7.4\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - D:\Program Files\ICQ7.4\ICQ.exe
O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - Winlogon Notify: DeviceNP - DeviceNP.dll (file missing)
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9fc8b38ddee9fbba\aestsrv.exe
O23 - Service: AMD External Events Utility - AMD - C:\windows\system32\atiesrxx.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Ltd - c:\Windows\system32\flcdlock.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Hercules DJ Control MP3 (HerculesDJControlMP3) - Unknown owner - D:\Program Files\Hercules\Audio\DJ Console Series\HerculesDJControlMP3.EXE
O23 - Service: HP Health Check Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP Power Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
O23 - Service: HP ProtectTools Service - Hewlett-Packard Development Company, L.P - c:\Program Files\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP DayStarter Service (HPDayStarterService) - Hewlett-Packard Company - c:\Program Files\Hewlett-Packard\HP QuickLook\HPDayStarterService.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: Drive Encryption Service (HpFkCryptService) - McAfee, Inc. - c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
O23 - Service: File Sanitizer for HP ProtectTools (HPFSService) - Hewlett-Packard - C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe
O23 - Service: HP Hotkey Monitor (hpHotkeyMonitor) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard - C:\windows\system32\Hpservice.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9fc8b38ddee9fbba\STacSV.exe
O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - D:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe
O23 - Service: ArcCapture (uArcCapture) - ArcSoft, Inc. - C:\windows\system32\uArcCapture.exe
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\windows\system32\vcsFPService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
--
End of file - 11917 bytes
======Scheduled tasks folder======
C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-3863125621-3407463611-2706026323-1005Core.job
C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-3863125621-3407463611-2706026323-1005UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3134413B-49B4-425C-98A5-893C1F195601}]
File Sanitizer for HP ProtectTools - C:\Program Files\Hewlett-Packard\File Sanitizer\IEBHO.dll [2009-12-12 117248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{395610AE-C624-4f58-B89E-23733EA00F9A}]
HP ProtectTools Security Manager Extension - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll [2009-12-03 1471752]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-09-22 191792]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2011-02-23 814160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files\Windows Live\Companion\companioncore.dll [2010-11-10 393600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2011-02-23 814160]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"QLBController"=C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe [2010-01-05 254520]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2009-08-25 186904]
"PDF Complete"=C:\Program Files\PDF Complete\pdfsty.exe [2009-10-23 563736]
"HPWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe [2009-12-17 8192]
"File Sanitizer"=C:\Program Files\Hewlett-Packard\File Sanitizer\CoreShredder.exe [2009-12-12 11265536]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray.exe [2009-12-03 495711]
"DTRun"=c:\Program Files\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe [2009-11-19 518656]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-06-25 98304]
"Hercules DJ Series"=D:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe [2009-07-09 505128]
"Creative SB Monitoring Utility"=RunDll32 sbavmon.dll,SBAVMonitor []
"HPPowerAssistant"=C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe [2010-08-23 1691192]
"Windows Mobile Device Center"=C:\windows\WindowsMobile\wmdc.exe [2007-05-31 648072]
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2011-02-23 3451496]
"ZoneAlarm Client"=D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe [2010-11-16 1043968]
"H2O"=C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe [2005-10-23 385024]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2009-06-17 2363392]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2010-11-10 4240760]
"ICQ"=D:\Program Files\ICQ7.4\ICQ.exe [2011-03-01 119608]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DeviceNP]
C:\windows\system32\DeviceNP.dll [2009-11-18 75320]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\windows\system32\webcheck.dll [2010-11-20 229376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 months======
2011-04-06 20:30:10 ----A---- C:\windows\system32\drivers\aswSnx.sys
2011-04-06 20:25:07 ----A---- C:\windows\system32\drivers\aswSP.sys
2011-04-06 20:25:07 ----A---- C:\windows\system32\drivers\aswRdr.sys
2011-04-06 20:25:07 ----A---- C:\windows\system32\drivers\aswFsBlk.sys
2011-04-06 20:25:06 ----A---- C:\windows\system32\drivers\aswTdi.sys
2011-04-06 20:25:06 ----A---- C:\windows\system32\drivers\aswMonFlt.sys
2011-04-06 20:24:55 ----A---- C:\windows\system32\aswBoot.exe
2011-04-06 20:24:52 ----D---- C:\Program Files\Alwil Software
2011-03-24 19:13:55 ----A---- C:\TDSSKiller.2.4.21.0_24.03.2011_18.13.55_log.txt
2011-03-22 21:37:11 ----D---- C:\windows\temp
2011-03-22 21:37:09 ----A---- C:\ComboFix.txt
2011-03-22 21:33:37 ----D---- C:\$RECYCLE.BIN
2011-03-22 21:23:02 ----A---- C:\windows\zip.exe
2011-03-22 21:23:02 ----A---- C:\windows\SWSC.exe
2011-03-22 21:23:02 ----A---- C:\windows\SWREG.exe
2011-03-22 21:23:02 ----A---- C:\windows\sed.exe
2011-03-22 21:23:02 ----A---- C:\windows\PEV.exe
2011-03-22 21:23:02 ----A---- C:\windows\NIRCMD.exe
2011-03-22 21:23:02 ----A---- C:\windows\MBR.exe
2011-03-22 21:23:02 ----A---- C:\windows\grep.exe
2011-03-22 21:22:46 ----D---- C:\Qoobox
2011-03-22 21:22:29 ----A---- C:\windows\SWXCACLS.exe
2011-03-22 21:22:26 ----D---- C:\32788R22FWJFW
2011-03-08 21:38:30 ----D---- C:\windows\system32\SPReview
2011-03-08 21:37:42 ----D---- C:\windows\system32\EventProviders
2011-03-08 21:35:02 ----A---- C:\windows\system32\dfshim.dll
2011-03-08 21:34:59 ----A---- C:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2011-03-08 21:34:59 ----A---- C:\windows\system32\drivers\TsUsbFlt.sys
2011-03-08 21:34:58 ----A---- C:\windows\system32\mstscax.dll
2011-03-08 21:34:56 ----A---- C:\windows\system32\mfc40.dll
2011-03-08 21:34:56 ----A---- C:\windows\system32\d3d10warp.dll
2011-03-08 21:34:55 ----A---- C:\windows\system32\sysmain.dll
2011-03-08 21:34:55 ----A---- C:\windows\system32\mfc40u.dll
2011-03-08 21:34:54 ----A---- C:\windows\system32\shell32.dll
2011-03-08 21:34:54 ----A---- C:\windows\system32\secproc_isv.dll
2011-03-08 21:34:53 ----A---- C:\windows\system32\secproc.dll
2011-03-08 21:34:53 ----A---- C:\windows\system32\RMActivate_isv.exe
2011-03-08 21:34:52 ----A---- C:\windows\system32\RMActivate.exe
2011-03-08 21:34:52 ----A---- C:\windows\system32\ieframe.dll
2011-03-08 21:34:51 ----A---- C:\windows\system32\spwizui.dll
2011-03-08 21:34:51 ----A---- C:\windows\system32\mscoree.dll
2011-03-08 21:34:50 ----A---- C:\windows\system32\ntkrnlpa.exe
2011-03-08 21:34:50 ----A---- C:\windows\system32\mf.dll
2011-03-08 21:34:50 ----A---- C:\windows\system32\mcupdate_GenuineIntel.dll
2011-03-08 21:34:49 ----A---- C:\windows\system32\mssrch.dll
2011-03-08 21:34:49 ----A---- C:\windows\system32\iertutil.dll
2011-03-08 21:34:49 ----A---- C:\windows\system32\CertEnroll.dll
2011-03-08 21:34:48 ----A---- C:\windows\system32\wmp.dll
2011-03-08 21:34:48 ----A---- C:\windows\system32\PresentationHostProxy.dll
2011-03-08 21:34:48 ----A---- C:\windows\system32\PresentationHost.exe
2011-03-08 21:34:48 ----A---- C:\windows\system32\esent.dll
2011-03-08 21:34:48 ----A---- C:\windows\system32\drivers\msiscsi.sys
2011-03-08 21:34:48 ----A---- C:\windows\system32\drivers\hwpolicy.sys
2011-03-08 21:34:47 ----A---- C:\windows\system32\tquery.dll
2011-03-08 21:34:47 ----A---- C:\windows\system32\schedsvc.dll
2011-03-08 21:34:47 ----A---- C:\windows\system32\ntoskrnl.exe
2011-03-08 21:34:46 ----A---- C:\windows\system32\RacEngn.dll
2011-03-08 21:34:46 ----A---- C:\windows\system32\ntdll.dll
2011-03-08 21:34:46 ----A---- C:\windows\system32\AuthFWSnapin.dll
2011-03-08 21:34:45 ----A---- C:\windows\system32\wininet.dll
2011-03-08 21:34:45 ----A---- C:\windows\system32\rdpdd.dll
2011-03-08 21:34:45 ----A---- C:\windows\system32\qmgr.dll
2011-03-08 21:34:45 ----A---- C:\windows\system32\ExplorerFrame.dll
2011-03-08 21:34:44 ----A---- C:\windows\system32\wevtsvc.dll
2011-03-08 21:34:44 ----A---- C:\windows\system32\vssapi.dll
2011-03-08 21:34:44 ----A---- C:\windows\system32\urlmon.dll
2011-03-08 21:34:44 ----A---- C:\windows\system32\ole32.dll
2011-03-08 21:34:44 ----A---- C:\windows\system32\drivers\tcpip.sys
2011-03-08 21:34:43 ----A---- C:\windows\system32\taskschd.dll
2011-03-08 21:34:43 ----A---- C:\windows\system32\SearchFolder.dll
2011-03-08 21:34:43 ----A---- C:\windows\system32\IKEEXT.DLL
2011-03-08 21:34:43 ----A---- C:\windows\system32\d3d9.dll
2011-03-08 21:34:43 ----A---- C:\windows\explorer.exe
2011-03-08 21:34:42 ----A---- C:\windows\system32\termsrv.dll
2011-03-08 21:34:42 ----A---- C:\windows\system32\spreview.exe
2011-03-08 21:34:42 ----A---- C:\windows\system32\spinstall.exe
2011-03-08 21:34:42 ----A---- C:\windows\system32\mstsc.exe
2011-03-08 21:34:42 ----A---- C:\windows\system32\kernel32.dll
2011-03-08 21:34:42 ----A---- C:\windows\system32\drivers\ntfs.sys
2011-03-08 21:34:42 ----A---- C:\windows\system32\crypt32.dll
2011-03-08 21:34:41 ----A---- C:\windows\system32\wer.dll
2011-03-08 21:34:41 ----A---- C:\windows\system32\rpcrt4.dll
2011-03-08 21:34:41 ----A---- C:\windows\system32\msxml6.dll
2011-03-08 21:34:41 ----A---- C:\windows\system32\lsasrv.dll
2011-03-08 21:34:41 ----A---- C:\windows\system32\gpsvc.dll
2011-03-08 21:34:41 ----A---- C:\windows\system32\dwmcore.dll
2011-03-08 21:34:41 ----A---- C:\windows\system32\certcli.dll
2011-03-08 21:34:40 ----A---- C:\windows\system32\WinSAT.exe
2011-03-08 21:34:40 ----A---- C:\windows\system32\wbengine.exe
2011-03-08 21:34:40 ----A---- C:\windows\system32\scavengeui.dll
2011-03-08 21:34:40 ----A---- C:\windows\system32\odbc32.dll
2011-03-08 21:34:40 ----A---- C:\windows\system32\mstime.dll
2011-03-08 21:34:40 ----A---- C:\windows\system32\MPSSVC.dll
2011-03-08 21:34:40 ----A---- C:\windows\system32\diagperf.dll
2011-03-08 21:34:39 ----A---- C:\windows\system32\winhttp.dll
2011-03-08 21:34:39 ----A---- C:\windows\system32\TSWorkspace.dll
2011-03-08 21:34:39 ----A---- C:\windows\system32\tsmf.dll
2011-03-08 21:34:39 ----A---- C:\windows\system32\quartz.dll
2011-03-08 21:34:39 ----A---- C:\windows\system32\msfeeds.dll
2011-03-08 21:34:39 ----A---- C:\windows\system32\localspl.dll
2011-03-08 21:34:39 ----A---- C:\windows\system32\iedkcs32.dll
2011-03-08 21:34:39 ----A---- C:\windows\system32\dot3api.dll
2011-03-08 21:34:38 ----A---- C:\windows\system32\VSSVC.exe
2011-03-08 21:34:38 ----A---- C:\windows\system32\setupapi.dll
2011-03-08 21:34:38 ----A---- C:\windows\system32\netlogon.dll
2011-03-08 21:34:38 ----A---- C:\windows\system32\MSVidCtl.dll
2011-03-08 21:34:38 ----A---- C:\windows\system32\drivers\nvstor.sys
2011-03-08 21:34:38 ----A---- C:\windows\system32\dbgeng.dll
2011-03-08 21:34:38 ----A---- C:\windows\system32\apphelp.dll
2011-03-08 21:34:37 ----A---- C:\windows\system32\WindowsCodecs.dll
2011-03-08 21:34:37 ----A---- C:\windows\system32\netcfgx.dll
2011-03-08 21:34:37 ----A---- C:\windows\system32\d3d11.dll
2011-03-08 21:34:36 ----A---- C:\windows\system32\WsmSvc.dll
2011-03-08 21:34:36 ----A---- C:\windows\system32\WMVDECOD.DLL
2011-03-08 21:34:36 ----A---- C:\windows\system32\winlogon.exe
2011-03-08 21:34:36 ----A---- C:\windows\system32\webio.dll
2011-03-08 21:34:36 ----A---- C:\windows\system32\user32.dll
2011-03-08 21:34:36 ----A---- C:\windows\system32\Query.dll
2011-03-08 21:34:36 ----A---- C:\windows\system32\drivers\srv.sys
2011-03-08 21:34:36 ----A---- C:\windows\system32\drivers\rdpwd.sys
2011-03-08 21:34:36 ----A---- C:\windows\system32\advapi32.dll
2011-03-08 21:34:35 ----A---- C:\windows\system32\upnp.dll
2011-03-08 21:34:35 ----A---- C:\windows\system32\schannel.dll
2011-03-08 21:34:35 ----A---- C:\windows\system32\netfxperf.dll
2011-03-08 21:34:35 ----A---- C:\windows\system32\mmcndmgr.dll
2011-03-08 21:34:35 ----A---- C:\windows\system32\DShowRdpFilter.dll
2011-03-08 21:34:35 ----A---- C:\windows\system32\drivers\srv2.sys
2011-03-08 21:34:35 ----A---- C:\windows\system32\drivers\nvraid.sys
2011-03-08 21:34:34 ----A---- C:\windows\system32\sppobjs.dll
2011-03-08 21:34:34 ----A---- C:\windows\system32\SessEnv.dll
2011-03-08 21:34:34 ----A---- C:\windows\system32\PortableDeviceApi.dll
2011-03-08 21:34:34 ----A---- C:\windows\system32\msv1_0.dll
2011-03-08 21:34:34 ----A---- C:\windows\system32\msdrm.dll
2011-03-08 21:34:34 ----A---- C:\windows\system32\lsm.exe
2011-03-08 21:34:34 ----A---- C:\windows\system32\imapi2fs.dll
2011-03-08 21:34:34 ----A---- C:\windows\system32\authui.dll
2011-03-08 21:34:33 ----A---- C:\windows\system32\winload.exe
2011-03-08 21:34:33 ----A---- C:\windows\system32\usp10.dll
2011-03-08 21:34:33 ----A---- C:\windows\system32\userenv.dll
2011-03-08 21:34:33 ----A---- C:\windows\system32\shlwapi.dll
2011-03-08 21:34:33 ----A---- C:\windows\system32\mcbuilder.exe
2011-03-08 21:34:33 ----A---- C:\windows\system32\KernelBase.dll
2011-03-08 21:34:33 ----A---- C:\windows\system32\d3d10_1core.dll
2011-03-08 21:34:33 ----A---- C:\windows\system32\certmgr.dll
2011-03-08 21:34:32 ----A---- C:\windows\system32\xpsservices.dll
2011-03-08 21:34:32 ----A---- C:\windows\system32\WebClnt.dll
2011-03-08 21:34:32 ----A---- C:\windows\system32\umpnpmgr.dll
2011-03-08 21:34:32 ----A---- C:\windows\system32\sppwinob.dll
2011-03-08 21:34:32 ----A---- C:\windows\system32\rpcss.dll
2011-03-08 21:34:32 ----A---- C:\windows\system32\iphlpsvc.dll
2011-03-08 21:34:32 ----A---- C:\windows\system32\comdlg32.dll
2011-03-08 21:34:32 ----A---- C:\windows\system32\cmd.exe
2011-03-08 21:34:32 ----A---- C:\windows\system32\audiosrv.dll
2011-03-08 21:34:31 ----A---- C:\windows\system32\Wldap32.dll
2011-03-08 21:34:31 ----A---- C:\windows\system32\win32spl.dll
2011-03-08 21:34:31 ----A---- C:\windows\system32\propsys.dll
2011-03-08 21:34:31 ----A---- C:\windows\system32\nlasvc.dll
2011-03-08 21:34:31 ----A---- C:\windows\system32\mfds.dll
2011-03-08 21:34:31 ----A---- C:\windows\system32\framedynos.dll
2011-03-08 21:34:31 ----A---- C:\windows\system32\drivers\volsnap.sys
2011-03-08 21:34:31 ----A---- C:\windows\system32\dnsapi.dll
2011-03-08 21:34:31 ----A---- C:\windows\system32\BFE.DLL
2011-03-08 21:34:30 ----A---- C:\windows\system32\wucltux.dll
2011-03-08 21:34:30 ----A---- C:\windows\system32\wuaueng.dll
2011-03-08 21:34:30 ----A---- C:\windows\system32\winresume.exe
2011-03-08 21:34:30 ----A---- C:\windows\system32\samsrv.dll
2011-03-08 21:34:30 ----A---- C:\windows\system32\profsvc.dll
2011-03-08 21:34:30 ----A---- C:\windows\system32\ncsi.dll
2011-03-08 21:34:30 ----A---- C:\windows\system32\drivers\netio.sys
2011-03-08 21:34:30 ----A---- C:\windows\system32\drivers\ndis.sys
2011-03-08 21:34:30 ----A---- C:\windows\system32\azroles.dll
2011-03-08 21:34:29 ----A---- C:\windows\system32\werconcpl.dll
2011-03-08 21:34:29 ----A---- C:\windows\system32\themeui.dll
2011-03-08 21:34:29 ----A---- C:\windows\system32\taskeng.exe
2011-03-08 21:34:29 ----A---- C:\windows\system32\spp.dll
2011-03-08 21:34:29 ----A---- C:\windows\system32\mswsock.dll
2011-03-08 21:34:29 ----A---- C:\windows\system32\drivers\storport.sys
2011-03-08 21:34:29 ----A---- C:\windows\system32\drivers\mrxsmb10.sys
2011-03-08 21:34:29 ----A---- C:\windows\system32\dhcpcore.dll
2011-03-08 21:34:29 ----A---- C:\windows\system32\credui.dll
2011-03-08 21:34:28 ----A---- C:\windows\system32\wintrust.dll
2011-03-08 21:34:28 ----A---- C:\windows\system32\taskcomp.dll
2011-03-08 21:34:28 ----A---- C:\windows\system32\NaturalLanguage6.dll
2011-03-08 21:34:28 ----A---- C:\windows\system32\msxml3.dll
2011-03-08 21:34:28 ----A---- C:\windows\system32\mfreadwrite.dll
2011-03-08 21:34:28 ----A---- C:\windows\system32\inetcomm.dll
2011-03-08 21:34:28 ----A---- C:\windows\system32\evr.dll
2011-03-08 21:34:28 ----A---- C:\windows\system32\dxgi.dll
2011-03-08 21:34:28 ----A---- C:\windows\system32\drivers\mrxdav.sys
2011-03-08 21:34:28 ----A---- C:\windows\system32\drivers\http.sys
2011-03-08 21:34:28 ----A---- C:\windows\system32\dbghelp.dll
2011-03-08 21:34:28 ----A---- C:\windows\system32\basecsp.dll
2011-03-08 21:34:27 ----A---- C:\windows\system32\WinSATAPI.dll
2011-03-08 21:34:27 ----A---- C:\windows\system32\vpnike.dll
2011-03-08 21:34:27 ----A---- C:\windows\system32\sqlsrv32.dll
2011-03-08 21:34:27 ----A---- C:\windows\system32\spoolsv.exe
2011-03-08 21:34:27 ----A---- C:\windows\system32\QAGENTRT.DLL
2011-03-08 21:34:27 ----A---- C:\windows\system32\gdi32.dll
2011-03-08 21:34:27 ----A---- C:\windows\system32\drivers\amdsata.sys
2011-03-08 21:34:27 ----A---- C:\windows\system32\drivers\1394ohci.sys
2011-03-08 21:34:27 ----A---- C:\windows\system32\calc.exe
2011-03-08 21:34:26 ----A---- C:\windows\system32\UIRibbon.dll
2011-03-08 21:34:26 ----A---- C:\windows\system32\sxs.dll
2011-03-08 21:34:26 ----A---- C:\windows\system32\srvsvc.dll
2011-03-08 21:34:26 ----A---- C:\windows\system32\lpksetup.exe
2011-03-08 21:34:26 ----A---- C:\windows\system32\ie4uinit.exe
2011-03-08 21:34:26 ----A---- C:\windows\system32\fveapi.dll
2011-03-08 21:34:26 ----A---- C:\windows\system32\drivers\fvevol.sys
2011-03-08 21:34:26 ----A---- C:\windows\system32\cryptsvc.dll
2011-03-08 21:34:25 ----A---- C:\windows\system32\ws2_32.dll
2011-03-08 21:34:25 ----A---- C:\windows\system32\stobject.dll
2011-03-08 21:34:25 ----A---- C:\windows\system32\prncache.dll
2011-03-08 21:34:25 ----A---- C:\windows\system32\printui.dll
2011-03-08 21:34:25 ----A---- C:\windows\system32\netshell.dll
2011-03-08 21:34:25 ----A---- C:\windows\system32\inetpp.dll
2011-03-08 21:34:25 ----A---- C:\windows\system32\hgprint.dll
2011-03-08 21:34:25 ----A---- C:\windows\system32\drivers\rdbss.sys
2011-03-08 21:34:25 ----A---- C:\windows\system32\drivers\msdsm.sys
2011-03-08 21:34:25 ----A---- C:\windows\system32\comctl32.dll
2011-03-08 21:34:24 ----A---- C:\windows\system32\WSDApi.dll
2011-03-08 21:34:24 ----A---- C:\windows\system32\wmpeffects.dll
2011-03-08 21:34:24 ----A---- C:\windows\system32\rpchttp.dll
2011-03-08 21:34:24 ----A---- C:\windows\system32\net1.exe
2011-03-08 21:34:24 ----A---- C:\windows\system32\msi.dll
2011-03-08 21:34:24 ----A---- C:\windows\system32\dps.dll
2011-03-08 21:34:24 ----A---- C:\windows\system32\dnsrslvr.dll
2011-03-08 21:34:24 ----A---- C:\windows\system32\ci.dll
2011-03-08 21:34:24 ----A---- C:\windows\system32\aitagent.exe
2011-03-08 21:34:24 ----A---- C:\windows\system32\aepdu.dll
2011-03-08 21:34:23 ----A---- C:\windows\system32\vds.exe
2011-03-08 21:34:23 ----A---- C:\windows\system32\scansetting.dll
2011-03-08 21:34:23 ----A---- C:\windows\system32\mfc42u.dll
2011-03-08 21:34:23 ----A---- C:\windows\system32\FXSSVC.exe
2011-03-08 21:34:23 ----A---- C:\windows\system32\drivers\pci.sys
2011-03-08 21:34:23 ----A---- C:\windows\system32\drivers\mrxsmb.sys
2011-03-08 21:34:22 ----A---- C:\windows\system32\WMVCORE.DLL
2011-03-08 21:34:22 ----A---- C:\windows\system32\wlangpui.dll
2011-03-08 21:34:22 ----A---- C:\windows\system32\QSHVHOST.DLL
2011-03-08 21:34:22 ----A---- C:\windows\system32\MMDevAPI.dll
2011-03-08 21:34:22 ----A---- C:\windows\system32\IPSECSVC.DLL
2011-03-08 21:34:22 ----A---- C:\windows\system32\drivers\usbport.sys
2011-03-08 21:34:22 ----A---- C:\windows\system32\drivers\mrxsmb20.sys
2011-03-08 21:34:22 ----A---- C:\windows\system32\davclnt.dll
2011-03-08 21:34:22 ----A---- C:\windows\system32\consent.exe
2011-03-08 21:34:22 ----A---- C:\windows\system32\aaclient.dll
2011-03-08 21:34:21 ----A---- C:\windows\system32\wpdshext.dll
2011-03-08 21:34:21 ----A---- C:\windows\system32\webservices.dll
2011-03-08 21:34:21 ----A---- C:\windows\system32\t2embed.dll
2011-03-08 21:34:21 ----A---- C:\windows\system32\pnidui.dll
2011-03-08 21:34:21 ----A---- C:\windows\system32\fde.dll
2011-03-08 21:34:21 ----A---- C:\windows\system32\drivers\termdd.sys
2011-03-08 21:34:20 ----A---- C:\windows\system32\wuapi.dll
2011-03-08 21:34:20 ----A---- C:\windows\system32\wscapi.dll
2011-03-08 21:34:20 ----A---- C:\windows\system32\TsUsbGDCoInstaller.dll
2011-03-08 21:34:20 ----A---- C:\windows\system32\SyncCenter.dll
2011-03-08 21:34:20 ----A---- C:\windows\system32\sdengin2.dll
2011-03-08 21:34:20 ----A---- C:\windows\system32\netdiagfx.dll
2011-03-08 21:34:20 ----A---- C:\windows\system32\drivers\sbp2port.sys
2011-03-08 21:34:20 ----A---- C:\windows\system32\drivers\amdxata.sys
2011-03-08 21:34:19 ----A---- C:\windows\system32\wisptis.exe
2011-03-08 21:34:19 ----A---- C:\windows\system32\WinSCard.dll
2011-03-08 21:34:19 ----A---- C:\windows\system32\WFS.exe
2011-03-08 21:34:19 ----A---- C:\windows\system32\pla.dll
2011-03-08 21:34:19 ----A---- C:\windows\system32\MSMPEG2ENC.DLL
2011-03-08 21:34:19 ----A---- C:\windows\system32\msasn1.dll
2011-03-08 21:34:19 ----A---- C:\windows\system32\mcmde.dll
2011-03-08 21:34:19 ----A---- C:\windows\system32\drivers\vhdmp.sys
2011-03-08 21:34:18 ----A---- C:\windows\system32\WUDFSvc.dll
2011-03-08 21:34:18 ----A---- C:\windows\system32\winsta.dll
2011-03-08 21:34:18 ----A---- C:\windows\system32\wiaservc.dll
2011-03-08 21:34:18 ----A---- C:\windows\system32\setupcl.exe
2011-03-08 21:34:18 ----A---- C:\windows\system32\rdpcore.dll
2011-03-08 21:34:18 ----A---- C:\windows\system32\ntshrui.dll
2011-03-08 21:34:18 ----A---- C:\windows\system32\imapi2.dll
2011-03-08 21:34:18 ----A---- C:\windows\system32\iepeers.dll
2011-03-08 21:34:18 ----A---- C:\windows\system32\DXPTaskRingtone.dll
2011-03-08 21:34:18 ----A---- C:\windows\system32\drivers\msahci.sys
2011-03-08 21:34:18 ----A---- C:\windows\system32\conhost.exe
2011-03-08 21:34:18 ----A---- C:\windows\system32\aeinv.dll
2011-03-08 21:34:17 ----A---- C:\windows\system32\gameux.dll
2011-03-08 21:34:17 ----A---- C:\windows\system32\dwmredir.dll
2011-03-08 21:34:17 ----A---- C:\windows\system32\drivers\Diskdump.sys
2011-03-08 21:34:16 ----A---- C:\windows\system32\WMPEncEn.dll
2011-03-08 21:34:16 ----A---- C:\windows\system32\winmm.dll
2011-03-08 21:34:16 ----A---- C:\windows\system32\vaultsvc.dll
2011-03-08 21:34:16 ----A---- C:\windows\system32\TabSvc.dll
2011-03-08 21:34:16 ----A---- C:\windows\system32\shsvcs.dll
2011-03-08 21:34:16 ----A---- C:\windows\system32\rasmans.dll
2011-03-08 21:34:16 ----A---- C:\windows\system32\onex.dll
2011-03-08 21:34:16 ----A---- C:\windows\system32\mssvp.dll
2011-03-08 21:34:16 ----A---- C:\windows\system32\hbaapi.dll
2011-03-08 21:34:16 ----A---- C:\windows\system32\drivers\udfs.sys
2011-03-08 21:34:16 ----A---- C:\windows\system32\drivers\acpi.sys
2011-03-08 21:34:16 ----A---- C:\windows\system32\autofmt.exe
2011-03-08 21:34:15 ----A---- C:\windows\system32\samcli.dll
2011-03-08 21:34:15 ----A---- C:\windows\system32\proquota.exe
2011-03-08 21:34:15 ----A---- C:\windows\system32\netiohlp.dll
2011-03-08 21:34:15 ----A---- C:\windows\system32\Narrator.exe
2011-03-08 21:34:15 ----A---- C:\windows\system32\msutb.dll
2011-03-08 21:34:15 ----A---- C:\windows\system32\IPHLPAPI.DLL
2011-03-08 21:34:15 ----A---- C:\windows\system32\halmacpi.dll
2011-03-08 21:34:15 ----A---- C:\windows\system32\hal.dll
2011-03-08 21:34:15 ----A---- C:\windows\system32\bootres.dll
2011-03-08 21:34:15 ----A---- C:\windows\system32\autochk.exe
2011-03-08 21:34:15 ----A---- C:\windows\system32\autoconv.exe
2011-03-08 21:34:15 ----A---- C:\windows\system32\AudioSes.dll
2011-03-08 21:34:15 ----A---- C:\windows\system32\audiodg.exe
2011-03-08 21:34:14 ----A---- C:\windows\system32\wcncsvc.dll
2011-03-08 21:34:14 ----A---- C:\windows\system32\thumbcache.dll
2011-03-08 21:34:14 ----A---- C:\windows\system32\tcpipcfg.dll
2011-03-08 21:34:14 ----A---- C:\windows\system32\srchadmin.dll
2011-03-08 21:34:14 ----A---- C:\windows\system32\schtasks.exe
2011-03-08 21:34:14 ----A---- C:\windows\system32\regapi.dll
2011-03-08 21:34:14 ----A---- C:\windows\system32\powercpl.dll
2011-03-08 21:34:14 ----A---- C:\windows\system32\msinfo32.exe
2011-03-08 21:34:14 ----A---- C:\windows\system32\msihnd.dll
2011-03-08 21:34:14 ----A---- C:\windows\system32\mimefilt.dll
2011-03-08 21:34:14 ----A---- C:\windows\system32\ipsmsnap.dll
2011-03-08 21:34:14 ----A---- C:\windows\system32\framedyn.dll
2011-03-08 21:34:14 ----A---- C:\windows\system32\eapphost.dll
2011-03-08 21:34:14 ----A---- C:\windows\system32\drivers\winusb.sys
2011-03-08 21:34:14 ----A---- C:\windows\system32\drivers\volmgr.sys
2011-03-08 21:34:14 ----A---- C:\windows\system32\drivers\srvnet.sys
2011-03-08 21:34:13 ----A---- C:\windows\system32\umpo.dll
2011-03-08 21:34:13 ----A---- C:\windows\system32\sspicli.dll
2011-03-08 21:34:13 ----A---- C:\windows\system32\QAGENT.DLL
2011-03-08 21:34:13 ----A---- C:\windows\system32\netid.dll
2011-03-08 21:34:13 ----A---- C:\windows\system32\mscorier.dll
2011-03-08 21:34:13 ----A---- C:\windows\system32\FXSCOVER.exe
2011-03-08 21:34:13 ----A---- C:\windows\system32\DXP.dll
2011-03-08 21:34:13 ----A---- C:\windows\system32\drivers\USBSTOR.SYS
2011-03-08 21:34:13 ----A---- C:\windows\system32\drivers\partmgr.sys
2011-03-08 21:34:13 ----A---- C:\windows\system32\drivers\netbt.sys
2011-03-08 21:34:13 ----A---- C:\windows\system32\AuxiliaryDisplayCpl.dll
2011-03-08 21:34:12 ----A---- C:\windows\system32\wdc.dll
2011-03-08 21:34:12 ----A---- C:\windows\system32\untfs.dll
2011-03-08 21:34:12 ----A---- C:\windows\system32\StructuredQuery.dll
2011-03-08 21:34:12 ----A---- C:\windows\system32\scesrv.dll
2011-03-08 21:34:12 ----A---- C:\windows\system32\rastls.dll
2011-03-08 21:34:12 ----A---- C:\windows\system32\oleaut32.dll
2011-03-08 21:34:12 ----A---- C:\windows\system32\drivers\ataport.sys
2011-03-08 21:34:12 ----A---- C:\windows\system32\actxprxy.dll
2011-03-08 21:34:11 ----A---- C:\windows\system32\WMNetMgr.dll
2011-03-08 21:34:11 ----A---- C:\windows\system32\wlanpref.dll
2011-03-08 21:34:11 ----A---- C:\windows\system32\Vault.dll
2011-03-08 21:34:11 ----A---- C:\windows\system32\sppsvc.exe
2011-03-08 21:34:11 ----A---- C:\windows\system32\sdclt.exe
2011-03-08 21:34:11 ----A---- C:\windows\system32\RpcRtRemote.dll
2011-03-08 21:34:11 ----A---- C:\windows\system32\Robocopy.exe
2011-03-08 21:34:11 ----A---- C:\windows\system32\nci.dll
2011-03-08 21:34:11 ----A---- C:\windows\system32\ListSvc.dll
2011-03-08 21:34:11 ----A---- C:\windows\system32\licmgr10.dll
2011-03-08 21:34:10 ----A---- C:\windows\system32\taskmgr.exe
2011-03-08 21:34:10 ----A---- C:\windows\system32\mtxclu.dll
2011-03-08 21:34:10 ----A---- C:\windows\system32\DxpTaskSync.dll
2011-03-08 21:34:10 ----A---- C:\windows\system32\drivers\FWPKCLNT.SYS
2011-03-08 21:34:10 ----A---- C:\windows\system32\Display.dll
2011-03-08 21:34:09 ----A---- C:\windows\system32\XpsRasterService.dll
2011-03-08 21:34:09 ----A---- C:\windows\system32\userinit.exe
2011-03-08 21:34:09 ----A---- C:\windows\system32\sharemediacpl.dll
2011-03-08 21:34:09 ----A---- C:\windows\system32\puiobj.dll
2011-03-08 21:34:09 ----A---- C:\windows\system32\mssphtb.dll
2011-03-08 21:34:09 ----A---- C:\windows\system32\msdri.dll
2011-03-08 21:34:09 ----A---- C:\windows\system32\drivers\usbvideo.sys
2011-03-08 21:34:09 ----A---- C:\windows\system32\drivers\mpio.sys
2011-03-08 21:34:09 ----A---- C:\windows\system32\drivers\mountmgr.sys
2011-03-08 21:34:09 ----A---- C:\windows\system32\drivers\iaStorV.sys
2011-03-08 21:34:08 ----A---- C:\windows\system32\termmgr.dll
2011-03-08 21:34:08 ----A---- C:\windows\system32\eudcedit.exe
2011-03-08 21:34:08 ----A---- C:\windows\system32\drivers\usbehci.sys
2011-03-08 21:34:08 ----A---- C:\windows\system32\drivers\scsiport.sys
2011-03-08 21:34:08 ----A---- C:\windows\system32\DiagCpl.dll
2011-03-08 21:34:07 ----A---- C:\windows\system32\wiadefui.dll
2011-03-08 21:34:07 ----A---- C:\windows\system32\sppcomapi.dll
2011-03-08 21:34:07 ----A---- C:\windows\system32\shsetup.dll
2011-03-08 21:34:07 ----A---- C:\windows\system32\rasppp.dll
2011-03-08 21:34:07 ----A---- C:\windows\system32\msdtctm.dll
2011-03-08 21:34:07 ----A---- C:\windows\system32\msconfig.exe
2011-03-08 21:34:07 ----A---- C:\windows\system32\logoncli.dll
2011-03-08 21:34:07 ----A---- C:\windows\system32\FirewallControlPanel.dll
2011-03-08 21:34:07 ----A---- C:\windows\system32\cabview.dll
2011-03-08 21:34:07 ----A---- C:\windows\system32\biocpl.dll
2011-03-08 21:34:06 ----A---- C:\windows\system32\wpccpl.dll
2011-03-08 21:34:06 ----A---- C:\windows\system32\themecpl.dll
2011-03-08 21:34:06 ----A---- C:\windows\system32\SensorsCpl.dll
2011-03-08 21:34:06 ----A---- C:\windows\system32\FWPUCLNT.DLL
2011-03-08 21:34:06 ----A---- C:\windows\system32\drivers\rdyboost.sys
2011-03-08 21:34:06 ----A---- C:\windows\system32\drivers\BTHUSB.SYS
2011-03-08 21:34:06 ----A---- C:\windows\system32\dnscmmc.dll
2011-03-08 21:34:05 ----A---- C:\windows\system32\winsrv.dll
2011-03-08 21:34:05 ----A---- C:\windows\system32\tapisrv.dll
2011-03-08 21:34:05 ----A---- C:\windows\system32\scecli.dll
2011-03-08 21:34:05 ----A---- C:\windows\system32\mscories.dll
2011-03-08 21:34:05 ----A---- C:\windows\system32\mscms.dll
2011-03-08 21:34:05 ----A---- C:\windows\system32\localsec.dll
2011-03-08 21:34:05 ----A---- C:\windows\system32\hgcpl.dll
2011-03-08 21:34:05 ----A---- C:\windows\system32\fontext.dll
2011-03-08 21:34:05 ----A---- C:\windows\system32\drivers\ksecdd.sys
2011-03-08 21:34:04 ----A---- C:\windows\system32\wlanui.dll
2011-03-08 21:34:04 ----A---- C:\windows\system32\wkssvc.dll
2011-03-08 21:34:04 ----A---- C:\windows\system32\VAN.dll
2011-03-08 21:34:04 ----A---- C:\windows\system32\usercpl.dll
2011-03-08 21:34:04 ----A---- C:\windows\system32\srcore.dll
2011-03-08 21:34:04 ----A---- C:\windows\system32\SndVolSSO.dll
2011-03-08 21:34:04 ----A---- C:\windows\system32\qedit.dll
2011-03-08 21:34:04 ----A---- C:\windows\system32\prntvpt.dll
2011-03-08 21:34:04 ----A---- C:\windows\system32\PerfCenterCPL.dll
2011-03-08 21:34:04 ----A---- C:\windows\system32\mprddm.dll
2011-03-08 21:34:04 ----A---- C:\windows\system32\KMSVC.DLL
2011-03-08 21:34:04 ----A---- C:\windows\system32\iasacct.dll
2011-03-08 21:34:04 ----A---- C:\windows\system32\drivers\usbhub.sys
2011-03-08 21:34:04 ----A---- C:\windows\system32\bcdsrv.dll
2011-03-08 21:34:04 ----A---- C:\windows\system32\batmeter.dll
2011-03-08 21:34:03 ----A---- C:\windows\system32\wpdbusenum.dll
2011-03-08 21:34:03 ----A---- C:\windows\system32\wksprt.exe
2011-03-08 21:34:03 ----A---- C:\windows\system32\w32tm.exe
2011-03-08 21:34:03 ----A---- C:\windows\system32\spwizeng.dll
2011-03-08 21:34:03 ----A---- C:\windows\system32\SndVol.exe
2011-03-08 21:34:03 ----A---- C:\windows\system32\qdvd.dll
2011-03-08 21:34:03 ----A---- C:\windows\system32\netcenter.dll
2011-03-08 21:34:03 ----A---- C:\windows\system32\mblctr.exe
2011-03-08 21:34:03 ----A---- C:\windows\system32\drivers\afd.sys
2011-03-08 21:34:03 ----A---- C:\windows\system32\azroleui.dll
2011-03-08 21:34:03 ----A---- C:\windows\system32\accessibilitycpl.dll
2011-03-08 21:34:02 ----A---- C:\windows\system32\zipfldr.dll
2011-03-08 21:34:02 ----A---- C:\windows\system32\networkmap.dll
2011-03-08 21:34:02 ----A---- C:\windows\system32\netjoin.dll
2011-03-08 21:34:02 ----A---- C:\windows\system32\MSAC3ENC.DLL
2011-03-08 21:34:02 ----A---- C:\windows\system32\fdeploy.dll
2011-03-08 21:34:02 ----A---- C:\windows\system32\drivers\ks.sys
2011-03-08 21:34:02 ----A---- C:\windows\system32\cryptui.dll
2011-03-08 21:34:02 ----A---- C:\windows\system32\adsldp.dll
2011-03-08 21:34:01 ----A---- C:\windows\system32\wusa.exe
2011-03-08 21:34:01 ----A---- C:\windows\system32\sud.dll
2011-03-08 21:34:01 ----A---- C:\windows\system32\prnfldr.dll
2011-03-08 21:34:01 ----A---- C:\windows\system32\photowiz.dll
2011-03-08 21:34:01 ----A---- C:\windows\system32\OnLineIDCpl.dll
2011-03-08 21:34:01 ----A---- C:\windows\system32\mspbda.dll
2011-03-08 21:34:01 ----A---- C:\windows\system32\msieftp.dll
2011-03-08 21:34:01 ----A---- C:\windows\system32\MCEWMDRMNDBootstrap.dll
2011-03-08 21:34:01 ----A---- C:\windows\system32\Faultrep.dll
2011-03-08 21:34:01 ----A---- C:\windows\system32\cfgmgr32.dll
2011-03-08 21:34:01 ----A---- C:\windows\system32\ActionCenter.dll
2011-03-08 21:34:00 ----A---- C:\windows\system32\taskhost.exe
2011-03-08 21:34:00 ----A---- C:\windows\system32\taskbarcpl.dll
2011-03-08 21:34:00 ----A---- C:\windows\system32\slui.exe
2011-03-08 21:34:00 ----A---- C:\windows\system32\rdpcorekmts.dll
2011-03-08 21:34:00 ----A---- C:\windows\system32\MediaMetadataHandler.dll
2011-03-08 21:34:00 ----A---- C:\windows\system32\iprtrmgr.dll
2011-03-08 21:34:00 ----A---- C:\windows\system32\iasrad.dll
2011-03-08 21:34:00 ----A---- C:\windows\system32\drivers\hidclass.sys
2011-03-08 21:34:00 ----A---- C:\windows\system32\dot3cfg.dll
2011-03-08 21:34:00 ----A---- C:\windows\system32\defaultlocationcpl.dll
2011-03-08 21:34:00 ----A---- C:\windows\system32\credssp.dll
2011-03-08 21:33:59 ----A---- C:\windows\system32\wpd_ci.dll
2011-03-08 21:33:59 ----A---- C:\windows\system32\sisbkup.dll
2011-03-08 21:33:59 ----A---- C:\windows\system32\shwebsvc.dll
2011-03-08 21:33:59 ----A---- C:\windows\system32\odbcjt32.dll
2011-03-08 21:33:59 ----A---- C:\windows\system32\ifsutil.dll
2011-03-08 21:33:59 ----A---- C:\windows\system32\ieUnatt.exe
2011-03-08 21:33:59 ----A---- C:\windows\system32\iesysprep.dll
2011-03-08 21:33:59 ----A---- C:\windows\system32\halacpi.dll
2011-03-08 21:33:59 ----A---- C:\windows\system32\ftp.exe
2011-03-08 21:33:59 ----A---- C:\windows\system32\efscore.dll
2011-03-08 21:33:58 ----A---- C:\windows\system32\syncui.dll
2011-03-08 21:33:58 ----A---- C:\windows\system32\sdcpl.dll
2011-03-08 21:33:58 ----A---- C:\windows\system32\recovery.dll
2011-03-08 21:33:58 ----A---- C:\windows\system32\rdpwsx.dll
2011-03-08 21:33:58 ----A---- C:\windows\system32\fsquirt.exe
2011-03-08 21:33:58 ----A---- C:\windows\system32\DeviceCenter.dll
2011-03-08 21:33:58 ----A---- C:\windows\system32\bcdedit.exe
2011-03-08 21:33:58 ----A---- C:\windows\system32\autoplay.dll
2011-03-08 21:33:58 ----A---- C:\windows\system32\ActionCenterCPL.dll
2011-03-08 21:33:57 ----A---- C:\windows\system32\wmpmde.dll
2011-03-08 21:33:57 ----A---- C:\windows\system32\vdsutil.dll
2011-03-08 21:33:57 ----A---- C:\windows\system32\systemcpl.dll
2011-03-08 21:33:57 ----A---- C:\windows\system32\sppnp.dll
2011-03-08 21:33:57 ----A---- C:\windows\system32\rtutils.dll
2011-03-08 21:33:57 ----A---- C:\windows\system32\recdisc.exe
2011-03-08 21:33:57 ----A---- C:\windows\system32\OobeFldr.dll
2011-03-08 21:33:57 ----A---- C:\windows\system32\ntprint.dll
2011-03-08 21:33:57 ----A---- C:\windows\system32\ntlanman.dll
2011-03-08 21:33:57 ----A---- C:\windows\system32\dskquoui.dll
2011-03-08 21:33:56 ----A---- C:\windows\system32\SmartcardCredentialProvider.dll
2011-03-08 21:33:56 ----A---- C:\windows\system32\sethc.exe
2011-03-08 21:33:56 ----A---- C:\windows\system32\rstrui.exe
2011-03-08 21:33:56 ----A---- C:\windows\system32\riched20.dll
2011-03-08 21:33:56 ----A---- C:\windows\system32\nshwfp.dll
2011-03-08 21:33:56 ----A---- C:\windows\system32\drivers\tdx.sys
2011-03-08 21:33:56 ----A---- C:\windows\system32\blackbox.dll
2011-03-08 21:33:56 ----A---- C:\windows\system32\bcdboot.exe
2011-03-08 21:33:56 ----A---- C:\windows\system32\AxInstSv.dll
2011-03-08 21:33:55 ----A---- C:\windows\system32\wmpsrcwp.dll
2011-03-08 21:33:55 ----A---- C:\windows\system32\netplwiz.dll
2011-03-08 21:33:55 ----A---- C:\windows\system32\NAPHLPR.DLL
2011-03-08 21:33:55 ----A---- C:\windows\system32\migisol.dll
2011-03-08 21:33:55 ----A---- C:\windows\system32\httpapi.dll
2011-03-08 21:33:55 ----A---- C:\windows\system32\fms.dll
2011-03-08 21:33:55 ----A---- C:\windows\system32\drivers\tssecsrv.sys
2011-03-08 21:33:55 ----A---- C:\windows\system32\dot3svc.dll
2011-03-08 21:33:55 ----A---- C:\windows\system32\cdosys.dll
2011-03-08 21:33:55 ----A---- C:\windows\system32\AuxiliaryDisplayServices.dll
2011-03-08 21:33:55 ----A---- C:\windows\system32\activeds.dll
2011-03-08 21:33:54 ----A---- C:\windows\system32\wsqmcons.exe
2011-03-08 21:33:54 ----A---- C:\windows\system32\wlanmsm.dll
2011-03-08 21:33:54 ----A---- C:\windows\system32\wavemsp.dll
2011-03-08 21:33:54 ----A---- C:\windows\system32\ReAgent.dll
2011-03-08 21:33:54 ----A---- C:\windows\system32\nshipsec.dll
2011-03-08 21:33:54 ----A---- C:\windows\system32\nlaapi.dll
2011-03-08 21:33:54 ----A---- C:\windows\system32\msftedit.dll
2011-03-08 21:33:54 ----A---- C:\windows\system32\isoburn.exe
2011-03-08 21:33:54 ----A---- C:\windows\system32\asycfilt.dll
2011-03-08 21:33:53 ----A---- C:\windows\system32\wvc.dll
2011-03-08 21:33:53 ----A---- C:\windows\system32\wuwebv.dll
2011-03-08 21:33:53 ----A---- C:\windows\system32\wtsapi32.dll
2011-03-08 21:33:53 ----A---- C:\windows\system32\tzutil.exe
2011-03-08 21:33:53 ----A---- C:\windows\system32\sysclass.dll
2011-03-08 21:33:53 ----A---- C:\windows\system32\provsvc.dll
2011-03-08 21:33:53 ----A---- C:\windows\system32\ocsetup.exe
2011-03-08 21:33:53 ----A---- C:\windows\system32\dsuiext.dll
2011-03-08 21:33:53 ----A---- C:\windows\system32\drivers\ndproxy.sys
2011-03-08 21:33:53 ----A---- C:\windows\system32\dot3ui.dll
2011-03-08 21:33:53 ----A---- C:\windows\system32\dfrgui.exe
2011-03-08 21:33:53 ----A---- C:\windows\system32\appinfo.dll
2011-03-08 21:33:52 ----A---- C:\windows\system32\wimgapi.dll
2011-03-08 21:33:52 ----A---- C:\windows\system32\webcheck.dll
2011-03-08 21:33:52 ----A---- C:\windows\system32\twext.dll
2011-03-08 21:33:52 ----A---- C:\windows\system32\shdocvw.dll
2011-03-08 21:33:52 ----A---- C:\windows\system32\mstask.dll
2011-03-08 21:33:52 ----A---- C:\windows\system32\certprop.dll
2011-03-08 21:33:51 ----A---- C:\windows\twain_32.dll
2011-03-08 21:33:51 ----A---- C:\windows\system32\uxlib.dll
2011-03-08 21:33:51 ----A---- C:\windows\system32\slwga.dll
2011-03-08 21:33:51 ----A---- C:\windows\system32\setupugc.exe
2011-03-08 21:33:51 ----A---- C:\windows\system32\qcap.dll
2011-03-08 21:33:51 ----A---- C:\windows\system32\qasf.dll
2011-03-08 21:33:51 ----A---- C:\windows\system32\occache.dll
2011-03-08 21:33:51 ----A---- C:\windows\system32\msrating.dll
2011-03-08 21:33:51 ----A---- C:\windows\system32\msfeedsbs.dll
2011-03-08 21:33:51 ----A---- C:\windows\system32\imm32.dll
2011-03-08 21:33:50 ----A---- C:\windows\system32\wwanconn.dll
2011-03-08 21:33:50 ----A---- C:\windows\system32\wmdrmsdk.dll
2011-03-08 21:33:50 ----A---- C:\windows\system32\srrstr.dll
2011-03-08 21:33:50 ----A---- C:\windows\system32\nslookup.exe
2011-03-08 21:33:50 ----A---- C:\windows\system32\msvfw32.dll
2011-03-08 21:33:50 ----A---- C:\windows\system32\mciavi32.dll
2011-03-08 21:33:50 ----A---- C:\windows\system32\imgutil.dll
2011-03-08 21:33:50 ----A---- C:\windows\system32\clusapi.dll
2011-03-08 21:33:50 ----A---- C:\windows\system32\audiodev.dll
2011-03-08 21:33:49 ----A---- C:\windows\system32\WPDShServiceObj.dll
2011-03-08 21:33:49 ----A---- C:\windows\system32\wimserv.exe
2011-03-08 21:33:49 ----A---- C:\windows\system32\TSpkg.dll
2011-03-08 21:33:49 ----A---- C:\windows\system32\msscp.dll
2011-03-08 21:33:49 ----A---- C:\windows\system32\diskraid.exe
2011-03-08 21:33:49 ----A---- C:\windows\system32\DevicePairingFolder.dll
2011-03-08 21:33:48 ----A---- C:\windows\system32\WindowsAnytimeUpgradeResults.exe
2011-03-08 21:33:48 ----A---- C:\windows\system32\sdrsvc.dll
2011-03-08 21:33:48 ----A---- C:\windows\system32\remotepg.dll
2011-03-08 21:33:48 ----A---- C:\windows\system32\rdpencom.dll
2011-03-08 21:33:48 ----A---- C:\windows\system32\raschap.dll
2011-03-08 21:33:48 ----A---- C:\windows\system32\QUTIL.DLL
2011-03-08 21:33:48 ----A---- C:\windows\system32\perfmon.exe
2011-03-08 21:33:48 ----A---- C:\windows\system32\odbccp32.dll
2011-03-08 21:33:48 ----A---- C:\windows\system32\networkexplorer.dll
2011-03-08 21:33:48 ----A---- C:\windows\system32\NAPCRYPT.DLL
2011-03-08 21:33:48 ----A---- C:\windows\system32\input.dll
2011-03-08 21:33:48 ----A---- C:\windows\system32\drmmgrtn.dll
2011-03-08 21:33:48 ----A---- C:\windows\system32\browser.dll
2011-03-08 21:33:48 ----A---- C:\windows\system32\acppage.dll
2011-03-08 21:33:47 ----A---- C:\windows\system32\wpdwcn.dll
2011-03-08 21:33:47 ----A---- C:\windows\system32\wmpdxm.dll
2011-03-08 21:33:47 ----A---- C:\windows\system32\vpnikeapi.dll
2011-03-08 21:33:47 ----A---- C:\windows\system32\vdsbas.dll
2011-03-08 21:33:47 ----A---- C:\windows\system32\UserAccountControlSettings.dll
2011-03-08 21:33:47 ----A---- C:\windows\system32\onexui.dll
2011-03-08 21:33:47 ----A---- C:\windows\system32\olepro32.dll
2011-03-08 21:33:47 ----A---- C:\windows\system32\ocsetapi.dll
2011-03-08 21:33:47 ----A---- C:\windows\system32\nltest.exe
2011-03-08 21:33:47 ----A---- C:\windows\system32\iTVData.dll
2011-03-08 21:33:47 ----A---- C:\windows\bfsvc.exe
2011-03-08 21:33:46 ----A---- C:\windows\system32\sspisrv.dll
2011-03-08 21:33:46 ----A---- C:\windows\system32\runonce.exe
2011-03-08 21:33:46 ----A---- C:\windows\system32\RegisterIEPKEYs.exe
2011-03-08 21:33:46 ----A---- C:\windows\system32\Mcx2Svc.dll
2011-03-08 21:33:46 ----A---- C:\windows\system32\logagent.exe
2011-03-08 21:33:46 ----A---- C:\windows\system32\inseng.dll
2011-03-08 21:33:46 ----A---- C:\windows\system32\dxdiagn.dll
2011-03-08 21:33:45 ----A---- C:\windows\system32\PnPUnattend.exe
2011-03-08 21:33:45 ----A---- C:\windows\system32\msvidc32.dll
2011-03-08 21:33:45 ----A---- C:\windows\system32\msiexec.exe
2011-03-08 21:33:45 ----A---- C:\windows\system32\MFPlay.dll
2011-03-08 21:33:45 ----A---- C:\windows\system32\eapp3hst.dll
2011-03-08 21:33:45 ----A---- C:\windows\system32\drivers\rmcast.sys
2011-03-08 21:33:45 ----A---- C:\windows\system32\d3d10level9.dll
2011-03-08 21:33:44 ----A---- C:\windows\system32\wudriver.dll
2011-03-08 21:33:44 ----A---- C:\windows\system32\wmpshell.dll
2011-03-08 21:33:44 ----A---- C:\windows\system32\wmdrmdev.dll
2011-03-08 21:33:44 ----A---- C:\windows\system32\unimdmat.dll
2011-03-08 21:33:44 ----A---- C:\windows\system32\tabcal.exe
2011-03-08 21:33:44 ----A---- C:\windows\system32\sqlcese30.dll
2011-03-08 21:33:44 ----A---- C:\windows\system32\shacct.dll
2011-03-08 21:33:44 ----A---- C:\windows\system32\rdpd3d.dll
2011-03-08 21:33:44 ----A---- C:\windows\system32\lsmproxy.dll
2011-03-08 21:33:44 ----A---- C:\windows\system32\iscsium.dll
2011-03-08 21:33:44 ----A---- C:\windows\system32\bitsadmin.exe
2011-03-08 21:33:43 ----A---- C:\windows\system32\WUDFPlatform.dll
2011-03-08 21:33:43 ----A---- C:\windows\system32\WPDSp.dll
2011-03-08 21:33:43 ----A---- C:\windows\system32\srvcli.dll
2011-03-08 21:33:43 ----A---- C:\windows\system32\PortableDeviceSyncProvider.dll
2011-03-08 21:33:43 ----A---- C:\windows\system32\pdh.dll
2011-03-08 21:33:43 ----A---- C:\windows\system32\OpcServices.dll
2011-03-08 21:33:43 ----A---- C:\windows\system32\olethk32.dll
2011-03-08 21:33:43 ----A---- C:\windows\system32\ncryptui.dll
2011-03-08 21:33:43 ----A---- C:\windows\system32\mprapi.dll
2011-03-08 21:33:43 ----A---- C:\windows\system32\MdSched.exe
2011-03-08 21:33:43 ----A---- C:\windows\system32\logman.exe
2011-03-08 21:33:43 ----A---- C:\windows\system32\djoin.exe
2011-03-08 21:33:43 ----A---- C:\windows\system32\cscapi.dll
2011-03-08 21:33:42 ----A---- C:\windows\system32\wwanprotdim.dll
2011-03-08 21:33:42 ----A---- C:\windows\system32\WMPhoto.dll
2011-03-08 21:33:42 ----A---- C:\windows\system32\utildll.dll
2011-03-08 21:33:42 ----A---- C:\windows\system32\tsgqec.dll
2011-03-08 21:33:42 ----A---- C:\windows\system32\QSVRMGMT.DLL
2011-03-08 21:33:42 ----A---- C:\windows\system32\PortableDeviceStatus.dll
2011-03-08 21:33:42 ----A---- C:\windows\system32\odbctrac.dll
2011-03-08 21:33:42 ----A---- C:\windows\system32\mshtmled.dll
2011-03-08 21:33:42 ----A---- C:\windows\system32\mapistub.dll
2011-03-08 21:33:42 ----A---- C:\windows\system32\mapi32.dll
2011-03-08 21:33:42 ----A---- C:\windows\system32\lpremove.exe
2011-03-08 21:33:42 ----A---- C:\windows\system32\ActionQueue.dll
2011-03-08 21:33:41 ----A---- C:\windows\system32\WMVSDECD.DLL
2011-03-08 21:33:41 ----A---- C:\windows\system32\wmdrmnet.dll
2011-03-08 21:33:41 ----A---- C:\windows\system32\WMADMOD.DLL
2011-03-08 21:33:41 ----A---- C:\windows\system32\WindowsAnytimeUpgrade.exe
2011-03-08 21:33:41 ----A---- C:\windows\system32\wiavideo.dll
2011-03-08 21:33:41 ----A---- C:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2011-03-08 21:33:41 ----A---- C:\windows\system32\takeown.exe
2011-03-08 21:33:41 ----A---- C:\windows\system32\sqmapi.dll
2011-03-08 21:33:41 ----A---- C:\windows\system32\iyuv_32.dll
2011-03-08 21:33:41 ----A---- C:\windows\system32\imagehlp.dll
2011-03-08 21:33:41 ----A---- C:\windows\system32\fphc.dll
2011-03-08 21:33:41 ----A---- C:\windows\system32\dot3msm.dll
2011-03-08 21:33:41 ----A---- C:\windows\system32\avifil32.dll
2011-03-08 21:33:40 ----A---- C:\windows\system32\unattend.dll
2011-03-08 21:33:40 ----A---- C:\windows\system32\sppinst.dll
2011-03-08 21:33:40 ----A---- C:\windows\system32\qdv.dll
2011-03-08 21:33:40 ----A---- C:\windows\system32\QCLIPROV.DLL
2011-03-08 21:33:40 ----A---- C:\windows\system32\msyuv.dll
2011-03-08 21:33:40 ----A---- C:\windows\system32\msrle32.dll
2011-03-08 21:33:40 ----A---- C:\windows\system32\msnetobj.dll
2011-03-08 21:33:40 ----A---- C:\windows\system32\EhStorAPI.dll
2011-03-08 21:33:40 ----A---- C:\windows\system32\cca.dll
2011-03-08 21:33:39 ----A---- C:\windows\system32\WUDFx.dll
2011-03-08 21:33:39 ----A---- C:\windows\system32\WUDFHost.exe
2011-03-08 21:33:39 ----A---- C:\windows\system32\wsnmp32.dll
2011-03-08 21:33:39 ----A---- C:\windows\system32\WMSPDMOD.DLL
2011-03-08 21:33:39 ----A---- C:\windows\system32\vfwwdm32.dll
2011-03-08 21:33:39 ----A---- C:\windows\system32\setupcln.dll
2011-03-08 21:33:39 ----A---- C:\windows\system32\RelPost.exe
2011-03-08 21:33:39 ----A---- C:\windows\system32\pdhui.dll
2011-03-08 21:33:39 ----A---- C:\windows\system32\MuiUnattend.exe
2011-03-08 21:33:39 ----A---- C:\windows\system32\drivers\bthport.sys
2011-03-08 21:33:39 ----A---- C:\windows\system32\cmstp.exe
2011-03-08 21:33:39 ----A---- C:\windows\system32\basesrv.dll
2011-03-08 21:33:38 ----A---- C:\windows\system32\wuauclt.exe
2011-03-08 21:33:38 ----A---- C:\windows\system32\umb.dll
2011-03-08 21:33:38 ----A---- C:\windows\system32\tsbyuv.dll
2011-03-08 21:33:38 ----A---- C:\windows\system32\relog.exe
2011-03-08 21:33:38 ----A---- C:\windows\system32\PrintIsolationProxy.dll
2011-03-08 21:33:38 ----A---- C:\windows\system32\msorcl32.dll
2011-03-08 21:33:38 ----A---- C:\windows\system32\iasrecst.dll
2011-03-08 21:33:38 ----A---- C:\windows\system32\drivers\tcpipreg.sys
2011-03-08 21:33:38 ----A---- C:\windows\system32\drivers\ndisuio.sys
2011-03-08 21:33:38 ----A---- C:\windows\system32\AzSqlExt.dll
2011-03-08 21:33:37 ----A---- C:\windows\system32\wkscli.dll
2011-03-08 21:33:37 ----A---- C:\windows\system32\WavDest.dll
2011-03-08 21:33:37 ----A---- C:\windows\system32\sppuinotify.dll
2011-03-08 21:33:37 ----A---- C:\windows\system32\spbcd.dll
2011-03-08 21:33:37 ----A---- C:\windows\system32\rastapi.dll
2011-03-08 21:33:37 ----A---- C:\windows\system32\netiougc.exe
2011-03-08 21:33:37 ----A---- C:\windows\system32\mydocs.dll
2011-03-08 21:33:37 ----A---- C:\windows\system32\iscsicli.exe
2011-03-08 21:33:37 ----A---- C:\windows\system32\diskpart.exe
2011-03-08 21:33:37 ----A---- C:\windows\system32\amstream.dll
2011-03-08 21:33:36 ----A---- C:\windows\system32\wmpps.dll
2011-03-08 21:33:36 ----A---- C:\windows\system32\syssetup.dll
2011-03-08 21:33:36 ----A---- C:\windows\system32\setbcdlocale.dll
2011-03-08 21:33:36 ----A---- C:\windows\system32\secproc_ssp_isv.dll
2011-03-08 21:33:36 ----A---- C:\windows\system32\secproc_ssp.dll
2011-03-08 21:33:36 ----A---- C:\windows\system32\resutils.dll
2011-03-08 21:33:36 ----A---- C:\windows\system32\nrpsrv.dll
2011-03-08 21:33:36 ----A---- C:\windows\system32\netbtugc.exe
2011-03-08 21:33:36 ----A---- C:\windows\system32\MultiDigiMon.exe
2011-03-08 21:33:36 ----A---- C:\windows\system32\itircl.dll
2011-03-08 21:33:36 ----A---- C:\windows\system32\CertPolEng.dll
2011-03-08 21:33:35 ----A---- C:\windows\system32\wuapp.exe
2011-03-08 21:33:35 ----A---- C:\windows\system32\WerFaultSecure.exe
2011-03-08 21:33:35 ----A---- C:\windows\system32\tlscsp.dll
2011-03-08 21:33:35 ----A---- C:\windows\system32\secur32.dll
2011-03-08 21:33:35 ----A---- C:\windows\system32\RMActivate_ssp_isv.exe
2011-03-08 21:33:35 ----A---- C:\windows\system32\ReAgentc.exe
2011-03-08 21:33:35 ----A---- C:\windows\system32\FXSTIFF.dll
2011-03-08 21:33:35 ----A---- C:\windows\system32\findstr.exe
2011-03-08 21:33:35 ----A---- C:\windows\system32\eappgnui.dll
2011-03-08 21:33:35 ----A---- C:\windows\system32\drivers\usbccgp.sys
2011-03-08 21:33:34 ----A---- C:\windows\system32\wiarpc.dll
2011-03-08 21:33:34 ----A---- C:\windows\system32\RMActivate_ssp.exe
2011-03-08 21:33:34 ----A---- C:\windows\system32\netutils.dll
2011-03-08 21:33:34 ----A---- C:\windows\system32\netapi32.dll
2011-03-08 21:33:34 ----A---- C:\windows\system32\muifontsetup.dll
2011-03-08 21:33:34 ----A---- C:\windows\system32\mobsync.exe
2011-03-08 21:33:34 ----A---- C:\windows\system32\mciqtz32.dll
2011-03-08 21:33:34 ----A---- C:\windows\system32\dnscacheugc.exe
2011-03-08 21:33:34 ----A---- C:\windows\system32\cabinet.dll
2011-03-08 21:33:33 ----A---- C:\windows\system32\sppc.dll
2011-03-08 21:33:33 ----A---- C:\windows\system32\spopk.dll
2011-03-08 21:33:33 ----A---- C:\windows\system32\shimgvw.dll
2011-03-08 21:33:33 ----A---- C:\windows\system32\prevhost.exe
2011-03-08 21:33:33 ----A---- C:\windows\system32\luainstall.dll
2011-03-08 21:33:33 ----A---- C:\windows\system32\iccvid.dll
2011-03-08 21:33:33 ----A---- C:\windows\system32\HotStartUserAgent.dll
2011-03-08 21:33:33 ----A---- C:\windows\system32\drivers\usbrpm.sys
2011-03-08 21:33:33 ----A---- C:\windows\system32\drivers\tdi.sys
2011-03-08 21:33:33 ----A---- C:\windows\system32\dosx.exe
2011-03-08 21:33:32 ----A---- C:\windows\system32\wdiasqmmodule.dll
2011-03-08 21:33:32 ----A---- C:\windows\system32\unlodctr.exe
2011-03-08 21:33:32 ----A---- C:\windows\system32\repair-bde.exe
2011-03-08 21:33:32 ----A---- C:\windows\system32\rdprefdrvapi.dll
2011-03-08 21:33:32 ----A---- C:\windows\system32\netcfg.exe
2011-03-08 21:33:32 ----A---- C:\windows\system32\msdmo.dll
2011-03-08 21:33:32 ----A---- C:\windows\system32\manage-bde.exe
2011-03-08 21:33:32 ----A---- C:\windows\system32\inetmib1.dll
2011-03-08 21:33:32 ----A---- C:\windows\system32\drivers\CompositeBus.sys
2011-03-08 21:33:31 ----A---- C:\windows\system32\WUDFCoinstaller.dll
2011-03-08 21:33:31 ----A---- C:\windows\system32\odbcconf.dll
2011-03-08 21:33:31 ----A---- C:\windows\system32\drivers\cdrom.sys
2011-03-08 21:33:30 ----A---- C:\windows\system32\wups.dll
2011-03-08 21:33:30 ----A---- C:\windows\system32\UIRibbonRes.dll
2011-03-08 21:33:30 ----A---- C:\windows\system32\profprov.dll
2011-03-08 21:33:30 ----A---- C:\windows\system32\perfts.dll
2011-03-08 21:33:30 ----A---- C:\windows\system32\browcli.dll
2011-03-08 21:33:29 ----A---- C:\windows\system32\TRAPI.dll
2011-03-08 21:33:29 ----A---- C:\windows\system32\RDPENCDD.dll
2011-03-08 21:33:29 ----A---- C:\windows\system32\msfeedssync.exe
2011-03-08 21:33:29 ----A---- C:\windows\system32\icaapi.dll
2011-03-08 21:33:29 ----A---- C:\windows\system32\FXSMON.dll
2011-03-08 21:33:29 ----A---- C:\windows\system32\elsTrans.dll
2011-03-08 21:33:29 ----A---- C:\windows\system32\drivers\tunnel.sys
2011-03-08 21:33:29 ----A---- C:\windows\system32\drivers\dfsc.sys
2011-03-08 21:33:28 ----A---- C:\windows\system32\wshbth.dll
2011-03-08 21:33:28 ----A---- C:\windows\system32\schedcli.dll
2011-03-08 21:33:28 ----A---- C:\windows\system32\napdsnap.dll
2011-03-08 21:33:28 ----A---- C:\windows\system32\LogonUI.exe
2011-03-08 21:33:28 ----A---- C:\windows\system32\dsauth.dll
2011-03-08 21:33:28 ----A---- C:\windows\system32\cscdll.dll
2011-03-08 21:33:28 ----A---- C:\windows\system32\bitsperf.dll
2011-03-08 21:33:27 ----A---- C:\windows\system32\sscore.dll
2011-03-08 21:33:27 ----A---- C:\windows\system32\drivers\acpipmi.sys
2011-03-08 21:33:26 ----A---- C:\windows\system32\wups2.dll
2011-03-08 21:33:26 ----A---- C:\windows\system32\wsdchngr.dll
2011-03-08 21:33:26 ----A---- C:\windows\system32\shgina.dll
2011-03-08 21:33:26 ----A---- C:\windows\system32\riched32.dll
2011-03-08 21:33:26 ----A---- C:\windows\system32\drivers\ndiswan.sys
2011-03-08 21:33:25 ----A---- C:\windows\system32\rdpcfgex.dll
2011-03-08 21:33:25 ----A---- C:\windows\system32\drivers\WUDFRd.sys
2011-03-08 21:33:25 ----A---- C:\windows\system32\drivers\hidusb.sys
2011-03-08 21:33:25 ----A---- C:\windows\system32\drivers\appid.sys
2011-03-08 21:33:24 ----A---- C:\windows\system32\wshirda.dll
2011-03-08 21:33:24 ----A---- C:\windows\system32\drivers\IPMIDrv.sys
2011-03-08 21:33:23 ----A---- C:\windows\system32\drivers\USBCAMD2.sys
2011-03-08 21:33:23 ----A---- C:\windows\system32\drivers\USBCAMD.sys
2011-03-08 21:33:23 ----A---- C:\windows\system32\drivers\kbdhid.sys
2011-03-08 21:33:22 ----A---- C:\windows\system32\spwmp.dll
2011-03-08 21:33:22 ----A---- C:\windows\system32\drivers\tdtcp.sys
2011-03-08 21:33:22 ----A---- C:\windows\system32\browseui.dll
2011-03-08 21:33:21 ----A---- C:\windows\system32\RDPREFDD.dll
2011-03-08 21:33:21 ----A---- C:\windows\system32\dxmasf.dll
2011-03-08 21:33:21 ----A---- C:\windows\system32\drivers\WUDFPf.sys
2011-03-08 21:33:21 ----A---- C:\windows\system32\drivers\wanarp.sys
2011-03-08 21:33:21 ----A---- C:\windows\system32\drivers\umbus.sys
2011-03-08 21:33:21 ----A---- C:\windows\system32\drivers\tdpipe.sys
2011-03-08 21:33:21 ----A---- C:\windows\system32\drivers\sffp_sd.sys
2011-03-08 21:33:21 ----A---- C:\windows\system32\drivers\scfilter.sys
2011-03-08 21:33:21 ----A---- C:\windows\system32\drivers\RDPCDD.sys
2011-03-08 21:33:21 ----A---- C:\windows\system32\drivers\HdAudio.sys
2011-03-08 21:33:21 ----A---- C:\windows\system32\drivers\hdaudbus.sys
2011-03-08 21:33:21 ----A---- C:\windows\system32\C_ISCII.DLL
2011-03-08 21:33:20 ----A---- C:\windows\system32\shunimpl.dll
2011-03-08 21:33:19 ----A---- C:\windows\system32\wmploc.DLL
2011-03-08 21:33:19 ----A---- C:\windows\system32\KBDUS.DLL
2011-03-08 21:33:19 ----A---- C:\windows\system32\KBDUGHR1.DLL
2011-03-08 21:33:19 ----A---- C:\windows\system32\KBDTURME.DLL
2011-03-08 21:33:19 ----A---- C:\windows\system32\KBDTAJIK.DLL
2011-03-08 21:33:19 ----A---- C:\windows\system32\KBDINTEL.DLL
2011-03-08 21:33:19 ----A---- C:\windows\system32\KBDINKAN.DLL
2011-03-08 21:33:18 ----A---- C:\windows\system32\KBDSF.DLL
2011-03-08 21:33:18 ----A---- C:\windows\system32\KBDNEPR.DLL
2011-03-08 21:33:18 ----A---- C:\windows\system32\KBDMON.DLL
2011-03-08 21:33:18 ----A---- C:\windows\system32\KBDMAORI.DLL
2011-03-08 21:33:18 ----A---- C:\windows\system32\KBDLT1.DLL
2011-03-08 21:33:18 ----A---- C:\windows\system32\kbdlk41a.dll
2011-03-08 21:33:18 ----A---- C:\windows\system32\KBDINTAM.DLL
2011-03-08 21:33:18 ----A---- C:\windows\system32\KBDINORI.DLL
2011-03-08 21:33:18 ----A---- C:\windows\system32\KBDINMAR.DLL
2011-03-08 21:33:18 ----A---- C:\windows\system32\KBDINHIN.DLL
2011-03-08 21:33:18 ----A---- C:\windows\system32\KBDGEO.DLL
2011-03-08 21:33:18 ----A---- C:\windows\system32\KBDBULG.DLL
2011-03-08 21:33:18 ----A---- C:\windows\system32\KBDBLR.DLL
2011-03-08 21:33:18 ----A---- C:\windows\system32\KBDBASH.DLL
2011-03-08 21:33:17 ----A---- C:\windows\system32\tzres.dll
2011-03-08 21:33:17 ----A---- C:\windows\system32\spwizres.dll
2011-03-08 21:33:17 ----A---- C:\windows\system32\pifmgr.dll
2011-03-08 21:33:17 ----A---- C:\windows\system32\nlsbres.dll
2011-03-08 21:33:17 ----A---- C:\windows\system32\KBDTUQ.DLL
2011-03-08 21:33:17 ----A---- C:\windows\system32\KBDTUF.DLL
2011-03-08 21:33:17 ----A---- C:\windows\system32\KBDSG.DLL
2011-03-08 21:33:17 ----A---- C:\windows\system32\KBDPO.DLL
2011-03-08 21:33:17 ----A---- C:\windows\system32\KBDINBEN.DLL
2011-03-08 21:33:17 ----A---- C:\windows\system32\KBDGR1.DLL
2011-03-08 21:33:17 ----A---- C:\windows\system32\KBDGKL.DLL
2011-03-08 21:33:17 ----A---- C:\windows\system32\KBDCZ1.DLL
2011-03-08 21:33:17 ----A---- C:\windows\system32\dpnaddr.dll
2011-03-08 21:33:17 ----A---- C:\windows\system32\BlbEvents.dll
2011-03-08 21:32:58 ----A---- C:\windows\system32\wmicmiplugin.dll
2011-03-08 21:32:58 ----A---- C:\windows\system32\wbemcomn.dll
2011-03-08 21:32:52 ----A---- C:\windows\system32\SmiEngine.dll
2011-03-08 21:32:48 ----A---- C:\windows\system32\wdscore.dll
2011-03-08 21:32:48 ----A---- C:\windows\system32\PkgMgr.exe
2011-03-08 21:32:30 ----A---- C:\windows\system32\drvstore.dll
2011-03-08 21:32:30 ----A---- C:\windows\system32\dpx.dll
2011-03-08 21:17:20 ----A---- C:\windows\system32\sbe.dll
2011-03-08 21:17:20 ----A---- C:\windows\system32\EncDec.dll
2011-03-08 21:17:20 ----A---- C:\windows\system32\CPFilters.dll
2011-03-08 21:17:19 ----A---- C:\windows\system32\DWrite.dll
2011-03-08 21:17:18 ----A---- C:\windows\system32\FntCache.dll
2011-03-08 21:17:18 ----A---- C:\windows\system32\d2d1.dll
2011-03-08 21:17:16 ----A---- C:\windows\system32\d3d10_1.dll
-
- Vzorný návštěvník
- Příspěvky: 208
- Registrován: 07 čer 2010 17:54
- Bydliště: SK
- Kontaktovat uživatele:
Re: Preventívka..... -pre motji
======List of files/folders modified in the last 1 months======
2011-04-07 13:31:22 ----D---- C:\Program Files\trend micro
2011-04-07 13:31:08 ----D---- C:\windows\Internet Logs
2011-04-07 13:30:28 ----D---- C:\ProgramData\HPQLOG
2011-04-07 13:30:19 ----A---- C:\windows\system32\log.txt
2011-04-07 13:28:32 ----D---- C:\windows\System32
2011-04-07 13:28:32 ----D---- C:\windows\inf
2011-04-07 13:28:32 ----A---- C:\windows\system32\PerfStringBackup.INI
2011-04-07 13:25:01 ----D---- C:\windows\Prefetch
2011-04-07 13:23:21 ----D---- C:\Windows
2011-04-07 13:15:52 ----D---- C:\windows\system32\config
2011-04-06 21:00:35 ----D---- C:\Users\Admin\AppData\Roaming\Skype
2011-04-06 20:30:10 ----D---- C:\windows\system32\drivers
2011-04-06 20:25:05 ----SHD---- C:\windows\Installer
2011-04-06 20:24:52 ----RD---- C:\Program Files
2011-04-06 20:24:46 ----SHD---- C:\System Volume Information
2011-04-06 20:06:24 ----D---- C:\Users\Admin\AppData\Roaming\ICQ
2011-04-06 19:31:52 ----D---- C:\Users\Admin\AppData\Roaming\skypePM
2011-04-06 15:54:42 ----D---- C:\windows\Minidump
2011-04-05 20:29:50 ----D---- C:\windows\system32\catroot2
2011-04-05 19:53:36 ----D---- C:\ProgramData
2011-04-03 21:50:01 ----D---- C:\Users\Admin\AppData\Roaming\uTorrent
2011-04-02 21:14:10 ----AD---- C:\ProgramData\TEMP
2011-03-30 16:06:17 ----D---- C:\Program Files\Windows Live
2011-03-28 14:43:22 ----D---- C:\windows\rescache
2011-03-25 20:40:41 ----RSD---- C:\windows\Fonts
2011-03-24 21:58:09 ----D---- C:\windows\system32\catroot
2011-03-24 21:57:22 ----D---- C:\windows\system32\DriverStore
2011-03-22 21:33:54 ----A---- C:\windows\system.ini
2011-03-22 21:27:38 ----D---- C:\windows\AppPatch
2011-03-22 21:27:36 ----D---- C:\Program Files\Common Files
2011-03-22 21:27:16 ----D---- C:\windows\system32\wbem
2011-03-14 10:42:12 ----D---- C:\windows\Tasks
2011-03-14 10:42:12 ----D---- C:\windows\system32\Tasks
2011-03-14 10:38:37 ----D---- C:\Temp
2011-03-14 09:09:59 ----RD---- C:\Users
2011-03-10 14:09:37 ----D---- C:\windows\debug
2011-03-08 22:06:59 ----D---- C:\windows\Microsoft.NET
2011-03-08 22:06:50 ----RSD---- C:\windows\assembly
2011-03-08 21:56:18 ----D---- C:\windows\winsxs
2011-03-08 21:48:58 ----D---- C:\Program Files\Windows Sidebar
2011-03-08 21:48:58 ----D---- C:\Program Files\Windows Portable Devices
2011-03-08 21:48:58 ----D---- C:\Program Files\Windows Photo Viewer
2011-03-08 21:48:58 ----D---- C:\Program Files\Windows Media Player
2011-03-08 21:48:58 ----D---- C:\Program Files\Windows Mail
2011-03-08 21:48:58 ----D---- C:\Program Files\Windows Journal
2011-03-08 21:48:58 ----D---- C:\Program Files\Internet Explorer
2011-03-08 21:48:58 ----D---- C:\Program Files\DVD Maker
2011-03-08 21:48:56 ----D---- C:\windows\servicing
2011-03-08 21:48:56 ----D---- C:\windows\ehome
2011-03-08 21:48:56 ----D---- C:\Program Files\Windows Defender
2011-03-08 21:48:53 ----D---- C:\windows\system32\sk-SK
2011-03-08 21:48:53 ----D---- C:\windows\system32\da-DK
2011-03-08 21:48:53 ----D---- C:\windows\PolicyDefinitions
2011-03-08 21:48:52 ----D---- C:\windows\system32\en-US
2011-03-08 21:48:50 ----D---- C:\windows\system32\oobe
2011-03-08 21:48:49 ----D---- C:\windows\system32\sysprep
2011-03-08 21:48:49 ----D---- C:\windows\system32\sppui
2011-03-08 21:48:49 ----D---- C:\windows\system32\Setup
2011-03-08 21:48:49 ----D---- C:\windows\system32\migration
2011-03-08 21:48:49 ----D---- C:\windows\system32\manifeststore
2011-03-08 21:48:49 ----D---- C:\windows\system32\es-ES
2011-03-08 21:48:49 ----D---- C:\windows\system32\en
2011-03-08 21:48:49 ----D---- C:\windows\system32\cs-CZ
2011-03-08 21:48:49 ----D---- C:\windows\system32\AdvancedInstallers
2011-03-08 21:48:48 ----D---- C:\windows\system32\drivers\en-US
2011-03-08 21:48:47 ----D---- C:\windows\system32\migwiz
2011-03-08 21:48:47 ----D---- C:\windows\system32\Dism
2011-03-08 21:48:24 ----D---- C:\windows\system32\Boot
2011-03-08 21:44:45 ----A---- C:\windows\system32\MRT.exe
2011-03-08 21:42:51 ----A---- C:\windows\system32\msclmd.dll
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 hpdskflt;HP Filter; C:\windows\system32\DRIVERS\hpdskflt.sys [2009-07-08 25656]
R0 iaStor;Intel RAID Controller; C:\windows\system32\DRIVERS\iaStor.sys [2009-08-07 330264]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 SafeBoot;SafeBoot; C:\windows\system32\drivers\SafeBoot.sys [2009-12-16 110520]
R0 SbAlg;SbAlg; C:\windows\system32\drivers\SbAlg.sys [2009-12-16 51800]
R0 SbFsLock;SbFsLock; C:\windows\system32\drivers\SbFsLock.sys [2009-12-16 13256]
R1 aswRdr;aswRdr; C:\windows\system32\drivers\aswRdr.sys [2011-02-23 25432]
R1 aswSnx;aswSnx; C:\windows\system32\drivers\aswSnx.sys [2011-02-23 371544]
R1 aswSP;aswSP; C:\windows\system32\drivers\aswSP.sys [2011-02-23 301528]
R1 aswTdi;avast! Network Shield Support; C:\windows\system32\drivers\aswTdi.sys [2011-02-23 49240]
R1 mfehidk;McAfee Inc. mfehidk; C:\windows\system32\drivers\mfehidk.sys [2009-05-16 214024]
R1 mfetdik;McAfee Inc. mfetdik; C:\windows\system32\drivers\mfetdik.sys [2009-05-16 55336]
R1 RsvLock;RsvLock; C:\windows\system32\drivers\RsvLock.sys [2009-12-16 40088]
R1 vmm;Virtual Machine Monitor; \??\C:\windows\system32\Drivers\vmm.sys [2010-11-26 229208]
R1 Vsdatant;Zone Alarm Firewall Driver; C:\windows\system32\DRIVERS\vsdatant.sys [2010-05-15 461400]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 aswFsBlk;aswFsBlk; C:\windows\system32\drivers\aswFsBlk.sys [2011-02-23 19544]
R2 aswMonFlt;aswMonFlt; \??\C:\windows\system32\drivers\aswMonFlt.sys [2011-02-23 53592]
R3 Accelerometer;HP Accelerometer; C:\windows\system32\DRIVERS\Accelerometer.sys [2009-07-08 33848]
R3 Afc;PPdus ASPI Shell; C:\windows\system32\drivers\Afc.sys [2006-11-11 18688]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2010-06-18 5586944]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2010-06-18 210432]
R3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver; C:\windows\system32\DRIVERS\ArcSoftVCapture.sys [2009-12-04 29824]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\windows\system32\DRIVERS\athr.sys [2009-10-05 1221632]
R3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\windows\system32\drivers\AtiHdmi.sys [2010-05-06 108560]
R3 BthEnum;Bluetooth Request Block Driver; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\windows\System32\Drivers\BTHUSB.sys [2010-11-20 60416]
R3 btwaudio;Bluetooth Audio Device Service; C:\windows\system32\drivers\btwaudio.sys [2009-09-17 86056]
R3 btwavdt;Bluetooth AVDT; C:\windows\system32\DRIVERS\btwavdt.sys [2009-09-17 108072]
R3 btwl2cap;Bluetooth L2CAP Service; C:\windows\system32\DRIVERS\btwl2cap.sys [2009-09-17 29472]
R3 btwrchid;btwrchid; C:\windows\system32\DRIVERS\btwrchid.sys [2009-09-17 18472]
R3 CLEDX;Team H2O CLEDX service; C:\windows\system32\DRIVERS\cledx.sys [2005-05-09 33792]
R3 HECI;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECI.sys [2009-09-17 41088]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\DRIVERS\HpqKbFiltr.sys [2009-07-16 15872]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\windows\system32\DRIVERS\snp2uvc.sys [2009-12-19 1763968]
R3 STHDA;IDT High Definition Audio CODEC; C:\windows\system32\DRIVERS\stwrt.sys [2009-12-03 423424]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2010-09-28 1303728]
R3 VPCNetS2;Virtual Machine Network Services Driver; C:\windows\system32\DRIVERS\VMNetSrv.sys [2007-01-29 59280]
S2 Parvdm;Parvdm; C:\windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 AgereSoftModem;Agere Systems Soft Modem; C:\windows\system32\DRIVERS\AGRSM.sys [2009-07-14 1035776]
S3 aic78xx;aic78xx; C:\windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 atikmdag;atikmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2010-06-18 5586944]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BTHPORT;Bluetooth Port Driver; C:\windows\System32\Drivers\BTHport.sys [2010-11-20 393216]
S3 Bulk;HDJBulk; C:\windows\System32\Drivers\HDJBulk.sys [2009-07-08 126464]
S3 catchme;catchme; \??\C:\Users\Admin\AppData\Local\Temp\catchme.sys []
S3 DAMDrv;DAMDrv; C:\windows\system32\DRIVERS\DAMDrv.sys [2009-10-21 32312]
S3 hamachi;Hamachi Network Interface; C:\windows\system32\DRIVERS\hamachi.sys [2010-02-03 26176]
S3 HDJMidi;DJ Control MP3 e2 MIDI; C:\windows\system32\DRIVERS\HDJMidi.sys [2009-07-08 124416]
S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd32.sys [2009-06-10 4756480]
S3 ksaud;Creative USB Audio Driver; C:\windows\system32\drivers\ksaud.sys [2009-08-05 886912]
S3 MfeAVFK;McAfee Inc. MfeAVFK; C:\windows\system32\drivers\MfeAVFK.sys [2009-05-16 79816]
S3 MfeBOPK;McAfee Inc. MfeBOPK; C:\windows\system32\drivers\MfeBOPK.sys [2009-05-16 35272]
S3 MfeRKDK;McAfee Inc. MfeRKDK; C:\windows\system32\drivers\MfeRKDK.sys [2009-05-16 34248]
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\windows\System32\Drivers\RtsUStor.sys [2009-11-11 181792]
S3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt86win7.sys [2010-03-04 277536]
S3 sisagp;SIS AGP Bus Filter; C:\windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 TPM;TPM; C:\windows\system32\drivers\tpm.sys [2009-07-14 30720]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 viaagp;VIA AGP Bus Filter; C:\windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WinUsb;WinUsb Driver; C:\windows\system32\drivers\WinUSB.SYS [2010-11-20 35968]
S4 Ipprgp;Ipprgp; C:\windows\system32\drivers\btwl2cap.sys [2009-09-17 29472]
S4 sptd;sptd; C:\windows\System32\Drivers\sptd.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AESTFilters;Andrea ST Filters Service; C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9fc8b38ddee9fbba\aestsrv.exe [2009-03-03 81920]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2010-06-18 176128]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-02-23 42184]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-09-04 595232]
R2 DpHost;@c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [2009-11-25 300808]
R2 HerculesDJControlMP3;Hercules DJ Control MP3; D:\Program Files\Hercules\Audio\DJ Console Series\HerculesDJControlMP3.EXE [2007-11-21 17408]
R2 HP ProtectTools Service;HP ProtectTools Service; c:\Program Files\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [2009-11-19 36864]
R2 HPDayStarterService;HP DayStarter Service; c:\Program Files\Hewlett-Packard\HP QuickLook\HPDayStarterService.exe [2010-01-08 81920]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2010-10-14 92216]
R2 HpFkCryptService;Drive Encryption Service; c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [2009-12-16 281192]
R2 HPFSService;File Sanitizer for HP ProtectTools; C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe [2009-12-12 297984]
R2 hpHotkeyMonitor;HP Hotkey Monitor; C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [2010-01-05 264248]
R2 hpsrv;HP Service; C:\windows\system32\Hpservice.exe [2009-07-08 26168]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2009-08-25 354840]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2009-06-17 73728]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2009-11-04 268824]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files\PDF Complete\pdfsvc.exe [2009-10-23 635416]
R2 PSI_SVC_2;Protexis Licensing V2; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2007-07-24 185632]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\windows\system32\svchost.exe [2009-07-14 20992]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2010-09-22 249136]
R2 STacSV;Audio Service; C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9fc8b38ddee9fbba\STacSV.exe [2009-12-03 229461]
R2 TeamViewer5;TeamViewer 5; D:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe [2010-07-06 173352]
R2 uArcCapture;ArcCapture; C:\windows\system32\uArcCapture.exe [2009-12-04 506472]
R2 vsmon;TrueVector Internet Monitor; C:\Windows\System32\ZoneLabs\vsmon.exe [2010-11-16 2435592]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\windows\system32\svchost.exe [2009-07-14 20992]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 1710464]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2010-10-14 751672]
S2 HP Health Check Service;HP Health Check Service; C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2010-11-15 126520]
S2 HP Power Assistant Service;HP Power Assistant Service; C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2010-08-23 103992]
S2 HP Wireless Assistant Service;HP Wireless Assistant Service; C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2009-12-17 102968]
S2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-11-04 2320920]
S2 vcsFPService;Validity VCS Fingerprint Service; C:\windows\system32\vcsFPService.exe [2009-12-14 1639728]
S3 ACDaemon;ArcSoft Connect Daemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2009-09-28 109056]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2010-09-28 68096]
S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing; c:\Windows\system32\flcdlock.exe [2009-11-18 362040]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2011-02-24 655624]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2010-07-29 1343400]
-----------------EOF-----------------
2011-04-07 13:31:22 ----D---- C:\Program Files\trend micro
2011-04-07 13:31:08 ----D---- C:\windows\Internet Logs
2011-04-07 13:30:28 ----D---- C:\ProgramData\HPQLOG
2011-04-07 13:30:19 ----A---- C:\windows\system32\log.txt
2011-04-07 13:28:32 ----D---- C:\windows\System32
2011-04-07 13:28:32 ----D---- C:\windows\inf
2011-04-07 13:28:32 ----A---- C:\windows\system32\PerfStringBackup.INI
2011-04-07 13:25:01 ----D---- C:\windows\Prefetch
2011-04-07 13:23:21 ----D---- C:\Windows
2011-04-07 13:15:52 ----D---- C:\windows\system32\config
2011-04-06 21:00:35 ----D---- C:\Users\Admin\AppData\Roaming\Skype
2011-04-06 20:30:10 ----D---- C:\windows\system32\drivers
2011-04-06 20:25:05 ----SHD---- C:\windows\Installer
2011-04-06 20:24:52 ----RD---- C:\Program Files
2011-04-06 20:24:46 ----SHD---- C:\System Volume Information
2011-04-06 20:06:24 ----D---- C:\Users\Admin\AppData\Roaming\ICQ
2011-04-06 19:31:52 ----D---- C:\Users\Admin\AppData\Roaming\skypePM
2011-04-06 15:54:42 ----D---- C:\windows\Minidump
2011-04-05 20:29:50 ----D---- C:\windows\system32\catroot2
2011-04-05 19:53:36 ----D---- C:\ProgramData
2011-04-03 21:50:01 ----D---- C:\Users\Admin\AppData\Roaming\uTorrent
2011-04-02 21:14:10 ----AD---- C:\ProgramData\TEMP
2011-03-30 16:06:17 ----D---- C:\Program Files\Windows Live
2011-03-28 14:43:22 ----D---- C:\windows\rescache
2011-03-25 20:40:41 ----RSD---- C:\windows\Fonts
2011-03-24 21:58:09 ----D---- C:\windows\system32\catroot
2011-03-24 21:57:22 ----D---- C:\windows\system32\DriverStore
2011-03-22 21:33:54 ----A---- C:\windows\system.ini
2011-03-22 21:27:38 ----D---- C:\windows\AppPatch
2011-03-22 21:27:36 ----D---- C:\Program Files\Common Files
2011-03-22 21:27:16 ----D---- C:\windows\system32\wbem
2011-03-14 10:42:12 ----D---- C:\windows\Tasks
2011-03-14 10:42:12 ----D---- C:\windows\system32\Tasks
2011-03-14 10:38:37 ----D---- C:\Temp
2011-03-14 09:09:59 ----RD---- C:\Users
2011-03-10 14:09:37 ----D---- C:\windows\debug
2011-03-08 22:06:59 ----D---- C:\windows\Microsoft.NET
2011-03-08 22:06:50 ----RSD---- C:\windows\assembly
2011-03-08 21:56:18 ----D---- C:\windows\winsxs
2011-03-08 21:48:58 ----D---- C:\Program Files\Windows Sidebar
2011-03-08 21:48:58 ----D---- C:\Program Files\Windows Portable Devices
2011-03-08 21:48:58 ----D---- C:\Program Files\Windows Photo Viewer
2011-03-08 21:48:58 ----D---- C:\Program Files\Windows Media Player
2011-03-08 21:48:58 ----D---- C:\Program Files\Windows Mail
2011-03-08 21:48:58 ----D---- C:\Program Files\Windows Journal
2011-03-08 21:48:58 ----D---- C:\Program Files\Internet Explorer
2011-03-08 21:48:58 ----D---- C:\Program Files\DVD Maker
2011-03-08 21:48:56 ----D---- C:\windows\servicing
2011-03-08 21:48:56 ----D---- C:\windows\ehome
2011-03-08 21:48:56 ----D---- C:\Program Files\Windows Defender
2011-03-08 21:48:53 ----D---- C:\windows\system32\sk-SK
2011-03-08 21:48:53 ----D---- C:\windows\system32\da-DK
2011-03-08 21:48:53 ----D---- C:\windows\PolicyDefinitions
2011-03-08 21:48:52 ----D---- C:\windows\system32\en-US
2011-03-08 21:48:50 ----D---- C:\windows\system32\oobe
2011-03-08 21:48:49 ----D---- C:\windows\system32\sysprep
2011-03-08 21:48:49 ----D---- C:\windows\system32\sppui
2011-03-08 21:48:49 ----D---- C:\windows\system32\Setup
2011-03-08 21:48:49 ----D---- C:\windows\system32\migration
2011-03-08 21:48:49 ----D---- C:\windows\system32\manifeststore
2011-03-08 21:48:49 ----D---- C:\windows\system32\es-ES
2011-03-08 21:48:49 ----D---- C:\windows\system32\en
2011-03-08 21:48:49 ----D---- C:\windows\system32\cs-CZ
2011-03-08 21:48:49 ----D---- C:\windows\system32\AdvancedInstallers
2011-03-08 21:48:48 ----D---- C:\windows\system32\drivers\en-US
2011-03-08 21:48:47 ----D---- C:\windows\system32\migwiz
2011-03-08 21:48:47 ----D---- C:\windows\system32\Dism
2011-03-08 21:48:24 ----D---- C:\windows\system32\Boot
2011-03-08 21:44:45 ----A---- C:\windows\system32\MRT.exe
2011-03-08 21:42:51 ----A---- C:\windows\system32\msclmd.dll
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 hpdskflt;HP Filter; C:\windows\system32\DRIVERS\hpdskflt.sys [2009-07-08 25656]
R0 iaStor;Intel RAID Controller; C:\windows\system32\DRIVERS\iaStor.sys [2009-08-07 330264]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 SafeBoot;SafeBoot; C:\windows\system32\drivers\SafeBoot.sys [2009-12-16 110520]
R0 SbAlg;SbAlg; C:\windows\system32\drivers\SbAlg.sys [2009-12-16 51800]
R0 SbFsLock;SbFsLock; C:\windows\system32\drivers\SbFsLock.sys [2009-12-16 13256]
R1 aswRdr;aswRdr; C:\windows\system32\drivers\aswRdr.sys [2011-02-23 25432]
R1 aswSnx;aswSnx; C:\windows\system32\drivers\aswSnx.sys [2011-02-23 371544]
R1 aswSP;aswSP; C:\windows\system32\drivers\aswSP.sys [2011-02-23 301528]
R1 aswTdi;avast! Network Shield Support; C:\windows\system32\drivers\aswTdi.sys [2011-02-23 49240]
R1 mfehidk;McAfee Inc. mfehidk; C:\windows\system32\drivers\mfehidk.sys [2009-05-16 214024]
R1 mfetdik;McAfee Inc. mfetdik; C:\windows\system32\drivers\mfetdik.sys [2009-05-16 55336]
R1 RsvLock;RsvLock; C:\windows\system32\drivers\RsvLock.sys [2009-12-16 40088]
R1 vmm;Virtual Machine Monitor; \??\C:\windows\system32\Drivers\vmm.sys [2010-11-26 229208]
R1 Vsdatant;Zone Alarm Firewall Driver; C:\windows\system32\DRIVERS\vsdatant.sys [2010-05-15 461400]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 aswFsBlk;aswFsBlk; C:\windows\system32\drivers\aswFsBlk.sys [2011-02-23 19544]
R2 aswMonFlt;aswMonFlt; \??\C:\windows\system32\drivers\aswMonFlt.sys [2011-02-23 53592]
R3 Accelerometer;HP Accelerometer; C:\windows\system32\DRIVERS\Accelerometer.sys [2009-07-08 33848]
R3 Afc;PPdus ASPI Shell; C:\windows\system32\drivers\Afc.sys [2006-11-11 18688]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2010-06-18 5586944]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2010-06-18 210432]
R3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver; C:\windows\system32\DRIVERS\ArcSoftVCapture.sys [2009-12-04 29824]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\windows\system32\DRIVERS\athr.sys [2009-10-05 1221632]
R3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\windows\system32\drivers\AtiHdmi.sys [2010-05-06 108560]
R3 BthEnum;Bluetooth Request Block Driver; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\windows\System32\Drivers\BTHUSB.sys [2010-11-20 60416]
R3 btwaudio;Bluetooth Audio Device Service; C:\windows\system32\drivers\btwaudio.sys [2009-09-17 86056]
R3 btwavdt;Bluetooth AVDT; C:\windows\system32\DRIVERS\btwavdt.sys [2009-09-17 108072]
R3 btwl2cap;Bluetooth L2CAP Service; C:\windows\system32\DRIVERS\btwl2cap.sys [2009-09-17 29472]
R3 btwrchid;btwrchid; C:\windows\system32\DRIVERS\btwrchid.sys [2009-09-17 18472]
R3 CLEDX;Team H2O CLEDX service; C:\windows\system32\DRIVERS\cledx.sys [2005-05-09 33792]
R3 HECI;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECI.sys [2009-09-17 41088]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\DRIVERS\HpqKbFiltr.sys [2009-07-16 15872]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\windows\system32\DRIVERS\snp2uvc.sys [2009-12-19 1763968]
R3 STHDA;IDT High Definition Audio CODEC; C:\windows\system32\DRIVERS\stwrt.sys [2009-12-03 423424]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2010-09-28 1303728]
R3 VPCNetS2;Virtual Machine Network Services Driver; C:\windows\system32\DRIVERS\VMNetSrv.sys [2007-01-29 59280]
S2 Parvdm;Parvdm; C:\windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 AgereSoftModem;Agere Systems Soft Modem; C:\windows\system32\DRIVERS\AGRSM.sys [2009-07-14 1035776]
S3 aic78xx;aic78xx; C:\windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 atikmdag;atikmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2010-06-18 5586944]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BTHPORT;Bluetooth Port Driver; C:\windows\System32\Drivers\BTHport.sys [2010-11-20 393216]
S3 Bulk;HDJBulk; C:\windows\System32\Drivers\HDJBulk.sys [2009-07-08 126464]
S3 catchme;catchme; \??\C:\Users\Admin\AppData\Local\Temp\catchme.sys []
S3 DAMDrv;DAMDrv; C:\windows\system32\DRIVERS\DAMDrv.sys [2009-10-21 32312]
S3 hamachi;Hamachi Network Interface; C:\windows\system32\DRIVERS\hamachi.sys [2010-02-03 26176]
S3 HDJMidi;DJ Control MP3 e2 MIDI; C:\windows\system32\DRIVERS\HDJMidi.sys [2009-07-08 124416]
S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd32.sys [2009-06-10 4756480]
S3 ksaud;Creative USB Audio Driver; C:\windows\system32\drivers\ksaud.sys [2009-08-05 886912]
S3 MfeAVFK;McAfee Inc. MfeAVFK; C:\windows\system32\drivers\MfeAVFK.sys [2009-05-16 79816]
S3 MfeBOPK;McAfee Inc. MfeBOPK; C:\windows\system32\drivers\MfeBOPK.sys [2009-05-16 35272]
S3 MfeRKDK;McAfee Inc. MfeRKDK; C:\windows\system32\drivers\MfeRKDK.sys [2009-05-16 34248]
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\windows\System32\Drivers\RtsUStor.sys [2009-11-11 181792]
S3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt86win7.sys [2010-03-04 277536]
S3 sisagp;SIS AGP Bus Filter; C:\windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 TPM;TPM; C:\windows\system32\drivers\tpm.sys [2009-07-14 30720]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 viaagp;VIA AGP Bus Filter; C:\windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WinUsb;WinUsb Driver; C:\windows\system32\drivers\WinUSB.SYS [2010-11-20 35968]
S4 Ipprgp;Ipprgp; C:\windows\system32\drivers\btwl2cap.sys [2009-09-17 29472]
S4 sptd;sptd; C:\windows\System32\Drivers\sptd.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AESTFilters;Andrea ST Filters Service; C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9fc8b38ddee9fbba\aestsrv.exe [2009-03-03 81920]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2010-06-18 176128]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-02-23 42184]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-09-04 595232]
R2 DpHost;@c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [2009-11-25 300808]
R2 HerculesDJControlMP3;Hercules DJ Control MP3; D:\Program Files\Hercules\Audio\DJ Console Series\HerculesDJControlMP3.EXE [2007-11-21 17408]
R2 HP ProtectTools Service;HP ProtectTools Service; c:\Program Files\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [2009-11-19 36864]
R2 HPDayStarterService;HP DayStarter Service; c:\Program Files\Hewlett-Packard\HP QuickLook\HPDayStarterService.exe [2010-01-08 81920]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2010-10-14 92216]
R2 HpFkCryptService;Drive Encryption Service; c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [2009-12-16 281192]
R2 HPFSService;File Sanitizer for HP ProtectTools; C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe [2009-12-12 297984]
R2 hpHotkeyMonitor;HP Hotkey Monitor; C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [2010-01-05 264248]
R2 hpsrv;HP Service; C:\windows\system32\Hpservice.exe [2009-07-08 26168]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2009-08-25 354840]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2009-06-17 73728]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2009-11-04 268824]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files\PDF Complete\pdfsvc.exe [2009-10-23 635416]
R2 PSI_SVC_2;Protexis Licensing V2; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2007-07-24 185632]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\windows\system32\svchost.exe [2009-07-14 20992]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2010-09-22 249136]
R2 STacSV;Audio Service; C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9fc8b38ddee9fbba\STacSV.exe [2009-12-03 229461]
R2 TeamViewer5;TeamViewer 5; D:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe [2010-07-06 173352]
R2 uArcCapture;ArcCapture; C:\windows\system32\uArcCapture.exe [2009-12-04 506472]
R2 vsmon;TrueVector Internet Monitor; C:\Windows\System32\ZoneLabs\vsmon.exe [2010-11-16 2435592]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\windows\system32\svchost.exe [2009-07-14 20992]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 1710464]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2010-10-14 751672]
S2 HP Health Check Service;HP Health Check Service; C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2010-11-15 126520]
S2 HP Power Assistant Service;HP Power Assistant Service; C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2010-08-23 103992]
S2 HP Wireless Assistant Service;HP Wireless Assistant Service; C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2009-12-17 102968]
S2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-11-04 2320920]
S2 vcsFPService;Validity VCS Fingerprint Service; C:\windows\system32\vcsFPService.exe [2009-12-14 1639728]
S3 ACDaemon;ArcSoft Connect Daemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2009-09-28 109056]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2010-09-28 68096]
S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing; c:\Windows\system32\flcdlock.exe [2009-11-18 362040]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2011-02-24 655624]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2010-07-29 1343400]
-----------------EOF-----------------
Re: Preventívka..... -pre motji

- zkopírujte do okénka:
ComboFix /Uninstall
-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.
***********

http://tharifas.sweb.cz/T-Cleaner.exe
-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir
***********

- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru

- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner

- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy



- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.
Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.
***********

http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech
***********
Pak by to mělo být ok.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
-
- Vzorný návštěvník
- Příspěvky: 208
- Registrován: 07 čer 2010 17:54
- Bydliště: SK
- Kontaktovat uživatele:
Re: Preventívka..... -pre motji
Fajn. Díky moc (nedávno mi CCleaner zmazal vyše 1,4GB). Mohla by si mi ešte prosím pozreť tento Dump ?
http://www.mediafire.com/?mte6zhyno37yx14
Nabehol pri uspávaní PC. Díky moc za všetko
http://www.mediafire.com/?mte6zhyno37yx14
Nabehol pri uspávaní PC. Díky moc za všetko

Re: Preventívka..... -pre motji
Ovladač od grafiky, máte ATI?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.