Re: Prosim o kontrolu logu
Napsal: 13 kvě 2010 17:48
Kaspersky nic nenasiel vsak? Tu je novy log, myslite ze stale mam "nieco" v PC?
PS: Dakujem za Vasu pomoc.
Logfile of random's system information tool 1.07 (written by random/random)
Run by Daniel at 2010-05-13 17:45:02
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 45 GB (51%) free of 89 GB
Total RAM: 2046 MB (39% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:45:41, on 13/05/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\ASUS\ATK Media\DMedia.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.Exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\Yahoo!\Common\YMailAdvisor.exe
C:\Program Files\ICQ6.5\ICQ.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Daniel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L3UG5YDO\RSIT[1].exe
C:\Program Files\trend micro\Daniel.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Yahoo!\Companion\Installs\cpn\ytbb.exe
C:\Windows\system32\SearchFilterHost.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ÿþ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: ZoneAlarm Toolbar Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: ZoneAlarm Toolbar - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [ISW] "C:\Program Files\CheckPoint\ZAForceField\ForceField.exe" /icon="hidden"
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [YMailAdvisor] "C:\Program Files\Yahoo!\Common\YMailAdvisor.exe"
O4 - HKCU\..\Run: [ICQ] "C:\PROGRA~1\ICQ6.5\ICQ.exe" silent
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SpywareTerminatorUpdate] "C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {A4735C9C-6626-4386-9B93-2D9B79047AB8} (MediaPlugin Control) - http://www.joj.sk/fileadmin/joj_player/ ... Player.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: ADSM Service (ADSMService) - Unknown owner - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\Windows\SYSTEM32\crypserv.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: ZoneAlarm Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.11\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.1.36\bin\mysqld.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
--
End of file - 9133 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
&Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2010-03-23 1205560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3}]
ZoneAlarm Toolbar Registrar - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll [2009-10-14 578928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-04-12 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
SingleInstance Class - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll [2010-03-23 158520]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - ZoneAlarm Toolbar - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll [2009-10-14 578928]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2010-03-23 1205560]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-03-01 857648]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-02-15 4390912]
"NvSvc"=C:\Windows\system32\nvsvc.dll [2007-04-04 86016]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2007-04-04 81920]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [2007-02-12 174872]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2007-04-04 8429568]
"ATKMEDIA"=C:\Program Files\ASUS\ATK Media\DMEDIA.EXE [2006-11-02 61440]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2010-05-03 2176512]
"ZoneAlarm Client"=C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe [2009-11-22 1037192]
"ISW"=C:\Program Files\CheckPoint\ZAForceField\ForceField.exe [2009-10-14 730480]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-05-06 2815192]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-04-04 36272]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-03-24 952768]
"YMailAdvisor"=C:\Program Files\Yahoo!\Common\YMailAdvisor.exe [2009-05-08 174424]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ICQ"=C:\PROGRA~1\ICQ6.5\ICQ.exe [2009-11-16 172792]
"Skype"=C:\Program Files\Skype\\Phone\Skype.exe [2010-04-06 26102056]
"SpywareTerminatorUpdate"=C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [2010-05-03 3037696]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Camera ScreenSaver]
C:\Windows\ASScrProlog.exe [2008-02-13 37232]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
C:\Windows\ASScrPro.exe [2008-02-13 33136]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerForPhone]
C:\Program Files\PowerForPhone\PowerForPhone.exe [2007-01-16 778240]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe [2008-05-26 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [2006-11-22 630784]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
C:\Program Files\TomTom HOME\TomTomHOME.exe [2007-03-14 3770024]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk]
C:\PROGRA~1\MICROS~2\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Daniel^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MagicDisc.lnk]
C:\PROGRA~1\MAGICD~1\MAGICD~1.EXE [2007-09-05 557568]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2009-09-03 548352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 months======
2010-05-12 21:37:42 ----A---- C:\Windows\ntbtlog.txt
2010-05-12 20:10:03 ----D---- C:\ProgramData\Kaspersky Lab
2010-05-09 13:21:36 ----D---- C:\ProgramData\Yahoo! Companion
2010-05-09 13:21:01 ----D---- C:\Users\Daniel\AppData\Roaming\Yahoo!
2010-05-09 12:59:25 ----A---- C:\Windows\system32\mshtmler.dll
2010-05-09 12:59:25 ----A---- C:\Windows\system32\mshtmled.dll
2010-05-09 12:59:25 ----A---- C:\Windows\system32\jsproxy.dll
2010-05-09 12:59:25 ----A---- C:\Windows\system32\ieui.dll
2010-05-09 12:59:25 ----A---- C:\Windows\system32\icardie.dll
2010-05-09 12:59:25 ----A---- C:\Windows\system32\admparse.dll
2010-05-09 12:59:24 ----A---- C:\Windows\system32\msls31.dll
2010-05-09 12:59:24 ----A---- C:\Windows\system32\imgutil.dll
2010-05-09 12:59:24 ----A---- C:\Windows\system32\iernonce.dll
2010-05-09 12:59:24 ----A---- C:\Windows\system32\ieakeng.dll
2010-05-09 12:59:24 ----A---- C:\Windows\system32\corpol.dll
2010-05-09 12:59:23 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-05-09 12:59:23 ----A---- C:\Windows\system32\licmgr10.dll
2010-05-09 12:59:23 ----A---- C:\Windows\system32\inseng.dll
2010-05-09 12:59:23 ----A---- C:\Windows\system32\iepeers.dll
2010-05-09 12:59:23 ----A---- C:\Windows\system32\dxtrans.dll
2010-05-09 12:59:23 ----A---- C:\Windows\system32\dxtmsft.dll
2010-05-09 12:59:22 ----A---- C:\Windows\system32\WinFXDocObj.exe
2010-05-09 12:59:22 ----A---- C:\Windows\system32\wextract.exe
2010-05-09 12:59:22 ----A---- C:\Windows\system32\webcheck.dll
2010-05-09 12:59:22 ----A---- C:\Windows\system32\occache.dll
2010-05-09 12:59:22 ----A---- C:\Windows\system32\msrating.dll
2010-05-09 12:59:22 ----A---- C:\Windows\system32\msfeedssync.exe
2010-05-09 12:59:22 ----A---- C:\Windows\system32\iesetup.dll
2010-05-09 12:59:22 ----A---- C:\Windows\system32\ieakui.dll
2010-05-09 12:59:22 ----A---- C:\Windows\system32\ieaksie.dll
2010-05-09 12:59:21 ----A---- C:\Windows\system32\pngfilt.dll
2010-05-09 12:59:21 ----A---- C:\Windows\system32\mstime.dll
2010-05-09 12:59:21 ----A---- C:\Windows\system32\msfeeds.dll
2010-05-09 12:59:21 ----A---- C:\Windows\system32\advpack.dll
2010-05-09 12:59:20 ----A---- C:\Windows\system32\vbscript.dll
2010-05-09 12:59:20 ----A---- C:\Windows\system32\jscript.dll
2010-05-09 12:59:20 ----A---- C:\Windows\system32\ieapfltr.dll
2010-05-09 12:59:19 ----A---- C:\Windows\system32\url.dll
2010-05-09 12:59:19 ----A---- C:\Windows\system32\iedkcs32.dll
2010-05-09 12:59:17 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2010-05-09 12:59:17 ----A---- C:\Windows\system32\SetDepNx.exe
2010-05-09 12:59:17 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2010-05-09 12:59:17 ----A---- C:\Windows\system32\PDMSetup.exe
2010-05-09 12:59:17 ----A---- C:\Windows\system32\mshta.exe
2010-05-09 12:59:17 ----A---- C:\Windows\system32\iexpress.exe
2010-05-09 12:59:17 ----A---- C:\Windows\system32\ieUnatt.exe
2010-05-09 12:59:17 ----A---- C:\Windows\system32\iesysprep.dll
2010-05-09 12:59:13 ----A---- C:\Windows\system32\iertutil.dll
2010-05-09 12:59:10 ----A---- C:\Windows\system32\ie4uinit.exe
2010-05-09 12:59:09 ----A---- C:\Windows\system32\wininet.dll
2010-05-09 12:59:08 ----A---- C:\Windows\system32\urlmon.dll
2010-05-09 12:59:07 ----A---- C:\Windows\system32\ieframe.dll
2010-05-09 12:59:06 ----A---- C:\Windows\system32\mshtml.dll
2010-05-07 20:19:47 ----A---- C:\ComboFix.txt
2010-05-07 20:18:51 ----SHD---- C:\$RECYCLE.BIN
2010-05-07 20:08:51 ----D---- C:\ComboFix
2010-05-07 20:08:16 ----A---- C:\Windows\SWXCACLS.exe
2010-05-07 19:43:28 ----A---- C:\Windows\zip.exe
2010-05-07 19:43:28 ----A---- C:\Windows\SWSC.exe
2010-05-07 19:43:28 ----A---- C:\Windows\SWREG.exe
2010-05-07 19:43:28 ----A---- C:\Windows\sed.exe
2010-05-07 19:43:28 ----A---- C:\Windows\PEV.exe
2010-05-07 19:43:28 ----A---- C:\Windows\NIRCMD.exe
2010-05-07 19:43:28 ----A---- C:\Windows\MBR.exe
2010-05-07 19:43:28 ----A---- C:\Windows\grep.exe
2010-05-07 19:43:22 ----D---- C:\Windows\ERDNT
2010-05-07 19:42:57 ----D---- C:\Qoobox
2010-05-07 19:16:06 ----D---- C:\rsit
2010-05-04 20:16:59 ----D---- C:\ProgramData\WindowsSearch
2010-05-04 19:02:18 ----D---- C:\Windows\system32\vi-VN
2010-05-04 19:02:18 ----D---- C:\Windows\system32\eu-ES
2010-05-04 19:02:18 ----D---- C:\Windows\system32\ca-ES
2010-05-04 18:57:14 ----D---- C:\Windows\system32\SPReview
2010-05-04 18:40:56 ----A---- C:\Windows\system32\scavenge.dll
2010-05-04 18:40:13 ----A---- C:\Windows\system32\compcln.exe
2010-05-04 18:26:34 ----A---- C:\Windows\system32\secur32.dll
2010-05-04 18:26:34 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2010-05-04 18:26:33 ----A---- C:\Windows\system32\secproc_ssp.dll
2010-05-04 18:26:33 ----A---- C:\Windows\system32\secproc_isv.dll
2010-05-04 18:26:33 ----A---- C:\Windows\system32\secproc.dll
2010-05-04 18:26:32 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2010-05-04 18:26:32 ----A---- C:\Windows\system32\SearchIndexer.exe
2010-05-04 18:26:32 ----A---- C:\Windows\system32\SearchFilterHost.exe
2010-05-04 18:26:32 ----A---- C:\Windows\system32\sdohlp.dll
2010-05-04 18:26:31 ----A---- C:\Windows\system32\sdclt.exe
2010-05-04 18:26:30 ----A---- C:\Windows\system32\rsaenh.dll
2010-05-04 18:26:29 ----A---- C:\Windows\system32\rtffilt.dll
2010-05-04 18:26:29 ----A---- C:\Windows\system32\rrinstaller.exe
2010-05-04 18:26:28 ----A---- C:\Windows\system32\samlib.dll
2010-05-04 18:26:28 ----A---- C:\Windows\system32\rtutils.dll
2010-05-04 18:26:28 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2010-05-04 18:26:28 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2010-05-04 18:26:28 ----A---- C:\Windows\system32\RMActivate_isv.exe
2010-05-04 18:26:27 ----A---- C:\Windows\system32\RMActivate.exe
2010-05-04 18:26:27 ----A---- C:\Windows\system32\riched20.dll
2010-05-04 18:26:26 ----A---- C:\Windows\system32\rpcss.dll
2010-05-04 18:26:26 ----A---- C:\Windows\system32\rpcrt4.dll
2010-05-04 18:26:26 ----A---- C:\Windows\system32\rpchttp.dll
2010-05-04 18:26:25 ----A---- C:\Windows\system32\scrrun.dll
2010-05-04 18:26:23 ----A---- C:\Windows\system32\SCardSvr.dll
2010-05-04 18:26:23 ----A---- C:\Windows\system32\scansetting.dll
2010-05-04 18:26:22 ----A---- C:\Windows\system32\samsrv.dll
2010-05-04 18:26:21 ----A---- C:\Windows\system32\scksp.dll
2010-05-04 18:26:21 ----A---- C:\Windows\system32\schedsvc.dll
2010-05-04 18:26:20 ----A---- C:\Windows\system32\scrobj.dll
2010-05-04 18:26:20 ----A---- C:\Windows\system32\scecli.dll
2010-05-04 18:26:18 ----A---- C:\Windows\system32\schannel.dll
2010-05-04 18:26:18 ----A---- C:\Windows\system32\scesrv.dll
2010-05-04 18:26:12 ----A---- C:\Windows\system32\pdh.dll
2010-05-04 18:26:11 ----A---- C:\Windows\system32\PerfCenterCPL.dll
2010-05-04 18:26:10 ----A---- C:\Windows\system32\perfdisk.dll
2010-05-04 18:26:10 ----A---- C:\Windows\system32\pcaui.dll
2010-05-04 18:26:10 ----A---- C:\Windows\system32\p2psvc.dll
2010-05-04 18:26:10 ----A---- C:\Windows\system32\P2PGraph.dll
2010-05-04 18:26:09 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2010-05-04 18:26:09 ----A---- C:\Windows\system32\PNPXAssoc.dll
2010-05-04 18:26:09 ----A---- C:\Windows\system32\PnPutil.exe
2010-05-04 18:26:09 ----A---- C:\Windows\system32\PnPUnattend.exe
2010-05-04 18:26:09 ----A---- C:\Windows\system32\pnpui.dll
2010-05-04 18:26:09 ----A---- C:\Windows\system32\pnpsetup.dll
2010-05-04 18:26:09 ----A---- C:\Windows\system32\pnidui.dll
2010-05-04 18:26:08 ----A---- C:\Windows\system32\powercpl.dll
2010-05-04 18:26:08 ----A---- C:\Windows\system32\PortableDeviceTypes.dll
2010-05-04 18:26:08 ----A---- C:\Windows\system32\PortableDeviceClassExtension.dll
2010-05-04 18:26:08 ----A---- C:\Windows\system32\pidgenx.dll
2010-05-04 18:26:08 ----A---- C:\Windows\system32\photowiz.dll
2010-05-04 18:26:07 ----A---- C:\Windows\system32\PkgMgr.exe
2010-05-04 18:26:07 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
2010-05-04 18:26:06 ----A---- C:\Windows\system32\ntkrnlpa.exe
2010-05-04 18:26:06 ----A---- C:\Windows\system32\ntdll.dll
2010-05-04 18:26:06 ----A---- C:\Windows\system32\nslookup.exe
2010-05-04 18:26:04 ----A---- C:\Windows\system32\offfilt.dll
2010-05-04 18:26:04 ----A---- C:\Windows\system32\NlsLexicons0009.dll
2010-05-04 18:26:04 ----A---- C:\Windows\system32\NlsLexicons0007.dll
2010-05-04 18:26:04 ----A---- C:\Windows\system32\nlhtml.dll
2010-05-04 18:26:03 ----A---- C:\Windows\system32\oleaut32.dll
2010-05-04 18:26:03 ----A---- C:\Windows\system32\ole32.dll
2010-05-04 18:26:03 ----A---- C:\Windows\system32\odbc32.dll
2010-05-04 18:26:02 ----A---- C:\Windows\system32\osk.exe
2010-05-04 18:26:02 ----A---- C:\Windows\system32\onex.dll
2010-05-04 18:26:02 ----A---- C:\Windows\system32\odbccp32.dll
2010-05-04 18:26:02 ----A---- C:\Windows\system32\odbcconf.dll
2010-05-04 18:26:01 ----A---- C:\Windows\system32\oobefldr.dll
2010-05-04 18:26:01 ----A---- C:\Windows\system32\olepro32.dll
2010-05-04 18:26:01 ----A---- C:\Windows\system32\oleprn.dll
2010-05-04 18:26:01 ----A---- C:\Windows\system32\ocsetup.exe
2010-05-04 18:26:00 ----A---- C:\Windows\system32\rasgcw.dll
2010-05-04 18:26:00 ----A---- C:\Windows\system32\rasdlg.dll
2010-05-04 18:26:00 ----A---- C:\Windows\system32\ntprint.dll
2010-05-04 18:26:00 ----A---- C:\Windows\system32\ntoskrnl.exe
2010-05-04 18:26:00 ----A---- C:\Windows\system32\ntmarta.dll
2010-05-04 18:25:59 ----A---- C:\Windows\system32\rastls.dll
2010-05-04 18:25:59 ----A---- C:\Windows\system32\rastapi.dll
2010-05-04 18:25:59 ----A---- C:\Windows\system32\rasppp.dll
2010-05-04 18:25:59 ----A---- C:\Windows\system32\rasplap.dll
2010-05-04 18:25:59 ----A---- C:\Windows\system32\rasmontr.dll
2010-05-04 18:25:59 ----A---- C:\Windows\system32\rasmans.dll
2010-05-04 18:25:59 ----A---- C:\Windows\system32\rasdial.exe
2010-05-04 18:25:59 ----A---- C:\Windows\system32\rasdiag.dll
2010-05-04 18:25:59 ----A---- C:\Windows\system32\raschap.dll
2010-05-04 18:25:59 ----A---- C:\Windows\system32\rasapi32.dll
2010-05-04 18:25:58 ----A---- C:\Windows\system32\RacEngn.dll
2010-05-04 18:25:58 ----A---- C:\Windows\system32\Query.dll
2010-05-04 18:25:58 ----A---- C:\Windows\system32\quartz.dll
2010-05-04 18:25:58 ----A---- C:\Windows\system32\qmgr.dll
2010-05-04 18:25:58 ----A---- C:\Windows\system32\qedit.dll
2010-05-04 18:25:57 ----A---- C:\Windows\system32\RelMon.dll
2010-05-04 18:25:57 ----A---- C:\Windows\system32\rekeywiz.exe
2010-05-04 18:25:57 ----A---- C:\Windows\system32\regsvc.dll
2010-05-04 18:25:56 ----A---- C:\Windows\system32\reg.exe
2010-05-04 18:25:56 ----A---- C:\Windows\system32\rdpencom.dll
2010-05-04 18:25:55 ----A---- C:\Windows\system32\regapi.dll
2010-05-04 18:25:55 ----A---- C:\Windows\system32\rdpwsx.dll
2010-05-04 18:25:54 ----A---- C:\Windows\system32\printui.dll
2010-05-04 18:25:54 ----A---- C:\Windows\system32\PresentationSettings.exe
2010-05-04 18:25:54 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
2010-05-04 18:25:54 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2010-05-04 18:25:54 ----A---- C:\Windows\system32\PresentationHost.exe
2010-05-04 18:25:53 ----A---- C:\Windows\system32\prnntfy.dll
2010-05-04 18:25:53 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
2010-05-04 18:25:53 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll
2010-05-04 18:25:53 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2010-05-04 18:25:53 ----A---- C:\Windows\system32\powrprof.dll
2010-05-04 18:25:51 ----A---- C:\Windows\system32\qdvd.dll
2010-05-04 18:25:51 ----A---- C:\Windows\system32\QAGENTRT.DLL
2010-05-04 18:25:51 ----A---- C:\Windows\system32\puiapi.dll
2010-05-04 18:25:50 ----A---- C:\Windows\system32\psisdecd.dll
2010-05-04 18:25:50 ----A---- C:\Windows\system32\PSHED.DLL
2010-05-04 18:25:50 ----A---- C:\Windows\system32\propsys.dll
2010-05-04 18:25:50 ----A---- C:\Windows\system32\propdefs.dll
2010-05-04 18:25:50 ----A---- C:\Windows\system32\profsvc.dll
2010-05-04 18:25:44 ----A---- C:\Windows\system32\sendmail.dll
2010-05-04 18:25:42 ----A---- C:\Windows\system32\shell32.dll
2010-05-04 18:25:41 ----A---- C:\Windows\system32\shlwapi.dll
2010-05-04 18:25:41 ----A---- C:\Windows\system32\shdocvw.dll
2010-05-04 18:25:40 ----A---- C:\Windows\system32\sethc.exe
2010-05-04 18:25:40 ----A---- C:\Windows\system32\services.exe
2010-05-04 18:25:39 ----A---- C:\Windows\system32\setupapi.dll
2010-05-04 18:25:29 ----A---- C:\Windows\system32\eapphost.dll
2010-05-04 18:25:29 ----A---- C:\Windows\system32\eappgnui.dll
2010-05-04 18:25:28 ----A---- C:\Windows\system32\EhStorAPI.dll
2010-05-04 18:25:28 ----A---- C:\Windows\system32\eappcfg.dll
2010-05-04 18:25:28 ----A---- C:\Windows\system32\eapp3hst.dll
2010-05-04 18:25:27 ----A---- C:\Windows\system32\dsprop.dll
2010-05-04 18:25:26 ----A---- C:\Windows\system32\evr.dll
2010-05-04 18:25:26 ----A---- C:\Windows\system32\eudcedit.exe
2010-05-04 18:25:26 ----A---- C:\Windows\system32\dxmasf.dll
2010-05-04 18:25:26 ----A---- C:\Windows\system32\dwm.exe
2010-05-04 18:25:26 ----A---- C:\Windows\system32\dsound.dll
2010-05-04 18:25:25 ----A---- C:\Windows\system32\f3ahvoas.dll
2010-05-04 18:25:25 ----A---- C:\Windows\system32\ExplorerFrame.dll
2010-05-04 18:25:25 ----A---- C:\Windows\system32\esent.dll
2010-05-04 18:25:25 ----A---- C:\Windows\explorer.exe
2010-05-04 18:25:24 ----A---- C:\Windows\system32\EncDec.dll
2010-05-04 18:25:24 ----A---- C:\Windows\system32\emdmgmt.dll
2010-05-04 18:25:24 ----A---- C:\Windows\system32\EhStorPwdMgr.dll
2010-05-04 18:25:24 ----A---- C:\Windows\system32\EhStorAuthn.dll
2010-05-04 18:25:23 ----A---- C:\Windows\system32\es.dll
2010-05-04 18:25:23 ----A---- C:\Windows\system32\EhStorShell.dll
2010-05-04 18:25:23 ----A---- C:\Windows\system32\diagperf.dll
2010-05-04 18:25:22 ----A---- C:\Windows\system32\dimsroam.dll
2010-05-04 18:25:22 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2010-05-04 18:25:21 ----A---- C:\Windows\system32\diskraid.exe
2010-05-04 18:25:21 ----A---- C:\Windows\system32\diskpart.exe
2010-05-04 18:25:20 ----A---- C:\Windows\system32\dfsr.exe
2010-05-04 18:25:20 ----A---- C:\Windows\system32\dfshim.dll
2010-05-04 18:25:20 ----A---- C:\Windows\system32\devmgr.dll
2010-05-04 18:25:18 ----A---- C:\Windows\system32\dhcpcsvc.dll
2010-05-04 18:25:17 ----A---- C:\Windows\system32\drvstore.dll
2010-05-04 18:25:17 ----A---- C:\Windows\system32\dpapimig.exe
2010-05-04 18:25:17 ----A---- C:\Windows\system32\dot3svc.dll
2010-05-04 18:25:17 ----A---- C:\Windows\system32\dot3msm.dll
2010-05-04 18:25:17 ----A---- C:\Windows\system32\dot3cfg.dll
2010-05-04 18:25:16 ----A---- C:\Windows\system32\drmmgrtn.dll
2010-05-04 18:25:15 ----A---- C:\Windows\system32\drvinst.exe
2010-05-04 18:25:15 ----A---- C:\Windows\system32\drmv2clt.dll
2010-05-04 18:25:14 ----A---- C:\Windows\system32\dnsrslvr.dll
2010-05-04 18:25:14 ----A---- C:\Windows\system32\dnsapi.dll
2010-05-04 18:25:14 ----A---- C:\Windows\system32\dmusic.dll
2010-05-04 18:25:14 ----A---- C:\Windows\system32\dmsynth.dll
2010-05-04 18:25:13 ----A---- C:\Windows\system32\hbaapi.dll
2010-05-04 18:25:11 ----A---- C:\Windows\system32\gpresult.exe
2010-05-04 18:25:09 ----A---- C:\Windows\system32\iasads.dll
2010-05-04 18:25:09 ----A---- C:\Windows\system32\gpupdate.exe
2010-05-04 18:25:09 ----A---- C:\Windows\system32\gpsvc.dll
2010-05-04 18:25:08 ----A---- C:\Windows\system32\iashlpr.dll
2010-05-04 18:25:08 ----A---- C:\Windows\system32\iasdatastore.dll
2010-05-04 18:25:08 ----A---- C:\Windows\system32\iasacct.dll
2010-05-04 18:25:06 ----A---- C:\Windows\system32\iasnap.dll
2010-05-04 18:25:06 ----A---- C:\Windows\system32\IasMigReader.exe
2010-05-04 18:25:06 ----A---- C:\Windows\system32\IasMigPlugin.dll
2010-05-04 18:25:05 ----A---- C:\Windows\system32\hidserv.dll
2010-05-04 18:25:05 ----A---- C:\Windows\system32\hdwwiz.exe
2010-05-04 18:25:04 ----A---- C:\Windows\system32\fontext.dll
2010-05-04 18:25:04 ----A---- C:\Windows\system32\findstr.exe
2010-05-04 18:25:04 ----A---- C:\Windows\system32\Faultrep.dll
2010-05-04 18:25:03 ----A---- C:\Windows\system32\fc.exe
2010-05-04 18:25:02 ----A---- C:\Windows\system32\feclient.dll
2010-05-04 18:25:02 ----A---- C:\Windows\system32\fdWSD.dll
2010-05-04 18:25:02 ----A---- C:\Windows\system32\fdWCN.dll
2010-05-04 18:25:02 ----A---- C:\Windows\system32\fdSSDP.dll
2010-05-04 18:25:01 ----A---- C:\Windows\system32\fdProxy.dll
2010-05-04 18:25:01 ----A---- C:\Windows\system32\fdeploy.dll
2010-05-04 18:25:01 ----A---- C:\Windows\system32\fdBthProxy.dll
2010-05-04 18:25:01 ----A---- C:\Windows\system32\fdBth.dll
2010-05-04 18:25:00 ----A---- C:\Windows\system32\gpapi.dll
2010-05-04 18:25:00 ----A---- C:\Windows\system32\gdi32.dll
2010-05-04 18:24:59 ----A---- C:\Windows\system32\gpedit.dll
2010-05-04 18:24:58 ----A---- C:\Windows\system32\fundisc.dll
2010-05-04 18:24:57 ----A---- C:\Windows\system32\ftp.exe
2010-05-04 18:24:57 ----A---- C:\Windows\system32\fsquirt.exe
2010-05-04 18:24:56 ----A---- C:\Windows\system32\FwRemoteSvr.dll
2010-05-04 18:24:56 ----A---- C:\Windows\system32\FunctionDiscoveryFolder.dll
2010-05-04 18:24:55 ----A---- C:\Windows\system32\gameux.dll
2010-05-04 18:24:55 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2010-05-04 18:24:54 ----A---- C:\Windows\system32\authui.dll
2010-05-04 18:24:54 ----A---- C:\Windows\system32\audiosrv.dll
2010-05-04 18:24:54 ----A---- C:\Windows\system32\AudioSes.dll
2010-05-04 18:24:53 ----A---- C:\Windows\system32\autochk.exe
2010-05-04 18:24:53 ----A---- C:\Windows\system32\authz.dll
2010-05-04 18:24:53 ----A---- C:\Windows\system32\audiodg.exe
2010-05-04 18:24:53 ----A---- C:\Windows\system32\atmfd.dll
2010-05-04 18:24:52 ----A---- C:\Windows\system32\AuxiliaryDisplayServices.dll
2010-05-04 18:24:52 ----A---- C:\Windows\system32\AuxiliaryDisplayDriverLib.dll
2010-05-04 18:24:52 ----A---- C:\Windows\system32\atmlib.dll
2010-05-04 18:24:51 ----A---- C:\Windows\system32\autofmt.exe
2010-05-04 18:24:51 ----A---- C:\Windows\system32\autoconv.exe
2010-05-04 18:24:50 ----A---- C:\Windows\system32\AuxiliaryDisplayCpl.dll
2010-05-04 18:24:50 ----A---- C:\Windows\system32\autoplay.dll
2010-05-04 18:24:46 ----A---- C:\Windows\system32\brcpl.dll
2010-05-04 18:24:44 ----A---- C:\Windows\system32\bthci.dll
2010-05-04 18:24:44 ----A---- C:\Windows\system32\browseui.dll
2010-05-04 18:24:42 ----A---- C:\Windows\system32\basecsp.dll
2010-05-04 18:24:41 ----A---- C:\Windows\system32\azroles.dll
2010-05-04 18:24:40 ----A---- C:\Windows\system32\blackbox.dll
2010-05-04 18:24:40 ----A---- C:\Windows\system32\bitsigd.dll
2010-05-04 18:24:40 ----A---- C:\Windows\system32\bcrypt.dll
2010-05-04 18:24:39 ----A---- C:\Windows\system32\BFE.DLL
2010-05-04 18:24:36 ----A---- C:\Windows\system32\accessibilitycpl.dll
2010-05-04 18:24:34 ----A---- C:\Windows\system32\aaclient.dll
2010-05-04 18:24:33 ----A---- C:\Windows\system32\apphelp.dll
2010-05-04 18:24:32 ----A---- C:\Windows\system32\Apphlpdm.dll
2010-05-04 18:24:31 ----A---- C:\Windows\system32\apds.dll
2010-05-04 18:24:30 ----A---- C:\Windows\system32\adsmsext.dll
2010-05-04 18:24:30 ----A---- C:\Windows\system32\adsldpc.dll
2010-05-04 18:24:29 ----A---- C:\Windows\system32\adtschema.dll
2010-05-04 18:24:28 ----A---- C:\Windows\system32\conime.exe
2010-05-04 18:24:28 ----A---- C:\Windows\system32\comuid.dll
2010-05-04 18:24:28 ----A---- C:\Windows\system32\comsvcs.dll
2010-05-04 18:24:28 ----A---- C:\Windows\system32\advapi32.dll
2010-05-04 18:24:27 ----A---- C:\Windows\system32\crypt32.dll
2010-05-04 18:24:27 ----A---- C:\Windows\system32\credui.dll
2010-05-04 18:24:26 ----A---- C:\Windows\system32\connect.dll
2010-05-04 18:24:26 ----A---- C:\Windows\system32\cmdial32.dll
2010-05-04 18:24:25 ----A---- C:\Windows\system32\comdlg32.dll
2010-05-04 18:24:24 ----A---- C:\Windows\system32\dbgeng.dll
2010-05-04 18:24:24 ----A---- C:\Windows\system32\cmmon32.exe
2010-05-04 18:24:23 ----A---- C:\Windows\system32\davclnt.dll
2010-05-04 18:24:23 ----A---- C:\Windows\system32\dataclen.dll
2010-05-04 18:24:23 ----A---- C:\Windows\system32\d3d9.dll
2010-05-04 18:24:22 ----A---- C:\Windows\system32\DevicePairingWizard.exe
2010-05-04 18:24:22 ----A---- C:\Windows\system32\DevicePairingProxy.dll
2010-05-04 18:24:22 ----A---- C:\Windows\system32\DevicePairing.dll
2010-05-04 18:24:22 ----A---- C:\Windows\system32\DeviceEject.exe
2010-05-04 18:24:21 ----A---- C:\Windows\system32\cscdll.dll
2010-05-04 18:24:21 ----A---- C:\Windows\system32\cscapi.dll
2010-05-04 18:24:21 ----A---- C:\Windows\system32\cryptui.dll
2010-05-04 18:24:21 ----A---- C:\Windows\system32\cryptsvc.dll
2010-05-04 18:24:20 ----A---- C:\Windows\system32\csrstub.exe
2010-05-04 18:24:20 ----A---- C:\Windows\system32\cscript.exe
2010-05-04 18:24:19 ----A---- C:\Windows\system32\cdd.dll
2010-05-04 18:24:18 ----A---- C:\Windows\system32\certmgr.dll
2010-05-04 18:24:18 ----A---- C:\Windows\system32\certcli.dll
2010-05-04 18:24:17 ----A---- C:\Windows\system32\CertEnrollUI.dll
2010-05-04 18:24:17 ----A---- C:\Windows\system32\CertEnroll.dll
2010-05-04 18:24:17 ----A---- C:\Windows\system32\bthudtask.exe
2010-05-04 18:24:17 ----A---- C:\Windows\system32\bthserv.dll
2010-05-04 18:24:16 ----A---- C:\Windows\system32\cbsra.exe
2010-05-04 18:24:15 ----A---- C:\Windows\system32\cipher.exe
2010-05-04 18:24:15 ----A---- C:\Windows\system32\ci.dll
2010-05-04 18:24:14 ----A---- C:\Windows\system32\CHxReadingStringIME.dll
2010-05-04 18:24:14 ----A---- C:\Windows\system32\chtbrkr.dll
2010-05-04 18:24:14 ----A---- C:\Windows\system32\chsbrkr.dll
2010-05-04 18:24:13 ----A---- C:\Windows\system32\certreq.exe
2010-05-04 18:24:13 ----A---- C:\Windows\system32\certprop.dll
2010-05-04 18:24:12 ----A---- C:\Windows\system32\msftedit.dll
2010-05-04 18:24:12 ----A---- C:\Windows\system32\certutil.exe
2010-05-04 18:24:11 ----A---- C:\Windows\system32\msihnd.dll
2010-05-04 18:24:11 ----A---- C:\Windows\system32\msiexec.exe
2010-05-04 18:24:11 ----A---- C:\Windows\system32\msexcl40.dll
2010-05-04 18:24:11 ----A---- C:\Windows\system32\msexch40.dll
2010-05-04 18:24:11 ----A---- C:\Windows\system32\msdtctm.dll
2010-05-04 18:24:09 ----A---- C:\Windows\system32\msi.dll
2010-05-04 18:24:07 ----A---- C:\Windows\system32\msdrm.dll
2010-05-04 18:24:06 ----A---- C:\Windows\system32\msdtcprx.dll
2010-05-04 18:24:06 ----A---- C:\Windows\system32\msctfui.dll
2010-05-04 18:24:06 ----A---- C:\Windows\system32\msctfp.dll
2010-05-04 18:24:06 ----A---- C:\Windows\system32\MsCtfMonitor.dll
2010-05-04 18:24:06 ----A---- C:\Windows\system32\msctf.dll
2010-05-04 18:24:04 ----A---- C:\Windows\system32\msimsg.dll
2010-05-04 18:24:03 ----A---- C:\Windows\system32\MPSSVC.dll
2010-05-04 18:24:02 ----A---- C:\Windows\system32\mprapi.dll
2010-05-04 18:24:02 ----A---- C:\Windows\system32\mpr.dll
2010-05-04 18:24:00 ----A---- C:\Windows\system32\modemui.dll
2010-05-04 18:24:00 ----A---- C:\Windows\system32\MMDevAPI.dll
2010-05-04 18:23:58 ----A---- C:\Windows\system32\mscandui.dll
2010-05-04 18:23:57 ----A---- C:\Windows\system32\mscms.dll
2010-05-04 18:23:56 ----A---- C:\Windows\system32\mscories.dll
2010-05-04 18:23:56 ----A---- C:\Windows\system32\mscorier.dll
2010-05-04 18:23:55 ----A---- C:\Windows\system32\mscoree.dll
2010-05-04 18:23:54 ----A---- C:\Windows\system32\netapi32.dll
2010-05-04 18:23:53 ----A---- C:\Windows\system32\netplwiz.dll
2010-05-04 18:23:53 ----A---- C:\Windows\system32\netcenter.dll
2010-05-04 18:23:53 ----A---- C:\Windows\system32\ncryptui.dll
2010-05-04 18:23:53 ----A---- C:\Windows\system32\ncrypt.dll
2010-05-04 18:23:52 ----A---- C:\Windows\system32\NetProjW.dll
2010-05-04 18:23:51 ----A---- C:\Windows\system32\netlogon.dll
2010-05-04 18:23:51 ----A---- C:\Windows\system32\netiohlp.dll
2010-05-04 18:23:51 ----A---- C:\Windows\system32\mtxclu.dll
2010-05-04 18:23:48 ----A---- C:\Windows\system32\msxml6.dll
2010-05-04 18:23:47 ----A---- C:\Windows\system32\NcdProp.dll
2010-05-04 18:23:47 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2010-05-04 18:23:47 ----A---- C:\Windows\system32\msxml3.dll
2010-05-04 18:23:44 ----A---- C:\Windows\system32\newdev.exe
2010-05-04 18:23:44 ----A---- C:\Windows\system32\newdev.dll
2010-05-04 18:23:44 ----A---- C:\Windows\system32\netshell.dll
2010-05-04 18:23:43 ----A---- C:\Windows\system32\networkmap.dll
2010-05-04 18:23:43 ----A---- C:\Windows\system32\networkitemfactory.dll
2010-05-04 18:23:43 ----A---- C:\Windows\system32\networkexplorer.dll
2010-05-04 18:23:42 ----A---- C:\Windows\system32\msnetobj.dll
2010-05-04 18:23:42 ----A---- C:\Windows\system32\msltus40.dll
2010-05-04 18:23:41 ----A---- C:\Windows\system32\msscntrs.dll
2010-05-04 18:23:41 ----A---- C:\Windows\system32\msscb.dll
2010-05-04 18:23:41 ----A---- C:\Windows\system32\msrepl40.dll
2010-05-04 18:23:41 ----A---- C:\Windows\system32\msrd3x40.dll
2010-05-04 18:23:41 ----A---- C:\Windows\system32\mspbde40.dll
2010-05-04 18:23:41 ----A---- C:\Windows\system32\MSMPEG2VDEC.DLL
2010-05-04 18:23:40 ----A---- C:\Windows\system32\msrd2x40.dll
2010-05-04 18:23:40 ----A---- C:\Windows\system32\msinfo32.exe
2010-05-04 18:23:40 ----A---- C:\Windows\system32\msimtf.dll
2010-05-04 18:23:39 ----A---- C:\Windows\system32\msjtes40.dll
2010-05-04 18:23:39 ----A---- C:\Windows\system32\msjter40.dll
2010-05-04 18:23:39 ----A---- C:\Windows\system32\msjint40.dll
2010-05-04 18:23:39 ----A---- C:\Windows\system32\msjetoledb40.dll
2010-05-04 18:23:39 ----A---- C:\Windows\system32\msjet40.dll
2010-05-04 18:23:39 ----A---- C:\Windows\system32\msisip.dll
2010-05-04 18:23:38 ----A---- C:\Windows\system32\msvcp60.dll
2010-05-04 18:23:38 ----A---- C:\Windows\system32\msv1_0.dll
2010-05-04 18:23:38 ----A---- C:\Windows\system32\msutb.dll
2010-05-04 18:23:38 ----A---- C:\Windows\system32\mstscax.dll
2010-05-04 18:23:37 ----A---- C:\Windows\system32\msxbde40.dll
2010-05-04 18:23:37 ----A---- C:\Windows\system32\mswstr10.dll
2010-05-04 18:23:37 ----A---- C:\Windows\system32\mswsock.dll
2010-05-04 18:23:37 ----A---- C:\Windows\system32\mswdat10.dll
2010-05-04 18:23:37 ----A---- C:\Windows\system32\msvcrt.dll
2010-05-04 18:23:36 ----A---- C:\Windows\system32\MSVidCtl.dll
2010-05-04 18:23:36 ----A---- C:\Windows\system32\mssphtb.dll
2010-05-04 18:23:36 ----A---- C:\Windows\system32\mssph.dll
2010-05-04 18:23:35 ----A---- C:\Windows\system32\mssrch.dll
2010-05-04 18:23:35 ----A---- C:\Windows\system32\mssprxy.dll
2010-05-04 18:23:35 ----A---- C:\Windows\system32\mssitlb.dll
2010-05-04 18:23:35 ----A---- C:\Windows\system32\msshooks.dll
2010-05-04 18:23:35 ----A---- C:\Windows\system32\msscp.dll
2010-05-04 18:23:34 ----A---- C:\Windows\system32\mstsc.exe
2010-05-04 18:23:34 ----A---- C:\Windows\system32\mstlsapi.dll
2010-05-04 18:23:34 ----A---- C:\Windows\system32\mstext40.dll
PS: Dakujem za Vasu pomoc.

Logfile of random's system information tool 1.07 (written by random/random)
Run by Daniel at 2010-05-13 17:45:02
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 45 GB (51%) free of 89 GB
Total RAM: 2046 MB (39% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:45:41, on 13/05/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\ASUS\ATK Media\DMedia.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.Exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\Yahoo!\Common\YMailAdvisor.exe
C:\Program Files\ICQ6.5\ICQ.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Daniel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L3UG5YDO\RSIT[1].exe
C:\Program Files\trend micro\Daniel.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Yahoo!\Companion\Installs\cpn\ytbb.exe
C:\Windows\system32\SearchFilterHost.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ÿþ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: ZoneAlarm Toolbar Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: ZoneAlarm Toolbar - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [ISW] "C:\Program Files\CheckPoint\ZAForceField\ForceField.exe" /icon="hidden"
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [YMailAdvisor] "C:\Program Files\Yahoo!\Common\YMailAdvisor.exe"
O4 - HKCU\..\Run: [ICQ] "C:\PROGRA~1\ICQ6.5\ICQ.exe" silent
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SpywareTerminatorUpdate] "C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {A4735C9C-6626-4386-9B93-2D9B79047AB8} (MediaPlugin Control) - http://www.joj.sk/fileadmin/joj_player/ ... Player.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: ADSM Service (ADSMService) - Unknown owner - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\Windows\SYSTEM32\crypserv.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: ZoneAlarm Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.11\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.1.36\bin\mysqld.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
--
End of file - 9133 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
&Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2010-03-23 1205560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3}]
ZoneAlarm Toolbar Registrar - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll [2009-10-14 578928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-04-12 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
SingleInstance Class - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll [2010-03-23 158520]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - ZoneAlarm Toolbar - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll [2009-10-14 578928]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2010-03-23 1205560]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-03-01 857648]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-02-15 4390912]
"NvSvc"=C:\Windows\system32\nvsvc.dll [2007-04-04 86016]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2007-04-04 81920]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [2007-02-12 174872]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2007-04-04 8429568]
"ATKMEDIA"=C:\Program Files\ASUS\ATK Media\DMEDIA.EXE [2006-11-02 61440]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2010-05-03 2176512]
"ZoneAlarm Client"=C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe [2009-11-22 1037192]
"ISW"=C:\Program Files\CheckPoint\ZAForceField\ForceField.exe [2009-10-14 730480]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-05-06 2815192]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-04-04 36272]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-03-24 952768]
"YMailAdvisor"=C:\Program Files\Yahoo!\Common\YMailAdvisor.exe [2009-05-08 174424]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ICQ"=C:\PROGRA~1\ICQ6.5\ICQ.exe [2009-11-16 172792]
"Skype"=C:\Program Files\Skype\\Phone\Skype.exe [2010-04-06 26102056]
"SpywareTerminatorUpdate"=C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [2010-05-03 3037696]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Camera ScreenSaver]
C:\Windows\ASScrProlog.exe [2008-02-13 37232]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
C:\Windows\ASScrPro.exe [2008-02-13 33136]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerForPhone]
C:\Program Files\PowerForPhone\PowerForPhone.exe [2007-01-16 778240]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe [2008-05-26 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [2006-11-22 630784]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
C:\Program Files\TomTom HOME\TomTomHOME.exe [2007-03-14 3770024]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk]
C:\PROGRA~1\MICROS~2\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Daniel^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MagicDisc.lnk]
C:\PROGRA~1\MAGICD~1\MAGICD~1.EXE [2007-09-05 557568]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2009-09-03 548352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 months======
2010-05-12 21:37:42 ----A---- C:\Windows\ntbtlog.txt
2010-05-12 20:10:03 ----D---- C:\ProgramData\Kaspersky Lab
2010-05-09 13:21:36 ----D---- C:\ProgramData\Yahoo! Companion
2010-05-09 13:21:01 ----D---- C:\Users\Daniel\AppData\Roaming\Yahoo!
2010-05-09 12:59:25 ----A---- C:\Windows\system32\mshtmler.dll
2010-05-09 12:59:25 ----A---- C:\Windows\system32\mshtmled.dll
2010-05-09 12:59:25 ----A---- C:\Windows\system32\jsproxy.dll
2010-05-09 12:59:25 ----A---- C:\Windows\system32\ieui.dll
2010-05-09 12:59:25 ----A---- C:\Windows\system32\icardie.dll
2010-05-09 12:59:25 ----A---- C:\Windows\system32\admparse.dll
2010-05-09 12:59:24 ----A---- C:\Windows\system32\msls31.dll
2010-05-09 12:59:24 ----A---- C:\Windows\system32\imgutil.dll
2010-05-09 12:59:24 ----A---- C:\Windows\system32\iernonce.dll
2010-05-09 12:59:24 ----A---- C:\Windows\system32\ieakeng.dll
2010-05-09 12:59:24 ----A---- C:\Windows\system32\corpol.dll
2010-05-09 12:59:23 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-05-09 12:59:23 ----A---- C:\Windows\system32\licmgr10.dll
2010-05-09 12:59:23 ----A---- C:\Windows\system32\inseng.dll
2010-05-09 12:59:23 ----A---- C:\Windows\system32\iepeers.dll
2010-05-09 12:59:23 ----A---- C:\Windows\system32\dxtrans.dll
2010-05-09 12:59:23 ----A---- C:\Windows\system32\dxtmsft.dll
2010-05-09 12:59:22 ----A---- C:\Windows\system32\WinFXDocObj.exe
2010-05-09 12:59:22 ----A---- C:\Windows\system32\wextract.exe
2010-05-09 12:59:22 ----A---- C:\Windows\system32\webcheck.dll
2010-05-09 12:59:22 ----A---- C:\Windows\system32\occache.dll
2010-05-09 12:59:22 ----A---- C:\Windows\system32\msrating.dll
2010-05-09 12:59:22 ----A---- C:\Windows\system32\msfeedssync.exe
2010-05-09 12:59:22 ----A---- C:\Windows\system32\iesetup.dll
2010-05-09 12:59:22 ----A---- C:\Windows\system32\ieakui.dll
2010-05-09 12:59:22 ----A---- C:\Windows\system32\ieaksie.dll
2010-05-09 12:59:21 ----A---- C:\Windows\system32\pngfilt.dll
2010-05-09 12:59:21 ----A---- C:\Windows\system32\mstime.dll
2010-05-09 12:59:21 ----A---- C:\Windows\system32\msfeeds.dll
2010-05-09 12:59:21 ----A---- C:\Windows\system32\advpack.dll
2010-05-09 12:59:20 ----A---- C:\Windows\system32\vbscript.dll
2010-05-09 12:59:20 ----A---- C:\Windows\system32\jscript.dll
2010-05-09 12:59:20 ----A---- C:\Windows\system32\ieapfltr.dll
2010-05-09 12:59:19 ----A---- C:\Windows\system32\url.dll
2010-05-09 12:59:19 ----A---- C:\Windows\system32\iedkcs32.dll
2010-05-09 12:59:17 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2010-05-09 12:59:17 ----A---- C:\Windows\system32\SetDepNx.exe
2010-05-09 12:59:17 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2010-05-09 12:59:17 ----A---- C:\Windows\system32\PDMSetup.exe
2010-05-09 12:59:17 ----A---- C:\Windows\system32\mshta.exe
2010-05-09 12:59:17 ----A---- C:\Windows\system32\iexpress.exe
2010-05-09 12:59:17 ----A---- C:\Windows\system32\ieUnatt.exe
2010-05-09 12:59:17 ----A---- C:\Windows\system32\iesysprep.dll
2010-05-09 12:59:13 ----A---- C:\Windows\system32\iertutil.dll
2010-05-09 12:59:10 ----A---- C:\Windows\system32\ie4uinit.exe
2010-05-09 12:59:09 ----A---- C:\Windows\system32\wininet.dll
2010-05-09 12:59:08 ----A---- C:\Windows\system32\urlmon.dll
2010-05-09 12:59:07 ----A---- C:\Windows\system32\ieframe.dll
2010-05-09 12:59:06 ----A---- C:\Windows\system32\mshtml.dll
2010-05-07 20:19:47 ----A---- C:\ComboFix.txt
2010-05-07 20:18:51 ----SHD---- C:\$RECYCLE.BIN
2010-05-07 20:08:51 ----D---- C:\ComboFix
2010-05-07 20:08:16 ----A---- C:\Windows\SWXCACLS.exe
2010-05-07 19:43:28 ----A---- C:\Windows\zip.exe
2010-05-07 19:43:28 ----A---- C:\Windows\SWSC.exe
2010-05-07 19:43:28 ----A---- C:\Windows\SWREG.exe
2010-05-07 19:43:28 ----A---- C:\Windows\sed.exe
2010-05-07 19:43:28 ----A---- C:\Windows\PEV.exe
2010-05-07 19:43:28 ----A---- C:\Windows\NIRCMD.exe
2010-05-07 19:43:28 ----A---- C:\Windows\MBR.exe
2010-05-07 19:43:28 ----A---- C:\Windows\grep.exe
2010-05-07 19:43:22 ----D---- C:\Windows\ERDNT
2010-05-07 19:42:57 ----D---- C:\Qoobox
2010-05-07 19:16:06 ----D---- C:\rsit
2010-05-04 20:16:59 ----D---- C:\ProgramData\WindowsSearch
2010-05-04 19:02:18 ----D---- C:\Windows\system32\vi-VN
2010-05-04 19:02:18 ----D---- C:\Windows\system32\eu-ES
2010-05-04 19:02:18 ----D---- C:\Windows\system32\ca-ES
2010-05-04 18:57:14 ----D---- C:\Windows\system32\SPReview
2010-05-04 18:40:56 ----A---- C:\Windows\system32\scavenge.dll
2010-05-04 18:40:13 ----A---- C:\Windows\system32\compcln.exe
2010-05-04 18:26:34 ----A---- C:\Windows\system32\secur32.dll
2010-05-04 18:26:34 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2010-05-04 18:26:33 ----A---- C:\Windows\system32\secproc_ssp.dll
2010-05-04 18:26:33 ----A---- C:\Windows\system32\secproc_isv.dll
2010-05-04 18:26:33 ----A---- C:\Windows\system32\secproc.dll
2010-05-04 18:26:32 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2010-05-04 18:26:32 ----A---- C:\Windows\system32\SearchIndexer.exe
2010-05-04 18:26:32 ----A---- C:\Windows\system32\SearchFilterHost.exe
2010-05-04 18:26:32 ----A---- C:\Windows\system32\sdohlp.dll
2010-05-04 18:26:31 ----A---- C:\Windows\system32\sdclt.exe
2010-05-04 18:26:30 ----A---- C:\Windows\system32\rsaenh.dll
2010-05-04 18:26:29 ----A---- C:\Windows\system32\rtffilt.dll
2010-05-04 18:26:29 ----A---- C:\Windows\system32\rrinstaller.exe
2010-05-04 18:26:28 ----A---- C:\Windows\system32\samlib.dll
2010-05-04 18:26:28 ----A---- C:\Windows\system32\rtutils.dll
2010-05-04 18:26:28 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2010-05-04 18:26:28 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2010-05-04 18:26:28 ----A---- C:\Windows\system32\RMActivate_isv.exe
2010-05-04 18:26:27 ----A---- C:\Windows\system32\RMActivate.exe
2010-05-04 18:26:27 ----A---- C:\Windows\system32\riched20.dll
2010-05-04 18:26:26 ----A---- C:\Windows\system32\rpcss.dll
2010-05-04 18:26:26 ----A---- C:\Windows\system32\rpcrt4.dll
2010-05-04 18:26:26 ----A---- C:\Windows\system32\rpchttp.dll
2010-05-04 18:26:25 ----A---- C:\Windows\system32\scrrun.dll
2010-05-04 18:26:23 ----A---- C:\Windows\system32\SCardSvr.dll
2010-05-04 18:26:23 ----A---- C:\Windows\system32\scansetting.dll
2010-05-04 18:26:22 ----A---- C:\Windows\system32\samsrv.dll
2010-05-04 18:26:21 ----A---- C:\Windows\system32\scksp.dll
2010-05-04 18:26:21 ----A---- C:\Windows\system32\schedsvc.dll
2010-05-04 18:26:20 ----A---- C:\Windows\system32\scrobj.dll
2010-05-04 18:26:20 ----A---- C:\Windows\system32\scecli.dll
2010-05-04 18:26:18 ----A---- C:\Windows\system32\schannel.dll
2010-05-04 18:26:18 ----A---- C:\Windows\system32\scesrv.dll
2010-05-04 18:26:12 ----A---- C:\Windows\system32\pdh.dll
2010-05-04 18:26:11 ----A---- C:\Windows\system32\PerfCenterCPL.dll
2010-05-04 18:26:10 ----A---- C:\Windows\system32\perfdisk.dll
2010-05-04 18:26:10 ----A---- C:\Windows\system32\pcaui.dll
2010-05-04 18:26:10 ----A---- C:\Windows\system32\p2psvc.dll
2010-05-04 18:26:10 ----A---- C:\Windows\system32\P2PGraph.dll
2010-05-04 18:26:09 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2010-05-04 18:26:09 ----A---- C:\Windows\system32\PNPXAssoc.dll
2010-05-04 18:26:09 ----A---- C:\Windows\system32\PnPutil.exe
2010-05-04 18:26:09 ----A---- C:\Windows\system32\PnPUnattend.exe
2010-05-04 18:26:09 ----A---- C:\Windows\system32\pnpui.dll
2010-05-04 18:26:09 ----A---- C:\Windows\system32\pnpsetup.dll
2010-05-04 18:26:09 ----A---- C:\Windows\system32\pnidui.dll
2010-05-04 18:26:08 ----A---- C:\Windows\system32\powercpl.dll
2010-05-04 18:26:08 ----A---- C:\Windows\system32\PortableDeviceTypes.dll
2010-05-04 18:26:08 ----A---- C:\Windows\system32\PortableDeviceClassExtension.dll
2010-05-04 18:26:08 ----A---- C:\Windows\system32\pidgenx.dll
2010-05-04 18:26:08 ----A---- C:\Windows\system32\photowiz.dll
2010-05-04 18:26:07 ----A---- C:\Windows\system32\PkgMgr.exe
2010-05-04 18:26:07 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
2010-05-04 18:26:06 ----A---- C:\Windows\system32\ntkrnlpa.exe
2010-05-04 18:26:06 ----A---- C:\Windows\system32\ntdll.dll
2010-05-04 18:26:06 ----A---- C:\Windows\system32\nslookup.exe
2010-05-04 18:26:04 ----A---- C:\Windows\system32\offfilt.dll
2010-05-04 18:26:04 ----A---- C:\Windows\system32\NlsLexicons0009.dll
2010-05-04 18:26:04 ----A---- C:\Windows\system32\NlsLexicons0007.dll
2010-05-04 18:26:04 ----A---- C:\Windows\system32\nlhtml.dll
2010-05-04 18:26:03 ----A---- C:\Windows\system32\oleaut32.dll
2010-05-04 18:26:03 ----A---- C:\Windows\system32\ole32.dll
2010-05-04 18:26:03 ----A---- C:\Windows\system32\odbc32.dll
2010-05-04 18:26:02 ----A---- C:\Windows\system32\osk.exe
2010-05-04 18:26:02 ----A---- C:\Windows\system32\onex.dll
2010-05-04 18:26:02 ----A---- C:\Windows\system32\odbccp32.dll
2010-05-04 18:26:02 ----A---- C:\Windows\system32\odbcconf.dll
2010-05-04 18:26:01 ----A---- C:\Windows\system32\oobefldr.dll
2010-05-04 18:26:01 ----A---- C:\Windows\system32\olepro32.dll
2010-05-04 18:26:01 ----A---- C:\Windows\system32\oleprn.dll
2010-05-04 18:26:01 ----A---- C:\Windows\system32\ocsetup.exe
2010-05-04 18:26:00 ----A---- C:\Windows\system32\rasgcw.dll
2010-05-04 18:26:00 ----A---- C:\Windows\system32\rasdlg.dll
2010-05-04 18:26:00 ----A---- C:\Windows\system32\ntprint.dll
2010-05-04 18:26:00 ----A---- C:\Windows\system32\ntoskrnl.exe
2010-05-04 18:26:00 ----A---- C:\Windows\system32\ntmarta.dll
2010-05-04 18:25:59 ----A---- C:\Windows\system32\rastls.dll
2010-05-04 18:25:59 ----A---- C:\Windows\system32\rastapi.dll
2010-05-04 18:25:59 ----A---- C:\Windows\system32\rasppp.dll
2010-05-04 18:25:59 ----A---- C:\Windows\system32\rasplap.dll
2010-05-04 18:25:59 ----A---- C:\Windows\system32\rasmontr.dll
2010-05-04 18:25:59 ----A---- C:\Windows\system32\rasmans.dll
2010-05-04 18:25:59 ----A---- C:\Windows\system32\rasdial.exe
2010-05-04 18:25:59 ----A---- C:\Windows\system32\rasdiag.dll
2010-05-04 18:25:59 ----A---- C:\Windows\system32\raschap.dll
2010-05-04 18:25:59 ----A---- C:\Windows\system32\rasapi32.dll
2010-05-04 18:25:58 ----A---- C:\Windows\system32\RacEngn.dll
2010-05-04 18:25:58 ----A---- C:\Windows\system32\Query.dll
2010-05-04 18:25:58 ----A---- C:\Windows\system32\quartz.dll
2010-05-04 18:25:58 ----A---- C:\Windows\system32\qmgr.dll
2010-05-04 18:25:58 ----A---- C:\Windows\system32\qedit.dll
2010-05-04 18:25:57 ----A---- C:\Windows\system32\RelMon.dll
2010-05-04 18:25:57 ----A---- C:\Windows\system32\rekeywiz.exe
2010-05-04 18:25:57 ----A---- C:\Windows\system32\regsvc.dll
2010-05-04 18:25:56 ----A---- C:\Windows\system32\reg.exe
2010-05-04 18:25:56 ----A---- C:\Windows\system32\rdpencom.dll
2010-05-04 18:25:55 ----A---- C:\Windows\system32\regapi.dll
2010-05-04 18:25:55 ----A---- C:\Windows\system32\rdpwsx.dll
2010-05-04 18:25:54 ----A---- C:\Windows\system32\printui.dll
2010-05-04 18:25:54 ----A---- C:\Windows\system32\PresentationSettings.exe
2010-05-04 18:25:54 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
2010-05-04 18:25:54 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2010-05-04 18:25:54 ----A---- C:\Windows\system32\PresentationHost.exe
2010-05-04 18:25:53 ----A---- C:\Windows\system32\prnntfy.dll
2010-05-04 18:25:53 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
2010-05-04 18:25:53 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll
2010-05-04 18:25:53 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2010-05-04 18:25:53 ----A---- C:\Windows\system32\powrprof.dll
2010-05-04 18:25:51 ----A---- C:\Windows\system32\qdvd.dll
2010-05-04 18:25:51 ----A---- C:\Windows\system32\QAGENTRT.DLL
2010-05-04 18:25:51 ----A---- C:\Windows\system32\puiapi.dll
2010-05-04 18:25:50 ----A---- C:\Windows\system32\psisdecd.dll
2010-05-04 18:25:50 ----A---- C:\Windows\system32\PSHED.DLL
2010-05-04 18:25:50 ----A---- C:\Windows\system32\propsys.dll
2010-05-04 18:25:50 ----A---- C:\Windows\system32\propdefs.dll
2010-05-04 18:25:50 ----A---- C:\Windows\system32\profsvc.dll
2010-05-04 18:25:44 ----A---- C:\Windows\system32\sendmail.dll
2010-05-04 18:25:42 ----A---- C:\Windows\system32\shell32.dll
2010-05-04 18:25:41 ----A---- C:\Windows\system32\shlwapi.dll
2010-05-04 18:25:41 ----A---- C:\Windows\system32\shdocvw.dll
2010-05-04 18:25:40 ----A---- C:\Windows\system32\sethc.exe
2010-05-04 18:25:40 ----A---- C:\Windows\system32\services.exe
2010-05-04 18:25:39 ----A---- C:\Windows\system32\setupapi.dll
2010-05-04 18:25:29 ----A---- C:\Windows\system32\eapphost.dll
2010-05-04 18:25:29 ----A---- C:\Windows\system32\eappgnui.dll
2010-05-04 18:25:28 ----A---- C:\Windows\system32\EhStorAPI.dll
2010-05-04 18:25:28 ----A---- C:\Windows\system32\eappcfg.dll
2010-05-04 18:25:28 ----A---- C:\Windows\system32\eapp3hst.dll
2010-05-04 18:25:27 ----A---- C:\Windows\system32\dsprop.dll
2010-05-04 18:25:26 ----A---- C:\Windows\system32\evr.dll
2010-05-04 18:25:26 ----A---- C:\Windows\system32\eudcedit.exe
2010-05-04 18:25:26 ----A---- C:\Windows\system32\dxmasf.dll
2010-05-04 18:25:26 ----A---- C:\Windows\system32\dwm.exe
2010-05-04 18:25:26 ----A---- C:\Windows\system32\dsound.dll
2010-05-04 18:25:25 ----A---- C:\Windows\system32\f3ahvoas.dll
2010-05-04 18:25:25 ----A---- C:\Windows\system32\ExplorerFrame.dll
2010-05-04 18:25:25 ----A---- C:\Windows\system32\esent.dll
2010-05-04 18:25:25 ----A---- C:\Windows\explorer.exe
2010-05-04 18:25:24 ----A---- C:\Windows\system32\EncDec.dll
2010-05-04 18:25:24 ----A---- C:\Windows\system32\emdmgmt.dll
2010-05-04 18:25:24 ----A---- C:\Windows\system32\EhStorPwdMgr.dll
2010-05-04 18:25:24 ----A---- C:\Windows\system32\EhStorAuthn.dll
2010-05-04 18:25:23 ----A---- C:\Windows\system32\es.dll
2010-05-04 18:25:23 ----A---- C:\Windows\system32\EhStorShell.dll
2010-05-04 18:25:23 ----A---- C:\Windows\system32\diagperf.dll
2010-05-04 18:25:22 ----A---- C:\Windows\system32\dimsroam.dll
2010-05-04 18:25:22 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2010-05-04 18:25:21 ----A---- C:\Windows\system32\diskraid.exe
2010-05-04 18:25:21 ----A---- C:\Windows\system32\diskpart.exe
2010-05-04 18:25:20 ----A---- C:\Windows\system32\dfsr.exe
2010-05-04 18:25:20 ----A---- C:\Windows\system32\dfshim.dll
2010-05-04 18:25:20 ----A---- C:\Windows\system32\devmgr.dll
2010-05-04 18:25:18 ----A---- C:\Windows\system32\dhcpcsvc.dll
2010-05-04 18:25:17 ----A---- C:\Windows\system32\drvstore.dll
2010-05-04 18:25:17 ----A---- C:\Windows\system32\dpapimig.exe
2010-05-04 18:25:17 ----A---- C:\Windows\system32\dot3svc.dll
2010-05-04 18:25:17 ----A---- C:\Windows\system32\dot3msm.dll
2010-05-04 18:25:17 ----A---- C:\Windows\system32\dot3cfg.dll
2010-05-04 18:25:16 ----A---- C:\Windows\system32\drmmgrtn.dll
2010-05-04 18:25:15 ----A---- C:\Windows\system32\drvinst.exe
2010-05-04 18:25:15 ----A---- C:\Windows\system32\drmv2clt.dll
2010-05-04 18:25:14 ----A---- C:\Windows\system32\dnsrslvr.dll
2010-05-04 18:25:14 ----A---- C:\Windows\system32\dnsapi.dll
2010-05-04 18:25:14 ----A---- C:\Windows\system32\dmusic.dll
2010-05-04 18:25:14 ----A---- C:\Windows\system32\dmsynth.dll
2010-05-04 18:25:13 ----A---- C:\Windows\system32\hbaapi.dll
2010-05-04 18:25:11 ----A---- C:\Windows\system32\gpresult.exe
2010-05-04 18:25:09 ----A---- C:\Windows\system32\iasads.dll
2010-05-04 18:25:09 ----A---- C:\Windows\system32\gpupdate.exe
2010-05-04 18:25:09 ----A---- C:\Windows\system32\gpsvc.dll
2010-05-04 18:25:08 ----A---- C:\Windows\system32\iashlpr.dll
2010-05-04 18:25:08 ----A---- C:\Windows\system32\iasdatastore.dll
2010-05-04 18:25:08 ----A---- C:\Windows\system32\iasacct.dll
2010-05-04 18:25:06 ----A---- C:\Windows\system32\iasnap.dll
2010-05-04 18:25:06 ----A---- C:\Windows\system32\IasMigReader.exe
2010-05-04 18:25:06 ----A---- C:\Windows\system32\IasMigPlugin.dll
2010-05-04 18:25:05 ----A---- C:\Windows\system32\hidserv.dll
2010-05-04 18:25:05 ----A---- C:\Windows\system32\hdwwiz.exe
2010-05-04 18:25:04 ----A---- C:\Windows\system32\fontext.dll
2010-05-04 18:25:04 ----A---- C:\Windows\system32\findstr.exe
2010-05-04 18:25:04 ----A---- C:\Windows\system32\Faultrep.dll
2010-05-04 18:25:03 ----A---- C:\Windows\system32\fc.exe
2010-05-04 18:25:02 ----A---- C:\Windows\system32\feclient.dll
2010-05-04 18:25:02 ----A---- C:\Windows\system32\fdWSD.dll
2010-05-04 18:25:02 ----A---- C:\Windows\system32\fdWCN.dll
2010-05-04 18:25:02 ----A---- C:\Windows\system32\fdSSDP.dll
2010-05-04 18:25:01 ----A---- C:\Windows\system32\fdProxy.dll
2010-05-04 18:25:01 ----A---- C:\Windows\system32\fdeploy.dll
2010-05-04 18:25:01 ----A---- C:\Windows\system32\fdBthProxy.dll
2010-05-04 18:25:01 ----A---- C:\Windows\system32\fdBth.dll
2010-05-04 18:25:00 ----A---- C:\Windows\system32\gpapi.dll
2010-05-04 18:25:00 ----A---- C:\Windows\system32\gdi32.dll
2010-05-04 18:24:59 ----A---- C:\Windows\system32\gpedit.dll
2010-05-04 18:24:58 ----A---- C:\Windows\system32\fundisc.dll
2010-05-04 18:24:57 ----A---- C:\Windows\system32\ftp.exe
2010-05-04 18:24:57 ----A---- C:\Windows\system32\fsquirt.exe
2010-05-04 18:24:56 ----A---- C:\Windows\system32\FwRemoteSvr.dll
2010-05-04 18:24:56 ----A---- C:\Windows\system32\FunctionDiscoveryFolder.dll
2010-05-04 18:24:55 ----A---- C:\Windows\system32\gameux.dll
2010-05-04 18:24:55 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2010-05-04 18:24:54 ----A---- C:\Windows\system32\authui.dll
2010-05-04 18:24:54 ----A---- C:\Windows\system32\audiosrv.dll
2010-05-04 18:24:54 ----A---- C:\Windows\system32\AudioSes.dll
2010-05-04 18:24:53 ----A---- C:\Windows\system32\autochk.exe
2010-05-04 18:24:53 ----A---- C:\Windows\system32\authz.dll
2010-05-04 18:24:53 ----A---- C:\Windows\system32\audiodg.exe
2010-05-04 18:24:53 ----A---- C:\Windows\system32\atmfd.dll
2010-05-04 18:24:52 ----A---- C:\Windows\system32\AuxiliaryDisplayServices.dll
2010-05-04 18:24:52 ----A---- C:\Windows\system32\AuxiliaryDisplayDriverLib.dll
2010-05-04 18:24:52 ----A---- C:\Windows\system32\atmlib.dll
2010-05-04 18:24:51 ----A---- C:\Windows\system32\autofmt.exe
2010-05-04 18:24:51 ----A---- C:\Windows\system32\autoconv.exe
2010-05-04 18:24:50 ----A---- C:\Windows\system32\AuxiliaryDisplayCpl.dll
2010-05-04 18:24:50 ----A---- C:\Windows\system32\autoplay.dll
2010-05-04 18:24:46 ----A---- C:\Windows\system32\brcpl.dll
2010-05-04 18:24:44 ----A---- C:\Windows\system32\bthci.dll
2010-05-04 18:24:44 ----A---- C:\Windows\system32\browseui.dll
2010-05-04 18:24:42 ----A---- C:\Windows\system32\basecsp.dll
2010-05-04 18:24:41 ----A---- C:\Windows\system32\azroles.dll
2010-05-04 18:24:40 ----A---- C:\Windows\system32\blackbox.dll
2010-05-04 18:24:40 ----A---- C:\Windows\system32\bitsigd.dll
2010-05-04 18:24:40 ----A---- C:\Windows\system32\bcrypt.dll
2010-05-04 18:24:39 ----A---- C:\Windows\system32\BFE.DLL
2010-05-04 18:24:36 ----A---- C:\Windows\system32\accessibilitycpl.dll
2010-05-04 18:24:34 ----A---- C:\Windows\system32\aaclient.dll
2010-05-04 18:24:33 ----A---- C:\Windows\system32\apphelp.dll
2010-05-04 18:24:32 ----A---- C:\Windows\system32\Apphlpdm.dll
2010-05-04 18:24:31 ----A---- C:\Windows\system32\apds.dll
2010-05-04 18:24:30 ----A---- C:\Windows\system32\adsmsext.dll
2010-05-04 18:24:30 ----A---- C:\Windows\system32\adsldpc.dll
2010-05-04 18:24:29 ----A---- C:\Windows\system32\adtschema.dll
2010-05-04 18:24:28 ----A---- C:\Windows\system32\conime.exe
2010-05-04 18:24:28 ----A---- C:\Windows\system32\comuid.dll
2010-05-04 18:24:28 ----A---- C:\Windows\system32\comsvcs.dll
2010-05-04 18:24:28 ----A---- C:\Windows\system32\advapi32.dll
2010-05-04 18:24:27 ----A---- C:\Windows\system32\crypt32.dll
2010-05-04 18:24:27 ----A---- C:\Windows\system32\credui.dll
2010-05-04 18:24:26 ----A---- C:\Windows\system32\connect.dll
2010-05-04 18:24:26 ----A---- C:\Windows\system32\cmdial32.dll
2010-05-04 18:24:25 ----A---- C:\Windows\system32\comdlg32.dll
2010-05-04 18:24:24 ----A---- C:\Windows\system32\dbgeng.dll
2010-05-04 18:24:24 ----A---- C:\Windows\system32\cmmon32.exe
2010-05-04 18:24:23 ----A---- C:\Windows\system32\davclnt.dll
2010-05-04 18:24:23 ----A---- C:\Windows\system32\dataclen.dll
2010-05-04 18:24:23 ----A---- C:\Windows\system32\d3d9.dll
2010-05-04 18:24:22 ----A---- C:\Windows\system32\DevicePairingWizard.exe
2010-05-04 18:24:22 ----A---- C:\Windows\system32\DevicePairingProxy.dll
2010-05-04 18:24:22 ----A---- C:\Windows\system32\DevicePairing.dll
2010-05-04 18:24:22 ----A---- C:\Windows\system32\DeviceEject.exe
2010-05-04 18:24:21 ----A---- C:\Windows\system32\cscdll.dll
2010-05-04 18:24:21 ----A---- C:\Windows\system32\cscapi.dll
2010-05-04 18:24:21 ----A---- C:\Windows\system32\cryptui.dll
2010-05-04 18:24:21 ----A---- C:\Windows\system32\cryptsvc.dll
2010-05-04 18:24:20 ----A---- C:\Windows\system32\csrstub.exe
2010-05-04 18:24:20 ----A---- C:\Windows\system32\cscript.exe
2010-05-04 18:24:19 ----A---- C:\Windows\system32\cdd.dll
2010-05-04 18:24:18 ----A---- C:\Windows\system32\certmgr.dll
2010-05-04 18:24:18 ----A---- C:\Windows\system32\certcli.dll
2010-05-04 18:24:17 ----A---- C:\Windows\system32\CertEnrollUI.dll
2010-05-04 18:24:17 ----A---- C:\Windows\system32\CertEnroll.dll
2010-05-04 18:24:17 ----A---- C:\Windows\system32\bthudtask.exe
2010-05-04 18:24:17 ----A---- C:\Windows\system32\bthserv.dll
2010-05-04 18:24:16 ----A---- C:\Windows\system32\cbsra.exe
2010-05-04 18:24:15 ----A---- C:\Windows\system32\cipher.exe
2010-05-04 18:24:15 ----A---- C:\Windows\system32\ci.dll
2010-05-04 18:24:14 ----A---- C:\Windows\system32\CHxReadingStringIME.dll
2010-05-04 18:24:14 ----A---- C:\Windows\system32\chtbrkr.dll
2010-05-04 18:24:14 ----A---- C:\Windows\system32\chsbrkr.dll
2010-05-04 18:24:13 ----A---- C:\Windows\system32\certreq.exe
2010-05-04 18:24:13 ----A---- C:\Windows\system32\certprop.dll
2010-05-04 18:24:12 ----A---- C:\Windows\system32\msftedit.dll
2010-05-04 18:24:12 ----A---- C:\Windows\system32\certutil.exe
2010-05-04 18:24:11 ----A---- C:\Windows\system32\msihnd.dll
2010-05-04 18:24:11 ----A---- C:\Windows\system32\msiexec.exe
2010-05-04 18:24:11 ----A---- C:\Windows\system32\msexcl40.dll
2010-05-04 18:24:11 ----A---- C:\Windows\system32\msexch40.dll
2010-05-04 18:24:11 ----A---- C:\Windows\system32\msdtctm.dll
2010-05-04 18:24:09 ----A---- C:\Windows\system32\msi.dll
2010-05-04 18:24:07 ----A---- C:\Windows\system32\msdrm.dll
2010-05-04 18:24:06 ----A---- C:\Windows\system32\msdtcprx.dll
2010-05-04 18:24:06 ----A---- C:\Windows\system32\msctfui.dll
2010-05-04 18:24:06 ----A---- C:\Windows\system32\msctfp.dll
2010-05-04 18:24:06 ----A---- C:\Windows\system32\MsCtfMonitor.dll
2010-05-04 18:24:06 ----A---- C:\Windows\system32\msctf.dll
2010-05-04 18:24:04 ----A---- C:\Windows\system32\msimsg.dll
2010-05-04 18:24:03 ----A---- C:\Windows\system32\MPSSVC.dll
2010-05-04 18:24:02 ----A---- C:\Windows\system32\mprapi.dll
2010-05-04 18:24:02 ----A---- C:\Windows\system32\mpr.dll
2010-05-04 18:24:00 ----A---- C:\Windows\system32\modemui.dll
2010-05-04 18:24:00 ----A---- C:\Windows\system32\MMDevAPI.dll
2010-05-04 18:23:58 ----A---- C:\Windows\system32\mscandui.dll
2010-05-04 18:23:57 ----A---- C:\Windows\system32\mscms.dll
2010-05-04 18:23:56 ----A---- C:\Windows\system32\mscories.dll
2010-05-04 18:23:56 ----A---- C:\Windows\system32\mscorier.dll
2010-05-04 18:23:55 ----A---- C:\Windows\system32\mscoree.dll
2010-05-04 18:23:54 ----A---- C:\Windows\system32\netapi32.dll
2010-05-04 18:23:53 ----A---- C:\Windows\system32\netplwiz.dll
2010-05-04 18:23:53 ----A---- C:\Windows\system32\netcenter.dll
2010-05-04 18:23:53 ----A---- C:\Windows\system32\ncryptui.dll
2010-05-04 18:23:53 ----A---- C:\Windows\system32\ncrypt.dll
2010-05-04 18:23:52 ----A---- C:\Windows\system32\NetProjW.dll
2010-05-04 18:23:51 ----A---- C:\Windows\system32\netlogon.dll
2010-05-04 18:23:51 ----A---- C:\Windows\system32\netiohlp.dll
2010-05-04 18:23:51 ----A---- C:\Windows\system32\mtxclu.dll
2010-05-04 18:23:48 ----A---- C:\Windows\system32\msxml6.dll
2010-05-04 18:23:47 ----A---- C:\Windows\system32\NcdProp.dll
2010-05-04 18:23:47 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2010-05-04 18:23:47 ----A---- C:\Windows\system32\msxml3.dll
2010-05-04 18:23:44 ----A---- C:\Windows\system32\newdev.exe
2010-05-04 18:23:44 ----A---- C:\Windows\system32\newdev.dll
2010-05-04 18:23:44 ----A---- C:\Windows\system32\netshell.dll
2010-05-04 18:23:43 ----A---- C:\Windows\system32\networkmap.dll
2010-05-04 18:23:43 ----A---- C:\Windows\system32\networkitemfactory.dll
2010-05-04 18:23:43 ----A---- C:\Windows\system32\networkexplorer.dll
2010-05-04 18:23:42 ----A---- C:\Windows\system32\msnetobj.dll
2010-05-04 18:23:42 ----A---- C:\Windows\system32\msltus40.dll
2010-05-04 18:23:41 ----A---- C:\Windows\system32\msscntrs.dll
2010-05-04 18:23:41 ----A---- C:\Windows\system32\msscb.dll
2010-05-04 18:23:41 ----A---- C:\Windows\system32\msrepl40.dll
2010-05-04 18:23:41 ----A---- C:\Windows\system32\msrd3x40.dll
2010-05-04 18:23:41 ----A---- C:\Windows\system32\mspbde40.dll
2010-05-04 18:23:41 ----A---- C:\Windows\system32\MSMPEG2VDEC.DLL
2010-05-04 18:23:40 ----A---- C:\Windows\system32\msrd2x40.dll
2010-05-04 18:23:40 ----A---- C:\Windows\system32\msinfo32.exe
2010-05-04 18:23:40 ----A---- C:\Windows\system32\msimtf.dll
2010-05-04 18:23:39 ----A---- C:\Windows\system32\msjtes40.dll
2010-05-04 18:23:39 ----A---- C:\Windows\system32\msjter40.dll
2010-05-04 18:23:39 ----A---- C:\Windows\system32\msjint40.dll
2010-05-04 18:23:39 ----A---- C:\Windows\system32\msjetoledb40.dll
2010-05-04 18:23:39 ----A---- C:\Windows\system32\msjet40.dll
2010-05-04 18:23:39 ----A---- C:\Windows\system32\msisip.dll
2010-05-04 18:23:38 ----A---- C:\Windows\system32\msvcp60.dll
2010-05-04 18:23:38 ----A---- C:\Windows\system32\msv1_0.dll
2010-05-04 18:23:38 ----A---- C:\Windows\system32\msutb.dll
2010-05-04 18:23:38 ----A---- C:\Windows\system32\mstscax.dll
2010-05-04 18:23:37 ----A---- C:\Windows\system32\msxbde40.dll
2010-05-04 18:23:37 ----A---- C:\Windows\system32\mswstr10.dll
2010-05-04 18:23:37 ----A---- C:\Windows\system32\mswsock.dll
2010-05-04 18:23:37 ----A---- C:\Windows\system32\mswdat10.dll
2010-05-04 18:23:37 ----A---- C:\Windows\system32\msvcrt.dll
2010-05-04 18:23:36 ----A---- C:\Windows\system32\MSVidCtl.dll
2010-05-04 18:23:36 ----A---- C:\Windows\system32\mssphtb.dll
2010-05-04 18:23:36 ----A---- C:\Windows\system32\mssph.dll
2010-05-04 18:23:35 ----A---- C:\Windows\system32\mssrch.dll
2010-05-04 18:23:35 ----A---- C:\Windows\system32\mssprxy.dll
2010-05-04 18:23:35 ----A---- C:\Windows\system32\mssitlb.dll
2010-05-04 18:23:35 ----A---- C:\Windows\system32\msshooks.dll
2010-05-04 18:23:35 ----A---- C:\Windows\system32\msscp.dll
2010-05-04 18:23:34 ----A---- C:\Windows\system32\mstsc.exe
2010-05-04 18:23:34 ----A---- C:\Windows\system32\mstlsapi.dll
2010-05-04 18:23:34 ----A---- C:\Windows\system32\mstext40.dll