Instaloval jsemSP3 SAS našel 3Trojany Agent a smazal je aktualizoval jsem prošlý Avast
Log posílám na dvakrát
Logfile of random's system information tool 1.06 (written by random/random)
Run by vf at 2009-06-23 20:00:07
Systém Microsoft Windows XP Professional Service Pack 3
System drive D: has 4 GB (45%) free of 10 GB
Total RAM: 287 MB (42% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:00:36, on 23.6.2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
E:\avast\aswUpdSv.exe
E:\avast\ashServ.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
E:\avast\ashDisp.exe
D:\Program Files\Postak\Postak.exe
D:\WINDOWS\system32\rundll32.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\IncrediMail\bin\IMApp.exe
D:\Program Files\IncrediMail\bin\ImNotfy.exe
D:\Program Files\IncrediMail\bin\IncMail.exe
D:\Program Files\Opera\Opera.exe
D:\Documents and Settings\vf.VF-D5864C983A5F\Plocha\RSIT.exe
d:\Program Files\trend micro\vf.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.sznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - D:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O2 - BHO: (no name) - {0eceeac0-8a08-11d4-a521-0020af300fc7} - (no file)
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - D:\WINDOWS\WebIE.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - E:\office\Office12\GRA8E1~1.DLL
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - E:\Free Download Manager\iefdm2.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &S-Rank - {B71B15CF-3093-459C-B764-AEB2486F2273} - D:\Program Files\Postak\SRank.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - D:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - D:\WINDOWS\WebIE.dll
O4 - HKLM\..\Run: [avast!] E:\avast\ashDisp.exe
O4 - HKLM\..\Run: [SMail] "D:\Program Files\Postak\Postak.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKCU\..\Run: [IncrediMail] D:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Eraser] D:\Program Files\Eraser\eraser.exe -hide
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Obsah aplikace OneNote.onetoc2
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://E:\office\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Stáhnout Free Download Managerem - file://E:\Free Download Manager\dllink.htm
O8 - Extra context menu item: Stáhnout video Free Download Managerem - file://E:\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Stáhnout vybrané Free Download Managerem - file://E:\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Stáhnout vše Free Download Managerem - file://E:\Free Download Manager\dlall.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\office\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\office\Office12\ONBttnIE.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - D:\WINDOWS\WebIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\office\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - D:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - D:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - D:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - D:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - D:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - D:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - D:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - D:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - E:\office\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - E:\avast\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - E:\avast\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - E:\avast\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - E:\avast\ashWebSv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - E:\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - D:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - D:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - D:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
--
End of file - 6803 bytes
======Scheduled tasks folder======
D:\WINDOWS\tasks\RegCure Program Check.job
D:\WINDOWS\tasks\RegCure.job
D:\WINDOWS\tasks\WGASetup.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0eceeac0-8a08-11d4-a521-0020af300fc7}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - D:\WINDOWS\WebIE.dll [2009-05-28 491520]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - E:\office\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}]
FDMIECookiesBHO Class - E:\Free Download Manager\iefdm2.dll [2008-12-30 98304]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - D:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-03-09 35840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-03-09 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{B71B15CF-3093-459C-B764-AEB2486F2273} - &S-Rank - D:\Program Files\Postak\SRank.dll [2007-05-16 269632]
{855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQToolBar - D:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2008-12-09 958200]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - D:\WINDOWS\WebIE.dll [2009-05-28 491520]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast!"=E:\avast\ashDisp.exe [2009-02-05 81000]
"SMail"=D:\Program Files\Postak\Postak.exe [2008-02-21 453936]
"BluetoothAuthenticationAgent"=bthprops.cpl,,BluetoothAuthenticationAgent []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"IncrediMail"=D:\Program Files\IncrediMail\bin\IncMail.exe [2009-06-07 251264]
"ctfmon.exe"=D:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Eraser"=D:\Program Files\Eraser\eraser.exe [2006-12-26 643072]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
E:\Reader\Reader_sl.exe [2008-01-11 39792]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
D:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-06-27 152872]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
D:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eraser]
D:\Program Files\Eraser\eraser.exe [2006-12-26 643072]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Free Download Manager]
E:\Free Download Manager\fdm.exe [2009-01-31 3399727]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NetChat]
D:\DOCUME~1\VFD41D~1.VF-\LOCALS~1\Temp\_tc0\NetChat.exe * []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OEXPRESS]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
D:\Program Files\Java\jre6\bin\jusched.exe [2009-03-09 148888]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{0228e555-4f9c-4e35-a3ec-b109a192b4c2}]
D:\Program Files\Google\Gmail Notifier\gnotify.exe []
D:\Documents and Settings\vf.VF-D5864C983A5F\Nabídka Start\Programy\Po spuštění
Obsah aplikace OneNote.onetoc2
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
D:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2008-12-22 356352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
D:\WINDOWS\system32\WgaLogon.dll [2008-09-06 267304]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{DAE0285D-0788-4E87-985E-01DF2EDE4ACD}"=D:\WINDOWS\system32\Wshxt.dll [2009-02-03 53248]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=E:\office\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=
scecli
scecli
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"E:\office\Office12\OUTLOOK.EXE"="E:\office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"E:\office\Office12\GROOVE.EXE"="E:\office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"E:\office\Office12\ONENOTE.EXE"="E:\office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"D:\Program Files\IncrediMail\bin\ImApp.exe"="D:\Program Files\IncrediMail\bin\ImApp.exe:*:Enabled:IncrediMail"
"D:\Program Files\IncrediMail\bin\IncMail.exe"="D:\Program Files\IncrediMail\bin\IncMail.exe:*:Enabled:IncrediMail"
"D:\Program Files\IncrediMail\bin\ImpCnt.exe"="D:\Program Files\IncrediMail\bin\ImpCnt.exe:*:Enabled:IncrediMail"
"D:\Program Files\Opera\opera.exe"="D:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
======List of files/folders created in the last 1 months======
2009-06-23 20:00:07 ----D---- D:\rsit
2009-06-23 18:24:21 ----A---- D:\WINDOWS\OEWABLog.txt
2009-06-23 18:24:15 ----HD---- D:\Program Files\Uninstall Information
2009-06-23 18:18:51 ----D---- D:\WINDOWS\Prefetch
2009-06-23 18:12:05 ----HDC---- D:\WINDOWS\$NtUninstallKB954211$
2009-06-23 18:09:32 ----HDC---- D:\WINDOWS\$NtUninstallKB952954$
2009-06-23 18:06:31 ----HDC---- D:\WINDOWS\$NtUninstallKB952287$
2009-06-23 18:03:04 ----HDC---- D:\WINDOWS\$NtUninstallKB952004$
2009-06-23 17:59:18 ----HDC---- D:\WINDOWS\$NtUninstallKB951748$
2009-06-23 17:55:01 ----HDC---- D:\WINDOWS\$NtUninstallKB951698$
2009-06-23 17:51:27 ----HDC---- D:\WINDOWS\$NtUninstallKB951376-v2$
2009-06-23 17:48:04 ----HDC---- D:\WINDOWS\$NtUninstallKB951066$
2009-06-23 17:44:58 ----HDC---- D:\WINDOWS\$NtUninstallKB950974$
2009-06-23 17:41:39 ----HDC---- D:\WINDOWS\$NtUninstallKB950762$
2009-06-23 17:37:59 ----HDC---- D:\WINDOWS\$NtUninstallKB946648$
2009-06-23 17:34:18 ----HDC---- D:\WINDOWS\$NtUninstallKB938464$
2009-06-23 17:26:38 ----HDC---- D:\WINDOWS\$NtUninstallKB923561$
2009-06-23 17:16:47 ----A---- D:\WINDOWS\setuplog.txt
2009-06-23 17:13:41 ----N---- D:\WINDOWS\system32\smtpapi.dll
2009-06-23 17:13:41 ----N---- D:\WINDOWS\system32\rwnh.dll
2009-06-23 17:13:41 ----N---- D:\WINDOWS\system32\comsdupd.exe
2009-06-23 17:13:35 ----N---- D:\WINDOWS\system32\aaclient.dll
2009-06-23 17:13:34 ----N---- D:\WINDOWS\system32\ati3d1ag.dll
2009-06-23 17:13:34 ----N---- D:\WINDOWS\system32\ati2dvag.dll
2009-06-23 17:13:34 ----N---- D:\WINDOWS\system32\ati2dvaa.dll
2009-06-23 17:13:34 ----N---- D:\WINDOWS\system32\ati2cqag.dll
2009-06-23 17:13:33 ----N---- D:\WINDOWS\system32\bitsprx4.dll
2009-06-23 17:13:33 ----N---- D:\WINDOWS\system32\azroles.dll
2009-06-23 17:13:33 ----N---- D:\WINDOWS\system32\ativvaxx.dll
2009-06-23 17:13:33 ----N---- D:\WINDOWS\system32\ativtmxx.dll
2009-06-23 17:13:33 ----N---- D:\WINDOWS\system32\ati3duag.dll
2009-06-23 17:13:32 ----N---- D:\WINDOWS\system32\credssp.dll
2009-06-23 17:13:31 ----N---- D:\WINDOWS\system32\dot3ui.dll
2009-06-23 17:13:31 ----N---- D:\WINDOWS\system32\dot3svc.dll
2009-06-23 17:13:31 ----N---- D:\WINDOWS\system32\dot3msm.dll
2009-06-23 17:13:31 ----N---- D:\WINDOWS\system32\dot3gpclnt.dll
2009-06-23 17:13:31 ----N---- D:\WINDOWS\system32\dot3dlg.dll
2009-06-23 17:13:31 ----N---- D:\WINDOWS\system32\dot3cfg.dll
2009-06-23 17:13:31 ----N---- D:\WINDOWS\system32\dot3api.dll
2009-06-23 17:13:31 ----N---- D:\WINDOWS\system32\dimsroam.dll
2009-06-23 17:13:31 ----N---- D:\WINDOWS\system32\dimsntfy.dll
2009-06-23 17:13:31 ----N---- D:\WINDOWS\system32\dhcpqec.dll
2009-06-23 17:13:30 ----N---- D:\WINDOWS\system32\eappprxy.dll
2009-06-23 17:13:30 ----N---- D:\WINDOWS\system32\eapphost.dll
2009-06-23 17:13:30 ----N---- D:\WINDOWS\system32\eappgnui.dll
2009-06-23 17:13:30 ----N---- D:\WINDOWS\system32\eappcfg.dll
2009-06-23 17:13:30 ----N---- D:\WINDOWS\system32\eapp3hst.dll
2009-06-23 17:13:30 ----N---- D:\WINDOWS\system32\eapolqec.dll
2009-06-23 17:13:29 ----N---- D:\WINDOWS\system32\eapsvc.dll
2009-06-23 17:13:29 ----N---- D:\WINDOWS\system32\eapqec.dll
2009-06-23 17:13:28 ----N---- D:\WINDOWS\system32\hsfcisp2.dll
2009-06-23 17:13:28 ----N---- D:\WINDOWS\system32\hccoin.dll
2009-06-23 17:13:26 ----N---- D:\WINDOWS\system32\kbdiultn.dll
2009-06-23 17:13:26 ----N---- D:\WINDOWS\system32\kbdbhc.dll
2009-06-23 17:13:25 ----N---- D:\WINDOWS\system32\kmsvc.dll
2009-06-23 17:13:25 ----N---- D:\WINDOWS\system32\kbdpash.dll
2009-06-23 17:13:25 ----N---- D:\WINDOWS\system32\kbdnepr.dll
2009-06-23 17:13:24 ----N---- D:\WINDOWS\system32\microsoft.managementconsole.dll
2009-06-23 17:13:24 ----N---- D:\WINDOWS\system32\mdmxsdk.dll
2009-06-23 17:13:24 ----N---- D:\WINDOWS\system32\l2gpstore.dll
2009-06-23 17:13:23 ----N---- D:\WINDOWS\system32\mmcperf.exe
2009-06-23 17:13:23 ----N---- D:\WINDOWS\system32\mmcfxcommon.dll
2009-06-23 17:13:23 ----N---- D:\WINDOWS\system32\mmcex.dll
2009-06-23 17:13:22 ----N---- D:\WINDOWS\system32\napmontr.dll
2009-06-23 17:13:22 ----N---- D:\WINDOWS\system32\napipsec.dll
2009-06-23 17:13:22 ----N---- D:\WINDOWS\system32\mtxparhd.dll
2009-06-23 17:13:22 ----N---- D:\WINDOWS\system32\msshavmsg.dll
2009-06-23 17:13:22 ----N---- D:\WINDOWS\system32\mssha.dll
2009-06-23 17:13:21 ----N---- D:\WINDOWS\system32\napstat.exe
2009-06-23 17:13:20 ----N---- D:\WINDOWS\system32\onex.dll
2009-06-23 17:13:20 ----N---- D:\WINDOWS\system32\nv4_disp.dll
2009-06-23 17:13:18 ----N---- D:\WINDOWS\system32\rasqec.dll
2009-06-23 17:13:18 ----N---- D:\WINDOWS\system32\qutil.dll
2009-06-23 17:13:18 ----N---- D:\WINDOWS\system32\qcliprov.dll
2009-06-23 17:13:18 ----N---- D:\WINDOWS\system32\qagentrt.dll
2009-06-23 17:13:18 ----N---- D:\WINDOWS\system32\qagent.dll
2009-06-23 17:13:17 ----N---- D:\WINDOWS\system32\slcoinst.dll
2009-06-23 17:13:17 ----N---- D:\WINDOWS\system32\setupn.exe
2009-06-23 17:13:17 ----N---- D:\WINDOWS\system32\s3gnb.dll
2009-06-23 17:13:17 ----N---- D:\WINDOWS\system32\rhttpaa.dll
2009-06-23 17:13:16 ----N---- D:\WINDOWS\system32\slserv.exe
2009-06-23 17:13:16 ----N---- D:\WINDOWS\system32\slrundll.exe
2009-06-23 17:13:16 ----N---- D:\WINDOWS\system32\slgen.dll
2009-06-23 17:13:16 ----N---- D:\WINDOWS\system32\slextspk.dll
2009-06-23 17:13:12 ----N---- D:\WINDOWS\system32\verclsid.exe
2009-06-23 17:13:12 ----N---- D:\WINDOWS\system32\tspkg.dll
2009-06-23 17:13:12 ----N---- D:\WINDOWS\system32\tsgqec.dll
2009-06-23 17:13:10 ----N---- D:\WINDOWS\system32\wlanapi.dll
2009-06-23 17:13:07 ----N---- D:\WINDOWS\system32\xmllite.dll
2009-06-23 17:13:07 ----N---- D:\WINDOWS\slrundll.exe
2009-06-23 17:08:06 ----D---- D:\WINDOWS\ServicePackFiles
2009-06-23 16:56:17 ----A---- D:\WINDOWS\002731_.tmp
2009-06-23 10:13:05 ----D---- D:\WINDOWS\l2schemas
2009-06-23 10:13:04 ----D---- D:\WINDOWS\system32\cs
2009-06-23 10:13:03 ----D---- D:\WINDOWS\system32\bits
2009-06-23 10:03:17 ----D---- D:\WINDOWS\network diagnostic
2009-06-23 09:58:49 ----D---- D:\WINDOWS\system32\ReinstallBackups
2009-06-23 09:56:00 ----A---- D:\WINDOWS\system32\msxml6r.dll
2009-06-23 09:55:57 ----A---- D:\WINDOWS\system32\wmpdxm.dll
2009-06-23 09:55:57 ----A---- D:\WINDOWS\system32\wmpasf.dll
2009-06-23 09:55:56 ----A---- D:\WINDOWS\system32\wmp.dll
2009-06-23 09:55:56 ----A---- D:\WINDOWS\system32\wmerror.dll
2009-06-23 09:55:55 ----A---- D:\WINDOWS\system32\mp4sdmod.dll
2009-06-23 09:55:55 ----A---- D:\WINDOWS\system32\mp43dmod.dll
2009-06-23 09:55:53 ----A---- D:\WINDOWS\system32\spiisupd.exe
2009-06-23 09:55:53 ----A---- D:\WINDOWS\system32\secedit.exe
2009-06-23 09:55:53 ----A---- D:\WINDOWS\system32\asr_pfu.exe
2009-06-23 09:55:49 ----A---- D:\WINDOWS\system32\auditusr.exe
2009-06-23 09:55:48 ----A---- D:\WINDOWS\system32\bthserv.dll
2009-06-23 09:55:48 ----A---- D:\WINDOWS\system32\bthci.dll
2009-06-23 09:55:48 ----A---- D:\WINDOWS\system32\blastcln.exe
2009-06-23 09:55:48 ----A---- D:\WINDOWS\system32\bitsprx3.dll
2009-06-23 09:55:48 ----A---- D:\WINDOWS\system32\bitsprx2.dll
2009-06-23 09:55:47 ----A---- D:\WINDOWS\system32\cmsetacl.dll
2009-06-23 09:55:47 ----A---- D:\WINDOWS\system32\btpanui.dll
2009-06-23 09:55:46 ----A---- D:\WINDOWS\system32\dsprpres.dll
2009-06-23 09:55:46 ----A---- D:\WINDOWS\system32\d3d9.dll
2009-06-23 09:55:45 ----A---- D:\WINDOWS\system32\encapi.dll
2009-06-23 09:55:45 ----A---- D:\WINDOWS\system32\dxdiagn.dll
2009-06-23 09:55:44 ----A---- D:\WINDOWS\system32\extmgr.dll
2009-06-23 09:55:44 ----A---- D:\WINDOWS\system32\encdec.dll
2009-06-23 09:55:43 ----A---- D:\WINDOWS\system32\fsquirt.exe
2009-06-23 09:55:43 ----A---- D:\WINDOWS\system32\fltmc.exe
2009-06-23 09:55:43 ----A---- D:\WINDOWS\system32\fltlib.dll
2009-06-23 09:55:42 ----A---- D:\WINDOWS\system32\httpapi.dll
2009-06-23 09:55:42 ----A---- D:\WINDOWS\system32\fwcfg.dll
2009-06-23 09:55:41 ----A---- D:\WINDOWS\system32\ieencode.dll
2009-06-23 09:55:40 ----A---- D:\WINDOWS\system32\ir41_qcx.dll
2009-06-23 09:55:40 ----A---- D:\WINDOWS\system32\ir41_qc.dll
2009-06-23 09:55:38 ----A---- D:\WINDOWS\system32\ir50_qc.dll
2009-06-23 09:55:38 ----A---- D:\WINDOWS\system32\ir50_32.dll
2009-06-23 09:55:37 ----A---- D:\WINDOWS\system32\ir50_qcx.dll
2009-06-23 09:55:36 ----A---- D:\WINDOWS\system32\kbdinbe1.dll
2009-06-23 09:55:36 ----A---- D:\WINDOWS\system32\kbdfi1.dll
2009-06-23 09:55:36 ----A---- D:\WINDOWS\system32\iuengine.dll
2009-06-23 09:55:35 ----A---- D:\WINDOWS\system32\kbdukx.dll
2009-06-23 09:55:35 ----A---- D:\WINDOWS\system32\kbdsmsno.dll
2009-06-23 09:55:35 ----A---- D:\WINDOWS\system32\kbdsmsfi.dll
2009-06-23 09:55:35 ----A---- D:\WINDOWS\system32\kbdno1.dll
2009-06-23 09:55:35 ----A---- D:\WINDOWS\system32\kbdmlt48.dll
2009-06-23 09:55:35 ----A---- D:\WINDOWS\system32\kbdmlt47.dll
2009-06-23 09:55:35 ----A---- D:\WINDOWS\system32\kbdmaori.dll
2009-06-23 09:55:35 ----A---- D:\WINDOWS\system32\kbdinmal.dll
2009-06-23 09:55:35 ----A---- D:\WINDOWS\system32\kbdinben.dll
2009-06-23 09:55:34 ----A---- D:\WINDOWS\system32\mstsc.exe
2009-06-23 09:55:33 ----A---- D:\WINDOWS\system32\mstscax.dll
2009-06-23 09:55:33 ----A---- D:\WINDOWS\system32\msdadiag.dll
2009-06-23 09:55:32 ----A---- D:\WINDOWS\system32\xpob2res.dll
2009-06-23 09:55:32 ----A---- D:\WINDOWS\system32\mssap.dll
2009-06-23 09:55:32 ----A---- D:\WINDOWS\system32\msftedit.dll
2009-06-23 09:55:31 ----A---- D:\WINDOWS\system32\p2pnetsh.dll
2009-06-23 09:55:31 ----A---- D:\WINDOWS\system32\p2pgraph.dll
2009-06-23 09:55:31 ----A---- D:\WINDOWS\system32\p2pgasvc.dll
2009-06-23 09:55:31 ----A---- D:\WINDOWS\system32\p2p.dll
2009-06-23 09:55:30 ----A---- D:\WINDOWS\system32\sbe.dll
2009-06-23 09:55:30 ----A---- D:\WINDOWS\system32\powercfg.exe
2009-06-23 09:55:30 ----A---- D:\WINDOWS\system32\pnrpnsp.dll
2009-06-23 09:55:30 ----A---- D:\WINDOWS\system32\photometadatahandler.dll
2009-06-23 09:55:30 ----A---- D:\WINDOWS\system32\p2psvc.dll
2009-06-23 09:55:29 ----A---- D:\WINDOWS\system32\smbinst.exe
2009-06-23 09:55:29 ----A---- D:\WINDOWS\system32\sdhcinst.dll
2009-06-23 09:55:29 ----A---- D:\WINDOWS\system32\sbeio.dll
2009-06-23 09:55:28 ----A---- D:\WINDOWS\system32\xpsp1res.dll
2009-06-23 09:55:28 ----A---- D:\WINDOWS\system32\spnpinst.exe
2009-06-23 09:55:26 ----A---- D:\WINDOWS\system32\xpsp3res.dll
2009-06-23 09:55:26 ----A---- D:\WINDOWS\system32\xpsp2res.dll
2009-06-23 09:55:25 ----A---- D:\WINDOWS\system32\w3ssl.dll
2009-06-23 09:55:25 ----A---- D:\WINDOWS\system32\tzchange.exe
2009-06-23 09:55:25 ----A---- D:\WINDOWS\system32\twext.dll
2009-06-23 09:55:25 ----A---- D:\WINDOWS\system32\strmfilt.dll
2009-06-23 09:55:24 ----A---- D:\WINDOWS\system32\windowscodecs.dll
2009-06-23 09:55:24 ----A---- D:\WINDOWS\system32\winbrand.dll
2009-06-23 09:55:23 ----A---- D:\WINDOWS\system32\wscntfy.exe
2009-06-23 09:55:23 ----A---- D:\WINDOWS\system32\wmphoto.dll
2009-06-23 09:55:23 ----A---- D:\WINDOWS\system32\winshfhc.dll
2009-06-23 09:55:23 ----A---- D:\WINDOWS\system32\winhttp.dll
2009-06-23 09:55:23 ----A---- D:\WINDOWS\system32\windowscodecsext.dll
2009-06-23 09:55:22 ----A---- D:\WINDOWS\system32\wuauclt1.exe
2009-06-23 09:55:22 ----A---- D:\WINDOWS\system32\wshbth.dll
2009-06-23 09:55:22 ----A---- D:\WINDOWS\system32\wscsvc.dll
2009-06-23 09:55:21 ----A---- D:\WINDOWS\system32\xmlprovi.dll
2009-06-23 09:55:21 ----A---- D:\WINDOWS\system32\xmlprov.dll
2009-06-23 09:55:21 ----A---- D:\WINDOWS\system32\wuauserv.dll
2009-06-23 09:55:21 ----A---- D:\WINDOWS\system32\wuaueng1.dll
2009-06-23 09:55:08 ----A---- D:\WINDOWS\system32\qmgr.dll
2009-06-23 09:55:08 ----A---- D:\WINDOWS\system32\pidgen.dll
2009-06-23 09:55:08 ----A---- D:\WINDOWS\system32\dpcdll.dll
2009-06-23 09:54:55 ----A---- D:\WINDOWS\system32\appmgmts.dll
2009-06-23 09:54:55 ----A---- D:\WINDOWS\system32\adsnw.dll
2009-06-23 09:54:54 ----A---- D:\WINDOWS\system32\eventtriggers.exe
2009-06-23 09:54:54 ----A---- D:\WINDOWS\system32\eventcreate.exe
2009-06-23 09:54:54 ----A---- D:\WINDOWS\system32\efsadu.dll
2009-06-23 09:54:54 ----A---- D:\WINDOWS\system32\driverquery.exe
2009-06-23 09:54:54 ----A---- D:\WINDOWS\system32\cipher.exe
2009-06-23 09:54:54 ----A---- D:\WINDOWS\system32\bootcfg.exe
2009-06-23 09:54:54 ----A---- D:\WINDOWS\system32\asr_fmt.exe
2009-06-23 09:54:54 ----A---- D:\WINDOWS\system32\appmgr.dll
2009-06-23 09:54:53 ----A---- D:\WINDOWS\system32\gpresult.exe
2009-06-23 09:54:53 ----A---- D:\WINDOWS\system32\gpedit.dll
2009-06-23 09:54:53 ----A---- D:\WINDOWS\system32\getmac.exe
2009-06-23 09:54:53 ----A---- D:\WINDOWS\system32\fdeploy.dll
2009-06-23 09:54:53 ----A---- D:\WINDOWS\system32\fde.dll
2009-06-23 09:54:52 ----A---- D:\WINDOWS\system32\mqlogmgr.dll
2009-06-23 09:54:52 ----A---- D:\WINDOWS\system32\mqise.dll
2009-06-23 09:54:52 ----A---- D:\WINDOWS\system32\mqdscli.dll
2009-06-23 09:54:52 ----A---- D:\WINDOWS\system32\mqbkup.exe
2009-06-23 09:54:52 ----A---- D:\WINDOWS\system32\mqad.dll
2009-06-23 09:54:52 ----A---- D:\WINDOWS\system32\logman.exe
2009-06-23 09:54:52 ----A---- D:\WINDOWS\system32\gptext.dll
2009-06-23 09:54:51 ----A---- D:\WINDOWS\system32\mqrtdep.dll
2009-06-23 09:54:51 ----A---- D:\WINDOWS\system32\mqrt.dll
2009-06-23 09:54:51 ----A---- D:\WINDOWS\system32\mqqm.dll
2009-06-23 09:54:51 ----A---- D:\WINDOWS\system32\mqoa.dll
2009-06-23 09:54:50 ----A---- D:\WINDOWS\system32\mqupgrd.dll
2009-06-23 09:54:50 ----A---- D:\WINDOWS\system32\mqtrig.dll
2009-06-23 09:54:50 ----A---- D:\WINDOWS\system32\mqtgsvc.exe
2009-06-23 09:54:50 ----A---- D:\WINDOWS\system32\mqsvc.exe
2009-06-23 09:54:50 ----A---- D:\WINDOWS\system32\mqsnap.dll
2009-06-23 09:54:50 ----A---- D:\WINDOWS\system32\mqsec.dll
2009-06-23 09:54:49 ----A---- D:\WINDOWS\system32\rsnotify.exe
2009-06-23 09:54:49 ----A---- D:\WINDOWS\system32\proxycfg.exe
2009-06-23 09:54:49 ----A---- D:\WINDOWS\system32\openfiles.exe
2009-06-23 09:54:49 ----A---- D:\WINDOWS\system32\nwwks.dll
2009-06-23 09:54:49 ----A---- D:\WINDOWS\system32\nwapi32.dll
2009-06-23 09:54:49 ----A---- D:\WINDOWS\system32\ntbackup.exe
2009-06-23 09:54:49 ----A---- D:\WINDOWS\system32\mqutil.dll
2009-06-23 09:54:48 ----A---- D:\WINDOWS\system32\tlntsvr.exe
2009-06-23 09:54:48 ----A---- D:\WINDOWS\system32\tlntsess.exe
2009-06-23 09:54:48 ----A---- D:\WINDOWS\system32\tlntadmn.exe
2009-06-23 09:54:48 ----A---- D:\WINDOWS\system32\tasklist.exe
2009-06-23 09:54:48 ----A---- D:\WINDOWS\system32\taskkill.exe
2009-06-23 09:54:48 ----A---- D:\WINDOWS\system32\systeminfo.exe
2009-06-23 09:54:48 ----A---- D:\WINDOWS\system32\schtasks.exe
2009-06-23 09:54:47 ----A---- D:\WINDOWS\system32\wsecedit.dll
2009-06-23 09:54:47 ----A---- D:\WINDOWS\system32\tracerpt.exe
2009-06-23 09:54:47 ----A---- D:\WINDOWS\system32\tlntsvrp.dll
2009-06-23 09:53:44 ----A---- D:\WINDOWS\hh.exe