Stránka 1 z 1

wbove prehliadace neustale vytacaju CPU na 100%

Napsal: 21 kvě 2011 20:05
od miamafia
Dobry den. chcem sa spytat, ci to sposobuje nejaky sajrajt v PC, alebo systemova chyba.. Po spusteni akehokolvek weboveho prehliacaca.. ci uz firefox, opera alebo chrome (na tom to zacalo) do par minut zacne procesor makat na 100% a neustale rastie vyuzitie pamate. na ochranu pouzivam Aviru, ta nic nenasla.. spybot-SD nieco nasiel, odstranil.. Prosim, hodte ocko na log. dakujem.

Logfile of random's system information tool 1.08 (written by random/random)
Run by Mia at 2011-05-21 20:51:05
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 25 GB (44%) free of 56 GB
Total RAM: 2431 MB (72% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:51:34, on 21. 5. 2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ATK0100\HControl.exe
C:\WINDOWS\sm56hlpr.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Program Files\Wireless Console 2\wcourier.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\VideoLAN\VLC\vlc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Mia\Dokumenty\Preberanie\RSIT(1).exe
C:\Program Files\trend micro\Mia.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qip.ru
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: QIPBHO - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Documents and Settings\Mia\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: BrowserPlugin - {BB54C912-5131-5114-A979-F4D5402448F1} - C:\Documents and Settings\Mia\Local Settings\Data aplikací\GamePlayLabs Plugin\BHO.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\Program Files\No1 Video Converter\msdxm.ocx (file missing)
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ASUS Live Update] C:\Program Files\ASUS\ASUS Live Update\ALU.exe
O4 - HKLM\..\Run: [Wireless Console 2] C:\Program Files\Wireless Console 2\wcourier.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Zshutdown] c:\sysprep\patch\sysprep.cmd
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\RunOnce: [SpybotDeletingA2394] command.com /c del "C:\WINDOWS\system32\skyx16.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4325] cmd.exe /c del "C:\WINDOWS\system32\skyx16.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8101] command.com /c del "C:\WINDOWS\system32\qz.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9922] cmd.exe /c del "C:\WINDOWS\system32\qz.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6332] command.com /c del "C:\WINDOWS\system32\qz.sys_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7583] cmd.exe /c del "C:\WINDOWS\system32\qz.sys_old"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB1635] command.com /c del "C:\WINDOWS\system32\skyx16.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2933] cmd.exe /c del "C:\WINDOWS\system32\skyx16.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9813] command.com /c del "C:\WINDOWS\system32\qz.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6916] cmd.exe /c del "C:\WINDOWS\system32\qz.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8446] command.com /c del "C:\WINDOWS\system32\qz.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8211] cmd.exe /c del "C:\WINDOWS\system32\qz.sys_old"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra button: QIP Infium - {1EF681F7-A04B-4D6D-9012-A307CCA55610} - C:\Program Files\QIP Infium\infium.exe (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.asus.com
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.17\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.5.8\bin\mysqld.exe

--
End of file - 9476 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95289393-33EA-4F8D-B952-483415B9C955}]
QIPBHO Class - C:\Documents and Settings\Mia\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll [2011-05-11 141184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BB54C912-5131-5114-A979-F4D5402448F1}]
BrowserPlugin - C:\Documents and Settings\Mia\Local Settings\Data aplikací\GamePlayLabs Plugin\BHO.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-02-02 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-02-02 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E718888-423F-11D2-876E-00A0C9082467} - &Radio - C:\Program Files\No1 Video Converter\msdxm.ocx []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HControl"=C:\WINDOWS\ATK0100\HControl.exe [2006-04-17 110592]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2006-04-26 7561216]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2006-04-26 86016]
"SMSERIAL"=C:\WINDOWS\sm56hlpr.exe [2006-01-19 544768]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2005-12-18 15797248]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"ASUS Live Update"=C:\Program Files\ASUS\ASUS Live Update\ALU.exe [2006-02-21 180224]
"Wireless Console 2"=C:\Program Files\Wireless Console 2\wcourier.exe [2005-10-17 987136]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2005-10-20 761945]
"Zshutdown"=c:\sysprep\patch\sysprep.cmd []
"ccApp"=C:\Program Files\Common Files\Symantec Shared\ccApp.exe [2004-08-28 58488]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2010-12-13 281768]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingA2394"=command.com /c del C:\WINDOWS\system32\skyx16.dll_old []
"SpybotDeletingC4325"=cmd.exe /c del C:\WINDOWS\system32\skyx16.dll_old []
"SpybotDeletingA8101"=command.com /c del C:\WINDOWS\system32\qz.dll_old []
"SpybotDeletingC9922"=cmd.exe /c del C:\WINDOWS\system32\qz.dll_old []
"SpybotDeletingA6332"=command.com /c del C:\WINDOWS\system32\qz.sys_old []
"SpybotDeletingC7583"=cmd.exe /c del C:\WINDOWS\system32\qz.sys_old []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctf [2011-05-21 248]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-01-26 2144088]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingB1635"=command.com /c del C:\WINDOWS\system32\skyx16.dll_old []
"SpybotDeletingD2933"=cmd.exe /c del C:\WINDOWS\system32\skyx16.dll_old []
"SpybotDeletingB9813"=command.com /c del C:\WINDOWS\system32\qz.dll_old []
"SpybotDeletingD6916"=cmd.exe /c del C:\WINDOWS\system32\qz.dll_old []
"SpybotDeletingB8446"=command.com /c del C:\WINDOWS\system32\qz.sys_old []
"SpybotDeletingD8211"=cmd.exe /c del C:\WINDOWS\system32\qz.sys_old []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Power_Gear]
C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe [2006-03-06 86016]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QIP Internet Guardian]
C:\Documents and Settings\Mia\Data aplikací\QipGuard\QipGuard.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-10-29 249064]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE [2004-12-14 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^ASUS ChkMail.lnk]
C:\PROGRA~1\ASUS\ASUSCH~1\ChkMail.exe [2003-09-12 32768]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Mia^Nabídka Start^Programy^Po spuštění^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
C:\PROGRA~1\MICROS~2\Office12\ONENOTEM.EXE [2006-10-26 98632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\VideoLAN\VLC\vlc.exe"="C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\TOTALCMD\TOTALCMD.EXE"="C:\TOTALCMD\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\groove.exe"="C:\Program Files\Microsoft Office\Office12\groove.exe:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\DC++\DCPlusPlus.exe"="C:\Program Files\DC++\DCPlusPlus.exe:*:Enabled:DC++"
"C:\Documents and Settings\Mia\Local Settings\Data aplikací\Google\Google Talk Plugin\googletalkplugin.exe"="C:\Documents and Settings\Mia\Local Settings\Data aplikací\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin"
"C:\Program Files\MATLAB\R2008b\BIN\WIN32\MATLAB.exe"="C:\Program Files\MATLAB\R2008b\BIN\WIN32\MATLAB.exe:*:Enabled:MATLAB"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\wamp\bin\apache\Apache2.2.17\bin\httpd.exe"="C:\wamp\bin\apache\Apache2.2.17\bin\httpd.exe:*:Enabled:Apache HTTP Server"
"C:\Program Files\QIP Infium\infium.exe"="C:\Program Files\QIP Infium\infium.exe:*:Enabled:QIP Infium"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

Re: wbove prehliadace neustale vytacaju CPU na 100%

Napsal: 21 kvě 2011 20:06
od miamafia
======List of files/folders created in the last 1 months======

2011-05-21 20:49:42 ----D---- C:\rsit
2011-05-21 20:42:07 ----A---- C:\WINDOWS\wininit.ini
2011-05-21 18:11:29 ----D---- C:\Program Files\TeaTimer (Spybot - Search & Destroy)
2011-05-21 18:11:29 ----D---- C:\Program Files\SDHelper (Spybot - Search & Destroy)
2011-05-21 18:11:29 ----D---- C:\Program Files\Misc. Support Library (Spybot - Search & Destroy)
2011-05-21 18:11:29 ----D---- C:\Program Files\File Scanner Library (Spybot - Search & Destroy)
2011-05-21 18:03:52 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2011-05-21 18:03:09 ----D---- C:\Program Files\Spybot - Search & Destroy
2011-05-21 17:54:04 ----D---- C:\Program Files\Trend Micro
2011-05-21 17:47:43 ----D---- C:\WINDOWS\pss
2011-05-21 17:28:53 ----D---- C:\Documents and Settings\Mia\Data aplikací\Malwarebytes
2011-05-21 17:27:36 ----A---- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2011-05-21 17:26:48 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2011-05-21 17:26:22 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-05-21 17:26:22 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2011-05-21 09:51:01 ----D---- C:\Documents and Settings\Mia\Data aplikací\QIP
2011-05-21 09:48:16 ----D---- C:\Program Files\QIP Infium
2011-05-21 01:54:48 ----RSHD---- C:\WINDOWS\system32\winwsl.exe
2011-05-21 01:54:48 ----RSHD---- C:\WINDOWS\system32\wintbpx.exe
2011-05-21 01:54:48 ----RSHD---- C:\WINDOWS\system32\wintbp.exe
2011-05-21 01:54:48 ----RSHD---- C:\WINDOWS\system32\winrvl.exe
2011-05-21 01:54:48 ----RSHD---- C:\WINDOWS\system32\winksl.exe
2011-05-21 01:54:48 ----RSHD---- C:\WINDOWS\system32\update.exe
2011-05-21 01:54:48 ----RSHD---- C:\WINDOWS\system32\servises.exe
2011-05-21 01:54:48 ----RSHD---- C:\WINDOWS\system32\regperf.exe
2011-05-21 01:54:48 ----RSHD---- C:\WINDOWS\system32\pnp.exe
2011-05-21 01:54:48 ----RSHD---- C:\WINDOWS\system32\per.exe
2011-05-21 01:54:48 ----RSHD---- C:\WINDOWS\system32\nvctrl.exe
2011-05-21 01:54:48 ----RSHD---- C:\WINDOWS\system32\mssearchnet.exe
2011-05-21 01:54:48 ----RSHD---- C:\WINDOWS\system32\fuck.exe
2011-05-21 01:54:48 ----RSHD---- C:\WINDOWS\system32\csm.exe
2011-05-21 01:54:48 ----RSHD---- C:\WINDOWS\system32\botzor.exe
2011-05-21 01:54:48 ----RSHD---- C:\WINDOWS\pnpasn32.exe
2011-05-21 01:54:48 ----RSHD---- C:\WINDOWS\hpsv.exe
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\winupie.exe
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\winmuschi.exe
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\vx2.dll
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\updatewinlocator.exe
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\system32\zp.dll
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\system32\zeropopupbar.dll
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\system32\wuauclt.dll
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\system32\wintft.dll
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\system32\winshow.dll
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\system32\winsb.dll
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\system32\winpup32.exe
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\system32\winpup.exe
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\system32\winlocatorhelper.dll
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\system32\winlocator.dll
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\system32\systemout.exe
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\system32\sysdll32.dll
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\system32\rx.exe
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\system32\pup.exe
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\system32\norton update.exe
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\system32\msmsgs.exe
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\system32\mscornet.exe
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\system32\issearch.exe
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\system32\isnotify.exe
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\system32\ismon.exe
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\system32\ishost.exe
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\system32\dfrgsrv.exe
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\system32\dfe1.exe
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\system32\df_kme.exe
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\system32\dcomcfg.exe
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\system32\bridge.dll
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\system32\axconfig.dll
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\system32\a.exe
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\system32\4ccc3cea.exe
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\psapi.dll
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\kernellos.dll
2011-05-21 01:54:47 ----RSHD---- C:\WINDOWS\cdproxyserv.exe
2011-05-21 01:54:46 ----RSHD---- C:\WINDOWS\windowsupd4.exe
2011-05-21 01:54:46 ----RSHD---- C:\WINDOWS\windowsupd2.exe
2011-05-21 01:54:46 ----RSHD---- C:\WINDOWS\windowsupd1.exe
2011-05-21 01:54:46 ----RSHD---- C:\WINDOWS\system32\winntcreate.exe
2011-05-21 01:54:46 ----RSHD---- C:\WINDOWS\system32\vx2.dll
2011-05-21 01:54:46 ----RSHD---- C:\WINDOWS\system32\vwix32.exe
2011-05-21 01:54:46 ----RSHD---- C:\WINDOWS\system32\uninmyad.exe
2011-05-21 01:54:46 ----RSHD---- C:\WINDOWS\system32\tps108.dll
2011-05-21 01:54:46 ----RSHD---- C:\WINDOWS\system32\tisa.dll
2011-05-21 01:54:46 ----RSHD---- C:\WINDOWS\system32\sysmonnt.exe
2011-05-21 01:54:46 ----RSHD---- C:\WINDOWS\system32\spwgoc.exe
2011-05-21 01:54:46 ----RSHD---- C:\WINDOWS\system32\rvreg.exe
2011-05-21 01:54:46 ----RSHD---- C:\WINDOWS\system32\rulesak.dll
2011-05-21 01:54:46 ----RSHD---- C:\WINDOWS\system32\myad.dll
2011-05-21 01:54:46 ----RSHD---- C:\WINDOWS\system32\msview.dll
2011-05-21 01:54:46 ----RSHD---- C:\WINDOWS\system32\msnavc32.exe
2011-05-21 01:54:46 ----RSHD---- C:\WINDOWS\system32\lspak.dll
2011-05-21 01:54:46 ----RSHD---- C:\WINDOWS\system32\localnrd.dll
2011-05-21 01:54:46 ----RSHD---- C:\WINDOWS\system32\host.dll
2011-05-21 01:54:46 ----RSHD---- C:\WINDOWS\system32\gdu.dll
2011-05-21 01:54:46 ----RSHD---- C:\WINDOWS\system32\dad.bat
2011-05-21 01:54:46 ----RSHD---- C:\WINDOWS\system32\cidrules.dll
2011-05-21 01:54:46 ----RSHD---- C:\WINDOWS\system32\6fo4svc.dll
2011-05-21 01:54:46 ----RSHD---- C:\WINDOWS\iehelper.dll
2011-05-21 01:54:46 ----RSHD---- C:\WINDOWS\cleanhistories.dll
2011-05-21 01:54:46 ----RSHD---- C:\WINDOWS\ads.js
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\t2serv.exe
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\t2serv.dll
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\system32\zlbw.dll
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\system32\wincom32.sys
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\system32\vb5dmspo.dll
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\system32\v4pbpt51.dll
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\system32\tisa.cnf
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\system32\tips.exe
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\system32\tippcls.dat
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\system32\tipp.dat
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\system32\timesrv.exe
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\system32\ticont.dll
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\system32\ticads.exe
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\system32\tconini.dat
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\system32\slbipsch.exe
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\system32\slbipsch.dll
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\system32\se.exe
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\system32\sd16win.dll
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\system32\ppl.exe
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\system32\nordsys.exe
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\system32\messenger.lib.exe
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\system32\lut.dat
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\system32\lcch.dat
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\system32\ladchkr.exe
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\system32\hook2.dll
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\system32\hook1.dll
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\system32\google.png.exe
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\system32\game3.exe
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\system32\game2.exe
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\system32\game1.exe
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\system32\alsys.exe
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\system32\adchkr.exe
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\sserrvv.exe
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\serrv.exe
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\reggserv.exe
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\msupdtwiz.exe
2011-05-21 01:54:45 ----RSHD---- C:\WINDOWS\cserv32.exe
2011-05-21 01:54:44 ----RSHD---- C:\WINDOWS\system32\wshtlprh.dll
2011-05-21 01:54:44 ----RSHD---- C:\WINDOWS\system32\wshnseri.exe
2011-05-21 01:54:44 ----RSHD---- C:\WINDOWS\system32\winftsap.exe
2011-05-21 01:54:44 ----RSHD---- C:\WINDOWS\system32\winftsap.dll
2011-05-21 01:54:44 ----RSHD---- C:\WINDOWS\system32\w3sskbda.dll
2011-05-21 01:54:44 ----RSHD---- C:\WINDOWS\system32\vsxmpgpc.dll
2011-05-21 01:54:44 ----RSHD---- C:\WINDOWS\system32\vnetsmme.dll
2011-05-21 01:54:44 ----RSHD---- C:\WINDOWS\system32\trafracp.dll
2011-05-21 01:54:44 ----RSHD---- C:\WINDOWS\system32\snmpmssw.exe
2011-05-21 01:54:44 ----RSHD---- C:\WINDOWS\system32\slbrmqtr.exe
2011-05-21 01:54:44 ----RSHD---- C:\WINDOWS\system32\shfoxpob.exe
2011-05-21 01:54:44 ----RSHD---- C:\WINDOWS\system32\secumsje.exe
2011-05-21 01:54:44 ----RSHD---- C:\WINDOWS\system32\scp3jgaw.dll
2011-05-21 01:54:44 ----RSHD---- C:\WINDOWS\system32\rdpwmsjt.exe
2011-05-21 01:54:44 ----RSHD---- C:\WINDOWS\system32\rcbdwmpd.dll
2011-05-21 01:54:44 ----RSHD---- C:\WINDOWS\system32\qdvtscf.dll
2011-05-21 01:54:44 ----RSHD---- C:\WINDOWS\system32\oebdfc.dll
2011-05-21 01:54:44 ----RSHD---- C:\WINDOWS\system32\msstersv.dll
2011-05-21 01:54:44 ----RSHD---- C:\WINDOWS\system32\msnsxole.exe
2011-05-21 01:54:44 ----RSHD---- C:\WINDOWS\system32\msnsxole.dll
2011-05-21 01:54:44 ----RSHD---- C:\WINDOWS\system32\mslsicwd.dll
2011-05-21 01:54:44 ----RSHD---- C:\WINDOWS\system32\msexcred.exe
2011-05-21 01:54:44 ----RSHD---- C:\WINDOWS\system32\msafiasn.dll
2011-05-21 01:54:44 ----RSHD---- C:\WINDOWS\system32\mqoacdmo.dll
2011-05-21 01:54:44 ----RSHD---- C:\WINDOWS\system32\mqadscp3.exe
2011-05-21 01:54:44 ----RSHD---- C:\WINDOWS\system32\mgmtmtxc.exe
2011-05-21 01:54:44 ----RSHD---- C:\WINDOWS\system32\mcd3mscm.dll
2011-05-21 01:54:44 ----RSHD---- C:\WINDOWS\system32\lmrtatkc.dll
2011-05-21 01:54:44 ----RSHD---- C:\WINDOWS\system32\kbdpkbdr.exe
2011-05-21 01:54:44 ----RSHD---- C:\WINDOWS\system32\kbdfwshe.exe
2011-05-21 01:54:44 ----RSHD---- C:\WINDOWS\system32\jgsdrpcn.exe
2011-05-21 01:54:44 ----RSHD---- C:\WINDOWS\system32\jgsdrpcn.dll
2011-05-21 01:54:44 ----RSHD---- C:\WINDOWS\system32\jgdwadsn.exe
2011-05-21 01:54:44 ----RSHD---- C:\WINDOWS\ccsserv.exe
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\xkrdk.dll
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\wiatwain.dll
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\unsocul.exe
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\sodahk.dll
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\replmap.dll
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\jgdwadsn.dll
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\iuennwcf.dll
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\ir32racp.exe
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\ipxwshel.exe
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\ipxrmfc4.dll
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\imesrdch.exe
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\icmpdx3j.dll
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\iaspdpus.dll
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\i4n27vl.exe
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\chkmfdep.exe
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\higehsg.dll
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\hhselz32.dll
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\fltlauto.exe
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\fileserv.dll
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\e1.dll
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\dsseds32.exe
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\dsseds32.dll
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\dpugmswe.dll
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\dnsrxpob.exe
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\deskmcd3.dll
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\ddemdmco.dll
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\davctool.exe
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\davctool.dll
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\confbrw.dll
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\comrkbdd.exe
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\camodpnm.exe
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\brwstat.dll
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\brwprf32.dll
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\brwperf.exe
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\brwmgr32.dll
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\brwconf.exe
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\avifipxr.dll
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\admeiolo.dll
2011-05-21 01:54:43 ----RSHD---- C:\WINDOWS\system32\actidmoc.exe
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\waladhpr.exe
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\system32\wzhelper.dll
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\system32\webalize.dll
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\system32\somatic.dll
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\system32\socul.dll
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\system32\smdnn05.dll
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\system32\servehost.exe
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\system32\seqsb.dll
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\system32\searchupdate33.exe
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\system32\searchupdate31.exe
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\system32\searchsquire33.dll
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\system32\searchsquire3.dll
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\system32\searchsquire2.dll
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\system32\searchsquire.dll
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\system32\seantb.dll
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\system32\s4helper.dll
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\system32\reg2.exe
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\system32\pqhelper.dll
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\system32\mygeek.dll
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\system32\msqsb.dll
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\system32\mslspcg.exe
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\system32\mgeekremove.exe
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\system32\ifsomatic.dll
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\system32\ifhelper.dll
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\system32\iebrw.dll
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\system32\hotlink.dll
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\system32\homepage.dll
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\system32\hmepge.dll
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\system32\gsim.dll
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\system32\comploader.dll
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\system32\barbho.dll
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\svrmgr.exe
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\ssmsgr.exe
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\ssls.exe
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\ssdgt.exe
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\sscrg.exe
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\gsim.dll
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\cssswd.exe
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\csssupd.exe
2011-05-21 01:54:42 ----RSHD---- C:\WINDOWS\adrsb.exe
2011-05-21 01:54:41 ----RSHD---- C:\WINDOWS\system32\shnlog.exe
2011-05-21 01:54:41 ----RSHD---- C:\WINDOWS\system32\rlvknlg.exe
2011-05-21 01:54:41 ----RSHD---- C:\WINDOWS\system32\rkinstaller.exe
2011-05-21 01:54:41 ----RSHD---- C:\WINDOWS\system32\rk.exe
2011-05-21 01:54:41 ----RSHD---- C:\WINDOWS\system32\msplus4.dll
2011-05-21 01:54:41 ----RSHD---- C:\WINDOWS\system32\msplus3.dll
2011-05-21 01:54:41 ----RSHD---- C:\WINDOWS\system32\msplus2.dll
2011-05-21 01:54:41 ----RSHD---- C:\WINDOWS\system32\msplus1.dll
2011-05-21 01:54:41 ----RSHD---- C:\WINDOWS\system32\msplus.dll
2011-05-21 01:54:41 ----RSHD---- C:\WINDOWS\system32\mrkscr.exe
2011-05-21 01:54:41 ----RSHD---- C:\WINDOWS\system32\intmon.exe
2011-05-21 01:54:41 ----RSHD---- C:\WINDOWS\skynetave.exe
2011-05-21 01:54:41 ----RSHD---- C:\WINDOWS\napatch.exe
2011-05-21 01:54:41 ----RSHD---- C:\WINDOWS\lsasss.exe
2011-05-21 01:54:41 ----RSHD---- C:\WINDOWS\lansas.exe
2011-05-21 01:54:41 ----RSHD---- C:\WINDOWS\cfg32s.dll
2011-05-21 01:54:41 ----RSHD---- C:\WINDOWS\cfg32r.dll
2011-05-21 01:54:41 ----RSHD---- C:\WINDOWS\cfg32o.dll
2011-05-21 01:54:41 ----RSHD---- C:\WINDOWS\cfg32.exe
2011-05-21 01:54:41 ----RSHD---- C:\WINDOWS\avserve3.exe
2011-05-21 01:54:41 ----RSHD---- C:\WINDOWS\avserve2.exe
2011-05-21 01:54:40 ----RSHD---- C:\WINDOWS\wserver.exe
2011-05-21 01:54:40 ----RSHD---- C:\WINDOWS\winlogon.scr
2011-05-21 01:54:40 ----RSHD---- C:\WINDOWS\system32\vlcx052.dll
2011-05-21 01:54:40 ----RSHD---- C:\WINDOWS\system32\speeder.exe
2011-05-21 01:54:40 ----RSHD---- C:\WINDOWS\system32\slpube03.dll
2011-05-21 01:54:40 ----RSHD---- C:\WINDOWS\system32\optserve.exe
2011-05-21 01:54:40 ----RSHD---- C:\WINDOWS\system32\optserve.dll
2011-05-21 01:54:40 ----RSHD---- C:\WINDOWS\system32\mstc.exe
2011-05-21 01:54:40 ----RSHD---- C:\WINDOWS\system32\msclt.exe
2011-05-21 01:54:40 ----RSHD---- C:\WINDOWS\system32\lp.exe
2011-05-21 01:54:40 ----RSHD---- C:\WINDOWS\system32\lp.dll
2011-05-21 01:54:40 ----RSHD---- C:\WINDOWS\system32\auole4.dll
2011-05-21 01:54:40 ----RSHD---- C:\WINDOWS\switpb.exe
2011-05-21 01:54:40 ----RSHD---- C:\WINDOWS\switpa.exe
2011-05-21 01:54:40 ----RSHD---- C:\WINDOWS\infodll.dll
2011-05-21 01:54:39 ----RSHD---- C:\WINDOWS\winlogon.exe
2011-05-21 01:54:39 ----RSHD---- C:\WINDOWS\visualguard.exe
2011-05-21 01:54:39 ----RSHD---- C:\WINDOWS\userconfig9x.dll
2011-05-21 01:54:39 ----RSHD---- C:\WINDOWS\system32\xpfirewall.exe
2011-05-21 01:54:39 ----RSHD---- C:\WINDOWS\system32\wpwmgrs.exe
2011-05-21 01:54:39 ----RSHD---- C:\WINDOWS\system32\winvnc.exe
2011-05-21 01:54:39 ----RSHD---- C:\WINDOWS\system32\wintasker.exe
2011-05-21 01:54:39 ----RSHD---- C:\WINDOWS\sysmonxp.exe
2011-05-21 01:54:39 ----RSHD---- C:\WINDOWS\symav.exe
2011-05-21 01:54:39 ----RSHD---- C:\WINDOWS\services.exe
2011-05-21 01:54:39 ----RSHD---- C:\WINDOWS\rundil32.exe
2011-05-21 01:54:39 ----RSHD---- C:\WINDOWS\rundil.exe
2011-05-21 01:54:39 ----RSHD---- C:\WINDOWS\phantom.exe
2011-05-21 01:54:39 ----RSHD---- C:\WINDOWS\pandaavengine.exe
2011-05-21 01:54:39 ----RSHD---- C:\WINDOWS\netmedia.exe
2011-05-21 01:54:39 ----RSHD---- C:\WINDOWS\msnmsgrs.exe
2011-05-21 01:54:39 ----RSHD---- C:\WINDOWS\maja.exe
2011-05-21 01:54:39 ----RSHD---- C:\WINDOWS\kasperskyaveng.exe
2011-05-21 01:54:39 ----RSHD---- C:\WINDOWS\jammer2nd.exe
2011-05-21 01:54:39 ----RSHD---- C:\WINDOWS\fvprotect.exe
2011-05-21 01:54:39 ----RSHD---- C:\WINDOWS\fooding.exe
2011-05-21 01:54:39 ----RSHD---- C:\WINDOWS\firewallsvr.exe
2011-05-21 01:54:39 ----RSHD---- C:\WINDOWS\easyav.exe
2011-05-21 01:54:39 ----RSHD---- C:\WINDOWS\diskmonitor.exe
2011-05-21 01:54:39 ----RSHD---- C:\WINDOWS\comp.cpl
2011-05-21 01:54:39 ----RSHD---- C:\WINDOWS\avprotect9x.exe
2011-05-21 01:54:39 ----RSHD---- C:\WINDOWS\avprotect.exe
2011-05-21 01:54:39 ----RSHD---- C:\WINDOWS\avpguard.exe
2011-05-21 01:54:39 ----RSHD---- C:\WINDOWS\avguard.exe
2011-05-21 01:54:39 ----RSHD---- C:\WINDOWS\avbgle.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\winsyscfg.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\winsys32.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\winsys.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\winsvc32.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\winstart.pif
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\winnt.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\wininfo.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\winhlpapi.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\wingmt32.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\winds.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\windowz.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\windowsfirewall.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\windasz-updote.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\win32.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\win24.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\wid32.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\wfdmgr.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\wfdgmr.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\wdns33.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\w32ntupdt.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\w1nt5k.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\twunk_65.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\timemanager.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\taskgmr32.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\taskgmr.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\taskgamr.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\tagmr.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\sysconf.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\sword.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\svshost.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\stagmr.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\sp2winfix.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\sp2fx.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\skybot.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\shell.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\service5.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\sd.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\scvhost32.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\scrigz.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\scalpe91.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\rundll.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\remote.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\protection.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\plugnplay32.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\picx.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\phantom.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\netcog.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\mtrnqs.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\mswins.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\mssck.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\msplus32.exe
2011-05-21 01:54:38 ----RSHD---- C:\WINDOWS\system32\msnl.exe
2011-05-21 01:54:37 ----RSHD---- C:\WINDOWS\system32\msmgrxp.exe
2011-05-21 01:54:37 ----RSHD---- C:\WINDOWS\system32\msgmr.exe
2011-05-21 01:54:37 ----RSHD---- C:\WINDOWS\system32\msdev32.exe
2011-05-21 01:54:36 ----RSHD---- C:\WINDOWS\system32\mouse.exe
2011-05-21 01:54:36 ----RSHD---- C:\WINDOWS\system32\microupdate.exe
2011-05-21 01:54:36 ----RSHD---- C:\WINDOWS\system32\memloader.exe
2011-05-21 01:54:36 ----RSHD---- C:\WINDOWS\system32\mcscn.exe
2011-05-21 01:54:36 ----RSHD---- C:\WINDOWS\system32\mailinfo.exe
2011-05-21 01:54:36 ----RSHD---- C:\WINDOWS\system32\logitechwls.exe
2011-05-21 01:54:36 ----RSHD---- C:\WINDOWS\system32\logic.exe
2011-05-21 01:54:36 ----RSHD---- C:\WINDOWS\system32\lienvdk.exe
2011-05-21 01:54:36 ----RSHD---- C:\WINDOWS\system32\lienvandekelder.exe
2011-05-21 01:54:36 ----RSHD---- C:\WINDOWS\system32\lientjeuh.exe
2011-05-21 01:54:35 ----RSHD---- C:\winssystem.exe
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\system32\winnb60.dll
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\system32\patch31345.exe
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\system32\osalogbe.exe
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\system32\msapasrc.dll
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\system32\msa64chk.dll
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\system32\microsystem.exe
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\system32\lien vd kelder.exe
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\system32\lien vande kelder.exe
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\system32\lien Van de kelderrr.exe
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\system32\lien van de kelder.exe
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\system32\lcd32.exe
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\system32\jusched32.exe
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\system32\itunegui.exe
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\system32\internet.exe
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\system32\iexplorer.exe
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\system32\hostdrvxp.exe
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\system32\hbmail.exe
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\system32\gothica.exe
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\system32\fixupdattr.exe
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\system32\evil.exe
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\system32\ds.exe
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\system32\dcomuser.exe
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\system32\coolbot.exe
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\system32\ccsrs.exe
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\system32\avpr.exe
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\system32\abs.exe
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\system32\666.exe
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\system32\1hellbot.exe
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\system32\0.exe
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\patch31345.exe
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\msnarrator.exe
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\mrhop.dll
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\mpgcom.dll
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\iempg2.dll
2011-05-21 01:54:35 ----RSHD---- C:\WINDOWS\iempg.dll
2011-05-21 01:54:35 ----RSHD---- C:\hellmsn.exe
2011-05-21 01:54:34 ----RSHD---- C:\WINDOWS\system32\winnb58.dll
2011-05-21 01:54:33 ----RSHD---- C:\WINDOWS\unstall.exe
2011-05-21 01:54:33 ----RSHD---- C:\WINDOWS\system32\winnb57.dll
2011-05-21 01:54:33 ----RSHD---- C:\WINDOWS\system32\winnb56.dll
2011-05-21 01:54:33 ----RSHD---- C:\WINDOWS\system32\winnb52.dll
2011-05-21 01:54:33 ----RSHD---- C:\WINDOWS\system32\winnb51.dll
2011-05-21 01:54:33 ----RSHD---- C:\WINDOWS\system32\winnb42.dll
2011-05-21 01:54:33 ----RSHD---- C:\WINDOWS\system32\winnb41.dll
2011-05-21 01:54:33 ----RSHD---- C:\WINDOWS\system32\winnb40.dll
2011-05-21 01:54:33 ----RSHD---- C:\WINDOWS\system32\windmy.dll
2011-05-21 01:54:33 ----RSHD---- C:\WINDOWS\system32\winats.dll
2011-05-21 01:54:33 ----RSHD---- C:\WINDOWS\system32\vtlbar1.dll
2011-05-21 01:54:33 ----RSHD---- C:\WINDOWS\system32\tubby.dll
2011-05-21 01:54:33 ----RSHD---- C:\WINDOWS\system32\tbc.dll
2011-05-21 01:54:33 ----RSHD---- C:\WINDOWS\system32\sys.exe
2011-05-21 01:54:33 ----RSHD---- C:\WINDOWS\system32\nn_bar31.dll
2011-05-21 01:54:33 ----RSHD---- C:\WINDOWS\system32\nn_bar22.dll
2011-05-21 01:54:33 ----RSHD---- C:\WINDOWS\system32\nn_bar21.dll
2011-05-21 01:54:33 ----RSHD---- C:\WINDOWS\system32\nn_bar.dll
2011-05-21 01:54:33 ----RSHD---- C:\WINDOWS\system32\nas.dll
2011-05-21 01:54:33 ----RSHD---- C:\WINDOWS\system32\myaccess.dll
2011-05-21 01:54:33 ----RSHD---- C:\WINDOWS\system32\mtc.dll
2011-05-21 01:54:33 ----RSHD---- C:\WINDOWS\system32\mapisvc32.exe
2011-05-21 01:54:33 ----RSHD---- C:\WINDOWS\system32\dll.dll
2011-05-21 01:54:33 ----RSHD---- C:\WINDOWS\mmups.exe
2011-05-21 01:54:33 ----RSHD---- C:\WINDOWS\mm63.ocx
2011-05-21 01:54:33 ----RSHD---- C:\WINDOWS\mm21.ocx
2011-05-21 01:54:33 ----RSHD---- C:\WINDOWS\mm20.ocx
2011-05-21 01:54:33 ----RSHD---- C:\WINDOWS\imgurla.exe
2011-05-21 01:54:33 ----RSHD---- C:\WINDOWS\a64sddd.exe
2011-05-21 01:54:32 ----RSHD---- C:\WINDOWS\xwrm.exe
2011-05-21 01:54:32 ----RSHD---- C:\WINDOWS\system32\wgavm.exe
2011-05-21 01:54:32 ----RSHD---- C:\WINDOWS\system32\wgareg.exe
2011-05-21 01:54:32 ----RSHD---- C:\WINDOWS\system32\version.exe
2011-05-21 01:54:32 ----RSHD---- C:\WINDOWS\system32\updtscheduler.exe
2011-05-21 01:54:32 ----RSHD---- C:\WINDOWS\system32\toolbar.dll
2011-05-21 01:54:32 ----RSHD---- C:\WINDOWS\system32\msxml4r.exe
2011-05-21 01:54:32 ----RSHD---- C:\WINDOWS\system32\msklive.dll
2011-05-21 01:54:32 ----RSHD---- C:\WINDOWS\system32\mseggrpid.dll
2011-05-21 01:54:32 ----RSHD---- C:\WINDOWS\system32\msegcompid.dll
2011-05-21 01:54:32 ----RSHD---- C:\WINDOWS\system32\mscache.dll
2011-05-21 01:54:32 ----RSHD---- C:\WINDOWS\system32\madise.dll
2011-05-21 01:54:32 ----RSHD---- C:\WINDOWS\system32\keyhost.exe
2011-05-21 01:54:32 ----RSHD---- C:\WINDOWS\system32\keyactivex.ocx
2011-05-21 01:54:32 ----RSHD---- C:\WINDOWS\system32\jeired.dll
2011-05-21 01:54:32 ----RSHD---- C:\WINDOWS\system32\iexplore.exe
2011-05-21 01:54:32 ----RSHD---- C:\WINDOWS\system32\ia.dll
2011-05-21 01:54:32 ----RSHD---- C:\WINDOWS\system32\gcasctrl.exe
2011-05-21 01:54:32 ----RSHD---- C:\WINDOWS\system32\egdial.dll
2011-05-21 01:54:32 ----RSHD---- C:\WINDOWS\system32\egdhtml_1027.dll
2011-05-21 01:54:32 ----RSHD---- C:\WINDOWS\system32\egdhtml_1026.dll
2011-05-21 01:54:32 ----RSHD---- C:\WINDOWS\system32\duel.exe
2011-05-21 01:54:32 ----RSHD---- C:\WINDOWS\system32\aupdate_uninstall.exe
2011-05-21 01:54:32 ----RSHD---- C:\WINDOWS\system32\aupdate.exe
2011-05-21 01:54:32 ----RSHD---- C:\WINDOWS\system32\adv.dll
2011-05-21 01:54:32 ----RSHD---- C:\WINDOWS\mscache.exe
2011-05-21 01:54:32 ----RSHD---- C:\WINDOWS\mscache.dll
2011-05-21 01:54:32 ----RSHD---- C:\WINDOWS\istsvc.exe
2011-05-21 01:54:32 ----RSHD---- C:\WINDOWS\exedialer.exe
2011-05-21 01:54:30 ----RSHD---- C:\WINDOWS\system32\winsrm32.dll
2011-05-21 01:54:30 ----RSHD---- C:\WINDOWS\system32\winenc32.dll
2011-05-21 01:54:30 ----RSHD---- C:\WINDOWS\system32\windowsie.dll
2011-05-21 01:54:30 ----RSHD---- C:\WINDOWS\system32\windec32.dll
2011-05-21 01:54:30 ----RSHD---- C:\WINDOWS\system32\iexplorr29.dll
2011-05-21 01:54:30 ----RSHD---- C:\WINDOWS\system32\iexplorr27.dll
2011-05-21 01:54:30 ----RSHD---- C:\WINDOWS\system32\iexplorr26.dll
2011-05-21 01:54:30 ----RSHD---- C:\WINDOWS\system32\iexplorr25.dll
2011-05-21 01:54:30 ----RSHD---- C:\WINDOWS\system32\iexplorr24.dll
2011-05-21 01:54:30 ----RSHD---- C:\WINDOWS\system32\iexplorr23.dll
2011-05-21 01:54:30 ----RSHD---- C:\WINDOWS\system32\iexplorr22.dll
2011-05-21 01:54:30 ----RSHD---- C:\WINDOWS\system32\iexplorr11.dll
2011-05-21 01:54:30 ----RSHD---- C:\WINDOWS\system32\egdhtml_1025.dll
2011-05-21 01:54:30 ----RSHD---- C:\WINDOWS\system32\egdhtml_1024.dll
2011-05-21 01:54:30 ----RSHD---- C:\WINDOWS\system32\egdhtml_1023.dll
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\wupdt.exe
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\winserv.exe
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\winobject.dll
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\wdskctl.exe
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\ts.exe
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\system32\winstart001.exe
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\system32\winstart.exe
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\system32\waeb.dll
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\system32\update_rsp.DLL
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\system32\update_removeold.dll
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\system32\update_hosts.dll
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\system32\update_com.dll
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\system32\update_bho.dll
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\system32\sbus.dll
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\system32\rsp001.dll
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\system32\rsp.dll
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\system32\install_all.dll
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\system32\ineb.dll
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\system32\iemsg.dll
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\system32\chgrgs.dll
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\system32\gws.dll
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\system32\drbr.dll
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\system32\bundler_mpb_sb.exe
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\system32\bmeb.dll
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\system32\bho001.dll
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\system32\bho.dll
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\system32\belop.dll
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\system32\atmtd.dll._
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\system32\atmtd.dll
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\system32\absnro.dll
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\system32\abeb.dll
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\systb.exe
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\systb.dll
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\ssk.exe
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\snbho.exe
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\rgrt.exe
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\pxckdlauninstall.exe
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\pxckdla.exe
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\offerssk.exe
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\invitessk.exe
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\id.exe
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\extract.exe
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\dsr.exe
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\dsr.dll
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\dlgb.exe
2011-05-21 01:54:29 ----RSHD---- C:\WINDOWS\dinst.exe
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\zopenssl.dll
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\yvsvga.sys
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\yvsvga.dll
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\yvprgb.dll
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\yvpp02.sys
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\yvpp01.sys
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\yvpp01.dll
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\yvbb01.dll
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\ydsvgd.sys
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\ydsvgd.dll
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\ycsvgd.sys
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\ycsvga.sys
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\ycsrgb.sys
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\xptptt.dll
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\xptp16.dll
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\xopptp.sys
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\xopptp.dll
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\xmsk64.sys
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\xmsk32.dll
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\xmm13g.dll
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\xdudtt.dll
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\xdpptp.sys
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\xcdmfree.dll
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\wz.dll
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\wxtwdx.dll
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\wtoolsb.dll
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\wndtx1.dll
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\winm32.dll
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\winlow.sys
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\winf44.dll
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\preload.ocx
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\msielink.dll
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\msiein.dll
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\internetfeatures.exe
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\iemonit.dll
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\iehost.exe
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\iehook.dll
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\iefeaturesversion.exe
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\iefeatures.exe
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\ieaccess2.dll
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\httper.dll
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\eghtmldialer.dll
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\dhtmlaccess.dll
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\system32\btiein.dll
2011-05-21 01:54:28 ----RSHD---- C:\WINDOWS\iehook.dll
2011-05-21 01:54:27 ----RSHD---- C:\WINDOWS\system32\wd.sys
2011-05-21 01:54:27 ----RSHD---- C:\WINDOWS\system32\w32_ss.exe
2011-05-21 01:54:27 ----RSHD---- C:\WINDOWS\system32\vtd_16.exe
2011-05-21 01:54:27 ----RSHD---- C:\WINDOWS\system32\vistax.dll
2011-05-21 01:54:27 ----RSHD---- C:\WINDOWS\system32\vdnt32.sys
2011-05-21 01:54:27 ----RSHD---- C:\WINDOWS\system32\vdmt16.sys
2011-05-21 01:54:27 ----RSHD---- C:\WINDOWS\system32\twpr32.dll
2011-05-21 01:54:27 ----RSHD---- C:\WINDOWS\system32\twpkad.dll
2011-05-21 01:54:27 ----RSHD---- C:\WINDOWS\system32\tcpwrk.dll
2011-05-21 01:54:27 ----RSHD---- C:\WINDOWS\system32\tcpr32.dll
2011-05-21 01:54:27 ----RSHD---- C:\WINDOWS\system32\tcpgdc.dll
2011-05-21 01:54:27 ----RSHD---- C:\WINDOWS\system32\tcpg4t.dll
2011-05-21 01:54:27 ----RSHD---- C:\WINDOWS\system32\svkvpn.sys
2011-05-21 01:54:27 ----RSHD---- C:\WINDOWS\system32\svkvpn.dll
2011-05-21 01:54:27 ----RSHD---- C:\WINDOWS\system32\svjvpn.sys
2011-05-21 01:54:27 ----RSHD---- C:\WINDOWS\system32\sndu32.dll
2011-05-21 01:54:27 ----RSHD---- C:\WINDOWS\system32\snda32.dll
2011-05-21 01:54:26 ----RSHD---- C:\WINDOWS\system32\smtapi.sys
2011-05-21 01:54:26 ----RSHD---- C:\WINDOWS\system32\sksdrvr2.sys
2011-05-21 01:54:26 ----RSHD---- C:\WINDOWS\system32\sksdll.dll
2011-05-21 01:54:26 ----RSHD---- C:\WINDOWS\system32\sks2drvr.sys
2011-05-21 01:54:26 ----RSHD---- C:\WINDOWS\system32\sertgs.dll
2011-05-21 01:54:26 ----RSHD---- C:\WINDOWS\system32\semd32.dll
2011-05-21 01:54:26 ----RSHD---- C:\WINDOWS\system32\se633mxx.dll
2011-05-21 01:54:26 ----RSHD---- C:\WINDOWS\system32\se500mdm.dll
2011-05-21 01:54:26 ----RSHD---- C:\WINDOWS\system32\sdmapi.sys
2011-05-21 01:54:26 ----RSHD---- C:\WINDOWS\system32\sdcard98.dll
2011-05-21 01:54:26 ----RSHD---- C:\WINDOWS\system32\satmmc.dll
2011-05-21 01:54:26 ----RSHD---- C:\WINDOWS\system32\satdll.dll
2011-05-21 01:54:26 ----RSHD---- C:\WINDOWS\system32\satau320.dll
2011-05-21 01:54:26 ----RSHD---- C:\WINDOWS\system32\rsdapi.dll
2011-05-21 01:54:26 ----RSHD---- C:\WINDOWS\system32\regp32.dll
2011-05-21 01:54:26 ----RSHD---- C:\WINDOWS\system32\rdrvr2.dll
2011-05-21 01:54:26 ----RSHD---- C:\WINDOWS\system32\qy.sys
2011-05-21 01:54:26 ----RSHD---- C:\WINDOWS\system32\qo.sys
2011-05-21 01:54:26 ----RSHD---- C:\WINDOWS\system32\qo.dll
2011-05-21 01:54:26 ----RSHD---- C:\WINDOWS\system32\psksds.dll
2011-05-21 01:54:26 ----D---- C:\WINDOWS\system32\skyx16.dll_old
2011-05-21 01:54:26 ----D---- C:\WINDOWS\system32\qz.sys_old
2011-05-21 01:54:26 ----D---- C:\WINDOWS\system32\qz.dll_old
2011-05-21 01:54:25 ----RSHD---- C:\WINDOWS\system32\prwsks.dll
2011-05-21 01:54:25 ----RSHD---- C:\WINDOWS\system32\prw76sks.sys
2011-05-21 01:54:25 ----RSHD---- C:\WINDOWS\system32\printpnp.dll
2011-05-21 01:54:25 ----RSHD---- C:\WINDOWS\system32\ppts16.dll
2011-05-21 01:54:25 ----RSHD---- C:\WINDOWS\system32\pptp32.dll
2011-05-21 01:54:25 ----RSHD---- C:\WINDOWS\system32\pptp24.sys
2011-05-21 01:54:25 ----RSHD---- C:\WINDOWS\system32\pptp16.dll
2011-05-21 01:54:25 ----RSHD---- C:\WINDOWS\system32\pdx.dll
2011-05-21 01:54:25 ----RSHD---- C:\WINDOWS\system32\openglss.dll
2011-05-21 01:54:25 ----RSHD---- C:\WINDOWS\system32\obbn13t.dll
2011-05-21 01:54:25 ----RSHD---- C:\WINDOWS\system32\nuclabdll.dll
2011-05-21 01:54:25 ----RSHD---- C:\WINDOWS\system32\nkunpack.dll
2011-05-21 01:54:25 ----RSHD---- C:\WINDOWS\system32\nkgfs.sys
2011-05-21 01:54:25 ----RSHD---- C:\WINDOWS\system32\nclabydll.dll
2011-05-21 01:54:25 ----RSHD---- C:\WINDOWS\system32\msplg7.dll
2011-05-21 01:54:25 ----RSHD---- C:\WINDOWS\system32\mmxf64.sys
2011-05-21 01:54:25 ----RSHD---- C:\WINDOWS\system32\mmxf32.dll
2011-05-21 01:54:25 ----RSHD---- C:\WINDOWS\system32\mmxeroxk.dll
2011-05-21 01:54:25 ----RSHD---- C:\WINDOWS\system32\mmx4xt.dll
2011-05-21 01:54:24 ----RSHD---- C:\WINDOWS\system32\mmx432.dll
2011-05-21 01:54:24 ----RSHD---- C:\WINDOWS\system32\mmx17g.dll
2011-05-21 01:54:24 ----RSHD---- C:\WINDOWS\system32\memlow.sys
2011-05-21 01:54:24 ----RSHD---- C:\WINDOWS\system32\mdfpro.dll
2011-05-21 01:54:24 ----RSHD---- C:\WINDOWS\system32\mcfg7a.dll
2011-05-21 01:54:24 ----RSHD---- C:\WINDOWS\system32\mcfcc4.dll
2011-05-21 01:54:24 ----RSHD---- C:\WINDOWS\system32\lsd_f3.dll
2011-05-21 01:54:24 ----RSHD---- C:\WINDOWS\system32\logon16x.dll
2011-05-21 01:54:24 ----RSHD---- C:\WINDOWS\system32\ljjhh.dll
2011-05-21 01:54:24 ----RSHD---- C:\WINDOWS\system32\lanmui.dll
2011-05-21 01:54:24 ----RSHD---- C:\WINDOWS\system32\lanh32.dll
2011-05-21 01:54:24 ----RSHD---- C:\WINDOWS\system32\klo5.sys
2011-05-21 01:54:24 ----RSHD---- C:\WINDOWS\system32\jsdapi.exe
2011-05-21 01:54:24 ----RSHD---- C:\WINDOWS\system32\iesdl4l.dll
2011-05-21 01:54:24 ----RSHD---- C:\WINDOWS\system32\ies4dll.dll
2011-05-21 01:54:24 ----RSHD---- C:\WINDOWS\system32\ideusr50.dll
2011-05-21 01:54:24 ----RSHD---- C:\WINDOWS\system32\hz.dll
2011-05-21 01:54:24 ----RSHD---- C:\WINDOWS\system32\hpprintx.dll
2011-05-21 01:54:24 ----RSHD---- C:\WINDOWS\system32\hm.sys
2011-05-21 01:54:24 ----RSHD---- C:\WINDOWS\system32\gdwxp3.dll
2011-05-21 01:54:24 ----RSHD---- C:\WINDOWS\system32\gdiwxp.dll
2011-05-21 01:54:23 ----RSHD---- C:\WINDOWS\system32\gatexkey.dll
2011-05-21 01:54:23 ----RSHD---- C:\WINDOWS\system32\fuxx32.dll
2011-05-21 01:54:23 ----RSHD---- C:\WINDOWS\system32\flashdrvr.dll
2011-05-21 01:54:23 ----RSHD---- C:\WINDOWS\system32\extxerox.dll
2011-05-21 01:54:23 ----RSHD---- C:\WINDOWS\system32\extfpu.dll
2011-05-21 01:54:23 ----RSHD---- C:\WINDOWS\system32\emldvc.dll
2011-05-21 01:54:23 ----RSHD---- C:\WINDOWS\system32\eexvpn.sys
2011-05-21 01:54:23 ----RSHD---- C:\WINDOWS\system32\eetvpn.sys
2011-05-21 01:54:23 ----RSHD---- C:\WINDOWS\system32\eetvpn.dll
2011-05-21 01:54:23 ----RSHD---- C:\WINDOWS\system32\dxtpdx.dll
2011-05-21 01:54:23 ----RSHD---- C:\WINDOWS\system32\dvd4free.dll
2011-05-21 01:54:23 ----RSHD---- C:\WINDOWS\system32\dvb06a.sys
2011-05-21 01:54:23 ----RSHD---- C:\WINDOWS\system32\dvb03a.sys
2011-05-21 01:54:22 ----RSHD---- C:\WINDOWS\system32\dvb03a.dll
2011-05-21 01:54:22 ----RSHD---- C:\WINDOWS\system32\drct16.dll
2011-05-21 01:54:22 ----RSHD---- C:\WINDOWS\system32\draw32.dll
2011-05-21 01:54:22 ----RSHD---- C:\WINDOWS\system32\docent2.dll
2011-05-21 01:54:22 ----RSHD---- C:\WINDOWS\system32\docent0.dll
2011-05-21 01:54:22 ----RSHD---- C:\WINDOWS\system32\directut.dll
2011-05-21 01:54:22 ----RSHD---- C:\WINDOWS\system32\directpt.dll
2011-05-21 01:54:22 ----RSHD---- C:\WINDOWS\system32\debugg.dll
2011-05-21 01:54:21 ----RSHD---- C:\WINDOWS\system32\ddirectz.dll
2011-05-21 01:54:21 ----RSHD---- C:\WINDOWS\system32\cz.dll
2011-05-21 01:54:21 ----RSHD---- C:\WINDOWS\system32\cm.dll
2011-05-21 01:54:21 ----RSHD---- C:\WINDOWS\system32\cert32.dll
2011-05-21 01:54:21 ----RSHD---- C:\WINDOWS\system32\cdscsix3.dll
2011-05-21 01:54:21 ----RSHD---- C:\WINDOWS\system32\c4.sys
2011-05-21 01:54:21 ----RSHD---- C:\WINDOWS\system32\c3.sys
2011-05-21 01:54:21 ----RSHD---- C:\WINDOWS\system32\c3.dll
2011-05-21 01:54:21 ----RSHD---- C:\WINDOWS\system32\bt848rom.dll
2011-05-21 01:54:21 ----RSHD---- C:\WINDOWS\system32\boot32.sys
2011-05-21 01:54:21 ----RSHD---- C:\WINDOWS\system32\bmtdhh.dll
2011-05-21 01:54:20 ----RSHD---- C:\WINDOWS\system32\support.exe
2011-05-21 01:54:20 ----RSHD---- C:\WINDOWS\system32\msxver64.sqr
2011-05-21 01:54:20 ----RSHD---- C:\WINDOWS\system32\ie.dll
2011-05-21 01:54:20 ----RSHD---- C:\WINDOWS\system32\idleui.dll
2011-05-21 01:54:20 ----RSHD---- C:\WINDOWS\system32\fwntoolbar.dll
2011-05-21 01:54:20 ----RSHD---- C:\WINDOWS\system32\ftapp.dll
2011-05-21 01:54:20 ----RSHD---- C:\WINDOWS\system32\flt.dll
2011-05-21 01:54:20 ----RSHD---- C:\WINDOWS\system32\flcp.dll
2011-05-21 01:54:20 ----RSHD---- C:\WINDOWS\system32\axxt32.dll
2011-05-21 01:54:20 ----RSHD---- C:\WINDOWS\system32\axdebugl.dll
2011-05-21 01:54:20 ----RSHD---- C:\WINDOWS\system32\avpx64.sys
2011-05-21 01:54:20 ----RSHD---- C:\WINDOWS\system32\avpx32.sys
2011-05-21 01:54:20 ----RSHD---- C:\WINDOWS\system32\avpx32.dll
2011-05-21 01:54:20 ----RSHD---- C:\WINDOWS\system32\avpp32.dll
2011-05-21 01:54:20 ----RSHD---- C:\WINDOWS\system32\avpi32.dll
2011-05-21 01:54:20 ----RSHD---- C:\WINDOWS\system32\avpe32.dll
2011-05-21 01:54:20 ----RSHD---- C:\WINDOWS\system32\avload32.dll
2011-05-21 01:54:20 ----RSHD---- C:\WINDOWS\savestartdate.exe
2011-05-21 01:54:20 ----RSHD---- C:\WINDOWS\frsk.exe
2011-05-21 01:54:19 ----RSHD---- C:\WINDOWS\system32\zz.dll
2011-05-21 01:54:19 ----RSHD---- C:\WINDOWS\system32\trk.dll
2011-05-21 01:54:19 ----RSHD---- C:\WINDOWS\system32\td1.dll
2011-05-21 01:54:19 ----RSHD---- C:\WINDOWS\system32\sysldr.dll
2011-05-21 01:54:19 ----RSHD---- C:\WINDOWS\system32\ss32.dll
2011-05-21 01:54:19 ----RSHD---- C:\WINDOWS\system32\ss.dll
2011-05-21 01:54:19 ----RSHD---- C:\WINDOWS\system32\pdfzzy.dll
2011-05-21 01:54:19 ----RSHD---- C:\WINDOWS\system32\pavb1u2.exe
2011-05-21 01:54:19 ----RSHD---- C:\WINDOWS\system32\otw0i.dll
2011-05-21 01:54:19 ----RSHD---- C:\WINDOWS\system32\ofrg.dll
2011-05-21 01:54:19 ----RSHD---- C:\WINDOWS\system32\n3tpa1p.dll
2011-05-21 01:54:19 ----RSHD---- C:\WINDOWS\system32\mpz300.dll
2011-05-21 01:54:19 ----RSHD---- C:\WINDOWS\system32\mmview_101.dll
2011-05-21 01:54:19 ----RSHD---- C:\WINDOWS\system32\mbr32.dll
2011-05-21 01:54:19 ----RSHD---- C:\WINDOWS\system32\lwz.dll
2011-05-21 01:54:19 ----RSHD---- C:\WINDOWS\system32\lstb4drc.exe
2011-05-21 01:54:19 ----RSHD---- C:\WINDOWS\system32\lstb4drc.dll
2011-05-21 01:54:19 ----RSHD---- C:\WINDOWS\system32\in10b6s.dll
2011-05-21 01:54:19 ----RSHD---- C:\WINDOWS\system32\im64.dll
2011-05-21 01:54:19 ----RSHD---- C:\WINDOWS\system32\gr02.dll
2011-05-21 01:54:19 ----RSHD---- C:\WINDOWS\system32\gold2.dll
2011-05-21 01:54:18 ----RSHD---- C:\WINDOWS\woinstall.exe
2011-05-21 01:54:18 ----RSHD---- C:\WINDOWS\system32\links.dll
2011-05-21 01:54:18 ----RSHD---- C:\WINDOWS\system32\keymap.dll
2011-05-21 01:54:18 ----RSHD---- C:\WINDOWS\system32\goupdate.exe
2011-05-21 01:54:18 ----RSHD---- C:\WINDOWS\system32\fone.dll
2011-05-21 01:54:18 ----RSHD---- C:\WINDOWS\system32\favorite.dll
2011-05-21 01:54:18 ----RSHD---- C:\WINDOWS\system32\favman.dll
2011-05-21 01:54:18 ----RSHD---- C:\WINDOWS\system32\favboot.dll
2011-05-21 01:54:18 ----RSHD---- C:\WINDOWS\system32\fastseekertoolbar.dll
2011-05-21 01:54:18 ----RSHD---- C:\WINDOWS\system32\f1.dll
2011-05-21 01:54:18 ----RSHD---- C:\WINDOWS\system32\ezstub.exe
2011-05-21 01:54:18 ----RSHD---- C:\WINDOWS\system32\ezpopstub.exe
2011-05-21 01:54:18 ----RSHD---- C:\WINDOWS\system32\expup.exe
2011-05-21 01:54:18 ----RSHD---- C:\WINDOWS\system32\expext.dll
2011-05-21 01:54:18 ----RSHD---- C:\WINDOWS\system32\estartlinkrotater.exe
2011-05-21 01:54:18 ----RSHD---- C:\WINDOWS\system32\eros.exe
2011-05-21 01:54:18 ----RSHD---- C:\WINDOWS\system32\emesx.dll
2011-05-21 01:54:18 ----RSHD---- C:\WINDOWS\system32\dlh0st.dll
2011-05-21 01:54:18 ----RSHD---- C:\WINDOWS\system32\casldr.dll
2011-05-21 01:54:18 ----RSHD---- C:\WINDOWS\system32\atpartners.dll
2011-05-21 01:54:18 ----RSHD---- C:\WINDOWS\system32\arb1tal.dll
2011-05-21 01:54:18 ----RSHD---- C:\WINDOWS\system32\aess2.dll
2011-05-21 01:54:18 ----RSHD---- C:\WINDOWS\system32\_epnt.sys
2011-05-21 01:54:18 ----RSHD---- C:\WINDOWS\goupdate.exe
2011-05-21 01:54:18 ----RSHD---- C:\WINDOWS\fastseekersetupv2.ocx
2011-05-21 01:54:18 ----RSHD---- C:\WINDOWS\fastseekersetup.ocx
2011-05-21 01:54:18 ----RSHD---- C:\WINDOWS\ezinstall.exe
2011-05-21 01:54:17 ----RSHD---- C:\WINDOWS\system32\urncbc.dll
2011-05-21 01:54:17 ----RSHD---- C:\WINDOWS\system32\urncb.dll
2011-05-21 01:54:17 ----RSHD---- C:\WINDOWS\system32\skytown.exe
2011-05-21 01:54:17 ----RSHD---- C:\WINDOWS\system32\rmashlex.dll
2011-05-21 01:54:17 ----RSHD---- C:\WINDOWS\system32\ptech.exe
2011-05-21 01:54:17 ----RSHD---- C:\WINDOWS\system32\pruttct.exe
2011-05-21 01:54:17 ----RSHD---- C:\WINDOWS\system32\prutsct.exe
2011-05-21 01:54:17 ----RSHD---- C:\WINDOWS\system32\prutpct.exe
2011-05-21 01:54:17 ----RSHD---- C:\WINDOWS\system32\nvrcr32.dll
2011-05-21 01:54:17 ----RSHD---- C:\WINDOWS\system32\iniwin32.dll
2011-05-21 01:54:17 ----RSHD---- C:\WINDOWS\system32\iebhos.dll
2011-05-21 01:54:17 ----RSHD---- C:\WINDOWS\system32\filgmo.exe
2011-05-21 01:54:17 ----RSHD---- C:\WINDOWS\system32\ei.exe
2011-05-21 01:54:17 ----RSHD---- C:\WINDOWS\system32\easywww3.exe
2011-05-21 01:54:17 ----RSHD---- C:\WINDOWS\system32\easywww2.exe
2011-05-21 01:54:17 ----RSHD---- C:\WINDOWS\system32\easywww.exe
2011-05-21 01:54:17 ----RSHD---- C:\WINDOWS\system32\dreampopper.dll
2011-05-21 01:54:17 ----RSHD---- C:\WINDOWS\system32\bkmsf32.dat
2011-05-21 01:54:17 ----RSHD---- C:\WINDOWS\system32\askearth17.exe
2011-05-21 01:54:17 ----RSHD---- C:\WINDOWS\redirect5.exe
2011-05-21 01:54:17 ----RSHD---- C:\WINDOWS\pi1.exe
2011-05-21 01:54:17 ----RSHD---- C:\WINDOWS\iewwwint.exe
2011-05-21 01:54:17 ----RSHD---- C:\WINDOWS\iewww.exe
2011-05-21 01:54:17 ----RSHD---- C:\WINDOWS\ewupdater.exe
2011-05-21 01:54:17 ----RSHD---- C:\WINDOWS\easywww3.exe
2011-05-21 01:54:17 ----RSHD---- C:\WINDOWS\easywww2.exe
2011-05-21 01:54:17 ----RSHD---- C:\WINDOWS\easywww.exe
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\winnj32.exe
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\winmc.exe
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\system32\rundnm.exe
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\system32\newmsrdk2.zip
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\system32\hookpopup.dll
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\system32\dun.exe
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\system32\dolsp.dll
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\system32\dialeroffline.dll
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\system32\diabolo.exe
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\system32\deltaclick.dll
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\system32\customtoolbar.dll
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\system32\crocopop32.exe
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\system32\comload.dll
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\system32\cdsync.dll
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\system32\cdlsp.dll
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\system32\cd_swf.dll
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\system32\cd_load.exe
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\system32\cd_htm.dll
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\system32\cd_gif.dll
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\system32\cd_clint.exe
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\system32\calsp.dll
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\syslr.exe
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\syskr.exe
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\sysjq.exe
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\sysea.exe
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\sys.reg
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\sistem.exe
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\sdkrr32.exe
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\dsearch1.bin
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\dsearch.bin
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\dlder.exe
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\dhupdt.exe
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\dhun.exe
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\dhsvr.exe
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\dhsigned.ocx
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\dhp2.dll
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\dhp.dll
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\dhkw1.bin
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\dhkw.bin
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\dhdomp1.bin
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\dhdomp.bin
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\dhdom1.bin
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\dhdom.bin
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\dhbrwsr.exe
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\dhbrowser.exe
2011-05-21 01:54:16 ----RSHD---- C:\WINDOWS\dealhlpr.dll
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\system32\xxxvideo.hta
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\system32\xplugin.dll
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\system32\word10.dll
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\sdkev.exe
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\qttasks.exe
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\olehelp.exe
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\ntyo32.exe
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\ntyk32.exe
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\ntwn.exe
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\ntwg.exe
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\navext.dll
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\my.css
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\mszv32.exe
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\msnc32.exe
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\msconfd.dll
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\mfcui32.exe
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\mfckb.exe
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\mfcbm32.dll
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\kk8pwxm634.exe
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\ipyx32.exe
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\ipog.dll
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\image.dll
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\iexplorer.exe
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\help_ecc.dll
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\help_dcc.dll
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\fonts\msoffice.hta
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\dpe.dll
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\default.css
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\d3zg.exe
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\d3ue.exe
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\d3nr32.exe
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\d3fl32.exe
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\d3fd32.exe
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\d3cq.exe
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\ctrlpan.dll
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\crvl.exe
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\bipw.exe
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\avpcc.dll
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\atlrl32.dll
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\atlfs32.exe
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\appwn32.exe
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\appsh.exe
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\apivt.exe
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\apijn32.exe
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\apigj.exe
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\apifb.exe
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\apiac.exe
2011-05-21 01:54:15 ----RSHD---- C:\WINDOWS\addkc32.exe
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\winyw32.exe
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\winres.dll
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\winproc32.exe
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\winns32.exe
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\winlo.exe
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\winlink.dll
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\winga.exe
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\wer1306.dll
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\webinfo.dll
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\wcadw.dll
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\toolband.dll
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\sys_ext.dll
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\submithook.dll
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\sqlbgb.dll
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\searchaddon.dll
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\sdkly.exe
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\sdkhb32.exe
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\sdkdh.exe
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\pnkeb.dll
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\opc.dll
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\olehelp.exe
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\oipa.dll
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\oifhhio.dll
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\ntdx.exe
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\netjh32.exe
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\navext.dll
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\mupdate.exe
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\mtwirl32.dll
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\msxmlpp.dll
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\msupdate.exe
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\mssz32.dll
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\msspi.dll
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\mssearch.dll
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\msph32.exe
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\msiesh.dll
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\mshelper.dll
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\msconfd.dll
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\mid.dll
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\mgs_32.dll
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\mfcuo.exe
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\mfcqc32.exe
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\mfcgt32.exe
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\kncjmlb.dll
2011-05-21 01:54:14 ----RSHD---- C:\WINDOWS\system32\kha.dll
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\jehmbyxrubdb.dll
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\ipst32.exe
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\ippy.exe
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\iphj32.exe
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\ipgs.exe
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\iewe32.exe
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\ieug32.exe
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\ietoolbar.dll
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\iehost34.exe
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\iefy.exe
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\iefi.exe
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\iefeatsl.dll
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\hlmk.dll
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\googlems.dll
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\gln.dll
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\gejafa.dll
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\gegnba.dll
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\famcff.dll
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\excel10.dll
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\dxm8vb.dll
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\dreplace.dll
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\dnsrelay.dll
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\dnserr.dll
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\dnse.dll
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\delj.dll
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\d3ul32.exe
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\d3gj.exe
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\d3fm.exe
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\ctrlpan.dll
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\ctfmon32.exe
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\crxa.exe
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\crsw32.exe
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\crko.exe
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\criticalupdater.exe
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\crcz.exe
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\crby32.exe
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\coolwebsearch-info.dll
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\bpln.dll
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\bootconf.exe
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\avpcc.dll
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\autosearch.dll
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\atlpv32.exe
2011-05-21 01:54:13 ----RSHD---- C:\WINDOWS\system32\atlkt32.exe
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\system32\msongn.exe
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\system32\msobfl.dll
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\system32\msnkmi.dll
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\system32\msncjk.dll
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\system32\msmm.exe
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\system32\msmdld.DLL
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\system32\msmc.exe
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\system32\mslefh.dll
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\system32\mskpkc.dll
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\system32\mskhhe.dll
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\system32\mskehb.dll
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\system32\mskceo.dll
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\system32\msjfbl.dll
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\system32\msibkd.dll
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\system32\msgdmf.exe
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\system32\msfaol.dll
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\system32\msenfh.dll
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\system32\mseffm.dll
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\system32\msedah.dll
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\system32\atlhy.exe
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\system32\astctl32.ocx
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\system32\astctl32.dll
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\system32\appoe32.exe
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\system32\appjc32.exe
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\system32\appis32.exe
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\system32\appio.exe
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\system32\apivy.exe
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\system32\apioe.exe
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\system32\apica.exe
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\system32\addwh32.exe
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\system32\addgp32.exe
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\system32\adddx.dll
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\system32\1.00.07.dll
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\smss.exe
2011-05-21 01:54:12 ----RSHD---- C:\WINDOWS\conscorr.exe
2011-05-21 01:54:11 ----RSHD---- C:\WINDOWS\uptodate.exe
2011-05-21 01:54:11 ----RSHD---- C:\WINDOWS\system32\mseclk.dll
2011-05-21 01:54:11 ----RSHD---- C:\WINDOWS\system32\msdlgk.dll
2011-05-21 01:54:11 ----RSHD---- C:\WINDOWS\system32\msdaim.dll
2011-05-21 01:54:11 ----RSHD---- C:\WINDOWS\system32\mscpbo.exe
2011-05-21 01:54:11 ----RSHD---- C:\WINDOWS\system32\mscdka.dll
2011-05-21 01:54:11 ----RSHD---- C:\WINDOWS\system32\msccof.exe
2011-05-21 01:54:11 ----RSHD---- C:\WINDOWS\system32\ipv6mons.dll
2011-05-21 01:54:11 ----RSHD---- C:\WINDOWS\system32\ietie.dll
2011-05-21 01:54:11 ----RSHD---- C:\WINDOWS\system32\ie_clrsch.dll
2011-05-21 01:54:11 ----RSHD---- C:\WINDOWS\system32\disable1.dll
2011-05-21 01:54:11 ----RSHD---- C:\WINDOWS\system32\disable.dll
2011-05-21 01:54:11 ----RSHD---- C:\WINDOWS\system32\ctbhooks.dll
2011-05-21 01:54:11 ----RSHD---- C:\WINDOWS\system32\csie.dll
2011-05-21 01:54:11 ----RSHD---- C:\WINDOWS\system32\bpv2t.dll
2011-05-21 01:54:11 ----RSHD---- C:\WINDOWS\system32\bpv2s.dll
2011-05-21 01:54:11 ----RSHD---- C:\WINDOWS\system32\bpv1a.dll
2011-05-21 01:54:11 ----RSHD---- C:\csrss.exe
2011-05-21 01:54:10 ----RSHD---- C:\WINDOWS\system32\stlbupdt.dll
2011-05-21 01:54:10 ----RSHD---- C:\WINDOWS\system32\stlbdist.dll
2011-05-21 01:54:10 ----RSHD---- C:\WINDOWS\system32\stlbad123.dll
2011-05-21 01:54:10 ----RSHD---- C:\WINDOWS\system32\rundll16.dll
2011-05-21 01:54:10 ----RSHD---- C:\WINDOWS\system32\rsstoolbar.dll
2011-05-21 01:54:10 ----RSHD---- C:\WINDOWS\system32\rem00001.dll
2011-05-21 01:54:10 ----RSHD---- C:\WINDOWS\system32\quicklaunchie.dll
2011-05-21 01:54:10 ----RSHD---- C:\WINDOWS\system32\msiefr40.dll
2011-05-21 01:54:10 ----RSHD---- C:\WINDOWS\system32\inetp60.dll
2011-05-21 01:54:10 ----RSHD---- C:\WINDOWS\system32\highlighthelper.dll
2011-05-21 01:54:10 ----RSHD---- C:\WINDOWS\system32\broweraidtoolbar.dll
2011-05-21 01:54:10 ----RSHD---- C:\WINDOWS\rundll16.dll
2011-05-21 01:54:10 ----RSHD---- C:\WINDOWS\oo4.dll
2011-05-21 01:54:10 ----RSHD---- C:\WINDOWS\cfg32p.dll
2011-05-21 01:54:10 ----RSHD---- C:\WINDOWS\bxxs5.dll
2011-05-21 01:54:10 ----RSHD---- C:\WINDOWS\bsx5.dll
2011-05-21 01:54:10 ----RSHD---- C:\WINDOWS\bs3.dll
2011-05-21 01:54:10 ----RSHD---- C:\WINDOWS\bs2.dll
2011-05-21 01:54:09 ----RSHD---- C:\WINDOWS\system32\unstsa2.exe
2011-05-21 01:54:09 ----RSHD---- C:\WINDOWS\system32\oo4.dll
2011-05-21 01:54:09 ----RSHD---- C:\WINDOWS\system32\iesearchbar.dll
2011-05-21 01:54:09 ----RSHD---- C:\WINDOWS\system32\bxxs5.dll
2011-05-21 01:54:09 ----RSHD---- C:\WINDOWS\system32\bxsx5.dll
2011-05-21 01:54:09 ----RSHD---- C:\WINDOWS\system32\bsx5.dll
2011-05-21 01:54:09 ----RSHD---- C:\WINDOWS\system32\bs3.dll
2011-05-21 01:54:09 ----RSHD---- C:\WINDOWS\system32\bs2.dll
2011-05-21 01:54:09 ----RSHD---- C:\WINDOWS\system32\anaamon.dll
2011-05-21 01:54:09 ----RSHD---- C:\WINDOWS\system32\acd.dll
2011-05-21 01:54:09 ----RSHD---- C:\WINDOWS\system32\5_0_1browserhelper5.dll
2011-05-21 01:54:02 ----RSHD---- C:\WINDOWS\system32\3_0_1browserhelper3.dll
2011-05-21 01:54:02 ----RSHD---- C:\WINDOWS\system32\2_0_1browserhelper2.dll
2011-05-21 01:54:01 ----RSHD---- C:\WINDOWS\system32\bdeverify.dll
2011-05-21 01:54:01 ----RSHD---- C:\WINDOWS\system32\bdesecureinstall.exe
2011-05-21 01:54:00 ----RSHD---- C:\WINDOWS\zeta.exe
2011-05-21 01:54:00 ----RSHD---- C:\WINDOWS\system32\vx3x.nls
2011-05-21 01:54:00 ----RSHD---- C:\WINDOWS\system32\vx3.nls
2011-05-21 01:54:00 ----RSHD---- C:\WINDOWS\system32\vx2x.nls
2011-05-21 01:54:00 ----RSHD---- C:\WINDOWS\system32\vx2.nls
2011-05-21 01:54:00 ----RSHD---- C:\WINDOWS\system32\vx1x.nls
2011-05-21 01:54:00 ----RSHD---- C:\WINDOWS\system32\vx1.nls
2011-05-21 01:54:00 ----RSHD---- C:\WINDOWS\system32\vx0x.nls
2011-05-21 01:54:00 ----RSHD---- C:\WINDOWS\system32\vx0.nls
2011-05-21 01:54:00 ----RSHD---- C:\WINDOWS\system32\nvms.dll
2011-05-21 01:54:00 ----RSHD---- C:\WINDOWS\system32\netut80ex.vxd
2011-05-21 01:54:00 ----RSHD---- C:\WINDOWS\system32\msxct.exe
2011-05-21 01:54:00 ----RSHD---- C:\WINDOWS\system32\msexreg.exe
2011-05-21 01:54:00 ----RSHD---- C:\WINDOWS\system32\mscb.dll
2011-05-21 01:54:00 ----RSHD---- C:\WINDOWS\system32\bdesecureinstall.cab
2011-05-21 01:54:00 ----RSHD---- C:\WINDOWS\system32\bdeinstall.exe
2011-05-21 01:54:00 ----RSHD---- C:\WINDOWS\system32\bdeinsta2.dll
2011-05-21 01:54:00 ----RSHD---- C:\WINDOWS\system32\bdefdi.dll
2011-05-21 01:54:00 ----RSHD---- C:\WINDOWS\system32\bdedownloader.dll
2011-05-21 01:54:00 ----RSHD---- C:\WINDOWS\system32\bdedata2.dll
2011-05-21 01:54:00 ----RSHD---- C:\WINDOWS\msxct.exe
2011-05-21 01:54:00 ----RSHD---- C:\WINDOWS\exul.exe
2011-05-21 01:54:00 ----RSHD---- C:\WINDOWS\exdl.exe
2011-05-21 01:54:00 ----RSHD---- C:\WINDOWS\exclean.exe
2011-05-21 01:54:00 ----RSHD---- C:\WINDOWS\bbchk.exe
2011-05-21 01:54:00 ----RSHD---- C:\WINDOWS\bargain4.exe
2011-05-21 01:54:00 ----RSHD---- C:\WINDOWS\ahcb.exe
2011-05-21 01:53:59 ----RSHD---- C:\WINDOWS\system32\winxp.exeopenopenopenopen
2011-05-21 01:53:59 ----RSHD---- C:\WINDOWS\system32\winxp.exeopenopenopen
2011-05-21 01:53:59 ----RSHD---- C:\WINDOWS\system32\winxp.exeopenopen
2011-05-21 01:53:59 ----RSHD---- C:\WINDOWS\system32\winxp.exeopen
2011-05-21 01:53:59 ----RSHD---- C:\WINDOWS\system32\winxp.exe
2011-05-21 01:53:59 ----RSHD---- C:\WINDOWS\system32\msbe.dll
2011-05-21 01:53:59 ----RSHD---- C:\WINDOWS\system32\mqexdlm.srg
2011-05-21 01:53:59 ----RSHD---- C:\WINDOWS\system32\javexulm.vxd
2011-05-21 01:53:59 ----RSHD---- C:\WINDOWS\system32\javex80.vxd
2011-05-21 01:53:59 ----RSHD---- C:\WINDOWS\system32\instsrv.exe
2011-05-21 01:53:59 ----RSHD---- C:\WINDOWS\system32\exul3.exe
2011-05-21 01:53:59 ----RSHD---- C:\WINDOWS\system32\exul1.exe
2011-05-21 01:53:59 ----RSHD---- C:\WINDOWS\system32\exul.exe
2011-05-21 01:53:59 ----RSHD---- C:\WINDOWS\system32\exdl3.exe
2011-05-21 01:53:59 ----RSHD---- C:\WINDOWS\system32\exdl2.exe
2011-05-21 01:53:59 ----RSHD---- C:\WINDOWS\system32\exdl1.exe
2011-05-21 01:53:59 ----RSHD---- C:\WINDOWS\system32\exdl0.exe
2011-05-21 01:53:59 ----RSHD---- C:\WINDOWS\system32\exdl.exe
2011-05-21 01:53:59 ----RSHD---- C:\WINDOWS\system32\exclean.exe
2011-05-21 01:53:59 ----RSHD---- C:\WINDOWS\system32\bbchk.exe
2011-05-21 01:53:59 ----RSHD---- C:\WINDOWS\system32\angelex.exe
2011-05-21 01:53:58 ----RSHD---- C:\WINDOWS\system32\wintems.exe
2011-05-21 01:53:58 ----RSHD---- C:\WINDOWS\system32\winhost.exe
2011-05-21 01:53:58 ----RSHD---- C:\WINDOWS\system32\wingo.exeopenopen
2011-05-21 01:53:58 ----RSHD---- C:\WINDOWS\system32\wingo.exeopen
2011-05-21 01:53:58 ----RSHD---- C:\WINDOWS\system32\wingo.exe
2011-05-21 01:53:58 ----RSHD---- C:\WINDOWS\system32\windll.exeopenopen
2011-05-21 01:53:58 ----RSHD---- C:\WINDOWS\system32\windll.exeopen
2011-05-21 01:53:58 ----RSHD---- C:\WINDOWS\system32\windll.exe
2011-05-21 01:53:58 ----RSHD---- C:\WINDOWS\system32\windirect.exe
2011-05-21 01:53:58 ----RSHD---- C:\WINDOWS\system32\win32lib.exe
2011-05-21 01:53:58 ----RSHD---- C:\WINDOWS\system32\sys_xp.exeopenopen
2011-05-21 01:53:58 ----RSHD---- C:\WINDOWS\system32\sys_xp.exeopen
2011-05-21 01:53:58 ----RSHD---- C:\WINDOWS\system32\sys_xp.exe
2011-05-21 01:53:58 ----RSHD---- C:\WINDOWS\system32\re_file.exe
2011-05-21 01:53:58 ----RSHD---- C:\WINDOWS\system32\loader_name.exeopenopen
2011-05-21 01:53:58 ----RSHD---- C:\WINDOWS\system32\loader_name.exeopen
2011-05-21 01:53:58 ----RSHD---- C:\WINDOWS\system32\loader_name.exe
2011-05-21 01:53:58 ----RSHD---- C:\WINDOWS\system32\hldrrr.exe
2011-05-21 01:53:58 ----RSHD---- C:\WINDOWS\system32\drvddll.exeopenopen
2011-05-21 01:53:58 ----RSHD---- C:\WINDOWS\system32\drvddll.exeopen
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\unast.exe
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\system32\tfde.dll
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\system32\safesearch.dll
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\system32\poller.exe
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\system32\msipcsv.exe
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\system32\msinfosys.dll
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\system32\ipclient.dll
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\system32\ipcclient.dll
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\system32\intfaxui.exe
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\system32\htmdeng.exe
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\system32\drvddll.exe
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\system32\drpmon.dll
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\system32\doriot.exe
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\system32\dlgli.exe
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\system32\bawindo.exeopenopen
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\system32\bawindo.exeopen
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\system32\bawindo.exe
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\system32\ast.exe
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\system32\anti_troj.exe
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\system32\anadscb.ocx
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\system32\anadsc.ocx
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\system32\amcis3.dll
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\system32\amcis2.dll
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\system32\amcis.dll
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\system32\advertcontrolxcontrol.ocx
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\system32\advert.dll
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\system32\adimage.dll
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\system32\_dll.exe
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\svcproc.exe
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\pool32.exe
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\nail.exe
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\ms spool32.exe
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\ms spool32.dat
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\ib.exe
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\bolger.dll
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\aurorahandler.dll
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\aurora.exe
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\ast.exe
2011-05-21 01:53:57 ----RSHD---- C:\WINDOWS\ac.aut
2011-05-21 01:53:57 ----RSHD---- C:\ntldr.exe
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\zserv.dll
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\voiceip.dll
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\system32\xxvyaj.exe
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\system32\wbtvsffd.exe
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\system32\susp_reco.exe
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\system32\stmtreco.exe
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\system32\stcloader.exe
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\system32\randreco.exe
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\system32\polau2c.exe
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\system32\nnmzoq.exe
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\system32\ln_reco.exe
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\system32\laziqn.exe
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\system32\imgiant.dll
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\system32\farmmext.exe
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\system32\ezxiiyv.exe
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\system32\bik.exe
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\system32\bdle4012.exe
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\system32\atmon.exe
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\system32\aplsp.dll
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\system32\7search.dll
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\system32\2searchinstaller.exe
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\system32\2ndsrch.dll
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\system32\007guard.exe
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\speeryox.dll
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\speer2.dll
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\pynix.dll
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\mxtarget.dll
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\morphacl.dll
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\imguninst.exe
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\imgiant.dll
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\farmmext.exe
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\ejgekgpq.ini
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\druninst.exe
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\dlmax.dll
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\ceres.dll
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\buddy.exe
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\btgrab.dll
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\biprep.exe
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\bi.dll
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\banner.dll
2011-05-21 01:53:56 ----RSHD---- C:\WINDOWS\abiuninst.htm
2011-05-21 01:53:55 ----RSHD---- C:\winstall.exe
2011-05-21 01:53:55 ----RSHD---- C:\WINDOWS\system32\twain32.dll
2011-05-21 01:53:55 ----RSHD---- C:\WINDOWS\system32\msietk1020.dll
2011-05-21 01:53:55 ----RSHD---- C:\WINDOWS\system32\msiebho.dll
2011-05-21 01:53:55 ----RSHD---- C:\WINDOWS\system32\ginuerep.dll
2011-05-21 01:53:55 ----RSHD---- C:\WINDOWS\system32\dxmpp.dll
2011-05-21 01:53:55 ----RSHD---- C:\WINDOWS\system32\2020search2.dll
2011-05-21 01:53:55 ----RSHD---- C:\WINDOWS\system32\2020search.dll
2011-05-21 01:53:55 ----RSHD---- C:\WINDOWS\mssvr.exe
2011-05-21 01:53:55 ----RSHD---- C:\WINDOWS\ihsn.exe
2011-05-21 01:53:55 ----RSHD---- C:\WINDOWS\fejgl.exe
2011-05-21 01:53:55 ----RSHD---- C:\WINDOWS\2020search2.dll
2011-05-21 01:53:55 ----RSHD---- C:\WINDOWS\2020search.dll
2011-05-21 01:53:55 ----RSHD---- C:\WINDOWS\2020install.exe
2011-05-21 01:53:54 ----RSHD---- C:\WINDOWS\xpupdate.exe
2011-05-21 01:53:54 ----RSHD---- C:\WINDOWS\system32\wnsinttr.exe
2011-05-21 01:53:54 ----RSHD---- C:\WINDOWS\system32\wnsintsv.exe
2011-05-21 01:53:54 ----RSHD---- C:\WINDOWS\system32\wnscpit.exe
2011-05-21 01:53:54 ----RSHD---- C:\WINDOWS\system32\wnscpcc.exe
2011-05-21 01:53:54 ----RSHD---- C:\WINDOWS\system32\wnsapisv.exe
2011-05-21 01:53:54 ----RSHD---- C:\WINDOWS\system32\wnsapisu.exe
2011-05-21 01:53:54 ----RSHD---- C:\WINDOWS\system32\wintsvsu.exe
2011-05-21 01:53:54 ----RSHD---- C:\WINDOWS\system32\winservs.exe
2011-05-21 01:53:54 ----RSHD---- C:\WINDOWS\system32\winservn.exe
2011-05-21 01:53:54 ----RSHD---- C:\WINDOWS\system32\ndrv.exe
2011-05-21 01:53:54 ----RSHD---- C:\WINDOWS\system32\ndrv.dll
2011-05-21 01:53:53 ----RSHD---- C:\WINDOWS\system32\winutil4.dll
2011-05-21 01:53:53 ----RSHD---- C:\WINDOWS\system32\winctl4.dll
2011-05-21 01:53:53 ----RSHD---- C:\WINDOWS\system32\fk.dll
2011-05-21 01:53:53 ----RSHD---- C:\WINDOWS\system32\filekiller.dll
2011-05-21 01:53:52 ----RSHD---- C:\WINDOWS\system32\winupd.exe
2011-05-21 01:53:52 ----RSHD---- C:\WINDOWS\system32\winsvc.exe
2011-05-21 01:53:52 ----RSHD---- C:\WINDOWS\system32\winctl3.ocx
2011-05-21 01:53:52 ----RSHD---- C:\WINDOWS\system32\svchost32.exe
2011-05-21 01:53:52 ----RSHD---- C:\WINDOWS\svchost.exe
2011-05-21 01:53:52 ----RSHD---- C:\WINDOWS\rundll16.exe
2011-05-21 01:53:52 ----RSHD---- C:\WINDOWS\explore.exe
2011-05-21 01:53:52 ----RSHD---- C:\WINDOWS\csrss.exe
2011-05-21 01:53:51 ----RSHD---- C:\WINDOWS\system32\svhost.exe
2011-05-21 01:53:51 ----RSHD---- C:\WINDOWS\system32\server.exe
2011-05-21 01:53:51 ----RSHD---- C:\WINDOWS\system32\regsvc32.exe
2011-05-21 01:52:24 ----SHD---- C:\FOUND.016
2011-05-21 01:45:14 ----D---- C:\Program Files\Malware Immunizer
2011-05-21 01:10:21 ----D---- C:\Program Files\Mozilla Firefox
2011-05-18 00:16:41 ----D---- C:\Documents and Settings\Mia\Data aplikací\Dev-Cpp
2011-05-15 11:10:24 ----SHD---- C:\FOUND.015
2011-05-14 18:43:46 ----D---- C:\wamp
2011-05-14 09:47:54 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype Extras
2011-05-14 09:47:43 ----D---- C:\Program Files\Common Files\Skype
2011-05-10 16:36:26 ----D---- C:\Documents and Settings\Mia\Data aplikací\Softland
2011-05-10 16:35:58 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2011-05-10 16:29:38 ----D---- C:\Documents and Settings\Mia\Data aplikací\Salty Brine
2011-05-09 10:49:10 ----SHD---- C:\FOUND.014
2011-05-03 21:33:50 ----D---- C:\Documents and Settings\Mia\Data aplikací\Opera
2011-05-03 21:33:40 ----D---- C:\Program Files\Opera

Re: wbove prehliadace neustale vytacaju CPU na 100%

Napsal: 21 kvě 2011 20:07
od miamafia
======List of files/folders modified in the last 1 months======

2011-05-21 18:14:18 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-05-21 17:49:08 ----RASH---- C:\boot.ini
2011-05-21 17:49:08 ----A---- C:\WINDOWS\win.ini
2011-05-21 17:49:08 ----A---- C:\WINDOWS\system.ini
2011-05-12 09:27:42 ----A---- C:\WINDOWS\system32\MRT.exe
2011-05-03 23:07:02 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-04-28 08:31:38 ----A---- C:\WINDOWS\ModemLog_Motorola SM56 Data Fax Modem.txt

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R0 risdptsk;risdptsk; C:\WINDOWS\system32\DRIVERS\risdptsk.sys [2005-07-13 27904]
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-05-09 43008]
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2011-03-26 137656]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2010-06-17 28520]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.3.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2011-01-13 20747]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2010-12-13 61960]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 ASNDIS5;ASNDIS5 Protocol Driver; \??\C:\WINDOWS\system32\ASNDIS5.SYS []
R3 BCM43XX;ASUS 802.11 ovládač sieťového adaptéru; C:\WINDOWS\system32\DRIVERS\bcmwl5.sys [2005-02-11 371712]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-12-19 4127232]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ATKACPI.sys [2005-02-17 5632]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2006-04-27 3659968]
R3 nvsmu;nvsmu; C:\WINDOWS\system32\DRIVERS\nvsmu.sys [2006-03-06 11136]
R3 rimsptsk;rimsptsk; C:\WINDOWS\system32\DRIVERS\rimsptsk.sys [2005-07-12 51328]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2007-10-23 103296]
R3 smserial;smserial; C:\WINDOWS\system32\DRIVERS\smserial.sys [2006-01-19 862340]
R3 SynMini;USB2.0 1.3M Web Cam; C:\WINDOWS\System32\Drivers\SynMini.sys [2005-10-03 720470]
R3 SynScan;USB2.0 1.3M Web Cam Still Image; C:\WINDOWS\System32\Drivers\SynScan.sys [2005-10-03 8278]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2005-10-20 191936]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2007-10-23 103296]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 SymEvent;SymEvent; \??\C:\Program Files\Symantec\SYMEVENT.SYS []
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-18 26496]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2011-03-26 269480]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2011-04-27 136360]
R2 ccEvtMgr;Symantec Event Manager; C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe [2004-08-28 197752]
R2 ccSetMgr;Symantec Settings Manager; C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe [2004-08-28 164984]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-02-02 153376]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2006-04-26 143427]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 ccPwdSvc;Symantec Password Validation; C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe [2004-08-28 78968]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 wampapache;wampapache; c:\wamp\bin\apache\apache2.2.17\bin\httpd.exe [2010-12-31 20549]
S3 wampmysqld;wampmysqld; c:\wamp\bin\mysql\mysql5.5.8\bin\mysqld.exe [2010-12-31 8133120]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Re: wbove prehliadace neustale vytacaju CPU na 100%

Napsal: 21 kvě 2011 21:11
od vyosek
Zdravim a pekny vecer preji :)

:arrow: Doporucuji odinstalovat Spybot - Search & Destroy - program ma uz nejlepsi leta davno za sebou a posledni cca 3 roky neni schopen celit aktualnim hrozbam. Sice Vam neco nasel, ale urcite tam toho jeste hodne bude. Po ukonceni leceni tam dame nejakou lepsi nahradu :wink:

:arrow: Stahnete RKill http://download.bleepingcomputer.com/grinler/rkill.com PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix

Re: wbove prehliadace neustale vytacaju CPU na 100%

Napsal: 22 kvě 2011 08:11
od miamafia
tak, isla som podla navodu a tu je ten log..

ComboFix 11-05-21.03 - Mia . 05. 2011 9:02.1.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.2431.1955 [GMT 2:00]
Spuštěný z: c:\documents and settings\Mia\Plocha\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Default User\WINDOWS
c:\documents and settings\Mia\WINDOWS
c:\windows\system32\config\systemprofile\WINDOWS
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-04-22 do 2011-05-22 )))))))))))))))))))))))))))))))
.
.
2011-05-21 18:49 . 2011-05-21 18:49 -------- d-----w- C:\rsit
2011-05-21 16:11 . 2011-05-21 16:11 -------- d-----w- c:\program files\TeaTimer (Spybot - Search & Destroy)
2011-05-21 16:11 . 2011-05-21 16:11 -------- d-----w- c:\program files\SDHelper (Spybot - Search & Destroy)
2011-05-21 16:11 . 2011-05-21 16:11 -------- d-----w- c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2011-05-21 16:11 . 2011-05-21 16:11 -------- d-----w- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2011-05-21 16:03 . 2011-05-21 16:03 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Spybot - Search & Destroy
2011-05-21 16:03 . 2011-05-21 16:03 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-05-21 15:54 . 2011-05-21 15:54 388096 ----a-r- c:\documents and settings\Mia\Data aplikací\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-05-21 15:54 . 2011-05-21 15:54 -------- d-----w- c:\program files\Trend Micro
2011-05-21 15:28 . 2011-05-21 15:28 -------- d-----w- c:\documents and settings\Mia\Data aplikací\Malwarebytes
2011-05-21 15:27 . 2010-12-20 16:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-21 15:26 . 2011-05-21 15:26 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-05-21 15:26 . 2011-05-21 15:26 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-05-21 15:26 . 2010-12-20 16:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-05-21 07:51 . 2011-05-21 07:51 -------- d-----w- c:\documents and settings\Mia\Data aplikací\QIP
2011-05-21 07:48 . 2011-05-11 12:58 141184 ----a-w- c:\documents and settings\Mia\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
2011-05-21 07:48 . 2011-05-21 07:48 -------- d-----w- c:\program files\QIP Infium
2011-05-20 23:54 . 2011-05-20 23:54 -------- d-----w- c:\windows\system32\skyx16.dll_old
2011-05-20 23:54 . 2011-05-20 23:54 -------- d-----w- c:\windows\system32\qz.sys_old
2011-05-20 23:54 . 2011-05-20 23:54 -------- d-----w- c:\windows\system32\qz.dll_old
2011-05-20 23:52 . 2011-05-20 23:52 -------- d-----w- C:\FOUND.016
2011-05-20 23:10 . 2011-05-20 23:10 -------- d-----w- c:\documents and settings\Mia\Local Settings\Data aplikací\Mozilla
2011-05-18 11:05 . 2011-05-18 11:05 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-17 22:16 . 2011-05-17 22:16 -------- d-----w- c:\documents and settings\Mia\Data aplikací\Dev-Cpp
2011-05-15 09:10 . 2011-05-15 09:10 -------- d-----w- C:\FOUND.015
2011-05-14 16:43 . 2011-05-14 16:43 -------- d-----w- C:\wamp
2011-05-14 07:47 . 2011-05-14 07:47 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Skype Extras
2011-05-14 07:47 . 2011-05-14 07:47 -------- d-----w- c:\program files\Common Files\Skype
2011-05-10 14:36 . 2011-05-10 14:36 -------- d-----w- c:\documents and settings\LocalService\Data aplikací\Softland
2011-05-10 14:36 . 2011-05-10 14:36 -------- d-----w- c:\documents and settings\Mia\Data aplikací\Softland
2011-05-10 14:35 . 2010-02-05 13:00 1700352 ----a-w- c:\windows\system32\GdiPlus.dll
2011-05-10 14:35 . 2011-05-10 14:35 -------- d-----w- c:\documents and settings\Mia\Local Settings\Data aplikací\PDF Annotator
2011-05-10 14:29 . 2011-05-10 14:29 -------- d-----w- c:\documents and settings\Mia\Data aplikací\Salty Brine
2011-05-09 08:49 . 2011-05-09 08:49 -------- d-----w- C:\FOUND.014
2011-05-03 19:33 . 2011-05-03 19:33 -------- d-----w- c:\documents and settings\Mia\Local Settings\Data aplikací\Opera
2011-05-03 19:33 . 2011-05-03 19:33 -------- d-----w- c:\documents and settings\All Users\Plocha
2011-05-03 19:33 . 2011-05-03 19:33 -------- d-----w- c:\program files\Opera
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-26 15:50 . 2011-01-07 13:44 137656 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-03-07 05:33 . 2011-01-07 12:20 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:36 . 2004-11-20 09:14 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:53 . 2004-11-20 09:14 1857920 ----a-w- c:\windows\system32\win32k.sys
2011-02-22 23:08 . 2004-11-20 09:14 916480 ----a-w- c:\windows\system32\wininet.dll
2011-02-22 23:08 . 2004-11-20 09:14 43520 ------w- c:\windows\system32\licmgr10.dll
2011-02-22 23:08 . 2004-11-20 09:14 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-02-22 11:42 . 2004-11-20 09:14 385024 ------w- c:\windows\system32\html.iec
2011-04-14 17:01 . 2011-05-20 23:10 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="c:\windows\ATK0100\HControl.exe" [2006-04-17 110592]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-04-26 7561216]
"nwiz"="nwiz.exe" [2006-04-27 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-04-26 86016]
"SMSERIAL"="sm56hlpr.exe" [2006-01-19 544768]
"RTHDCPL"="RTHDCPL.EXE" [2005-12-18 15797248]
"ASUS Live Update"="c:\program files\ASUS\ASUS Live Update\ALU.exe" [2006-02-21 180224]
"Wireless Console 2"="c:\program files\Wireless Console 2\wcourier.exe" [2005-10-17 987136]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-10-20 761945]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2004-08-28 58488]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-12-13 281768]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^ASUS ChkMail.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\ASUS ChkMail.lnk
backup=c:\windows\pss\ASUS ChkMail.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Mia^Nabídka Start^Programy^Po spuštění^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
path=c:\documents and settings\Mia\Nabídka Start\Programy\Po spuštění\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
backup=c:\windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-26 22:47 31016 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Power_Gear]
2006-03-06 15:13 86016 ----a-w- c:\program files\ASUS\Power4 Gear\BatteryLife.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-10-29 12:49 249064 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\TOTALCMD\\TOTALCMD.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\groove.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\DC++\\DCPlusPlus.exe"=
"c:\\Program Files\\MATLAB\\R2008b\\BIN\\WIN32\\MATLAB.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\wamp\\bin\\apache\\Apache2.2.17\\bin\\httpd.exe"=
"c:\\Program Files\\QIP Infium\\infium.exe"=
.
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [7. 1. 2011 15:44 136360]
R3 SynMini;USB2.0 1.3M Web Cam;c:\windows\system32\drivers\SynMini.sys [7. 1. 2011 20:24 720470]
R3 SynScan;USB2.0 1.3M Web Cam Still Image;c:\windows\system32\drivers\SynScan.sys [7. 1. 2011 20:24 8278]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18. 3. 2010 13:16 130384]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18. 3. 2010 13:16 753504]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://qip.ru
uDefault_Search_URL = hxxp://search.qip.ru
uSearchAssistant = hxxp://search.qip.ru/ie
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Mia\Data aplikací\Mozilla\Firefox\Profiles\mmk87apy.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{BB54C912-5131-5114-A979-F4D5402448F1} - c:\documents and settings\Mia\Local Settings\Data aplikací\GamePlayLabs Plugin\BHO.dll
HKLM-Run-Zshutdown - c:\sysprep\patch\sysprep.cmd
MSConfigStartUp-QIP Internet Guardian - c:\documents and settings\Mia\Data aplikací\QipGuard\QipGuard.exe
AddRemove-QipGuard - c:\documents and settings\Mia\Data aplikací\QipGuard\QipGuard.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-05-22 09:06
Windows 5.1.2600 Service Pack 3 FAT NTAPI
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(1600)
c:\windows\system32\webcheck.dll
.
Celkový čas: 2011-05-22 09:08:24
ComboFix-quarantined-files.txt 2011-05-22 07:08
.
Před spuštěním: Volných bajtů: 24 703 434 752
Po spuštění: Volných bajtů: 24 914 853 888
.
WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - ED5A75891492A0C724D56EE0DE51B1AF

Re: wbove prehliadace neustale vytacaju CPU na 100%

Napsal: 22 kvě 2011 08:39
od vyosek
:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    File::
    c:\windows\system32\qz.sys_old
    c:\windows\system32\qz.dll_old
    
    DDS::
    uStart Page = hxxp://qip.ru
    uDefault_Search_URL = hxxp://search.qip.ru
    uSearchAssistant = hxxp://search.qip.ru/ie
    
    RegLock::
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    
    Registry::
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    [-HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
    
    Reboot::
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci

Re: wbove prehliadace neustale vytacaju CPU na 100%

Napsal: 22 kvě 2011 09:03
od miamafia
vykonane. :)

ComboFix 11-05-21.03 - Mia . 05. 2011 9:51.2.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.2431.1944 [GMT 2:00]
Spuštěný z: c:\documents and settings\Mia\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Mia\Plocha\CFScript.txt
AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
FILE ::
"c:\windows\system32\qz.dll_old"
"c:\windows\system32\qz.sys_old"
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-04-22 do 2011-05-22 )))))))))))))))))))))))))))))))
.
.
2011-05-21 18:49 . 2011-05-21 18:49 -------- d-----w- C:\rsit
2011-05-21 16:11 . 2011-05-21 16:11 -------- d-----w- c:\program files\TeaTimer (Spybot - Search & Destroy)
2011-05-21 16:11 . 2011-05-21 16:11 -------- d-----w- c:\program files\SDHelper (Spybot - Search & Destroy)
2011-05-21 16:11 . 2011-05-21 16:11 -------- d-----w- c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2011-05-21 16:11 . 2011-05-21 16:11 -------- d-----w- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2011-05-21 16:03 . 2011-05-21 16:03 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Spybot - Search & Destroy
2011-05-21 16:03 . 2011-05-21 16:03 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-05-21 15:54 . 2011-05-21 15:54 388096 ----a-r- c:\documents and settings\Mia\Data aplikací\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-05-21 15:54 . 2011-05-21 15:54 -------- d-----w- c:\program files\Trend Micro
2011-05-21 15:28 . 2011-05-21 15:28 -------- d-----w- c:\documents and settings\Mia\Data aplikací\Malwarebytes
2011-05-21 15:27 . 2010-12-20 16:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-21 15:26 . 2011-05-21 15:26 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-05-21 15:26 . 2011-05-21 15:26 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-05-21 15:26 . 2010-12-20 16:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-05-21 07:51 . 2011-05-21 07:51 -------- d-----w- c:\documents and settings\Mia\Data aplikací\QIP
2011-05-21 07:48 . 2011-05-11 12:58 141184 ----a-w- c:\documents and settings\Mia\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
2011-05-21 07:48 . 2011-05-21 07:48 -------- d-----w- c:\program files\QIP Infium
2011-05-20 23:54 . 2011-05-20 23:54 -------- d-----w- c:\windows\system32\skyx16.dll_old
2011-05-20 23:54 . 2011-05-20 23:54 -------- d-----w- c:\windows\system32\qz.sys_old
2011-05-20 23:54 . 2011-05-20 23:54 -------- d-----w- c:\windows\system32\qz.dll_old
2011-05-20 23:52 . 2011-05-20 23:52 -------- d-----w- C:\FOUND.016
2011-05-20 23:10 . 2011-05-20 23:10 -------- d-----w- c:\documents and settings\Mia\Local Settings\Data aplikací\Mozilla
2011-05-18 11:05 . 2011-05-18 11:05 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-17 22:16 . 2011-05-17 22:16 -------- d-----w- c:\documents and settings\Mia\Data aplikací\Dev-Cpp
2011-05-15 09:10 . 2011-05-15 09:10 -------- d-----w- C:\FOUND.015
2011-05-14 16:43 . 2011-05-14 16:43 -------- d-----w- C:\wamp
2011-05-14 07:47 . 2011-05-14 07:47 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Skype Extras
2011-05-14 07:47 . 2011-05-14 07:47 -------- d-----w- c:\program files\Common Files\Skype
2011-05-10 14:36 . 2011-05-10 14:36 -------- d-----w- c:\documents and settings\LocalService\Data aplikací\Softland
2011-05-10 14:36 . 2011-05-10 14:36 -------- d-----w- c:\documents and settings\Mia\Data aplikací\Softland
2011-05-10 14:35 . 2010-02-05 13:00 1700352 ----a-w- c:\windows\system32\GdiPlus.dll
2011-05-10 14:35 . 2011-05-10 14:35 -------- d-----w- c:\documents and settings\Mia\Local Settings\Data aplikací\PDF Annotator
2011-05-10 14:29 . 2011-05-10 14:29 -------- d-----w- c:\documents and settings\Mia\Data aplikací\Salty Brine
2011-05-09 08:49 . 2011-05-09 08:49 -------- d-----w- C:\FOUND.014
2011-05-03 19:33 . 2011-05-03 19:33 -------- d-----w- c:\documents and settings\Mia\Local Settings\Data aplikací\Opera
2011-05-03 19:33 . 2011-05-03 19:33 -------- d-----w- c:\documents and settings\All Users\Plocha
2011-05-03 19:33 . 2011-05-03 19:33 -------- d-----w- c:\program files\Opera
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-26 15:50 . 2011-01-07 13:44 137656 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-03-07 05:33 . 2011-01-07 12:20 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:36 . 2004-11-20 09:14 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:53 . 2004-11-20 09:14 1857920 ----a-w- c:\windows\system32\win32k.sys
2011-02-22 23:08 . 2004-11-20 09:14 916480 ----a-w- c:\windows\system32\wininet.dll
2011-02-22 23:08 . 2004-11-20 09:14 43520 ------w- c:\windows\system32\licmgr10.dll
2011-02-22 23:08 . 2004-11-20 09:14 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-02-22 11:42 . 2004-11-20 09:14 385024 ------w- c:\windows\system32\html.iec
2011-04-14 17:01 . 2011-05-20 23:10 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="c:\windows\ATK0100\HControl.exe" [2006-04-17 110592]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-04-26 7561216]
"nwiz"="nwiz.exe" [2006-04-27 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-04-26 86016]
"SMSERIAL"="sm56hlpr.exe" [2006-01-19 544768]
"RTHDCPL"="RTHDCPL.EXE" [2005-12-18 15797248]
"ASUS Live Update"="c:\program files\ASUS\ASUS Live Update\ALU.exe" [2006-02-21 180224]
"Wireless Console 2"="c:\program files\Wireless Console 2\wcourier.exe" [2005-10-17 987136]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-10-20 761945]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2004-08-28 58488]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-12-13 281768]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^ASUS ChkMail.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\ASUS ChkMail.lnk
backup=c:\windows\pss\ASUS ChkMail.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Mia^Nabídka Start^Programy^Po spuštění^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
path=c:\documents and settings\Mia\Nabídka Start\Programy\Po spuštění\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
backup=c:\windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-26 22:47 31016 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Power_Gear]
2006-03-06 15:13 86016 ----a-w- c:\program files\ASUS\Power4 Gear\BatteryLife.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\TOTALCMD\\TOTALCMD.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\groove.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\DC++\\DCPlusPlus.exe"=
"c:\\Program Files\\MATLAB\\R2008b\\BIN\\WIN32\\MATLAB.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\wamp\\bin\\apache\\Apache2.2.17\\bin\\httpd.exe"=
"c:\\Program Files\\QIP Infium\\infium.exe"=
.
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [7. 1. 2011 15:44 136360]
R3 SynMini;USB2.0 1.3M Web Cam;c:\windows\system32\drivers\SynMini.sys [7. 1. 2011 20:24 720470]
R3 SynScan;USB2.0 1.3M Web Cam Still Image;c:\windows\system32\drivers\SynScan.sys [7. 1. 2011 20:24 8278]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18. 3. 2010 13:16 130384]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18. 3. 2010 13:16 753504]
.
.
------- Doplňkový sken -------
.
uSearchAssistant = hxxp://search.qip.ru/ie
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Mia\Data aplikací\Mozilla\Firefox\Profiles\mmk87apy.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-05-22 09:56
Windows 5.1.2600 Service Pack 3 FAT NTAPI
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(1700)
c:\windows\system32\webcheck.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\sm56hlpr.exe
c:\windows\RTHDCPL.EXE
c:\windows\ATK0100\ATKOSD.exe
.
**************************************************************************
.
Celkový čas: 2011-05-22 10:00:16 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-05-22 08:00
ComboFix2.txt 2011-05-22 07:08
.
Před spuštěním: Volných bajtů: 24 886 476 800
Po spuštění: Volných bajtů: 24 875 728 896
.
- - End Of File - - 2AE7A249F7041F0AFDB588FD81EFD4CF

Re: wbove prehliadace neustale vytacaju CPU na 100%

Napsal: 22 kvě 2011 11:45
od miamafia
mam taky pocit, ze uz PC bezi normalne. nepretazuje ho nic..

DAKUJEM velmi pekne za pomoc. :) :thumbsups:

Re: wbove prehliadace neustale vytacaju CPU na 100%

Napsal: 22 kvě 2011 15:45
od vyosek
:arrow: Nedavejte prosim logy do code - spatne se lusti a boli z toho oci - ja jsem Vam to s dovolenim editnul...

:arrow: Odinstalujte Combofix
  • Start - Spustit (nebo pouzijte klavesobou zkratku Win+R)
  • Napiste ComboFix /Uninstall
  • Stisknete Enter
  • Tohle smaze Combofix a jeho slozky
:arrow: T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner (viz muj podpis)
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za 14 dni

:arrow: Doporucuji odinstalovat Spybot - Search & Destroy - program ma uz nejlepsi leta davno za sebou a posledni cca 3 roky neni schopen celit aktualnim hrozbam :arrow: A poprosim o novy log z RSIT a zhodnoceni stavu PC

Re: wbove prehliadace neustale vytacaju CPU na 100%

Napsal: 23 kvě 2011 10:00
od miamafia
tak, urobila som vsetko co som mala. a ospravedlnujem sa za vkladanie do codu. :) chcela som setrit miesto. :D
tu je posledny vypis z RSTI. dufam, ze uz bude PC ciste a budem mat pokoj od havedi. :) zatial velmi pekne dakujem.



Logfile of random's system information tool 1.08 (written by random/random)
Run by Mia at 2011-05-23 10:57:39
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 30 GB (53%) free of 56 GB
Total RAM: 2431 MB (82% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:57:53, on 23. 5. 2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ATK0100\HControl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\sm56hlpr.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Program Files\Wireless Console 2\wcourier.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\Mia\Dokumenty\Preberanie\RSIT(1).exe
C:\Program Files\trend micro\Mia.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: QIPBHO Class - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Documents and Settings\Mia\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: QIPBHO - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Documents and Settings\Mia\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {8E718888-423F-11D2-876E-00A0C9082467} - (no file)
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [ASUS Live Update] C:\Program Files\ASUS\ASUS Live Update\ALU.exe
O4 - HKLM\..\Run: [Wireless Console 2] C:\Program Files\Wireless Console 2\wcourier.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra button: QIP Infium - {1EF681F7-A04B-4D6D-9012-A307CCA55610} - C:\Program Files\QIP Infium\infium.exe (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.asus.com
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.17\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.5.8\bin\mysqld.exe

--
End of file - 7196 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95289393-33EA-4F8D-B952-483415B9C955}]
QIPBHO Class - C:\Documents and Settings\Mia\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll [2011-05-11 141184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-02-02 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-02-02 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E718888-423F-11D2-876E-00A0C9082467}

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HControl"=C:\WINDOWS\ATK0100\HControl.exe [2006-04-17 110592]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2006-04-26 7561216]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2006-04-26 86016]
"SMSERIAL"=C:\WINDOWS\sm56hlpr.exe [2006-01-19 544768]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2005-12-18 15797248]
"ASUS Live Update"=C:\Program Files\ASUS\ASUS Live Update\ALU.exe [2006-02-21 180224]
"Wireless Console 2"=C:\Program Files\Wireless Console 2\wcourier.exe [2005-10-17 987136]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2005-10-20 761945]
"ccApp"=C:\Program Files\Common Files\Symantec Shared\ccApp.exe [2004-08-28 58488]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2010-12-13 281768]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Power_Gear]
C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe [2006-03-06 86016]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^ASUS ChkMail.lnk]
C:\PROGRA~1\ASUS\ASUSCH~1\ChkMail.exe [2003-09-12 32768]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Mia^Nabídka Start^Programy^Po spuštění^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
C:\PROGRA~1\MICROS~2\Office12\ONENOTEM.EXE [2006-10-26 98632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\VideoLAN\VLC\vlc.exe"="C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\TOTALCMD\TOTALCMD.EXE"="C:\TOTALCMD\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\groove.exe"="C:\Program Files\Microsoft Office\Office12\groove.exe:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\DC++\DCPlusPlus.exe"="C:\Program Files\DC++\DCPlusPlus.exe:*:Enabled:DC++"
"C:\Program Files\MATLAB\R2008b\BIN\WIN32\MATLAB.exe"="C:\Program Files\MATLAB\R2008b\BIN\WIN32\MATLAB.exe:*:Enabled:MATLAB"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\wamp\bin\apache\Apache2.2.17\bin\httpd.exe"="C:\wamp\bin\apache\Apache2.2.17\bin\httpd.exe:*:Enabled:Apache HTTP Server"
"C:\Program Files\QIP Infium\infium.exe"="C:\Program Files\QIP Infium\infium.exe:*:Enabled:QIP Infium"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2011-05-23 10:57:02 ----D---- C:\rsit
2011-05-23 10:47:26 ----D---- C:\Program Files\CCleaner
2011-05-23 10:47:02 ----D---- C:\Program Files\Google
2011-05-22 15:26:32 ----SHD---- C:\Recycled
2011-05-22 09:54:46 ----D---- C:\WINDOWS\temp
2011-05-22 09:00:49 ----A---- C:\Boot.bak
2011-05-22 09:00:44 ----RASHD---- C:\cmdcons
2011-05-21 20:42:07 ----A---- C:\WINDOWS\wininit.ini
2011-05-21 18:11:29 ----D---- C:\Program Files\TeaTimer (Spybot - Search & Destroy)
2011-05-21 18:11:29 ----D---- C:\Program Files\SDHelper (Spybot - Search & Destroy)
2011-05-21 18:11:29 ----D---- C:\Program Files\Misc. Support Library (Spybot - Search & Destroy)
2011-05-21 18:11:29 ----D---- C:\Program Files\File Scanner Library (Spybot - Search & Destroy)
2011-05-21 18:03:52 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2011-05-21 18:03:09 ----D---- C:\Program Files\Spybot - Search & Destroy
2011-05-21 17:54:04 ----D---- C:\Program Files\Trend Micro
2011-05-21 17:47:43 ----D---- C:\WINDOWS\pss
2011-05-21 17:28:53 ----D---- C:\Documents and Settings\Mia\Data aplikací\Malwarebytes
2011-05-21 17:26:48 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2011-05-21 09:51:01 ----D---- C:\Documents and Settings\Mia\Data aplikací\QIP
2011-05-21 09:48:16 ----D---- C:\Program Files\QIP Infium
2011-05-21 01:54:26 ----D---- C:\WINDOWS\system32\skyx16.dll_old
2011-05-21 01:54:26 ----D---- C:\WINDOWS\system32\qz.sys_old
2011-05-21 01:54:26 ----D---- C:\WINDOWS\system32\qz.dll_old
2011-05-21 01:52:24 ----D---- C:\FOUND.016
2011-05-21 01:10:21 ----D---- C:\Program Files\Mozilla Firefox
2011-05-18 00:16:41 ----D---- C:\Documents and Settings\Mia\Data aplikací\Dev-Cpp
2011-05-15 11:10:24 ----D---- C:\FOUND.015
2011-05-14 18:43:46 ----D---- C:\wamp
2011-05-14 09:47:54 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype Extras
2011-05-14 09:47:43 ----D---- C:\Program Files\Common Files\Skype
2011-05-10 16:36:26 ----D---- C:\Documents and Settings\Mia\Data aplikací\Softland
2011-05-10 16:35:58 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2011-05-10 16:29:38 ----D---- C:\Documents and Settings\Mia\Data aplikací\Salty Brine
2011-05-09 10:49:10 ----D---- C:\FOUND.014
2011-05-03 21:33:50 ----D---- C:\Documents and Settings\Mia\Data aplikací\Opera
2011-05-03 21:33:40 ----D---- C:\Program Files\Opera

======List of files/folders modified in the last 1 months======

2011-05-23 10:43:18 ----N---- C:\WINDOWS\SchedLgU.Txt
2011-05-22 09:56:46 ----A---- C:\WINDOWS\system.ini
2011-05-22 09:00:50 ----RASH---- C:\boot.ini
2011-05-21 17:49:08 ----A---- C:\WINDOWS\win.ini
2011-05-12 09:27:42 ----A---- C:\WINDOWS\system32\MRT.exe
2011-05-03 23:07:02 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-04-28 08:31:38 ----A---- C:\WINDOWS\ModemLog_Motorola SM56 Data Fax Modem.txt

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R0 risdptsk;risdptsk; C:\WINDOWS\system32\DRIVERS\risdptsk.sys [2005-07-13 27904]
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-05-09 43008]
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2011-03-26 137656]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2010-06-17 28520]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.3.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2011-01-13 20747]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2010-12-13 61960]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 ASNDIS5;ASNDIS5 Protocol Driver; \??\C:\WINDOWS\system32\ASNDIS5.SYS []
R3 BCM43XX;ASUS 802.11 ovládač sieťového adaptéru; C:\WINDOWS\system32\DRIVERS\bcmwl5.sys [2005-02-11 371712]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-12-19 4127232]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ATKACPI.sys [2005-02-17 5632]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2006-04-27 3659968]
R3 nvsmu;nvsmu; C:\WINDOWS\system32\DRIVERS\nvsmu.sys [2006-03-06 11136]
R3 rimsptsk;rimsptsk; C:\WINDOWS\system32\DRIVERS\rimsptsk.sys [2005-07-12 51328]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2007-10-23 103296]
R3 smserial;smserial; C:\WINDOWS\system32\DRIVERS\smserial.sys [2006-01-19 862340]
R3 SynMini;USB2.0 1.3M Web Cam; C:\WINDOWS\System32\Drivers\SynMini.sys [2005-10-03 720470]
R3 SynScan;USB2.0 1.3M Web Cam Still Image; C:\WINDOWS\System32\Drivers\SynScan.sys [2005-10-03 8278]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2005-10-20 191936]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2007-10-23 103296]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 SymEvent;SymEvent; \??\C:\Program Files\Symantec\SYMEVENT.SYS []
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-18 26496]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2011-03-26 269480]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2011-04-27 136360]
R2 ccEvtMgr;Symantec Event Manager; C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe [2004-08-28 197752]
R2 ccSetMgr;Symantec Settings Manager; C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe [2004-08-28 164984]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-02-02 153376]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2006-04-26 143427]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-05-23 135664]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 ccPwdSvc;Symantec Password Validation; C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe [2004-08-28 78968]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 wampapache;wampapache; c:\wamp\bin\apache\apache2.2.17\bin\httpd.exe [2010-12-31 20549]
S3 wampmysqld;wampmysqld; c:\wamp\bin\mysql\mysql5.5.8\bin\mysqld.exe [2010-12-31 8133120]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Re: wbove prehliadace neustale vytacaju CPU na 100%

Napsal: 23 kvě 2011 12:41
od vyosek
:arrow: Spustte HJT a provedeme fixnuti polozek
  • HJT najdete zde C:\Program Files\trend micro\Mia.exe
  • Otevre se Vam okno, kliknete na Do a system scan only
  • V dalsim okne najdete radky které jsem Vam vypsal nize, vedle nich je ctverecek, do ktereho udelate zatrzitko
  • R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
    R3 - URLSearchHook: QIPBHO Class - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Documents and Settings\Mia\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
  • Kliknete na Fix checked (vlevo dole)
  • HJT se Vas zepta zda opravdu ANO, s tim souhlasite a je hotovo Obrázek
:arrow: Jinak nic spatneho nevidim

Re: wbove prehliadace neustale vytacaju CPU na 100%

Napsal: 23 kvě 2011 12:55
od miamafia
3 krat huraaaa huraaaaaa huraaaaaaaa. :worship: :worship: :worship:

DAKUJEM VELMI PEKNE.. :) :clapping: :wub:


ps: dufam, ze sem nebudem musiet opat prist. :)
ps2: nech mate menej prace s nami zenami. :D

Re: wbove prehliadace neustale vytacaju CPU na 100%

Napsal: 23 kvě 2011 14:16
od vyosek
U nas budete vzdy vitana, staci se treba cca jednou za pul roku zastavit treba jen v sekci preventivek :wink:

Prace se zenami, to je legrace, u nas i jedna kolegyne lusti logy - motji

Jinak nemate zac, rad jsem pomohl :)