Kontrola logu z RSIT
Napsal: 23 bře 2010 21:23
Logfile of random's system information tool 1.06 (written by random/random)
Run by Michal at 2010-03-23 21:20:05
Microsoft® Windows Vista™ Home Basic Service Pack 2
System drive C: has 106 GB (80%) free of 133 GB
Total RAM: 2039 MB (44% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:20:22, on 23. 3. 2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18882)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\pthosttr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Norton Internet Security\Engine\17.0.0.136\ccSvcHst.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Používateľ\Downloads\RSIT.exe
C:\Program Files\trend micro\Michal.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (file missing)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\17.0.0.136\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\17.0.0.136\IPSBHO.DLL
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\17.0.0.136\coIEPlg.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [PTHOSTTR] C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\RunOnce: [AVG FirstScan] "C:\Program Files\AVG\AVG9\avgfrw.exe" /firstscan /delay=120 /runonce
O4 - HKLM\..\RunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstall ... er=9.0.790
O4 - HKCU\..\RunOnce: [SYMNRT] C:\Program Files\Internet Explorer\iexplore.exe http://www.symantec.com/techsupp/servle ... 5.0000034c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O13 - Gopher Prefix:
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: DeviceNP - C:\Windows\SYSTEM32\DeviceNP.dll
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\Windows\system32\AEADISRV.EXE
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Ltd - C:\Windows\system32\flcdlock.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\17.0.0.136\ccSvcHst.exe
--
End of file - 5616 bytes
======Scheduled tasks folder======
C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
C:\Windows\tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Symantec NCO BHO - C:\Program Files\Norton Internet Security\Engine\17.0.0.136\coIEPlg.dll [2009-08-29 392560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Symantec Intrusion Prevention - C:\Program Files\Norton Internet Security\Engine\17.0.0.136\IPSBHO.DLL [2009-08-30 79224]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files\Norton Internet Security\Engine\17.0.0.136\coIEPlg.dll [2009-08-29 392560]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"PTHOSTTR"=C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE [2007-01-09 145184]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-03-27 1045800]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-05-22 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2008-05-22 166424]
"Persistence"=C:\Windows\system32\igfxpers.exe [2008-05-22 133656]
"QlbCtrl.exe"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2008-05-14 177456]
"hpWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2008-04-15 488752]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2007-02-21 1183744]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"AVG FirstScan"=C:\Program Files\AVG\AVG9\avgfrw.exe /firstscan /delay=120 /runonce []
"AvgUninstallURL"=cmd.exe /c start http://www.avg.com/ww.special-uninstall ... er=9.0.790 []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SYMNRT"=C:\Program Files\Internet Explorer\iexplore.exe [2010-01-02 638216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-12-11 948672]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-12-22 35760]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
C:\Program Files\ICQ7.0\ICQ.exe silent loginmode=4 []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^DVD Check.lnk]
C:\PROGRA~1\INTERV~1\DVDCHE~1\DVDCheck.exe [2008-05-23 197904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DeviceNP]
C:\Windows\system32\DeviceNP.dll [2007-06-08 49152]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2008-02-11 204800]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=
"NoDriveTypeAutoRun"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2010-03-23 21:20:05 ----D---- C:\rsit
2010-03-23 21:20:05 ----D---- C:\Program Files\trend micro
2010-03-23 20:53:17 ----D---- C:\Users\Michal\AppData\Roaming\Tific
2010-03-23 20:52:33 ----D---- C:\Program Files\Common Files\Symantec Shared
2010-03-23 20:51:57 ----D---- C:\Program Files\Norton Internet Security
2010-03-23 20:51:50 ----D---- C:\Program Files\NortonInstaller
2010-03-23 20:02:32 ----D---- C:\Program Files\AVG
2010-03-23 20:02:08 ----D---- C:\ProgramData\avg9
2010-03-20 18:10:02 ----D---- C:\Program Files\7-Zip
2010-03-20 17:42:36 ----D---- C:\ProgramData\Kaspersky Lab
2010-03-20 17:31:32 ----D---- C:\ProgramData\Kaspersky Lab Setup Files
2010-03-18 15:33:24 ----D---- C:\ProgramData\Symantec
2010-03-17 18:01:18 ----RA---- C:\Windows\system32\GEARAspi.dll
2010-03-17 18:01:17 ----DC---- C:\Windows\system32\DRVSTORE
2010-03-17 18:00:55 ----D---- C:\Program Files\Symantec
2010-03-17 18:00:17 ----D---- C:\ProgramData\Norton
2010-03-17 17:58:44 ----D---- C:\ProgramData\NortonInstaller
2010-03-15 19:05:12 ----D---- C:\ProgramData\Mozilla
2010-03-13 19:57:55 ----D---- C:\Program Files\Microsoft Silverlight
2010-03-13 19:15:46 ----D---- C:\Program Files\LSI SoftModem
2010-03-13 13:17:57 ----A---- C:\Windows\system32\winhttp.dll
2010-03-13 13:17:51 ----A---- C:\Windows\system32\httpapi.dll
2010-03-13 13:17:50 ----A---- C:\Windows\system32\nshhttp.dll
2010-03-13 10:18:30 ----D---- C:\Program Files\Windows Portable Devices
2010-03-13 10:17:54 ----A---- C:\Windows\system32\UIAnimation.dll
2010-03-13 10:17:53 ----A---- C:\Windows\system32\UIRibbonRes.dll
2010-03-13 10:17:53 ----A---- C:\Windows\system32\UIRibbon.dll
2010-03-13 10:17:33 ----A---- C:\Windows\system32\WMPhoto.dll
2010-03-13 10:17:32 ----A---- C:\Windows\system32\XpsRasterService.dll
2010-03-13 10:17:32 ----A---- C:\Windows\system32\XpsPrint.dll
2010-03-13 10:17:32 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2010-03-13 10:17:32 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2010-03-13 10:17:32 ----A---- C:\Windows\system32\WindowsCodecs.dll
2010-03-13 10:17:32 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
2010-03-13 10:17:32 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll
2010-03-13 10:17:32 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
2010-03-13 10:17:32 ----A---- C:\Windows\system32\dxdiagn.dll
2010-03-13 10:17:32 ----A---- C:\Windows\system32\dxdiag.exe
2010-03-13 10:17:32 ----A---- C:\Windows\system32\d3d10warp.dll
2010-03-13 10:17:32 ----A---- C:\Windows\system32\d2d1.dll
2010-03-13 10:17:32 ----A---- C:\Windows\system32\cdd.dll
2010-03-13 10:17:31 ----A---- C:\Windows\system32\xpsservices.dll
2010-03-13 10:17:31 ----A---- C:\Windows\system32\OpcServices.dll
2010-03-13 10:17:31 ----A---- C:\Windows\system32\FntCache.dll
2010-03-13 10:17:31 ----A---- C:\Windows\system32\dxgi.dll
2010-03-13 10:17:31 ----A---- C:\Windows\system32\DWrite.dll
2010-03-13 10:17:31 ----A---- C:\Windows\system32\d3d11.dll
2010-03-13 10:17:31 ----A---- C:\Windows\system32\d3d10level9.dll
2010-03-13 10:17:31 ----A---- C:\Windows\system32\d3d10core.dll
2010-03-13 10:17:31 ----A---- C:\Windows\system32\d3d10_1core.dll
2010-03-13 10:17:31 ----A---- C:\Windows\system32\d3d10_1.dll
2010-03-13 10:17:31 ----A---- C:\Windows\system32\d3d10.dll
2010-03-13 10:17:14 ----A---- C:\Windows\system32\WPDShextAutoplay.exe
2010-03-13 10:17:14 ----A---- C:\Windows\system32\wpdbusenum.dll
2010-03-13 10:17:14 ----A---- C:\Windows\system32\BthMtpContextHandler.dll
2010-03-13 10:17:11 ----A---- C:\Windows\system32\PortableDeviceConnectApi.dll
2010-03-13 10:17:10 ----A---- C:\Windows\system32\WPDSp.dll
2010-03-13 10:17:10 ----A---- C:\Windows\system32\WPDShServiceObj.dll
2010-03-13 10:17:10 ----A---- C:\Windows\system32\wpdshext.dll
2010-03-13 10:17:10 ----A---- C:\Windows\system32\wpd_ci.dll
2010-03-13 10:17:10 ----A---- C:\Windows\system32\PortableDeviceWMDRM.dll
2010-03-13 10:17:10 ----A---- C:\Windows\system32\PortableDeviceTypes.dll
2010-03-13 10:17:10 ----A---- C:\Windows\system32\PortableDeviceClassExtension.dll
2010-03-13 10:17:10 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2010-03-13 10:16:40 ----A---- C:\Windows\system32\UIAutomationCore.dll
2010-03-13 10:16:40 ----A---- C:\Windows\system32\oleaccrc.dll
2010-03-13 10:16:40 ----A---- C:\Windows\system32\oleacc.dll
2010-03-13 10:13:58 ----A---- C:\Windows\system32\secproc_isv.dll
2010-03-13 10:13:57 ----A---- C:\Windows\system32\secproc.dll
2010-03-13 10:13:53 ----A---- C:\Windows\system32\RMActivate_isv.exe
2010-03-13 10:13:52 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2010-03-13 10:13:52 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2010-03-13 10:13:51 ----A---- C:\Windows\system32\RMActivate.exe
2010-03-13 10:13:50 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2010-03-13 10:13:50 ----A---- C:\Windows\system32\secproc_ssp.dll
2010-03-13 10:13:50 ----A---- C:\Windows\system32\msdrm.dll
2010-03-13 10:13:45 ----A---- C:\Windows\system32\gameux.dll
2010-03-13 10:13:43 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2010-03-13 10:13:43 ----A---- C:\Windows\system32\Apphlpdm.dll
2010-03-13 10:13:23 ----A---- C:\Windows\system32\wmp.dll
2010-03-13 10:13:18 ----A---- C:\Windows\system32\unregmp2.exe
2010-03-13 10:13:15 ----A---- C:\Windows\system32\wmploc.DLL
2010-03-13 10:01:42 ----A---- C:\Windows\system32\kerberos.dll
2010-03-13 10:01:39 ----A---- C:\Windows\system32\schannel.dll
2010-03-13 10:01:30 ----A---- C:\Windows\system32\msxml6.dll
2010-03-13 10:01:29 ----A---- C:\Windows\system32\msxml3.dll
2010-03-13 09:51:29 ----A---- C:\Windows\system32\tzres.dll
2010-03-13 09:51:08 ----A---- C:\Windows\system32\mstscax.dll
2010-03-13 09:50:54 ----A---- C:\Windows\system32\WMVCORE.DLL
2010-03-13 09:50:53 ----A---- C:\Windows\system32\mf.dll
2010-03-13 09:49:37 ----A---- C:\Windows\system32\WMSPDMOD.DLL
2010-03-13 09:40:55 ----A---- C:\Windows\system32\netiohlp.dll
2010-03-13 09:40:54 ----A---- C:\Windows\system32\NETSTAT.EXE
2010-03-13 09:40:54 ----A---- C:\Windows\system32\ARP.EXE
2010-03-13 09:40:53 ----A---- C:\Windows\system32\TCPSVCS.EXE
2010-03-13 09:40:53 ----A---- C:\Windows\system32\finger.exe
2010-03-13 09:40:52 ----A---- C:\Windows\system32\ROUTE.EXE
2010-03-13 09:40:52 ----A---- C:\Windows\system32\MRINFO.EXE
2010-03-13 09:40:52 ----A---- C:\Windows\system32\HOSTNAME.EXE
2010-03-13 09:40:50 ----A---- C:\Windows\system32\netevent.dll
2010-03-13 09:40:31 ----A---- C:\Windows\system32\wlanmsm.dll
2010-03-13 09:40:30 ----A---- C:\Windows\system32\L2SecHC.dll
2010-03-13 09:40:29 ----A---- C:\Windows\system32\wlansec.dll
2010-03-13 09:40:29 ----A---- C:\Windows\system32\wlanapi.dll
2010-03-13 09:40:28 ----A---- C:\Windows\system32\wlansvc.dll
2010-03-13 09:40:25 ----A---- C:\Windows\system32\wkssvc.dll
2010-03-13 09:40:21 ----A---- C:\Windows\system32\localspl.dll
2010-03-13 09:39:11 ----A---- C:\Windows\system32\rpcrt4.dll
2010-03-13 09:25:17 ----D---- C:\Windows\system32\vi-VN
2010-03-13 09:25:17 ----D---- C:\Windows\system32\eu-ES
2010-03-13 09:25:17 ----D---- C:\Windows\system32\ca-ES
2010-03-13 09:22:15 ----D---- C:\Windows\system32\SPReview
2010-03-13 09:13:06 ----A---- C:\Windows\system32\scavenge.dll
2010-03-13 09:13:02 ----A---- C:\Windows\system32\compcln.exe
2010-03-13 09:09:38 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2010-03-13 09:09:38 ----A---- C:\Windows\system32\SearchIndexer.exe
2010-03-13 09:09:38 ----A---- C:\Windows\system32\SearchFilterHost.exe
2010-03-13 09:09:37 ----A---- C:\Windows\system32\sdohlp.dll
2010-03-13 09:09:37 ----A---- C:\Windows\system32\sdclt.exe
2010-03-13 09:09:37 ----A---- C:\Windows\system32\scrrun.dll
2010-03-13 09:09:37 ----A---- C:\Windows\system32\SCardSvr.dll
2010-03-13 09:09:37 ----A---- C:\Windows\system32\scansetting.dll
2010-03-13 09:09:37 ----A---- C:\Windows\system32\samsrv.dll
2010-03-13 09:09:37 ----A---- C:\Windows\system32\samlib.dll
2010-03-13 09:09:37 ----A---- C:\Windows\system32\rtutils.dll
2010-03-13 09:09:37 ----A---- C:\Windows\system32\rtffilt.dll
2010-03-13 09:09:37 ----A---- C:\Windows\system32\rsaenh.dll
2010-03-13 09:09:37 ----A---- C:\Windows\system32\rrinstaller.exe
2010-03-13 09:09:37 ----A---- C:\Windows\system32\rpchttp.dll
2010-03-13 09:09:37 ----A---- C:\Windows\system32\rpcss.dll
2010-03-13 09:09:37 ----A---- C:\Windows\system32\riched20.dll
2010-03-13 09:09:36 ----A---- C:\Windows\system32\schedsvc.dll
2010-03-13 09:09:36 ----A---- C:\Windows\system32\scrobj.dll
2010-03-13 09:09:36 ----A---- C:\Windows\system32\scksp.dll
2010-03-13 09:09:36 ----A---- C:\Windows\system32\scesrv.dll
2010-03-13 09:09:36 ----A---- C:\Windows\system32\scecli.dll
2010-03-13 09:09:35 ----A---- C:\Windows\system32\powercpl.dll
2010-03-13 09:09:35 ----A---- C:\Windows\system32\PNPXAssoc.dll
2010-03-13 09:09:35 ----A---- C:\Windows\system32\PnPutil.exe
2010-03-13 09:09:35 ----A---- C:\Windows\system32\PnPUnattend.exe
2010-03-13 09:09:35 ----A---- C:\Windows\system32\pnpui.dll
2010-03-13 09:09:35 ----A---- C:\Windows\system32\pnpsetup.dll
2010-03-13 09:09:35 ----A---- C:\Windows\system32\pnidui.dll
2010-03-13 09:09:35 ----A---- C:\Windows\system32\perfdisk.dll
2010-03-13 09:09:35 ----A---- C:\Windows\system32\PerfCenterCPL.dll
2010-03-13 09:09:35 ----A---- C:\Windows\system32\pdh.dll
2010-03-13 09:09:35 ----A---- C:\Windows\system32\pcaui.dll
2010-03-13 09:09:35 ----A---- C:\Windows\system32\p2psvc.dll
2010-03-13 09:09:35 ----A---- C:\Windows\system32\P2PGraph.dll
2010-03-13 09:09:34 ----A---- C:\Windows\system32\PkgMgr.exe
2010-03-13 09:09:34 ----A---- C:\Windows\system32\pidgenx.dll
2010-03-13 09:09:34 ----A---- C:\Windows\system32\photowiz.dll
2010-03-13 09:09:34 ----A---- C:\Windows\system32\ntdll.dll
2010-03-13 09:09:34 ----A---- C:\Windows\system32\nslookup.exe
2010-03-13 09:09:33 ----A---- C:\Windows\system32\onex.dll
2010-03-13 09:09:33 ----A---- C:\Windows\system32\oleaut32.dll
2010-03-13 09:09:33 ----A---- C:\Windows\system32\ole32.dll
2010-03-13 09:09:33 ----A---- C:\Windows\system32\offfilt.dll
2010-03-13 09:09:33 ----A---- C:\Windows\system32\odbccp32.dll
2010-03-13 09:09:33 ----A---- C:\Windows\system32\odbcconf.dll
2010-03-13 09:09:33 ----A---- C:\Windows\system32\odbc32.dll
2010-03-13 09:09:33 ----A---- C:\Windows\system32\NlsLexicons0009.dll
2010-03-13 09:09:33 ----A---- C:\Windows\system32\NlsLexicons0007.dll
2010-03-13 09:09:33 ----A---- C:\Windows\system32\nlhtml.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\RelMon.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\rekeywiz.exe
2010-03-13 09:09:32 ----A---- C:\Windows\system32\regsvc.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\rastapi.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\rasppp.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\rasplap.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\rasmontr.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\rasmans.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\raschap.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\rasgcw.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\rasdlg.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\rasdial.exe
2010-03-13 09:09:32 ----A---- C:\Windows\system32\rasdiag.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\rasapi32.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\RacEngn.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\Query.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\qmgr.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\qedit.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\osk.exe
2010-03-13 09:09:32 ----A---- C:\Windows\system32\oobefldr.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\olepro32.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\oleprn.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\ocsetup.exe
2010-03-13 09:09:32 ----A---- C:\Windows\system32\ntprint.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\ntmarta.dll
2010-03-13 09:09:31 ----A---- C:\Windows\system32\regapi.dll
2010-03-13 09:09:31 ----A---- C:\Windows\system32\reg.exe
2010-03-13 09:09:31 ----A---- C:\Windows\system32\rdpwsx.dll
2010-03-13 09:09:31 ----A---- C:\Windows\system32\rdpencom.dll
2010-03-13 09:09:31 ----A---- C:\Windows\system32\puiapi.dll
2010-03-13 09:09:31 ----A---- C:\Windows\system32\prnntfy.dll
2010-03-13 09:09:31 ----A---- C:\Windows\system32\printui.dll
2010-03-13 09:09:31 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
2010-03-13 09:09:31 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2010-03-13 09:09:31 ----A---- C:\Windows\system32\PresentationHost.exe
2010-03-13 09:09:31 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2010-03-13 09:09:31 ----A---- C:\Windows\system32\powrprof.dll
2010-03-13 09:09:30 ----A---- C:\Windows\system32\qdvd.dll
2010-03-13 09:09:30 ----A---- C:\Windows\system32\QAGENTRT.DLL
2010-03-13 09:09:30 ----A---- C:\Windows\system32\psisdecd.dll
2010-03-13 09:09:30 ----A---- C:\Windows\system32\PSHED.DLL
2010-03-13 09:09:30 ----A---- C:\Windows\system32\propsys.dll
2010-03-13 09:09:30 ----A---- C:\Windows\system32\propdefs.dll
2010-03-13 09:09:30 ----A---- C:\Windows\system32\profsvc.dll
2010-03-13 09:09:29 ----A---- C:\Windows\system32\sendmail.dll
2010-03-13 09:09:28 ----A---- C:\Windows\system32\shlwapi.dll
2010-03-13 09:09:28 ----A---- C:\Windows\system32\shell32.dll
2010-03-13 09:09:28 ----A---- C:\Windows\system32\shdocvw.dll
2010-03-13 09:09:28 ----A---- C:\Windows\system32\setupapi.dll
2010-03-13 09:09:28 ----A---- C:\Windows\system32\sethc.exe
2010-03-13 09:09:28 ----A---- C:\Windows\system32\services.exe
2010-03-13 09:09:27 ----A---- C:\Windows\system32\eapphost.dll
2010-03-13 09:09:27 ----A---- C:\Windows\system32\eappgnui.dll
2010-03-13 09:09:27 ----A---- C:\Windows\system32\eappcfg.dll
2010-03-13 09:09:27 ----A---- C:\Windows\system32\eapp3hst.dll
2010-03-13 09:09:26 ----A---- C:\Windows\system32\EhStorAPI.dll
2010-03-13 09:09:25 ----A---- C:\Windows\system32\ExplorerFrame.dll
2010-03-13 09:09:25 ----A---- C:\Windows\system32\evr.dll
2010-03-13 09:09:25 ----A---- C:\Windows\system32\eudcedit.exe
2010-03-13 09:09:25 ----A---- C:\Windows\system32\dwm.exe
2010-03-13 09:09:25 ----A---- C:\Windows\system32\dsprop.dll
2010-03-13 09:09:25 ----A---- C:\Windows\system32\dsound.dll
2010-03-13 09:09:24 ----A---- C:\Windows\system32\f3ahvoas.dll
2010-03-13 09:09:24 ----A---- C:\Windows\system32\esent.dll
2010-03-13 09:09:24 ----A---- C:\Windows\system32\EncDec.dll
2010-03-13 09:09:24 ----A---- C:\Windows\system32\emdmgmt.dll
2010-03-13 09:09:24 ----A---- C:\Windows\system32\EhStorPwdMgr.dll
2010-03-13 09:09:24 ----A---- C:\Windows\system32\EhStorAuthn.dll
2010-03-13 09:09:24 ----A---- C:\Windows\explorer.exe
2010-03-13 09:09:23 ----A---- C:\Windows\system32\es.dll
2010-03-13 09:09:23 ----A---- C:\Windows\system32\EhStorShell.dll
2010-03-13 09:09:23 ----A---- C:\Windows\system32\diskraid.exe
2010-03-13 09:09:23 ----A---- C:\Windows\system32\diskpart.exe
2010-03-13 09:09:23 ----A---- C:\Windows\system32\dimsroam.dll
2010-03-13 09:09:23 ----A---- C:\Windows\system32\diagperf.dll
2010-03-13 09:09:23 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2010-03-13 09:09:23 ----A---- C:\Windows\system32\dfshim.dll
2010-03-13 09:09:22 ----A---- C:\Windows\system32\dpapimig.exe
2010-03-13 09:09:22 ----A---- C:\Windows\system32\dot3cfg.dll
2010-03-13 09:09:22 ----A---- C:\Windows\system32\dhcpcsvc.dll
2010-03-13 09:09:22 ----A---- C:\Windows\system32\dfsr.exe
2010-03-13 09:09:22 ----A---- C:\Windows\system32\devmgr.dll
2010-03-13 09:09:21 ----A---- C:\Windows\system32\hbaapi.dll
2010-03-13 09:09:21 ----A---- C:\Windows\system32\drvstore.dll
2010-03-13 09:09:21 ----A---- C:\Windows\system32\drvinst.exe
2010-03-13 09:09:21 ----A---- C:\Windows\system32\drmv2clt.dll
2010-03-13 09:09:21 ----A---- C:\Windows\system32\drmmgrtn.dll
2010-03-13 09:09:21 ----A---- C:\Windows\system32\dot3svc.dll
2010-03-13 09:09:21 ----A---- C:\Windows\system32\dot3msm.dll
2010-03-13 09:09:21 ----A---- C:\Windows\system32\dnsrslvr.dll
2010-03-13 09:09:21 ----A---- C:\Windows\system32\dnsapi.dll
2010-03-13 09:09:21 ----A---- C:\Windows\system32\dmusic.dll
2010-03-13 09:09:21 ----A---- C:\Windows\system32\dmsynth.dll
2010-03-13 09:09:20 ----A---- C:\Windows\system32\gpsvc.dll
2010-03-13 09:09:20 ----A---- C:\Windows\system32\gpresult.exe
2010-03-13 09:09:19 ----A---- C:\Windows\system32\iasnap.dll
2010-03-13 09:09:19 ----A---- C:\Windows\system32\iashlpr.dll
2010-03-13 09:09:19 ----A---- C:\Windows\system32\iasdatastore.dll
2010-03-13 09:09:19 ----A---- C:\Windows\system32\iasads.dll
2010-03-13 09:09:19 ----A---- C:\Windows\system32\iasacct.dll
2010-03-13 09:09:19 ----A---- C:\Windows\system32\gpupdate.exe
2010-03-13 09:09:18 ----A---- C:\Windows\system32\IasMigReader.exe
2010-03-13 09:09:18 ----A---- C:\Windows\system32\IasMigPlugin.dll
2010-03-13 09:09:17 ----A---- C:\Windows\system32\hidserv.dll
2010-03-13 09:09:17 ----A---- C:\Windows\system32\hdwwiz.exe
2010-03-13 09:09:17 ----A---- C:\Windows\system32\fontext.dll
2010-03-13 09:09:17 ----A---- C:\Windows\system32\findstr.exe
2010-03-13 09:09:17 ----A---- C:\Windows\system32\fc.exe
2010-03-13 09:09:17 ----A---- C:\Windows\system32\Faultrep.dll
2010-03-13 09:09:16 ----A---- C:\Windows\system32\gpedit.dll
2010-03-13 09:09:16 ----A---- C:\Windows\system32\gpapi.dll
2010-03-13 09:09:16 ----A---- C:\Windows\system32\gdi32.dll
2010-03-13 09:09:16 ----A---- C:\Windows\system32\fundisc.dll
2010-03-13 09:09:16 ----A---- C:\Windows\system32\feclient.dll
2010-03-13 09:09:16 ----A---- C:\Windows\system32\fdWSD.dll
2010-03-13 09:09:16 ----A---- C:\Windows\system32\fdWCN.dll
2010-03-13 09:09:16 ----A---- C:\Windows\system32\fdSSDP.dll
2010-03-13 09:09:16 ----A---- C:\Windows\system32\fdProxy.dll
2010-03-13 09:09:16 ----A---- C:\Windows\system32\fdeploy.dll
2010-03-13 09:09:16 ----A---- C:\Windows\system32\fdBthProxy.dll
2010-03-13 09:09:16 ----A---- C:\Windows\system32\fdBth.d
Run by Michal at 2010-03-23 21:20:05
Microsoft® Windows Vista™ Home Basic Service Pack 2
System drive C: has 106 GB (80%) free of 133 GB
Total RAM: 2039 MB (44% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:20:22, on 23. 3. 2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18882)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\pthosttr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Norton Internet Security\Engine\17.0.0.136\ccSvcHst.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Používateľ\Downloads\RSIT.exe
C:\Program Files\trend micro\Michal.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (file missing)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\17.0.0.136\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\17.0.0.136\IPSBHO.DLL
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\17.0.0.136\coIEPlg.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [PTHOSTTR] C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\RunOnce: [AVG FirstScan] "C:\Program Files\AVG\AVG9\avgfrw.exe" /firstscan /delay=120 /runonce
O4 - HKLM\..\RunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstall ... er=9.0.790
O4 - HKCU\..\RunOnce: [SYMNRT] C:\Program Files\Internet Explorer\iexplore.exe http://www.symantec.com/techsupp/servle ... 5.0000034c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O13 - Gopher Prefix:
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: DeviceNP - C:\Windows\SYSTEM32\DeviceNP.dll
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\Windows\system32\AEADISRV.EXE
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Ltd - C:\Windows\system32\flcdlock.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\17.0.0.136\ccSvcHst.exe
--
End of file - 5616 bytes
======Scheduled tasks folder======
C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
C:\Windows\tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Symantec NCO BHO - C:\Program Files\Norton Internet Security\Engine\17.0.0.136\coIEPlg.dll [2009-08-29 392560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Symantec Intrusion Prevention - C:\Program Files\Norton Internet Security\Engine\17.0.0.136\IPSBHO.DLL [2009-08-30 79224]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files\Norton Internet Security\Engine\17.0.0.136\coIEPlg.dll [2009-08-29 392560]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"PTHOSTTR"=C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE [2007-01-09 145184]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-03-27 1045800]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-05-22 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2008-05-22 166424]
"Persistence"=C:\Windows\system32\igfxpers.exe [2008-05-22 133656]
"QlbCtrl.exe"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2008-05-14 177456]
"hpWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2008-04-15 488752]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2007-02-21 1183744]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"AVG FirstScan"=C:\Program Files\AVG\AVG9\avgfrw.exe /firstscan /delay=120 /runonce []
"AvgUninstallURL"=cmd.exe /c start http://www.avg.com/ww.special-uninstall ... er=9.0.790 []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SYMNRT"=C:\Program Files\Internet Explorer\iexplore.exe [2010-01-02 638216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-12-11 948672]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-12-22 35760]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
C:\Program Files\ICQ7.0\ICQ.exe silent loginmode=4 []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^DVD Check.lnk]
C:\PROGRA~1\INTERV~1\DVDCHE~1\DVDCheck.exe [2008-05-23 197904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DeviceNP]
C:\Windows\system32\DeviceNP.dll [2007-06-08 49152]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2008-02-11 204800]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=
"NoDriveTypeAutoRun"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2010-03-23 21:20:05 ----D---- C:\rsit
2010-03-23 21:20:05 ----D---- C:\Program Files\trend micro
2010-03-23 20:53:17 ----D---- C:\Users\Michal\AppData\Roaming\Tific
2010-03-23 20:52:33 ----D---- C:\Program Files\Common Files\Symantec Shared
2010-03-23 20:51:57 ----D---- C:\Program Files\Norton Internet Security
2010-03-23 20:51:50 ----D---- C:\Program Files\NortonInstaller
2010-03-23 20:02:32 ----D---- C:\Program Files\AVG
2010-03-23 20:02:08 ----D---- C:\ProgramData\avg9
2010-03-20 18:10:02 ----D---- C:\Program Files\7-Zip
2010-03-20 17:42:36 ----D---- C:\ProgramData\Kaspersky Lab
2010-03-20 17:31:32 ----D---- C:\ProgramData\Kaspersky Lab Setup Files
2010-03-18 15:33:24 ----D---- C:\ProgramData\Symantec
2010-03-17 18:01:18 ----RA---- C:\Windows\system32\GEARAspi.dll
2010-03-17 18:01:17 ----DC---- C:\Windows\system32\DRVSTORE
2010-03-17 18:00:55 ----D---- C:\Program Files\Symantec
2010-03-17 18:00:17 ----D---- C:\ProgramData\Norton
2010-03-17 17:58:44 ----D---- C:\ProgramData\NortonInstaller
2010-03-15 19:05:12 ----D---- C:\ProgramData\Mozilla
2010-03-13 19:57:55 ----D---- C:\Program Files\Microsoft Silverlight
2010-03-13 19:15:46 ----D---- C:\Program Files\LSI SoftModem
2010-03-13 13:17:57 ----A---- C:\Windows\system32\winhttp.dll
2010-03-13 13:17:51 ----A---- C:\Windows\system32\httpapi.dll
2010-03-13 13:17:50 ----A---- C:\Windows\system32\nshhttp.dll
2010-03-13 10:18:30 ----D---- C:\Program Files\Windows Portable Devices
2010-03-13 10:17:54 ----A---- C:\Windows\system32\UIAnimation.dll
2010-03-13 10:17:53 ----A---- C:\Windows\system32\UIRibbonRes.dll
2010-03-13 10:17:53 ----A---- C:\Windows\system32\UIRibbon.dll
2010-03-13 10:17:33 ----A---- C:\Windows\system32\WMPhoto.dll
2010-03-13 10:17:32 ----A---- C:\Windows\system32\XpsRasterService.dll
2010-03-13 10:17:32 ----A---- C:\Windows\system32\XpsPrint.dll
2010-03-13 10:17:32 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2010-03-13 10:17:32 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2010-03-13 10:17:32 ----A---- C:\Windows\system32\WindowsCodecs.dll
2010-03-13 10:17:32 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
2010-03-13 10:17:32 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll
2010-03-13 10:17:32 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
2010-03-13 10:17:32 ----A---- C:\Windows\system32\dxdiagn.dll
2010-03-13 10:17:32 ----A---- C:\Windows\system32\dxdiag.exe
2010-03-13 10:17:32 ----A---- C:\Windows\system32\d3d10warp.dll
2010-03-13 10:17:32 ----A---- C:\Windows\system32\d2d1.dll
2010-03-13 10:17:32 ----A---- C:\Windows\system32\cdd.dll
2010-03-13 10:17:31 ----A---- C:\Windows\system32\xpsservices.dll
2010-03-13 10:17:31 ----A---- C:\Windows\system32\OpcServices.dll
2010-03-13 10:17:31 ----A---- C:\Windows\system32\FntCache.dll
2010-03-13 10:17:31 ----A---- C:\Windows\system32\dxgi.dll
2010-03-13 10:17:31 ----A---- C:\Windows\system32\DWrite.dll
2010-03-13 10:17:31 ----A---- C:\Windows\system32\d3d11.dll
2010-03-13 10:17:31 ----A---- C:\Windows\system32\d3d10level9.dll
2010-03-13 10:17:31 ----A---- C:\Windows\system32\d3d10core.dll
2010-03-13 10:17:31 ----A---- C:\Windows\system32\d3d10_1core.dll
2010-03-13 10:17:31 ----A---- C:\Windows\system32\d3d10_1.dll
2010-03-13 10:17:31 ----A---- C:\Windows\system32\d3d10.dll
2010-03-13 10:17:14 ----A---- C:\Windows\system32\WPDShextAutoplay.exe
2010-03-13 10:17:14 ----A---- C:\Windows\system32\wpdbusenum.dll
2010-03-13 10:17:14 ----A---- C:\Windows\system32\BthMtpContextHandler.dll
2010-03-13 10:17:11 ----A---- C:\Windows\system32\PortableDeviceConnectApi.dll
2010-03-13 10:17:10 ----A---- C:\Windows\system32\WPDSp.dll
2010-03-13 10:17:10 ----A---- C:\Windows\system32\WPDShServiceObj.dll
2010-03-13 10:17:10 ----A---- C:\Windows\system32\wpdshext.dll
2010-03-13 10:17:10 ----A---- C:\Windows\system32\wpd_ci.dll
2010-03-13 10:17:10 ----A---- C:\Windows\system32\PortableDeviceWMDRM.dll
2010-03-13 10:17:10 ----A---- C:\Windows\system32\PortableDeviceTypes.dll
2010-03-13 10:17:10 ----A---- C:\Windows\system32\PortableDeviceClassExtension.dll
2010-03-13 10:17:10 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2010-03-13 10:16:40 ----A---- C:\Windows\system32\UIAutomationCore.dll
2010-03-13 10:16:40 ----A---- C:\Windows\system32\oleaccrc.dll
2010-03-13 10:16:40 ----A---- C:\Windows\system32\oleacc.dll
2010-03-13 10:13:58 ----A---- C:\Windows\system32\secproc_isv.dll
2010-03-13 10:13:57 ----A---- C:\Windows\system32\secproc.dll
2010-03-13 10:13:53 ----A---- C:\Windows\system32\RMActivate_isv.exe
2010-03-13 10:13:52 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2010-03-13 10:13:52 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2010-03-13 10:13:51 ----A---- C:\Windows\system32\RMActivate.exe
2010-03-13 10:13:50 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2010-03-13 10:13:50 ----A---- C:\Windows\system32\secproc_ssp.dll
2010-03-13 10:13:50 ----A---- C:\Windows\system32\msdrm.dll
2010-03-13 10:13:45 ----A---- C:\Windows\system32\gameux.dll
2010-03-13 10:13:43 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2010-03-13 10:13:43 ----A---- C:\Windows\system32\Apphlpdm.dll
2010-03-13 10:13:23 ----A---- C:\Windows\system32\wmp.dll
2010-03-13 10:13:18 ----A---- C:\Windows\system32\unregmp2.exe
2010-03-13 10:13:15 ----A---- C:\Windows\system32\wmploc.DLL
2010-03-13 10:01:42 ----A---- C:\Windows\system32\kerberos.dll
2010-03-13 10:01:39 ----A---- C:\Windows\system32\schannel.dll
2010-03-13 10:01:30 ----A---- C:\Windows\system32\msxml6.dll
2010-03-13 10:01:29 ----A---- C:\Windows\system32\msxml3.dll
2010-03-13 09:51:29 ----A---- C:\Windows\system32\tzres.dll
2010-03-13 09:51:08 ----A---- C:\Windows\system32\mstscax.dll
2010-03-13 09:50:54 ----A---- C:\Windows\system32\WMVCORE.DLL
2010-03-13 09:50:53 ----A---- C:\Windows\system32\mf.dll
2010-03-13 09:49:37 ----A---- C:\Windows\system32\WMSPDMOD.DLL
2010-03-13 09:40:55 ----A---- C:\Windows\system32\netiohlp.dll
2010-03-13 09:40:54 ----A---- C:\Windows\system32\NETSTAT.EXE
2010-03-13 09:40:54 ----A---- C:\Windows\system32\ARP.EXE
2010-03-13 09:40:53 ----A---- C:\Windows\system32\TCPSVCS.EXE
2010-03-13 09:40:53 ----A---- C:\Windows\system32\finger.exe
2010-03-13 09:40:52 ----A---- C:\Windows\system32\ROUTE.EXE
2010-03-13 09:40:52 ----A---- C:\Windows\system32\MRINFO.EXE
2010-03-13 09:40:52 ----A---- C:\Windows\system32\HOSTNAME.EXE
2010-03-13 09:40:50 ----A---- C:\Windows\system32\netevent.dll
2010-03-13 09:40:31 ----A---- C:\Windows\system32\wlanmsm.dll
2010-03-13 09:40:30 ----A---- C:\Windows\system32\L2SecHC.dll
2010-03-13 09:40:29 ----A---- C:\Windows\system32\wlansec.dll
2010-03-13 09:40:29 ----A---- C:\Windows\system32\wlanapi.dll
2010-03-13 09:40:28 ----A---- C:\Windows\system32\wlansvc.dll
2010-03-13 09:40:25 ----A---- C:\Windows\system32\wkssvc.dll
2010-03-13 09:40:21 ----A---- C:\Windows\system32\localspl.dll
2010-03-13 09:39:11 ----A---- C:\Windows\system32\rpcrt4.dll
2010-03-13 09:25:17 ----D---- C:\Windows\system32\vi-VN
2010-03-13 09:25:17 ----D---- C:\Windows\system32\eu-ES
2010-03-13 09:25:17 ----D---- C:\Windows\system32\ca-ES
2010-03-13 09:22:15 ----D---- C:\Windows\system32\SPReview
2010-03-13 09:13:06 ----A---- C:\Windows\system32\scavenge.dll
2010-03-13 09:13:02 ----A---- C:\Windows\system32\compcln.exe
2010-03-13 09:09:38 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2010-03-13 09:09:38 ----A---- C:\Windows\system32\SearchIndexer.exe
2010-03-13 09:09:38 ----A---- C:\Windows\system32\SearchFilterHost.exe
2010-03-13 09:09:37 ----A---- C:\Windows\system32\sdohlp.dll
2010-03-13 09:09:37 ----A---- C:\Windows\system32\sdclt.exe
2010-03-13 09:09:37 ----A---- C:\Windows\system32\scrrun.dll
2010-03-13 09:09:37 ----A---- C:\Windows\system32\SCardSvr.dll
2010-03-13 09:09:37 ----A---- C:\Windows\system32\scansetting.dll
2010-03-13 09:09:37 ----A---- C:\Windows\system32\samsrv.dll
2010-03-13 09:09:37 ----A---- C:\Windows\system32\samlib.dll
2010-03-13 09:09:37 ----A---- C:\Windows\system32\rtutils.dll
2010-03-13 09:09:37 ----A---- C:\Windows\system32\rtffilt.dll
2010-03-13 09:09:37 ----A---- C:\Windows\system32\rsaenh.dll
2010-03-13 09:09:37 ----A---- C:\Windows\system32\rrinstaller.exe
2010-03-13 09:09:37 ----A---- C:\Windows\system32\rpchttp.dll
2010-03-13 09:09:37 ----A---- C:\Windows\system32\rpcss.dll
2010-03-13 09:09:37 ----A---- C:\Windows\system32\riched20.dll
2010-03-13 09:09:36 ----A---- C:\Windows\system32\schedsvc.dll
2010-03-13 09:09:36 ----A---- C:\Windows\system32\scrobj.dll
2010-03-13 09:09:36 ----A---- C:\Windows\system32\scksp.dll
2010-03-13 09:09:36 ----A---- C:\Windows\system32\scesrv.dll
2010-03-13 09:09:36 ----A---- C:\Windows\system32\scecli.dll
2010-03-13 09:09:35 ----A---- C:\Windows\system32\powercpl.dll
2010-03-13 09:09:35 ----A---- C:\Windows\system32\PNPXAssoc.dll
2010-03-13 09:09:35 ----A---- C:\Windows\system32\PnPutil.exe
2010-03-13 09:09:35 ----A---- C:\Windows\system32\PnPUnattend.exe
2010-03-13 09:09:35 ----A---- C:\Windows\system32\pnpui.dll
2010-03-13 09:09:35 ----A---- C:\Windows\system32\pnpsetup.dll
2010-03-13 09:09:35 ----A---- C:\Windows\system32\pnidui.dll
2010-03-13 09:09:35 ----A---- C:\Windows\system32\perfdisk.dll
2010-03-13 09:09:35 ----A---- C:\Windows\system32\PerfCenterCPL.dll
2010-03-13 09:09:35 ----A---- C:\Windows\system32\pdh.dll
2010-03-13 09:09:35 ----A---- C:\Windows\system32\pcaui.dll
2010-03-13 09:09:35 ----A---- C:\Windows\system32\p2psvc.dll
2010-03-13 09:09:35 ----A---- C:\Windows\system32\P2PGraph.dll
2010-03-13 09:09:34 ----A---- C:\Windows\system32\PkgMgr.exe
2010-03-13 09:09:34 ----A---- C:\Windows\system32\pidgenx.dll
2010-03-13 09:09:34 ----A---- C:\Windows\system32\photowiz.dll
2010-03-13 09:09:34 ----A---- C:\Windows\system32\ntdll.dll
2010-03-13 09:09:34 ----A---- C:\Windows\system32\nslookup.exe
2010-03-13 09:09:33 ----A---- C:\Windows\system32\onex.dll
2010-03-13 09:09:33 ----A---- C:\Windows\system32\oleaut32.dll
2010-03-13 09:09:33 ----A---- C:\Windows\system32\ole32.dll
2010-03-13 09:09:33 ----A---- C:\Windows\system32\offfilt.dll
2010-03-13 09:09:33 ----A---- C:\Windows\system32\odbccp32.dll
2010-03-13 09:09:33 ----A---- C:\Windows\system32\odbcconf.dll
2010-03-13 09:09:33 ----A---- C:\Windows\system32\odbc32.dll
2010-03-13 09:09:33 ----A---- C:\Windows\system32\NlsLexicons0009.dll
2010-03-13 09:09:33 ----A---- C:\Windows\system32\NlsLexicons0007.dll
2010-03-13 09:09:33 ----A---- C:\Windows\system32\nlhtml.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\RelMon.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\rekeywiz.exe
2010-03-13 09:09:32 ----A---- C:\Windows\system32\regsvc.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\rastapi.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\rasppp.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\rasplap.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\rasmontr.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\rasmans.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\raschap.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\rasgcw.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\rasdlg.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\rasdial.exe
2010-03-13 09:09:32 ----A---- C:\Windows\system32\rasdiag.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\rasapi32.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\RacEngn.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\Query.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\qmgr.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\qedit.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\osk.exe
2010-03-13 09:09:32 ----A---- C:\Windows\system32\oobefldr.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\olepro32.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\oleprn.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\ocsetup.exe
2010-03-13 09:09:32 ----A---- C:\Windows\system32\ntprint.dll
2010-03-13 09:09:32 ----A---- C:\Windows\system32\ntmarta.dll
2010-03-13 09:09:31 ----A---- C:\Windows\system32\regapi.dll
2010-03-13 09:09:31 ----A---- C:\Windows\system32\reg.exe
2010-03-13 09:09:31 ----A---- C:\Windows\system32\rdpwsx.dll
2010-03-13 09:09:31 ----A---- C:\Windows\system32\rdpencom.dll
2010-03-13 09:09:31 ----A---- C:\Windows\system32\puiapi.dll
2010-03-13 09:09:31 ----A---- C:\Windows\system32\prnntfy.dll
2010-03-13 09:09:31 ----A---- C:\Windows\system32\printui.dll
2010-03-13 09:09:31 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
2010-03-13 09:09:31 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2010-03-13 09:09:31 ----A---- C:\Windows\system32\PresentationHost.exe
2010-03-13 09:09:31 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2010-03-13 09:09:31 ----A---- C:\Windows\system32\powrprof.dll
2010-03-13 09:09:30 ----A---- C:\Windows\system32\qdvd.dll
2010-03-13 09:09:30 ----A---- C:\Windows\system32\QAGENTRT.DLL
2010-03-13 09:09:30 ----A---- C:\Windows\system32\psisdecd.dll
2010-03-13 09:09:30 ----A---- C:\Windows\system32\PSHED.DLL
2010-03-13 09:09:30 ----A---- C:\Windows\system32\propsys.dll
2010-03-13 09:09:30 ----A---- C:\Windows\system32\propdefs.dll
2010-03-13 09:09:30 ----A---- C:\Windows\system32\profsvc.dll
2010-03-13 09:09:29 ----A---- C:\Windows\system32\sendmail.dll
2010-03-13 09:09:28 ----A---- C:\Windows\system32\shlwapi.dll
2010-03-13 09:09:28 ----A---- C:\Windows\system32\shell32.dll
2010-03-13 09:09:28 ----A---- C:\Windows\system32\shdocvw.dll
2010-03-13 09:09:28 ----A---- C:\Windows\system32\setupapi.dll
2010-03-13 09:09:28 ----A---- C:\Windows\system32\sethc.exe
2010-03-13 09:09:28 ----A---- C:\Windows\system32\services.exe
2010-03-13 09:09:27 ----A---- C:\Windows\system32\eapphost.dll
2010-03-13 09:09:27 ----A---- C:\Windows\system32\eappgnui.dll
2010-03-13 09:09:27 ----A---- C:\Windows\system32\eappcfg.dll
2010-03-13 09:09:27 ----A---- C:\Windows\system32\eapp3hst.dll
2010-03-13 09:09:26 ----A---- C:\Windows\system32\EhStorAPI.dll
2010-03-13 09:09:25 ----A---- C:\Windows\system32\ExplorerFrame.dll
2010-03-13 09:09:25 ----A---- C:\Windows\system32\evr.dll
2010-03-13 09:09:25 ----A---- C:\Windows\system32\eudcedit.exe
2010-03-13 09:09:25 ----A---- C:\Windows\system32\dwm.exe
2010-03-13 09:09:25 ----A---- C:\Windows\system32\dsprop.dll
2010-03-13 09:09:25 ----A---- C:\Windows\system32\dsound.dll
2010-03-13 09:09:24 ----A---- C:\Windows\system32\f3ahvoas.dll
2010-03-13 09:09:24 ----A---- C:\Windows\system32\esent.dll
2010-03-13 09:09:24 ----A---- C:\Windows\system32\EncDec.dll
2010-03-13 09:09:24 ----A---- C:\Windows\system32\emdmgmt.dll
2010-03-13 09:09:24 ----A---- C:\Windows\system32\EhStorPwdMgr.dll
2010-03-13 09:09:24 ----A---- C:\Windows\system32\EhStorAuthn.dll
2010-03-13 09:09:24 ----A---- C:\Windows\explorer.exe
2010-03-13 09:09:23 ----A---- C:\Windows\system32\es.dll
2010-03-13 09:09:23 ----A---- C:\Windows\system32\EhStorShell.dll
2010-03-13 09:09:23 ----A---- C:\Windows\system32\diskraid.exe
2010-03-13 09:09:23 ----A---- C:\Windows\system32\diskpart.exe
2010-03-13 09:09:23 ----A---- C:\Windows\system32\dimsroam.dll
2010-03-13 09:09:23 ----A---- C:\Windows\system32\diagperf.dll
2010-03-13 09:09:23 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2010-03-13 09:09:23 ----A---- C:\Windows\system32\dfshim.dll
2010-03-13 09:09:22 ----A---- C:\Windows\system32\dpapimig.exe
2010-03-13 09:09:22 ----A---- C:\Windows\system32\dot3cfg.dll
2010-03-13 09:09:22 ----A---- C:\Windows\system32\dhcpcsvc.dll
2010-03-13 09:09:22 ----A---- C:\Windows\system32\dfsr.exe
2010-03-13 09:09:22 ----A---- C:\Windows\system32\devmgr.dll
2010-03-13 09:09:21 ----A---- C:\Windows\system32\hbaapi.dll
2010-03-13 09:09:21 ----A---- C:\Windows\system32\drvstore.dll
2010-03-13 09:09:21 ----A---- C:\Windows\system32\drvinst.exe
2010-03-13 09:09:21 ----A---- C:\Windows\system32\drmv2clt.dll
2010-03-13 09:09:21 ----A---- C:\Windows\system32\drmmgrtn.dll
2010-03-13 09:09:21 ----A---- C:\Windows\system32\dot3svc.dll
2010-03-13 09:09:21 ----A---- C:\Windows\system32\dot3msm.dll
2010-03-13 09:09:21 ----A---- C:\Windows\system32\dnsrslvr.dll
2010-03-13 09:09:21 ----A---- C:\Windows\system32\dnsapi.dll
2010-03-13 09:09:21 ----A---- C:\Windows\system32\dmusic.dll
2010-03-13 09:09:21 ----A---- C:\Windows\system32\dmsynth.dll
2010-03-13 09:09:20 ----A---- C:\Windows\system32\gpsvc.dll
2010-03-13 09:09:20 ----A---- C:\Windows\system32\gpresult.exe
2010-03-13 09:09:19 ----A---- C:\Windows\system32\iasnap.dll
2010-03-13 09:09:19 ----A---- C:\Windows\system32\iashlpr.dll
2010-03-13 09:09:19 ----A---- C:\Windows\system32\iasdatastore.dll
2010-03-13 09:09:19 ----A---- C:\Windows\system32\iasads.dll
2010-03-13 09:09:19 ----A---- C:\Windows\system32\iasacct.dll
2010-03-13 09:09:19 ----A---- C:\Windows\system32\gpupdate.exe
2010-03-13 09:09:18 ----A---- C:\Windows\system32\IasMigReader.exe
2010-03-13 09:09:18 ----A---- C:\Windows\system32\IasMigPlugin.dll
2010-03-13 09:09:17 ----A---- C:\Windows\system32\hidserv.dll
2010-03-13 09:09:17 ----A---- C:\Windows\system32\hdwwiz.exe
2010-03-13 09:09:17 ----A---- C:\Windows\system32\fontext.dll
2010-03-13 09:09:17 ----A---- C:\Windows\system32\findstr.exe
2010-03-13 09:09:17 ----A---- C:\Windows\system32\fc.exe
2010-03-13 09:09:17 ----A---- C:\Windows\system32\Faultrep.dll
2010-03-13 09:09:16 ----A---- C:\Windows\system32\gpedit.dll
2010-03-13 09:09:16 ----A---- C:\Windows\system32\gpapi.dll
2010-03-13 09:09:16 ----A---- C:\Windows\system32\gdi32.dll
2010-03-13 09:09:16 ----A---- C:\Windows\system32\fundisc.dll
2010-03-13 09:09:16 ----A---- C:\Windows\system32\feclient.dll
2010-03-13 09:09:16 ----A---- C:\Windows\system32\fdWSD.dll
2010-03-13 09:09:16 ----A---- C:\Windows\system32\fdWCN.dll
2010-03-13 09:09:16 ----A---- C:\Windows\system32\fdSSDP.dll
2010-03-13 09:09:16 ----A---- C:\Windows\system32\fdProxy.dll
2010-03-13 09:09:16 ----A---- C:\Windows\system32\fdeploy.dll
2010-03-13 09:09:16 ----A---- C:\Windows\system32\fdBthProxy.dll
2010-03-13 09:09:16 ----A---- C:\Windows\system32\fdBth.d