Logfile of random's system information tool 1.05 (written by random/random)
Run by 1 at 2009-02-14 17:13:20
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 61 GB (77%) free of 80 GB
Total RAM: 2047 MB (54% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:13:48, on 14.02.2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe
C:\Program Files\Hewlett-Packard\ToolBoxFX\bin\HPTLBXFX.exe
C:\Program Files\Winamp\winampa.exe
C:\PROGRA~1\SYMANT~1\vptray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\ASUS\WLAN Card Utilities\Center.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe
C:\Program Files\TRENDware\TEW504UB\ACU.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
L:\Software\SYMANT~1.2-N\INSTAL~1\NSCTOP.EXE
C:\Program Files\MagicDisc\MagicDisc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Prevx\prevx.exe
C:\Program Files\Prevx\prevx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Real\RealPlayer\realplay.exe
C:\Program Files\StrongDC++\StrongDC.exe
C:\Documents and Settings\1\Рабочий стол\RSIT.exe
C:\Program Files\trend micro\1.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://securityrespo...r/fix_homepage/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://securityrespo...r/fix_homepage/R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Ссылки
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: (no name) - {27C57E1A-0B8F-4FB9-91F6-F2B38567AE73} - C:\WINDOWS\system32\avifil.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program
Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows
Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common
Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ToolBoxFX] "C:\Program Files\Hewlett-Packard\ToolBoxFX\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /systrayIcon:on /fl:on
/fr:on /appData:on
O4 - HKLM\..\Run: [zzzHPSETUP] E:\Setup.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\\vptray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Control Center] C:\Program Files\ASUS\WLAN Card Utilities\Center.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [basicsmssmenu] "C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe"
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [ACU] "C:\Program Files\TRENDware\TEW504UB\ACU.exe" -nogui
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Global Startup: 802.11a_g Wireless Client Utility.lnk = ?
O4 - Global Startup: Ускоренный запуск Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp
Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: &Экспорт в Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Add to Windows &Live Favorites -
http://favorites.liv...m/quickadd.aspxO8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common
Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common
Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Справочные материалы - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.mi...b?1269032225296O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.mi...b?1206016445125O17 - HKLM\System\CCS\Services\Tcpip\..\{14746F4B-1A8D-4B1E-B6FE-3B5B09C1DFE0}: NameServer = 85.255.112.16;85.255.112.79
O17 - HKLM\System\CCS\Services\Tcpip\..\{B1A619F4-3DEF-4F9D-ABF7-CE26522AADE2}: NameServer = 85.255.112.16;85.255.112.79
O17 - HKLM\System\CS1\Services\Tcpip\..\{14746F4B-1A8D-4B1E-B6FE-3B5B09C1DFE0}: NameServer = 192.168.0.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{14746F4B-1A8D-4B1E-B6FE-3B5B09C1DFE0}: NameServer = 85.255.112.16;85.255.112.79
O17 - HKLM\System\CS3\Services\Tcpip\..\{14746F4B-1A8D-4B1E-B6FE-3B5B09C1DFE0}: NameServer = 85.255.112.16;85.255.112.79
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: acaptuser32.dll
O23 - Service: ABBYY FineReader 9.0 PE Licensing Service (ABBYY.Licensing.FineReader.Professional.9.0) - ABBYY (BIT Software) - C:\Program Files\Common
Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: ASWLSVC - Unknown owner - C:\WINDOWS\system32\ASWLSVC.exe
O23 - Service: Basics Service - Seagate Technology LLC - C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: CSIScanner - Prevx - C:\Program Files\Prevx\prevx.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Журнал событий (Eventlog) - Корпорация Майкрософт - C:\WINDOWS\system32\services.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet
Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Служба COM записи компакт-дисков IMAPI (ImapiService) - Корпорация Майкрософт - C:\WINDOWS\system32\imapi.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NetMeeting Remote Desktop Sharing (mnmsrvc) - Корпорация Майкрософт - C:\WINDOWS\system32\mnmsrvc.exe
O23 - Service: Symantec System Center Discovery Service (NSCTOP) - Symantec Corporation - L:\Software\SYMANT~1.2-N\INSTAL~1\NSCTOP.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Plug and Play (PlugPlay) - Корпорация Майкрософт - C:\WINDOWS\system32\services.exe
O23 - Service: Диспетчер сеанса справки для удаленного рабочего стола (RDSessMgr) - Корпорация Майкрософт - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Смарт-карты (SCardSvr) - Корпорация Майкрософт - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Sony SCSI Helper Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Журналы и оповещения производительности (SysmonLog) - Корпорация Майкрософт - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: Теневое копирование тома (VSS) - Корпорация Майкрософт - C:\WINDOWS\System32\vssvc.exe
O23 - Service: Адаптер производительности WMI (WmiApSrv) - Корпорация Майкрософт - C:\WINDOWS\system32\wbem\wmiapsrv.exe
--
End of file - 14262 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2008-09-23 1088296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
Winamp Toolbar Loader - C:\Program Files\Winamp Toolbar\winamptb.dll [2008-03-20 1267040]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27C57E1A-0B8F-4FB9-91F6-F2B38567AE73}]
C:\WINDOWS\system32\avifil.dll [2008-11-25 116480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2009-01-31 304736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-11-23 320920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2006-08-31 322368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11 345480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll [2008-10-19 652784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live Toolbar\msntb.dll [2006-09-27 544032]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-11-23 34816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-11-23 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
SmartSelect Class - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11 345480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - Winamp Toolbar - C:\Program Files\Winamp Toolbar\winamptb.dll [2008-03-20 1267040]
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - Windows Live Toolbar - C:\Program Files\Windows Live Toolbar\msntb.dll [2006-09-27 544032]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11 345480]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ToolBoxFX"=C:\Program Files\Hewlett-Packard\ToolBoxFX\bin\HPTLBXFX.exe [2007-03-26 53248]
"zzzHPSETUP"=E:\Setup.exe []
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2008-03-27 36352]
"vptray"=C:\PROGRA~1\SYMANT~1\\vptray.exe [2008-09-30 125368]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2009-01-31 185872]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-11-23 136600]
"PWRISOVM.EXE"=C:\Program Files\PowerISO\PWRISOVM.EXE [2008-03-15 233472]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"HP Software Update"=C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe [2007-03-11 49152]
"Control Center"=C:\Program Files\ASUS\WLAN Card Utilities\Center.exe [2006-03-02 1667584]
"ccApp"=C:\Program Files\Common Files\Symantec Shared\ccApp.exe [2008-06-24 53096]
"basicsmssmenu"=C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe [2007-10-09 169328]
"Adobe Acrobat Speed Launcher"=C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [2008-06-12 37232]
"ACU"=C:\Program Files\TRENDware\TEW504UB\ACU.exe [2005-04-21 323584]
"Acrobat Assistant 8.0"=C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [2008-06-11 640376]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2009-02-11 399504]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2008-09-23 21755688]
"MsnMsgr"=C:\Program Files\MSN Messenger\MsnMsgr.Exe [2007-01-19 5674352]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"uTorrent"=C:\Program Files\uTorrent\uTorrent.exe [2008-10-09 270128]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPUsageTracking]
C:\Program Files\Hewlett-Packard\HP UT\bin\hppusg.exe [2007-05-03 36864]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
C:\WINDOWS\system32\NvCpl.dll [2007-11-06 8523776]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
C:\WINDOWS\system32\NvMcTray.dll [2007-11-06 81920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NWEReboot]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
C:\WINDOWS\RTHDCPL.EXE [2007-03-21 16126464]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
C:\Program Files\uTorrent\uTorrent.exe [2008-10-09 270128]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^1^Главное
меню^Программы^Автозагрузка^StrongDC++.lnk]
C:\PROGRA~1\STRONG~1\StrongDC.exe [2006-11-05 2736128]
C:\Documents and Settings\All Users\Главное меню\Программы\Автозагрузка
802.11a_g Wireless Client Utility.lnk - C:\Program Files\TRENDware\TEW504UB\WLACU.exe
Ускоренный запуск Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Documents and Settings\1\Главное меню\Программы\Автозагрузка
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
MagicDisc.lnk - C:\Program Files\MagicDisc\MagicDisc.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="acaptuser32.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
C:\WINDOWS\system32\NavLogon.dll [2008-09-30 43448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Real\RealPlayer\realplay.exe"="C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\C]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\boot.com c:
shell\Open\command - C:\resycled\boot.com c:
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\boot.com d:
shell\Open\command - D:\resycled\boot.com d:
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\L]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\boot.com l:
shell\Open\command - L:\resycled\boot.com l:
======List of files/folders created in the last 3 months======
2010-03-19 23:57:53 ----A---- C:\WINDOWS\system32\wucltui.dll.mui
2010-03-19 23:57:52 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2010-03-19 23:57:52 ----A---- C:\WINDOWS\system32\wuaueng.dll.mui
2010-03-19 23:57:52 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
2010-03-19 23:12:54 ----A---- C:\WINDOWS\system32\RemSvc.exe
2010-03-19 23:12:54 ----A---- C:\WINDOWS\system32\ASWLSVC.exe
2010-03-19 23:12:54 ----A---- C:\WINDOWS\system32\ASWL2K.exe
2010-03-14 16:51:44 ----SD---- C:\Documents and Settings\1\Application Data\Microsoft
2010-03-14 16:51:44 ----D---- C:\Documents and Settings\1\Application Data\Identities
2010-03-14 16:51:44 ----ASH---- C:\Documents and Settings\1\Application Data\desktop.ini
2010-03-14 16:48:45 ----D---- C:\WINDOWS\Minidump
2010-03-14 16:48:40 ----A---- C:\WINDOWS\ntbtlog.txt
2010-03-06 19:13:55 ----A---- C:\WINDOWS\system32\h323log.txt
2010-03-06 19:10:01 ----A---- C:\WINDOWS\system32\usbui.dll
2010-03-06 19:09:27 ----A---- C:\WINDOWS\imsins.BAK
2010-03-06 19:09:25 ----SHD---- C:\WINDOWS\Installer
2010-03-06 19:09:25 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-03-06 19:09:24 ----D---- C:\Program Files\Common Files\ODBC
2010-03-06 19:09:24 ----A---- C:\WINDOWS\ODBCINST.INI
2010-03-06 19:09:21 ----RD---- C:\Program Files
2010-03-06 19:09:21 ----D---- C:\Program Files\Common Files\SpeechEngines
2010-03-06 19:09:21 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-03-06 19:09:21 ----D---- C:\Program Files\Common Files
2010-03-06 19:09:18 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2010-03-06 19:09:18 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2010-03-06 19:09:18 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2010-03-06 19:09:17 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2010-03-06 19:09:17 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2010-03-06 19:09:17 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2010-03-06 19:09:17 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2010-03-06 19:09:17 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2010-03-06 19:09:17 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2010-03-06 19:09:17 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2010-03-06 19:09:16 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2010-03-06 19:09:16 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2010-03-06 19:09:15 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2010-03-06 19:09:15 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2010-03-06 19:09:15 ----RA---- C:\WINDOWS\system32\kbdest.dll
2010-03-06 19:09:14 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2010-03-06 19:09:14 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2010-03-06 19:09:14 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2010-03-06 19:09:14 ----RA---- C:\WINDOWS\system32\kbdro.dll
2010-03-06 19:09:14 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2010-03-06 19:09:14 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2010-03-06 19:09:14 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2010-03-06 19:09:14 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2010-03-06 19:09:14 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
2010-03-06 19:09:14 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
2010-03-06 19:09:14 ----RA---- C:\WINDOWS\system32\kbdcz.dll
2010-03-06 19:09:14 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2010-03-06 19:09:14 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2010-03-06 19:09:11 ----A---- C:\WINDOWS\system32\kbdycc.dll
2010-03-06 19:09:11 ----A---- C:\WINDOWS\system32\kbduzb.dll
2010-03-06 19:09:11 ----A---- C:\WINDOWS\system32\kbdur.dll
2010-03-06 19:09:11 ----A---- C:\WINDOWS\system32\kbdtat.dll
2010-03-06 19:09:11 ----A---- C:\WINDOWS\system32\kbdmon.dll
2010-03-06 19:09:11 ----A---- C:\WINDOWS\system32\kbdkyr.dll
2010-03-06 19:09:11 ----A---- C:\WINDOWS\system32\kbdkaz.dll
2010-03-06 19:09:11 ----A---- C:\WINDOWS\system32\kbdbu.dll
2010-03-06 19:09:11 ----A---- C:\WINDOWS\system32\kbdblr.dll
2010-03-06 19:09:11 ----A---- C:\WINDOWS\system32\kbdaze.dll
2010-03-06 19:09:10 ----A---- C:\WINDOWS\system32\spxcoins.dll
2010-03-06 19:09:10 ----A---- C:\WINDOWS\system32\irclass.dll
2010-03-06 19:09:10 ----A---- C:\WINDOWS\system32\dgsetup.dll
2010-03-06 19:09:10 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2010-03-06 19:09:09 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2010-03-06 19:09:08 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2010-03-06 19:09:08 ----A---- C:\WINDOWS\TASKMAN.EXE
2010-03-06 19:09:07 ----A---- C:\WINDOWS\system32\batt.dll
2010-03-06 19:09:07 ----A---- C:\WINDOWS\notepad.exe
2010-03-06 19:09:06 ----A---- C:\WINDOWS\system32\storprop.dll
2010-03-06 19:09:02 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
2010-03-06 19:09:01 ----RA---- C:\WINDOWS\SET21.tmp
2010-03-06 19:09:00 ----RA---- C:\WINDOWS\SET8.tmp
2010-03-06 19:08:57 ----RA---- C:\WINDOWS\SET4.tmp
2010-03-06 19:08:56 ----RA---- C:\WINDOWS\SET3.tmp
2010-03-06 19:08:52 ----D---- C:\WINDOWS\system32\CatRoot2
2010-03-06 19:08:52 ----D---- C:\WINDOWS\system32\CatRoot
2010-03-06 19:08:47 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2010-03-06 19:08:28 ----A---- C:\WINDOWS\setuplog.txt
2010-03-06 19:08:26 ----SHD---- C:\System Volume Information
2010-03-06 19:08:26 ----D---- C:\Documents and Settings
2010-03-06 19:06:59 ----RASH---- C:\boot.ini
2010-03-06 19:00:31 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-03-06 19:00:31 ----RSD---- C:\WINDOWS\Fonts
2010-03-06 19:00:31 ----RD---- C:\WINDOWS\Web
2010-03-06 19:00:31 ----HD---- C:\WINDOWS\inf
2010-03-06 19:00:31 ----D---- C:\WINDOWS\WinSxS
2010-03-06 19:00:31 ----D---- C:\WINDOWS\twain_32
2010-03-06 19:00:31 ----D---- C:\WINDOWS\Temp
2010-03-06 19:00:31 ----D---- C:\WINDOWS\system32\wins
2010-03-06 19:00:31 ----D---- C:\WINDOWS\system32\wbem
2010-03-06 19:00:31 ----D---- C:\WINDOWS\system32\usmt
2010-03-06 19:00:31 ----D---- C:\WINDOWS\system32\spool
2010-03-06 19:00:31 ----D---- C:\WINDOWS\system32\ShellExt
2010-03-06 19:00:31 ----D---- C:\WINDOWS\system32\Setup
2010-03-06 19:00:31 ----D---- C:\WINDOWS\system32\ras
2010-03-06 19:00:31 ----D---- C:\WINDOWS\system32\oobe
2010-03-06 19:00:31 ----D---- C:\WINDOWS\system32\npp
2010-03-06 19:00:31 ----D---- C:\WINDOWS\system32\mui
2010-03-06 19:00:31 ----D---- C:\WINDOWS\system32\inetsrv
2010-03-06 19:00:31 ----D---- C:\WINDOWS\system32\IME
2010-03-06 19:00:31 ----D---- C:\WINDOWS\system32\icsxml
2010-03-06 19:00:31 ----D---- C:\WINDOWS\system32\ias
2010-03-06 19:00:31 ----D---- C:\WINDOWS\system32\export
2010-03-06 19:00:31 ----D---- C:\WINDOWS\system32\drivers
2010-03-06 19:00:31 ----D---- C:\WINDOWS\system32\dhcp
2010-03-06 19:00:31 ----D---- C:\WINDOWS\system32\config
2010-03-06 19:00:31 ----D---- C:\WINDOWS\system32\3com_dmi
2010-03-06 19:00:31 ----D---- C:\WINDOWS\system32\3076
2010-03-06 19:00:31 ----D---- C:\WINDOWS\system32\2052
2010-03-06 19:00:31 ----D---- C:\WINDOWS\system32\1054
2010-03-06 19:00:31 ----D---- C:\WINDOWS\system32\1049
2010-03-06 19:00:31 ----D---- C:\WINDOWS\system32\1042
2010-03-06 19:00:31 ----D---- C:\WINDOWS\system32\1041
2010-03-06 19:00:31 ----D---- C:\WINDOWS\system32\1037
2010-03-06 19:00:31 ----D---- C:\WINDOWS\system32\1033
2010-03-06 19:00:31 ----D---- C:\WINDOWS\system32\1031
2010-03-06 19:00:31 ----D---- C:\WINDOWS\system32\1028
2010-03-06 19:00:31 ----D---- C:\WINDOWS\system32\1025
2010-03-06 19:00:31 ----D---- C:\WINDOWS\system32
2010-03-06 19:00:31 ----D---- C:\WINDOWS\system
2010-03-06 19:00:31 ----D---- C:\WINDOWS\security
2010-03-06 19:00:31 ----D---- C:\WINDOWS\Resources
2010-03-06 19:00:31 ----D---- C:\WINDOWS\repair
2010-03-06 19:00:31 ----D---- C:\WINDOWS\Provisioning
2010-03-06 19:00:31 ----D---- C:\WINDOWS\PeerNet
2010-03-06 19:00:31 ----D---- C:\WINDOWS\pchealth
2010-03-06 19:00:31 ----D---- C:\WINDOWS\mui
2010-03-06 19:00:31 ----D---- C:\WINDOWS\msapps
2010-03-06 19:00:31 ----D---- C:\WINDOWS\msagent
2010-03-06 19:00:31 ----D---- C:\WINDOWS\Media
2010-03-06 19:00:31 ----D---- C:\WINDOWS\java
2010-03-06 19:00:31 ----D---- C:\WINDOWS\ime
2010-03-06 19:00:31 ----D---- C:\WINDOWS\Help
2010-03-06 19:00:31 ----D---- C:\WINDOWS\Driver Cache
2010-03-06 19:00:31 ----D---- C:\WINDOWS\Debug
2010-03-06 19:00:31 ----D---- C:\WINDOWS\Cursors
2010-03-06 19:00:31 ----D---- C:\WINDOWS\Connection Wizard
2010-03-06 19:00:31 ----D---- C:\WINDOWS\Config
2010-03-06 19:00:31 ----D---- C:\WINDOWS\AppPatch
2010-03-06 19:00:31 ----D---- C:\WINDOWS\addins
2010-03-06 19:00:31 ----D---- C:\WINDOWS
2010-03-06 19:00:30 ----A---- C:\WINDOWS\DUMP397e.tmp
2010-03-06 19:00:30 ----A---- C:\WINDOWS\DUMP30e3.tmp
2010-03-06 19:00:30 ----A---- C:\WINDOWS\DUMP2b07.tmp
2010-03-06 19:00:30 ----A---- C:\WINDOWS\DUMP29fe.tmp
2010-03-06 19:00:30 ----A---- C:\WINDOWS\DUMP26f0.tmp
2010-03-06 17:52:15 ----A---- C:\WINDOWS\smscfg.ini
2010-03-06 17:26:37 ----SHD---- C:\RECYCLER
2010-03-06 17:10:17 ----A---- C:\ASWL2K.ini
2010-03-06 17:08:36 ----A---- C:\WINDOWS\system32\ASUSW32N50.dll
2010-03-06 17:08:33 ----D---- C:\Program Files\ASUS
2010-03-06 17:04:41 ----D---- C:\WINDOWS\nview
2010-03-06 17:04:41 ----A---- C:\WINDOWS\system32\nvudisp.exe
2010-03-06 17:04:18 ----A---- C:\WINDOWS\system32\NVUNINST.EXE
2010-03-06 16:46:27 ----D---- C:\WINDOWS\system32\Attansic
2010-03-06 16:46:25 ----D---- C:\Program Files\Attansic
2010-03-06 16:46:11 ----D---- C:\WINDOWS\system32\Lang
2010-03-06 16:45:02 ----RA---- C:\WINDOWS\system32\ChCfg.exe
2010-03-06 16:44:48 ----D---- C:\WINDOWS\system32\RTCOM
2010-03-06 16:44:46 ----A---- C:\WINDOWS\system32\ksuser.dll
2010-03-06 16:44:24 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2010-03-06 16:44:23 ----HDC---- C:\WINDOWS\$NtUninstallKB888111WXPSP2$
2010-03-06 16:44:20 ----RA---- C:\WINDOWS\SoundMan.exe
2010-03-06 16:44:19 ----RA---- C:\WINDOWS\SkyTel.exe
2010-03-06 16:44:18 ----RA---- C:\WINDOWS\RtlUpd.exe
2010-03-06 16:44:16 ----RA---- C:\WINDOWS\RTLCPL.exe
2010-03-06 16:44:08 ----RA---- C:\WINDOWS\RTHDCPL.exe
2010-03-06 16:44:07 ----RA---- C:\WINDOWS\MicCal.exe
2010-03-06 16:44:05 ----RA---- C:\WINDOWS\Alcmtr.exe
2010-03-06 16:44:04 ----RA---- C:\WINDOWS\alcwzrd.exe
2010-03-06 16:44:03 ----D---- C:\Program Files\Realtek
2010-03-06 16:44:02 ----HD---- C:\Program Files\InstallShield Installation Information
2010-03-06 16:44:00 ----RA---- C:\WINDOWS\RtlExUpd.dll
2010-03-06 16:44:00 ----A---- C:\WINDOWS\HideWin.exe
2010-03-06 16:43:57 ----D---- C:\Program Files\Common Files\InstallShield
2010-03-06 16:42:48 ----D---- C:\WINDOWS\ASUSInstAll
2010-03-06 16:37:13 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-03-06 16:37:13 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-03-06 16:37:12 ----D---- C:\Program Files\Intel
2010-03-06 16:37:02 ----D---- C:\Intel
2010-03-06 16:31:07 ----A---- C:\WINDOWS\Ascd_log.ini
2010-03-06 16:30:56 ----A---- C:\WINDOWS\Ascd_tmp.ini
2010-03-06 16:28:28 ----HD---- C:\Program Files\Uninstall Information
2010-03-06 16:24:15 ----D---- C:\WINDOWS\SoftwareDistribution
2010-03-06 16:24:13 ----SD---- C:\WINDOWS\system32\Microsoft
2010-03-06 16:24:13 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-03-06 16:18:04 ----D---- C:\WINDOWS\system32\xircom
2010-03-06 16:18:04 ----D---- C:\Program Files\xerox
2010-03-06 16:18:04 ----D---- C:\Program Files\microsoft frontpage
2010-03-06 16:18:01 ----HD---- C:\WINDOWS\$hf_mig$
2010-03-06 16:17:52 ----A---- C:\WINDOWS\control.ini
2010-03-06 16:17:52 ----A---- C:\AUTOEXEC.BAT
2010-03-06 16:17:46 ----A---- C:\WINDOWS\OEWABLog.txt
2010-03-06 16:17:44 ----A---- C:\WINDOWS\system32\mapi32.dll
2010-03-06 16:17:15 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-03-06 16:17:15 ----RD---- C:\WINDOWS\Offline Web Pages
2010-03-06 16:17:15 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2010-03-06 16:17:12 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2010-03-06 16:17:09 ----HD---- C:\Program Files\WindowsUpdate
2010-03-06 16:17:07 ----D---- C:\Program Files\Online Services
2010-03-06 16:16:55 ----D---- C:\WINDOWS\system32\DirectX
2010-03-06 16:16:37 ----A---- C:\WINDOWS\system32\atrace.dll
2010-03-06 16:16:34 ----A---- C:\WINDOWS\system32\desktop.ini
2010-03-06 16:16:34 ----A---- C:\WINDOWS\desktop.ini
2010-03-06 16:16:28 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2010-03-06 16:16:27 ----A---- C:\WINDOWS\system32\acctres.dll
2010-03-06 16:16:26 ----D---- C:\Program Files\Common Files\Services
2010-03-06 16:16:24 ----SD---- C:\WINDOWS\Tasks
2010-03-06 16:16:24 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2010-03-06 16:16:23 ----D---- C:\Program Files\Common Files\MSSoap
2010-03-06 16:16:20 ----D---- C:\WINDOWS\srchasst
2010-03-06 16:16:19 ----D---- C:\WINDOWS\system32\Macromed
2010-03-06 16:16:16 ----A---- C:\WINDOWS\system32\wuauserv.dll
2010-03-06 16:16:16 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2010-03-06 16:16:16 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2010-03-06 16:16:15 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2010-03-06 16:16:15 ----A---- C:\WINDOWS\system32\qmgr.dll
2010-03-06 16:16:15 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2010-03-06 16:16:15 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2010-03-06 16:16:11 ----D---- C:\Program Files\Movie Maker
2010-03-06 16:16:08 ----A---- C:\WINDOWS\system32\safrslv.dll
2010-03-06 16:16:08 ----A---- C:\WINDOWS\system32\safrdm.dll
2010-03-06 16:16:08 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2010-03-06 16:16:07 ----A---- C:\WINDOWS\system32\racpldlg.dll
2010-03-06 16:16:04 ----D---- C:\WINDOWS\system32\Restore
2010-03-06 16:16:04 ----A---- C:\WINDOWS\system32\srsvc.dll
2010-03-06 16:16:04 ----A---- C:\WINDOWS\system32\srrstr.dll
2010-03-06 16:16:04 ----A---- C:\WINDOWS\system32\srclient.dll
2010-03-06 16:16:04 ----A---- C:\WINDOWS\system32\fltmc.exe
2010-03-06 16:16:04 ----A---- C:\WINDOWS\system32\fltlib.dll
2010-03-06 16:16:03 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2010-03-06 16:16:03 ----A---- C:\WINDOWS\system32\mnmdd.dll
2010-03-06 16:16:03 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2010-03-06 16:16:03 ----A---- C:\WINDOWS\system32\ils.dll
2010-03-06 16:16:02 ----A---- C:\WINDOWS\system32\msconf.dll
2010-03-06 16:16:02 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2010-03-06 16:16:00 ----D---- C:\Program Files\NetMeeting
2010-03-06 16:16:00 ----A---- C:\WINDOWS\system32\msoert2.dll
2010-03-06 16:16:00 ----A---- C:\WINDOWS\system32\msoeacct.dll
2010-03-06 16:15:59 ----A---- C:\WINDOWS\system32\inetres.dll
2010-03-06 16:15:59 ----A---- C:\WINDOWS\system32\inetcomm.dll
2010-03-06 16:15:57 ----D---- C:\Program Files\Outlook Express
2010-03-06 16:15:57 ----A---- C:\WINDOWS\system32\schedsvc.dll
2010-03-06 16:15:57 ----A---- C:\WINDOWS\system32\mstinit.exe
2010-03-06 16:15:57 ----A---- C:\WINDOWS\system32\mstask.dll
2010-03-06 16:15:56 ----A---- C:\WINDOWS\system32\isign32.dll
2010-03-06 16:15:56 ----A---- C:\WINDOWS\system32\inetcfg.dll
2010-03-06 16:15:56 ----A---- C:\WINDOWS\system32\icwphbk.dll
2010-03-06 16:15:56 ----A---- C:\WINDOWS\system32\icwdial.dll
2010-03-06 16:15:51 ----D---- C:\Program Files\Common Files\System
2010-03-06 16:15:50 ----D---- C:\Program Files\Internet Explorer
2010-03-06 16:15:42 ----D---- C:\Program Files\ComPlus Applications
2010-03-06 16:15:41 ----A---- C:\WINDOWS\vbaddin.ini
2010-03-06 16:15:41 ----A---- C:\WINDOWS\vb.ini
2010-03-06 16:15:37 ----D---- C:\WINDOWS\Registration
2010-03-06 16:15:19 ----D---- C:\Program Files\Windows Media Player
2010-03-06 16:15:16 ----D---- C:\Program Files\Messenger
2010-03-06 16:15:13 ----D---- C:\Program Files\MSN Gaming Zone
2010-03-06 16:15:13 ----A---- C:\WINDOWS\system32\write.exe
2010-03-06 16:15:05 ----A---- C:\WINDOWS\system32\winchat.exe
2010-03-06 16:15:05 ----A---- C:\WINDOWS\system32\sndvol32.exe
2010-03-06 16:15:05 ----A---- C:\WINDOWS\system32\hticons.dll
2010-03-06 16:15:05 ----A---- C:\WINDOWS\system32\avwav.dll
2010-03-06 16:15:05 ----A---- C:\WINDOWS\system32\avtapi.dll
2010-03-06 16:15:05 ----A---- C:\WINDOWS\system32\avmeter.dll
2010-03-06 16:14:59 ----A---- C:\WINDOWS\system32\getuname.dll
2010-03-06 16:14:59 ----A---- C:\WINDOWS\system32\charmap.exe
2010-03-06 16:14:58 ----A---- C:\WINDOWS\system32\winmine.exe
2010-03-06 16:14:58 ----A---- C:\WINDOWS\system32\sol.exe
2010-03-06 16:14:58 ----A---- C:\WINDOWS\system32\mshearts.exe
2010-03-06 16:14:58 ----A---- C:\WINDOWS\system32\freecell.exe
2010-03-06 16:14:57 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2010-03-06 16:14:57 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2010-03-06 16:14:57 ----A---- C:\WINDOWS\system32\tslabels.ini
2010-03-06 16:14:57 ----A---- C:\WINDOWS\system32\tskill.exe
2010-03-06 16:14:57 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2010-03-06 16:14:57 ----A---- C:\WINDOWS\system32\tscon.exe
2010-03-06 16:14:57 ----A---- C:\WINDOWS\system32\shadow.exe
2010-03-06 16:14:57 ----A---- C:\WINDOWS\system32\rwinsta.exe
2010-03-06 16:14:57 ----A---- C:\WINDOWS\system32\reset.exe
2010-03-06 16:14:57 ----A---- C:\WINDOWS\system32\regini.exe
2010-03-06 16:14:57 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2010-03-06 16:14:57 ----A---- C:\WINDOWS\system32\qwinsta.exe
2010-03-06 16:14:57 ----A---- C:\WINDOWS\system32\qappsrv.exe
2010-03-06 16:14:57 ----A---- C:\WINDOWS\system32\msg.exe
2010-03-06 16:14:57 ----A---- C:\WINDOWS\system32\logoff.exe
2010-03-06 16:14:56 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2010-03-06 16:14:56 ----A---- C:\WINDOWS\system32\mtxex.dll
2010-03-06 16:14:56 ----A---- C:\WINDOWS\system32\mtxdm.dll
2010-03-06 16:14:56 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2010-03-06 16:14:56 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2010-03-06 16:14:56 ----A---- C:\WINDOWS\system32\cdmodem.dll
2010-03-06 16:14:55 ----A---- C:\WINDOWS\system32\stclient.dll
2010-03-06 16:14:55 ----A---- C:\WINDOWS\system32\comsnap.dll
2010-03-06 16:14:55 ----A---- C:\WINDOWS\system32\comrepl.dll
2010-03-06 16:14:55 ----A---- C:\WINDOWS\system32\comaddin.dll
2010-03-06 16:14:51 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2010-03-06 16:14:50 ----A---- C:\WINDOWS\system32\sndrec32.exe
2010-03-06 16:14:50 ----A---- C:\WINDOWS\system32\mplay32.exe
2010-03-06 16:14:50 ----A---- C:\WINDOWS\system32\hypertrm.dll
2010-03-06 16:14:50 ----A---- C:\WINDOWS\system32\accwiz.exe
2010-03-06 16:14:49 ----D---- C:\Program Files\Windows NT
2010-03-06 16:14:49 ----A---- C:\WINDOWS\system32\spider.exe
2010-03-06 16:14:49 ----A---- C:\WINDOWS\system32\mspaint.exe
2010-03-06 16:14:49 ----A---- C:\WINDOWS\system32\clipbrd.exe
2010-03-06 16:14:48 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2010-03-06 16:14:48 ----A---- C:\WINDOWS\system32\sessmgr.exe
2010-03-06 16:14:48 ----A---- C:\WINDOWS\system32\remotepg.dll
2010-03-06 16:14:48 ----A---- C:\WINDOWS\system32\rdshost.exe
2010-03-06 16:14:48 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2010-03-06 16:14:48 ----A---- C:\WINDOWS\system32\mstscax.dll
2010-03-06 16:14:48 ----A---- C:\WINDOWS\system32\mstsc.exe
2010-03-06 16:14:47 ----A---- C:\WINDOWS\system32\tscupgrd.exe
2010-03-06 16:14:47 ----A---- C:\WINDOWS\system32\termsrv.dll
2010-03-06 16:14:47 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2010-03-06 16:14:47 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2010-03-06 16:14:47 ----A---- C:\WINDOWS\system32\rdpclip.exe
2010-03-06 16:14:47 ----A---- C:\WINDOWS\system32\rdchost.dll
2010-03-06 16:14:47 ----A---- C:\WINDOWS\system32\qprocess.exe
2010-03-06 16:14:47 ----A---- C:\WINDOWS\system32\icaapi.dll
2010-03-06 16:14:47 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2010-03-06 16:14:46 ----D---- C:\WINDOWS\system32\MsDtc
2010-03-06 16:14:46 ----A---- C:\WINDOWS\system32\xolehlp.dll
2010-03-06 16:14:46 ----A---- C:\WINDOWS\system32\mtxoci.dll
2010-03-06 16:14:46 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2010-03-06 16:14:46 ----A---- C:\WINDOWS\system32\msdtctm.dll
2010-03-06 16:14:46 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2010-03-06 16:14:46 ----A---- C:\WINDOWS\system32\msdtclog.dll
2010-03-06 16:14:46 ----A---- C:\WINDOWS\system32\msdtc.exe
2010-03-06 16:14:45 ----D---- C:\WINDOWS\system32\Com
2010-03-06 16:14:45 ----A---- C:\WINDOWS\system32\colbact.dll
2010-03-06 16:14:45 ----A---- C:\WINDOWS\system32\clbcatex.dll
2010-03-06 16:14:45 ----A---- C:\WINDOWS\system32\catsrvps.dll
2010-03-06 16:14:44 ----A---- C:\WINDOWS\system32\comuid.dll
2010-03-06 16:14:44 ----A---- C:\WINDOWS\system32\comsvcs.dll
2010-03-06 16:14:44 ----A---- C:\WINDOWS\system32\clbcatq.dll
2010-03-06 16:14:44 ----A---- C:\WINDOWS\system32\catsrvut.dll
2010-03-06 16:14:44 ----A---- C:\WINDOWS\system32\catsrv.dll
2010-03-06 16:14:39 ----A---- C:\WINDOWS\system32\servdeps.dll
2010-03-06 16:14:39 ----A---- C:\WINDOWS\system32\mmfutil.dll
2010-03-06 16:14:39 ----A---- C:\WINDOWS\system32\licwmi.dll
2010-03-06 16:14:39 ----A---- C:\WINDOWS\system32\cmprops.dll
2009-02-14 17:13:21 ----D---- C:\Program Files\trend micro
2009-02-14 17:13:20 ----D---- C:\rsit
2009-02-14 15:56:27 ----D---- C:\Documents and Settings\1\Application Data\Malwarebytes
2009-02-14 15:56:22 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-02-14 15:56:21 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-02-14 12:20:13 ----D---- C:\Program Files\Prevx
2009-02-14 12:20:09 ----D---- C:\Documents and Settings\All Users\Application Data\PrevxCSI
2009-02-14 09:40:04 ----A---- C:\WINDOWS\wininit.ini
2009-02-03 20:19:19 ----A---- C:\WINDOWS\IE4 Error Log.txt
2009-02-03 18:32:44 ----D---- C:\Program Files\File Renamer Deluxe
2009-02-03 18:32:44 ----D---- C:\Documents and Settings\1\Application Data\Kristanix Software
2009-02-01 16:47:30 ----D---- C:\Program Files\GribUser
2009-02-01 16:28:39 ----D---- C:\Program Files\FBReader
2009-01-31 19:19:12 ----D---- C:\Program Files\Common Files\xing shared
2009-01-31 15:53:47 ----D---- C:\Program Files\Common Fi