Logfile of random's system information tool 1.06 (written by random/random)
Run by PHVDM at 2009-11-07 23:02:47
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 15 GB (26%) free of 57 GB
Total RAM: 3070 MB (46% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:06:07, on 7/11/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18828)
Boot mode: Normal
Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\services.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Windows\system32\WLANExt.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\ATK Hotkey\ASLDRSrv.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\AsGHost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Program Files\ATK Hotkey\Hcontrol.exe
C:\Program Files\ATKOSD2\ATKOSD2.exe
C:\Program Files\Wireless Console 2\wcourier.exe
C:\Program Files\ASUS\Splendid\ACMON.exe
C:\Program Files\P4G\BatteryLife.exe
C:\Windows\System32\ACEngSvr.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\ATK Hotkey\ATKOSD.exe
C:\Windows\system32\ifxspmgt.exe
C:\Windows\system32\ifxtcs.exe
C:\Program Files\iolo\common\lib\ioloServiceManager.exe
C:\Program Files\iolo\System Mechanic\IoloSGCtrl.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\iolo\System Mechanic\SystemGuardAlerter.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Program Files\Webroot\WebrootSecurity\SSU.EXE
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\PHVDM\Desktop\RSIT.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\trend micro\PHVDM.exe
C:\Windows\system32\rundll32.exe
C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.hln.beR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.asus.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Ask.com Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Ask.com Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [RtHDVCpl] "RtHDVCpl.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [NvSvc] "RUNDLL32.EXE" C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [YMailAdvisor] "C:\Program Files\Yahoo!\Common\YMailAdvisor.exe"
O4 - HKLM\..\Run: [IFXSPMGT] "C:\Windows\system32\ifxspmgt.exe" /NotifyLogon
O4 - HKLM\..\Run: [iolo Startup] "C:\Program Files\iolo\Common\Lib\ioloLManager.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [Sidebar] "C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [AdobeUpdater6] "C:\Program Files\Common Files\Adobe\Updater6\Adobe_Updater.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Referencia - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cabO18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: APSHook.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updateservice (gupdate1ca3d0d5096250a) (gupdate1ca3d0d5096250a) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - C:\Windows\system32\ifxspmgt.exe
O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - C:\Windows\system32\ifxtcs.exe
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iolo System Guard (IOLO_SRV) - Unknown owner - C:\Program Files\iolo\System Mechanic\IoloSGCtrl.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (
http://www.webroot.com) - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
--
End of file - 12199 bytes
======Scheduled tasks folder======
C:\Windows\tasks\AutoSmartDefrag.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\Norton Internet Security - Run Full System Scan - PHVDM.job
C:\Windows\tasks\SmartDefrag.job
C:\Windows\tasks\User_Feed_Synchronization-{317E8191-5478-4C5F-83DF-8413893B31CE}.job
C:\Windows\tasks\wrSpySweeper_L9B6191A18BF7491ABB9406B72E8955C9.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
&Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2009-09-20 1172280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1E8A6170-7264-4D0F-BEAE-D42A53123C75}]
C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll [2006-10-23 96984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2009-08-04 1586472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-09-23 256112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll [2009-10-09 762864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [2009-09-23 458736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask.com Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2009-04-02 809864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
SingleInstance Class - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll [2009-09-20 158008]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{90222687-F593-4738-B738-FBEE9C7B26DF} - Show Norton Toolbar - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll [2006-10-23 565960]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-09-23 256112]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2009-09-20 1172280]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Ask.com Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2009-04-02 809864]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-02-15 4390912]
"ccApp"=C:\Program Files\Common Files\Symantec Shared\ccApp.exe [2006-10-24 107112]
"osCheck"=C:\Program Files\Norton Internet Security\osCheck.exe [2006-10-27 22696]
"Symantec PIF AlertEng"=C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe [2008-01-29 583048]
"NvSvc"=C:\Windows\system32\nvsvc.dll [2007-04-04 86016]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2007-04-04 8429568]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2007-04-04 81920]
"YMailAdvisor"=C:\Program Files\Yahoo!\Common\YMailAdvisor.exe [2009-05-08 174424]
"IFXSPMGT"=C:\Windows\system32\ifxspmgt.exe [2007-02-26 677408]
"iolo Startup"=C:\Program Files\iolo\Common\Lib\ioloLManager.exe [2009-10-21 313784]
"SpySweeper"=C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe [2009-05-13 6345840]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-09-23 39408]
"AdobeUpdater6"=C:\Program Files\Common Files\Adobe\Updater6\Adobe_Updater.exe [2009-01-08 2521464]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Camera ScreenSaver]
C:\Windows\ASScrProlog.exe [2007-06-08 37232]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
C:\Windows\ASScrPro.exe [2007-06-08 33136]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [2007-02-12 174872]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
C:\Program Files\Nero\Nero 7\InCD\InCD.exe [2007-03-26 1057328]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-26 161328]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerForPhone]
C:\Program Files\PowerForPhone\PowerForPhone.exe [2007-01-15 778240]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe [2009-09-02 25623336]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [2006-11-22 630784]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-09-23 39408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-03-01 857648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="APSHook.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2009-09-03 548352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
ASWLNPkg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro35]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro35.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WebrootSpySweeperService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WRConsumerService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{474804c2-a83b-11de-8f3a-001bfc6de1aa}]
shell\AutoRun\command - G:\Recycle\P-1-3-64-8794238531-8742492-9897532\Furio.exe
shell\open\command - G:\Recycle\P-1-3-64-8794238531-8742492-9897532\Furio.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{474804c5-a83b-11de-8f3a-001bfc6de1aa}]
shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cdb0ee4e-a84a-11de-8c9e-001bfc6de1aa}]
shell\AutoRun\command - G:\9jyhdim8.exe
shell\open\command - G:\9jyhdim8.exe
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - NOTEPAD.EXE %1
.reg - open - NOTEPAD.EXE %1
.scr - open - NOTEPAD.EXE %1
.vbs - open - NOTEPAD.EXE %1
======List of files/folders created in the last 2 months======
2009-11-07 23:02:49 ----D---- C:\Program Files\trend micro
2009-11-07 23:02:47 ----D---- C:\rsit
2009-11-07 18:24:23 ----A---- C:\Windows\ntbtlog.txt
2009-11-06 21:49:08 ----D---- C:\Program Files\Wise Disk Cleaner
2009-11-06 16:24:57 ----D---- C:\Program Files\Mio Technology
2009-11-04 11:51:28 ----A---- C:\Windows\system32\mshtml.dll
2009-11-01 11:51:32 ----SHD---- C:\Config.Msi
2009-10-30 11:35:09 ----A---- C:\Windows\system32\wups2.dll
2009-10-30 11:35:09 ----A---- C:\Windows\system32\wuauclt.exe
2009-10-30 11:35:08 ----A---- C:\Windows\system32\wucltux.dll
2009-10-30 11:35:07 ----A---- C:\Windows\system32\wuaueng.dll
2009-10-30 11:34:09 ----A---- C:\Windows\system32\wups.dll
2009-10-30 11:34:09 ----A---- C:\Windows\system32\wudriver.dll
2009-10-30 11:34:08 ----A---- C:\Windows\system32\wuapi.dll
2009-10-30 11:33:50 ----A---- C:\Windows\system32\wuwebv.dll
2009-10-30 11:33:50 ----A---- C:\Windows\system32\wuapp.exe
2009-10-28 13:16:45 ----A---- C:\Windows\system32\wmp.dll
2009-10-28 13:16:36 ----A---- C:\Windows\system32\unregmp2.exe
2009-10-28 13:16:28 ----A---- C:\Windows\system32\wmploc.DLL
2009-10-26 13:19:28 ----D---- C:\Program Files\AnalogX
2009-10-26 12:47:17 ----D---- C:\Program Files\CPUID
2009-10-26 12:47:08 ----D---- C:\Program Files\Ask.com
2009-10-26 12:40:50 ----A---- C:\Windows\system32\IncContxMenu.dll
2009-10-20 08:55:20 ----A---- C:\Windows\system32\Incinerator.dll
2009-10-20 08:55:07 ----A---- C:\Windows\system32\smrgdf.exe
2009-10-20 08:55:07 ----A---- C:\Windows\system32\iolobtdfg.exe
2009-10-20 08:54:57 ----D---- C:\Program Files\iolo
2009-10-17 09:51:10 ----D---- C:\Program Files\Microsoft Silverlight
2009-10-14 08:58:44 ----A---- C:\Windows\system32\ntoskrnl.exe
2009-10-14 08:58:42 ----A---- C:\Windows\system32\ntkrnlpa.exe
2009-10-14 08:58:20 ----A---- C:\Windows\system32\msv1_0.dll
2009-10-14 08:54:08 ----A---- C:\Windows\system32\ieframe.dll
2009-10-14 08:54:05 ----A---- C:\Windows\system32\iertutil.dll
2009-10-14 08:54:03 ----A---- C:\Windows\system32\urlmon.dll
2009-10-14 08:54:02 ----A---- C:\Windows\system32\wininet.dll
2009-10-14 08:54:00 ----A---- C:\Windows\system32\occache.dll
2009-10-14 08:54:00 ----A---- C:\Windows\system32\msfeeds.dll
2009-10-14 08:53:59 ----A---- C:\Windows\system32\iedkcs32.dll
2009-10-14 08:53:55 ----A---- C:\Windows\system32\ieui.dll
2009-10-14 08:53:52 ----A---- C:\Windows\system32\iepeers.dll
2009-10-14 08:53:51 ----A---- C:\Windows\system32\msfeedsbs.dll
2009-10-14 08:53:51 ----A---- C:\Windows\system32\ieUnatt.exe
2009-10-14 08:53:50 ----A---- C:\Windows\system32\jsproxy.dll
2009-10-14 08:53:50 ----A---- C:\Windows\system32\iesysprep.dll
2009-10-14 08:53:49 ----A---- C:\Windows\system32\ie4uinit.exe
2009-10-14 08:53:48 ----A---- C:\Windows\system32\msfeedssync.exe
2009-10-14 08:53:47 ----A---- C:\Windows\system32\iesetup.dll
2009-10-14 08:53:47 ----A---- C:\Windows\system32\iernonce.dll
2009-10-14 08:51:36 ----A---- C:\Windows\system32\msasn1.dll
2009-10-14 04:47:52 ----A---- C:\Windows\system32\WMSPDMOD.DLL
2009-10-12 21:29:34 ----D---- C:\Windows\pss
2009-10-11 16:35:10 ----D---- C:\Program Files\SUPERAntiSpyware
2009-10-11 16:32:56 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2009-10-11 13:41:33 ----D---- C:\ProgramData\SUPERAntiSpyware.com
2009-10-11 13:41:32 ----D---- C:\Users\PHVDM\AppData\Roaming\SUPERAntiSpyware.com
2009-10-10 12:53:24 ----D---- C:\Users\PHVDM\AppData\Roaming\Malwarebytes
2009-10-10 12:52:45 ----D---- C:\ProgramData\Malwarebytes
2009-10-10 12:52:43 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-10-09 20:35:32 ----A---- C:\Windows\system32\deploytk.dll
2009-10-09 20:35:31 ----A---- C:\Windows\system32\javaws.exe
2009-10-09 20:35:31 ----A---- C:\Windows\system32\javaw.exe
2009-10-09 20:35:30 ----A---- C:\Windows\system32\java.exe
2009-10-09 20:34:04 ----D---- C:\Program Files\Java
2009-10-07 23:05:19 ----D---- C:\Program Files\Microsoft
2009-10-07 23:04:37 ----D---- C:\Program Files\Windows Live SkyDrive
2009-10-07 23:03:40 ----D---- C:\Program Files\Windows Live
2009-10-07 22:54:41 ----D---- C:\Program Files\Common Files\Windows Live
2009-10-07 13:24:10 ----D---- C:\Program Files\MSECache
2009-10-06 18:14:37 ----A---- C:\EventLOG.txt
2009-10-06 13:49:29 ----A---- C:\Windows\system32\mfc45.dll
2009-10-06 13:49:20 ----D---- C:\Users\PHVDM\AppData\Roaming\iolo
2009-10-06 13:49:20 ----D---- C:\ProgramData\iolo
2009-10-06 09:13:53 ----D---- C:\ProgramData\Yahoo!
2009-10-06 09:13:17 ----D---- C:\ProgramData\Yahoo! Companion
2009-10-06 09:13:01 ----D---- C:\Users\PHVDM\AppData\Roaming\Yahoo!
2009-10-06 09:10:45 ----D---- C:\Program Files\Yahoo!
2009-10-03 14:36:08 ----D---- C:\Program Files\RegCleaner
2009-10-03 12:05:34 ----D---- C:\Users\PHVDM\AppData\Roaming\skypePM
2009-10-01 10:17:21 ----D---- C:\ProgramData\WindowsSearch
2009-09-30 15:41:28 ----A---- C:\Windows\ODBC.INI
2009-09-30 15:41:21 ----A---- C:\Windows\system32\mdimon.dll
2009-09-30 15:39:32 ----D---- C:\Program Files\Common Files\DESIGNER
2009-09-30 15:38:32 ----D---- C:\Windows\PCHEALTH
2009-09-30 15:38:32 ----D---- C:\Program Files\Microsoft.NET
2009-09-30 15:38:32 ----D---- C:\Program Files\Microsoft Office
2009-09-30 13:58:55 ----A---- C:\Windows\system32\msonpmon.dll
2009-09-30 13:37:11 ----D---- C:\Users\PHVDM\AppData\Roaming\GetRightToGo
2009-09-30 11:26:00 ----D---- C:\ProgramData\Adobe
2009-09-30 11:25:23 ----D---- C:\Program Files\Common Files\Adobe
2009-09-30 11:25:23 ----D---- C:\Program Files\Adobe
2009-09-29 09:40:07 ----D---- C:\Program Files\MSSOAP
2009-09-29 09:40:07 ----D---- C:\Program Files\Common Files\MSSoap
2009-09-29 09:39:48 ----D---- C:\Users\PHVDM\AppData\Roaming\Webroot
2009-09-29 09:39:48 ----D---- C:\ProgramData\Webroot
2009-09-29 09:39:48 ----D---- C:\Program Files\Webroot
2009-09-29 09:39:48 ----A---- C:\Windows\WRSetup.dll
2009-09-28 13:49:43 ----D---- C:\Program Files\Wise Registry Cleaner 3
2009-09-28 12:46:14 ----D---- C:\ProgramData\Hitman Pro
2009-09-28 12:46:13 ----D---- C:\Program Files\Hitman Pro 3.5
2009-09-27 19:55:53 ----D---- C:\Users\PHVDM\AppData\Roaming\12Voip
2009-09-27 19:54:39 ----D---- C:\Program Files\12Voip.com
2009-09-25 11:31:40 ----D---- C:\Program Files\CleanCache 3.0
2009-09-25 10:15:29 ----D---- C:\Windows\system32\eu-ES
2009-09-25 10:15:29 ----D---- C:\Windows\system32\ca-ES
2009-09-25 10:15:28 ----D---- C:\Windows\system32\vi-VN
2009-09-24 14:51:41 ----D---- C:\Users\PHVDM\AppData\Roaming\VoipBuster
2009-09-24 14:50:10 ----D---- C:\Program Files\VoipBuster.com
2009-09-24 13:19:39 ----D---- C:\Users\PHVDM\AppData\Roaming\AdobeUM
2009-09-24 12:52:17 ----D---- C:\Users\PHVDM\AppData\Roaming\Skype
2009-09-24 12:49:32 ----D---- C:\Program Files\Common Files\Skype
2009-09-24 12:49:19 ----RD---- C:\Program Files\Skype
2009-09-24 12:48:48 ----D---- C:\ProgramData\Skype
2009-09-24 11:59:05 ----D---- C:\Windows\Internet Logs
2009-09-24 11:34:19 ----D---- C:\ProgramData\IObit
2009-09-24 10:43:28 ----D---- C:\Users\PHVDM\AppData\Roaming\IObit
2009-09-24 10:43:28 ----D---- C:\Program Files\IObit
2009-09-24 08:46:18 ----D---- C:\Windows\system32\EventProviders
2009-09-23 19:00:56 ----D---- C:\ProgramData\Office Genuine Advantage
2009-09-23 16:51:56 ----A---- C:\Windows\system32\NlsLexicons0007.dll
2009-09-23 16:51:52 ----A---- C:\Windows\system32\SLsvc.exe
2009-09-23 16:51:52 ----A---- C:\Windows\system32\SLCExt.dll
2009-09-23 16:51:50 ----A---- C:\Windows\system32\FunctionDiscoveryFolder.dll
2009-09-23 16:51:50 ----A---- C:\Windows\system32\DevicePairingWizard.exe
2009-09-23 16:51:48 ----A---- C:\Windows\system32\NlsLexicons0009.dll
2009-09-23 16:51:46 ----A---- C:\Windows\system32\mssrch.dll
2009-09-23 16:51:44 ----A---- C:\Windows\system32\tquery.dll
2009-09-23 16:51:42 ----A---- C:\Windows\system32\RMActivate_isv.exe
2009-09-23 16:51:42 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
2009-09-23 16:51:41 ----A---- C:\Windows\system32\scavenge.dll
2009-09-23 16:51:41 ----A---- C:\Windows\system32\RMActivate.exe
2009-09-23 16:51:40 ----A---- C:\Windows\system32\msi.dll
2009-09-23 16:51:39 ----A---- C:\Windows\system32\imapi2fs.dll
2009-09-23 16:51:38 ----A---- C:\Windows\system32\WscEapPr.dll
2009-09-23 16:51:38 ----A---- C:\Windows\system32\wcnwiz2.dll
2009-09-23 16:51:38 ----A---- C:\Windows\system32\secproc_isv.dll
2009-09-23 16:51:37 ----A---- C:\Windows\system32\sysmain.dll
2009-09-23 16:51:36 ----A---- C:\Windows\system32\icardagt.exe
2009-09-23 16:51:34 ----A---- C:\Windows\system32\EhStorShell.dll
2009-09-23 16:51:34 ----A---- C:\Windows\system32\AuxiliaryDisplayCpl.dll
2009-09-23 16:51:33 ----A---- C:\Windows\system32\spreview.exe
2009-09-23 16:51:33 ----A---- C:\Windows\system32\spinstall.exe
2009-09-23 16:51:33 ----A---- C:\Windows\system32\drmv2clt.dll
2009-09-23 16:51:31 ----A---- C:\Windows\system32\spwizui.dll
2009-09-23 16:51:31 ----A---- C:\Windows\system32\shell32.dll
2009-09-23 16:51:31 ----A---- C:\Windows\system32\secproc.dll
2009-09-23 16:51:31 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2009-09-23 16:51:30 ----A---- C:\Windows\system32\p2psvc.dll
2009-09-23 16:51:29 ----A---- C:\Windows\system32\SearchIndexer.exe
2009-09-23 16:51:29 ----A---- C:\Windows\system32\mssvp.dll
2009-09-23 16:51:28 ----A---- C:\Windows\system32\mssphtb.dll
2009-09-23 16:51:28 ----A---- C:\Windows\system32\mssph.dll
2009-09-23 16:51:28 ----A---- C:\Windows\system32\MSMPEG2VDEC.DLL
2009-09-23 16:51:28 ----A---- C:\Windows\system32\mscoree.dll
2009-09-23 16:51:27 ----A---- C:\Windows\system32\sdohlp.dll
2009-09-23 16:51:27 ----A---- C:\Windows\system32\imapi2.dll
2009-09-23 16:51:26 ----A---- C:\Windows\system32\IMJP10K.DLL
2009-09-23 16:51:26 ----A---- C:\Windows\system32\esent.dll
2009-09-23 16:51:26 ----A---- C:\Windows\system32\DevicePairing.dll
2009-09-23 16:51:25 ----A---- C:\Windows\system32\wevtsvc.dll
2009-09-23 16:51:25 ----A---- C:\Windows\system32\sperror.dll
2009-09-23 16:51:25 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2009-09-23 16:51:25 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2009-09-23 16:51:25 ----A---- C:\Windows\system32\korwbrkr.dll
2009-09-23 16:51:24 ----A---- C:\Windows\system32\SLC.dll
2009-09-23 16:51:24 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2009-09-23 16:51:24 ----A---- C:\Windows\system32\msshsq.dll
2009-09-23 16:51:22 ----A---- C:\Windows\system32\msjet40.dll
2009-09-23 16:51:22 ----A---- C:\Windows\system32\MPSSVC.dll
2009-09-23 16:51:21 ----A---- C:\Windows\system32\Query.dll
2009-09-23 16:51:21 ----A---- C:\Windows\system32\msxml6.dll
2009-09-23 16:51:20 ----A---- C:\Windows\system32\qmgr.dll
2009-09-23 16:51:20 ----A---- C:\Windows\system32\P2PGraph.dll
2009-09-23 16:51:20 ----A---- C:\Windows\system32\msexch40.dll
2009-09-23 16:51:20 ----A---- C:\Windows\system32\diagperf.dll
2009-09-23 16:51:19 ----A---- C:\Windows\system32\ole32.dll
2009-09-23 16:51:19 ----A---- C:\Windows\system32\ntdll.dll
2009-09-23 16:51:19 ----A---- C:\Windows\system32\IasMigReader.exe
2009-09-23 16:51:18 ----A---- C:\Windows\system32\winload.exe
2009-09-23 16:51:18 ----A---- C:\Windows\system32\srchadmin.dll
2009-09-23 16:51:18 ----A---- C:\Windows\system32\msxml3.dll
2009-09-23 16:51:18 ----A---- C:\Windows\system32\mblctr.exe
2009-09-23 16:51:18 ----A---- C:\Windows\system32\EncDec.dll
2009-09-23 16:51:17 ----A---- C:\Windows\system32\uDWM.dll
2009-09-23 16:51:17 ----A---- C:\Windows\system32\riched20.dll
2009-09-23 16:51:17 ----A---- C:\Windows\system32\mmc.exe
2009-09-23 16:51:17 ----A---- C:\Windows\system32\IasMigPlugin.dll
2009-09-23 16:51:17 ----A---- C:\Windows\system32\dfsr.exe
2009-09-23 16:51:16 ----A---- C:\Windows\system32\RacEngn.dll
2009-09-23 16:51:16 ----A---- C:\Windows\system32\fdBth.dll
2009-09-23 16:51:15 ----A---- C:\Windows\system32\kernel32.dll
2009-09-23 16:51:14 ----A---- C:\Windows\system32\spoolss.dll
2009-09-23 16:51:14 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2009-09-23 16:51:14 ----A---- C:\Windows\system32\SearchFilterHost.exe
2009-09-23 16:51:14 ----A---- C:\Windows\system32\schedsvc.dll
2009-09-23 16:51:14 ----A---- C:\Windows\system32\milcore.dll
2009-09-23 16:51:14 ----A---- C:\Windows\system32\EhStorAPI.dll
2009-09-23 16:51:14 ----A---- C:\Windows\system32\CertEnroll.dll
2009-09-23 16:51:13 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2009-09-23 16:51:12 ----A---- C:\Windows\system32\msvcp60.dll
2009-09-23 16:51:12 ----A---- C:\Windows\system32\msjtes40.dll
2009-09-23 16:51:12 ----A---- C:\Windows\system32\infocardapi.dll
2009-09-23 16:51:12 ----A---- C:\Windows\system32\gpedit.dll
2009-09-23 16:51:12 ----A---- C:\Windows\system32\AuxiliaryDisplayDriverLib.dll
2009-09-23 16:51:11 ----A---- C:\Windows\system32\WinSAT.exe
2009-09-23 16:51:10 ----A---- C:\Windows\system32\PresentationSettings.exe
2009-09-23 16:51:10 ----A---- C:\Windows\system32\mstext40.dll
2009-09-23 16:51:10 ----A---- C:\Windows\system32\Magnify.exe
2009-09-23 16:51:10 ----A---- C:\Windows\system32\es.dll
2009-09-23 16:51:10 ----A---- C:\Windows\system32\AuxiliaryDisplayServices.dll
2009-09-23 16:51:09 ----A---- C:\Windows\system32\advapi32.dll
2009-09-23 16:51:08 ----A---- C:\Windows\system32\WMPhoto.dll
2009-09-23 16:51:08 ----A---- C:\Windows\system32\WebClnt.dll
2009-09-23 16:51:08 ----A---- C:\Windows\system32\slwmi.dll
2009-09-23 16:51:08 ----A---- C:\Windows\system32\msexcl40.dll
2009-09-23 16:51:07 ----A---- C:\Windows\system32\WindowsAnytimeUpgradeCPL.dll
2009-09-23 16:51:07 ----A---- C:\Windows\system32\vssapi.dll
2009-09-23 16:51:07 ----A---- C:\Windows\system32\msxbde40.dll
2009-09-23 16:51:07 ----A---- C:\Windows\system32\comsvcs.dll
2009-09-23 16:51:06 ----A---- C:\Windows\system32\NetProjW.dll
2009-09-23 16:51:06 ----A---- C:\Windows\system32\authui.dll
2009-09-23 16:51:05 ----A---- C:\Windows\system32\propsys.dll
2009-09-23 16:51:05 ----A---- C:\Windows\system32\PresentationHost.exe
2009-09-23 16:51:05 ----A---- C:\Windows\system32\newdev.dll
2009-09-23 16:51:05 ----A---- C:\Windows\system32\msrepl40.dll
2009-09-23 16:51:04 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-09-23 16:51:04 ----A---- C:\Windows\system32\iasrecst.dll
2009-09-23 16:51:04 ----A---- C:\Windows\system32\gpsvc.dll
2009-09-23 16:51:04 ----A---- C:\Windows\system32\eudcedit.exe
2009-09-23 16:51:04 ----A---- C:\Windows\system32\crypt32.dll
2009-09-23 16:51:04 ----A---- C:\Windows\explorer.exe
2009-09-23 16:51:03 ----A---- C:\Windows\system32\setupapi.dll
2009-09-23 16:51:03 ----A---- C:\Windows\system32\rpcss.dll
2009-09-23 16:51:03 ----A---- C:\Windows\system32\mspbde40.dll
2009-09-23 16:51:02 ----A---- C:\Windows\system32\msltus40.dll
2009-09-23 16:51:02 ----A---- C:\Windows\system32\mfc42.dll
2009-09-23 16:51:02 ----A---- C:\Windows\system32\davclnt.dll
2009-09-23 16:51:02 ----A---- C:\Windows\system32\d3d9.dll
2009-09-23 16:51:01 ----A---- C:\Windows\system32\shlwapi.dll
2009-09-23 16:51:01 ----A---- C:\Windows\system32\msrd3x40.dll
2009-09-23 16:51:01 ----A---- C:\Windows\system32\msdtctm.dll
2009-09-23 16:51:01 ----A---- C:\Windows\system32\EhStorPwdMgr.dll
2009-09-23 16:51:01 ----A---- C:\Windows\system32\EhStorAuthn.dll
2009-09-23 16:51:01 ----A---- C:\Windows\system32\browseui.dll
2009-09-23 16:51:00 ----A---- C:\Windows\system32\wevtapi.dll
2009-09-23 16:51:00 ----A---- C:\Windows\system32\photowiz.dll
2009-09-23 16:51:00 ----A---- C:\Windows\system32\nlhtml.dll
2009-09-23 16:50:59 ----A---- C:\Windows\system32\user32.dll
2009-09-23 16:50:59 ----A---- C:\Windows\system32\samsrv.dll
2009-09-23 16:50:59 ----A---- C:\Windows\system32\ci.dll
2009-09-23 16:50:58 ----A---- C:\Windows\system32\win32spl.dll
2009-09-23 16:50:58 ----A---- C:\Windows\system32\WcnNetsh.dll
2009-09-23 16:50:58 ----A---- C:\Windows\system32\SLCommDlg.dll
2009-09-23 16:50:58 ----A---- C:\Windows\system32\quartz.dll
2009-09-23 16:50:58 ----A---- C:\Windows\system32\oleaut32.dll
2009-09-23 16:50:57 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
2009-09-23 16:50:57 ----A---- C:\Windows\system32\netshell.dll
2009-09-23 16:50:57 ----A---- C:\Windows\system32\IKEEXT.DLL
2009-09-23 16:50:57 ----A---- C:\Windows\system32\compcln.exe
2009-09-23 16:50:56 ----A---- C:\Windows\system32\xmlfilter.dll
2009-09-23 16:50:56 ----A---- C:\Windows\system32\winhttp.dll
2009-09-23 16:50:56 ----A---- C:\Windows\system32\mswstr10.dll
2009-09-23 16:50:56 ----A---- C:\Windows\system32\audiosrv.dll
2009-09-23 16:50:56 ----A---- C:\Windows\system32\apds.dll
2009-09-23 16:50:55 ----A---- C:\Windows\system32\msvcrt.dll
2009-09-23 16:50:55 ----A---- C:\Windows\system32\msctf.dll
2009-09-23 16:50:55 ----A---- C:\Windows\system32\emdmgmt.dll
2009-09-23 16:50:54 ----A---- C:\Windows\system32\VSSVC.exe
2009-09-23 16:50:54 ----A---- C:\Windows\system32\QAGENTRT.DLL
2009-09-23 16:50:54 ----A---- C:\Windows\system32\mfc42u.dll
2009-09-23 16:50:54 ----A---- C:\Windows\system32\iphlpsvc.dll
2009-09-23 16:50:54 ----A---- C:\Windows\system32\gdi32.dll
2009-09-23 16:50:53 ----A---- C:\Windows\system32\sqlsrv32.dll
2009-09-23 16:50:53 ----A---- C:\Windows\system32\SLUI.exe
2009-09-23 16:50:53 ----A---- C:\Windows\system32\msrd2x40.dll
2009-09-23 16:50:53 ----A---- C:\Windows\system32\eapphost.dll
2009-09-23 16:50:52 ----A---- C:\Windows\system32\winresume.exe
2009-09-23 16:50:52 ----A---- C:\Windows\system32\shdocvw.dll
2009-09-23 16:50:52 ----A---- C:\Windows\system32\propdefs.dll
2009-09-23 16:50:52 ----A---- C:\Windows\system32\odbc32.dll
2009-09-23 16:50:51 ----A---- C:\Windows\system32\wevtutil.exe
2009-09-23 16:50:51 ----A---- C:\Windows\system32\dbgeng.dll
2009-09-23 16:50:50 ----A---- C:\Windows\system32\mssitlb.dll
2009-09-23 16:50:49 ----A---- C:\Windows\system32\WsmSvc.dll
2009-09-23 16:50:49 ----A---- C:\Windows\system32\swprv.dll
2009-09-23 16:50:49 ----A---- C:\Windows\system32\mmcndmgr.dll
2009-09-23 16:50:48 ----A---- C:\Windows\system32\vds.exe
2009-09-23 16:50:48 ----A---- C:\Windows\system32\usp10.dll
2009-09-23 16:50:47 ----A---- C:\Windows\system32\netlogon.dll
2009-09-23 16:50:47 ----A---- C:\Windows\system32\msscb.dll
2009-09-23 16:50:47 ----A---- C:\Windows\system32\msctfp.dll
2009-09-23 16:50:47 ----A---- C:\Windows\system32\fdBthProxy.dll
2009-09-23 16:50:47 ----A---- C:\Windows\system32\drvinst.exe
2009-09-23 16:50:47 ----A---- C:\Windows\system32\devmgr.dll
2009-09-23 16:50:47 ----A---- C:\Windows\system32\DevicePairingProxy.dll
2009-09-23 16:50:47 ----A---- C:\Windows\system32\BFE.DLL
2009-09-23 16:50:47 ----A---- C:\Windows\system32\adsldpc.dll
2009-09-23 16:50:46 ----A---- C:\Windows\system32\WSDApi.dll
2009-09-23 16:50:46 ----A---- C:\Windows\system32\WMVSDECD.DLL
2009-09-23 16:50:46 ----A---- C:\Windows\system32\Wldap32.dll
2009-09-23 16:50:46 ----A---- C:\Windows\system32\wcnwiz.dll
2009-09-23 16:50:46 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
2009-09-23 16:50:46 ----A---- C:\Windows\system32\evr.dll
2009-09-23 16:50:45 ----A---- C:\Windows\system32\WindowsCodecs.dll
2009-09-23 16:50:45 ----A---- C:\Windows\system32\wercon.exe
2009-09-23 16:50:45 ----A---- C:\Windows\system32\services.exe
2009-09-23 16:50:44 ----A---- C:\Windows\system32\wcncsvc.dll
2009-09-23 16:50:44 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2009-09-23 16:50:44 ----A---- C:\Windows\system32\mimefilt.dll
2009-09-23 16:50:44 ----A---- C:\Windows\system32\comdlg32.dll
2009-09-23 16:50:44 ----A---- C:\Windows\system32\adtschema.dll
2009-09-23 16:50:43 ----A---- C:\Windows\system32\taskeng.exe
2009-09-23 16:50:43 ----A---- C:\Windows\system32\reg.exe
2009-09-23 16:50:43 ----A---- C:\Windows\system32\mswdat10.dll
2009-09-23 16:50:43 ----A---- C:\Windows\system32\msjter40.dll
2009-09-23 16:50:43 ----A---- C:\Windows\system32\msdtcprx.dll
2009-09-23 16:50:43 ----A---- C:\Windows\system32\msdrm.dll
2009-09-23 16:50:43 ----A---- C:\Windows\system32\ipsmsnap.dll
2009-09-23 16:50:43 ----A---- C:\Windows\system32\certcli.dll
2009-09-23 16:50:42 ----A---- C:\Windows\system32\WMNetMgr.dll
2009-09-23 16:50:42 ----A---- C:\Windows\system32\w32time.dll
2009-09-23 16:50:42 ----A---- C:\Windows\system32\umpnpmgr.dll
2009-09-23 16:50:42 ----A---- C:\Windows\system32\rtffilt.dll
2009-09-23 16:50:42 ----A---- C:\Windows\system32\dnsapi.dll
2009-09-23 16:50:42 ----A---- C:\Windows\system32\certutil.exe
2009-09-23 16:50:41 ----A---- C:\Windows\system32\rsaenh.dll
2009-09-23 16:50:41 ----A---- C:\Windows\system32\msshooks.dll
2009-09-23 16:50:41 ----A---- C:\Windows\system32\msscntrs.dll
2009-09-23 16:50:41 ----A---- C:\Windows\system32\msihnd.dll
2009-09-23 16:50:41 ----A---- C:\Windows\system32\IPSECSVC.DLL
2009-09-23 16:50:41 ----A---- C:\Windows\system32\bthserv.dll
2009-09-23 16:50:41 ----A---- C:\Windows\system32\bcrypt.dll
2009-09-23 16:50:40 ----A---- C:\Windows\system32\TsWpfWrp.exe
2009-09-23 16:50:40 ----A---- C:\Windows\system32\msstrc.dll
2009-09-23 16:50:40 ----A---- C:\Windows\system32\MMDevAPI.dll
2009-09-23 16:50:38 ----A---- C:\Windows\system32\netapi32.dll
2009-09-23 16:50:38 ----A---- C:\Windows\system32\mtxclu.dll
2009-09-23 16:50:38 ----A---- C:\Windows\system32\mscories.dll
2009-09-23 16:50:38 ----A---- C:\Windows\system32\inetpp.dll
2009-09-23 16:50:38 ----A---- C:\Windows\system32\inetcomm.dll
2009-09-23 16:50:38 ----A---- C:\Windows\system32\hidserv.dll
2009-09-23 16:50:38 ----A---- C:\Windows\system32\fundisc.dll
2009-09-23 16:50:38 ----A---- C:\Windows\system32\dfshim.dll
2009-09-23 16:50:38 ----A---- C:\Windows\system32\cryptsvc.dll
2009-09-23 16:50:37 ----A---- C:\Windows\system32\wmicmiplugin.dll
2009-09-23 16:50:37 ----A---- C:\Windows\system32\termsrv.dll
2009-09-23 16:50:37 ----A---- C:\Windows\system32\profsvc.dll
2009-09-23 16:50:37 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2009-09-23 16:50:36 ----A---- C:\Windows\system32\wdc.dll
2009-09-23 16:50:36 ----A---- C:\Windows\system32\shsvcs.dll
2009-09-23 16:50:36 ----A---- C:\Windows\system32\msiexec.exe