Voila le scanner LOG:
<code>Logfile of random's system information tool 1.06 (written by random/random)
Run by Admin at 2009-05-25 14:29:22
Microsoft Windows XP Professional Service Pack 3
System drive C: has 5 GB (9%) free of 50 GB
Total RAM: 1014 MB (60% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:30:29, on 25.05.2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\ICQ6Toolbar\ICQ Service.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Power Translator 11\LogoMedia TranslateDotNet Server.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\NMSAccessU.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Admin\Рабочий стол\RSIT.exe
C:\Program Files\USB Disk Security\USBGuard.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Archivos de Programa\Sys_Kl\sys_kl.exe
C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
C:\Program Files\Mail.Ru\Agent\MAgent.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\KillSoft\KillWatcher\kwatch.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Trend Micro\HijackThis\Admin.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\GridinSoft Trojan Killer\trojankiller.exe
C:\Program Files\Avira\AntiVir Desktop\GUARDGUI.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbox.digsby.com/ie
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://searchbox.digsby.com/search?q=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 74.55.63.27:58258
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
R3 - URLSearchHook: Live-Foot Toolbar - {8f81d798-5b23-4832-abc3-a4f94b2f3d94} - C:\Program Files\Live-Foot\tbLive.dll
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe
O2 - BHO: IE7Pro BHO - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IEPro\iepro.dll
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\Snagit 9\SnagitBHO.dll
O2 - BHO: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll (file missing)
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: CmjBrowserHelperObject Object - {07A11D74-9D25-4fea-A833-8B0D76A5577A} - C:\Program Files\Mindjet\MindManager 7\Mm7InternetExplorer.dll
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Спутник@Mail.Ru - {8984B388-A5BB-4DF7-B274-77B879E179DB} - c:\program files\Mail.Ru\Sputnik\MailRuSputnik.dll
O2 - BHO: Live-Foot Toolbar - {8f81d798-5b23-4832-abc3-a4f94b2f3d94} - C:\Program Files\Live-Foot\tbLive.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: AIEBHO.SiteWatcherBHO - {d9d423dd-80d0-48d8-9e8c-43ae08cf1ed8} - mscoree.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\YTSingleInstance.dll
O3 - Toolbar: LEC - {1DBAB667-A486-421e-AFE4-CF07DD0088E5} - C:\Program Files\Power Translator 11\Applications\LEC IE Translation Extension.dll
O3 - Toolbar: Спутник@Mail.Ru - {09900DE8-1DCA-443F-9243-26FF581438AF} - c:\program files\Mail.Ru\Sputnik\MailRuSputnik.dll
O4 - HKLM\..\Run: [USB Antivirus] C:\Program Files\USB Disk Security\USBGuard.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Sys_Kl] C:\Archivos de Programa\Sys_Kl\sys_kl.exe 1
O4 - HKLM\..\Run: [MAgent] C:\Program Files\Mail.Ru\Agent\MAgent.exe -LM
O4 - HKLM\..\Run: [FBI] C:\Program Files\BPK\FBI.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [KillWatcher] C:\Program Files\KillSoft\KillWatcher\kwatch.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [GridinSoft Trojan Killer] "C:\Program Files\GridinSoft Trojan Killer\trojankiller.exe" 0
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [VistaIcon] C:\Program Files\VistaDriveIcon\VistaDrv.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [ZZZZ1_FirstLogonSetting] %SystemRoot%\System32\rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\custom.inf,OnceFirstLogonInstall,0 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [IE7_012] rundll32 advpack.dll,LaunchINFSectionEx IE7int.inf,AfterUserStart,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [ZZZZ1_FirstLogonSetting] %SystemRoot%\System32\rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\custom.inf,OnceFirstLogonInstall,0 (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [ZZZZ2_FirstLogonSetting] %SystemRoot%\System32\rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\custom.inf,NewUserFirstLogonInstall,0 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [ZZZZ2_FirstLogonSetting] %SystemRoot%\System32\rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\custom.inf,NewUserFirstLogonInstall,0 (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &Dйfinition Encarta - http://fr.encarta.msn.com/encnet/features/dictionary/quickDictionary.htm
O8 - Extra context menu item: &Tout tйlйcharger avec FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Tйlйcharger avec FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: &Экспорт в Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Поиск@Mail.Ru - res://c:\program files\Mail.Ru\Sputnik\MailRuSputnik.dll/282
O8 - Extra context menu item: Словари@Mail.Ru - res://c:\program files\Mail.Ru\Sputnik\MailRuSputnik.dll/283
O9 - Extra button: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll
O9 - Extra 'Tools' menuitem: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll
O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
O9 - Extra button: Mail.Ru Агент - {7558B7E5-7B26-4201-BEDB-00D5FF534523} - C:\Program Files\Mail.Ru\Agent\magent.exe
O9 - Extra 'Tools' menuitem: Mail.Ru Агент - {7558B7E5-7B26-4201-BEDB-00D5FF534523} - C:\Program Files\Mail.Ru\Agent\magent.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Справочные материалы - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Send to Mindjet MindManager - {941E1A34-C6AF-4baa-A973-224F9C3E04BF} - C:\Program Files\Mindjet\MindManager 7\Mm7InternetExplorer.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - D:\DOCUMENTS\DOCUMENTS AISULUU\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - D:\DOCUMENTS\DOCUMENTS AISULUU\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/russian/partner/rus/kavwebscan_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} (Java Plug-in 1.6.0_12) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{1424B255-4C98-4F85-B370-6C350C2CBEAF}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS1\Services\Tcpip\..\{1424B255-4C98-4F85-B370-6C350C2CBEAF}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS2\Services\Tcpip\..\{1424B255-4C98-4F85-B370-6C350C2CBEAF}: NameServer = 208.67.222.222,208.67.220.220
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\rserver30\newtstop.dll, C:\WINDOWS\system32\vksaver.dll
O23 - Service: McAfee Application Installer Cleanup (0276901237425767) (0276901237425767mcinstcleanup) - Unknown owner - C:\DOCUME~1\Admin\LOCALS~1\Temp\027690~1.EXE (file missing)
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Журнал событий (Eventlog) - Корпорация Майкрософт - C:\WINDOWS\system32\services.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: Служба COM записи компакт-дисков IMAPI (ImapiService) - Корпорация Майкрософт - C:\WINDOWS\system32\imapi.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LEC TranslateDotNet Server - Language Engineering Corporation, LLC - C:\Program Files\Power Translator 11\LogoMedia TranslateDotNet Server.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\Common Files\NMSAccessU.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: Plug and Play (PlugPlay) - Корпорация Майкрософт - C:\WINDOWS\system32\services.exe
O23 - Service: Смарт-карты (SCardSvr) - Корпорация Майкрософт - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: Журналы и оповещения производительности (SysmonLog) - Корпорация Майкрософт - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
O23 - Service: Теневое копирование тома (VSS) - Корпорация Майкрософт - C:\WINDOWS\System32\vssvc.exe
O23 - Service: Адаптер производительности WMI (WmiApSrv) - Корпорация Майкрософт - C:\WINDOWS\system32\wbem\wmiapsrv.exe
End of file - 16023 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\1-Click Maintenance.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Auslogics Console Defragmentation.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{6FFC594A-0049-4AA5-9E5B-6477C02D569B}.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{CA658A75-8FEA-4042-8114-3096A531FA0D}.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{FD6B345F-FD14-423C-A152-7C1656A552CE}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00011268-E188-40DF-A514-835FCD78B1BF}]
IE7Pro BHO - C:\Program Files\IEPro\iepro.dll [2008-09-24 756840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00C6482D-C502-44C8-8409-FCE54AD9C208}]
SnagIt Toolbar Loader - C:\Program Files\TechSmith\Snagit 9\SnagitBHO.dll [2008-11-06 68936]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}]
Dealio Toolbar - C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]
&Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll [2008-07-28 882416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07A11D74-9D25-4fea-A833-8B0D76A5577A}]
CmjBrowserHelperObject Object - C:\Program Files\Mindjet\MindManager 7\Mm7InternetExplorer.dll [2007-05-18 71184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}]
FGCatchUrl - C:\Program Files\FlashGet\jccatch.dll [2007-05-16 94308]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2009-03-19 312928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-09-15 1562960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8984B388-A5BB-4DF7-B274-77B879E179DB}]
MailRuBHO Class - c:\program files\Mail.Ru\Sputnik\MailRuSputnik.dll [2009-04-25 680624]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8f81d798-5b23-4832-abc3-a4f94b2f3d94}]
Live-Foot Toolbar - C:\Program Files\Live-Foot\tbLive.dll [2008-11-24 1784856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2009-02-24 2403392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}]
McAfee SiteAdvisor BHO - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll [2009-02-13 150032]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d9d423dd-80d0-48d8-9e8c-43ae08cf1ed8}]
AIEBHO.SiteWatcherBHO - C:\WINDOWS\system32\mscoree.dll [2007-10-24 282112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-03-09 35840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-03-09 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F156768E-81EF-470C-9057-481BA8380DBA}]
FlashGet GetFlash Class - C:\Program Files\FlashGet\getflash.dll [2007-05-16 163840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
SingleInstance Class - C:\Program Files\Yahoo!\Companion\Installs\cpn2\YTSingleInstance.dll [2008-07-28 160496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{1DBAB667-A486-421e-AFE4-CF07DD0088E5} - LEC - C:\Program Files\Power Translator 11\Applications\LEC IE Translation Extension.dll [2006-08-31 2834432]
{09900DE8-1DCA-443F-9243-26FF581438AF} - Спутник@Mail.Ru - c:\program files\Mail.Ru\Sputnik\MailRuSputnik.dll [2009-04-25 680624]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"USB Antivirus"=C:\Program Files\USB Disk Security\USBGuard.exe [2008-06-21 798720]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-03-09 148888]
"Camera Assistant Software"=C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe [2007-10-25 413696]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-12-06 1024000]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2008-02-05 141848]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2008-02-05 162328]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2008-02-05 137752]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
"Sys_Kl"=C:\Archivos de Programa\Sys_Kl\sys_kl.exe [2006-09-13 414208]
"MAgent"=C:\Program Files\Mail.Ru\Agent\MAgent.exe [2009-04-25 6210744]
"FBI"=C:\Program Files\BPK\FBI.exe []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]
"KillWatcher"=C:\Program Files\KillSoft\KillWatcher\kwatch.exe [2004-05-16 969728]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-02-06 3885408]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2001-02-20 8192]
"GridinSoft Trojan Killer"=C:\Program Files\GridinSoft Trojan Killer\trojankiller.exe [2009-05-22 3805184]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ad-Aware]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccleaner]
C:\Program Files\CCleaner\CCleaner.exe [2008-05-28 1197296]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2001-02-20 8192]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-07-24 490952]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eMuleAutoStart]
C:\Program Files\eMule\eMule.exe [2008-08-02 5484544]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FBI]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Flashget]
C:\Program Files\FlashGet\flashget.exe [2007-05-30 1986608]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2009-03-12 342312]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MAgent]
C:\Program Files\Mail.Ru\Agent\MAgent.exe [2009-04-25 6210744]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ManyCam]
C:\Program Files\ManyCam 2.4\ManyCam.exe [2009-03-16 1824040]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [2009-02-20 4363504]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMReminderService]
C:\Program Files\Mindjet\MindManager 7\MMReminderService.exe [2007-05-18 37392]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NotebookHardwareControl]
C:\Program Files\Notebook Hardware Control\nhc.exe [2007-05-04 2629632]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerGramo]
C:\Program Files\Monsters\PowerGramo\PowerGramo.exe [2009-02-15 847872]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pragma5]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
C:\WINDOWS\RTHDCPL.EXE [2008-10-09 17021440]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe [2009-03-06 24139560]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\somnifero]
C:\Program Files\Rico Software\RS Somnнfero\somnifero.exe [2006-02-27 364629]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe [2009-02-24 171448]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2009-03-19 198160]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPSMain]
C:\WINDOWS\system32\TPSMain.exe [2007-10-16 266240]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TuneUp MemOptimizer]
C:\Program Files\TuneUp Utilities 2009\MemOptimizer.exe [2008-12-11 155904]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\USB Safely Remove]
C:\Program Files\USB Safely Remove\USBSafelyRemove.exe [2008-02-05 1280512]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\USBFireWall]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YMailAdvisor]
C:\Program Files\Yahoo!\Common\YMailAdvisor.exe [2008-06-06 125208]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YSearchProtection]
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe [2008-07-11 223984]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoneAlarm Client]
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Admin^Главное меню^Программы^Автозагрузка^Create virtual drive.lnk]
C:\WEBSER~1\etc\utils\Boot.exe [2003-03-22 6656]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Admin^Главное меню^Программы^Автозагрузка^Free Music Zilla.lnk]
C:\PROGRA~1\FREEMU~1\FMZilla.exe [2009-02-10 732352]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Главное меню^Программы^Автозагрузка^Net Send GUI.lnk]
C:\PROGRA~1\FOMINE~1\NETSEN~1.EXE []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Главное меню^Программы^Автозагрузка^Total Commander.lnk]
C:\PROGRA~1\TOTALC~1\Totalcmd.exe [2008-12-31 1091768]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\WINDOWS\system32\rserver30\newtstop.dll, C:\WINDOWS\system32\vksaver.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2007-05-25 204800]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll [2007-06-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
nwprovau
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoSMConfigurePrograms"=1
"MaxRecentDocs"=16
"NoDriveAutoRun"=67108483
"NoSharedDocuments_XXX_Temp"=00000000
"NoUserNameInStartMenu"=1
"NoSharedDocuments"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoStrCmpLogical"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\FlashGet\flashget.exe"="C:\Program Files\FlashGet\flashget.exe:*:Enabled:FlashGet"
"D:\games\KONAMI\PES2009\pes2009.exe"="D:\games\KONAMI\PES2009\pes2009.exe:*:Enabled:Pro Evolution Soccer 2009"
"C:\Program Files\eMule\emule.exe"="C:\Program Files\eMule\emule.exe:*:Enabled:eMule"
"D:\games\valve\hl.exe"="D:\games\valve\hl.exe:*:Enabled:Half-Life Launcher"
"C:\WebServers\usr\local\apache\Apache.exe"="C:\WebServers\usr\local\apache\Apache.exe:*:Enabled:Apache"
"C:\Program Files\StrongDC++\StrongDC.exe"="C:\Program Files\StrongDC++\StrongDC.exe:*:Enabled:StrongDC++"
"C:\Program Files\Total Commander\Totalcmd.exe"="C:\Program Files\Total Commander\Totalcmd.exe:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\Program Files\IEPro\MiniDM.exe"="C:\Program Files\IEPro\MiniDM.exe:*:Enabled:MiniDM"
"C:\Documents and Settings\Admin\Application Data\U3\0391D57123015927\0DE4F643-C398-46ec-9339-2362F2311932\Exec\skype.exe"="C:\Documents and Settings\Admin\Application Data\U3\0391D57123015927\0DE4F643-C398-46ec-9339-2362F2311932\Exec\skype.exe:*:Enabled:Skype. Take a deep breath "
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"D:\FlashGet\flashget.exe"="D:\FlashGet\flashget.exe:*:Enabled:FlashGet"
"C:\Program Files\Free Music Zilla\FMZilla.exe"="C:\Program Files\Free Music Zilla\FMZilla.exe:*:Enabled:FMZilla"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"D:\games\KONAMI\PES2009\GCP2009.exe"="D:\games\KONAMI\PES2009\GCP2009.exe:*:Enabled:Pro Evolution Soccer 2009"
"D:\DOCUMENTS\DOCUMENTS AISULUU\ICQ6.5\ICQ.exe"="D:\DOCUMENTS\DOCUMENTS AISULUU\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\ma-config.com\maconfservice.exe"="C:\Program Files\ma-config.com\maconfservice.exe:LocalSubNet:Enabled:maconfservice"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ"
"C:\Program Files\Mail.Ru\Agent\magent.exe"="C:\Program Files\Mail.Ru\Agent\magent.exe:*:Enabled:Mail.Ru Агент"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\TVAnts\Tvants.exe"="C:\Program Files\TVAnts\Tvants.exe:*:Enabled:TVAnts"
"C:\Program Files\VideoLAN\VLC\vlc.exe"="C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player"
"C:\Program Files\Rico Software\RS Somnнfero\somnifero.exe"="C:\Program Files\Rico Software\RS Somnнfero\somnifero.exe:*:Enabled:somnifero"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1e5de7ea-10d0-11de-aee6-df71460e96c6}]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RUNdLl32.ExE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1e5de7eb-10d0-11de-aee6-df71460e96c6}]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RUNdLl32.ExE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1e5de7ec-10d0-11de-aee6-df71460e96c6}]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RUNdLl32.ExE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1e5de7ed-10d0-11de-aee6-df71460e96c6}]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RUNdLl32.ExE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{759f7b26-027b-11de-930e-001e334514d3}]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b3fe87b3-3099-11de-b463-001e334514d3}]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
======File associations======
.js - edit - "C:\Program Files\Macromedia\Dreamweaver 8\dreamweaver.exe" "%1"
.js - open -
======List of files/folders created in the last 2 months======
2009-05-25 13:57:34 ----D---- C:\rsit
2009-05-25 13:17:59 ----D---- C:\Program Files\Ad-remover
2009-05-25 12:56:21 ----D---- C:\Program Files\Trend Micro
2009-05-25 12:11:29 ----D---- C:\Documents and Settings\Admin\Application Data\Malwarebytes
2009-05-25 12:11:14 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-05-25 12:11:13 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-05-25 11:57:04 ----D---- C:\Program Files\GridinSoft Trojan Killer
2009-05-25 11:50:09 ----D---- C:\Program Files\Microsoft Windows OneCare Live
2009-05-24 23:39:27 ----D---- C:\Documents and Settings\Admin\Application Data\Opera
2009-05-24 23:38:09 ----D---- C:\Program Files\Opera
2009-05-24 21:14:46 ----A---- C:\WINDOWS\wininit.ini
2009-05-24 19:40:54 ----D---- C:\WINDOWS\dp_wsed
2009-05-24 14:47:58 ----A---- C:\WINDOWS\system32\securenet.dll
2009-05-23 13:19:09 ----D---- C:\Program Files\Mindscape
2009-05-23 09:00:19 ----A---- C:\WINDOWS\system32\dijpg.dll
2009-05-23 08:58:57 ----D---- C:\Program Files\Rico Software
2009-05-21 19:52:52 ----D---- C:\Program Files\AIDA32 - Enterprise System Information
2009-05-21 19:34:35 ----A---- C:\WINDOWS\system32\d3dx10_41.dll
2009-05-21 19:34:35 ----A---- C:\WINDOWS\system32\D3DCompiler_41.dll
2009-05-21 19:34:33 ----A---- C:\WINDOWS\system32\D3DX9_41.dll
2009-05-21 19:34:31 ----A---- C:\WINDOWS\system32\XAudio2_4.dll
2009-05-21 19:34:31 ----A---- C:\WINDOWS\system32\XAPOFX1_3.dll
2009-05-21 19:34:29 ----A---- C:\WINDOWS\system32\xactengine3_4.dll
2009-05-21 19:34:27 ----A---- C:\WINDOWS\system32\X3DAudio1_6.dll
2009-05-21 19:28:31 ----D---- C:\Direct X 9.c
2009-05-21 11:36:36 ----D---- C:\WINDOWS\system32\IMAGES
2009-05-21 11:24:07 ----A---- C:\WINDOWS\CK.txt
2009-05-21 11:20:42 ----D---- C:\Archivos de Programa
2009-05-19 20:02:20 ----D---- C:\Documents and Settings\Admin\Application Data\Thunderbird
2009-05-18 12:35:40 ----D---- C:\Documents and Settings\Admin\Application Data\Thinstall
2009-05-18 12:21:12 ----D---- C:\Program Files\Common Files\Common Share
2009-05-18 12:18:49 ----D---- C:\Program Files\Aplus FLV to MP3 Converter
2009-05-18 12:17:19 ----D---- C:\Mp3 Output
2009-05-18 12:17:15 ----A---- C:\WINDOWS\system32\NCMedia.dll
2009-05-18 12:17:15 ----A---- C:\WINDOWS\system32\libmp3lame-0.dll
2009-05-18 12:17:14 ----D---- C:\Program Files\Smallvideosoft
2009-05-12 15:03:22 ----A---- C:\Logfile.txt
2009-05-12 14:59:33 ----D---- C:\Documents and Settings\All Users\Application Data\SysDll
2009-05-12 14:59:31 ----D---- C:\Documents and Settings\All Users\Application Data\SysDir
2009-05-12 14:59:02 ----D---- C:\Documents and Settings\All Users\Application Data\The Best KeyLogger
2009-05-11 13:12:03 ----D---- C:\Documents and Settings\Admin\Application Data\gtk-2.0
2009-05-11 12:50:27 ----D---- C:\Documents and Settings\Admin\Application Data\Talkback
2009-05-10 14:57:04 ----RA---- C:\WINDOWS\system32\memorybar.exe
2009-05-10 13:38:44 ----D---- C:\Program Files\KillSoft
2009-05-09 11:09:03 ----D---- C:\Program Files\xp-AntiSpy
2009-05-08 18:30:07 ----D---- C:\WINDOWS\system32\LogFiles
2009-05-07 15:57:57 ----A---- C:\WINDOWS\cdplayer.ini
2009-05-02 19:29:50 ----D---- C:\Program Files\Microsoft
2009-05-02 19:29:28 ----D---- C:\Program Files\Windows Live SkyDrive
2009-05-02 19:28:55 ----D---- C:\Program Files\Windows Live
2009-05-02 19:16:34 ----D---- C:\Program Files\Common Files\Windows Live
2009-05-01 22:34:15 ----A---- C:\WINDOWS\DaemonPlugin.INI
2009-04-30 07:38:04 ----D---- C:\Program Files\Avira
2009-04-30 07:38:04 ----D---- C:\Documents and Settings\All Users\Application Data\Avira
2009-04-28 19:09:36 ----D---- C:\Program Files\ma-config.com
2009-04-28 19:09:35 ----D---- C:\Documents and Settings\All Users\Application Data\ma-config.com
2009-04-28 18:12:17 ----D---- C:\Program Files\SystemRequirementsLab
2009-04-28 18:12:04 ----D---- C:\Documents and Settings\Admin\Application Data\SystemRequirementsLab
2009-04-28 15:11:19 ----D---- C:\Documents and Settings\Admin\Application Data\DivX
2009-04-27 19:47:13 ----D---- C:\Program Files\ICQ6Toolbar
2009-04-27 19:46:52 ----D---- C:\Documents and Settings\All Users\Application Data\ICQ
2009-04-27 17:48:14 ----N---- C:\WINDOWS\system32\pxinsi64.exe
2009-04-27 17:48:14 ----N---- C:\WINDOWS\system32\pxinsa64.exe
2009-04-27 17:48:14 ----N---- C:\WINDOWS\system32\pxhpinst.exe
2009-04-27 17:48:14 ----N---- C:\WINDOWS\system32\pxcpyi64.exe
2009-04-27 17:48:14 ----N---- C:\WINDOWS\system32\pxcpya64.exe
2009-04-27 17:48:13 ----N---- C:\WINDOWS\system32\vxblock.dll
2009-04-27 17:48:13 ----N---- C:\WINDOWS\system32\pxwave.dll
2009-04-27 17:48:13 ----N---- C:\WINDOWS\system32\pxsfs.dll
2009-04-27 17:48:13 ----N---- C:\WINDOWS\system32\pxmas.dll
2009-04-27 17:48:13 ----N---- C:\WINDOWS\system32\pxdrv.dll
2009-04-27 17:48:13 ----N---- C:\WINDOWS\system32\pxafs.dll
2009-04-27 17:48:12 ----N---- C:\WINDOWS\system32\px.dll
2009-04-27 17:47:30 ----D---- C:\Program Files\Common Files\DivX Shared
2009-04-27 17:47:29 ----D---- C:\Program Files\DivX
2009-04-25 22:01:52 ----D---- C:\WINDOWS\system32\windows media
2009-04-25 22:01:41 ----D---- C:\WINDOWS\RegisteredPackages
2009-04-25 22:01:40 ----HD---- C:\WINDOWS\msdownld.tmp
2009-04-25 22:01:31 ----D---- C:\Program Files\Windows Media Components
2009-04-25 21:45:51 ----D---- C:\Program Files\TVAnts
2009-04-24 10:28:50 ----A---- C:\WINDOWS\system32\shell32.dll
2009-04-24 09:50:04 ----D---- C:\Documents and Settings\All Users\Application Data\WebcamMax
2009-04-24 09:50:04 ----D---- C:\Documents and Settings\Admin\Application Data\WebcamMax
2009-04-24 09:42:45 ----D---- C:\Program Files\WebcamMax
2009-04-22 21:34:05 ----D---- C:\WINDOWS\system32\Adobe
2009-04-22 16:56:12 ----D---- C:\skin
2009-04-22 16:56:10 ----D---- C:\graphics
2009-04-22 03:13:03 ----RASH---- C:\BOOTSECT.BAK
2009-04-22 03:13:02 ----H---- C:\Boot.BAK
2009-04-22 03:13:00 ----SHD---- C:\Boot
2009-04-19 13:05:23 ----D---- C:\Documents and Settings\Admin\Application Data\Mra
2009-04-19 13:05:02 ----D---- C:\Program Files\Mail.Ru
2009-04-16 21:51:27 ----D---- C:\Program Files\Common Files\Skype
2009-04-16 21:51:23 ----RD---- C:\Program Files\Skype
2009-04-15 23:24:40 ----A---- C:\WINDOWS\system32\dpl100.dll
2009-04-15 23:24:38 ----A---- C:\WINDOWS\system32\divx_xx11.dll
2009-04-15 23:24:38 ----A---- C:\WINDOWS\system32\divx_xx0c.dll
2009-04-15 23:24:38 ----A---- C:\WINDOWS\system32\divx_xx0a.dll
2009-04-15 23:24:38 ----A---- C:\WINDOWS\system32\divx_xx07.dll
2009-04-15 23:24:38 ----A---- C:\WINDOWS\system32\DivX.dll
2009-04-15 18:01:51 ----A---- C:\WINDOWS\system32\igfxres.dll
2009-04-15 17:58:54 ----A---- C:\WINDOWS\system32\igxprd32.dll
2009-04-15 17:58:54 ----A---- C:\WINDOWS\system32\igxpdv32.dll
2009-04-15 17:58:54 ----A---- C:\WINDOWS\system32\igfxtray.exe
2009-04-15 17:58:54 ----A---- C:\WINDOWS\system32\igfxsrvc.dll
2009-04-15 17:58:54 ----A---- C:\WINDOWS\system32\igfxpers.exe
2009-04-15 17:58:54 ----A---- C:\WINDOWS\system32\hccutils.dll
2009-04-15 17:58:53 ----A---- C:\WINDOWS\system32\igxpgd32.dll
2009-04-15 17:58:53 ----A---- C:\WINDOWS\system32\igxpdx32.dll
2009-04-15 17:58:53 ----A---- C:\WINDOWS\system32\igmedkrn.dll
2009-04-15 17:58:53 ----A---- C:\WINDOWS\system32\igfxsrvc.exe
2009-04-15 17:58:53 ----A---- C:\WINDOWS\system32\igfxress.dll
2009-04-15 17:58:53 ----A---- C:\WINDOWS\system32\igfxpph.dll
2009-04-15 17:58:53 ----A---- C:\WINDOWS\system32\igfxdev.dll
2009-04-15 17:58:53 ----A---- C:\WINDOWS\system32\igfxCoIn_v4833.dll
2009-04-15 17:58:53 ----A---- C:\WINDOWS\system32\hkcmd.exe
2009-04-15 17:58:49 ----A---- C:\WINDOWS\system32\igxpun.exe
2009-04-15 17:50:51 ----D---- C:\WINDOWS\system32\Lang
2009-04-15 00:00:56 ----D---- C:\WINDOWS\system32\appmgmt
2009-04-14 00:34:17 ----A---- C:\WINDOWS\NDSTray.INI
2009-04-14 00:00:04 ----A---- C:\WINDOWS\ModemLog_TOSHIBA Software Modem.txt
2009-04-13 19:48:34 ----D---- C:\Documents and Settings\Admin\Application Data\Toshiba
2009-04-13 19:42:27 ----A---- C:\WINDOWS\NDSBrow.INI
2009-04-13 19:14:56 ----D---- C:\Program Files\Synaptics
2009-04-13 19:14:56 ----A---- C:\WINDOWS\system32\SynTPAPI.dll
2009-04-13 19:14:56 ----A---- C:\WINDOWS\system32\SynCtrl.dll
2009-04-13 19:14:56 ----A---- C:\WINDOWS\system32\SynCOM.dll
2009-04-13 19:00:57 ----A---- C:\WINDOWS\system32\TPSAddin.dll
2009-04-13 19:00:56 ----A---- C:\WINDOWS\system32\TPwrCfg.dll
2009-04-13 19:00:55 ----A---- C:\WINDOWS\system32\TPwrReg.dll
2009-04-13 19:00:55 ----A---- C:\WINDOWS\system32\TPSTrace.dll
2009-04-13 19:00:55 ----A---- C:\WINDOWS\system32\TPSMainCtl.dll
2009-04-13 19:00:55 ----A---- C:\WINDOWS\system32\TPSMain.exe
2009-04-13 19:00:55 ----A---- C:\WINDOWS\system32\TPSDel.dll
2009-04-13 19:00:55 ----A---- C:\WINDOWS\system32\TPSBattM.exe
2009-04-13 19:00:55 ----A---- C:\WINDOWS\system32\TPeculiarity.dll
2009-04-13 19:00:55 ----A---- C:\WINDOWS\system32\CpuPerf.dll
2009-04-13 18:54:01 ----D---- C:\Program Files\TOSHIBA
2009-04-13 18:46:21 ----D---- C:\Program Files\ltmoh
2009-04-13 18:46:21 ----A---- C:\WINDOWS\system32\tosmreg.ini
2009-04-13 18:46:21 ----A---- C:\WINDOWS\system32\tosmreg.exe
2009-04-13 18:46:21 ----A---- C:\WINDOWS\system32\cseltbl.ini
2009-04-13 18:46:21 ----A---- C:\WINDOWS\system32\csellang.ini
2009-04-13 18:46:21 ----A---- C:\WINDOWS\system32\csellang.dll
2009-04-13 18:46:21 ----A---- C:\WINDOWS\system32\cselect.exe
2009-04-13 18:45:45 ----N---- C:\WINDOWS\agrsmdel.exe
2009-04-13 18:45:45 ----A---- C:\WINDOWS\system32\agrsmsvc.exe
2009-04-13 18:45:44 ----A---- C:\WINDOWS\system32\agrscoin.dll
2009-04-13 18:41:30 ----D---- C:\TD08TBF
2009-04-13 18:40:56 ----D---- C:\Program Files\Camera Assistant Software for Toshiba
2009-04-13 18:20:40 ----D---- C:\Documents and Settings\Admin\Application Data\ManyCam
2009-04-13 18:20:39 ----D---- C:\Program Files\ManyCam 2.4
2009-04-13 07:29:11 ----D---- C:\Dev-Pas
2009-04-11 19:08:53 ----D---- C:\Program Files\CamStudio
2009-04-11 18:54:48 ----D---- C:\Program Files\MSECache
2009-04-11 18:52:53 ----D---- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2009-04-11 18:52:46 ----D---- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2009-04-11 10:17:20 ----A---- C:\WINDOWS\system32\TUKernel.exe
2009-04-10 15:26:27 ----D---- C:\Program Files\Rational Rose Ent
2009-04-08 09:01:40 ----A---- C:\WINDOWS\system32\javaws.exe
2009-04-08 09:01:40 ----A---- C:\WINDOWS\system32\javaw.exe
2009-04-08 09:01:40 ----A---- C:\WINDOWS\system32\java.exe
2009-04-08 02:21:02 ----D---- C:\Documents and Settings\Admin\Application Data\vlc
2009-04-08 02:17:30 ----D---- C:\Documents and Settings\Admin\Application Data\MozillaControl
2009-04-08 02:13:47 ----D---- C:\Program Files\VideoLAN
2009-04-08 01:29:32 ----D---- C:\Documents and Settings\All Users\Application Data\TVU Networks
2009-04-03 13:53:34 ----D---- C:\WINDOWS\setup.pss
2009-04-03 13:53:34 ----A---- C:\WINDOWS\UPGRADE.TXT
2009-03-29 12:05:08 ----A---- C:\rollback.ini
2009-03-29 11:14:24 ----D---- C:\Documents and Settings\All Users\Application Data\MailFrontier
2009-03-29 10:58:24 ----D---- C:\WINDOWS\Internet Logs
2009-03-29 10:56:50 ----D---- C:\WINDOWS\ie8updates
2009-03-29 10:51:48 ----HDC---- C:\WINDOWS\ie8
2009-03-27 13:13:28 ----D---- C:\Program Files\Power Translator 11
2009-03-26 11:03:10 ----A---- C:\WINDOWS\system32\libexpatw.dll
======List of files/folders modified in the last 2 months======
2009-05-25 14:30:03 ----D---- C:\WINDOWS\Temp
2009-05-25 14:29:19 ----D---- C:\WINDOWS\system32\CatRoot2
2009-05-25 14:15:00 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-05-25 14:04:48 ----D---- C:\WINDOWS
2009-05-25 14:04:08 ----D---- C:\WINDOWS\system32\drivers
2009-05-25 14:04:08 ----D---- C:\WINDOWS\system32
2009-05-25 13:46:47 ----D---- C:\Program Files\Mozilla Firefox
2009-05-25 13:37:19 ----SHD---- C:\WINDOWS\Installer
2009-05-25 13:35:58 ----AD---- C:\Program Files
2009-05-25 11:59:52 ----D---- C:\WINDOWS\system32\ShellExt
2009-05-25 10:27:10 ----D---- C:\Program Files\Power Data Recovery
2009-05-24 23:09:58 ----D---- C:\WINDOWS\Prefetch
2009-05-24 23:00:42 ----D---- C:\Documents and Settings\Admin\Application Data\Skype
2009-05-24 21:52:38 ----HD---- C:\WINDOWS\inf
2009-05-24 20:38:51 ----SD---- C:\WINDOWS\Tasks
2009-05-24 20:29:46 ----D---- C:\Program Files\eMule
2009-05-24 20:24:56 ----D---- C:\Program Files\Google
2009-05-24 20:24:56 ----D---- C:\Documents and Settings\All Users\Application Data\Google
2009-05-24 19:47:55 ----AD---- C:\Program Files\Common Files\Microsoft Shared
2009-05-24 19:47:55 ----AD---- C:\Program Files\Common Files
2009-05-24 18:22:44 ----D---- C:\Documents and Settings\Admin\Application Data\skypePM
2009-05-24 14:42:47 ----RSH---- C:\boot.ini
2009-05-24 14:42:47 ----A---- C:\WINDOWS\win.ini
2009-05-24 14:42:47 ----A---- C:\WINDOWS\system.ini
2009-05-21 20:30:30 ----D---- C:\Program Files\Free Music Zilla
2009-05-21 19:38:17 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-05-21 19:38:16 ----D---- C:\WINDOWS\system32\CatRoot
2009-05-21 19:38:11 ----D---- C:\WINDOWS\system32\ReinstallBackups
2009-05-21 19:37:21 ----HD---- C:\Program Files\InstallShield Installation Information
2009-05-21 19:36:49 ----D---- C:\WINDOWS\system
2009-05-21 19:34:43 ----D---- C:\WINDOWS\system32\DirectX
2009-05-21 19:33:01 ----RSD---- C:\WINDOWS\assembly
2009-05-21 14:38:56 ----D---- C:\Program Files\FlashGet
2009-05-20 15:42:18 ----D---- C:\WINDOWS\WinSxS
2009-05-19 20:02:40 ----D---- C:\Documents and Settings\Admin\Application Data\Mozilla
2009-05-14 21:23:31 ----D---- C:\Program Files\Digsby
2009-05-11 15:43:35 ----D---- C:\Program Files\CommentCaMarche
2009-05-09 08:03:58 ----D---- C:\WINDOWS\Microsoft.NET
2009-05-02 20:59:17 ----D---- C:\Program Files\Microsoft Silverlight
2009-05-02 19:56:21 ----SD---- C:\Documents and Settings\Admin\Application Data\Microsoft
2009-05-02 19:29:35 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-05-02 19:29:04 ----RSD---- C:\WINDOWS\Fonts
2009-05-01 22:33:31 ----D---- C:\Documents and Settings\Admin\Application Data\DAEMON Tools
2009-04-29 15:39:30 ----D---- C:\Program Files\IpTv Player
2009-04-28 00:25:47 ----D---- C:\Documents and Settings\Admin\Application Data\ICQ
2009-04-27 16:18:32 ----SHD---- C:\System Volume Information
2009-04-26 14:22:26 ----D---- C:\Documents and Settings\Admin\Application Data\VSO
2009-04-26 02:12:46 ----D---- C:\WINDOWS\pss
2009-04-22 21:55:30 ----D---- C:\Program Files\Windows Media Player
2009-04-22 16:56:24 ----D---- C:\Program Files\ICQ6.5
2009-04-20 04:04:05 ----D---- C:\Program Files\The KMPlayer
2009-04-20 02:45:00 ----D---- C:\WINDOWS\system32\config
2009-04-20 02:44:37 ----D---- C:\WINDOWS\system32\wbem
2009-04-20 02:44:36 ----D---- C:\WINDOWS\Registration
2009-04-20 02:06:58 ----D---- C:\Documents and Settings
2009-04-19 18:26:54 ----D---- C:\Program Files\Notepad++
2009-04-19 18:07:31 ----A---- C:\WINDOWS\ODBC.INI
2009-04-19 17:50:25 ----D---- C:\Program Files\Wandering IPs
2009-04-19 17:37:25 ----D---- C:\Documents and Settings\Admin\Application Data\RaimaRadioPro
2009-04-17 11:52:50 ----D---- C:\WINDOWS\system32\CPLDAPU
2009-04-16 21:51:27 ----D---- C:\Documents and Settings\All Users\Application Data\Skype
2009-04-15 21:25:21 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-04-14 23:56:46 ----D---- C:\Documents and Settings\Admin\Application Data\Lavasoft
2009-04-13 19:28:23 ----D---- C:\Program Files\Intel
2009-04-13 19:14:47 ----D---- C:\Program Files\Common Files\InstallShield
2009-04-13 19:00:56 ----D---- C:\WINDOWS\Help
2009-04-13 18:46:21 ----D---- C:\WINDOWS\Driver Cache
2009-04-13 18:45:15 ----D---- C:\Program Files\WinRAR
2009-04-11 19:41:40 ----D---- C:\WINDOWS\Debug
2009-04-11 19:06:19 ----D---- C:\Documents and Settings\All Users\Application Data\2DBoy
2009-04-11 19:01:25 ----D---- C:\WINDOWS\system32\DRM
2009-04-11 19:00:39 ----D---- C:\WINDOWS\SoftwareDistribution
2009-04-11 18:59:58 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-04-11 18:55:10 ----D---- C:\Program Files\Microsoft Office
2009-04-11 09:42:00 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2009-04-08 09:01:25 ----D---- C:\Program Files\Java
2009-04-08 01:57:36 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-04-07 21:23:00 ----D---- C:\Program Files\Unlocker
2009-04-06 11:40:05 ----D---- C:\Program Files\Internet Explorer
2009-04-03 09:55:48 ----D---- C:\WINDOWS\system32\Restore
2009-04-03 02:20:20 ----D---- C:\WINDOWS\system32\ias
2009-03-29 15:26:42 ----D---- C:\Downloads
2009-03-29 11:30:22 ----D---- C:\WINDOWS\system32\ru-ru
2009-03-29 11:30:20 ----D---- C:\WINDOWS\Media
2009-03-29 10:56:47 ----HD---- C:\WINDOWS\$hf_mig$
2009-03-26 10:43:18 ----D---- C:\Documents and Settings\Admin\Application Data\codeblocks
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
R1 intelppm;Драйвер Intel процессора; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-15 40704]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-02-13 28376]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-03-24 55640]
R2 Netdevio;TOSHIBA Network Device Usermode I/O Protocol; C:\WINDOWS\system32\DRIVERS\netdevio.sys [2003-01-29 12032]
R2 NwlnkIpx;NWLink IPX/SPX/NetBIOS-совместимый транспортный протокол; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-15 88320]
R2 NwlnkNb;NWLink NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2008-04-15 63232]
R2 NwlnkSpx;Протокол NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2008-04-15 55936]
R2 rspndr;Ответчик обнаружения топологии уровня связи; C:\WINDOWS\system32\DRIVERS\rspndr.sys [2008-10-11 62848]
R3 AgereSoftModem;TOSHIBA V92 Software Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2006-11-28 1161888]
R3 CmBatt;Драйвер батареи с ACPI-управлением (Майкрософт); C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-14 13952]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-01-15 23848]
R3 HDAudBus;Драйвер шины Microsoft UAA для High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-15 144384]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2007-05-25 5761760]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-10-13 4879360]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver; C:\WINDOWS\system32\DRIVERS\ManyCam.sys [2008-01-14 21632]
R3 NWRDR;NetWare Rdr; C:\WINDOWS\system32\DRIVERS\nwrdr.sys [2008-04-15 163584]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2008-10-31 117888]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2007-12-06 220032]
R3 usbccgp;Драйвер универсального родительского