Vir adirka (vyřešeno)

Sekce věnovaná virům a jiným škodlivým kódům, rovněž ale nástrojům, kterým se lze proti nim bránit…

Moderátoři: Mods_senior, Security team

nováček
Příspěvky: 8
Registrován: březen 07
Pohlaví: Nespecifikováno
Stav:
Offline

Vir adirka (vyřešeno)

Příspěvekod » 17 bře 2007 09:29

prosím pomoste mam tady nejaky vir adirka anejde vymazat co stim?

Reklama
Uživatelský avatar
fredik
člen Security týmu
Master Level 7
Master Level 7
Příspěvky: 4680
Registrován: červenec 06
Pohlaví: Muž
Stav:
Offline

Příspěvekod fredik » 17 bře 2007 09:32

Vlož sem log z HijackThis ať je vidět jaký postup přesně zvolit.

nováček
Příspěvky: 8
Registrován: březen 07
Pohlaví: Nespecifikováno
Stav:
Offline

Příspěvekod » 17 bře 2007 09:47

Logfile of HijackThis v1.99.1
Scan saved at 9:44:13, on 17.3.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\ICQLite\ICQLite.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\Program Files\Skype\Plugin Manager\SkypePM.exe
C:\WINDOWS\system32\adirka.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\Lenka\LOCALS~1\Temp\Dočasný adresář 1 pro hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.icq.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\Program Files\ICQToolbar\toolbaru.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [sysinter] C:\WINDOWS\system32\adirss.exe
O4 - HKLM\..\Run: [lnwin.exe] C:\WINDOWS\system32\lnwin.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ICQ Lite] "C:\Program Files\ICQLite\ICQLite.exe" -minimize
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\nbj.exe"
O4 - HKCU\..\Run: [adirka] C:\WINDOWS\system32\adirka.exe
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'rsvp32_2.dll' missing
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 0242390843
O17 - HKLM\System\CCS\Services\Tcpip\..\{358A2281-3B3F-45E1-AD29-740B6C36AE67}: NameServer = 212.158.128.2,212.158.128.3
O17 - HKLM\System\CCS\Services\Tcpip\..\{5925BEE0-0A02-4F05-8F43-A20ADCDDEAD8}: NameServer = 192.168.6.9
O17 - HKLM\System\CS1\Services\Tcpip\..\{358A2281-3B3F-45E1-AD29-740B6C36AE67}: NameServer = 212.158.128.2,212.158.128.3
O17 - HKLM\System\CS2\Services\Tcpip\..\{358A2281-3B3F-45E1-AD29-740B6C36AE67}: NameServer = 212.158.128.2,212.158.128.3
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

Uživatelský avatar
fredik
člen Security týmu
Master Level 7
Master Level 7
Příspěvky: 4680
Registrován: červenec 06
Pohlaví: Muž
Stav:
Offline

Příspěvekod fredik » 17 bře 2007 09:50

Postupuj přesně podle tohoto návodu bod po bodu:
sakiri píše:1. krok
Stáhni si LSPFix a spusť ho.
V okně zatrhni čtvereček u volby I know what i'm doing a zaktivují se ti šipečky mezi okny.A potom v levém okně označ rsvp32_2.dll šipkama >> jej přesuň do pravého okna.Poté klikni na tlačítko Finish.
Ale nepřesunuj nic jiného jinak by jsi si mohl znefukčnit internet a kdyby v tom pravém bude ještě něco jiného než rsvp32_2.dll tak ho tak to přesuň šipkami << zpět do levého okna.

2.krok
Teprve poté co aplikuješ LSPFix tak postpuj takto.

Stáhni si SDFix a spusť ho ,vybalí se do vlastní složky (bude asi na C:\SDfix).

Poté restartuj PC do nouzového režimu.Otevři složku kde je vybalený SDFix a spusť soubor RunThis.bat a stiskni Y pro zahájení čistícího procesu.
Pro dokončení bude třeba stisknout libovolnou klávesu a počítač se restartuje.
Při nabíhání operačního systému budeš muset po vyzvání stisknout libovolnou klávesu pro vstup do do Win.

Po naběhnutí OS by ti měl zobrazit výpis SDFixu tak ho sem zkopíruj pokud by ti nevyběhne tak je umístěný ve své vlastní složce jako Report.txt (nezapomeň sem zkopírovat jeho obsah) + nový HJT log.

+ si tam nezapomeň nainstalovat firewall.
Až to provedeš tak sem dej ty dva logy (Sdfix a z HJT)

nováček
Příspěvky: 8
Registrován: březen 07
Pohlaví: Nespecifikováno
Stav:
Offline

Příspěvekod » 17 bře 2007 10:13

je to asi blby ale ja nevim jak mam restartovat pc do nouyovyho sistemu

Uživatelský avatar
fredik
člen Security týmu
Master Level 7
Master Level 7
Příspěvky: 4680
Registrován: červenec 06
Pohlaví: Muž
Stav:
Offline

Příspěvekod fredik » 17 bře 2007 10:16

To je v pořádku niko není vševědoucí, tady najdeš postup jak se tam dostat: Jak spustit Windows v NR

nováček
Příspěvky: 8
Registrován: březen 07
Pohlaví: Nespecifikováno
Stav:
Offline

Příspěvekod » 17 bře 2007 10:35

SDFix: Version 1.73

Run by Lenka - so 17.03.2007 - 10:22:10,81

Microsoft Windows XP [Verze 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:

Name:
wincom32

Path:
\??\C:\WINDOWS\system32\wincom32.sys

wincom32 Deleted



Restoring Windows Registry Entries
Restoring Default Hosts File


Rebooting...

Normal Mode:
Checking Files:

Below files will be copied to Backups folder then removed:

C:\WINDOWS\SYSTEM32\PFB0E0~1.DLL - Deleted
C:\WINDOWS\SYSTEM32\PFCA7F~1.DLL - Deleted
C:\WINDOWS\SYSTEM32\SFXZMT~1.DLL - Deleted
C:\WINDOWS\SYSTEM32\SFXZMT~2.DLL - Deleted
C:\WINDOWS\SYSTEM32\SFXZMT~3.DLL - Deleted
C:\WINDOWS\SYSTEM32\SFXZMT~4.DLL - Deleted
C:\WINDOWS\pp.exe - Deleted
C:\WINDOWS\system32\adirka.dll - Deleted
C:\WINDOWS\system32\adirka.exe - Deleted
C:\WINDOWS\system32\dd.exe - Deleted
C:\WINDOWS\system32\sm.exe - Deleted
C:\WINDOWS\system32\via.exe - Deleted
C:\WINDOWS\system32\wincom32.ini - Deleted
C:\WINDOWS\system32\wincom32.sys - Deleted
C:\WINDOWS\system32\zlbw.dll - Deleted



ADS Check:

C:\WINDOWS\system32
No streams found.


Final Check:

Remaining Services:
------------------



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\ICQLite\\ICQLite.exe"="C:\\Program Files\\ICQLite\\ICQLite.exe:*:Enabled:ICQ Lite"
"C:\\Program Files\\GameSpy Arcade\\Aphex.exe"="C:\\Program Files\\GameSpy Arcade\\Aphex.exe:*:Enabled:GameSpy Arcade"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\WINDOWS\\system32\\sm.exe"="C:\\WINDOWS\\system32\\sm.exe:*:Enabled:enable"
"C:\\WINDOWS\\system32\\dd.exe"="C:\\WINDOWS\\system32\\dd.exe:*:Enabled:enable"
"C:\\WINDOWS\\system32\\adirss.exe"="C:\\WINDOWS\\system32\\adirss.exe:*:Enabled:enable"
"C:\\WINDOWS\\system32\\lnwin.exe"="C:\\WINDOWS\\system32\\lnwin.exe:*:Enabled:enable"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype. The whole world can talk for free."


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"


Remaining Files:
---------------
C:\WINDOWS\system32\rsvp32_2.dll Found - LSP!

Backups Folder: - C:\SDFix\backups\backups.zip

Checking For Files with Hidden Attributes :

C:\Program Files\Canon\MP Navigator 3.0\uinstrsc.dll
C:\Program Files\Canon\MP Navigator 3.0\Maint.exe
C:\WINDOWS\Temp\2hsyr3v6.TMP

Finished














Logfile of HijackThis v1.99.1
Scan saved at 10:34:37, on 17.3.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\Program Files\Skype\Plugin Manager\SkypePM.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\Lenka\LOCALS~1\Temp\Dočasný adresář 2 pro hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.icq.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\Program Files\ICQToolbar\toolbaru.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\nbj.exe"
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 0242390843
O17 - HKLM\System\CCS\Services\Tcpip\..\{358A2281-3B3F-45E1-AD29-740B6C36AE67}: NameServer = 212.158.128.2,212.158.128.3
O17 - HKLM\System\CCS\Services\Tcpip\..\{5925BEE0-0A02-4F05-8F43-A20ADCDDEAD8}: NameServer = 192.168.6.9
O17 - HKLM\System\CS1\Services\Tcpip\..\{358A2281-3B3F-45E1-AD29-740B6C36AE67}: NameServer = 212.158.128.2,212.158.128.3
O17 - HKLM\System\CS2\Services\Tcpip\..\{358A2281-3B3F-45E1-AD29-740B6C36AE67}: NameServer = 212.158.128.2,212.158.128.3
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

Uživatelský avatar
fredik
člen Security týmu
Master Level 7
Master Level 7
Příspěvky: 4680
Registrován: červenec 06
Pohlaví: Muž
Stav:
Offline

Příspěvekod fredik » 17 bře 2007 11:05

Fixni v HJT toto:

Spusť znovu HijackThis a zaškrtni v něm okénka před řádky:
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
po zaškrtnutí klikni na tlačítko Fix Checked

Pro lepší zabezpečení Pc by bylo dobré si doinstalovat Firewall (doporučil bych ti asi Kerio - je v čestině) odkaz na stažení najdeš zde:

Jelikož registry jsou věc ošemetná tak zvaž jestli se pustíš do tohoto bodu co je v citaci:
sakiri píše:Jinak máš tam nějaké zůstatky v registrech takže pokud chceš odstranit tak udělej toto:
Poté co to fixneš tak restartuj PC do nouzového režimu.

Jelikož registry jsou vždy velice citlivá věc tak udělej zálohu registru při záloze postupuj takhle:
Start -> Spustit (Run) a do volného řádku zkopírovat ten tučně modrý text:
regedit /e c:\registrybackup.reg
a dej enter

Budou se zálohovat registry nemělo by to trvat dlouho.

Teprve když skončí tak udělej toto:
Otevři poznámkový blok a do něj zkopíruj ten to text:

Kód: Vybrat vše

REGEDIT4

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\dd.exe"=-
"C:\\WINDOWS\\system32\\sm.exe"=-
"C:\\WINDOWS\\system32\\adirss.exe"=-
"C:\\WINDOWS\\system32\\lnwin.exe"=-


Pak dej Soubor (File) -> Uložit jako (Save As) -> jak je Název souboru (File name) tak do toho řádku napiš:fix.reg
Jak je Typ souboru (Save as type) tak tam vyber *všechny soubory (*all files)
A ulož ho na plochu.
Naploše by se měl objevit fix.reg spusť ho vyskočí hláška kde odklikni Ano (Yes) poté je další hláška kde odklikni OK

No a poté restartuj do normálního režimu.


Pro jistotu jestli ještě nemáš někde něco v sytému tak udělej toto:
Stáhni si Mwav. Proveď update a spusť prohlídku přes tlačítko Scan & Clean (nesmíš mít zatrhnutou volbu Scan Only). Pokud ještě něco najde tak to odstraní. Po skončení prohlídky bude chtít možná restart tak ho povol.

Pak ještě pročisti Win. tímto: CCleaner (Čistič a Problémy).

A to bude vše pokud nemáš nějaké další problémy.

Uživatelský avatar
fredik
člen Security týmu
Master Level 7
Master Level 7
Příspěvky: 4680
Registrován: červenec 06
Pohlaví: Muž
Stav:
Offline

Příspěvekod fredik » 17 bře 2007 11:27

gnaver: Založ si vlastní téma a tady ten příspěvek zruš!
Zatím postupuj jak je napsaný návod nejdříve LSPfix až po něm SdFix.

nováček
Příspěvky: 8
Registrován: březen 07
Pohlaví: Nespecifikováno
Stav:
Offline

Příspěvekod » 17 bře 2007 11:33

dekuju moc jestli uz to tam neni tak uz nic zatim nepotrebuju :D

Uživatelský avatar
fredik
člen Security týmu
Master Level 7
Master Level 7
Příspěvky: 4680
Registrován: červenec 06
Pohlaví: Muž
Stav:
Offline

Příspěvekod fredik » 17 bře 2007 11:37

Už by to mělo být v pořádku ale raději to zkus projet ještě tím Mwav, jestli tam ještě někde není něco skryto, jak jsem psal. Měj se Obrázek

nováček
Příspěvky: 8
Registrován: březen 07
Pohlaví: Nespecifikováno
Stav:
Offline

Příspěvekod » 17 bře 2007 20:43

program MWAV mi nasel tohle tak plosim poradte mam ten poprvi a vubec nevim co s tim


Sat Mar 17 20:26:07 2007 => MWAV in SPECIAL PROMOTION MODE.
Sat Mar 17 20:26:07 2007 => **********************************************************
Sat Mar 17 20:26:07 2007 => MicroWorld Anti Virus & Spyware Toolkit Utility.
Sat Mar 17 20:26:07 2007 => Copyright © 2003-2006, MicroWorld Technologies Inc.
Sat Mar 17 20:26:07 2007 => **********************************************************
Sat Mar 17 20:26:07 2007 => Source: C:\DOCUME~1\Lenka\LOCALS~1\TEMPOR~1\Content.IE5\3KT7OJ4E\MWAV_1~1.EXE
Sat Mar 17 20:26:07 2007 => Version 9.1.7 (C:\DOCUME~1\Lenka\LOCALS~1\Temp\mexe.com)
Sat Mar 17 20:26:07 2007 => Log File: C:\DOCUME~1\Lenka\LOCALS~1\Temp\MWAV.LOG
Sat Mar 17 20:26:07 2007 => MWAV Registered: TRUE.
Sat Mar 17 20:26:07 2007 => User Account: Lenka
Sat Mar 17 20:26:07 2007 => OS Type: Windows Workstation
Sat Mar 17 20:26:07 2007 => OS: Windows XP
Sat Mar 17 20:26:07 2007 => Ver: Service Pack 2 (Build 2600)
Sat Mar 17 20:26:07 2007 => Windows Root Folder: C:\WINDOWS
Sat Mar 17 20:26:07 2007 => Windows Sys32 Folder: C:\WINDOWS\system32
Sat Mar 17 20:26:07 2007 => Local Fixed Drives: c:\
Sat Mar 17 20:26:07 2007 => MWAV Mode: Scan and Clean files (for viruses, adware and spyware).
Sat Mar 17 20:26:07 2007 => Latest Date of files inside MWAV: 16 Mar 2007 09:34:1.
Sat Mar 17 20:26:10 2007 => AV Library Loaded...
Sat Mar 17 20:26:10 2007 => MWAV doing self scanning...
Sat Mar 17 20:26:10 2007 => Scanning File C:\DOCUME~1\Lenka\LOCALS~1\Temp\Getvlist.exe
Sat Mar 17 20:26:10 2007 => Scanning File C:\DOCUME~1\Lenka\LOCALS~1\Temp\main.avi
Sat Mar 17 20:26:10 2007 => Scanning File C:\DOCUME~1\Lenka\LOCALS~1\Temp\virus.avi
Sat Mar 17 20:26:10 2007 => Scanning File C:\DOCUME~1\Lenka\LOCALS~1\Temp\ScanningProcess.exe
Sat Mar 17 20:26:10 2007 => Scanning File C:\DOCUME~1\Lenka\LOCALS~1\Temp\Kave.dll
Sat Mar 17 20:26:10 2007 => Scanning File C:\DOCUME~1\Lenka\LOCALS~1\Temp\prloader.dll
Sat Mar 17 20:26:10 2007 => MWAV files are clean.
Sat Mar 17 20:26:34 2007 => Virus Database Date: 3/16/2007
Sat Mar 17 20:26:34 2007 => Virus Database Count: 282250
Sat Mar 17 20:27:57 2007 => Downloading AntiVirus and Anti-Spyware Databases...
Sat Mar 17 20:28:29 2007 => Downloads Successful...
Sat Mar 17 20:28:38 2007 => Indexed Spyware Databases Successfully Created...
Sat Mar 17 20:28:38 2007 => Reload of AntiVirus Signatures successfully done.
Sat Mar 17 20:28:38 2007 => Virus Database Date: 3/17/2007
Sat Mar 17 20:28:38 2007 => Virus Database Count: 282636

Sat Mar 17 20:28:40 2007 => **********************************************************
Sat Mar 17 20:28:40 2007 => MicroWorld Anti Virus & Spyware Toolkit Utility.
Sat Mar 17 20:28:40 2007 => Copyright © 2003-2006, MicroWorld Technologies Inc.
Sat Mar 17 20:28:40 2007 =>
Sat Mar 17 20:28:40 2007 => Support: support@mwti.net
Sat Mar 17 20:28:40 2007 => Web: http://www.mwti.net
Sat Mar 17 20:28:40 2007 => **********************************************************
Sat Mar 17 20:28:40 2007 => Version 9.1.7 (C:\DOCUME~1\Lenka\LOCALS~1\Temp\mexe.com)
Sat Mar 17 20:28:40 2007 => Log File: C:\DOCUME~1\Lenka\LOCALS~1\Temp\MWAV.LOG
Sat Mar 17 20:28:40 2007 => User Account: Lenka
Sat Mar 17 20:28:40 2007 => Windows Root Folder: C:\WINDOWS
Sat Mar 17 20:28:40 2007 => Windows Sys32 Folder: C:\WINDOWS\system32
Sat Mar 17 20:28:40 2007 => OS: Windows XP
Sat Mar 17 20:28:40 2007 => Ver: Service Pack 2 (Build 2600)
Sat Mar 17 20:28:40 2007 => Latest Date of files inside MWAV: 17 Mar 2007 17:36:4.

Sat Mar 17 20:28:40 2007 => Options Selected by User:
Sat Mar 17 20:28:40 2007 => Memory Check: Enabled
Sat Mar 17 20:28:40 2007 => Registry Check: Enabled
Sat Mar 17 20:28:40 2007 => StartUp Folder Check: Enabled
Sat Mar 17 20:28:40 2007 => System Folder Check: Enabled
Sat Mar 17 20:28:40 2007 => System Area Check: Disabled
Sat Mar 17 20:28:40 2007 => Services Check: Enabled
Sat Mar 17 20:28:40 2007 => Drive Check Option Disabled
Sat Mar 17 20:28:40 2007 => Folder Check: Disabled

Sat Mar 17 20:28:42 2007 => ***** Scanning Memory Files *****
Sat Mar 17 20:28:42 2007 => Scanning File C:\WINDOWS\System32\smss.exe
Sat Mar 17 20:28:42 2007 => Scanning File C:\WINDOWS\system32\ntdll.dll
Sat Mar 17 20:28:42 2007 => Scanning File C:\WINDOWS\SYSTEM32\CSRSS.EXE
Sat Mar 17 20:28:42 2007 => Scanning File C:\WINDOWS\system32\CSRSRV.dll
Sat Mar 17 20:28:42 2007 => Scanning File C:\WINDOWS\system32\basesrv.dll
Sat Mar 17 20:28:42 2007 => Scanning File C:\WINDOWS\system32\winsrv.dll
Sat Mar 17 20:28:42 2007 => Scanning File C:\WINDOWS\system32\GDI32.dll
Sat Mar 17 20:28:42 2007 => Scanning File C:\WINDOWS\system32\KERNEL32.dll
Sat Mar 17 20:28:42 2007 => Scanning File C:\WINDOWS\system32\USER32.dll
Sat Mar 17 20:28:42 2007 => Scanning File C:\WINDOWS\system32\sxs.dll
Sat Mar 17 20:28:42 2007 => Scanning File C:\WINDOWS\system32\ADVAPI32.dll
Sat Mar 17 20:28:43 2007 => Scanning File C:\WINDOWS\system32\RPCRT4.dll
Sat Mar 17 20:28:43 2007 => Scanning File C:\WINDOWS\SYSTEM32\WINLOGON.EXE
Sat Mar 17 20:28:43 2007 => Scanning File C:\WINDOWS\system32\AUTHZ.dll
Sat Mar 17 20:28:43 2007 => Scanning File C:\WINDOWS\system32\msvcrt.dll
Sat Mar 17 20:28:43 2007 => Scanning File C:\WINDOWS\system32\CRYPT32.dll
Sat Mar 17 20:28:43 2007 => Scanning File C:\WINDOWS\system32\MSASN1.dll
Sat Mar 17 20:28:43 2007 => Scanning File C:\WINDOWS\system32\NDdeApi.dll
Sat Mar 17 20:28:43 2007 => Scanning File C:\WINDOWS\system32\PROFMAP.dll
Sat Mar 17 20:28:43 2007 => Scanning File C:\WINDOWS\system32\NETAPI32.dll
Sat Mar 17 20:28:43 2007 => Scanning File C:\WINDOWS\system32\USERENV.dll
Sat Mar 17 20:28:43 2007 => Scanning File C:\WINDOWS\system32\PSAPI.DLL
Sat Mar 17 20:28:43 2007 => Scanning File C:\WINDOWS\system32\REGAPI.dll
Sat Mar 17 20:28:43 2007 => Scanning File C:\WINDOWS\system32\Secur32.dll
Sat Mar 17 20:28:43 2007 => Scanning File C:\WINDOWS\system32\SETUPAPI.dll
Sat Mar 17 20:28:43 2007 => Scanning File C:\WINDOWS\system32\VERSION.dll
Sat Mar 17 20:28:43 2007 => Scanning File C:\WINDOWS\system32\WINSTA.dll
Sat Mar 17 20:28:43 2007 => Scanning File C:\WINDOWS\system32\WINTRUST.dll
Sat Mar 17 20:28:43 2007 => Scanning File C:\WINDOWS\system32\IMAGEHLP.dll
Sat Mar 17 20:28:43 2007 => Scanning File C:\WINDOWS\system32\WS2_32.dll
Sat Mar 17 20:28:43 2007 => Scanning File C:\WINDOWS\system32\WS2HELP.dll
Sat Mar 17 20:28:43 2007 => Scanning File C:\WINDOWS\system32\IMM32.DLL
Sat Mar 17 20:28:43 2007 => Scanning File C:\WINDOWS\system32\MSGINA.dll
Sat Mar 17 20:28:44 2007 => Scanning File C:\WINDOWS\system32\SHELL32.dll
Sat Mar 17 20:28:44 2007 => Scanning File C:\WINDOWS\system32\SHLWAPI.dll
Sat Mar 17 20:28:44 2007 => Scanning File C:\WINDOWS\system32\COMCTL32.dll
Sat Mar 17 20:28:44 2007 => Scanning File C:\WINDOWS\system32\ODBC32.dll
Sat Mar 17 20:28:44 2007 => Scanning File C:\WINDOWS\system32\comdlg32.dll
Sat Mar 17 20:28:44 2007 => Scanning File C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
Sat Mar 17 20:28:44 2007 => Scanning File C:\WINDOWS\system32\odbcint.dll
Sat Mar 17 20:28:44 2007 => Scanning File C:\WINDOWS\system32\SHSVCS.dll
Sat Mar 17 20:28:44 2007 => Scanning File C:\WINDOWS\system32\sfc.dll
Sat Mar 17 20:28:44 2007 => Scanning File C:\WINDOWS\system32\sfc_os.dll
Sat Mar 17 20:28:44 2007 => Scanning File C:\WINDOWS\system32\ole32.dll
Sat Mar 17 20:28:44 2007 => Scanning File C:\WINDOWS\system32\Apphelp.dll
Sat Mar 17 20:28:44 2007 => Scanning File C:\WINDOWS\system32\msctfime.ime
Sat Mar 17 20:28:44 2007 => Scanning File C:\WINDOWS\system32\WINSCARD.DLL
Sat Mar 17 20:28:44 2007 => Scanning File C:\WINDOWS\system32\WTSAPI32.dll
Sat Mar 17 20:28:44 2007 => Scanning File C:\WINDOWS\system32\uxtheme.dll
Sat Mar 17 20:28:44 2007 => Scanning File C:\WINDOWS\system32\WINMM.dll
Sat Mar 17 20:28:44 2007 => Scanning File C:\WINDOWS\system32\cscdll.dll
Sat Mar 17 20:28:44 2007 => Scanning File C:\WINDOWS\system32\WlNotify.dll
Sat Mar 17 20:28:44 2007 => Scanning File C:\WINDOWS\system32\WINSPOOL.DRV
Sat Mar 17 20:28:44 2007 => Scanning File C:\WINDOWS\system32\MPR.dll
Sat Mar 17 20:28:44 2007 => Scanning File C:\WINDOWS\system32\rsaenh.dll
Sat Mar 17 20:28:44 2007 => Scanning File C:\WINDOWS\system32\SAMLIB.dll
Sat Mar 17 20:28:44 2007 => Scanning File C:\WINDOWS\system32\msv1_0.dll
Sat Mar 17 20:28:44 2007 => Scanning File C:\WINDOWS\system32\iphlpapi.dll
Sat Mar 17 20:28:44 2007 => Scanning File C:\WINDOWS\system32\cscui.dll
Sat Mar 17 20:28:44 2007 => Scanning File C:\WINDOWS\system32\wdmaud.drv
Sat Mar 17 20:28:44 2007 => Scanning File C:\WINDOWS\system32\MPRAPI.dll
Sat Mar 17 20:28:44 2007 => Scanning File C:\WINDOWS\system32\ACTIVEDS.dll
Sat Mar 17 20:28:44 2007 => Scanning File C:\WINDOWS\system32\adsldpc.dll
Sat Mar 17 20:28:44 2007 => Scanning File C:\WINDOWS\system32\WLDAP32.dll
Sat Mar 17 20:28:45 2007 => Scanning File C:\WINDOWS\system32\ATL.DLL
Sat Mar 17 20:28:45 2007 => Scanning File C:\WINDOWS\system32\OLEAUT32.dll
Sat Mar 17 20:28:45 2007 => Scanning File C:\WINDOWS\system32\rtutils.dll
Sat Mar 17 20:28:45 2007 => Scanning File C:\WINDOWS\system32\msacm32.drv
Sat Mar 17 20:28:45 2007 => Scanning File C:\WINDOWS\system32\MSACM32.dll
Sat Mar 17 20:28:45 2007 => Scanning File C:\WINDOWS\system32\xpsp2res.dll
Sat Mar 17 20:28:45 2007 => Scanning File C:\WINDOWS\system32\midimap.dll
Sat Mar 17 20:28:45 2007 => Scanning File C:\WINDOWS\system32\COMRes.dll
Sat Mar 17 20:28:45 2007 => Scanning File C:\WINDOWS\system32\CLBCATQ.DLL
Sat Mar 17 20:28:45 2007 => Scanning File C:\WINDOWS\system32\NTMARTA.DLL
Sat Mar 17 20:28:45 2007 => Scanning File C:\WINDOWS\system32\services.exe
Sat Mar 17 20:28:45 2007 => Scanning File C:\WINDOWS\system32\SCESRV.dll
Sat Mar 17 20:28:45 2007 => Scanning File C:\WINDOWS\system32\umpnpmgr.dll
Sat Mar 17 20:28:45 2007 => Scanning File C:\WINDOWS\system32\NCObjAPI.DLL
Sat Mar 17 20:28:45 2007 => Scanning File C:\WINDOWS\system32\MSVCP60.dll
Sat Mar 17 20:28:45 2007 => Scanning File C:\WINDOWS\system32\ShimEng.dll
Sat Mar 17 20:28:45 2007 => Scanning File C:\WINDOWS\AppPatch\AcGenral.DLL
Sat Mar 17 20:28:45 2007 => Scanning File C:\WINDOWS\system32\eventlog.dll
Sat Mar 17 20:28:45 2007 => Scanning File C:\WINDOWS\system32\lsass.exe
Sat Mar 17 20:28:45 2007 => Scanning File C:\WINDOWS\system32\LSASRV.dll
Sat Mar 17 20:28:45 2007 => Scanning File C:\WINDOWS\system32\NTDSAPI.dll
Sat Mar 17 20:28:45 2007 => Scanning File C:\WINDOWS\system32\DNSAPI.dll
Sat Mar 17 20:28:45 2007 => Scanning File C:\WINDOWS\system32\SAMSRV.dll
Sat Mar 17 20:28:45 2007 => Scanning File C:\WINDOWS\system32\cryptdll.dll
Sat Mar 17 20:28:45 2007 => Scanning File C:\WINDOWS\system32\msprivs.dll
Sat Mar 17 20:28:45 2007 => Scanning File C:\WINDOWS\system32\kerberos.dll
Sat Mar 17 20:28:45 2007 => Scanning File C:\WINDOWS\system32\netlogon.dll
Sat Mar 17 20:28:45 2007 => Scanning File C:\WINDOWS\system32\w32time.dll
Sat Mar 17 20:28:45 2007 => Scanning File C:\WINDOWS\system32\schannel.dll
Sat Mar 17 20:28:46 2007 => Scanning File C:\WINDOWS\system32\wdigest.dll
Sat Mar 17 20:28:46 2007 => Scanning File C:\WINDOWS\system32\scecli.dll
Sat Mar 17 20:28:46 2007 => Scanning File C:\WINDOWS\system32\ipsecsvc.dll
Sat Mar 17 20:28:46 2007 => Scanning File C:\WINDOWS\system32\oakley.DLL
Sat Mar 17 20:28:46 2007 => Scanning File C:\WINDOWS\system32\WINIPSEC.DLL
Sat Mar 17 20:28:46 2007 => Scanning File C:\WINDOWS\system32\mswsock.dll
Sat Mar 17 20:28:46 2007 => Scanning File C:\WINDOWS\system32\hnetcfg.dll
Sat Mar 17 20:28:46 2007 => Scanning File C:\WINDOWS\System32\wshtcpip.dll
Sat Mar 17 20:28:46 2007 => Scanning File C:\WINDOWS\system32\pstorsvc.dll
Sat Mar 17 20:28:46 2007 => Scanning File C:\WINDOWS\system32\psbase.dll
Sat Mar 17 20:28:46 2007 => Scanning File C:\WINDOWS\system32\dssenh.dll
Sat Mar 17 20:28:46 2007 => Scanning File C:\WINDOWS\system32\svchost.exe
Sat Mar 17 20:28:46 2007 => Scanning File c:\windows\system32\rpcss.dll
Sat Mar 17 20:28:46 2007 => Scanning File c:\windows\system32\termsrv.dll
Sat Mar 17 20:28:46 2007 => Scanning File c:\windows\system32\ICAAPI.dll
Sat Mar 17 20:28:46 2007 => Scanning File c:\windows\system32\mstlsapi.dll
Sat Mar 17 20:28:46 2007 => Scanning File C:\WINDOWS\System32\winrnr.dll
Sat Mar 17 20:28:46 2007 => Scanning File C:\WINDOWS\system32\rasadhlp.dll
Sat Mar 17 20:28:46 2007 => Scanning File c:\windows\system32\dhcpcsvc.dll
Sat Mar 17 20:28:46 2007 => Scanning File c:\windows\system32\wzcsvc.dll
Sat Mar 17 20:28:46 2007 => Scanning File c:\windows\system32\WMI.dll
Sat Mar 17 20:28:46 2007 => Scanning File c:\windows\system32\ESENT.dll
Sat Mar 17 20:28:46 2007 => Scanning File C:\WINDOWS\System32\rastls.dll
Sat Mar 17 20:28:46 2007 => Scanning File C:\WINDOWS\system32\CRYPTUI.dll
Sat Mar 17 20:28:46 2007 => Scanning File C:\WINDOWS\system32\WININET.dll
Sat Mar 17 20:28:46 2007 => Scanning File C:\WINDOWS\system32\Normaliz.dll
Sat Mar 17 20:28:46 2007 => Scanning File C:\WINDOWS\system32\iertutil.dll
Sat Mar 17 20:28:46 2007 => Scanning File C:\WINDOWS\System32\RASAPI32.dll
Sat Mar 17 20:28:46 2007 => Scanning File C:\WINDOWS\System32\rasman.dll
Sat Mar 17 20:28:46 2007 => Scanning File C:\WINDOWS\System32\TAPI32.dll
Sat Mar 17 20:28:46 2007 => Scanning File C:\WINDOWS\System32\raschap.dll
Sat Mar 17 20:28:46 2007 => Scanning File c:\windows\system32\schedsvc.dll
Sat Mar 17 20:28:46 2007 => Scanning File C:\WINDOWS\System32\MSIDLE.DLL
Sat Mar 17 20:28:46 2007 => Scanning File c:\windows\system32\audiosrv.dll
Sat Mar 17 20:28:46 2007 => Scanning File c:\windows\system32\wkssvc.dll
Sat Mar 17 20:28:46 2007 => Scanning File c:\windows\system32\cryptsvc.dll
Sat Mar 17 20:28:46 2007 => Scanning File c:\windows\system32\certcli.dll
Sat Mar 17 20:28:46 2007 => Scanning File c:\windows\system32\netman.dll
Sat Mar 17 20:28:46 2007 => Scanning File c:\windows\system32\netshell.dll
Sat Mar 17 20:28:47 2007 => Scanning File c:\windows\system32\credui.dll
Sat Mar 17 20:28:47 2007 => Scanning File c:\windows\system32\WZCSAPI.DLL
Sat Mar 17 20:28:47 2007 => Scanning File c:\windows\system32\srvsvc.dll
Sat Mar 17 20:28:47 2007 => Scanning File c:\windows\pchealth\helpctr\binaries\pchsvc.dll
Sat Mar 17 20:28:47 2007 => Scanning File c:\windows\system32\es.dll
Sat Mar 17 20:28:47 2007 => Scanning File c:\windows\system32\ersvc.dll
Sat Mar 17 20:28:47 2007 => Scanning File c:\windows\system32\wuauserv.dll
Sat Mar 17 20:28:47 2007 => Scanning File c:\windows\system32\wbem\wmisvc.dll
Sat Mar 17 20:28:47 2007 => Scanning File C:\WINDOWS\system32\VSSAPI.DLL
Sat Mar 17 20:28:47 2007 => Scanning File C:\WINDOWS\system32\wuaueng.dll
Sat Mar 17 20:28:47 2007 => Scanning File C:\WINDOWS\System32\ADVPACK.dll
Sat Mar 17 20:28:47 2007 => Scanning File C:\WINDOWS\System32\SHFOLDER.dll
Sat Mar 17 20:28:47 2007 => Scanning File C:\WINDOWS\System32\WINHTTP.dll
Sat Mar 17 20:28:47 2007 => Scanning File C:\WINDOWS\System32\Cabinet.dll
Sat Mar 17 20:28:47 2007 => Scanning File C:\WINDOWS\System32\mspatcha.dll
Sat Mar 17 20:28:47 2007 => Scanning File c:\windows\system32\trkwks.dll
Sat Mar 17 20:28:47 2007 => Scanning File c:\windows\system32\srsvc.dll
Sat Mar 17 20:28:47 2007 => Scanning File c:\windows\system32\POWRPROF.dll
Sat Mar 17 20:28:47 2007 => Scanning File c:\windows\system32\seclogon.dll
Sat Mar 17 20:28:47 2007 => Scanning File c:\windows\system32\sens.dll
Sat Mar 17 20:28:47 2007 => Scanning File c:\windows\system32\wscsvc.dll
Sat Mar 17 20:28:47 2007 => Scanning File c:\windows\system32\msi.dll
Sat Mar 17 20:28:47 2007 => Scanning File c:\windows\system32\ipnathlp.dll
Sat Mar 17 20:28:47 2007 => Scanning File C:\WINDOWS\system32\comsvcs.dll
Sat Mar 17 20:28:47 2007 => Scanning File C:\WINDOWS\system32\colbact.DLL
Sat Mar 17 20:28:47 2007 => Scanning File C:\WINDOWS\system32\MTXCLU.DLL
Sat Mar 17 20:28:47 2007 => Scanning File C:\WINDOWS\system32\WSOCK32.dll
Sat Mar 17 20:28:47 2007 => Scanning File C:\WINDOWS\System32\CLUSAPI.DLL
Sat Mar 17 20:28:47 2007 => Scanning File C:\WINDOWS\System32\RESUTILS.DLL
Sat Mar 17 20:28:47 2007 => Scanning File c:\windows\system32\browser.dll
Sat Mar 17 20:28:47 2007 => Scanning File C:\WINDOWS\system32\wbem\wbemcomn.dll
Sat Mar 17 20:28:47 2007 => Scanning File C:\WINDOWS\System32\Wbem\wbemcore.dll
Sat Mar 17 20:28:48 2007 => Scanning File C:\WINDOWS\System32\Wbem\esscli.dll
Sat Mar 17 20:28:48 2007 => Scanning File C:\WINDOWS\System32\Wbem\FastProx.dll
Sat Mar 17 20:28:48 2007 => Scanning File C:\WINDOWS\system32\wbem\wbemsvc.dll
Sat Mar 17 20:28:48 2007 => Scanning File C:\WINDOWS\system32\wbem\wmiutils.dll
Sat Mar 17 20:28:48 2007 => Scanning File C:\WINDOWS\system32\wbem\repdrvfs.dll
Sat Mar 17 20:28:48 2007 => Scanning File C:\WINDOWS\system32\wbem\wmiprvsd.dll
Sat Mar 17 20:28:48 2007 => Scanning File C:\WINDOWS\system32\wbem\wbemess.dll
Sat Mar 17 20:28:48 2007 => Scanning File C:\WINDOWS\system32\wbem\ncprov.dll
Sat Mar 17 20:28:48 2007 => Scanning File C:\WINDOWS\system32\netcfgx.dll
Sat Mar 17 20:28:48 2007 => Scanning File c:\windows\system32\tapisrv.dll
Sat Mar 17 20:28:48 2007 => Scanning File c:\windows\system32\rasmans.dll
Sat Mar 17 20:28:48 2007 => Scanning File C:\WINDOWS\System32\rastapi.dll
Sat Mar 17 20:28:48 2007 => Scanning File C:\WINDOWS\System32\unimdm.tsp
Sat Mar 17 20:28:48 2007 => Scanning File C:\WINDOWS\System32\uniplat.dll
Sat Mar 17 20:28:48 2007 => Scanning File C:\WINDOWS\System32\kmddsp.tsp
Sat Mar 17 20:28:48 2007 => Scanning File C:\WINDOWS\System32\ndptsp.tsp
Sat Mar 17 20:28:48 2007 => Scanning File C:\WINDOWS\System32\ipconf.tsp
Sat Mar 17 20:28:48 2007 => Scanning File C:\WINDOWS\System32\h323.tsp
Sat Mar 17 20:28:48 2007 => Scanning File C:\WINDOWS\System32\hidphone.tsp
Sat Mar 17 20:28:48 2007 => Scanning File C:\WINDOWS\System32\HID.DLL
Sat Mar 17 20:28:48 2007 => Scanning File C:\WINDOWS\System32\rasppp.dll
Sat Mar 17 20:28:48 2007 => Scanning File C:\WINDOWS\System32\ntlsapi.dll
Sat Mar 17 20:28:48 2007 => Scanning File C:\WINDOWS\System32\RASDLG.dll
Sat Mar 17 20:28:48 2007 => Scanning File C:\WINDOWS\system32\upnp.dll
Sat Mar 17 20:28:48 2007 => Scanning File C:\WINDOWS\system32\SSDPAPI.dll
Sat Mar 17 20:28:48 2007 => Scanning File C:\WINDOWS\system32\msxml3.dll
Sat Mar 17 20:28:48 2007 => Scanning File C:\WINDOWS\system32\wups.dll
Sat Mar 17 20:28:48 2007 => Scanning File C:\WINDOWS\system32\licdll.dll
Sat Mar 17 20:28:48 2007 => Scanning File C:\WINDOWS\system32\urlmon.dll
Sat Mar 17 20:28:48 2007 => Scanning File c:\windows\system32\dnsrslvr.dll
Sat Mar 17 20:28:49 2007 => Scanning File c:\windows\system32\lmhsvc.dll
Sat Mar 17 20:28:49 2007 => Scanning File c:\windows\system32\webclnt.dll
Sat Mar 17 20:28:49 2007 => Scanning File c:\windows\system32\ssdpsrv.dll
Sat Mar 17 20:28:49 2007 => Scanning File C:\WINDOWS\system32\spoolsv.exe
Sat Mar 17 20:28:49 2007 => Scanning File C:\WINDOWS\system32\SPOOLSS.DLL
Sat Mar 17 20:28:49 2007 => Scanning File C:\WINDOWS\system32\localspl.dll
Sat Mar 17 20:28:49 2007 => Scanning File C:\WINDOWS\system32\cnbjmon.dll
Sat Mar 17 20:28:49 2007 => Scanning File C:\WINDOWS\system32\CNMLM83.DLL
Sat Mar 17 20:28:49 2007 => Scanning File C:\WINDOWS\system32\pjlmon.dll
Sat Mar 17 20:28:49 2007 => Scanning File C:\WINDOWS\system32\tcpmon.dll
Sat Mar 17 20:28:49 2007 => Scanning File C:\WINDOWS\system32\usbmon.dll
Sat Mar 17 20:28:49 2007 => Scanning File C:\WINDOWS\System32\spool\PRTPROCS\W32X86\CNMPD83.DLL
Sat Mar 17 20:28:49 2007 => Scanning File C:\WINDOWS\system32\win32spl.dll
Sat Mar 17 20:28:49 2007 => Scanning File C:\WINDOWS\system32\NETRAP.dll
Sat Mar 17 20:28:49 2007 => Scanning File C:\WINDOWS\system32\inetpp.dll
Sat Mar 17 20:28:49 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\aswUpdSv.exe
Sat Mar 17 20:28:49 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\aswCmnS.dll
Sat Mar 17 20:28:49 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\aswCmnOS.dll
Sat Mar 17 20:28:49 2007 => Scanning File C:\WINDOWS\system32\MSVCP71.dll
Sat Mar 17 20:28:49 2007 => Scanning File C:\WINDOWS\system32\MSVCR71.dll
Sat Mar 17 20:28:49 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\aswCmnB.dll
Sat Mar 17 20:28:49 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\ashServ.exe
Sat Mar 17 20:28:49 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\aswAux.dll
Sat Mar 17 20:28:49 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\aswEngin.dll
Sat Mar 17 20:28:49 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\aswScan.dll
Sat Mar 17 20:28:49 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\ashBase.dll
Sat Mar 17 20:28:49 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\ashTask.dll
Sat Mar 17 20:28:49 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\aswInteg.dll
Sat Mar 17 20:28:49 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\aswIdle.dll
Sat Mar 17 20:28:49 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\Aavm4h.dll
Sat Mar 17 20:28:49 2007 => Scanning File C:\WINDOWS\system32\dbghelp.dll
Sat Mar 17 20:28:49 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\Czech\Base.dll
Sat Mar 17 20:28:49 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\UNACEV2.DLL
Sat Mar 17 20:28:49 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\AhResMai.dll
Sat Mar 17 20:28:49 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\ahResMes.dll
Sat Mar 17 20:28:49 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\AhResNS.dll
Sat Mar 17 20:28:49 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\AhResOut.dll
Sat Mar 17 20:28:49 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\ahResP2P.dll
Sat Mar 17 20:28:49 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\AhResStd.dll
Sat Mar 17 20:28:49 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\AhResWS.dll
Sat Mar 17 20:28:49 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\ashSSqlt.dll
Sat Mar 17 20:28:50 2007 => Scanning File C:\WINDOWS\system32\perfos.dll
Sat Mar 17 20:28:50 2007 => Scanning File C:\WINDOWS\system32\nvsvc32.exe
Sat Mar 17 20:28:50 2007 => Scanning File C:\WINDOWS\system32\nvapi.dll
Sat Mar 17 20:28:50 2007 => Scanning File c:\windows\system32\wiaservc.dll
Sat Mar 17 20:28:50 2007 => Scanning File c:\windows\system32\CFGMGR32.dll
Sat Mar 17 20:28:50 2007 => Scanning File c:\windows\system32\mscms.dll
Sat Mar 17 20:28:50 2007 => Scanning File C:\WINDOWS\system32\actxprxy.dll
Sat Mar 17 20:28:50 2007 => Scanning File C:\WINDOWS\system32\wdfmgr.exe
Sat Mar 17 20:28:50 2007 => Scanning File C:\WINDOWS\Explorer.EXE
Sat Mar 17 20:28:50 2007 => Scanning File C:\WINDOWS\system32\BROWSEUI.dll
Sat Mar 17 20:28:50 2007 => Scanning File C:\WINDOWS\system32\SHDOCVW.dll
Sat Mar 17 20:28:50 2007 => Scanning File C:\WINDOWS\system32\themeui.dll
Sat Mar 17 20:28:50 2007 => Scanning File C:\WINDOWS\system32\MSIMG32.dll
Sat Mar 17 20:28:50 2007 => Scanning File C:\WINDOWS\system32\msutb.dll
Sat Mar 17 20:28:50 2007 => Scanning File C:\WINDOWS\system32\MSCTF.dll
Sat Mar 17 20:28:50 2007 => Scanning File C:\PROGRA~1\WINDOW~2\wmpband.dll
Sat Mar 17 20:28:50 2007 => Scanning File C:\WINDOWS\system32\LINKINFO.dll
Sat Mar 17 20:28:50 2007 => Scanning File C:\WINDOWS\system32\ntshrui.dll
Sat Mar 17 20:28:50 2007 => Scanning File C:\WINDOWS\system32\ieframe.dll
Sat Mar 17 20:28:50 2007 => Scanning File C:\WINDOWS\system32\MLANG.dll
Sat Mar 17 20:28:50 2007 => Scanning File C:\PROGRA~1\ScanSoft\OMNIPA~1.0\OPHOOK~1.DLL
Sat Mar 17 20:28:50 2007 => Scanning File C:\WINDOWS\system32\webcheck.dll
Sat Mar 17 20:28:51 2007 => Scanning File C:\WINDOWS\system32\stobject.dll
Sat Mar 17 20:28:51 2007 => Scanning File C:\WINDOWS\system32\BatMeter.dll
Sat Mar 17 20:28:51 2007 => Scanning File C:\WINDOWS\System32\drprov.dll
Sat Mar 17 20:28:51 2007 => Scanning File C:\WINDOWS\System32\ntlanman.dll
Sat Mar 17 20:28:51 2007 => Scanning File C:\WINDOWS\System32\NETUI0.dll
Sat Mar 17 20:28:51 2007 => Scanning File C:\WINDOWS\System32\NETUI1.dll
Sat Mar 17 20:28:51 2007 => Scanning File C:\WINDOWS\System32\davclnt.dll
Sat Mar 17 20:28:51 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\ashMaiSv.exe
Sat Mar 17 20:28:51 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\ashUInt.dll
Sat Mar 17 20:28:51 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\XT1922.dll
Sat Mar 17 20:28:51 2007 => Scanning File C:\WINDOWS\system32\MFC71.DLL
Sat Mar 17 20:28:51 2007 => Scanning File C:\WINDOWS\system32\RICHED20.DLL
Sat Mar 17 20:28:51 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\Czech\Lang.dll
Sat Mar 17 20:28:51 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\Czech\langmai.dll
Sat Mar 17 20:28:51 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\ashWebSv.exe
Sat Mar 17 20:28:51 2007 => Scanning File C:\WINDOWS\system32\security.dll
Sat Mar 17 20:28:51 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\ashWsFtr.dll
Sat Mar 17 20:28:51 2007 => Scanning File C:\WINDOWS\system32\OLEACC.dll
Sat Mar 17 20:28:51 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\AhResWs.dll
Sat Mar 17 20:28:51 2007 => Scanning File C:\WINDOWS\System32\alg.exe
Sat Mar 17 20:28:51 2007 => Scanning File C:\WINDOWS\RTHDCPL.EXE
Sat Mar 17 20:28:52 2007 => Scanning File C:\WINDOWS\system32\DSOUND.DLL
Sat Mar 17 20:28:52 2007 => Scanning File C:\WINDOWS\system32\HHCTRL.OCX
Sat Mar 17 20:28:52 2007 => Scanning File C:\WINDOWS\system32\mui\0005\HHCTRLui.dll
Sat Mar 17 20:28:52 2007 => Scanning File C:\WINDOWS\system32\KsUser.dll
Sat Mar 17 20:28:52 2007 => Scanning File C:\WINDOWS\system32\RUNDLL32.EXE
Sat Mar 17 20:28:52 2007 => Scanning File C:\WINDOWS\system32\NvMcTray.dll
Sat Mar 17 20:28:52 2007 => Scanning File C:\PROGRA~1\ScanSoft\OMNIPA~1.0\OPWARE~1.EXE
Sat Mar 17 20:28:52 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
Sat Mar 17 20:28:52 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\aswCmnOS.dll
Sat Mar 17 20:28:52 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\ashBase.dll
Sat Mar 17 20:28:52 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\aswCmnB.dll
Sat Mar 17 20:28:52 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\aswCmnS.dll
Sat Mar 17 20:28:52 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\ashTask.dll
Sat Mar 17 20:28:52 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\aswAux.dll
Sat Mar 17 20:28:52 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\Aavm4h.dll
Sat Mar 17 20:28:52 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\AavmRpch.dll
Sat Mar 17 20:28:52 2007 => Scanning File c:\PROGRA~1\ALWILS~1\avast4\ahruimai.dll
Sat Mar 17 20:28:52 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\ashUInt.dll
Sat Mar 17 20:28:52 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\XT1922.dll
Sat Mar 17 20:28:52 2007 => Scanning File c:\PROGRA~1\ALWILS~1\avast4\ahruimes.dll
Sat Mar 17 20:28:52 2007 => Scanning File c:\PROGRA~1\ALWILS~1\avast4\ahruins.dll
Sat Mar 17 20:28:52 2007 => Scanning File c:\PROGRA~1\ALWILS~1\avast4\ahruiout.dll
Sat Mar 17 20:28:52 2007 => Scanning File C:\WINDOWS\system32\MAPI32.dll
Sat Mar 17 20:28:52 2007 => Scanning File c:\PROGRA~1\ALWILS~1\avast4\ahruip2p.dll
Sat Mar 17 20:28:52 2007 => Scanning File c:\PROGRA~1\ALWILS~1\avast4\ahruistd.dll
Sat Mar 17 20:28:52 2007 => Scanning File c:\PROGRA~1\ALWILS~1\avast4\ahruiws.dll
Sat Mar 17 20:28:52 2007 => Scanning File C:\WINDOWS\system32\ctfmon.exe
Sat Mar 17 20:28:52 2007 => Scanning File C:\PROGRA~1\MESSEN~1\msmsgs.exe
Sat Mar 17 20:28:52 2007 => Scanning File C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.2180_x-ww_522f9f82\gdiplus.dll
Sat Mar 17 20:28:52 2007 => Scanning File C:\WINDOWS\system32\XPOB2RES.DLL
Sat Mar 17 20:28:52 2007 => Scanning File C:\PROGRA~1\Skype\Phone\Skype.exe
Sat Mar 17 20:28:53 2007 => Scanning File C:\WINDOWS\system32\olepro32.dll
Sat Mar 17 20:28:53 2007 => Scanning File C:\PROGRA~1\COMMON~1\System\wab32.dll
Sat Mar 17 20:28:53 2007 => Scanning File C:\WINDOWS\system32\MSOERT2.dll
Sat Mar 17 20:28:53 2007 => Scanning File C:\PROGRA~1\COMMON~1\System\wab32res.dll
Sat Mar 17 20:28:53 2007 => Scanning File C:\WINDOWS\system32\dxdiagn.dll
Sat Mar 17 20:28:53 2007 => Scanning File C:\WINDOWS\system32\wbem\wbemprox.dll
Sat Mar 17 20:28:53 2007 => Scanning File C:\WINDOWS\system32\devenum.dll
Sat Mar 17 20:28:53 2007 => Scanning File C:\WINDOWS\system32\msdmo.dll
Sat Mar 17 20:28:53 2007 => Scanning File C:\WINDOWS\system32\sensapi.dll
Sat Mar 17 20:28:53 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\soffice.exe
Sat Mar 17 20:28:53 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\MSVCR71.dll
Sat Mar 17 20:28:53 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\uwinapi.dll
Sat Mar 17 20:28:53 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\soffice.BIN
Sat Mar 17 20:28:53 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\vcl680mi.dll
Sat Mar 17 20:28:53 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\sot680mi.dll
Sat Mar 17 20:28:53 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\tl680mi.dll
Sat Mar 17 20:28:53 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\cppu3.dll
Sat Mar 17 20:28:53 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\sal3.dll
Sat Mar 17 20:28:54 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\STLPOR~1.DLL
Sat Mar 17 20:28:54 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\MSVCP71.dll
Sat Mar 17 20:28:54 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\vos3MSC.dll
Sat Mar 17 20:28:54 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\BASEGF~1.DLL
Sat Mar 17 20:28:54 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\utl680mi.dll
Sat Mar 17 20:28:54 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\SALHEL~1.DLL
Sat Mar 17 20:28:54 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\COMPHE~1.DLL
Sat Mar 17 20:28:54 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\CPPUHE~1.DLL
Sat Mar 17 20:28:54 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\UCBHEL~1.DLL
Sat Mar 17 20:28:54 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\icuuc26.dll
Sat Mar 17 20:28:54 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\icudt26l.dll
Sat Mar 17 20:28:54 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\svl680mi.dll
Sat Mar 17 20:28:54 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\svt680mi.dll
Sat Mar 17 20:28:54 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\tk680mi.dll
Sat Mar 17 20:28:54 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\jvmfwk3.dll
Sat Mar 17 20:28:54 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\libxml2.dll
Sat Mar 17 20:28:54 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\SERVIC~1.DLL
Sat Mar 17 20:28:54 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\SHLIBL~1.DLL
Sat Mar 17 20:28:54 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\SIMPLE~1.DLL
Sat Mar 17 20:28:54 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\NESTED~1.DLL
Sat Mar 17 20:28:54 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\TYPEMG~1.DLL
Sat Mar 17 20:28:54 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\IMPLRE~1.DLL
Sat Mar 17 20:28:54 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\SECURI~1.DLL
Sat Mar 17 20:28:54 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\reg3.dll
Sat Mar 17 20:28:55 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\store3.dll
Sat Mar 17 20:28:55 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\REGTYP~1.DLL
Sat Mar 17 20:28:55 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\CONFIG~1.DLL
Sat Mar 17 20:28:55 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\TYPECO~1.DLL
Sat Mar 17 20:28:55 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\SYSMGR~1.DLL
Sat Mar 17 20:28:55 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\SAXUNO~1.DLL
Sat Mar 17 20:28:55 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\LOAB4D~1.DLL
Sat Mar 17 20:28:55 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\BEHELP~1.DLL
Sat Mar 17 20:28:55 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\URIPRO~1.DLL
Sat Mar 17 20:28:55 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\ucb1.dll
Sat Mar 17 20:28:55 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\fwl680mi.dll
Sat Mar 17 20:28:55 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\fwi680mi.dll
Sat Mar 17 20:28:55 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\ucpfile1.dll
Sat Mar 17 20:28:55 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\sfx680mi.dll
Sat Mar 17 20:28:55 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\fwe680mi.dll
Sat Mar 17 20:28:55 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\sb680mi.dll
Sat Mar 17 20:28:55 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\xcr680mi.dll
Sat Mar 17 20:28:55 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\j680mi_g.dll
Sat Mar 17 20:28:55 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\JVMACC~1.DLL
Sat Mar 17 20:28:55 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\fwk680mi.dll
Sat Mar 17 20:28:55 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\msci_uno.dll
Sat Mar 17 20:28:55 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\spl680mi.dll
Sat Mar 17 20:28:55 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\OLEAUT~1.DLL
Sat Mar 17 20:28:55 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\EMSER6~1.DLL
Sat Mar 17 20:28:55 2007 => Scanning File C:\PROGRA~1\Skype\PLUGIN~1\SkypePM.exe
Sat Mar 17 20:28:56 2007 => Scanning File C:\PROGRA~1\Skype\PLUGIN~1\EZPMUT~1.DLL
Sat Mar 17 20:28:56 2007 => Scanning File C:\PROGRA~1\ICQLite\ICQLite.exe
Sat Mar 17 20:28:56 2007 => Scanning File C:\WINDOWS\system32\MFC42.DLL
Sat Mar 17 20:28:56 2007 => Scanning File C:\PROGRA~1\ICQLite\ICQRT.dll
Sat Mar 17 20:28:56 2007 => Scanning File C:\PROGRA~1\ICQLite\LITESK~1.DLL
Sat Mar 17 20:28:56 2007 => Scanning File C:\PROGRA~1\ICQLite\ICQLSRP.dll
Sat Mar 17 20:28:56 2007 => Scanning File C:\PROGRA~1\ICQLite\EMOEXT~1.DLL
Sat Mar 17 20:28:56 2007 => Scanning File C:\WINDOWS\system32\MFC42LOC.DLL
Sat Mar 17 20:28:56 2007 => Scanning File C:\WINDOWS\system32\Icmp.dll
Sat Mar 17 20:28:56 2007 => Scanning File C:\PROGRA~1\ICQLite\LiteRes.dll
Sat Mar 17 20:28:56 2007 => Scanning File C:\PROGRA~1\ICQLite\MISB.dll
Sat Mar 17 20:28:56 2007 => Scanning File C:\PROGRA~1\ICQLite\actskin4.ocx
Sat Mar 17 20:28:56 2007 => Scanning File C:\PROGRA~1\ICQLite\LiteUtil.dll
Sat Mar 17 20:28:57 2007 => Scanning File C:\WINDOWS\system32\RICHED32.DLL
Sat Mar 17 20:28:57 2007 => Scanning File C:\WINDOWS\system32\asycfilt.dll
Sat Mar 17 20:28:57 2007 => Scanning File C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx
Sat Mar 17 20:28:57 2007 => Scanning File C:\WINDOWS\system32\mshtml.dll
Sat Mar 17 20:28:57 2007 => Scanning File C:\WINDOWS\system32\msls31.dll
Sat Mar 17 20:28:57 2007 => Scanning File C:\WINDOWS\system32\msimtf.dll
Sat Mar 17 20:28:57 2007 => Scanning File C:\WINDOWS\system32\jscript.dll
Sat Mar 17 20:28:57 2007 => Scanning File c:\WINDOWS\system32\msxml4.dll
Sat Mar 17 20:28:57 2007 => Scanning File C:\WINDOWS\system32\vbscript.dll
Sat Mar 17 20:28:57 2007 => Scanning File C:\WINDOWS\system32\Macromed\Common\SwSupport.dll
Sat Mar 17 20:28:57 2007 => Scanning File C:\WINDOWS\system32\ddrawex.dll
Sat Mar 17 20:28:57 2007 => Scanning File C:\WINDOWS\system32\DDRAW.dll
Sat Mar 17 20:28:57 2007 => Scanning File C:\WINDOWS\system32\DCIMAN32.dll
Sat Mar 17 20:28:57 2007 => Scanning File C:\WINDOWS\system32\USP10.dll
Sat Mar 17 20:28:57 2007 => Scanning File C:\WINDOWS\system32\ImgUtil.dll
Sat Mar 17 20:28:57 2007 => Scanning File C:\WINDOWS\system32\iepeers.dll
Sat Mar 17 20:28:57 2007 => Scanning File C:\PROGRA~1\INTERN~1\iexplore.exe
Sat Mar 17 20:28:57 2007 => Scanning File C:\WINDOWS\system32\IEUI.dll
Sat Mar 17 20:28:57 2007 => Scanning File C:\WINDOWS\system32\xmllite.dll
Sat Mar 17 20:28:57 2007 => Scanning File C:\PROGRA~1\INTERN~1\ieproxy.dll
Sat Mar 17 20:28:57 2007 => Scanning File C:\PROGRA~1\ICQTOO~1\toolbaru.dll
Sat Mar 17 20:28:57 2007 => Scanning File C:\PROGRA~1\Adobe\ACROBA~1.0CE\Reader\ActiveX\ACROIE~1.DLL
Sat Mar 17 20:28:57 2007 => Scanning File C:\PROGRA~1\Canon\EASY-W~1\EWPBRO~1.DLL
Sat Mar 17 20:28:57 2007 => Scanning File C:\PROGRA~1\Canon\EASY-W~1\EWPCore.dll
Sat Mar 17 20:28:57 2007 => Scanning File C:\PROGRA~1\Java\JRE15~1.0_0\bin\ssv.dll
Sat Mar 17 20:28:58 2007 => Scanning File c:\PROGRA~1\google\GOOGLE~2.DLL
Sat Mar 17 20:28:58 2007 => Scanning File C:\WINDOWS\system32\ieapfltr.dll
Sat Mar 17 20:28:58 2007 => Scanning File C:\WINDOWS\system32\mshtmled.dll
Sat Mar 17 20:28:58 2007 => Scanning File C:\WINDOWS\system32\Dxtrans.dll
Sat Mar 17 20:28:58 2007 => Scanning File C:\WINDOWS\system32\Dxtmsft.dll
Sat Mar 17 20:28:58 2007 => Scanning File C:\WINDOWS\system32\msfeeds.dll
Sat Mar 17 20:28:58 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\shlxthdl.dll
Sat Mar 17 20:28:58 2007 => Scanning File C:\WINDOWS\system32\pngfilt.dll
Sat Mar 17 20:28:58 2007 => Scanning File C:\WINDOWS\system32\corpol.dll
Sat Mar 17 20:28:58 2007 => Scanning File C:\WINDOWS\system32\cryptnet.dll
Sat Mar 17 20:28:58 2007 => Scanning File C:\DOCUME~1\Lenka\LOCALS~1\Temp\mexe.com
Sat Mar 17 20:28:58 2007 => Scanning File C:\DOCUME~1\Lenka\LOCALS~1\Temp\msvl64.dll
Sat Mar 17 20:28:58 2007 => Scanning File C:\DOCUME~1\Lenka\LOCALS~1\Temp\kave.dll
Sat Mar 17 20:28:58 2007 => Scanning File C:\WINDOWS\system32\VDMDBG.DLL
Sat Mar 17 20:28:58 2007 => Scanning File C:\DOCUME~1\Lenka\LOCALS~1\Temp\ScanningProcess.exe
Sat Mar 17 20:28:58 2007 => Scanning File C:\DOCUME~1\Lenka\LOCALS~1\Temp\prloader.dll
Sat Mar 17 20:28:58 2007 => Scanning File C:\DOCUME~1\Lenka\LOCALS~1\Temp\prkernel.ppl
Sat Mar 17 20:28:58 2007 => Scanning File c:\docume~1\lenka\locals~1\temp\avpmgr.ppl
Sat Mar 17 20:28:58 2007 => Scanning File c:\docume~1\lenka\locals~1\temp\wdiskio.ppl
Sat Mar 17 20:28:58 2007 => Scanning File c:\docume~1\lenka\locals~1\temp\nfio.ppl
Sat Mar 17 20:28:58 2007 => Scanning File c:\docume~1\lenka\locals~1\temp\avlib.ppl
Sat Mar 17 20:28:58 2007 => Scanning File c:\docume~1\lenka\locals~1\temp\dtreg.ppl
Sat Mar 17 20:28:58 2007 => Scanning File c:\docume~1\lenka\locals~1\temp\prutil.ppl
Sat Mar 17 20:28:58 2007 => Scanning File c:\docume~1\lenka\locals~1\temp\avp1.ppl
Sat Mar 17 20:28:58 2007 => Scanning File c:\docume~1\lenka\locals~1\temp\l_llio.ppl
Sat Mar 17 20:28:58 2007 => Scanning File c:\docume~1\lenka\locals~1\temp\ichk2.ppl
Sat Mar 17 20:28:58 2007 => Scanning File c:\docume~1\lenka\locals~1\temp\sfdb.ppl
Sat Mar 17 20:28:58 2007 => Scanning File c:\docume~1\lenka\locals~1\temp\icheckersa.ppl
Sat Mar 17 20:28:58 2007 => Scanning File c:\docume~1\lenka\locals~1\temp\hashmd5.ppl
Sat Mar 17 20:28:58 2007 => Scanning File c:\docume~1\lenka\locals~1\temp\hashcont.ppl
Sat Mar 17 20:28:58 2007 => Scanning File c:\docume~1\lenka\locals~1\temp\hccmp.ppl
Sat Mar 17 20:28:58 2007 => Scanning File c:\docume~1\lenka\locals~1\temp\iwgen.ppl

Sat Mar 17 20:28:58 2007 => ***** Scanning Registry Files *****

Sat Mar 17 20:28:58 2007 => Scanning HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
Sat Mar 17 20:28:58 2007 => Scanning File C:\WINDOWS\system32\SHELL32.dll
Sat Mar 17 20:28:58 2007 => Scanning File C:\WINDOWS\system32\SHELL32.dll
Sat Mar 17 20:28:58 2007 => Scanning File C:\WINDOWS\system32\webcheck.dll
Sat Mar 17 20:28:58 2007 => Scanning File C:\WINDOWS\system32\stobject.dll

Sat Mar 17 20:28:58 2007 => Scanning HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad

Sat Mar 17 20:28:58 2007 => Scanning HKLM\SOFTWARE\Microsoft\Internet Explorer\Plugins\Extension

Sat Mar 17 20:28:58 2007 => Scanning HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar
Sat Mar 17 20:28:58 2007 => Scanning File c:\PROGRA~1\google\GOOGLE~2.DLL
Sat Mar 17 20:28:58 2007 => Scanning File C:\PROGRA~1\Canon\EASY-W~1\Toolband.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\PROGRA~1\ICQTOO~1\toolbaru.dll

Sat Mar 17 20:28:59 2007 => Scanning HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects
Sat Mar 17 20:28:59 2007 => {055FD26D-3A88-4e15-963D-DC8493744B1D} = C:\Program Files\ICQToolbar\toolbaru.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\PROGRA~1\ICQTOO~1\toolbaru.dll
Sat Mar 17 20:28:59 2007 => {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} = C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\PROGRA~1\Adobe\ACROBA~1.0CE\Reader\ActiveX\ACROIE~1.DLL
Sat Mar 17 20:28:59 2007 => {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} = C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\PROGRA~1\Canon\EASY-W~1\EWPBRO~1.DLL
Sat Mar 17 20:28:59 2007 => {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} = C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\PROGRA~1\Java\JRE15~1.0_0\bin\ssv.dll
Sat Mar 17 20:28:59 2007 => {AA58ED58-01DD-4d91-8333-CF10577473F7} = c:\program files\google\googletoolbar2.dll
Sat Mar 17 20:28:59 2007 => Scanning File c:\PROGRA~1\google\GOOGLE~2.DLL

Sat Mar 17 20:28:59 2007 => Scanning HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\browseui.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\browseui.dll

Sat Mar 17 20:28:59 2007 => Scanning HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\mmsys.cpl
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\icmui.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\rshx32.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\docprop.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\ntshrui.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\themeui.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\deskadp.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\deskmon.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\dssec.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\SlayerXP.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\shscrap.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\diskcopy.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\ntlanui2.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\System32\icmui.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\icmui.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\printui.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\dskquoui.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\syncui.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\hticons.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\fontext.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\icmui.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\rshx32.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\ntshrui.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\deskperf.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\cryptext.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\cryptext.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\NETSHELL.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\NETSHELL.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\wiashext.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\wiashext.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\wiashext.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\wiashext.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\wiashext.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\remotepg.dll
Sat Mar 17 20:28:59 2007 => Scanning File C:\WINDOWS\system32\wshext.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\PROGRA~1\COMMON~1\System\OLEDB~1\oledb32.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\mstask.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\mstask.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\mstask.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\shdocvw.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\wuaucpl.cpl
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\shdocvw.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\shdocvw.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\shdocvw.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\shdocvw.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\shdocvw.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\shdocvw.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\shdocvw.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\shdocvw.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\twext.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\twext.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\shmedia.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\shmedia.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\shmedia.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\shmedia.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\shmedia.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\shmedia.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\browseui.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\browseui.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\browseui.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\browseui.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\browseui.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\browseui.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\ieframe.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\browseui.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\browseui.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\browseui.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\browseui.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\browseui.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\browseui.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\browseui.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\browseui.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\browseui.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\browseui.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\browseui.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\browseui.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\browseui.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\browseui.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\browseui.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\browseui.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\browseui.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\browseui.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\browseui.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\browseui.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\shdocvw.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\shdocvw.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\ieframe.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\shdocvw.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\ieframe.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\ieframe.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\ieframe.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\ieframe.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\ieframe.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\ieframe.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\shdocvw.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\shdocvw.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\shdocvw.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\shdocvw.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\ieframe.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\ieframe.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\shdocvw.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\sendmail.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\sendmail.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\occache.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\webcheck.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\webcheck.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\webcheck.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\webcheck.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\webcheck.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\webcheck.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\webcheck.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\webcheck.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\webcheck.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\webcheck.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\appwiz.cpl
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\appwiz.cpl
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\appwiz.cpl
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\shimgvw.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\shimgvw.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\shimgvw.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\shimgvw.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\shimgvw.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\shimgvw.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\netplwiz.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\netplwiz.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\netplwiz.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\netplwiz.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\zipfldr.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\zipfldr.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\zipfldr.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\extmgr.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\msieftp.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\docprop2.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\docprop2.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\docprop2.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\docprop2.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\docprop2.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\docprop2.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\dsquery.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\dsquery.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\dsquery.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\dsquery.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\dsuiext.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\dsuiext.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\mydocs.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\mydocs.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\mydocs.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\System32\cscui.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\System32\cscui.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\System32\cscui.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\msagent\agentpsh.dll
Sat Mar 17 20:29:00 2007 => Scanning File C:\WINDOWS\system32\dfsshlex.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\photowiz.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\System32\mmcshext.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\cabview.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\PROGRA~1\OUTLOO~1\wabfind.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\wmpshell.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\wmpshell.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\wmpshell.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\nvcpl.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\nvcpl.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\nvshell.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\nvshell.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\nvshell.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\shlxthdl.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\shlxthdl.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\shlxthdl.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\PROGRA~1\OPENOF~1.0\program\shlxthdl.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\browseui.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\ieframe.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\ieframe.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\ieframe.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\ieframe.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\ieframe.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\ieframe.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\ieframe.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\ieframe.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\ieframe.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\ieframe.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\ieframe.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\ieframe.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\ieframe.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\ieframe.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\ieframe.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\ieframe.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\ieframe.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\ieframe.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\ieframe.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\ieframe.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\ieframe.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\ieframe.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\PROGRA~1\ICQLite\ICQLIT~1.DLL
Sat Mar 17 20:29:01 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\ashShell.dll

Sat Mar 17 20:29:01 2007 => Scanning HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows

Sat Mar 17 20:29:01 2007 => Scanning HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\Explorer.exe
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\userinit.exe
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\dskquota.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\iedkcs32.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\scecli.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\iedkcs32.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\scecli.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\System32\cscui.dll
Sat Mar 17 20:29:01 2007 => Invalid Entry DllName = appmgmts.dll (in key SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}). Deleting Registry Key {c6dc5466-785a-11d2-84d0-00c04fb169f7}...
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\crypt32.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\cryptnet.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\cscdll.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\wlnotify.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\wlnotify.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\sclgntfy.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\WlNotify.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\wlnotify.dll
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\wlnotify.dll

Sat Mar 17 20:29:01 2007 => Scanning HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

Sat Mar 17 20:29:01 2007 => Scanning HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System

Sat Mar 17 20:29:01 2007 => Scanning HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows

Sat Mar 17 20:29:01 2007 => Scanning HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AEDEBUG
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\drwtsn32.exe

Sat Mar 17 20:29:01 2007 => Scanning HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
Sat Mar 17 20:29:01 2007 => Scanning File C:\WINDOWS\system32\ntsd.exe

Sat Mar 17 20:29:02 2007 => Scanning HKCU\Control Panel\Desktop
Sat Mar 17 20:29:02 2007 => Scanning File C:\WINDOWS\system32\ssstars.scr

Sat Mar 17 20:29:02 2007 => Scanning HKLM\SYSTEM\CurrentControlSet\Control\WOW
Sat Mar 17 20:29:02 2007 => Scanning File C:\WINDOWS\system32\ntvdm.exe
Sat Mar 17 20:29:02 2007 => Scanning File C:\WINDOWS\system32\ntvdm.exe

Sat Mar 17 20:29:02 2007 => Scanning HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components
Sat Mar 17 20:29:02 2007 => Scanning File C:\WINDOWS\system32\ieudinit.exe
Sat Mar 17 20:29:02 2007 => Scanning File C:\WINDOWS\inf\unregmp2.exe
Sat Mar 17 20:29:02 2007 => Scanning File C:\WINDOWS\system32\ie4uinit.exe
Sat Mar 17 20:29:02 2007 => Scanning File C:\WINDOWS\system32\RunDLL32.exe
Sat Mar 17 20:29:02 2007 => Scanning File C:\WINDOWS\system32\RunDLL32.exe
Sat Mar 17 20:29:02 2007 => Scanning File C:\WINDOWS\system32\shmgrate.exe
Sat Mar 17 20:29:02 2007 => Scanning File C:\WINDOWS\system32\regsvr32.exe
Sat Mar 17 20:29:02 2007 => Scanning File C:\PROGRA~1\OUTLOO~1\setup50.exe
Sat Mar 17 20:29:02 2007 => Scanning File C:\WINDOWS\system32\rundll32.exe
Sat Mar 17 20:29:02 2007 => Scanning File C:\WINDOWS\system32\rundll32.exe
Sat Mar 17 20:29:02 2007 => Scanning File C:\WINDOWS\system32\rundll32.exe
Sat Mar 17 20:29:02 2007 => Scanning File C:\PROGRA~1\OUTLOO~1\setup50.exe
Sat Mar 17 20:29:02 2007 => Scanning File C:\WINDOWS\system32\regsvr32.exe
Sat Mar 17 20:29:02 2007 => Scanning File C:\WINDOWS\system32\ie4uinit.exe

Sat Mar 17 20:29:02 2007 => Scanning HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run

Sat Mar 17 20:29:02 2007 => Scanning HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run

Sat Mar 17 20:29:02 2007 => Scanning HKLM\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Run

Sat Mar 17 20:29:02 2007 => Scanning HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Run

Sat Mar 17 20:29:02 2007 => Scanning HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Sat Mar 17 20:29:02 2007 => Scanning File C:\WINDOWS\RTHDCPL.EXE
Sat Mar 17 20:29:02 2007 => Scanning File C:\WINDOWS\SkyTel.EXE
Sat Mar 17 20:29:02 2007 => Scanning File C:\WINDOWS\system32\RUNDLL32.EXE
Sat Mar 17 20:29:02 2007 => Scanning File C:\WINDOWS\system32\nwiz.exe
Sat Mar 17 20:29:02 2007 => Scanning File C:\WINDOWS\system32\RUNDLL32.EXE
Sat Mar 17 20:29:02 2007 => Scanning File C:\PROGRA~1\COMMON~1\SCANSO~1\SSBKGD~1\SSBKGD~1.EXE
Sat Mar 17 20:29:02 2007 => Scanning File C:\PROGRA~1\ScanSoft\OMNIPA~1.0\OPWARE~1.EXE
Sat Mar 17 20:29:02 2007 => Scanning File C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

Sat Mar 17 20:29:02 2007 => Scanning HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce

Sat Mar 17 20:29:02 2007 => Scanning HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx

Sat Mar 17 20:29:02 2007 => Scanning HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices

Sat Mar 17 20:29:02 2007 => Scanning HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce

Sat Mar 17 20:29:02 2007 => Scanning HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Sat Mar 17 20:29:02 2007 => Scanning File C:\WINDOWS\system32\ctfmon.exe
Sat Mar 17 20:29:02 2007 => Scanning File C:\PROGRA~1\MESSEN~1\msmsgs.exe
Sat Mar 17 20:29:02 2007 => Scanning File C:\PROGRA~1\Skype\Phone\Skype.exe
Sat Mar 17 20:29:02 2007 => Scanning File C:\PROGRA~1\Ahead\NEROBA~1\nbj.exe

Sat Mar 17 20:29:03 2007 => Scanning HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Sat Mar 17 20:29:03 2007 => Scanning File C:\PROGRA~1\ICQLite\ICQLite.exe

Sat Mar 17 20:29:03 2007 => Scanning HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx

Sat Mar 17 20:29:03 2007 => Scanning HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices

Sat Mar 17 20:29:03 2007 => Scanning HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\Setup

Sat Mar 17 20:29:03 2007 => Scanning HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Sat Mar 17 20:29:03 2007 => Scanning File C:\WINDOWS\system32\CTFMON.EXE
Sat Mar 17 20:29:03 2007 => ERROR!!! Invalid Entry adirka = C:\WINDOWS\system32\adirka.exe (in key .DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run). Removing it.

Sat Mar 17 20:29:03 2007 => Scanning HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\


Zpět na “Viry, antiviry, firewally…”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 5 hostů