Logfile of random's system information tool 1.06 (written by random/random) Run by ASUS at 2009-11-25 18:34:46 Microsoft® Windows Vista™ Home Premium Service Pack 2 System drive C: has 24 GB (43%) free of 57 GB Total RAM: 1790 MB (40% free) Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 18:34:56, on 25.11.2009 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v7.00 (7.00.6002.18005) Boot mode: Normal Running processes: C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Program Files\ASUS\ASUS Live Update\ALU.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe C:\Windows\RtHDVCpl.exe C:\Program Files\ASUS\ATK Media\DMedia.exe C:\Program Files\Apoint2K\Apoint.exe C:\Program Files\PowerForPhone\PowerForPhone.exe C:\Windows\ASScrPro.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Alwil Software\Avast4\ashDisp.exe C:\Program Files\Companion Suite IH\MFServices.exe C:\Program Files\Companion Suite IH\MFPrintServer.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\DAEMON Tools Lite\daemon.exe C:\Program Files\uTorrent\uTorrent.exe C:\Program Files\ICQ6.5\ICQ.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Apoint2K\ApMsgFwd.exe C:\Program Files\Apoint2K\HidFind.exe C:\Program Files\Apoint2K\Apntex.exe C:\Program Files\Apoint2K\Apvfb.exe C:\Program Files\Windows Live\Contacts\wlcomm.exe C:\Program Files\Windows Media Player\wmplayer.exe C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\wuauclt.exe C:\Users\Public\Downloads\RSIT.exe C:\Program Files\Trend Micro\HijackThis\ASUS.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.asus.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.asus.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: (no name) - - (no file) R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll O1 - Hosts: ::1 localhost O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [Skytel] Skytel.exe O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe O4 - HKLM\..\Run: [PowerForPhone] C:\Program Files\PowerForPhone\PowerForPhone.exe O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [LiveUpdate] C:\Program Files\Byteswarm\LiveUpdate\LiveUpdate.exe O4 - HKLM\..\Run: [MFServices] "C:\Program Files\Companion Suite IH\MFServices.exe" -n O4 - HKLM\..\Run: [MFPrintServer] "C:\Program Files\Companion Suite IH\MFPrintServer.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ6.5\ICQ.exe" silent O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST') O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe O13 - Gopher Prefix: O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O23 - Service: ADSM Service (ADSMService) - Unknown owner - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe O23 - Service: Anmeldedienst NetlogonPolicyAgent (NetlogonPolicyAgent) - Unknown owner - C:\Windows\system32\ActionQueuet.exe O23 - Service: sgbx_device - Sagem - C:\Windows\system32\sgbxcoms.exe O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe -- End of file - 8330 bytes ======Scheduled tasks folder====== C:\Windows\tasks\Ad-Aware Update (Weekly).job ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}] Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-23 62080] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}] RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2009-08-15 312928] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Windows Live Anmelde-Hilfsprogramm - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2008-12-09 958200] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184] "SMSERIAL"=C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [2006-11-22 630784] "StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2006-11-10 90112] "RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-09-03 4702208] "Skytel"=C:\Windows\Skytel.exe [2007-08-03 1826816] "ATKMEDIA"=C:\Program Files\ASUS\ATK Media\DMEDIA.EXE [2006-11-02 61440] "Apoint"=C:\Program Files\Apoint2K\Apoint.exe [2006-09-12 155648] "PowerForPhone"=C:\Program Files\PowerForPhone\PowerForPhone.exe [2007-06-26 778240] "ASUS Screen Saver Protector"=C:\Windows\ASScrPro.exe [2008-11-13 33136] "ASUS Camera ScreenSaver"=C:\Windows\ASScrProlog.exe [2008-11-13 37232] "TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2009-08-15 198160] "avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2008-11-26 81000] "LiveUpdate"=C:\Program Files\Byteswarm\LiveUpdate\LiveUpdate.exe [2004-08-28 2150400] "MFServices"=C:\Program Files\Companion Suite IH\MFServices.exe [2005-07-08 151552] "MFPrintServer"=C:\Program Files\Companion Suite IH\MFPrintServer.exe [2005-07-08 61440] "SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280] "Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2009-09-10 1312080] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920] "WindowsWelcomeCenter"=oobefldr.dll,ShowWelcomeCenter [] "msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883840] "DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2009-04-23 691656] "Skype"=C:\Program Files\Skype\\Phone\Skype.exe [2009-10-09 25623336] "uTorrent"=C:\Program Files\uTorrent\uTorrent.exe [2009-09-06 288560] "ICQ"=C:\Program Files\ICQ6.5\ICQ.exe [2009-03-01 172792] "ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorUser"=0 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 "EnableUIADesktopToggle"=0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "BindDirectlyToPropertySetStorage"= [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eef06cb1-9bde-11de-bb67-001d60ee9d2f}] shell\AutoRun\command - G:\LaunchU3.exe -a ======List of files/folders created in the last 1 months====== 2009-11-25 18:34:46 ----D---- C:\rsit 2009-11-24 13:10:14 ----D---- C:\Users\ASUS\AppData\Roaming\Malwarebytes 2009-11-24 13:10:05 ----D---- C:\ProgramData\Malwarebytes 2009-11-24 13:10:05 ----D---- C:\Program Files\Malwarebytes' Anti-Malware 2009-11-24 06:57:42 ----D---- C:\Program Files\Panda Security 2009-11-24 06:54:46 ----D---- C:\Program Files\Trend Micro 2009-11-24 00:03:23 ----A---- C:\Windows\system32\lsdelete.exe 2009-11-23 21:33:46 ----A---- C:\Windows\ntbtlog.txt 2009-11-23 20:47:25 ----DC---- C:\Windows\system32\DRVSTORE 2009-11-23 20:31:05 ----D---- C:\ProgramData\Lavasoft 2009-11-23 20:31:05 ----D---- C:\Program Files\Lavasoft 2009-11-23 20:30:36 ----HDC---- C:\ProgramData\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6} 2009-11-22 07:58:40 ----D---- C:\Program Files\ICQ Link Patch 2009-11-21 15:36:44 ----A---- C:\Windows\system32\javaws.exe 2009-11-21 15:36:44 ----A---- C:\Windows\system32\javaw.exe 2009-11-21 15:36:44 ----A---- C:\Windows\system32\java.exe 2009-11-13 13:13:36 ----D---- C:\Windows\Profiles 2009-11-13 13:13:33 ----D---- C:\Users\ASUS\AppData\Roaming\InterTrust 2009-11-13 13:13:13 ----A---- C:\Windows\IsUn0407.exe 2009-11-10 21:58:37 ----A---- C:\Windows\system32\WSDApi.dll 2009-11-05 03:00:30 ----D---- C:\Program Files\MSXML 4.0 2009-11-04 08:06:18 ----A---- C:\Windows\system32\mshtml.dll 2009-11-03 19:15:12 ----A---- C:\Windows\system32\csfpm.dll 2009-11-03 19:15:11 ----A---- C:\Windows\system32\csfpm9x.dll 2009-11-03 19:13:53 ----A---- C:\Windows\system32\imhost32.dll 2009-11-03 19:13:53 ----A---- C:\Windows\system32\imgman32.dll 2009-11-03 19:13:03 ----A---- C:\Windows\system32\sgbxvs.dll 2009-11-03 19:13:03 ----A---- C:\Windows\system32\sgbxusb1.dll 2009-11-03 19:13:03 ----A---- C:\Windows\system32\sgbxjswr.dll 2009-11-03 19:13:03 ----A---- C:\Windows\system32\sgbxinsr.dll 2009-11-03 19:13:03 ----A---- C:\Windows\system32\sgbxcur.dll 2009-11-03 19:13:02 ----A---- C:\Windows\system32\sgbxserv.dll 2009-11-03 19:13:00 ----A---- C:\Windows\system32\sgbxpmui.dll 2009-11-03 19:12:59 ----A---- C:\Windows\system32\sgbxins.dll 2009-11-03 19:12:58 ----A---- C:\Windows\system32\sgbxih.exe 2009-11-03 19:12:58 ----A---- C:\Windows\system32\sgbxhbn3.dll 2009-11-03 19:12:58 ----A---- C:\Windows\system32\sgbxhbn1.dll 2009-11-03 19:12:57 ----A---- C:\Windows\system32\sgbxcu.dll 2009-11-03 19:12:57 ----A---- C:\Windows\system32\sgbxcomm.dll 2009-11-03 19:12:56 ----A---- C:\Windows\system32\sgbxcfg.exe 2009-11-03 19:12:56 ----A---- C:\Windows\system32\sgbxcfg.dll 2009-11-03 19:12:55 ----A---- C:\Windows\system32\sgbxplc.ini 2009-11-03 19:12:54 ----A---- C:\Windows\system32\sgbxunrs.dll 2009-11-03 19:12:54 ----A---- C:\Windows\system32\sgbxun9x.exe 2009-11-03 19:12:54 ----A---- C:\Windows\system32\sgbxuir.dll 2009-11-03 19:12:54 ----A---- C:\Windows\system32\sgbxpswr.dll 2009-11-03 19:12:54 ----A---- C:\Windows\system32\sgbxprpr.dll 2009-11-03 19:12:54 ----A---- C:\Windows\system32\sgbxlpar.dll 2009-11-03 19:12:53 ----A---- C:\Windows\system32\sgbxxc.dll 2009-11-03 19:12:53 ----A---- C:\Windows\system32\sgbxupdb.dll 2009-11-03 19:12:53 ----A---- C:\Windows\system32\sgbxui.dll 2009-11-03 19:12:53 ----A---- C:\Windows\system32\sgbxto32.dll 2009-11-03 19:12:53 ----A---- C:\Windows\system32\sgbxsk2.dll 2009-11-03 19:12:52 ----A---- C:\Windows\system32\sgbxsk1.dll 2009-11-03 19:12:52 ----A---- C:\Windows\system32\sgbxsk0.dll 2009-11-03 19:12:52 ----A---- C:\Windows\system32\sgbxpswx.exe 2009-11-03 19:12:52 ----A---- C:\Windows\system32\sgbxpswb.dll 2009-11-03 19:12:52 ----A---- C:\Windows\system32\sgbxpsw.dll 2009-11-03 19:12:52 ----A---- C:\Windows\system32\sgbxprpb.dll 2009-11-03 19:12:51 ----A---- C:\Windows\system32\sgbxprp.dll 2009-11-03 19:12:51 ----A---- C:\Windows\system32\sgbxpr32.dll 2009-11-03 19:12:51 ----A---- C:\Windows\system32\sgbxppx.dll 2009-11-03 19:12:51 ----A---- C:\Windows\system32\sgbxpp32.dll 2009-11-03 19:12:50 ----A---- C:\Windows\system32\sgbxlpab.dll 2009-11-03 19:12:49 ----A---- C:\Windows\system32\sgbxlpa.dll 2009-11-03 19:12:49 ----A---- C:\Windows\system32\sgbxjswx.exe 2009-11-03 19:12:49 ----A---- C:\Windows\system32\sgbxjswb.dll 2009-11-03 19:12:49 ----A---- C:\Windows\system32\sgbxjsw.dll 2009-11-03 19:12:49 ----A---- C:\Windows\system32\sgbxhpep.dll 2009-11-03 19:12:48 ----A---- C:\Windows\system32\sgbxhpeh.dll 2009-11-03 19:12:48 ----A---- C:\Windows\system32\sgbxhpec.dll 2009-11-03 19:12:48 ----A---- C:\Windows\system32\sgbxft32.dll 2009-11-03 19:12:48 ----A---- C:\Windows\system32\sgbxflib.dll 2009-11-03 19:12:48 ----A---- C:\Windows\system32\sgbxflat.dll 2009-11-03 19:12:47 ----A---- C:\Windows\system32\sgbxcomx.dll 2009-11-03 19:12:45 ----A---- C:\Windows\system32\sgbxcf32.dll 2009-11-03 19:12:45 ----A---- C:\Windows\system32\ptzipw32.dll 2009-11-03 19:12:45 ----A---- C:\Windows\system32\lexinpst.exe 2009-11-03 19:12:45 ----A---- C:\Windows\system32\lexgo.exe 2009-11-03 19:12:44 ----A---- C:\Windows\system32\sgbxutil.dll 2009-11-03 19:12:44 ----A---- C:\Windows\system32\lexedf.dll 2009-11-03 19:12:43 ----A---- C:\Windows\system32\sgbxprox.dll 2009-11-03 19:12:43 ----A---- C:\Windows\system32\sgbxppls.exe 2009-11-03 19:12:43 ----A---- C:\Windows\system32\sgbxpplc.dll 2009-11-03 19:12:42 ----A---- C:\Windows\system32\sgbxlmpm.dll 2009-11-03 19:12:42 ----A---- C:\Windows\system32\sgbxinsb.dll 2009-11-03 19:12:41 ----A---- C:\Windows\system32\sgbxgf.dll 2009-11-03 19:12:41 ----A---- C:\Windows\system32\sgbxcub.dll 2009-11-03 19:12:40 ----A---- C:\Windows\system32\sgbxcoms.exe 2009-11-03 19:12:40 ----A---- C:\Windows\system32\sgbxcomc.dll 2009-11-03 19:12:39 ----D---- C:\D6 2009-11-03 19:12:17 ----D---- C:\Program Files\Companion Suite IH 2009-11-03 19:11:14 ----D---- C:\Program Files\Companion Suite IH West Setup Files V1_1_2 2009-11-02 16:03:49 ----D---- C:\Program Files\Raw Modders Union 2009-10-29 09:15:40 ----A---- C:\ProgramData\windows.txt 2009-10-26 19:27:14 ----A---- C:\Windows\system32\wups2.dll 2009-10-26 19:27:14 ----A---- C:\Windows\system32\wuauclt.exe 2009-10-26 19:27:13 ----A---- C:\Windows\system32\wucltux.dll 2009-10-26 19:27:13 ----A---- C:\Windows\system32\wuaueng.dll 2009-10-26 19:26:51 ----A---- C:\Windows\system32\wups.dll 2009-10-26 19:26:51 ----A---- C:\Windows\system32\wudriver.dll 2009-10-26 19:26:51 ----A---- C:\Windows\system32\wuapi.dll 2009-10-26 19:26:32 ----A---- C:\Windows\system32\wuwebv.dll 2009-10-26 19:26:32 ----A---- C:\Windows\system32\wuapp.exe ======List of files/folders modified in the last 1 months====== 2009-11-25 18:34:56 ----D---- C:\Windows\Prefetch 2009-11-25 18:34:48 ----D---- C:\Windows\Temp 2009-11-25 18:31:34 ----D---- C:\Windows\Tasks 2009-11-25 18:31:27 ----D---- C:\Windows\system32\drivers 2009-11-25 18:27:45 ----D---- C:\Users\ASUS\AppData\Roaming\uTorrent 2009-11-25 14:54:06 ----D---- C:\Users\ASUS\AppData\Roaming\vlc 2009-11-25 07:04:31 ----D---- C:\Windows\system32\catroot 2009-11-25 07:04:28 ----D---- C:\Windows\winsxs 2009-11-25 01:10:01 ----SHD---- C:\System Volume Information 2009-11-24 14:15:34 ----D---- C:\Windows\System32 2009-11-24 14:15:34 ----D---- C:\Windows\inf 2009-11-24 14:15:34 ----A---- C:\Windows\system32\PerfStringBackup.INI 2009-11-24 14:03:02 ----A---- C:\Windows\system32\acovcnt.exe 2009-11-24 13:10:05 ----RD---- C:\Program Files 2009-11-24 13:10:05 ----HD---- C:\ProgramData 2009-11-23 21:35:17 ----D---- C:\Windows\system32\catroot2 2009-11-23 21:33:46 ----D---- C:\Windows 2009-11-23 20:48:41 ----D---- C:\Windows\system32\Tasks 2009-11-23 20:31:42 ----SHD---- C:\Windows\Installer 2009-11-22 08:17:01 ----SD---- C:\Users\ASUS\AppData\Roaming\Microsoft 2009-11-21 15:36:40 ----D---- C:\Program Files\Java 2009-11-21 15:11:15 ----HD---- C:\Program Files\InstallShield Installation Information 2009-11-14 07:08:37 ----D---- C:\Users\ASUS\AppData\Roaming\Skype 2009-11-14 00:08:54 ----D---- C:\Users\ASUS\AppData\Roaming\skypePM 2009-11-13 13:13:38 ----D---- C:\Program Files\Mozilla Thunderbird 2009-11-13 13:13:33 ----D---- C:\Windows\system32\Adobe 2009-11-13 13:13:33 ----D---- C:\Program Files\Common Files\Adobe 2009-11-13 13:13:33 ----D---- C:\Program Files\Adobe 2009-11-06 17:51:53 ----D---- C:\Program Files\Mozilla Firefox 2009-11-06 15:50:35 ----D---- C:\Users\ASUS\AppData\Roaming\dvdcss 2009-11-05 18:36:21 ----A---- C:\Windows\system32\mrt.exe 2009-11-05 03:21:31 ----D---- C:\Windows\system32\spool 2009-11-03 19:15:14 ----RSD---- C:\Windows\Fonts 2009-11-03 19:13:16 ----D---- C:\Windows\twain_32 2009-11-02 20:42:06 ----N---- C:\Windows\system32\MpSigStub.exe 2009-11-02 07:36:27 ----D---- C:\Windows\rescache 2009-11-02 07:19:19 ----D---- C:\Windows\system32\de-DE ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2008-11-26 23152] R1 aswSP;avast! Self Protection; C:\Windows\system32\drivers\aswSP.sys [2008-11-26 111184] R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2008-11-26 50864] R2 ASMMAP;ASMMAP; \??\C:\Program Files\ATKGFNEX\ASMMAP.sys [2007-07-24 13880] R2 aswFsBlk;aswFsBlk; C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-11-26 20560] R2 aswMonFlt;aswMonFlt; C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-11-26 51792] R2 ghaio;ghaio; \??\C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [2007-08-03 20936] R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2007-02-24 39936] R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2007-01-24 42496] R3 ApfiltrService;Alps Pointing-device Filter Driver; C:\Windows\system32\DRIVERS\Apfiltr.sys [2006-08-30 140800] R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2007-04-11 704000] R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2007-05-24 2609152] R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-21 14208] R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-09-05 1953944] R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2007-01-24 5632] R3 MODEMCSA;Unimodem-Datenstromfiltergerät; C:\Windows\system32\drivers\MODEMCSA.sys [2008-01-21 18432] R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATKACPI.sys [2006-12-14 7680] R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2007-03-05 76288] R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-04-11 89088] R3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2006-11-22 982272] S3 a7z6yk7s;a7z6yk7s; C:\Windows\system32\drivers\a7z6yk7s.sys [] S3 drmkaud;Microsoft Kernel-DRM-Audioentschlüsselung; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632] S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520] S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192] S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888] S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504] S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016] S3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016] S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328] S3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-02 194048] S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656] S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616] S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 ADSMService;ADSM Service; C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe [2007-05-18 73728] R2 ASLDRService;ASLDR Service; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [2007-02-06 94208] R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2008-11-26 18752] R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2007-05-24 602112] R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [2007-08-08 94208] R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2008-11-26 155160] R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2008-10-19 222456] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2009-11-23 1184912] R2 spmgr;spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [2007-08-03 125496] R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2008-11-26 254040] R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2008-11-26 352920] S2 NetlogonPolicyAgent;Anmeldedienst NetlogonPolicyAgent; C:\Windows\system32\ActionQueuet.exe [2008-01-21 63488] S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632] S3 sgbx_device;sgbx_device; C:\Windows\system32\sgbxcoms.exe [2005-07-08 466944] -----------------EOF-----------------