
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
proces firefox.exe se neukončí s vypnutím programu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Re: proces firefox.exe se neukončí s vypnutím programu
Log najdete zde:
C:\ComboFix.txt
C:\ComboFix.txt
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: proces firefox.exe se neukončí s vypnutím programu
bohužel, není 

Re: proces firefox.exe se neukončí s vypnutím programu
To není možné. Že tam ještě máte ten NOD?
Nevykládejte si to zle, ale tohle se ještě nestalo.

Albert Einstein: Jen dvě věci jsou nekonečné - vesmír a lidská hloupost. Tím prvním si ovšem nejsem tak jist.
Re: proces firefox.exe se neukončí s vypnutím programu
nemám
opravdu

Re: proces firefox.exe se neukončí s vypnutím programu
Poprosím o nový log ze Rsitu.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: proces firefox.exe se neukončí s vypnutím programu
Logfile of random's system information tool 1.08 (written by random/random)
Run by WoMec at 2011-07-04 00:49:44
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 28 GB (28%) free of 102 GB
Total RAM: 4094 MB (56% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 0:49:52, on 4.7.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\QIP 2010\qip.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files\trend micro\WoMec.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Infium] "C:\Program Files (x86)\QIP 2010\qip.exe"m Files (x
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\Microsoft Office\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\Spybot - Search & Destroy\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} (Java Plug-in 1.6.0_20) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{6B2110FC-4F70-4EF9-9C8E-5A9E9215E9AA}: NameServer = 94.199.199.192,94.199.199.199
O18 - Protocol: brx - {9C160F90-74D1-11D3-AB60-0060977C1F29} - (no file)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\Skype4COM.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Autodata Limited License Service - Autodata Limited - C:\Program Files (x86)\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies, Inc. - C:\Program Files (x86)\WinPcap\rpcapd.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9124 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
"C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe"
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s
C:\Windows\system32\svchost.exe -k bthaudiosvc
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"taskhost.exe"
C:\Windows\Explorer.EXE
"C:\Windows\system32\Dwm.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Windows\System32\rundll32.exe" sbavmon.dll,SBAVMonitor
"C:\Program Files (x86)\MagicTune Premium\MagicTuneEngine.exe"
"C:\Windows\WindowsMobile\wmdc.exe"
"C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe"
"C:\Program Files (x86)\QIP 2010\qip.exe" m Files (x
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
WLIDSvcM.exe 640
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\MagicTune Premium\MagicTune.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\svchost.exe -k secsvcs
"taskhost.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 524 528 536 65536 532
C:\Windows\System32\svchost.exe -k WerSvcGroup
"C:\Users\WoMec\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-04-20 43520]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~2\Spybot - Search & Destroy\SDHelper.dll [2009-01-26 1879896]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-05-19 41760]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2009-12-08 9642528]
"Creative SB Monitoring Utility"=RunDll32 sbavmon.dll,SBAVMonitor []
"MagicTuneEngine"=C:\Program Files (x86)\MagicTune Premium\MagicTuneEngine.exe [2009-06-15 24064]
"Windows Mobile Device Center"=C:\Windows\WindowsMobile\wmdc.exe [2007-05-31 660360]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"=C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]
"Infium"=C:\Program Files (x86)\QIP 2010\qip.exe [2011-06-24 6804864]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2011-05-25 1951112]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe [2010-11-10 4240760]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2011-01-07 253672]
"LogMeIn Hamachi Ui"=C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2011-05-25 1951112]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
GoogleUpdateTaskMachineCore.job
GoogleUpdateTaskMachineUA.job
SA.DAT
SCHEDLGU.TXT
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2011-05-07 249344]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
FencesShellExt - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files (x86)\Stardock\Fences\FencesMenu64.dll [2009-10-02 134656]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecure"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 months======
2011-07-04 00:48:11 ----D---- C:\rsit
2011-07-03 23:44:54 ----SHD---- C:\$RECYCLE.BIN
2011-07-03 23:33:33 ----A---- C:\Windows\zip.exe
2011-07-03 23:33:33 ----A---- C:\Windows\SWSC.exe
2011-07-03 23:33:33 ----A---- C:\Windows\SWREG.exe
2011-07-03 23:33:33 ----A---- C:\Windows\sed.exe
2011-07-03 23:33:33 ----A---- C:\Windows\PEV.exe
2011-07-03 23:33:33 ----A---- C:\Windows\NIRCMD.exe
2011-07-03 23:33:33 ----A---- C:\Windows\MBR.exe
2011-07-03 23:33:33 ----A---- C:\Windows\grep.exe
2011-07-03 23:33:25 ----D---- C:\Windows\ERDNT
2011-07-03 22:52:21 ----D---- C:\Users\WoMec\AppData\Roaming\Wireshark
2011-07-03 22:36:25 ----D---- C:\Program Files\Wireshark
2011-07-03 22:18:54 ----D---- C:\Program Files\trend micro
2011-07-03 17:42:25 ----D---- C:\Program Files (x86)\Spyware Terminator
2011-07-03 17:27:38 ----A---- C:\Windows\ScanSpyware.INI
2011-07-03 17:18:49 ----D---- C:\Users\WoMec\AppData\Roaming\ScanSpyware
2011-07-03 17:11:08 ----D---- C:\Windows\InstallDir
2011-07-03 16:38:07 ----D---- C:\Users\WoMec\AppData\Roaming\Malwarebytes
2011-07-03 16:37:58 ----A---- C:\Windows\system32\drivers\mbam.sys
2011-06-29 14:41:28 ----A---- C:\Windows\SYSWOW64\drvinst.exe
2011-06-29 14:41:28 ----A---- C:\Windows\SYSWOW64\devrtl.dll
2011-06-29 14:41:28 ----A---- C:\Windows\SYSWOW64\devobj.dll
2011-06-29 14:41:28 ----A---- C:\Windows\SYSWOW64\cfgmgr32.dll
2011-06-29 14:41:28 ----A---- C:\Windows\system32\umpnpmgr.dll
2011-06-29 14:41:21 ----A---- C:\Windows\SYSWOW64\tquery.dll
2011-06-29 14:41:21 ----A---- C:\Windows\SYSWOW64\SearchProtocolHost.exe
2011-06-29 14:41:21 ----A---- C:\Windows\SYSWOW64\SearchIndexer.exe
2011-06-29 14:41:21 ----A---- C:\Windows\SYSWOW64\SearchFilterHost.exe
2011-06-29 14:41:21 ----A---- C:\Windows\SYSWOW64\mssvp.dll
2011-06-29 14:41:21 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2011-06-29 14:41:21 ----A---- C:\Windows\SYSWOW64\mssphtb.dll
2011-06-29 14:41:21 ----A---- C:\Windows\SYSWOW64\mssph.dll
2011-06-29 14:41:21 ----A---- C:\Windows\system32\tquery.dll
2011-06-29 14:41:21 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2011-06-29 14:41:21 ----A---- C:\Windows\system32\SearchIndexer.exe
2011-06-29 14:41:21 ----A---- C:\Windows\system32\SearchFilterHost.exe
2011-06-29 14:41:21 ----A---- C:\Windows\system32\mssvp.dll
2011-06-29 14:41:21 ----A---- C:\Windows\system32\mssrch.dll
2011-06-29 14:41:21 ----A---- C:\Windows\system32\mssphtb.dll
2011-06-29 14:41:21 ----A---- C:\Windows\system32\mssph.dll
2011-06-29 14:41:21 ----A---- C:\Windows\system32\msscntrs.dll
2011-06-29 14:41:20 ----A---- C:\Windows\SYSWOW64\msscntrs.dll
2011-06-21 13:25:30 ----D---- C:\Windows\C5C1C0F0D62F4DBF81D4D7EF397C228B.TMP
2011-06-15 14:40:12 ----D---- C:\Program Files (x86)\Activision
2011-06-15 11:22:43 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-06-15 11:22:43 ----A---- C:\Windows\system32\mshtmled.dll
2011-06-15 11:22:42 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-06-15 11:22:42 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-06-15 11:22:42 ----A---- C:\Windows\system32\iertutil.dll
2011-06-15 11:22:41 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-06-15 11:22:41 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2011-06-15 11:22:41 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-06-15 11:22:41 ----A---- C:\Windows\system32\urlmon.dll
2011-06-15 11:22:41 ----A---- C:\Windows\system32\jscript9.dll
2011-06-15 11:22:41 ----A---- C:\Windows\system32\jscript.dll
2011-06-15 11:22:41 ----A---- C:\Windows\system32\ieui.dll
2011-06-15 11:22:40 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-06-15 11:22:39 ----A---- C:\Windows\system32\mshtml.dll
2011-06-15 11:22:38 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-06-15 11:22:38 ----A---- C:\Windows\system32\ieframe.dll
2011-06-15 11:10:38 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2011-06-15 11:10:38 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-06-15 11:10:38 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2011-06-15 11:10:18 ----A---- C:\Windows\system32\win32k.sys
2011-06-15 11:10:12 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-06-15 11:10:12 ----A---- C:\Windows\system32\drivers\afd.sys
2011-06-15 11:09:55 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-06-15 11:09:55 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-06-15 11:09:55 ----A---- C:\Windows\system32\drivers\srv.sys
2011-06-15 11:09:19 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2011-06-15 11:09:19 ----A---- C:\Windows\system32\inetcomm.dll
2011-06-15 11:09:17 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2011-06-15 11:09:17 ----A---- C:\Windows\system32\oleaut32.dll
2011-06-14 11:35:13 ----D---- C:\Windows\system32\SPReview
2011-06-14 11:33:58 ----D---- C:\Windows\system32\EventProviders
2011-06-14 11:31:24 ----A---- C:\Windows\system32\netfxperf.dll
2011-06-14 11:31:24 ----A---- C:\Windows\system32\dfshim.dll
2011-06-14 11:31:18 ----A---- C:\Windows\SYSWOW64\dfshim.dll
2011-06-14 11:31:15 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2011-06-14 11:31:15 ----A---- C:\Windows\system32\mstscax.dll
2011-06-14 11:31:15 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2011-06-14 11:31:15 ----A---- C:\Windows\system32\d3d10warp.dll
2011-06-14 11:31:13 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2011-06-14 11:31:11 ----A---- C:\Windows\SYSWOW64\mfc40u.dll
2011-06-14 11:31:11 ----A---- C:\Windows\SYSWOW64\mfc40.dll
2011-06-14 11:31:11 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2011-06-14 11:31:11 ----A---- C:\Windows\system32\sysmain.dll
2011-06-14 11:31:10 ----A---- C:\Windows\SYSWOW64\pmcsnap.dll
2011-06-14 11:31:10 ----A---- C:\Windows\system32\shell32.dll
2011-06-14 11:31:10 ----A---- C:\Windows\system32\MSVidCtl.dll
2011-06-14 11:31:09 ----A---- C:\Windows\system32\wmp.dll
2011-06-14 11:31:08 ----A---- C:\Windows\system32\ntdll.dll
2011-06-14 11:31:08 ----A---- C:\Windows\system32\mscoree.dll
2011-06-14 11:31:08 ----A---- C:\Windows\system32\mmcndmgr.dll
2011-06-14 11:31:07 ----A---- C:\Windows\system32\secproc_isv.dll
2011-06-14 11:31:07 ----A---- C:\Windows\system32\RMActivate_isv.exe
2011-06-14 11:31:07 ----A---- C:\Windows\system32\mf.dll
2011-06-14 11:31:06 ----A---- C:\Windows\SYSWOW64\shell32.dll
2011-06-14 11:31:06 ----A---- C:\Windows\SYSWOW64\secproc_isv.dll
2011-06-14 11:31:06 ----A---- C:\Windows\SYSWOW64\secproc.dll
2011-06-14 11:31:06 ----A---- C:\Windows\SYSWOW64\RMActivate_isv.exe
2011-06-14 11:31:06 ----A---- C:\Windows\system32\xpsservices.dll
2011-06-14 11:31:06 ----A---- C:\Windows\system32\secproc.dll
2011-06-14 11:31:06 ----A---- C:\Windows\system32\rpcrt4.dll
2011-06-14 11:31:06 ----A---- C:\Windows\system32\RMActivate.exe
2011-06-14 11:31:05 ----A---- C:\Windows\SYSWOW64\RMActivate.exe
2011-06-14 11:31:05 ----A---- C:\Windows\SYSWOW64\PushPrinterConnections.exe
2011-06-14 11:31:05 ----A---- C:\Windows\SYSWOW64\ppcsnap.dll
2011-06-14 11:31:05 ----A---- C:\Windows\system32\schedsvc.dll
2011-06-14 11:31:05 ----A---- C:\Windows\system32\ole32.dll
2011-06-14 11:31:04 ----A---- C:\Windows\SYSWOW64\mscoree.dll
2011-06-14 11:31:04 ----A---- C:\Windows\system32\spwizui.dll
2011-06-14 11:31:03 ----A---- C:\Windows\SYSWOW64\mf.dll
2011-06-14 11:31:03 ----A---- C:\Windows\system32\wevtsvc.dll
2011-06-14 11:31:03 ----A---- C:\Windows\system32\taskschd.dll
2011-06-14 11:31:03 ----A---- C:\Windows\system32\RacEngn.dll
2011-06-14 11:31:03 ----A---- C:\Windows\system32\ExplorerFrame.dll
2011-06-14 11:31:03 ----A---- C:\Windows\system32\diagperf.dll
2011-06-14 11:31:02 ----A---- C:\Windows\SYSWOW64\CertEnroll.dll
2011-06-14 11:31:02 ----A---- C:\Windows\system32\vssapi.dll
2011-06-14 11:31:02 ----A---- C:\Windows\system32\UIRibbon.dll
2011-06-14 11:31:02 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2011-06-14 11:31:02 ----A---- C:\Windows\system32\msxml3.dll
2011-06-14 11:31:02 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2011-06-14 11:31:02 ----A---- C:\Windows\system32\drivers\msiscsi.sys
2011-06-14 11:31:01 ----A---- C:\Windows\SYSWOW64\wmp.dll
2011-06-14 11:31:00 ----A---- C:\Windows\SYSWOW64\PresentationHostProxy.dll
2011-06-14 11:31:00 ----A---- C:\Windows\SYSWOW64\PresentationHost.exe
2011-06-14 11:31:00 ----A---- C:\Windows\system32\WsmSvc.dll
2011-06-14 11:31:00 ----A---- C:\Windows\system32\WMVCORE.DLL
2011-06-14 11:31:00 ----A---- C:\Windows\system32\spreview.exe
2011-06-14 11:31:00 ----A---- C:\Windows\system32\rdpdd.dll
2011-06-14 11:31:00 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2011-06-14 11:31:00 ----A---- C:\Windows\system32\PresentationHost.exe
2011-06-14 11:31:00 ----A---- C:\Windows\system32\MPSSVC.dll
2011-06-14 11:30:59 ----A---- C:\Windows\system32\WinSAT.exe
2011-06-14 11:30:59 ----A---- C:\Windows\system32\spinstall.exe
2011-06-14 11:30:59 ----A---- C:\Windows\system32\CertEnroll.dll
2011-06-14 11:30:58 ----A---- C:\Windows\SYSWOW64\RacEngn.dll
2011-06-14 11:30:58 ----A---- C:\Windows\system32\WMVDECOD.DLL
2011-06-14 11:30:58 ----A---- C:\Windows\system32\SearchFolder.dll
2011-06-14 11:30:58 ----A---- C:\Windows\system32\msxml6.dll
2011-06-14 11:30:58 ----A---- C:\Windows\system32\IKEEXT.DLL
2011-06-14 11:30:58 ----A---- C:\Windows\system32\d3d9.dll
2011-06-14 11:30:58 ----A---- C:\Windows\system32\AuthFWSnapin.dll
2011-06-14 11:30:57 ----A---- C:\Windows\SYSWOW64\AuthFWSnapin.dll
2011-06-14 11:30:57 ----A---- C:\Windows\system32\VSSVC.exe
2011-06-14 11:30:57 ----A---- C:\Windows\system32\kernel32.dll
2011-06-14 11:30:57 ----A---- C:\Windows\system32\gpsvc.dll
2011-06-14 11:30:57 ----A---- C:\Windows\system32\dwmcore.dll
2011-06-14 11:30:57 ----A---- C:\Windows\system32\dbgeng.dll
2011-06-14 11:30:56 ----A---- C:\Windows\system32\drivers\ndis.sys
2011-06-14 11:30:56 ----A---- C:\Windows\system32\drivers\http.sys
2011-06-14 11:30:56 ----A---- C:\Windows\system32\crypt32.dll
2011-06-14 11:30:55 ----A---- C:\Windows\SYSWOW64\ole32.dll
2011-06-14 11:30:55 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2011-06-14 11:30:55 ----A---- C:\Windows\system32\TSWorkspace.dll
2011-06-14 11:30:55 ----A---- C:\Windows\system32\schannel.dll
2011-06-14 11:30:55 ----A---- C:\Windows\system32\qmgr.dll
2011-06-14 11:30:55 ----A---- C:\Windows\system32\lsasrv.dll
2011-06-14 11:30:55 ----A---- C:\Windows\system32\KernelBase.dll
2011-06-14 11:30:55 ----A---- C:\Windows\system32\audiosrv.dll
2011-06-14 11:30:55 ----A---- C:\Windows\system32\actxprxy.dll
2011-06-14 11:30:54 ----A---- C:\Windows\system32\termsrv.dll
2011-06-14 11:30:54 ----A---- C:\Windows\system32\sqmapi.dll
2011-06-14 11:30:54 ----A---- C:\Windows\system32\mstsc.exe
2011-06-14 11:30:54 ----A---- C:\Windows\system32\imapi2fs.dll
2011-06-14 11:30:54 ----A---- C:\Windows\system32\gpprefcl.dll
2011-06-14 11:30:53 ----A---- C:\Windows\SYSWOW64\vssapi.dll
2011-06-14 11:30:53 ----A---- C:\Windows\SYSWOW64\SearchFolder.dll
2011-06-14 11:30:53 ----A---- C:\Windows\SYSWOW64\d3d9.dll
2011-06-14 11:30:53 ----A---- C:\Windows\system32\winhttp.dll
2011-06-14 11:30:53 ----A---- C:\Windows\system32\setupapi.dll
2011-06-14 11:30:53 ----A---- C:\Windows\system32\QAGENTRT.DLL
2011-06-14 11:30:53 ----A---- C:\Windows\system32\propsys.dll
2011-06-14 11:30:53 ----A---- C:\Windows\system32\netlogon.dll
2011-06-14 11:30:53 ----A---- C:\Windows\system32\msv1_0.dll
2011-06-14 11:30:53 ----A---- C:\Windows\system32\d3d11.dll
2011-06-14 11:30:52 ----A---- C:\Windows\SYSWOW64\taskschd.dll
2011-06-14 11:30:52 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2011-06-14 11:30:52 ----A---- C:\Windows\system32\werconcpl.dll
2011-06-14 11:30:52 ----A---- C:\Windows\system32\wbengine.exe
2011-06-14 11:30:52 ----A---- C:\Windows\system32\user32.dll
2011-06-14 11:30:52 ----A---- C:\Windows\system32\taskeng.exe
2011-06-14 11:30:52 ----A---- C:\Windows\system32\rpcss.dll
2011-06-14 11:30:52 ----A---- C:\Windows\system32\PushPrinterConnections.exe
2011-06-14 11:30:52 ----A---- C:\Windows\system32\odbc32.dll
2011-06-14 11:30:52 ----A---- C:\Windows\system32\authui.dll
2011-06-14 11:30:51 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2011-06-14 11:30:51 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2011-06-14 11:30:51 ----A---- C:\Windows\system32\WSDApi.dll
2011-06-14 11:30:51 ----A---- C:\Windows\system32\umrdp.dll
2011-06-14 11:30:51 ----A---- C:\Windows\system32\scavengeui.dll
2011-06-14 11:30:51 ----A---- C:\Windows\system32\drivers\tdx.sys
2011-06-14 11:30:51 ----A---- C:\Windows\system32\drivers\netio.sys
2011-06-14 11:30:51 ----A---- C:\Windows\system32\drivers\netbt.sys
2011-06-14 11:30:51 ----A---- C:\Windows\system32\dhcpcore.dll
2011-06-14 11:30:51 ----A---- C:\Windows\system32\certmgr.dll
2011-06-14 11:30:50 ----A---- C:\Windows\SYSWOW64\wer.dll
2011-06-14 11:30:50 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2011-06-14 11:30:50 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2011-06-14 11:30:50 ----A---- C:\Windows\SYSWOW64\certcli.dll
2011-06-14 11:30:50 ----A---- C:\Windows\system32\webio.dll
2011-06-14 11:30:50 ----A---- C:\Windows\system32\tsmf.dll
2011-06-14 11:30:50 ----A---- C:\Windows\system32\shlwapi.dll
2011-06-14 11:30:50 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2011-06-14 11:30:50 ----A---- C:\Windows\system32\netshell.dll
2011-06-14 11:30:50 ----A---- C:\Windows\system32\ncsi.dll
2011-06-14 11:30:50 ----A---- C:\Windows\system32\msdtctm.dll
2011-06-14 11:30:50 ----A---- C:\Windows\system32\msdrm.dll
2011-06-14 11:30:50 ----A---- C:\Windows\system32\localspl.dll
2011-06-14 11:30:50 ----A---- C:\Windows\system32\framedynos.dll
2011-06-14 11:30:49 ----A---- C:\Windows\SYSWOW64\tcpmonui.dll
2011-06-14 11:30:49 ----A---- C:\Windows\SYSWOW64\odbc32.dll
2011-06-14 11:30:49 ----A---- C:\Windows\system32\ws2_32.dll
2011-06-14 11:30:49 ----A---- C:\Windows\system32\winlogon.exe
2011-06-14 11:30:49 ----A---- C:\Windows\system32\usp10.dll
2011-06-14 11:30:49 ----A---- C:\Windows\system32\quartz.dll
2011-06-14 11:30:49 ----A---- C:\Windows\system32\nlasvc.dll
2011-06-14 11:30:49 ----A---- C:\Windows\system32\netcfgx.dll
2011-06-14 11:30:49 ----A---- C:\Windows\system32\lsm.exe
2011-06-14 11:30:49 ----A---- C:\Windows\system32\drivers\cng.sys
2011-06-14 11:30:49 ----A---- C:\Windows\system32\comdlg32.dll
2011-06-14 11:30:49 ----A---- C:\Windows\system32\appmgr.dll
2011-06-14 11:30:48 ----A---- C:\Windows\SYSWOW64\winhttp.dll
2011-06-14 11:30:48 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2011-06-14 11:30:48 ----A---- C:\Windows\SYSWOW64\tsmf.dll
2011-06-14 11:30:48 ----A---- C:\Windows\SYSWOW64\setupapi.dll
2011-06-14 11:30:48 ----A---- C:\Windows\SYSWOW64\quartz.dll
2011-06-14 11:30:48 ----A---- C:\Windows\SYSWOW64\dot3api.dll
2011-06-14 11:30:48 ----A---- C:\Windows\system32\wpdshext.dll
2011-06-14 11:30:48 ----A---- C:\Windows\system32\wmpps.dll
2011-06-14 11:30:48 ----A---- C:\Windows\system32\Query.dll
2011-06-14 11:30:48 ----A---- C:\Windows\system32\QAGENT.DLL
2011-06-14 11:30:48 ----A---- C:\Windows\system32\mswsock.dll
2011-06-14 11:30:48 ----A---- C:\Windows\system32\dxgi.dll
2011-06-14 11:30:48 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2011-06-14 11:30:48 ----A---- C:\Windows\system32\drivers\csc.sys
2011-06-14 11:30:48 ----A---- C:\Windows\system32\BFE.DLL
2011-06-14 11:30:48 ----A---- C:\Windows\system32\azroles.dll
2011-06-14 11:30:48 ----A---- C:\Windows\system32\apphelp.dll
2011-06-14 11:30:47 ----A---- C:\Windows\SYSWOW64\MSVidCtl.dll
2011-06-14 11:30:47 ----A---- C:\Windows\SYSWOW64\dbgeng.dll
2011-06-14 11:30:47 ----A---- C:\Windows\SYSWOW64\apphelp.dll
2011-06-14 11:30:47 ----A---- C:\Windows\system32\win32spl.dll
2011-06-14 11:30:47 ----A---- C:\Windows\system32\Vault.dll
2011-06-14 11:30:47 ----A---- C:\Windows\system32\samsrv.dll
2011-06-14 11:30:47 ----A---- C:\Windows\system32\lpksetup.exe
2011-06-14 11:30:47 ----A---- C:\Windows\system32\DShowRdpFilter.dll
2011-06-14 11:30:47 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-06-14 11:30:47 ----A---- C:\Windows\system32\cmd.exe
2011-06-14 11:30:46 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2011-06-14 11:30:46 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2011-06-14 11:30:46 ----A---- C:\Windows\SYSWOW64\webio.dll
2011-06-14 11:30:46 ----A---- C:\Windows\SYSWOW64\netlogon.dll
2011-06-14 11:30:46 ----A---- C:\Windows\SYSWOW64\netcfgx.dll
2011-06-14 11:30:46 ----A---- C:\Windows\SYSWOW64\d3d11.dll
2011-06-14 11:30:46 ----A---- C:\Windows\system32\WindowsCodecs.dll
2011-06-14 11:30:46 ----A---- C:\Windows\system32\WebClnt.dll
2011-06-14 11:30:46 ----A---- C:\Windows\system32\rdpclip.exe
2011-06-14 11:30:46 ----A---- C:\Windows\system32\cscsvc.dll
2011-06-14 11:30:45 ----A---- C:\Windows\SYSWOW64\WsmSvc.dll
2011-06-14 11:30:45 ----A---- C:\Windows\SYSWOW64\upnp.dll
2011-06-14 11:30:45 ----A---- C:\Windows\SYSWOW64\Query.dll
2011-06-14 11:30:45 ----A---- C:\Windows\SYSWOW64\gpprefcl.dll
2011-06-14 11:30:45 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2011-06-14 11:30:45 ----A---- C:\Windows\system32\Wldap32.dll
2011-06-14 11:30:45 ----A---- C:\Windows\system32\taskcomp.dll
2011-06-14 11:30:45 ----A---- C:\Windows\system32\sxs.dll
2011-06-14 11:30:45 ----A---- C:\Windows\system32\pnidui.dll
2011-06-14 11:30:45 ----A---- C:\Windows\system32\mfds.dll
2011-06-14 11:30:45 ----A---- C:\Windows\system32\mcbuilder.exe
2011-06-14 11:30:45 ----A---- C:\Windows\system32\drivers\vhdmp.sys
2011-06-14 11:30:45 ----A---- C:\Windows\system32\cscobj.dll
2011-06-14 11:30:44 ----A---- C:\Windows\SYSWOW64\schannel.dll
2011-06-14 11:30:44 ----A---- C:\Windows\SYSWOW64\SessEnv.dll
2011-06-14 11:30:44 ----A---- C:\Windows\SYSWOW64\PortableDeviceApi.dll
2011-06-14 11:30:44 ----A---- C:\Windows\SYSWOW64\netfxperf.dll
2011-06-14 11:30:44 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2011-06-14 11:30:44 ----A---- C:\Windows\SYSWOW64\msdrm.dll
2011-06-14 11:30:44 ----A---- C:\Windows\SYSWOW64\mmcndmgr.dll
2011-06-14 11:30:44 ----A---- C:\Windows\SYSWOW64\imapi2fs.dll
2011-06-14 11:30:44 ----A---- C:\Windows\SYSWOW64\DShowRdpFilter.dll
2011-06-14 11:30:44 ----A---- C:\Windows\SYSWOW64\authui.dll
2011-06-14 11:30:44 ----A---- C:\Windows\system32\wuaueng.dll
2011-06-14 11:30:44 ----A---- C:\Windows\system32\winsta.dll
2011-06-14 11:30:44 ----A---- C:\Windows\system32\webservices.dll
2011-06-14 11:30:44 ----A---- C:\Windows\system32\sqlsrv32.dll
2011-06-14 11:30:44 ----A---- C:\Windows\system32\spoolsv.exe
2011-06-14 11:30:44 ----A---- C:\Windows\system32\SessEnv.dll
2011-06-14 11:30:44 ----A---- C:\Windows\system32\rdpendp.dll
2011-06-14 11:30:44 ----A---- C:\Windows\system32\ipsmsnap.dll
2011-06-14 11:30:44 ----A---- C:\Windows\system32\hgprint.dll
2011-06-14 11:30:44 ----A---- C:\Windows\system32\fveapi.dll
2011-06-14 11:30:44 ----A---- C:\Windows\system32\dot3api.dll
2011-06-14 11:30:43 ----A---- C:\Windows\SYSWOW64\usp10.dll
2011-06-14 11:30:43 ----A---- C:\Windows\SYSWOW64\shlwapi.dll
2011-06-14 11:30:43 ----A---- C:\Windows\SYSWOW64\mcbuilder.exe
2011-06-14 11:30:43 ----A---- C:\Windows\SYSWOW64\certmgr.dll
2011-06-14 11:30:43 ----A---- C:\Windows\system32\WMNetMgr.dll
2011-06-14 11:30:43 ----A---- C:\Windows\system32\schtasks.exe
2011-06-14 11:30:43 ----A---- C:\Windows\system32\prncache.dll
2011-06-14 11:30:43 ----A---- C:\Windows\system32\mcmde.dll
2011-06-14 11:30:43 ----A---- C:\Windows\system32\gdi32.dll
2011-06-14 11:30:43 ----A---- C:\Windows\system32\drivers\volsnap.sys
2011-06-14 11:30:43 ----A---- C:\Windows\system32\drivers\msrpc.sys
2011-06-14 11:30:42 ----A---- C:\Windows\SYSWOW64\xpsservices.dll
2011-06-14 11:30:42 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2011-06-14 11:30:42 ----A---- C:\Windows\SYSWOW64\userenv.dll
2011-06-14 11:30:42 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2011-06-14 11:30:42 ----A---- C:\Windows\SYSWOW64\comdlg32.dll
2011-06-14 11:30:42 ----A---- C:\Windows\system32\wuapi.dll
2011-06-14 11:30:42 ----A---- C:\Windows\system32\wlanpref.dll
2011-06-14 11:30:42 ----A---- C:\Windows\system32\wintrust.dll
2011-06-14 11:30:42 ----A---- C:\Windows\system32\vpnike.dll
2011-06-14 11:30:42 ----A---- C:\Windows\system32\userenv.dll
2011-06-14 11:30:42 ----A---- C:\Windows\system32\photowiz.dll
2011-06-14 11:30:42 ----A---- C:\Windows\system32\IPSECSVC.DLL
2011-06-14 11:30:42 ----A---- C:\Windows\system32\FXSSVC.exe
2011-06-14 11:30:42 ----A---- C:\Windows\system32\framedyn.dll
2011-06-14 11:30:42 ----A---- C:\Windows\system32\evr.dll
2011-06-14 11:30:42 ----A---- C:\Windows\system32\drivers\rdbss.sys
2011-06-14 11:30:42 ----A---- C:\Windows\system32\drivers\1394ohci.sys
2011-06-14 11:30:42 ----A---- C:\Windows\system32\AudioSes.dll
2011-06-14 11:30:41 ----A---- C:\Windows\SYSWOW64\cmd.exe
2011-06-14 11:30:41 ----A---- C:\Windows\system32\wmpmde.dll
2011-06-14 11:30:41 ----A---- C:\Windows\system32\WMPEncEn.dll
2011-06-14 11:30:41 ----A---- C:\Windows\system32\wmpeffects.dll
2011-06-14 11:30:41 ----A---- C:\Windows\system32\tscfgwmi.dll
2011-06-14 11:30:41 ----A---- C:\Windows\system32\SyncCenter.dll
2011-06-14 11:30:41 ----A---- C:\Windows\system32\srvsvc.dll
2011-06-14 11:30:41 ----A---- C:\Windows\system32\sppobjs.dll
2011-06-14 11:30:41 ----A---- C:\Windows\system32\shsvcs.dll
2011-06-14 11:30:41 ----A---- C:\Windows\system32\mfreadwrite.dll
2011-06-14 11:30:41 ----A---- C:\Windows\system32\aepdu.dll
2011-06-14 11:30:41 ----A---- C:\Windows\system32\aeinv.dll
2011-06-14 11:30:40 ----A---- C:\Windows\SYSWOW64\Wldap32.dll
2011-06-14 11:30:40 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2011-06-14 11:30:40 ----A---- C:\Windows\SYSWOW64\user32.dll
2011-06-14 11:30:40 ----A---- C:\Windows\SYSWOW64\rdpendp.dll
2011-06-14 11:30:40 ----A---- C:\Windows\SYSWOW64\propsys.dll
2011-06-14 11:30:40 ----A---- C:\Windows\SYSWOW64\mfds.dll
2011-06-14 11:30:40 ----A---- C:\Windows\SYSWOW64\framedynos.dll
2011-06-14 11:30:40 ----A---- C:\Windows\system32\WinSATAPI.dll
2011-06-14 11:30:40 ----A---- C:\Windows\system32\vmicsvc.exe
2011-06-14 11:30:40 ----A---- C:\Windows\system32\stobject.dll
2011-06-14 11:30:40 ----A---- C:\Windows\system32\netdiagfx.dll
2011-06-14 11:30:40 ----A---- C:\Windows\system32\localsec.dll
2011-06-14 11:30:40 ----A---- C:\Windows\system32\iphlpsvc.dll
2011-06-14 11:30:40 ----A---- C:\Windows\system32\imapi2.dll
2011-06-14 11:30:40 ----A---- C:\Windows\system32\fde.dll
2011-06-14 11:30:40 ----A---- C:\Windows\system32\drivers\vmbus.sys
2011-06-14 11:30:40 ----A---- C:\Windows\system32\drivers\udfs.sys
2011-06-14 11:30:40 ----A---- C:\Windows\system32\credui.dll
2011-06-14 11:30:40 ----A---- C:\Windows\system32\cdd.dll
2011-06-14 11:30:40 ----A---- C:\Windows\system32\bcryptprimitives.dll
2011-06-14 11:30:39 ----A---- C:\Windows\SYSWOW64\ncsi.dll
2011-06-14 11:30:39 ----A---- C:\Windows\SYSWOW64\azroles.dll
2011-06-14 11:30:39 ----A---- C:\Windows\SYSWOW64\appmgr.dll
2011-06-14 11:30:39 ----A---- C:\Windows\system32\tcpipcfg.dll
2011-06-14 11:30:39 ----A---- C:\Windows\system32\spp.dll
2011-06-14 11:30:39 ----A---- C:\Windows\system32\QSHVHOST.DLL
2011-06-14 11:30:39 ----A---- C:\Windows\system32\netid.dll
2011-06-14 11:30:39 ----A---- C:\Windows\system32\inetpp.dll
2011-06-14 11:30:39 ----A---- C:\Windows\system32\drivers\fltMgr.sys
2011-06-14 11:30:39 ----A---- C:\Windows\system32\davclnt.dll
2011-06-14 11:30:39 ----A---- C:\Windows\system32\cscui.dll
2011-06-14 11:30:39 ----A---- C:\Windows\system32\biocpl.dll
2011-06-14 11:30:38 ----A---- C:\Windows\SYSWOW64\themeui.dll
2011-06-14 11:30:38 ----A---- C:\Windows\SYSWOW64\taskeng.exe
2011-06-14 11:30:38 ----A---- C:\Windows\SYSWOW64\spp.dll
2011-06-14 11:30:38 ----A---- C:\Windows\SYSWOW64\mswsock.dll
2011-06-14 11:30:38 ----A---- C:\Windows\SYSWOW64\dhcpcore.dll
2011-06-14 11:30:38 ----A---- C:\Windows\SYSWOW64\credui.dll
2011-06-14 11:30:38 ----A---- C:\Windows\system32\wusa.exe
2011-06-14 11:30:38 ----A---- C:\Windows\system32\scansetting.dll
2011-06-14 11:30:38 ----A---- C:\Windows\system32\profsvc.dll
2011-06-14 11:30:38 ----A---- C:\Windows\system32\printui.dll
2011-06-14 11:30:38 ----A---- C:\Windows\system32\pla.dll
2011-06-14 11:30:38 ----A---- C:\Windows\system32\mspbda.dll
2011-06-14 11:30:38 ----A---- C:\Windows\system32\msinfo32.exe
2011-06-14 11:30:38 ----A---- C:\Windows\system32\gameux.dll
2011-06-14 11:30:38 ----A---- C:\Windows\system32\conhost.exe
2011-06-14 11:30:38 ----A---- C:\Windows\splwow64.exe
2011-06-14 11:30:37 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2011-06-14 11:30:37 ----A---- C:\Windows\SYSWOW64\NaturalLanguage6.dll
2011-06-14 11:30:37 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2011-06-14 11:30:37 ----A---- C:\Windows\SYSWOW64\mfreadwrite.dll
2011-06-14 11:30:37 ----A---- C:\Windows\SYSWOW64\dxgi.dll
2011-06-14 11:30:37 ----A---- C:\Windows\SYSWOW64\dbghelp.dll
2011-06-14 11:30:37 ----A---- C:\Windows\SYSWOW64\basecsp.dll
2011-06-14 11:30:37 ----A---- C:\Windows\system32\wiaservc.dll
2011-06-14 11:30:37 ----A---- C:\Windows\system32\vds.exe
2011-06-14 11:30:37 ----A---- C:\Windows\system32\rpchttp.dll
2011-06-14 11:30:37 ----A---- C:\Windows\system32\msdri.dll
2011-06-14 11:30:37 ----A---- C:\Windows\system32\mscms.dll
2011-06-14 11:30:37 ----A---- C:\Windows\system32\IPHLPAPI.DLL
2011-06-14 11:30:37 ----A---- C:\Windows\system32\FirewallControlPanel.dll
2011-06-14 11:30:37 ----A---- C:\Windows\system32\drivers\pci.sys
2011-06-14 11:30:37 ----A---- C:\Windows\system32\cryptsvc.dll
2011-06-14 11:30:37 ----A---- C:\Windows\system32\aitagent.exe
2011-06-14 11:30:37 ----A---- C:\Windows\system32\AdmTmpl.dll
2011-06-14 11:30:36 ----A---- C:\Windows\SYSWOW64\WinSATAPI.dll
2011-06-14 11:30:36 ----A---- C:\Windows\SYSWOW64\taskcomp.dll
2011-06-14 11:30:36 ----A---- C:\Windows\SYSWOW64\evr.dll
2011-06-14 11:30:36 ----A---- C:\Windows\SYSWOW64\calc.exe
2011-06-14 11:30:36 ----A---- C:\Windows\system32\XpsRasterService.dll
2011-06-14 11:30:36 ----A---- C:\Windows\system32\wisptis.exe
2011-06-14 11:30:36 ----A---- C:\Windows\system32\sppwinob.dll
2011-06-14 11:30:36 ----A---- C:\Windows\system32\rdpcore.dll
2011-06-14 11:30:36 ----A---- C:\Windows\system32\ocsetup.exe
2011-06-14 11:30:36 ----A---- C:\Windows\system32\ocsetapi.dll
2011-06-14 11:30:36 ----A---- C:\Windows\system32\msi.dll
2011-06-14 11:30:36 ----A---- C:\Windows\system32\DXP.dll
2011-06-14 11:30:36 ----A---- C:\Windows\system32\drivers\volmgr.sys
2011-06-14 11:30:36 ----A---- C:\Windows\system32\drivers\rasl2tp.sys
2011-06-14 11:30:36 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2011-06-14 11:30:36 ----A---- C:\Windows\system32\cfgmgr32.dll
2011-06-14 11:30:35 ----A---- C:\Windows\SYSWOW64\UIRibbon.dll
2011-06-14 11:30:35 ----A---- C:\Windows\SYSWOW64\sqlsrv32.dll
2011-06-14 11:30:35 ----A---- C:\Windows\system32\wpdbusenum.dll
2011-06-14 11:30:35 ----A---- C:\Windows\system32\wcncsvc.dll
2011-06-14 11:30:35 ----A---- C:\Windows\system32\upnp.dll
2011-06-14 11:30:35 ----A---- C:\Windows\system32\Robocopy.exe
2011-06-14 11:30:35 ----A---- C:\Windows\system32\ntshrui.dll
2011-06-14 11:30:35 ----A---- C:\Windows\system32\mprapi.dll
2011-06-14 11:30:35 ----A---- C:\Windows\system32\eapphost.dll
2011-06-14 11:30:35 ----A---- C:\Windows\system32\eapp3hst.dll
2011-06-14 11:30:35 ----A---- C:\Windows\system32\drivers\msdsm.sys
2011-06-14 11:30:35 ----A---- C:\Windows\system32\ci.dll
2011-06-14 11:30:34 ----A---- C:\Windows\SYSWOW64\ws2_32.dll
2011-06-14 11:30:34 ----A---- C:\Windows\SYSWOW64\sxs.dll
2011-06-14 11:30:34 ----A---- C:\Windows\SYSWOW64\stobject.dll
2011-06-14 11:30:34 ----A---- C:\Windows\SYSWOW64\netshell.dll
2011-06-14 11:30:34 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2011-06-14 11:30:34 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2011-06-14 11:30:34 ----A---- C:\Windows\SYSWOW64\comctl32.dll
2011-06-14 11:30:34 ----A---- C:\Windows\system32\thumbcache.dll
2011-06-14 11:30:34 ----A---- C:\Windows\system32\t2embed.dll
2011-06-14 11:30:34 ----A---- C:\Windows\system32\sspicli.dll
2011-06-14 11:30:34 ----A---- C:\Windows\system32\scecli.dll
2011-06-14 11:30:34 ----A---- C:\Windows\system32\PerfCenterCPL.dll
2011-06-14 11:30:34 ----A---- C:\Windows\system32\MSMPEG2ENC.DLL
2011-06-14 11:30:34 ----A---- C:\Windows\system32\msasn1.dll
2011-06-14 11:30:34 ----A---- C:\Windows\system32\hal.dll
2011-06-14 11:30:34 ----A---- C:\Windows\system32\DxpTaskSync.dll
2011-06-14 11:30:34 ----A---- C:\Windows\system32\dwmredir.dll
2011-06-14 11:30:34 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2011-06-14 11:30:34 ----A---- C:\Windows\system32\drivers\HpSAMD.sys
2011-06-14 11:30:34 ----A---- C:\Windows\system32\drivers\fvevol.sys
2011-06-14 11:30:34 ----A---- C:\Windows\system32\drivers\Classpnp.sys
2011-06-14 11:30:33 ----A---- C:\Windows\SYSWOW64\WSDApi.dll
2011-06-14 11:30:33 ----A---- C:\Windows\SYSWOW64\wmpeffects.dll
2011-06-14 11:30:33 ----A---- C:\Windows\SYSWOW64\rpchttp.dll
2011-06-14 11:30:33 ----A---- C:\Windows\SYSWOW64\prncache.dll
2011-06-14 11:30:33 ----A---- C:\Windows\SYSWOW64\printui.dll
2011-06-14 11:30:33 ----A---- C:\Windows\SYSWOW64\net1.exe
2011-06-14 11:30:33 ----A---- C:\Windows\SYSWOW64\msi.dll
2011-06-14 11:30:33 ----A---- C:\Windows\system32\themeui.dll
2011-06-14 11:30:33 ----A---- C:\Windows\system32\scrptadm.dll
2011-06-14 11:30:33 ----A---- C:\Windows\system32\puiobj.dll
2011-06-14 11:30:33 ----A---- C:\Windows\system32\onex.dll
2011-06-14 11:30:33 ----A---- C:\Windows\system32\nlaapi.dll
2011-06-14 11:30:33 ----A---- C:\Windows\system32\iasrad.dll
2011-06-14 11:30:33 ----A---- C:\Windows\system32\DXPTaskRingtone.dll
2011-06-14 11:30:33 ----A---- C:\Windows\system32\drivers\ipfltdrv.sys
2011-06-14 11:30:33 ----A---- C:\Windows\system32\aaclient.dll
2011-06-14 11:30:32 ----A---- C:\Windows\SYSWOW64\scansetting.dll
2011-06-14 11:30:32 ----A---- C:\Windows\SYSWOW64\MMDevAPI.dll
2011-06-14 11:30:32 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2011-06-14 11:30:32 ----A---- C:\Windows\system32\wscapi.dll
2011-06-14 11:30:32 ----A---- C:\Windows\system32\wow64.dll
2011-06-14 11:30:32 ----A---- C:\Windows\system32\wlangpui.dll
2011-06-14 11:30:32 ----A---- C:\Windows\system32\wiadefui.dll
2011-06-14 11:30:32 ----A---- C:\Windows\system32\wdc.dll
2011-06-14 11:30:32 ----A---- C:\Windows\system32\VAN.dll
2011-06-14 11:30:32 ----A---- C:\Windows\system32\StructuredQuery.dll
2011-06-14 11:30:32 ----A---- C:\Windows\system32\SndVol.exe
2011-06-14 11:30:32 ----A---- C:\Windows\system32\sdengin2.dll
2011-06-14 11:30:32 ----A---- C:\Windows\system32\scesrv.dll
2011-06-14 11:30:32 ----A---- C:\Windows\system32\samcli.dll
2011-06-14 11:30:32 ----A---- C:\Windows\system32\rasmans.dll
2011-06-14 11:30:32 ----A---- C:\Windows\system32\netcenter.dll
2011-06-14 11:30:32 ----A---- C:\Windows\system32\msftedit.dll
2011-06-14 11:30:32 ----A---- C:\Windows\system32\dskquoui.dll
2011-06-14 11:30:32 ----A---- C:\Windows\system32\drivers\partmgr.sys
2011-06-14 11:30:32 ----A---- C:\Windows\system32\drivers\ndiswan.sys
2011-06-14 11:30:31 ----A---- C:\Windows\SYSWOW64\WMVCORE.DLL
2011-06-14 11:30:31 ----A---- C:\Windows\SYSWOW64\wlangpui.dll
2011-06-14 11:30:31 ----A---- C:\Windows\SYSWOW64\t2embed.dll
2011-06-14 11:30:31 ----A---- C:\Windows\SYSWOW64\QSHVHOST.DLL
2011-06-14 11:30:31 ----A---- C:\Windows\SYSWOW64\pnidui.dll
2011-06-14 11:30:31 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2011-06-14 11:30:31 ----A---- C:\Windows\system32\wucltux.dll
2011-06-14 11:30:31 ----A---- C:\Windows\system32\TabSvc.dll
2011-06-14 11:30:31 ----A---- C:\Windows\system32\srchadmin.dll
2011-06-14 11:30:31 ----A---- C:\Windows\system32\regapi.dll
2011-06-14 11:30:31 ----A---- C:\Windows\system32\QUTIL.DLL
2011-06-14 11:30:31 ----A---- C:\Windows\system32\iasacct.dll
2011-06-14 11:30:31 ----A---- C:\Windows\system32\drivers\termdd.sys
2011-06-14 11:30:31 ----A---- C:\Windows\system32\consent.exe
2011-06-14 11:30:30 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2011-06-14 11:30:30 ----A---- C:\Windows\SYSWOW64\wscapi.dll
2011-06-14 11:30:30 ----A---- C:\Windows\SYSWOW64\wpdshext.dll
2011-06-14 11:30:30 ----A---- C:\Windows\SYSWOW64\webservices.dll
2011-06-14 11:30:30 ----A---- C:\Windows\SYSWOW64\SyncCenter.dll
2011-06-14 11:30:30 ----A---- C:\Windows\SYSWOW64\scrptadm.dll
2011-06-14 11:30:30 ----A---- C:\Windows\SYSWOW64\netdiagfx.dll
2011-06-14 11:30:30 ----A---- C:\Windows\SYSWOW64\fde.dll
2011-06-14 11:30:30 ----A---- C:\Windows\system32\WUDFSvc.dll
2011-06-14 11:30:30 ----A---- C:\Windows\system32\wksprt.exe
2011-06-14 11:30:30 ----A---- C:\Windows\system32\taskhost.exe
2011-06-14 11:30:30 ----A---- C:\Windows\system32\setupcl.exe
2011-06-14 11:30:30 ----A---- C:\Windows\system32\rastls.dll
2011-06-14 11:30:30 ----A---- C:\Windows\system32\drivers\msahci.sys
2011-06-14 11:30:30 ----A---- C:\Windows\system32\drivers\acpi.sys
2011-06-14 11:30:29 ----A---- C:\Windows\SYSWOW64\WinSCard.dll
2011-06-14 11:30:29 ----A---- C:\Windows\SYSWOW64\pla.dll
2011-06-14 11:30:29 ----A---- C:\Windows\SYSWOW64\msasn1.dll
2011-06-14 11:30:29 ----A---- C:\Windows\SYSWOW64\cscobj.dll
2011-06-14 11:30:29 ----A---- C:\Windows\system32\tapisrv.dll
2011-06-14 11:30:29 ----A---- C:\Windows\system32\netiohlp.dll
2011-06-14 11:30:29 ----A---- C:\Windows\system32\msconfig.exe
2011-06-14 11:30:29 ----A---- C:\Windows\system32\mimefilt.dll
2011-06-14 11:30:29 ----A---- C:\Windows\system32\lsmproxy.dll
2011-06-14 11:30:29 ----A---- C:\Windows\system32\ListSvc.dll
2011-06-14 11:30:29 ----A---- C:\Windows\system32\hgcpl.dll
2011-06-14 11:30:29 ----A---- C:\Windows\system32\fdeploy.dll
2011-06-14 11:30:29 ----A---- C:\Windows\system32\drivers\raspptp.sys
2011-06-14 11:30:29 ----A---- C:\Windows\system32\drivers\ks.sys
2011-06-14 11:30:29 ----A---- C:\Windows\system32\clusapi.dll
2011-06-14 11:30:29 ----A---- C:\Windows\system32\basecsp.dll
2011-06-14 11:30:28 ----A---- C:\Windows\SYSWOW64\winsta.dll
2011-06-14 11:30:28 ----A---- C:\Windows\SYSWOW64\rdpcore.dll
2011-06-14 11:30:28 ----A---- C:\Windows\SYSWOW64\ntshrui.dll
2011-06-14 11:30:28 ----A---- C:\Windows\SYSWOW64\MSMPEG2ENC.DLL
2011-06-14 11:30:28 ----A---- C:\Windows\SYSWOW64\imapi2.dll
2011-06-14 11:30:28 ----A---- C:\Windows\SYSWOW64\gameux.dll
2011-06-14 11:30:28 ----A---- C:\Windows\SYSWOW64\DXPTaskRingtone.dll
2011-06-14 11:30:28 ----A---- C:\Windows\system32\TsUsbGDCoInstaller.dll
2011-06-14 11:30:28 ----A---- C:\Windows\system32\RpcRtRemote.dll
2011-06-14 11:30:28 ----A---- C:\Windows\system32\riched20.dll
2011-06-14 11:30:28 ----A---- C:\Windows\system32\mtxclu.dll
2011-06-14 11:30:28 ----A---- C:\Windows\system32\drivers\sbp2port.sys
2011-06-14 11:30:28 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2011-06-14 11:30:28 ----A---- C:\Windows\system32\dnscmmc.dll
2011-06-14 11:30:28 ----A---- C:\Windows\system32\AuxiliaryDisplayCpl.dll
2011-06-14 11:30:27 ----A---- C:\Windows\SYSWOW64\WMPEncEn.dll
2011-06-14 11:30:27 ----A---- C:\Windows\SYSWOW64\winmm.dll
2011-06-14 11:30:27 ----A---- C:\Windows\SYSWOW64\shsvcs.dll
2011-06-14 11:30:27 ----A---- C:\Windows\SYSWOW64\onex.dll
2011-06-14 11:30:27 ----A---- C:\Windows\SYSWOW64\hbaapi.dll
2011-06-14 11:30:27 ----A---- C:\Windows\SYSWOW64\autofmt.exe
2011-06-14 11:30:27 ----A---- C:\Windows\system32\themecpl.dll
2011-06-14 11:30:27 ----A---- C:\Windows\system32\sharemediacpl.dll
2011-06-14 11:30:27 ----A---- C:\Windows\system32\SensorsCpl.dll
2011-06-14 11:30:27 ----A---- C:\Windows\system32\powercpl.dll
2011-06-14 11:30:27 ----A---- C:\Windows\system32\netjoin.dll
2011-06-14 11:30:27 ----A---- C:\Windows\system32\nci.dll
2011-06-14 11:30:27 ----A---- C:\Windows\system32\logoncli.dll
2011-06-14 11:30:27 ----A---- C:\Windows\system32\Faultrep.dll
2011-06-14 11:30:27 ----A---- C:\Windows\system32\eudcedit.exe
2011-06-14 11:30:26 ----A---- C:\Windows\SYSWOW64\thumbcache.dll
2011-06-14 11:30:26 ----A---- C:\Windows\SYSWOW64\samcli.dll
2011-06-14 11:30:26 ----A---- C:\Windows\SYSWOW64\regapi.dll
2011-06-14 11:30:26 ----A---- C:\Windows\SYSWOW64\proquota.exe
2011-06-14 11:30:26 ----A---- C:\Windows\SYSWOW64\netiohlp.dll
2011-06-14 11:30:26 ----A---- C:\Windows\SYSWOW64\msutb.dll
2011-06-14 11:30:26 ----A---- C:\Windows\SYSWOW64\msinfo32.exe
2011-06-14 11:30:26 ----A---- C:\Windows\SYSWOW64\mimefilt.dll
2011-06-14 11:30:26 ----A---- C:\Windows\SYSWOW64\ipsmsnap.dll
2011-06-14 11:30:26 ----A---- C:\Windows\SYSWOW64\IPHLPAPI.DLL
2011-06-14 11:30:26 ----A---- C:\Windows\SYSWOW64\autochk.exe
2011-06-14 11:30:26 ----A---- C:\Windows\SYSWOW64\autoconv.exe
2011-06-14 11:30:26 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2011-06-14 11:30:26 ----A---- C:\Windows\system32\wkssvc.dll
2011-06-14 11:30:26 ----A---- C:\Windows\system32\vpnikeapi.dll
2011-06-14 11:30:26 ----A---- C:\Windows\system32\sppcomapi.dll
2011-06-14 11:30:26 ----A---- C:\Windows\system32\nshipsec.dll
2011-06-14 11:30:26 ----A---- C:\Windows\system32\Narrator.exe
2011-06-14 11:30:26 ----A---- C:\Windows\system32\fms.dll
2011-06-14 11:30:26 ----A---- C:\Windows\system32\comctl32.dll
2011-06-14 11:30:26 ----A---- C:\Windows\system32\cabview.dll
2011-06-14 11:30:26 ----A---- C:\Windows\system32\autochk.exe
2011-06-14 11:30:26 ----A---- C:\Windows\system32\autofmt.exe
2011-06-14 11:30:26 ----A---- C:\Windows\system32\autoconv.exe
2011-06-14 11:30:26 ----A---- C:\Windows\system32\audiodg.exe
2011-06-14 11:30:25 ----A---- C:\Windows\SYSWOW64\wcncsvc.dll
2011-06-14 11:30:25 ----A---- C:\Windows\SYSWOW64\tcpipcfg.dll
2011-06-14 11:30:25 ----A---- C:\Windows\SYSWOW64\srchadmin.dll
2011-06-14 11:30:25 ----A---- C:\Windows\SYSWOW64\schtasks.exe
2011-06-14 11:30:25 ----A---- C:\Windows\SYSWOW64\powercpl.dll
2011-06-14 11:30:25 ----A---- C:\Windows\SYSWOW64\msihnd.dll
2011-06-14 11:30:25 ----A---- C:\Windows\SYSWOW64\mscorier.dll
Run by WoMec at 2011-07-04 00:49:44
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 28 GB (28%) free of 102 GB
Total RAM: 4094 MB (56% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 0:49:52, on 4.7.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\QIP 2010\qip.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files\trend micro\WoMec.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Infium] "C:\Program Files (x86)\QIP 2010\qip.exe"m Files (x
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\Microsoft Office\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\Spybot - Search & Destroy\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} (Java Plug-in 1.6.0_20) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{6B2110FC-4F70-4EF9-9C8E-5A9E9215E9AA}: NameServer = 94.199.199.192,94.199.199.199
O18 - Protocol: brx - {9C160F90-74D1-11D3-AB60-0060977C1F29} - (no file)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\Skype4COM.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Autodata Limited License Service - Autodata Limited - C:\Program Files (x86)\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies, Inc. - C:\Program Files (x86)\WinPcap\rpcapd.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9124 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
"C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe"
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s
C:\Windows\system32\svchost.exe -k bthaudiosvc
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"taskhost.exe"
C:\Windows\Explorer.EXE
"C:\Windows\system32\Dwm.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Windows\System32\rundll32.exe" sbavmon.dll,SBAVMonitor
"C:\Program Files (x86)\MagicTune Premium\MagicTuneEngine.exe"
"C:\Windows\WindowsMobile\wmdc.exe"
"C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe"
"C:\Program Files (x86)\QIP 2010\qip.exe" m Files (x
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
WLIDSvcM.exe 640
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\MagicTune Premium\MagicTune.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\svchost.exe -k secsvcs
"taskhost.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 524 528 536 65536 532
C:\Windows\System32\svchost.exe -k WerSvcGroup
"C:\Users\WoMec\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-04-20 43520]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~2\Spybot - Search & Destroy\SDHelper.dll [2009-01-26 1879896]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-05-19 41760]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2009-12-08 9642528]
"Creative SB Monitoring Utility"=RunDll32 sbavmon.dll,SBAVMonitor []
"MagicTuneEngine"=C:\Program Files (x86)\MagicTune Premium\MagicTuneEngine.exe [2009-06-15 24064]
"Windows Mobile Device Center"=C:\Windows\WindowsMobile\wmdc.exe [2007-05-31 660360]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"=C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]
"Infium"=C:\Program Files (x86)\QIP 2010\qip.exe [2011-06-24 6804864]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2011-05-25 1951112]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe [2010-11-10 4240760]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2011-01-07 253672]
"LogMeIn Hamachi Ui"=C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2011-05-25 1951112]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
GoogleUpdateTaskMachineCore.job
GoogleUpdateTaskMachineUA.job
SA.DAT
SCHEDLGU.TXT
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2011-05-07 249344]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
FencesShellExt - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files (x86)\Stardock\Fences\FencesMenu64.dll [2009-10-02 134656]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecure"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 months======
2011-07-04 00:48:11 ----D---- C:\rsit
2011-07-03 23:44:54 ----SHD---- C:\$RECYCLE.BIN
2011-07-03 23:33:33 ----A---- C:\Windows\zip.exe
2011-07-03 23:33:33 ----A---- C:\Windows\SWSC.exe
2011-07-03 23:33:33 ----A---- C:\Windows\SWREG.exe
2011-07-03 23:33:33 ----A---- C:\Windows\sed.exe
2011-07-03 23:33:33 ----A---- C:\Windows\PEV.exe
2011-07-03 23:33:33 ----A---- C:\Windows\NIRCMD.exe
2011-07-03 23:33:33 ----A---- C:\Windows\MBR.exe
2011-07-03 23:33:33 ----A---- C:\Windows\grep.exe
2011-07-03 23:33:25 ----D---- C:\Windows\ERDNT
2011-07-03 22:52:21 ----D---- C:\Users\WoMec\AppData\Roaming\Wireshark
2011-07-03 22:36:25 ----D---- C:\Program Files\Wireshark
2011-07-03 22:18:54 ----D---- C:\Program Files\trend micro
2011-07-03 17:42:25 ----D---- C:\Program Files (x86)\Spyware Terminator
2011-07-03 17:27:38 ----A---- C:\Windows\ScanSpyware.INI
2011-07-03 17:18:49 ----D---- C:\Users\WoMec\AppData\Roaming\ScanSpyware
2011-07-03 17:11:08 ----D---- C:\Windows\InstallDir
2011-07-03 16:38:07 ----D---- C:\Users\WoMec\AppData\Roaming\Malwarebytes
2011-07-03 16:37:58 ----A---- C:\Windows\system32\drivers\mbam.sys
2011-06-29 14:41:28 ----A---- C:\Windows\SYSWOW64\drvinst.exe
2011-06-29 14:41:28 ----A---- C:\Windows\SYSWOW64\devrtl.dll
2011-06-29 14:41:28 ----A---- C:\Windows\SYSWOW64\devobj.dll
2011-06-29 14:41:28 ----A---- C:\Windows\SYSWOW64\cfgmgr32.dll
2011-06-29 14:41:28 ----A---- C:\Windows\system32\umpnpmgr.dll
2011-06-29 14:41:21 ----A---- C:\Windows\SYSWOW64\tquery.dll
2011-06-29 14:41:21 ----A---- C:\Windows\SYSWOW64\SearchProtocolHost.exe
2011-06-29 14:41:21 ----A---- C:\Windows\SYSWOW64\SearchIndexer.exe
2011-06-29 14:41:21 ----A---- C:\Windows\SYSWOW64\SearchFilterHost.exe
2011-06-29 14:41:21 ----A---- C:\Windows\SYSWOW64\mssvp.dll
2011-06-29 14:41:21 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2011-06-29 14:41:21 ----A---- C:\Windows\SYSWOW64\mssphtb.dll
2011-06-29 14:41:21 ----A---- C:\Windows\SYSWOW64\mssph.dll
2011-06-29 14:41:21 ----A---- C:\Windows\system32\tquery.dll
2011-06-29 14:41:21 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2011-06-29 14:41:21 ----A---- C:\Windows\system32\SearchIndexer.exe
2011-06-29 14:41:21 ----A---- C:\Windows\system32\SearchFilterHost.exe
2011-06-29 14:41:21 ----A---- C:\Windows\system32\mssvp.dll
2011-06-29 14:41:21 ----A---- C:\Windows\system32\mssrch.dll
2011-06-29 14:41:21 ----A---- C:\Windows\system32\mssphtb.dll
2011-06-29 14:41:21 ----A---- C:\Windows\system32\mssph.dll
2011-06-29 14:41:21 ----A---- C:\Windows\system32\msscntrs.dll
2011-06-29 14:41:20 ----A---- C:\Windows\SYSWOW64\msscntrs.dll
2011-06-21 13:25:30 ----D---- C:\Windows\C5C1C0F0D62F4DBF81D4D7EF397C228B.TMP
2011-06-15 14:40:12 ----D---- C:\Program Files (x86)\Activision
2011-06-15 11:22:43 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-06-15 11:22:43 ----A---- C:\Windows\system32\mshtmled.dll
2011-06-15 11:22:42 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-06-15 11:22:42 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-06-15 11:22:42 ----A---- C:\Windows\system32\iertutil.dll
2011-06-15 11:22:41 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-06-15 11:22:41 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2011-06-15 11:22:41 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-06-15 11:22:41 ----A---- C:\Windows\system32\urlmon.dll
2011-06-15 11:22:41 ----A---- C:\Windows\system32\jscript9.dll
2011-06-15 11:22:41 ----A---- C:\Windows\system32\jscript.dll
2011-06-15 11:22:41 ----A---- C:\Windows\system32\ieui.dll
2011-06-15 11:22:40 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-06-15 11:22:39 ----A---- C:\Windows\system32\mshtml.dll
2011-06-15 11:22:38 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-06-15 11:22:38 ----A---- C:\Windows\system32\ieframe.dll
2011-06-15 11:10:38 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2011-06-15 11:10:38 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-06-15 11:10:38 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2011-06-15 11:10:18 ----A---- C:\Windows\system32\win32k.sys
2011-06-15 11:10:12 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-06-15 11:10:12 ----A---- C:\Windows\system32\drivers\afd.sys
2011-06-15 11:09:55 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-06-15 11:09:55 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-06-15 11:09:55 ----A---- C:\Windows\system32\drivers\srv.sys
2011-06-15 11:09:19 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2011-06-15 11:09:19 ----A---- C:\Windows\system32\inetcomm.dll
2011-06-15 11:09:17 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2011-06-15 11:09:17 ----A---- C:\Windows\system32\oleaut32.dll
2011-06-14 11:35:13 ----D---- C:\Windows\system32\SPReview
2011-06-14 11:33:58 ----D---- C:\Windows\system32\EventProviders
2011-06-14 11:31:24 ----A---- C:\Windows\system32\netfxperf.dll
2011-06-14 11:31:24 ----A---- C:\Windows\system32\dfshim.dll
2011-06-14 11:31:18 ----A---- C:\Windows\SYSWOW64\dfshim.dll
2011-06-14 11:31:15 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2011-06-14 11:31:15 ----A---- C:\Windows\system32\mstscax.dll
2011-06-14 11:31:15 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2011-06-14 11:31:15 ----A---- C:\Windows\system32\d3d10warp.dll
2011-06-14 11:31:13 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2011-06-14 11:31:11 ----A---- C:\Windows\SYSWOW64\mfc40u.dll
2011-06-14 11:31:11 ----A---- C:\Windows\SYSWOW64\mfc40.dll
2011-06-14 11:31:11 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2011-06-14 11:31:11 ----A---- C:\Windows\system32\sysmain.dll
2011-06-14 11:31:10 ----A---- C:\Windows\SYSWOW64\pmcsnap.dll
2011-06-14 11:31:10 ----A---- C:\Windows\system32\shell32.dll
2011-06-14 11:31:10 ----A---- C:\Windows\system32\MSVidCtl.dll
2011-06-14 11:31:09 ----A---- C:\Windows\system32\wmp.dll
2011-06-14 11:31:08 ----A---- C:\Windows\system32\ntdll.dll
2011-06-14 11:31:08 ----A---- C:\Windows\system32\mscoree.dll
2011-06-14 11:31:08 ----A---- C:\Windows\system32\mmcndmgr.dll
2011-06-14 11:31:07 ----A---- C:\Windows\system32\secproc_isv.dll
2011-06-14 11:31:07 ----A---- C:\Windows\system32\RMActivate_isv.exe
2011-06-14 11:31:07 ----A---- C:\Windows\system32\mf.dll
2011-06-14 11:31:06 ----A---- C:\Windows\SYSWOW64\shell32.dll
2011-06-14 11:31:06 ----A---- C:\Windows\SYSWOW64\secproc_isv.dll
2011-06-14 11:31:06 ----A---- C:\Windows\SYSWOW64\secproc.dll
2011-06-14 11:31:06 ----A---- C:\Windows\SYSWOW64\RMActivate_isv.exe
2011-06-14 11:31:06 ----A---- C:\Windows\system32\xpsservices.dll
2011-06-14 11:31:06 ----A---- C:\Windows\system32\secproc.dll
2011-06-14 11:31:06 ----A---- C:\Windows\system32\rpcrt4.dll
2011-06-14 11:31:06 ----A---- C:\Windows\system32\RMActivate.exe
2011-06-14 11:31:05 ----A---- C:\Windows\SYSWOW64\RMActivate.exe
2011-06-14 11:31:05 ----A---- C:\Windows\SYSWOW64\PushPrinterConnections.exe
2011-06-14 11:31:05 ----A---- C:\Windows\SYSWOW64\ppcsnap.dll
2011-06-14 11:31:05 ----A---- C:\Windows\system32\schedsvc.dll
2011-06-14 11:31:05 ----A---- C:\Windows\system32\ole32.dll
2011-06-14 11:31:04 ----A---- C:\Windows\SYSWOW64\mscoree.dll
2011-06-14 11:31:04 ----A---- C:\Windows\system32\spwizui.dll
2011-06-14 11:31:03 ----A---- C:\Windows\SYSWOW64\mf.dll
2011-06-14 11:31:03 ----A---- C:\Windows\system32\wevtsvc.dll
2011-06-14 11:31:03 ----A---- C:\Windows\system32\taskschd.dll
2011-06-14 11:31:03 ----A---- C:\Windows\system32\RacEngn.dll
2011-06-14 11:31:03 ----A---- C:\Windows\system32\ExplorerFrame.dll
2011-06-14 11:31:03 ----A---- C:\Windows\system32\diagperf.dll
2011-06-14 11:31:02 ----A---- C:\Windows\SYSWOW64\CertEnroll.dll
2011-06-14 11:31:02 ----A---- C:\Windows\system32\vssapi.dll
2011-06-14 11:31:02 ----A---- C:\Windows\system32\UIRibbon.dll
2011-06-14 11:31:02 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2011-06-14 11:31:02 ----A---- C:\Windows\system32\msxml3.dll
2011-06-14 11:31:02 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2011-06-14 11:31:02 ----A---- C:\Windows\system32\drivers\msiscsi.sys
2011-06-14 11:31:01 ----A---- C:\Windows\SYSWOW64\wmp.dll
2011-06-14 11:31:00 ----A---- C:\Windows\SYSWOW64\PresentationHostProxy.dll
2011-06-14 11:31:00 ----A---- C:\Windows\SYSWOW64\PresentationHost.exe
2011-06-14 11:31:00 ----A---- C:\Windows\system32\WsmSvc.dll
2011-06-14 11:31:00 ----A---- C:\Windows\system32\WMVCORE.DLL
2011-06-14 11:31:00 ----A---- C:\Windows\system32\spreview.exe
2011-06-14 11:31:00 ----A---- C:\Windows\system32\rdpdd.dll
2011-06-14 11:31:00 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2011-06-14 11:31:00 ----A---- C:\Windows\system32\PresentationHost.exe
2011-06-14 11:31:00 ----A---- C:\Windows\system32\MPSSVC.dll
2011-06-14 11:30:59 ----A---- C:\Windows\system32\WinSAT.exe
2011-06-14 11:30:59 ----A---- C:\Windows\system32\spinstall.exe
2011-06-14 11:30:59 ----A---- C:\Windows\system32\CertEnroll.dll
2011-06-14 11:30:58 ----A---- C:\Windows\SYSWOW64\RacEngn.dll
2011-06-14 11:30:58 ----A---- C:\Windows\system32\WMVDECOD.DLL
2011-06-14 11:30:58 ----A---- C:\Windows\system32\SearchFolder.dll
2011-06-14 11:30:58 ----A---- C:\Windows\system32\msxml6.dll
2011-06-14 11:30:58 ----A---- C:\Windows\system32\IKEEXT.DLL
2011-06-14 11:30:58 ----A---- C:\Windows\system32\d3d9.dll
2011-06-14 11:30:58 ----A---- C:\Windows\system32\AuthFWSnapin.dll
2011-06-14 11:30:57 ----A---- C:\Windows\SYSWOW64\AuthFWSnapin.dll
2011-06-14 11:30:57 ----A---- C:\Windows\system32\VSSVC.exe
2011-06-14 11:30:57 ----A---- C:\Windows\system32\kernel32.dll
2011-06-14 11:30:57 ----A---- C:\Windows\system32\gpsvc.dll
2011-06-14 11:30:57 ----A---- C:\Windows\system32\dwmcore.dll
2011-06-14 11:30:57 ----A---- C:\Windows\system32\dbgeng.dll
2011-06-14 11:30:56 ----A---- C:\Windows\system32\drivers\ndis.sys
2011-06-14 11:30:56 ----A---- C:\Windows\system32\drivers\http.sys
2011-06-14 11:30:56 ----A---- C:\Windows\system32\crypt32.dll
2011-06-14 11:30:55 ----A---- C:\Windows\SYSWOW64\ole32.dll
2011-06-14 11:30:55 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2011-06-14 11:30:55 ----A---- C:\Windows\system32\TSWorkspace.dll
2011-06-14 11:30:55 ----A---- C:\Windows\system32\schannel.dll
2011-06-14 11:30:55 ----A---- C:\Windows\system32\qmgr.dll
2011-06-14 11:30:55 ----A---- C:\Windows\system32\lsasrv.dll
2011-06-14 11:30:55 ----A---- C:\Windows\system32\KernelBase.dll
2011-06-14 11:30:55 ----A---- C:\Windows\system32\audiosrv.dll
2011-06-14 11:30:55 ----A---- C:\Windows\system32\actxprxy.dll
2011-06-14 11:30:54 ----A---- C:\Windows\system32\termsrv.dll
2011-06-14 11:30:54 ----A---- C:\Windows\system32\sqmapi.dll
2011-06-14 11:30:54 ----A---- C:\Windows\system32\mstsc.exe
2011-06-14 11:30:54 ----A---- C:\Windows\system32\imapi2fs.dll
2011-06-14 11:30:54 ----A---- C:\Windows\system32\gpprefcl.dll
2011-06-14 11:30:53 ----A---- C:\Windows\SYSWOW64\vssapi.dll
2011-06-14 11:30:53 ----A---- C:\Windows\SYSWOW64\SearchFolder.dll
2011-06-14 11:30:53 ----A---- C:\Windows\SYSWOW64\d3d9.dll
2011-06-14 11:30:53 ----A---- C:\Windows\system32\winhttp.dll
2011-06-14 11:30:53 ----A---- C:\Windows\system32\setupapi.dll
2011-06-14 11:30:53 ----A---- C:\Windows\system32\QAGENTRT.DLL
2011-06-14 11:30:53 ----A---- C:\Windows\system32\propsys.dll
2011-06-14 11:30:53 ----A---- C:\Windows\system32\netlogon.dll
2011-06-14 11:30:53 ----A---- C:\Windows\system32\msv1_0.dll
2011-06-14 11:30:53 ----A---- C:\Windows\system32\d3d11.dll
2011-06-14 11:30:52 ----A---- C:\Windows\SYSWOW64\taskschd.dll
2011-06-14 11:30:52 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2011-06-14 11:30:52 ----A---- C:\Windows\system32\werconcpl.dll
2011-06-14 11:30:52 ----A---- C:\Windows\system32\wbengine.exe
2011-06-14 11:30:52 ----A---- C:\Windows\system32\user32.dll
2011-06-14 11:30:52 ----A---- C:\Windows\system32\taskeng.exe
2011-06-14 11:30:52 ----A---- C:\Windows\system32\rpcss.dll
2011-06-14 11:30:52 ----A---- C:\Windows\system32\PushPrinterConnections.exe
2011-06-14 11:30:52 ----A---- C:\Windows\system32\odbc32.dll
2011-06-14 11:30:52 ----A---- C:\Windows\system32\authui.dll
2011-06-14 11:30:51 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2011-06-14 11:30:51 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2011-06-14 11:30:51 ----A---- C:\Windows\system32\WSDApi.dll
2011-06-14 11:30:51 ----A---- C:\Windows\system32\umrdp.dll
2011-06-14 11:30:51 ----A---- C:\Windows\system32\scavengeui.dll
2011-06-14 11:30:51 ----A---- C:\Windows\system32\drivers\tdx.sys
2011-06-14 11:30:51 ----A---- C:\Windows\system32\drivers\netio.sys
2011-06-14 11:30:51 ----A---- C:\Windows\system32\drivers\netbt.sys
2011-06-14 11:30:51 ----A---- C:\Windows\system32\dhcpcore.dll
2011-06-14 11:30:51 ----A---- C:\Windows\system32\certmgr.dll
2011-06-14 11:30:50 ----A---- C:\Windows\SYSWOW64\wer.dll
2011-06-14 11:30:50 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2011-06-14 11:30:50 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2011-06-14 11:30:50 ----A---- C:\Windows\SYSWOW64\certcli.dll
2011-06-14 11:30:50 ----A---- C:\Windows\system32\webio.dll
2011-06-14 11:30:50 ----A---- C:\Windows\system32\tsmf.dll
2011-06-14 11:30:50 ----A---- C:\Windows\system32\shlwapi.dll
2011-06-14 11:30:50 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2011-06-14 11:30:50 ----A---- C:\Windows\system32\netshell.dll
2011-06-14 11:30:50 ----A---- C:\Windows\system32\ncsi.dll
2011-06-14 11:30:50 ----A---- C:\Windows\system32\msdtctm.dll
2011-06-14 11:30:50 ----A---- C:\Windows\system32\msdrm.dll
2011-06-14 11:30:50 ----A---- C:\Windows\system32\localspl.dll
2011-06-14 11:30:50 ----A---- C:\Windows\system32\framedynos.dll
2011-06-14 11:30:49 ----A---- C:\Windows\SYSWOW64\tcpmonui.dll
2011-06-14 11:30:49 ----A---- C:\Windows\SYSWOW64\odbc32.dll
2011-06-14 11:30:49 ----A---- C:\Windows\system32\ws2_32.dll
2011-06-14 11:30:49 ----A---- C:\Windows\system32\winlogon.exe
2011-06-14 11:30:49 ----A---- C:\Windows\system32\usp10.dll
2011-06-14 11:30:49 ----A---- C:\Windows\system32\quartz.dll
2011-06-14 11:30:49 ----A---- C:\Windows\system32\nlasvc.dll
2011-06-14 11:30:49 ----A---- C:\Windows\system32\netcfgx.dll
2011-06-14 11:30:49 ----A---- C:\Windows\system32\lsm.exe
2011-06-14 11:30:49 ----A---- C:\Windows\system32\drivers\cng.sys
2011-06-14 11:30:49 ----A---- C:\Windows\system32\comdlg32.dll
2011-06-14 11:30:49 ----A---- C:\Windows\system32\appmgr.dll
2011-06-14 11:30:48 ----A---- C:\Windows\SYSWOW64\winhttp.dll
2011-06-14 11:30:48 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2011-06-14 11:30:48 ----A---- C:\Windows\SYSWOW64\tsmf.dll
2011-06-14 11:30:48 ----A---- C:\Windows\SYSWOW64\setupapi.dll
2011-06-14 11:30:48 ----A---- C:\Windows\SYSWOW64\quartz.dll
2011-06-14 11:30:48 ----A---- C:\Windows\SYSWOW64\dot3api.dll
2011-06-14 11:30:48 ----A---- C:\Windows\system32\wpdshext.dll
2011-06-14 11:30:48 ----A---- C:\Windows\system32\wmpps.dll
2011-06-14 11:30:48 ----A---- C:\Windows\system32\Query.dll
2011-06-14 11:30:48 ----A---- C:\Windows\system32\QAGENT.DLL
2011-06-14 11:30:48 ----A---- C:\Windows\system32\mswsock.dll
2011-06-14 11:30:48 ----A---- C:\Windows\system32\dxgi.dll
2011-06-14 11:30:48 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2011-06-14 11:30:48 ----A---- C:\Windows\system32\drivers\csc.sys
2011-06-14 11:30:48 ----A---- C:\Windows\system32\BFE.DLL
2011-06-14 11:30:48 ----A---- C:\Windows\system32\azroles.dll
2011-06-14 11:30:48 ----A---- C:\Windows\system32\apphelp.dll
2011-06-14 11:30:47 ----A---- C:\Windows\SYSWOW64\MSVidCtl.dll
2011-06-14 11:30:47 ----A---- C:\Windows\SYSWOW64\dbgeng.dll
2011-06-14 11:30:47 ----A---- C:\Windows\SYSWOW64\apphelp.dll
2011-06-14 11:30:47 ----A---- C:\Windows\system32\win32spl.dll
2011-06-14 11:30:47 ----A---- C:\Windows\system32\Vault.dll
2011-06-14 11:30:47 ----A---- C:\Windows\system32\samsrv.dll
2011-06-14 11:30:47 ----A---- C:\Windows\system32\lpksetup.exe
2011-06-14 11:30:47 ----A---- C:\Windows\system32\DShowRdpFilter.dll
2011-06-14 11:30:47 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-06-14 11:30:47 ----A---- C:\Windows\system32\cmd.exe
2011-06-14 11:30:46 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2011-06-14 11:30:46 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2011-06-14 11:30:46 ----A---- C:\Windows\SYSWOW64\webio.dll
2011-06-14 11:30:46 ----A---- C:\Windows\SYSWOW64\netlogon.dll
2011-06-14 11:30:46 ----A---- C:\Windows\SYSWOW64\netcfgx.dll
2011-06-14 11:30:46 ----A---- C:\Windows\SYSWOW64\d3d11.dll
2011-06-14 11:30:46 ----A---- C:\Windows\system32\WindowsCodecs.dll
2011-06-14 11:30:46 ----A---- C:\Windows\system32\WebClnt.dll
2011-06-14 11:30:46 ----A---- C:\Windows\system32\rdpclip.exe
2011-06-14 11:30:46 ----A---- C:\Windows\system32\cscsvc.dll
2011-06-14 11:30:45 ----A---- C:\Windows\SYSWOW64\WsmSvc.dll
2011-06-14 11:30:45 ----A---- C:\Windows\SYSWOW64\upnp.dll
2011-06-14 11:30:45 ----A---- C:\Windows\SYSWOW64\Query.dll
2011-06-14 11:30:45 ----A---- C:\Windows\SYSWOW64\gpprefcl.dll
2011-06-14 11:30:45 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2011-06-14 11:30:45 ----A---- C:\Windows\system32\Wldap32.dll
2011-06-14 11:30:45 ----A---- C:\Windows\system32\taskcomp.dll
2011-06-14 11:30:45 ----A---- C:\Windows\system32\sxs.dll
2011-06-14 11:30:45 ----A---- C:\Windows\system32\pnidui.dll
2011-06-14 11:30:45 ----A---- C:\Windows\system32\mfds.dll
2011-06-14 11:30:45 ----A---- C:\Windows\system32\mcbuilder.exe
2011-06-14 11:30:45 ----A---- C:\Windows\system32\drivers\vhdmp.sys
2011-06-14 11:30:45 ----A---- C:\Windows\system32\cscobj.dll
2011-06-14 11:30:44 ----A---- C:\Windows\SYSWOW64\schannel.dll
2011-06-14 11:30:44 ----A---- C:\Windows\SYSWOW64\SessEnv.dll
2011-06-14 11:30:44 ----A---- C:\Windows\SYSWOW64\PortableDeviceApi.dll
2011-06-14 11:30:44 ----A---- C:\Windows\SYSWOW64\netfxperf.dll
2011-06-14 11:30:44 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2011-06-14 11:30:44 ----A---- C:\Windows\SYSWOW64\msdrm.dll
2011-06-14 11:30:44 ----A---- C:\Windows\SYSWOW64\mmcndmgr.dll
2011-06-14 11:30:44 ----A---- C:\Windows\SYSWOW64\imapi2fs.dll
2011-06-14 11:30:44 ----A---- C:\Windows\SYSWOW64\DShowRdpFilter.dll
2011-06-14 11:30:44 ----A---- C:\Windows\SYSWOW64\authui.dll
2011-06-14 11:30:44 ----A---- C:\Windows\system32\wuaueng.dll
2011-06-14 11:30:44 ----A---- C:\Windows\system32\winsta.dll
2011-06-14 11:30:44 ----A---- C:\Windows\system32\webservices.dll
2011-06-14 11:30:44 ----A---- C:\Windows\system32\sqlsrv32.dll
2011-06-14 11:30:44 ----A---- C:\Windows\system32\spoolsv.exe
2011-06-14 11:30:44 ----A---- C:\Windows\system32\SessEnv.dll
2011-06-14 11:30:44 ----A---- C:\Windows\system32\rdpendp.dll
2011-06-14 11:30:44 ----A---- C:\Windows\system32\ipsmsnap.dll
2011-06-14 11:30:44 ----A---- C:\Windows\system32\hgprint.dll
2011-06-14 11:30:44 ----A---- C:\Windows\system32\fveapi.dll
2011-06-14 11:30:44 ----A---- C:\Windows\system32\dot3api.dll
2011-06-14 11:30:43 ----A---- C:\Windows\SYSWOW64\usp10.dll
2011-06-14 11:30:43 ----A---- C:\Windows\SYSWOW64\shlwapi.dll
2011-06-14 11:30:43 ----A---- C:\Windows\SYSWOW64\mcbuilder.exe
2011-06-14 11:30:43 ----A---- C:\Windows\SYSWOW64\certmgr.dll
2011-06-14 11:30:43 ----A---- C:\Windows\system32\WMNetMgr.dll
2011-06-14 11:30:43 ----A---- C:\Windows\system32\schtasks.exe
2011-06-14 11:30:43 ----A---- C:\Windows\system32\prncache.dll
2011-06-14 11:30:43 ----A---- C:\Windows\system32\mcmde.dll
2011-06-14 11:30:43 ----A---- C:\Windows\system32\gdi32.dll
2011-06-14 11:30:43 ----A---- C:\Windows\system32\drivers\volsnap.sys
2011-06-14 11:30:43 ----A---- C:\Windows\system32\drivers\msrpc.sys
2011-06-14 11:30:42 ----A---- C:\Windows\SYSWOW64\xpsservices.dll
2011-06-14 11:30:42 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2011-06-14 11:30:42 ----A---- C:\Windows\SYSWOW64\userenv.dll
2011-06-14 11:30:42 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2011-06-14 11:30:42 ----A---- C:\Windows\SYSWOW64\comdlg32.dll
2011-06-14 11:30:42 ----A---- C:\Windows\system32\wuapi.dll
2011-06-14 11:30:42 ----A---- C:\Windows\system32\wlanpref.dll
2011-06-14 11:30:42 ----A---- C:\Windows\system32\wintrust.dll
2011-06-14 11:30:42 ----A---- C:\Windows\system32\vpnike.dll
2011-06-14 11:30:42 ----A---- C:\Windows\system32\userenv.dll
2011-06-14 11:30:42 ----A---- C:\Windows\system32\photowiz.dll
2011-06-14 11:30:42 ----A---- C:\Windows\system32\IPSECSVC.DLL
2011-06-14 11:30:42 ----A---- C:\Windows\system32\FXSSVC.exe
2011-06-14 11:30:42 ----A---- C:\Windows\system32\framedyn.dll
2011-06-14 11:30:42 ----A---- C:\Windows\system32\evr.dll
2011-06-14 11:30:42 ----A---- C:\Windows\system32\drivers\rdbss.sys
2011-06-14 11:30:42 ----A---- C:\Windows\system32\drivers\1394ohci.sys
2011-06-14 11:30:42 ----A---- C:\Windows\system32\AudioSes.dll
2011-06-14 11:30:41 ----A---- C:\Windows\SYSWOW64\cmd.exe
2011-06-14 11:30:41 ----A---- C:\Windows\system32\wmpmde.dll
2011-06-14 11:30:41 ----A---- C:\Windows\system32\WMPEncEn.dll
2011-06-14 11:30:41 ----A---- C:\Windows\system32\wmpeffects.dll
2011-06-14 11:30:41 ----A---- C:\Windows\system32\tscfgwmi.dll
2011-06-14 11:30:41 ----A---- C:\Windows\system32\SyncCenter.dll
2011-06-14 11:30:41 ----A---- C:\Windows\system32\srvsvc.dll
2011-06-14 11:30:41 ----A---- C:\Windows\system32\sppobjs.dll
2011-06-14 11:30:41 ----A---- C:\Windows\system32\shsvcs.dll
2011-06-14 11:30:41 ----A---- C:\Windows\system32\mfreadwrite.dll
2011-06-14 11:30:41 ----A---- C:\Windows\system32\aepdu.dll
2011-06-14 11:30:41 ----A---- C:\Windows\system32\aeinv.dll
2011-06-14 11:30:40 ----A---- C:\Windows\SYSWOW64\Wldap32.dll
2011-06-14 11:30:40 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2011-06-14 11:30:40 ----A---- C:\Windows\SYSWOW64\user32.dll
2011-06-14 11:30:40 ----A---- C:\Windows\SYSWOW64\rdpendp.dll
2011-06-14 11:30:40 ----A---- C:\Windows\SYSWOW64\propsys.dll
2011-06-14 11:30:40 ----A---- C:\Windows\SYSWOW64\mfds.dll
2011-06-14 11:30:40 ----A---- C:\Windows\SYSWOW64\framedynos.dll
2011-06-14 11:30:40 ----A---- C:\Windows\system32\WinSATAPI.dll
2011-06-14 11:30:40 ----A---- C:\Windows\system32\vmicsvc.exe
2011-06-14 11:30:40 ----A---- C:\Windows\system32\stobject.dll
2011-06-14 11:30:40 ----A---- C:\Windows\system32\netdiagfx.dll
2011-06-14 11:30:40 ----A---- C:\Windows\system32\localsec.dll
2011-06-14 11:30:40 ----A---- C:\Windows\system32\iphlpsvc.dll
2011-06-14 11:30:40 ----A---- C:\Windows\system32\imapi2.dll
2011-06-14 11:30:40 ----A---- C:\Windows\system32\fde.dll
2011-06-14 11:30:40 ----A---- C:\Windows\system32\drivers\vmbus.sys
2011-06-14 11:30:40 ----A---- C:\Windows\system32\drivers\udfs.sys
2011-06-14 11:30:40 ----A---- C:\Windows\system32\credui.dll
2011-06-14 11:30:40 ----A---- C:\Windows\system32\cdd.dll
2011-06-14 11:30:40 ----A---- C:\Windows\system32\bcryptprimitives.dll
2011-06-14 11:30:39 ----A---- C:\Windows\SYSWOW64\ncsi.dll
2011-06-14 11:30:39 ----A---- C:\Windows\SYSWOW64\azroles.dll
2011-06-14 11:30:39 ----A---- C:\Windows\SYSWOW64\appmgr.dll
2011-06-14 11:30:39 ----A---- C:\Windows\system32\tcpipcfg.dll
2011-06-14 11:30:39 ----A---- C:\Windows\system32\spp.dll
2011-06-14 11:30:39 ----A---- C:\Windows\system32\QSHVHOST.DLL
2011-06-14 11:30:39 ----A---- C:\Windows\system32\netid.dll
2011-06-14 11:30:39 ----A---- C:\Windows\system32\inetpp.dll
2011-06-14 11:30:39 ----A---- C:\Windows\system32\drivers\fltMgr.sys
2011-06-14 11:30:39 ----A---- C:\Windows\system32\davclnt.dll
2011-06-14 11:30:39 ----A---- C:\Windows\system32\cscui.dll
2011-06-14 11:30:39 ----A---- C:\Windows\system32\biocpl.dll
2011-06-14 11:30:38 ----A---- C:\Windows\SYSWOW64\themeui.dll
2011-06-14 11:30:38 ----A---- C:\Windows\SYSWOW64\taskeng.exe
2011-06-14 11:30:38 ----A---- C:\Windows\SYSWOW64\spp.dll
2011-06-14 11:30:38 ----A---- C:\Windows\SYSWOW64\mswsock.dll
2011-06-14 11:30:38 ----A---- C:\Windows\SYSWOW64\dhcpcore.dll
2011-06-14 11:30:38 ----A---- C:\Windows\SYSWOW64\credui.dll
2011-06-14 11:30:38 ----A---- C:\Windows\system32\wusa.exe
2011-06-14 11:30:38 ----A---- C:\Windows\system32\scansetting.dll
2011-06-14 11:30:38 ----A---- C:\Windows\system32\profsvc.dll
2011-06-14 11:30:38 ----A---- C:\Windows\system32\printui.dll
2011-06-14 11:30:38 ----A---- C:\Windows\system32\pla.dll
2011-06-14 11:30:38 ----A---- C:\Windows\system32\mspbda.dll
2011-06-14 11:30:38 ----A---- C:\Windows\system32\msinfo32.exe
2011-06-14 11:30:38 ----A---- C:\Windows\system32\gameux.dll
2011-06-14 11:30:38 ----A---- C:\Windows\system32\conhost.exe
2011-06-14 11:30:38 ----A---- C:\Windows\splwow64.exe
2011-06-14 11:30:37 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2011-06-14 11:30:37 ----A---- C:\Windows\SYSWOW64\NaturalLanguage6.dll
2011-06-14 11:30:37 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2011-06-14 11:30:37 ----A---- C:\Windows\SYSWOW64\mfreadwrite.dll
2011-06-14 11:30:37 ----A---- C:\Windows\SYSWOW64\dxgi.dll
2011-06-14 11:30:37 ----A---- C:\Windows\SYSWOW64\dbghelp.dll
2011-06-14 11:30:37 ----A---- C:\Windows\SYSWOW64\basecsp.dll
2011-06-14 11:30:37 ----A---- C:\Windows\system32\wiaservc.dll
2011-06-14 11:30:37 ----A---- C:\Windows\system32\vds.exe
2011-06-14 11:30:37 ----A---- C:\Windows\system32\rpchttp.dll
2011-06-14 11:30:37 ----A---- C:\Windows\system32\msdri.dll
2011-06-14 11:30:37 ----A---- C:\Windows\system32\mscms.dll
2011-06-14 11:30:37 ----A---- C:\Windows\system32\IPHLPAPI.DLL
2011-06-14 11:30:37 ----A---- C:\Windows\system32\FirewallControlPanel.dll
2011-06-14 11:30:37 ----A---- C:\Windows\system32\drivers\pci.sys
2011-06-14 11:30:37 ----A---- C:\Windows\system32\cryptsvc.dll
2011-06-14 11:30:37 ----A---- C:\Windows\system32\aitagent.exe
2011-06-14 11:30:37 ----A---- C:\Windows\system32\AdmTmpl.dll
2011-06-14 11:30:36 ----A---- C:\Windows\SYSWOW64\WinSATAPI.dll
2011-06-14 11:30:36 ----A---- C:\Windows\SYSWOW64\taskcomp.dll
2011-06-14 11:30:36 ----A---- C:\Windows\SYSWOW64\evr.dll
2011-06-14 11:30:36 ----A---- C:\Windows\SYSWOW64\calc.exe
2011-06-14 11:30:36 ----A---- C:\Windows\system32\XpsRasterService.dll
2011-06-14 11:30:36 ----A---- C:\Windows\system32\wisptis.exe
2011-06-14 11:30:36 ----A---- C:\Windows\system32\sppwinob.dll
2011-06-14 11:30:36 ----A---- C:\Windows\system32\rdpcore.dll
2011-06-14 11:30:36 ----A---- C:\Windows\system32\ocsetup.exe
2011-06-14 11:30:36 ----A---- C:\Windows\system32\ocsetapi.dll
2011-06-14 11:30:36 ----A---- C:\Windows\system32\msi.dll
2011-06-14 11:30:36 ----A---- C:\Windows\system32\DXP.dll
2011-06-14 11:30:36 ----A---- C:\Windows\system32\drivers\volmgr.sys
2011-06-14 11:30:36 ----A---- C:\Windows\system32\drivers\rasl2tp.sys
2011-06-14 11:30:36 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2011-06-14 11:30:36 ----A---- C:\Windows\system32\cfgmgr32.dll
2011-06-14 11:30:35 ----A---- C:\Windows\SYSWOW64\UIRibbon.dll
2011-06-14 11:30:35 ----A---- C:\Windows\SYSWOW64\sqlsrv32.dll
2011-06-14 11:30:35 ----A---- C:\Windows\system32\wpdbusenum.dll
2011-06-14 11:30:35 ----A---- C:\Windows\system32\wcncsvc.dll
2011-06-14 11:30:35 ----A---- C:\Windows\system32\upnp.dll
2011-06-14 11:30:35 ----A---- C:\Windows\system32\Robocopy.exe
2011-06-14 11:30:35 ----A---- C:\Windows\system32\ntshrui.dll
2011-06-14 11:30:35 ----A---- C:\Windows\system32\mprapi.dll
2011-06-14 11:30:35 ----A---- C:\Windows\system32\eapphost.dll
2011-06-14 11:30:35 ----A---- C:\Windows\system32\eapp3hst.dll
2011-06-14 11:30:35 ----A---- C:\Windows\system32\drivers\msdsm.sys
2011-06-14 11:30:35 ----A---- C:\Windows\system32\ci.dll
2011-06-14 11:30:34 ----A---- C:\Windows\SYSWOW64\ws2_32.dll
2011-06-14 11:30:34 ----A---- C:\Windows\SYSWOW64\sxs.dll
2011-06-14 11:30:34 ----A---- C:\Windows\SYSWOW64\stobject.dll
2011-06-14 11:30:34 ----A---- C:\Windows\SYSWOW64\netshell.dll
2011-06-14 11:30:34 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2011-06-14 11:30:34 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2011-06-14 11:30:34 ----A---- C:\Windows\SYSWOW64\comctl32.dll
2011-06-14 11:30:34 ----A---- C:\Windows\system32\thumbcache.dll
2011-06-14 11:30:34 ----A---- C:\Windows\system32\t2embed.dll
2011-06-14 11:30:34 ----A---- C:\Windows\system32\sspicli.dll
2011-06-14 11:30:34 ----A---- C:\Windows\system32\scecli.dll
2011-06-14 11:30:34 ----A---- C:\Windows\system32\PerfCenterCPL.dll
2011-06-14 11:30:34 ----A---- C:\Windows\system32\MSMPEG2ENC.DLL
2011-06-14 11:30:34 ----A---- C:\Windows\system32\msasn1.dll
2011-06-14 11:30:34 ----A---- C:\Windows\system32\hal.dll
2011-06-14 11:30:34 ----A---- C:\Windows\system32\DxpTaskSync.dll
2011-06-14 11:30:34 ----A---- C:\Windows\system32\dwmredir.dll
2011-06-14 11:30:34 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2011-06-14 11:30:34 ----A---- C:\Windows\system32\drivers\HpSAMD.sys
2011-06-14 11:30:34 ----A---- C:\Windows\system32\drivers\fvevol.sys
2011-06-14 11:30:34 ----A---- C:\Windows\system32\drivers\Classpnp.sys
2011-06-14 11:30:33 ----A---- C:\Windows\SYSWOW64\WSDApi.dll
2011-06-14 11:30:33 ----A---- C:\Windows\SYSWOW64\wmpeffects.dll
2011-06-14 11:30:33 ----A---- C:\Windows\SYSWOW64\rpchttp.dll
2011-06-14 11:30:33 ----A---- C:\Windows\SYSWOW64\prncache.dll
2011-06-14 11:30:33 ----A---- C:\Windows\SYSWOW64\printui.dll
2011-06-14 11:30:33 ----A---- C:\Windows\SYSWOW64\net1.exe
2011-06-14 11:30:33 ----A---- C:\Windows\SYSWOW64\msi.dll
2011-06-14 11:30:33 ----A---- C:\Windows\system32\themeui.dll
2011-06-14 11:30:33 ----A---- C:\Windows\system32\scrptadm.dll
2011-06-14 11:30:33 ----A---- C:\Windows\system32\puiobj.dll
2011-06-14 11:30:33 ----A---- C:\Windows\system32\onex.dll
2011-06-14 11:30:33 ----A---- C:\Windows\system32\nlaapi.dll
2011-06-14 11:30:33 ----A---- C:\Windows\system32\iasrad.dll
2011-06-14 11:30:33 ----A---- C:\Windows\system32\DXPTaskRingtone.dll
2011-06-14 11:30:33 ----A---- C:\Windows\system32\drivers\ipfltdrv.sys
2011-06-14 11:30:33 ----A---- C:\Windows\system32\aaclient.dll
2011-06-14 11:30:32 ----A---- C:\Windows\SYSWOW64\scansetting.dll
2011-06-14 11:30:32 ----A---- C:\Windows\SYSWOW64\MMDevAPI.dll
2011-06-14 11:30:32 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2011-06-14 11:30:32 ----A---- C:\Windows\system32\wscapi.dll
2011-06-14 11:30:32 ----A---- C:\Windows\system32\wow64.dll
2011-06-14 11:30:32 ----A---- C:\Windows\system32\wlangpui.dll
2011-06-14 11:30:32 ----A---- C:\Windows\system32\wiadefui.dll
2011-06-14 11:30:32 ----A---- C:\Windows\system32\wdc.dll
2011-06-14 11:30:32 ----A---- C:\Windows\system32\VAN.dll
2011-06-14 11:30:32 ----A---- C:\Windows\system32\StructuredQuery.dll
2011-06-14 11:30:32 ----A---- C:\Windows\system32\SndVol.exe
2011-06-14 11:30:32 ----A---- C:\Windows\system32\sdengin2.dll
2011-06-14 11:30:32 ----A---- C:\Windows\system32\scesrv.dll
2011-06-14 11:30:32 ----A---- C:\Windows\system32\samcli.dll
2011-06-14 11:30:32 ----A---- C:\Windows\system32\rasmans.dll
2011-06-14 11:30:32 ----A---- C:\Windows\system32\netcenter.dll
2011-06-14 11:30:32 ----A---- C:\Windows\system32\msftedit.dll
2011-06-14 11:30:32 ----A---- C:\Windows\system32\dskquoui.dll
2011-06-14 11:30:32 ----A---- C:\Windows\system32\drivers\partmgr.sys
2011-06-14 11:30:32 ----A---- C:\Windows\system32\drivers\ndiswan.sys
2011-06-14 11:30:31 ----A---- C:\Windows\SYSWOW64\WMVCORE.DLL
2011-06-14 11:30:31 ----A---- C:\Windows\SYSWOW64\wlangpui.dll
2011-06-14 11:30:31 ----A---- C:\Windows\SYSWOW64\t2embed.dll
2011-06-14 11:30:31 ----A---- C:\Windows\SYSWOW64\QSHVHOST.DLL
2011-06-14 11:30:31 ----A---- C:\Windows\SYSWOW64\pnidui.dll
2011-06-14 11:30:31 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2011-06-14 11:30:31 ----A---- C:\Windows\system32\wucltux.dll
2011-06-14 11:30:31 ----A---- C:\Windows\system32\TabSvc.dll
2011-06-14 11:30:31 ----A---- C:\Windows\system32\srchadmin.dll
2011-06-14 11:30:31 ----A---- C:\Windows\system32\regapi.dll
2011-06-14 11:30:31 ----A---- C:\Windows\system32\QUTIL.DLL
2011-06-14 11:30:31 ----A---- C:\Windows\system32\iasacct.dll
2011-06-14 11:30:31 ----A---- C:\Windows\system32\drivers\termdd.sys
2011-06-14 11:30:31 ----A---- C:\Windows\system32\consent.exe
2011-06-14 11:30:30 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2011-06-14 11:30:30 ----A---- C:\Windows\SYSWOW64\wscapi.dll
2011-06-14 11:30:30 ----A---- C:\Windows\SYSWOW64\wpdshext.dll
2011-06-14 11:30:30 ----A---- C:\Windows\SYSWOW64\webservices.dll
2011-06-14 11:30:30 ----A---- C:\Windows\SYSWOW64\SyncCenter.dll
2011-06-14 11:30:30 ----A---- C:\Windows\SYSWOW64\scrptadm.dll
2011-06-14 11:30:30 ----A---- C:\Windows\SYSWOW64\netdiagfx.dll
2011-06-14 11:30:30 ----A---- C:\Windows\SYSWOW64\fde.dll
2011-06-14 11:30:30 ----A---- C:\Windows\system32\WUDFSvc.dll
2011-06-14 11:30:30 ----A---- C:\Windows\system32\wksprt.exe
2011-06-14 11:30:30 ----A---- C:\Windows\system32\taskhost.exe
2011-06-14 11:30:30 ----A---- C:\Windows\system32\setupcl.exe
2011-06-14 11:30:30 ----A---- C:\Windows\system32\rastls.dll
2011-06-14 11:30:30 ----A---- C:\Windows\system32\drivers\msahci.sys
2011-06-14 11:30:30 ----A---- C:\Windows\system32\drivers\acpi.sys
2011-06-14 11:30:29 ----A---- C:\Windows\SYSWOW64\WinSCard.dll
2011-06-14 11:30:29 ----A---- C:\Windows\SYSWOW64\pla.dll
2011-06-14 11:30:29 ----A---- C:\Windows\SYSWOW64\msasn1.dll
2011-06-14 11:30:29 ----A---- C:\Windows\SYSWOW64\cscobj.dll
2011-06-14 11:30:29 ----A---- C:\Windows\system32\tapisrv.dll
2011-06-14 11:30:29 ----A---- C:\Windows\system32\netiohlp.dll
2011-06-14 11:30:29 ----A---- C:\Windows\system32\msconfig.exe
2011-06-14 11:30:29 ----A---- C:\Windows\system32\mimefilt.dll
2011-06-14 11:30:29 ----A---- C:\Windows\system32\lsmproxy.dll
2011-06-14 11:30:29 ----A---- C:\Windows\system32\ListSvc.dll
2011-06-14 11:30:29 ----A---- C:\Windows\system32\hgcpl.dll
2011-06-14 11:30:29 ----A---- C:\Windows\system32\fdeploy.dll
2011-06-14 11:30:29 ----A---- C:\Windows\system32\drivers\raspptp.sys
2011-06-14 11:30:29 ----A---- C:\Windows\system32\drivers\ks.sys
2011-06-14 11:30:29 ----A---- C:\Windows\system32\clusapi.dll
2011-06-14 11:30:29 ----A---- C:\Windows\system32\basecsp.dll
2011-06-14 11:30:28 ----A---- C:\Windows\SYSWOW64\winsta.dll
2011-06-14 11:30:28 ----A---- C:\Windows\SYSWOW64\rdpcore.dll
2011-06-14 11:30:28 ----A---- C:\Windows\SYSWOW64\ntshrui.dll
2011-06-14 11:30:28 ----A---- C:\Windows\SYSWOW64\MSMPEG2ENC.DLL
2011-06-14 11:30:28 ----A---- C:\Windows\SYSWOW64\imapi2.dll
2011-06-14 11:30:28 ----A---- C:\Windows\SYSWOW64\gameux.dll
2011-06-14 11:30:28 ----A---- C:\Windows\SYSWOW64\DXPTaskRingtone.dll
2011-06-14 11:30:28 ----A---- C:\Windows\system32\TsUsbGDCoInstaller.dll
2011-06-14 11:30:28 ----A---- C:\Windows\system32\RpcRtRemote.dll
2011-06-14 11:30:28 ----A---- C:\Windows\system32\riched20.dll
2011-06-14 11:30:28 ----A---- C:\Windows\system32\mtxclu.dll
2011-06-14 11:30:28 ----A---- C:\Windows\system32\drivers\sbp2port.sys
2011-06-14 11:30:28 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2011-06-14 11:30:28 ----A---- C:\Windows\system32\dnscmmc.dll
2011-06-14 11:30:28 ----A---- C:\Windows\system32\AuxiliaryDisplayCpl.dll
2011-06-14 11:30:27 ----A---- C:\Windows\SYSWOW64\WMPEncEn.dll
2011-06-14 11:30:27 ----A---- C:\Windows\SYSWOW64\winmm.dll
2011-06-14 11:30:27 ----A---- C:\Windows\SYSWOW64\shsvcs.dll
2011-06-14 11:30:27 ----A---- C:\Windows\SYSWOW64\onex.dll
2011-06-14 11:30:27 ----A---- C:\Windows\SYSWOW64\hbaapi.dll
2011-06-14 11:30:27 ----A---- C:\Windows\SYSWOW64\autofmt.exe
2011-06-14 11:30:27 ----A---- C:\Windows\system32\themecpl.dll
2011-06-14 11:30:27 ----A---- C:\Windows\system32\sharemediacpl.dll
2011-06-14 11:30:27 ----A---- C:\Windows\system32\SensorsCpl.dll
2011-06-14 11:30:27 ----A---- C:\Windows\system32\powercpl.dll
2011-06-14 11:30:27 ----A---- C:\Windows\system32\netjoin.dll
2011-06-14 11:30:27 ----A---- C:\Windows\system32\nci.dll
2011-06-14 11:30:27 ----A---- C:\Windows\system32\logoncli.dll
2011-06-14 11:30:27 ----A---- C:\Windows\system32\Faultrep.dll
2011-06-14 11:30:27 ----A---- C:\Windows\system32\eudcedit.exe
2011-06-14 11:30:26 ----A---- C:\Windows\SYSWOW64\thumbcache.dll
2011-06-14 11:30:26 ----A---- C:\Windows\SYSWOW64\samcli.dll
2011-06-14 11:30:26 ----A---- C:\Windows\SYSWOW64\regapi.dll
2011-06-14 11:30:26 ----A---- C:\Windows\SYSWOW64\proquota.exe
2011-06-14 11:30:26 ----A---- C:\Windows\SYSWOW64\netiohlp.dll
2011-06-14 11:30:26 ----A---- C:\Windows\SYSWOW64\msutb.dll
2011-06-14 11:30:26 ----A---- C:\Windows\SYSWOW64\msinfo32.exe
2011-06-14 11:30:26 ----A---- C:\Windows\SYSWOW64\mimefilt.dll
2011-06-14 11:30:26 ----A---- C:\Windows\SYSWOW64\ipsmsnap.dll
2011-06-14 11:30:26 ----A---- C:\Windows\SYSWOW64\IPHLPAPI.DLL
2011-06-14 11:30:26 ----A---- C:\Windows\SYSWOW64\autochk.exe
2011-06-14 11:30:26 ----A---- C:\Windows\SYSWOW64\autoconv.exe
2011-06-14 11:30:26 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2011-06-14 11:30:26 ----A---- C:\Windows\system32\wkssvc.dll
2011-06-14 11:30:26 ----A---- C:\Windows\system32\vpnikeapi.dll
2011-06-14 11:30:26 ----A---- C:\Windows\system32\sppcomapi.dll
2011-06-14 11:30:26 ----A---- C:\Windows\system32\nshipsec.dll
2011-06-14 11:30:26 ----A---- C:\Windows\system32\Narrator.exe
2011-06-14 11:30:26 ----A---- C:\Windows\system32\fms.dll
2011-06-14 11:30:26 ----A---- C:\Windows\system32\comctl32.dll
2011-06-14 11:30:26 ----A---- C:\Windows\system32\cabview.dll
2011-06-14 11:30:26 ----A---- C:\Windows\system32\autochk.exe
2011-06-14 11:30:26 ----A---- C:\Windows\system32\autofmt.exe
2011-06-14 11:30:26 ----A---- C:\Windows\system32\autoconv.exe
2011-06-14 11:30:26 ----A---- C:\Windows\system32\audiodg.exe
2011-06-14 11:30:25 ----A---- C:\Windows\SYSWOW64\wcncsvc.dll
2011-06-14 11:30:25 ----A---- C:\Windows\SYSWOW64\tcpipcfg.dll
2011-06-14 11:30:25 ----A---- C:\Windows\SYSWOW64\srchadmin.dll
2011-06-14 11:30:25 ----A---- C:\Windows\SYSWOW64\schtasks.exe
2011-06-14 11:30:25 ----A---- C:\Windows\SYSWOW64\powercpl.dll
2011-06-14 11:30:25 ----A---- C:\Windows\SYSWOW64\msihnd.dll
2011-06-14 11:30:25 ----A---- C:\Windows\SYSWOW64\mscorier.dll
Re: proces firefox.exe se neukončí s vypnutím programu
2011-06-14 11:30:25 ----A---- C:\Windows\SYSWOW64\framedyn.dll
2011-06-14 11:30:25 ----A---- C:\Windows\SYSWOW64\eapphost.dll
2011-06-14 11:30:25 ----A---- C:\Windows\system32\wwanconn.dll
2011-06-14 11:30:25 ----A---- C:\Windows\system32\wpd_ci.dll
2011-06-14 11:30:25 ----A---- C:\Windows\system32\wlanui.dll
2011-06-14 11:30:25 ----A---- C:\Windows\system32\shsetup.dll
2011-06-14 11:30:25 ----A---- C:\Windows\system32\sdclt.exe
2011-06-14 11:30:25 ----A---- C:\Windows\system32\prntvpt.dll
2011-06-14 11:30:25 ----A---- C:\Windows\system32\mscorier.dll
2011-06-14 11:30:25 ----A---- C:\Windows\system32\drivers\winusb.sys
2011-06-14 11:30:25 ----A---- C:\Windows\system32\drivers\wanarp.sys
2011-06-14 11:30:25 ----A---- C:\Windows\system32\drivers\scsiport.sys
2011-06-14 11:30:25 ----A---- C:\Windows\system32\bcdsrv.dll
2011-06-14 11:30:24 ----A---- C:\Windows\SYSWOW64\wlanpref.dll
2011-06-14 11:30:24 ----A---- C:\Windows\SYSWOW64\wdc.dll
2011-06-14 11:30:24 ----A---- C:\Windows\SYSWOW64\Vault.dll
2011-06-14 11:30:24 ----A---- C:\Windows\SYSWOW64\untfs.dll
2011-06-14 11:30:24 ----A---- C:\Windows\SYSWOW64\StructuredQuery.dll
2011-06-14 11:30:24 ----A---- C:\Windows\SYSWOW64\scesrv.dll
2011-06-14 11:30:24 ----A---- C:\Windows\SYSWOW64\rastls.dll
2011-06-14 11:30:24 ----A---- C:\Windows\SYSWOW64\QAGENT.DLL
2011-06-14 11:30:24 ----A---- C:\Windows\SYSWOW64\netid.dll
2011-06-14 11:30:24 ----A---- C:\Windows\SYSWOW64\nci.dll
2011-06-14 11:30:24 ----A---- C:\Windows\SYSWOW64\AuxiliaryDisplayCpl.dll
2011-06-14 11:30:24 ----A---- C:\Windows\SYSWOW64\actxprxy.dll
2011-06-14 11:30:24 ----A---- C:\Windows\system32\wmpsrcwp.dll
2011-06-14 11:30:24 ----A---- C:\Windows\system32\qedit.dll
2011-06-14 11:30:24 ----A---- C:\Windows\system32\mprddm.dll
2011-06-14 11:30:24 ----A---- C:\Windows\system32\mblctr.exe
2011-06-14 11:30:24 ----A---- C:\Windows\system32\fontext.dll
2011-06-14 11:30:24 ----A---- C:\Windows\system32\drivers\volmgrx.sys
2011-06-14 11:30:24 ----A---- C:\Windows\system32\drivers\hidclass.sys
2011-06-14 11:30:24 ----A---- C:\Windows\system32\drivers\BTHUSB.SYS
2011-06-14 11:30:24 ----A---- C:\Windows\system32\drivers\bthport.sys
2011-06-14 11:30:24 ----A---- C:\Windows\system32\dps.dll
2011-06-14 11:30:24 ----A---- C:\Windows\system32\Display.dll
2011-06-14 11:30:24 ----A---- C:\Windows\system32\credssp.dll
2011-06-14 11:30:24 ----A---- C:\Windows\system32\batmeter.dll
2011-06-14 11:30:24 ----A---- C:\Windows\system32\AxInstSv.dll
2011-06-14 11:30:23 ----A---- C:\Windows\SYSWOW64\WMNetMgr.dll
2011-06-14 11:30:23 ----A---- C:\Windows\SYSWOW64\taskmgr.exe
2011-06-14 11:30:23 ----A---- C:\Windows\SYSWOW64\RpcRtRemote.dll
2011-06-14 11:30:23 ----A---- C:\Windows\SYSWOW64\Robocopy.exe
2011-06-14 11:30:23 ----A---- C:\Windows\SYSWOW64\DxpTaskSync.dll
2011-06-14 11:30:23 ----A---- C:\Windows\system32\wpccpl.dll
2011-06-14 11:30:23 ----A---- C:\Windows\system32\usercpl.dll
2011-06-14 11:30:23 ----A---- C:\Windows\system32\sppsvc.exe
2011-06-14 11:30:23 ----A---- C:\Windows\system32\SndVolSSO.dll
2011-06-14 11:30:23 ----A---- C:\Windows\system32\rtutils.dll
2011-06-14 11:30:23 ----A---- C:\Windows\system32\rasppp.dll
2011-06-14 11:30:23 ----A---- C:\Windows\system32\provsvc.dll
2011-06-14 11:30:23 ----A---- C:\Windows\system32\MCEWMDRMNDBootstrap.dll
2011-06-14 11:30:23 ----A---- C:\Windows\system32\drivers\winhv.sys
2011-06-14 11:30:23 ----A---- C:\Windows\system32\DiagCpl.dll
2011-06-14 11:30:23 ----A---- C:\Windows\system32\bootres.dll
2011-06-14 11:30:22 ----A---- C:\Windows\SYSWOW64\XpsRasterService.dll
2011-06-14 11:30:22 ----A---- C:\Windows\SYSWOW64\userinit.exe
2011-06-14 11:30:22 ----A---- C:\Windows\SYSWOW64\termmgr.dll
2011-06-14 11:30:22 ----A---- C:\Windows\SYSWOW64\puiobj.dll
2011-06-14 11:30:22 ----A---- C:\Windows\SYSWOW64\mtxclu.dll
2011-06-14 11:30:22 ----A---- C:\Windows\SYSWOW64\logoncli.dll
2011-06-14 11:30:22 ----A---- C:\Windows\SYSWOW64\eudcedit.exe
2011-06-14 11:30:22 ----A---- C:\Windows\SYSWOW64\Display.dll
2011-06-14 11:30:22 ----A---- C:\Windows\system32\WPDShServiceObj.dll
2011-06-14 11:30:22 ----A---- C:\Windows\system32\untfs.dll
2011-06-14 11:30:22 ----A---- C:\Windows\system32\taskmgr.exe
2011-06-14 11:30:22 ----A---- C:\Windows\system32\shdocvw.dll
2011-06-14 11:30:22 ----A---- C:\Windows\system32\proquota.exe
2011-06-14 11:30:22 ----A---- C:\Windows\system32\prnfldr.dll
2011-06-14 11:30:22 ----A---- C:\Windows\system32\pdh.dll
2011-06-14 11:30:22 ----A---- C:\Windows\system32\MSAC3ENC.DLL
2011-06-14 11:30:22 ----A---- C:\Windows\system32\hbaapi.dll
2011-06-14 11:30:22 ----A---- C:\Windows\system32\dxdiagn.dll
2011-06-14 11:30:22 ----A---- C:\Windows\system32\drivers\rdyboost.sys
2011-06-14 11:30:22 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2011-06-14 11:30:22 ----A---- C:\Windows\system32\drivers\ataport.sys
2011-06-14 11:30:22 ----A---- C:\Windows\system32\dot3cfg.dll
2011-06-14 11:30:21 ----A---- C:\Windows\SYSWOW64\wiadefui.dll
2011-06-14 11:30:21 ----A---- C:\Windows\SYSWOW64\themecpl.dll
2011-06-14 11:30:21 ----A---- C:\Windows\SYSWOW64\sppcomapi.dll
2011-06-14 11:30:21 ----A---- C:\Windows\SYSWOW64\shsetup.dll
2011-06-14 11:30:21 ----A---- C:\Windows\SYSWOW64\SensorsCpl.dll
2011-06-14 11:30:21 ----A---- C:\Windows\SYSWOW64\rasppp.dll
2011-06-14 11:30:21 ----A---- C:\Windows\SYSWOW64\FWPUCLNT.DLL
2011-06-14 11:30:21 ----A---- C:\Windows\SYSWOW64\FirewallControlPanel.dll
2011-06-14 11:30:21 ----A---- C:\Windows\SYSWOW64\cabview.dll
2011-06-14 11:30:21 ----A---- C:\Windows\system32\userinit.exe
2011-06-14 11:30:21 ----A---- C:\Windows\system32\slui.exe
2011-06-14 11:30:21 ----A---- C:\Windows\system32\rdpcorekmts.dll
2011-06-14 11:30:21 ----A---- C:\Windows\system32\accessibilitycpl.dll
2011-06-14 11:30:20 ----A---- C:\Windows\SYSWOW64\tapisrv.dll
2011-06-14 11:30:20 ----A---- C:\Windows\SYSWOW64\scecli.dll
2011-06-14 11:30:20 ----A---- C:\Windows\SYSWOW64\mscories.dll
2011-06-14 11:30:20 ----A---- C:\Windows\SYSWOW64\mscms.dll
2011-06-14 11:30:20 ----A---- C:\Windows\SYSWOW64\localsec.dll
2011-06-14 11:30:20 ----A---- C:\Windows\SYSWOW64\hgcpl.dll
2011-06-14 11:30:20 ----A---- C:\Windows\SYSWOW64\fontext.dll
2011-06-14 11:30:20 ----A---- C:\Windows\SYSWOW64\dnscmmc.dll
2011-06-14 11:30:20 ----A---- C:\Windows\system32\zipfldr.dll
2011-06-14 11:30:20 ----A---- C:\Windows\system32\sud.dll
2011-06-14 11:30:20 ----A---- C:\Windows\system32\msieftp.dll
2011-06-14 11:30:20 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2011-06-14 11:30:20 ----A---- C:\Windows\system32\drivers\storvsc.sys
2011-06-14 11:30:20 ----A---- C:\Windows\system32\DeviceCenter.dll
2011-06-14 11:30:20 ----A---- C:\Windows\system32\defaultlocationcpl.dll
2011-06-14 11:30:19 ----A---- C:\Windows\SYSWOW64\wlanui.dll
2011-06-14 11:30:19 ----A---- C:\Windows\SYSWOW64\VAN.dll
2011-06-14 11:30:19 ----A---- C:\Windows\SYSWOW64\usercpl.dll
2011-06-14 11:30:19 ----A---- C:\Windows\SYSWOW64\SndVolSSO.dll
2011-06-14 11:30:19 ----A---- C:\Windows\SYSWOW64\qedit.dll
2011-06-14 11:30:19 ----A---- C:\Windows\SYSWOW64\prntvpt.dll
2011-06-14 11:30:19 ----A---- C:\Windows\SYSWOW64\PerfCenterCPL.dll
2011-06-14 11:30:19 ----A---- C:\Windows\SYSWOW64\netcenter.dll
2011-06-14 11:30:19 ----A---- C:\Windows\SYSWOW64\mprddm.dll
2011-06-14 11:30:19 ----A---- C:\Windows\SYSWOW64\iasacct.dll
2011-06-14 11:30:19 ----A---- C:\Windows\SYSWOW64\batmeter.dll
2011-06-14 11:30:19 ----A---- C:\Windows\system32\twext.dll
2011-06-14 11:30:19 ----A---- C:\Windows\system32\taskbarcpl.dll
2011-06-14 11:30:19 ----A---- C:\Windows\system32\srcore.dll
2011-06-14 11:30:19 ----A---- C:\Windows\system32\rdpwsx.dll
2011-06-14 11:30:19 ----A---- C:\Windows\system32\qdvd.dll
2011-06-14 11:30:19 ----A---- C:\Windows\system32\OnLineIDCpl.dll
2011-06-14 11:30:19 ----A---- C:\Windows\system32\networkmap.dll
2011-06-14 11:30:19 ----A---- C:\Windows\system32\dot3svc.dll
2011-06-14 11:30:19 ----A---- C:\Windows\system32\cryptui.dll
2011-06-14 11:30:19 ----A---- C:\Windows\system32\ActionCenter.dll
2011-06-14 11:30:18 ----A---- C:\Windows\SYSWOW64\zipfldr.dll
2011-06-14 11:30:18 ----A---- C:\Windows\SYSWOW64\w32tm.exe
2011-06-14 11:30:18 ----A---- C:\Windows\SYSWOW64\spwizeng.dll
2011-06-14 11:30:18 ----A---- C:\Windows\SYSWOW64\SndVol.exe
2011-06-14 11:30:18 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2011-06-14 11:30:18 ----A---- C:\Windows\SYSWOW64\networkmap.dll
2011-06-14 11:30:18 ----A---- C:\Windows\SYSWOW64\netjoin.dll
2011-06-14 11:30:18 ----A---- C:\Windows\SYSWOW64\MSAC3ENC.DLL
2011-06-14 11:30:18 ----A---- C:\Windows\SYSWOW64\fdeploy.dll
2011-06-14 11:30:18 ----A---- C:\Windows\SYSWOW64\cryptui.dll
2011-06-14 11:30:18 ----A---- C:\Windows\SYSWOW64\azroleui.dll
2011-06-14 11:30:18 ----A---- C:\Windows\SYSWOW64\adsldp.dll
2011-06-14 11:30:18 ----A---- C:\Windows\SYSWOW64\accessibilitycpl.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\uxlib.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\tzutil.exe
2011-06-14 11:30:18 ----A---- C:\Windows\system32\systemcpl.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\sysclass.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\syncui.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\sspisrv.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\sisbkup.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\shwebsvc.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\sdcpl.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\recovery.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\recdisc.exe
2011-06-14 11:30:18 ----A---- C:\Windows\system32\OobeFldr.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\netplwiz.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\ncryptui.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\MediaMetadataHandler.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\isoburn.exe
2011-06-14 11:30:18 ----A---- C:\Windows\system32\httpapi.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\efscore.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\dsuiext.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\drivers\rdpdr.sys
2011-06-14 11:30:18 ----A---- C:\Windows\system32\drivers\mpio.sys
2011-06-14 11:30:18 ----A---- C:\Windows\system32\drivers\hwpolicy.sys
2011-06-14 11:30:18 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2011-06-14 11:30:18 ----A---- C:\Windows\system32\certcli.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\cca.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\bcdedit.exe
2011-06-14 11:30:18 ----A---- C:\Windows\system32\azroleui.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\autoplay.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\asycfilt.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\appinfo.dll
2011-06-14 11:30:17 ----A---- C:\Windows\SYSWOW64\wusa.exe
2011-06-14 11:30:17 ----A---- C:\Windows\SYSWOW64\sud.dll
2011-06-14 11:30:17 ----A---- C:\Windows\SYSWOW64\prnfldr.dll
2011-06-14 11:30:17 ----A---- C:\Windows\SYSWOW64\photowiz.dll
2011-06-14 11:30:17 ----A---- C:\Windows\SYSWOW64\OnLineIDCpl.dll
2011-06-14 11:30:17 ----A---- C:\Windows\SYSWOW64\msieftp.dll
2011-06-14 11:30:17 ----A---- C:\Windows\SYSWOW64\MediaMetadataHandler.dll
2011-06-14 11:30:17 ----A---- C:\Windows\SYSWOW64\MCEWMDRMNDBootstrap.dll
2011-06-14 11:30:17 ----A---- C:\Windows\SYSWOW64\Faultrep.dll
2011-06-14 11:30:17 ----A---- C:\Windows\SYSWOW64\credssp.dll
2011-06-14 11:30:17 ----A---- C:\Windows\SYSWOW64\ActionCenter.dll
2011-06-14 11:30:17 ----A---- C:\Windows\system32\wlanmsm.dll
2011-06-14 11:30:17 ----A---- C:\Windows\system32\vdsutil.dll
2011-06-14 11:30:17 ----A---- C:\Windows\system32\termmgr.dll
2011-06-14 11:30:17 ----A---- C:\Windows\system32\spwizeng.dll
2011-06-14 11:30:17 ----A---- C:\Windows\system32\sdrsvc.dll
2011-06-14 11:30:17 ----A---- C:\Windows\system32\msvidc32.dll
2011-06-14 11:30:17 ----A---- C:\Windows\system32\msscp.dll
2011-06-14 11:30:17 ----A---- C:\Windows\system32\MFPlay.dll
2011-06-14 11:30:17 ----A---- C:\Windows\system32\AuxiliaryDisplayServices.dll
2011-06-14 11:30:17 ----A---- C:\Windows\system32\ActionCenterCPL.dll
2011-06-14 11:30:16 ----A---- C:\Windows\SYSWOW64\wmpmde.dll
2011-06-14 11:30:16 ----A---- C:\Windows\SYSWOW64\syncui.dll
2011-06-14 11:30:16 ----A---- C:\Windows\SYSWOW64\sisbkup.dll
2011-06-14 11:30:16 ----A---- C:\Windows\SYSWOW64\shwebsvc.dll
2011-06-14 11:30:16 ----A---- C:\Windows\SYSWOW64\odbcjt32.dll
2011-06-14 11:30:16 ----A---- C:\Windows\SYSWOW64\ntlanman.dll
2011-06-14 11:30:16 ----A---- C:\Windows\SYSWOW64\iprtrmgr.dll
2011-06-14 11:30:16 ----A---- C:\Windows\SYSWOW64\ifsutil.dll
2011-06-14 11:30:16 ----A---- C:\Windows\SYSWOW64\iasrad.dll
2011-06-14 11:30:16 ----A---- C:\Windows\SYSWOW64\ftp.exe
2011-06-14 11:30:16 ----A---- C:\Windows\SYSWOW64\efscore.dll
2011-06-14 11:30:16 ----A---- C:\Windows\SYSWOW64\dskquoui.dll
2011-06-14 11:30:16 ----A---- C:\Windows\SYSWOW64\dot3cfg.dll
2011-06-14 11:30:16 ----A---- C:\Windows\SYSWOW64\DeviceCenter.dll
2011-06-14 11:30:16 ----A---- C:\Windows\SYSWOW64\defaultlocationcpl.dll
2011-06-14 11:30:16 ----A---- C:\Windows\SYSWOW64\autoplay.dll
2011-06-14 11:30:16 ----A---- C:\Windows\SYSWOW64\ActionCenterCPL.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\wwanprotdim.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\wmdrmsdk.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\UserAccountControlSettings.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\tsgqec.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\srvcli.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\sqlcese30.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\slwga.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\sethc.exe
2011-06-14 11:30:16 ----A---- C:\Windows\system32\secur32.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\rstrui.exe
2011-06-14 11:30:16 ----A---- C:\Windows\system32\ReAgent.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\rdpd3d.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\odbctrac.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\odbccp32.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\ntlanman.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\iyuv_32.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\iTVData.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\iprtrmgr.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\drmmgrtn.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\drivers\vmstorfl.sys
2011-06-14 11:30:16 ----A---- C:\Windows\system32\drivers\ndproxy.sys
2011-06-14 11:30:15 ----A---- C:\Windows\SYSWOW64\wmpsrcwp.dll
2011-06-14 11:30:15 ----A---- C:\Windows\SYSWOW64\systemcpl.dll
2011-06-14 11:30:15 ----A---- C:\Windows\SYSWOW64\SmartcardCredentialProvider.dll
2011-06-14 11:30:15 ----A---- C:\Windows\SYSWOW64\sethc.exe
2011-06-14 11:30:15 ----A---- C:\Windows\SYSWOW64\rtutils.dll
2011-06-14 11:30:15 ----A---- C:\Windows\SYSWOW64\riched20.dll
2011-06-14 11:30:15 ----A---- C:\Windows\SYSWOW64\OobeFldr.dll
2011-06-14 11:30:15 ----A---- C:\Windows\SYSWOW64\ntprint.dll
2011-06-14 11:30:15 ----A---- C:\Windows\SYSWOW64\nshwfp.dll
2011-06-14 11:30:15 ----A---- C:\Windows\SYSWOW64\netplwiz.dll
2011-06-14 11:30:15 ----A---- C:\Windows\SYSWOW64\NAPHLPR.DLL
2011-06-14 11:30:15 ----A---- C:\Windows\SYSWOW64\migisol.dll
2011-06-14 11:30:15 ----A---- C:\Windows\SYSWOW64\fms.dll
2011-06-14 11:30:15 ----A---- C:\Windows\SYSWOW64\blackbox.dll
2011-06-14 11:30:15 ----A---- C:\Windows\SYSWOW64\activeds.dll
2011-06-14 11:30:15 ----A---- C:\Windows\system32\wavemsp.dll
2011-06-14 11:30:15 ----A---- C:\Windows\system32\TSpkg.dll
2011-06-14 11:30:15 ----A---- C:\Windows\system32\srrstr.dll
2011-06-14 11:30:15 ----A---- C:\Windows\system32\sppnp.dll
2011-06-14 11:30:15 ----A---- C:\Windows\system32\ntprint.dll
2011-06-14 11:30:15 ----A---- C:\Windows\system32\nslookup.exe
2011-06-14 11:30:15 ----A---- C:\Windows\system32\NAPHLPR.DLL
2011-06-14 11:30:15 ----A---- C:\Windows\system32\msiexec.exe
2011-06-14 11:30:15 ----A---- C:\Windows\system32\fsquirt.exe
2011-06-14 11:30:15 ----A---- C:\Windows\system32\DevicePairingFolder.dll
2011-06-14 11:30:15 ----A---- C:\Windows\system32\certprop.dll
2011-06-14 11:30:15 ----A---- C:\Windows\system32\bcdboot.exe
2011-06-14 11:30:15 ----A---- C:\Windows\system32\acppage.dll
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\wvc.dll
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\wtsapi32.dll
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\wlanmsm.dll
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\wavemsp.dll
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\tzutil.exe
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\ReAgent.dll
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\provsvc.dll
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\ocsetup.exe
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\nshipsec.dll
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\nlaapi.dll
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\msftedit.dll
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\isoburn.exe
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\httpapi.dll
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\dsuiext.dll
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\dot3ui.dll
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\dfrgui.exe
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\cdosys.dll
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\asycfilt.dll
2011-06-14 11:30:14 ----A---- C:\Windows\system32\wvc.dll
2011-06-14 11:30:14 ----A---- C:\Windows\system32\wuwebv.dll
2011-06-14 11:30:14 ----A---- C:\Windows\system32\wsqmcons.exe
2011-06-14 11:30:14 ----A---- C:\Windows\system32\wsnmp32.dll
2011-06-14 11:30:14 ----A---- C:\Windows\system32\wmpdxm.dll
2011-06-14 11:30:14 ----A---- C:\Windows\system32\wmdrmdev.dll
2011-06-14 11:30:14 ----A---- C:\Windows\system32\wkscli.dll
2011-06-14 11:30:14 ----A---- C:\Windows\system32\WinSCard.dll
2011-06-14 11:30:14 ----A---- C:\Windows\system32\WerFaultSecure.exe
2011-06-14 11:30:14 ----A---- C:\Windows\system32\remotepg.dll
2011-06-14 11:30:14 ----A---- C:\Windows\system32\PresentationSettings.exe
2011-06-14 11:30:14 ----A---- C:\Windows\system32\networkexplorer.dll
2011-06-14 11:30:14 ----A---- C:\Windows\system32\net1.exe
2011-06-14 11:30:14 ----A---- C:\Windows\system32\ftp.exe
2011-06-14 11:30:14 ----A---- C:\Windows\system32\dfrgui.exe
2011-06-14 11:30:14 ----A---- C:\Windows\system32\cdosys.dll
2011-06-14 11:30:14 ----A---- C:\Windows\system32\cabinet.dll
2011-06-14 11:30:14 ----A---- C:\Windows\system32\blackbox.dll
2011-06-14 11:30:13 ----A---- C:\Windows\twain_32.dll
2011-06-14 11:30:13 ----A---- C:\Windows\SYSWOW64\wimgapi.dll
2011-06-14 11:30:13 ----A---- C:\Windows\SYSWOW64\twext.dll
2011-06-14 11:30:13 ----A---- C:\Windows\SYSWOW64\shdocvw.dll
2011-06-14 11:30:13 ----A---- C:\Windows\SYSWOW64\setupugc.exe
2011-06-14 11:30:13 ----A---- C:\Windows\SYSWOW64\qcap.dll
2011-06-14 11:30:13 ----A---- C:\Windows\SYSWOW64\qasf.dll
2011-06-14 11:30:13 ----A---- C:\Windows\SYSWOW64\mstask.dll
2011-06-14 11:30:13 ----A---- C:\Windows\SYSWOW64\AdmTmpl.dll
2011-06-14 11:30:13 ----A---- C:\Windows\system32\WUDFPlatform.dll
2011-06-14 11:30:13 ----A---- C:\Windows\system32\unimdmat.dll
2011-06-14 11:30:13 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2011-06-14 11:30:13 ----A---- C:\Windows\system32\OpcServices.dll
2011-06-14 11:30:13 ----A---- C:\Windows\system32\msyuv.dll
2011-06-14 11:30:13 ----A---- C:\Windows\system32\msrle32.dll
2011-06-14 11:30:13 ----A---- C:\Windows\system32\mfps.dll
2011-06-14 11:30:13 ----A---- C:\Windows\system32\mapistub.dll
2011-06-14 11:30:13 ----A---- C:\Windows\system32\mapi32.dll
2011-06-14 11:30:13 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2011-06-14 11:30:12 ----A---- C:\Windows\SYSWOW64\WPDShServiceObj.dll
2011-06-14 11:30:12 ----A---- C:\Windows\SYSWOW64\wmdrmsdk.dll
2011-06-14 11:30:12 ----A---- C:\Windows\SYSWOW64\uxlib.dll
2011-06-14 11:30:12 ----A---- C:\Windows\SYSWOW64\slwga.dll
2011-06-14 11:30:12 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2011-06-14 11:30:12 ----A---- C:\Windows\SYSWOW64\nslookup.exe
2011-06-14 11:30:12 ----A---- C:\Windows\SYSWOW64\msvfw32.dll
2011-06-14 11:30:12 ----A---- C:\Windows\SYSWOW64\msscp.dll
2011-06-14 11:30:12 ----A---- C:\Windows\SYSWOW64\mciavi32.dll
2011-06-14 11:30:12 ----A---- C:\Windows\SYSWOW64\DevicePairingFolder.dll
2011-06-14 11:30:12 ----A---- C:\Windows\SYSWOW64\clusapi.dll
2011-06-14 11:30:12 ----A---- C:\Windows\SYSWOW64\audiodev.dll
2011-06-14 11:30:12 ----A---- C:\Windows\system32\wmpshell.dll
2011-06-14 11:30:12 ----A---- C:\Windows\system32\WindowsAnytimeUpgradeResults.exe
2011-06-14 11:30:12 ----A---- C:\Windows\system32\tsbyuv.dll
2011-06-14 11:30:12 ----A---- C:\Windows\system32\seclogon.dll
2011-06-14 11:30:12 ----A---- C:\Windows\system32\rdpencom.dll
2011-06-14 11:30:12 ----A---- C:\Windows\system32\perfmon.exe
2011-06-14 11:30:12 ----A---- C:\Windows\system32\muifontsetup.dll
2011-06-14 11:30:12 ----A---- C:\Windows\system32\iscsium.dll
2011-06-14 11:30:12 ----A---- C:\Windows\system32\ifsutil.dll
2011-06-14 11:30:12 ----A---- C:\Windows\system32\drivers\umbus.sys
2011-06-14 11:30:12 ----A---- C:\Windows\system32\diskraid.exe
2011-06-14 11:30:12 ----A---- C:\Windows\system32\d3d10level9.dll
2011-06-14 11:30:11 ----A---- C:\Windows\SYSWOW64\wimserv.exe
2011-06-14 11:30:11 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2011-06-14 11:30:11 ----A---- C:\Windows\SYSWOW64\remotepg.dll
2011-06-14 11:30:11 ----A---- C:\Windows\SYSWOW64\rdpencom.dll
2011-06-14 11:30:11 ----A---- C:\Windows\SYSWOW64\raschap.dll
2011-06-14 11:30:11 ----A---- C:\Windows\SYSWOW64\QUTIL.DLL
2011-06-14 11:30:11 ----A---- C:\Windows\SYSWOW64\perfmon.exe
2011-06-14 11:30:11 ----A---- C:\Windows\SYSWOW64\odbccp32.dll
2011-06-14 11:30:11 ----A---- C:\Windows\SYSWOW64\networkexplorer.dll
2011-06-14 11:30:11 ----A---- C:\Windows\SYSWOW64\NAPCRYPT.DLL
2011-06-14 11:30:11 ----A---- C:\Windows\SYSWOW64\input.dll
2011-06-14 11:30:11 ----A---- C:\Windows\SYSWOW64\drmmgrtn.dll
2011-06-14 11:30:11 ----A---- C:\Windows\SYSWOW64\diskraid.exe
2011-06-14 11:30:11 ----A---- C:\Windows\SYSWOW64\acppage.dll
2011-06-14 11:30:11 ----A---- C:\Windows\system32\wpdwcn.dll
2011-06-14 11:30:11 ----A---- C:\Windows\system32\WMADMOD.DLL
2011-06-14 11:30:11 ----A---- C:\Windows\system32\wiavideo.dll
2011-06-14 11:30:11 ----A---- C:\Windows\system32\umb.dll
2011-06-14 11:30:11 ----A---- C:\Windows\system32\tlscsp.dll
2011-06-14 11:30:11 ----A---- C:\Windows\system32\syssetup.dll
2011-06-14 11:30:11 ----A---- C:\Windows\system32\runonce.exe
2011-06-14 11:30:11 ----A---- C:\Windows\system32\raschap.dll
2011-06-14 11:30:11 ----A---- C:\Windows\system32\qasf.dll
2011-06-14 11:30:11 ----A---- C:\Windows\system32\netutils.dll
2011-06-14 11:30:11 ----A---- C:\Windows\system32\NAPCRYPT.DLL
2011-06-14 11:30:11 ----A---- C:\Windows\system32\FXSAPI.dll
2011-06-14 11:30:11 ----A---- C:\Windows\system32\dbghelp.dll
2011-06-14 11:30:11 ----A---- C:\Windows\system32\browser.dll
2011-06-14 11:30:11 ----A---- C:\Windows\system32\AzSqlExt.dll
2011-06-14 11:30:11 ----A---- C:\Windows\system32\ActionQueue.dll
2011-06-14 11:30:11 ----A---- C:\Windows\bfsvc.exe
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\wpdwcn.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\wmpshell.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\wmpdxm.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\wmdrmdev.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\vpnikeapi.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\vdsbas.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\UserAccountControlSettings.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\shacct.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\runonce.exe
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\onexui.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\olepro32.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\ocsetapi.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\msvidc32.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\msiexec.exe
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\MFPlay.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\lsmproxy.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\logagent.exe
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\iTVData.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\eapp3hst.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\dxdiagn.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\d3d10level9.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\bitsadmin.exe
2011-06-14 11:30:10 ----A---- C:\Windows\system32\WPDSp.dll
2011-06-14 11:30:10 ----A---- C:\Windows\system32\WMVSDECD.DLL
2011-06-14 11:30:10 ----A---- C:\Windows\system32\wmdrmnet.dll
2011-06-14 11:30:10 ----A---- C:\Windows\system32\vss_ps.dll
2011-06-14 11:30:10 ----A---- C:\Windows\system32\vdsbas.dll
2011-06-14 11:30:10 ----A---- C:\Windows\system32\tabcal.exe
2011-06-14 11:30:10 ----A---- C:\Windows\system32\shacct.dll
2011-06-14 11:30:10 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2011-06-14 11:30:10 ----A---- C:\Windows\system32\QSVRMGMT.DLL
2011-06-14 11:30:10 ----A---- C:\Windows\system32\qcap.dll
2011-06-14 11:30:10 ----A---- C:\Windows\system32\PrintIsolationProxy.dll
2011-06-14 11:30:10 ----A---- C:\Windows\system32\nltest.exe
2011-06-14 11:30:10 ----A---- C:\Windows\system32\mstask.dll
2011-06-14 11:30:10 ----A---- C:\Windows\system32\MdSched.exe
2011-06-14 11:30:10 ----A---- C:\Windows\system32\Mcx2Svc.dll
2011-06-14 11:30:10 ----A---- C:\Windows\system32\logman.exe
2011-06-14 11:30:10 ----A---- C:\Windows\system32\drivers\USBAUDIO.sys
2011-06-14 11:30:10 ----A---- C:\Windows\system32\drivers\tcpipreg.sys
2011-06-14 11:30:10 ----A---- C:\Windows\system32\drivers\rmcast.sys
2011-06-14 11:30:10 ----A---- C:\Windows\system32\cscapi.dll
2011-06-14 11:30:10 ----A---- C:\Windows\system32\bitsadmin.exe
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\WPDSp.dll
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\unimdmat.dll
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\srvcli.dll
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\sqlcese30.dll
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\rdpd3d.dll
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\QSVRMGMT.DLL
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\PortableDeviceSyncProvider.dll
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\PortableDeviceStatus.dll
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\pdh.dll
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\OpcServices.dll
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\olethk32.dll
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\odbctrac.dll
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\ncryptui.dll
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\mprapi.dll
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\logman.exe
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\iscsium.dll
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\cscapi.dll
2011-06-14 11:30:09 ----A---- C:\Windows\system32\wudriver.dll
2011-06-14 11:30:09 ----A---- C:\Windows\system32\WMSPDMOD.DLL
2011-06-14 11:30:09 ----A---- C:\Windows\system32\vmictimeprovider.dll
2011-06-14 11:30:09 ----A---- C:\Windows\system32\spbcd.dll
2011-06-14 11:30:09 ----A---- C:\Windows\system32\secproc_ssp.dll
2011-06-14 11:30:09 ----A---- C:\Windows\system32\qdv.dll
2011-06-14 11:30:09 ----A---- C:\Windows\system32\PortableDeviceSyncProvider.dll
2011-06-14 11:30:09 ----A---- C:\Windows\system32\PortableDeviceStatus.dll
2011-06-14 11:30:09 ----A---- C:\Windows\system32\msnetobj.dll
2011-06-14 11:30:09 ----A---- C:\Windows\system32\fphc.dll
2011-06-14 11:30:09 ----A---- C:\Windows\system32\drivers\ndisuio.sys
2011-06-14 11:30:09 ----A---- C:\Windows\system32\dot3ui.dll
2011-06-14 11:30:09 ----A---- C:\Windows\system32\CscMig.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\WMVSDECD.DLL
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\wmdrmnet.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\WMADMOD.DLL
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\wiavideo.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\utildll.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\takeown.exe
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\sqmapi.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\sppinst.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\qdv.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\QCLIPROV.DLL
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\msyuv.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\msrle32.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\msnetobj.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\mapistub.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\mapi32.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\iyuv_32.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\fphc.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\EhStorAPI.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\dot3msm.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\cmstp.exe
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\cca.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\avifil32.dll
2011-06-14 11:30:08 ----A---- C:\Windows\system32\WUDFx.dll
2011-06-14 11:30:08 ----A---- C:\Windows\system32\WUDFHost.exe
2011-06-14 11:30:08 ----A---- C:\Windows\system32\WMPhoto.dll
2011-06-14 11:30:08 ----A---- C:\Windows\system32\WavDest.dll
2011-06-14 11:30:08 ----A---- C:\Windows\system32\vfwwdm32.dll
2011-06-14 11:30:08 ----A---- C:\Windows\system32\takeown.exe
2011-06-14 11:30:08 ----A---- C:\Windows\system32\shimgvw.dll
2011-06-14 11:30:08 ----A---- C:\Windows\system32\QCLIPROV.DLL
2011-06-14 11:30:08 ----A---- C:\Windows\system32\PnPUnattend.exe
2011-06-14 11:30:08 ----A---- C:\Windows\system32\nrpsrv.dll
2011-06-14 11:30:08 ----A---- C:\Windows\system32\netapi32.dll
2011-06-14 11:30:08 ----A---- C:\Windows\system32\iasrecst.dll
2011-06-14 11:30:08 ----A---- C:\Windows\system32\HotStartUserAgent.dll
2011-06-14 11:30:08 ----A---- C:\Windows\system32\EhStorAPI.dll
2011-06-14 11:30:08 ----A---- C:\Windows\system32\djoin.exe
2011-06-14 11:30:08 ----A---- C:\Windows\system32\cmstp.exe
2011-06-14 11:30:08 ----A---- C:\Windows\system32\CertPolEng.dll
2011-06-14 11:30:08 ----A---- C:\Windows\system32\amstream.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\wsnmp32.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\WMSPDMOD.DLL
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\wkscli.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\vfwwdm32.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\tsbyuv.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\spbcd.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\setupcln.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\secproc_ssp_isv.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\secproc_ssp.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\resutils.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\relog.exe
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\rastapi.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\pdhui.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\netiougc.exe
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\netbtugc.exe
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\mydocs.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\MuiUnattend.exe
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\msorcl32.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\itircl.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\iscsicli.exe
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\iasrecst.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\diskpart.exe
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\AzSqlExt.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\amstream.dll
2011-06-14 11:30:07 ----A---- C:\Windows\system32\wuauclt.exe
2011-06-14 11:30:07 ----A---- C:\Windows\system32\sscore.dll
2011-06-14 11:30:07 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2011-06-14 11:30:07 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2011-06-14 11:30:07 ----A---- C:\Windows\system32\relog.exe
2011-06-14 11:30:07 ----A---- C:\Windows\system32\mydocs.dll
2011-06-14 11:30:07 ----A---- C:\Windows\system32\MultiDigiMon.exe
2011-06-14 11:30:07 ----A---- C:\Windows\system32\msdmo.dll
2011-06-14 11:30:07 ----A---- C:\Windows\system32\mobsync.exe
2011-06-14 11:30:07 ----A---- C:\Windows\system32\KMSVC.DLL
2011-06-14 11:30:07 ----A---- C:\Windows\system32\itircl.dll
2011-06-14 11:30:07 ----A---- C:\Windows\system32\iscsicli.exe
2011-06-14 11:30:07 ----A---- C:\Windows\system32\fdProxy.dll
2011-06-14 11:30:07 ----A---- C:\Windows\system32\drivers\usbser.sys
2011-06-14 11:30:07 ----A---- C:\Windows\system32\drivers\pacer.sys
2011-06-14 11:30:07 ----A---- C:\Windows\system32\dot3msm.dll
2011-06-14 11:30:07 ----A---- C:\Windows\system32\diskpart.exe
2011-06-14 11:30:07 ----A---- C:\Windows\system32\BWUnpairElevated.dll
2011-06-14 11:30:07 ----A---- C:\Windows\system32\browcli.dll
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\wmpps.dll
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\WerFaultSecure.exe
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\tlscsp.dll
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\syssetup.dll
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\sppc.dll
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\spopk.dll
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\shimgvw.dll
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\secur32.dll
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp_isv.exe
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp.exe
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\ReAgentc.exe
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\netutils.dll
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\netapi32.dll
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\muifontsetup.dll
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\mobsync.exe
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\mciqtz32.dll
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\luainstall.dll
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\iccvid.dll
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\findstr.exe
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\eappgnui.dll
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\CertPolEng.dll
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\cabinet.dll
2011-06-14 11:30:06 ----A---- C:\Windows\system32\wuapp.exe
2011-06-14 11:30:06 ----A---- C:\Windows\system32\wdiasqmmodule.dll
2011-06-14 11:30:06 ----A---- C:\Windows\system32\sppc.dll
2011-06-14 11:30:06 ----A---- C:\Windows\system32\spopk.dll
2011-06-14 11:30:06 ----A---- C:\Windows\system32\schedcli.dll
2011-06-14 11:30:06 ----A---- C:\Windows\system32\repair-bde.exe
2011-06-14 11:30:06 ----A---- C:\Windows\system32\RDPENCDD.dll
2011-06-14 11:30:06 ----A---- C:\Windows\system32\qprocess.exe
2011-06-14 11:30:06 ----A---- C:\Windows\system32\qappsrv.exe
2011-06-14 11:30:06 ----A---- C:\Windows\system32\onexui.dll
2011-06-14 11:30:06 ----A---- C:\Windows\system32\mciqtz32.dll
2011-06-14 11:30:06 ----A---- C:\Windows\system32\manage-bde.exe
2011-06-14 11:30:06 ----A---- C:\Windows\system32\luainstall.dll
2011-06-14 11:30:06 ----A---- C:\Windows\system32\inetmib1.dll
2011-06-14 11:30:06 ----A---- C:\Windows\system32\imagehlp.dll
2011-06-14 11:30:06 ----A---- C:\Windows\system32\choice.exe
2011-06-14 11:30:06 ----A---- C:\Windows\system32\chglogon.exe
2011-06-14 11:30:06 ----A---- C:\Windows\system32\FXSTIFF.dll
2011-06-14 11:30:06 ----A---- C:\Windows\system32\findstr.exe
2011-06-14 11:30:06 ----A---- C:\Windows\system32\eappgnui.dll
2011-06-14 11:30:06 ----A---- C:\Windows\system32\drivers\tunnel.sys
2011-06-14 11:30:06 ----A---- C:\Windows\system32\drivers\dfsc.sys
2011-06-14 11:30:05 ----A---- C:\Windows\SYSWOW64\wups.dll
2011-06-14 11:30:05 ----A---- C:\Windows\SYSWOW64\unlodctr.exe
2011-06-14 11:30:05 ----A---- C:\Windows\SYSWOW64\UIRibbonRes.dll
2011-06-14 11:30:05 ----A---- C:\Windows\SYSWOW64\rdprefdrvapi.dll
2011-06-14 11:30:05 ----A---- C:\Windows\SYSWOW64\perfts.dll
2011-06-14 11:30:05 ----A---- C:\Windows\SYSWOW64\odbcconf.dll
2011-06-14 11:30:05 ----A---- C:\Windows\SYSWOW64\msdmo.dll
2011-06-14 11:30:05 ----A---- C:\Windows\SYSWOW64\inetmib1.dll
2011-06-14 11:30:05 ----A---- C:\Windows\SYSWOW64\imm32.dll
2011-06-14 11:30:05 ----A---- C:\Windows\SYSWOW64\browcli.dll
2011-06-14 11:30:05 ----A---- C:\Windows\system32\WUDFCoinstaller.dll
2011-06-14 11:30:05 ----A---- C:\Windows\system32\wshbth.dll
2011-06-14 11:30:05 ----A---- C:\Windows\system32\vmstorfltres.dll
2011-06-14 11:30:05 ----A---- C:\Windows\system32\vmicres.dll
2011-06-14 11:30:05 ----A---- C:\Windows\system32\vmbusres.dll
2011-06-14 11:30:05 ----A---- C:\Windows\system32\UIRibbonRes.dll
2011-06-14 11:30:05 ----A---- C:\Windows\system32\tskill.exe
2011-06-14 11:30:05 ----A---- C:\Windows\system32\tsdiscon.exe
2011-06-14 11:30:05 ----A---- C:\Windows\system32\tscon.exe
2011-06-14 11:30:05 ----A---- C:\Windows\system32\TRAPI.dll
2011-06-14 11:30:05 ----A---- C:\Windows\system32\shadow.exe
2011-06-14 11:30:05 ----A---- C:\Windows\system32\rwinsta.exe
2011-06-14 11:30:05 ----A---- C:\Windows\system32\profprov.dll
2011-06-14 11:30:05 ----A---- C:\Windows\system32\odbcconf.dll
2011-06-14 11:30:05 ----A---- C:\Windows\system32\LogonUI.exe
2011-06-14 11:30:05 ----A---- C:\Windows\system32\logoff.exe
2011-06-14 11:30:05 ----A---- C:\Windows\system32\chgusr.exe
2011-06-14 11:30:05 ----A---- C:\Windows\system32\chgport.exe
2011-06-14 11:30:05 ----A---- C:\Windows\system32\FXSMON.dll
2011-06-14 11:30:05 ----A---- C:\Windows\system32\fixmapi.exe
2011-06-14 11:30:05 ----A---- C:\Windows\system32\elsTrans.dll
2011-06-14 11:30:05 ----A---- C:\Windows\system32\dsauth.dll
2011-06-14 11:30:05 ----A---- C:\Windows\system32\drivers\tdi.sys
2011-06-14 11:30:04 ----A---- C:\Windows\SYSWOW64\wshbth.dll
2011-06-14 11:30:04 ----A---- C:\Windows\SYSWOW64\TRAPI.dll
2011-06-14 11:30:04 ----A---- C:\Windows\SYSWOW64\schedcli.dll
2011-06-14 11:30:04 ----A---- C:\Windows\SYSWOW64\napdsnap.dll
2011-06-14 11:30:04 ----A---- C:\Windows\SYSWOW64\elsTrans.dll
2011-06-14 11:30:04 ----A---- C:\Windows\SYSWOW64\dsauth.dll
2011-06-14 11:30:04 ----A---- C:\Windows\SYSWOW64\cscdll.dll
2011-06-14 11:30:04 ----A---- C:\Windows\SYSWOW64\bitsperf.dll
2011-06-14 11:30:04 ----A---- C:\Windows\system32\reset.exe
2011-06-14 11:30:04 ----A---- C:\Windows\system32\rdprefdrvapi.dll
2011-06-14 11:30:04 ----A---- C:\Windows\system32\query.exe
2011-06-14 11:30:04 ----A---- C:\Windows\system32\napdsnap.dll
2011-06-14 11:30:04 ----A---- C:\Windows\system32\change.exe
2011-06-14 11:30:04 ----A---- C:\Windows\system32\FXSUNATD.exe
2011-06-14 11:30:04 ----A---- C:\Windows\system32\drivers\usbrpm.sys
2011-06-14 11:30:04 ----A---- C:\Windows\system32\drivers\acpipmi.sys
2011-06-14 11:30:04 ----A---- C:\Windows\system32\cscdll.dll
2011-06-14 11:30:04 ----A---- C:\Windows\system32\bitsperf.dll
2011-06-14 11:30:03 ----A---- C:\Windows\SYSWOW64\wsdchngr.dll
2011-06-14 11:30:03 ----A---- C:\Windows\SYSWOW64\sscore.dll
2011-06-14 11:30:03 ----A---- C:\Windows\SYSWOW64\shgina.dll
2011-06-14 11:30:03 ----A---- C:\Windows\SYSWOW64\riched32.dll
2011-06-14 11:30:03 ----A---- C:\Windows\system32\wups2.dll
2011-06-14 11:30:03 ----A---- C:\Windows\system32\wups.dll
2011-06-14 11:30:03 ----A---- C:\Windows\system32\wsdchngr.dll
2011-06-14 11:30:03 ----A---- C:\Windows\system32\shgina.dll
2011-06-14 11:30:03 ----A---- C:\Windows\system32\PJLMON.DLL
2011-06-14 11:30:02 ----A---- C:\Windows\SYSWOW64\wshirda.dll
2011-06-14 11:30:02 ----A---- C:\Windows\system32\wshirda.dll
2011-06-14 11:30:02 ----A---- C:\Windows\system32\wow64win.dll
2011-06-14 11:30:02 ----A---- C:\Windows\system32\wow64cpu.dll
2011-06-14 11:30:02 ----A---- C:\Windows\system32\vmbuspipe.dll
2011-06-14 11:30:02 ----A---- C:\Windows\system32\spwmp.dll
2011-06-14 11:30:02 ----A---- C:\Windows\system32\riched32.dll
2011-06-14 11:30:02 ----A---- C:\Windows\system32\rdpcfgex.dll
2011-06-14 11:30:02 ----A---- C:\Windows\system32\drivers\USBCAMD2.sys
2011-06-14 11:30:02 ----A---- C:\Windows\system32\drivers\kbdhid.sys
2011-06-14 11:30:02 ----A---- C:\Windows\system32\drivers\IPMIDrv.sys
2011-06-14 11:30:02 ----A---- C:\Windows\system32\drivers\hidusb.sys
2011-06-14 11:30:02 ----A---- C:\Windows\system32\drivers\CompositeBus.sys
2011-06-14 11:30:02 ----A---- C:\Windows\system32\drivers\appid.sys
2011-06-14 11:30:02 ----A---- C:\Windows\system32\browseui.dll
2011-06-14 11:30:01 ----AH---- C:\Windows\system32\api-ms-win-core-ums-l1-1-0.dll
2011-06-14 11:30:01 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2011-06-14 11:30:01 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2011-06-14 11:30:01 ----A---- C:\Windows\SYSWOW64\shunimpl.dll
2011-06-14 11:30:01 ----A---- C:\Windows\SYSWOW64\KBDTUQ.DLL
2011-06-14 11:30:01 ----A---- C:\Windows\SYSWOW64\KBDTUF.DLL
2011-06-14 11:30:01 ----A---- C:\Windows\SYSWOW64\KBDSG.DLL
2011-06-14 11:30:01 ----A---- C:\Windows\SYSWOW64\kbdlk41a.dll
2011-06-14 11:30:01 ----A---- C:\Windows\SYSWOW64\KBDGR1.DLL
2011-06-14 11:30:01 ----A---- C:\Windows\SYSWOW64\KBDGKL.DLL
2011-06-14 11:30:01 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2011-06-14 11:30:01 ----A---- C:\Windows\SYSWOW64\C_ISCII.DLL
2011-06-14 11:30:01 ----A---- C:\Windows\SYSWOW64\browseui.dll
2011-06-14 11:30:01 ----A---- C:\Windows\system32\VmdCoinstall.dll
2011-06-14 11:30:01 ----A---- C:\Windows\system32\VmbusCoinstaller.dll
2011-06-14 11:30:01 ----A---- C:\Windows\system32\shunimpl.dll
2011-06-14 11:30:01 ----A---- C:\Windows\system32\KBDTUQ.DLL
2011-06-14 11:30:01 ----A---- C:\Windows\system32\KBDTUF.DLL
2011-06-14 11:30:01 ----A---- C:\Windows\system32\KBDSG.DLL
2011-06-14 11:30:01 ----A---- C:\Windows\system32\KBDSF.DLL
2011-06-14 11:30:01 ----A---- C:\Windows\system32\KBDPO.DLL
2011-06-14 11:30:01 ----A---- C:\Windows\system32\KBDNEPR.DLL
2011-06-14 11:30:01 ----A---- C:\Windows\system32\kbdlk41a.dll
2011-06-14 11:30:01 ----A---- C:\Windows\system32\KBDINTAM.DLL
2011-06-14 11:30:01 ----A---- C:\Windows\system32\KBDINBEN.DLL
2011-06-14 11:30:01 ----A---- C:\Windows\system32\KBDGR1.DLL
2011-06-14 11:30:01 ----A---- C:\Windows\system32\KBDGKL.DLL
2011-06-14 11:30:01 ----A---- C:\Windows\system32\IcCoinstall.dll
2011-06-14 11:30:01 ----A---- C:\Windows\system32\dxmasf.dll
2011-06-14 11:30:01 ----A---- C:\Windows\system32\drivers\WUDFRd.sys
2011-06-14 11:30:01 ----A---- C:\Windows\system32\drivers\WUDFPf.sys
2011-06-14 11:30:01 ----A---- C:\Windows\system32\drivers\sffp_sd.sys
2011-06-14 11:30:01 ----A---- C:\Windows\system32\drivers\scfilter.sys
2011-06-14 11:30:01 ----A---- C:\Windows\system32\drivers\HdAudio.sys
2011-06-14 11:30:01 ----A---- C:\Windows\system32\drivers\hdaudbus.sys
2011-06-14 11:30:01 ----A---- C:\Windows\system32\drivers\cdrom.sys
2011-06-14 11:30:01 ----A---- C:\Windows\system32\C_ISCII.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\tzres.dll
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\spwizres.dll
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\pifmgr.dll
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\nlsbres.dll
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDUS.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDUGHR1.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDTURME.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDTAJIK.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDSF.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDPO.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDNEPR.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDMON.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDMAORI.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDLT1.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDINTEL.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDINTAM.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDINORI.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDINMAR.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDINKAN.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDINHIN.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDINBEN.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDGEO.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDCZ1.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDBULG.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDBLR.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDBASH.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\dpnaddr.dll
2011-06-14 11:30:00 ----A---- C:\Windows\system32\wmploc.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\tzres.dll
2011-06-14 11:30:00 ----A---- C:\Windows\system32\spwizres.dll
2011-06-14 11:30:00 ----A---- C:\Windows\system32\pifmgr.dll
2011-06-14 11:30:00 ----A---- C:\Windows\system32\nlsbres.dll
2011-06-14 11:30:00 ----A---- C:\Windows\system32\KBDUS.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\KBDUGHR1.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\KBDTURME.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\KBDTAJIK.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\KBDMON.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\KBDMAORI.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\KBDLT1.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\KBDINTEL.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\KBDINORI.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\KBDINMAR.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\KBDINKAN.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\KBDINHIN.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\KBDGEO.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\KBDCZ1.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\KBDBULG.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\KBDBLR.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\KBDBASH.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\drivers\vms3cap.sys
2011-06-14 11:30:00 ----A---- C:\Windows\system32\drivers\VMBusHID.sys
2011-06-14 11:30:00 ----A---- C:\Windows\system32\dpnaddr.dll
2011-06-14 11:30:00 ----A---- C:\Windows\system32\BlbEvents.dll
2011-06-14 11:29:50 ----A---- C:\Windows\SYSWOW64\wdscore.dll
2011-06-14 11:29:50 ----A---- C:\Windows\SYSWOW64\printmanagement.msc
2011-06-14 11:29:50 ----A---- C:\Windows\SYSWOW64\PkgMgr.exe
2011-06-14 11:29:46 ----A---- C:\Windows\SYSWOW64\drvstore.dll
2011-06-14 11:29:46 ----A---- C:\Windows\SYSWOW64\dpx.dll
2011-06-14 11:29:44 ----A---- C:\Windows\SYSWOW64\wbemcomn.dll
2011-06-14 11:28:34 ----A---- C:\Windows\system32\wmicmiplugin.dll
2011-06-14 11:28:34 ----A---- C:\Windows\system32\wbemcomn.dll
2011-06-14 11:28:27 ----A---- C:\Windows\system32\SmiEngine.dll
2011-06-14 11:28:26 ----A---- C:\Windows\system32\PkgMgr.exe
2011-06-14 11:28:20 ----A---- C:\Windows\system32\drvstore.dll
2011-06-14 11:28:19 ----A---- C:\Windows\system32\dpx.dll
2011-06-13 10:05:56 ----D---- C:\Program Files (x86)\Valve
2011-06-12 19:55:03 ----D---- C:\Program Files (x86)\Portal
2011-06-12 17:46:54 ----D---- C:\Users\WoMec\AppData\Roaming\vlc
2011-06-10 15:12:23 ----D---- C:\Users\WoMec\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2011-06-10 15:09:26 ----D---- C:\Program Files\Common Files\PACE Anti-Piracy
2011-06-10 15:09:26 ----A---- C:\Windows\SurCode.INI
======List of files/folders modified in the last 1 months======
2011-07-04 00:49:44 ----D---- C:\Windows\Temp
2011-07-04 00:42:26 ----D---- C:\ProgramData
2011-07-04 00:42:23 ----D---- C:\ProgramData\Microsoft
2011-07-04 00:39:13 ----D---- C:\Windows\system32\config
2011-07-04 00:38:54 ----SHD---- C:\Windows\Installer
2011-07-04 00:38:46 ----D---- C:\Windows\system32\DriverStore
2011-07-04 00:38:46 ----D---- C:\Windows\system32\drivers
2011-07-04 00:38:46 ----D---- C:\Windows\system32\catroot
2011-07-04 00:38:46 ----D---- C:\Windows\inf
2011-07-04 00:38:11 ----RD---- C:\Program Files
2011-07-04 00:38:02 ----SHD---- C:\System Volume Information
2011-07-04 00:05:42 ----D---- C:\Windows\System32
2011-07-04 00:05:25 ----D---- C:\Program Files (x86)\QIP 2010
2011-07-03 23:54:22 ----D---- C:\Boot
2011-07-03 23:45:45 ----D---- C:\Windows\Prefetch
2011-07-03 23:44:18 ----D---- C:\Windows
2011-07-03 23:39:00 ----A---- C:\Windows\system.ini
2011-07-03 23:38:56 ----D---- C:\Windows\system32\drivers\etc
2011-07-03 23:38:32 ----D---- C:\Windows\SysWOW64
2011-07-03 23:38:31 ----RD---- C:\Program Files (x86)
2011-07-03 23:36:48 ----D---- C:\Windows\SYSWOW64\drivers
2011-07-03 23:36:48 ----D---- C:\Windows\AppPatch
2011-07-03 23:36:47 ----D---- C:\Program Files\Common Files
2011-07-03 23:36:47 ----D---- C:\Program Files (x86)\Common Files
2011-07-03 22:36:43 ----D---- C:\Windows\winsxs
2011-07-03 22:02:57 ----D---- C:\Program Files (x86)\totalcmd
2011-07-03 17:40:11 ----D---- C:\Users\WoMec\AppData\Roaming\uTorrent
2011-07-03 17:39:35 ----D---- C:\Windows\debug
2011-07-03 16:50:14 ----D---- C:\Windows\pss
2011-07-01 15:05:57 ----AD---- C:\Program Files (x86)\RQMONEY_1_3
2011-06-29 15:18:54 ----RSD---- C:\Windows\Fonts
2011-06-29 14:58:07 ----D---- C:\Program Files (x86)\Microsoft Office
2011-06-29 14:40:11 ----D---- C:\Windows\system32\catroot2
2011-06-27 19:37:54 ----D---- C:\Windows\rescache
2011-06-27 18:17:22 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-06-27 17:06:48 ----D---- C:\Program Files (x86)\Google
2011-06-25 14:55:35 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-06-23 16:34:40 ----D---- C:\Program Files (x86)\SpeedFan
2011-06-22 15:37:06 ----D---- C:\Program Files (x86)\Mozilla Thunderbird
2011-06-16 18:26:08 ----RSD---- C:\Windows\assembly
2011-06-16 18:26:08 ----D---- C:\Windows\Microsoft.NET
2011-06-16 10:38:14 ----D---- C:\Program Files\NVIDIA Corporation
2011-06-15 14:35:18 ----D---- C:\Users\WoMec\AppData\Roaming\Bioshock
2011-06-15 11:40:03 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2011-06-15 11:38:48 ----D---- C:\Program Files\Internet Explorer
2011-06-15 11:38:48 ----D---- C:\Program Files (x86)\Internet Explorer
2011-06-15 11:28:35 ----D---- C:\Program Files (x86)\Adobe
2011-06-15 11:25:51 ----A---- C:\Windows\system32\MRT.exe
2011-06-15 11:23:23 ----AD---- C:\Program Files\Common Files\Microsoft Shared
2011-06-15 11:01:26 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-06-15 11:01:26 ----D---- C:\Program Files (x86)\Codemasters
2011-06-15 11:00:26 ----D---- C:\Program Files (x86)\z2 Remote2PC
2011-06-15 10:59:53 ----D---- C:\Windows\WindowsMobile
2011-06-15 10:59:35 ----DC---- C:\Windows\system32\DRVSTORE
2011-06-15 10:58:32 ----D---- C:\Program Files (x86)\Nokia
2011-06-15 10:56:43 ----D---- C:\Program Files (x86)\National Instruments
2011-06-15 10:01:56 ----D---- C:\Users\WoMec\AppData\Roaming\Adobe
2011-06-15 10:01:45 ----D---- C:\Program Files\Adobe
2011-06-15 10:01:43 ----D---- C:\Program Files\Common Files\Adobe
2011-06-15 09:59:28 ----D---- C:\Program Files (x86)\MeeSoft
2011-06-14 11:48:36 ----D---- C:\Program Files (x86)\Windows Sidebar
2011-06-14 11:48:36 ----D---- C:\Program Files (x86)\Windows Portable Devices
2011-06-14 11:48:36 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2011-06-14 11:48:36 ----D---- C:\Program Files (x86)\Windows Media Player
2011-06-14 11:48:36 ----D---- C:\Program Files (x86)\Windows Mail
2011-06-14 11:48:35 ----D---- C:\Windows\servicing
2011-06-14 11:48:35 ----D---- C:\Program Files\Windows Sidebar
2011-06-14 11:48:35 ----D---- C:\Program Files\Windows Portable Devices
2011-06-14 11:48:35 ----D---- C:\Program Files\Windows Photo Viewer
2011-06-14 11:48:35 ----D---- C:\Program Files\Windows Media Player
2011-06-14 11:48:35 ----D---- C:\Program Files\Windows Mail
2011-06-14 11:48:35 ----D---- C:\Program Files\Windows Journal
2011-06-14 11:48:35 ----D---- C:\Program Files\Windows Defender
2011-06-14 11:48:35 ----D---- C:\Program Files\DVD Maker
2011-06-14 11:48:34 ----D---- C:\Windows\SYSWOW64\Setup
2011-06-14 11:48:34 ----D---- C:\Windows\SYSWOW64\oobe
2011-06-14 11:48:34 ----D---- C:\Windows\SYSWOW64\migration
2011-06-14 11:48:34 ----D---- C:\Windows\SYSWOW64\da-DK
2011-06-14 11:48:34 ----D---- C:\Windows\SYSWOW64\cs-CZ
2011-06-14 11:48:34 ----D---- C:\Windows\SYSWOW64\cs
2011-06-14 11:48:34 ----D---- C:\Windows\SYSWOW64\AdvancedInstallers
2011-06-14 11:48:34 ----D---- C:\Windows\ehome
2011-06-14 11:48:33 ----D---- C:\Windows\SYSWOW64\wbem
2011-06-14 11:48:33 ----D---- C:\Windows\SYSWOW64\sppui
2011-06-14 11:48:33 ----D---- C:\Windows\SYSWOW64\migwiz
2011-06-14 11:48:33 ----D---- C:\Windows\SYSWOW64\manifeststore
2011-06-14 11:48:33 ----D---- C:\Windows\SYSWOW64\es-ES
2011-06-14 11:48:33 ----D---- C:\Windows\SYSWOW64\Dism
2011-06-14 11:48:30 ----D---- C:\Windows\system32\sppui
2011-06-14 11:48:30 ----D---- C:\Windows\system32\Setup
2011-06-14 11:48:30 ----D---- C:\Windows\system32\oobe
2011-06-14 11:48:30 ----D---- C:\Windows\system32\migration
2011-06-14 11:48:30 ----D---- C:\Windows\system32\manifeststore
2011-06-14 11:48:30 ----D---- C:\Windows\system32\es-ES
2011-06-14 11:48:30 ----D---- C:\Windows\system32\en-US
2011-06-14 11:48:30 ----D---- C:\Windows\system32\da-DK
2011-06-14 11:48:30 ----D---- C:\Windows\system32\cs-CZ
2011-06-14 11:48:30 ----D---- C:\Windows\system32\cs
2011-06-14 11:48:30 ----D---- C:\Windows\system32\AdvancedInstallers
2011-06-14 11:48:30 ----D---- C:\Windows\PolicyDefinitions
2011-06-14 11:48:29 ----D---- C:\Windows\system32\wbem
2011-06-14 11:48:29 ----D---- C:\Windows\system32\migwiz
2011-06-14 11:48:29 ----D---- C:\Windows\system32\drivers\cs-CZ
2011-06-14 11:48:29 ----D---- C:\Windows\system32\Dism
2011-06-14 11:48:22 ----D---- C:\Windows\system32\Boot
2011-06-14 11:40:28 ----A---- C:\Windows\SYSWOW64\msclmd.dll
2011-06-14 11:40:28 ----A---- C:\Windows\system32\msclmd.dll
2011-06-14 01:01:50 ----D---- C:\Users\WoMec\AppData\Roaming\Skype
2011-06-14 00:03:22 ----D---- C:\Users\WoMec\AppData\Roaming\skypePM
2011-06-12 19:42:33 ----D---- C:\Windows\Logs
2011-06-12 19:38:45 ----D---- C:\Program Files (x86)\CCleaner
2011-06-10 17:33:40 ----D---- C:\Users\WoMec\AppData\Roaming\vlc-BackupByVLCPortable
2011-06-10 15:09:26 ----D---- C:\Users\WoMec\AppData\Roaming\PACE Anti-Piracy
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 speedfan;speedfan; C:\Windows\SysWOW64\speedfan.sys [2007-02-07 14104]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-01-30 834544]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-12-21 141264]
R1 MagicTune;MagicTune; C:\Windows\system32\drivers\MTiCtwl.sys [2008-11-04 23096]
R1 Tosrfcom;Bluetooth RFCOMM; C:\Windows\System32\Drivers\tosrfcom.sys [2009-07-28 81768]
R2 adfs;adfs; C:\Windows\system32\drivers\adfs.sys [2008-06-27 88632]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-12-21 170640]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2010-12-21 170640]
R2 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2010-12-21 50624]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-12-08 2223392]
R3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-08-20 239616]
R3 tosporte;Bluetooth COM Port; C:\Windows\system32\DRIVERS\tosporte.sys [2009-06-17 54664]
R3 tosrfbd;Bluetooth RFBUS; C:\Windows\system32\DRIVERS\tosrfbd.sys [2009-08-28 211560]
R3 Tosrfhid;Bluetooth RFHID; C:\Windows\system32\DRIVERS\Tosrfhid.sys [2009-06-19 94336]
R3 Tosrfusb;Bluetooth USB Controller; C:\Windows\system32\DRIVERS\tosrfusb.sys [2009-08-05 58744]
S1 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys []
S3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2009-09-30 121872]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-11-04 6088192]
S3 bomebus;Bome's Virtual MIDI Port Bus Service; C:\Windows\system32\DRIVERS\bomebus.sys [2009-10-15 34376]
S3 bomemidi;Bome's Virtual MIDI Port; C:\Windows\system32\drivers\bomemidi.sys [2009-10-15 30792]
S3 BthAudioHF;BthAudioHF Service; C:\Windows\system32\DRIVERS\BthAudioHF.sys [2009-12-21 52224]
S3 BthAvrcp;Bluetooth AVRCP Profile; C:\Windows\system32\DRIVERS\BthAvrcp.sys [2009-08-13 29184]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2010-11-20 552448]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2010-11-20 80384]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2007-11-21 89640]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2007-11-21 116016]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2007-11-21 33584]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2007-11-21 19760]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 cpuz130;cpuz130; \??\C:\Users\WoMec\AppData\Local\Temp\cpuz130\cpuz_x64.sys []
S3 csr_a2dp;Bluetooth AV Profile; C:\Windows\system32\drivers\bthav.sys [2009-12-21 78848]
S3 ENTECH64;ENTECH64; \??\C:\Windows\system32\DRIVERS\ENTECH64.sys [2007-08-20 12744]
S3 ksaud;Creative USB Audio Driver; C:\Windows\system32\drivers\ksaud.sys [2009-12-15 1148288]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2010-12-02 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2010-12-02 27136]
S3 NPF;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2010-06-25 35344]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys []
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 RivaTuner64;RivaTuner64; \??\C:\Program Files (x86)\RivaTuner v2.24\RivaTuner64.sys [2010-01-31 19952]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 TFsExDisk;TFsExDisk; \??\C:\Windows\System32\Drivers\TFsExDisk.sys [2009-12-14 16392]
S3 toshidpt;Bluetooth HID Port; C:\Windows\system32\drivers\Toshidpt.sys [2009-06-19 9608]
S3 tosrfbnp;Bluetooth RFBNEP; C:\Windows\System32\Drivers\tosrfbnp.sys [2009-06-19 50664]
S3 tosrfnds;Bluetooth Personal Area Network; C:\Windows\system32\DRIVERS\tosrfnds.sys [2009-07-24 26472]
S3 TosRfSnd;Bluetooth Audio; C:\Windows\system32\drivers\tosrfsnd.sys [2009-08-05 63856]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 TVICHW32;TVICHW32; \??\C:\Windows\system32\DRIVERS\TVICHW32.SYS []
S3 TVICHW64;TVICHW64; \??\C:\Windows\SysWOW64\Drivers\TVICHW64.SYS [2005-10-09 13824]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2010-12-02 9216]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2009-07-14 19968]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2010-11-20 32768]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2010-12-02 9216]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 VMnetAdapter;VMware Virtual Ethernet Adapter Driver; C:\Windows\system32\DRIVERS\vmnetadapter.sys []
S3 wceusbsh;Windows CE USB Serial Host Driver; C:\Windows\system32\DRIVERS\wceusbsh.sys [2005-03-24 119552]
S4 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-11-04 202752]
R2 Autodata Limited License Service;Autodata Limited License Service; C:\Program Files (x86)\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe [2010-04-14 72704]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-05-25 2275720]
R2 HFGService;Handsfree Headset Service; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2011-02-23 1005160]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2011-04-03 75136]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-04-16 136176]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2010-01-31 72704]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-02-03 1038088]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-02-03 655624]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-04-16 136176]
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-22 136120]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files (x86)\WinPcap\rpcapd.exe [2010-06-25 117264]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2009-07-30 192368]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-06-13 1255736]
S4 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
2011-06-14 11:30:25 ----A---- C:\Windows\SYSWOW64\eapphost.dll
2011-06-14 11:30:25 ----A---- C:\Windows\system32\wwanconn.dll
2011-06-14 11:30:25 ----A---- C:\Windows\system32\wpd_ci.dll
2011-06-14 11:30:25 ----A---- C:\Windows\system32\wlanui.dll
2011-06-14 11:30:25 ----A---- C:\Windows\system32\shsetup.dll
2011-06-14 11:30:25 ----A---- C:\Windows\system32\sdclt.exe
2011-06-14 11:30:25 ----A---- C:\Windows\system32\prntvpt.dll
2011-06-14 11:30:25 ----A---- C:\Windows\system32\mscorier.dll
2011-06-14 11:30:25 ----A---- C:\Windows\system32\drivers\winusb.sys
2011-06-14 11:30:25 ----A---- C:\Windows\system32\drivers\wanarp.sys
2011-06-14 11:30:25 ----A---- C:\Windows\system32\drivers\scsiport.sys
2011-06-14 11:30:25 ----A---- C:\Windows\system32\bcdsrv.dll
2011-06-14 11:30:24 ----A---- C:\Windows\SYSWOW64\wlanpref.dll
2011-06-14 11:30:24 ----A---- C:\Windows\SYSWOW64\wdc.dll
2011-06-14 11:30:24 ----A---- C:\Windows\SYSWOW64\Vault.dll
2011-06-14 11:30:24 ----A---- C:\Windows\SYSWOW64\untfs.dll
2011-06-14 11:30:24 ----A---- C:\Windows\SYSWOW64\StructuredQuery.dll
2011-06-14 11:30:24 ----A---- C:\Windows\SYSWOW64\scesrv.dll
2011-06-14 11:30:24 ----A---- C:\Windows\SYSWOW64\rastls.dll
2011-06-14 11:30:24 ----A---- C:\Windows\SYSWOW64\QAGENT.DLL
2011-06-14 11:30:24 ----A---- C:\Windows\SYSWOW64\netid.dll
2011-06-14 11:30:24 ----A---- C:\Windows\SYSWOW64\nci.dll
2011-06-14 11:30:24 ----A---- C:\Windows\SYSWOW64\AuxiliaryDisplayCpl.dll
2011-06-14 11:30:24 ----A---- C:\Windows\SYSWOW64\actxprxy.dll
2011-06-14 11:30:24 ----A---- C:\Windows\system32\wmpsrcwp.dll
2011-06-14 11:30:24 ----A---- C:\Windows\system32\qedit.dll
2011-06-14 11:30:24 ----A---- C:\Windows\system32\mprddm.dll
2011-06-14 11:30:24 ----A---- C:\Windows\system32\mblctr.exe
2011-06-14 11:30:24 ----A---- C:\Windows\system32\fontext.dll
2011-06-14 11:30:24 ----A---- C:\Windows\system32\drivers\volmgrx.sys
2011-06-14 11:30:24 ----A---- C:\Windows\system32\drivers\hidclass.sys
2011-06-14 11:30:24 ----A---- C:\Windows\system32\drivers\BTHUSB.SYS
2011-06-14 11:30:24 ----A---- C:\Windows\system32\drivers\bthport.sys
2011-06-14 11:30:24 ----A---- C:\Windows\system32\dps.dll
2011-06-14 11:30:24 ----A---- C:\Windows\system32\Display.dll
2011-06-14 11:30:24 ----A---- C:\Windows\system32\credssp.dll
2011-06-14 11:30:24 ----A---- C:\Windows\system32\batmeter.dll
2011-06-14 11:30:24 ----A---- C:\Windows\system32\AxInstSv.dll
2011-06-14 11:30:23 ----A---- C:\Windows\SYSWOW64\WMNetMgr.dll
2011-06-14 11:30:23 ----A---- C:\Windows\SYSWOW64\taskmgr.exe
2011-06-14 11:30:23 ----A---- C:\Windows\SYSWOW64\RpcRtRemote.dll
2011-06-14 11:30:23 ----A---- C:\Windows\SYSWOW64\Robocopy.exe
2011-06-14 11:30:23 ----A---- C:\Windows\SYSWOW64\DxpTaskSync.dll
2011-06-14 11:30:23 ----A---- C:\Windows\system32\wpccpl.dll
2011-06-14 11:30:23 ----A---- C:\Windows\system32\usercpl.dll
2011-06-14 11:30:23 ----A---- C:\Windows\system32\sppsvc.exe
2011-06-14 11:30:23 ----A---- C:\Windows\system32\SndVolSSO.dll
2011-06-14 11:30:23 ----A---- C:\Windows\system32\rtutils.dll
2011-06-14 11:30:23 ----A---- C:\Windows\system32\rasppp.dll
2011-06-14 11:30:23 ----A---- C:\Windows\system32\provsvc.dll
2011-06-14 11:30:23 ----A---- C:\Windows\system32\MCEWMDRMNDBootstrap.dll
2011-06-14 11:30:23 ----A---- C:\Windows\system32\drivers\winhv.sys
2011-06-14 11:30:23 ----A---- C:\Windows\system32\DiagCpl.dll
2011-06-14 11:30:23 ----A---- C:\Windows\system32\bootres.dll
2011-06-14 11:30:22 ----A---- C:\Windows\SYSWOW64\XpsRasterService.dll
2011-06-14 11:30:22 ----A---- C:\Windows\SYSWOW64\userinit.exe
2011-06-14 11:30:22 ----A---- C:\Windows\SYSWOW64\termmgr.dll
2011-06-14 11:30:22 ----A---- C:\Windows\SYSWOW64\puiobj.dll
2011-06-14 11:30:22 ----A---- C:\Windows\SYSWOW64\mtxclu.dll
2011-06-14 11:30:22 ----A---- C:\Windows\SYSWOW64\logoncli.dll
2011-06-14 11:30:22 ----A---- C:\Windows\SYSWOW64\eudcedit.exe
2011-06-14 11:30:22 ----A---- C:\Windows\SYSWOW64\Display.dll
2011-06-14 11:30:22 ----A---- C:\Windows\system32\WPDShServiceObj.dll
2011-06-14 11:30:22 ----A---- C:\Windows\system32\untfs.dll
2011-06-14 11:30:22 ----A---- C:\Windows\system32\taskmgr.exe
2011-06-14 11:30:22 ----A---- C:\Windows\system32\shdocvw.dll
2011-06-14 11:30:22 ----A---- C:\Windows\system32\proquota.exe
2011-06-14 11:30:22 ----A---- C:\Windows\system32\prnfldr.dll
2011-06-14 11:30:22 ----A---- C:\Windows\system32\pdh.dll
2011-06-14 11:30:22 ----A---- C:\Windows\system32\MSAC3ENC.DLL
2011-06-14 11:30:22 ----A---- C:\Windows\system32\hbaapi.dll
2011-06-14 11:30:22 ----A---- C:\Windows\system32\dxdiagn.dll
2011-06-14 11:30:22 ----A---- C:\Windows\system32\drivers\rdyboost.sys
2011-06-14 11:30:22 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2011-06-14 11:30:22 ----A---- C:\Windows\system32\drivers\ataport.sys
2011-06-14 11:30:22 ----A---- C:\Windows\system32\dot3cfg.dll
2011-06-14 11:30:21 ----A---- C:\Windows\SYSWOW64\wiadefui.dll
2011-06-14 11:30:21 ----A---- C:\Windows\SYSWOW64\themecpl.dll
2011-06-14 11:30:21 ----A---- C:\Windows\SYSWOW64\sppcomapi.dll
2011-06-14 11:30:21 ----A---- C:\Windows\SYSWOW64\shsetup.dll
2011-06-14 11:30:21 ----A---- C:\Windows\SYSWOW64\SensorsCpl.dll
2011-06-14 11:30:21 ----A---- C:\Windows\SYSWOW64\rasppp.dll
2011-06-14 11:30:21 ----A---- C:\Windows\SYSWOW64\FWPUCLNT.DLL
2011-06-14 11:30:21 ----A---- C:\Windows\SYSWOW64\FirewallControlPanel.dll
2011-06-14 11:30:21 ----A---- C:\Windows\SYSWOW64\cabview.dll
2011-06-14 11:30:21 ----A---- C:\Windows\system32\userinit.exe
2011-06-14 11:30:21 ----A---- C:\Windows\system32\slui.exe
2011-06-14 11:30:21 ----A---- C:\Windows\system32\rdpcorekmts.dll
2011-06-14 11:30:21 ----A---- C:\Windows\system32\accessibilitycpl.dll
2011-06-14 11:30:20 ----A---- C:\Windows\SYSWOW64\tapisrv.dll
2011-06-14 11:30:20 ----A---- C:\Windows\SYSWOW64\scecli.dll
2011-06-14 11:30:20 ----A---- C:\Windows\SYSWOW64\mscories.dll
2011-06-14 11:30:20 ----A---- C:\Windows\SYSWOW64\mscms.dll
2011-06-14 11:30:20 ----A---- C:\Windows\SYSWOW64\localsec.dll
2011-06-14 11:30:20 ----A---- C:\Windows\SYSWOW64\hgcpl.dll
2011-06-14 11:30:20 ----A---- C:\Windows\SYSWOW64\fontext.dll
2011-06-14 11:30:20 ----A---- C:\Windows\SYSWOW64\dnscmmc.dll
2011-06-14 11:30:20 ----A---- C:\Windows\system32\zipfldr.dll
2011-06-14 11:30:20 ----A---- C:\Windows\system32\sud.dll
2011-06-14 11:30:20 ----A---- C:\Windows\system32\msieftp.dll
2011-06-14 11:30:20 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2011-06-14 11:30:20 ----A---- C:\Windows\system32\drivers\storvsc.sys
2011-06-14 11:30:20 ----A---- C:\Windows\system32\DeviceCenter.dll
2011-06-14 11:30:20 ----A---- C:\Windows\system32\defaultlocationcpl.dll
2011-06-14 11:30:19 ----A---- C:\Windows\SYSWOW64\wlanui.dll
2011-06-14 11:30:19 ----A---- C:\Windows\SYSWOW64\VAN.dll
2011-06-14 11:30:19 ----A---- C:\Windows\SYSWOW64\usercpl.dll
2011-06-14 11:30:19 ----A---- C:\Windows\SYSWOW64\SndVolSSO.dll
2011-06-14 11:30:19 ----A---- C:\Windows\SYSWOW64\qedit.dll
2011-06-14 11:30:19 ----A---- C:\Windows\SYSWOW64\prntvpt.dll
2011-06-14 11:30:19 ----A---- C:\Windows\SYSWOW64\PerfCenterCPL.dll
2011-06-14 11:30:19 ----A---- C:\Windows\SYSWOW64\netcenter.dll
2011-06-14 11:30:19 ----A---- C:\Windows\SYSWOW64\mprddm.dll
2011-06-14 11:30:19 ----A---- C:\Windows\SYSWOW64\iasacct.dll
2011-06-14 11:30:19 ----A---- C:\Windows\SYSWOW64\batmeter.dll
2011-06-14 11:30:19 ----A---- C:\Windows\system32\twext.dll
2011-06-14 11:30:19 ----A---- C:\Windows\system32\taskbarcpl.dll
2011-06-14 11:30:19 ----A---- C:\Windows\system32\srcore.dll
2011-06-14 11:30:19 ----A---- C:\Windows\system32\rdpwsx.dll
2011-06-14 11:30:19 ----A---- C:\Windows\system32\qdvd.dll
2011-06-14 11:30:19 ----A---- C:\Windows\system32\OnLineIDCpl.dll
2011-06-14 11:30:19 ----A---- C:\Windows\system32\networkmap.dll
2011-06-14 11:30:19 ----A---- C:\Windows\system32\dot3svc.dll
2011-06-14 11:30:19 ----A---- C:\Windows\system32\cryptui.dll
2011-06-14 11:30:19 ----A---- C:\Windows\system32\ActionCenter.dll
2011-06-14 11:30:18 ----A---- C:\Windows\SYSWOW64\zipfldr.dll
2011-06-14 11:30:18 ----A---- C:\Windows\SYSWOW64\w32tm.exe
2011-06-14 11:30:18 ----A---- C:\Windows\SYSWOW64\spwizeng.dll
2011-06-14 11:30:18 ----A---- C:\Windows\SYSWOW64\SndVol.exe
2011-06-14 11:30:18 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2011-06-14 11:30:18 ----A---- C:\Windows\SYSWOW64\networkmap.dll
2011-06-14 11:30:18 ----A---- C:\Windows\SYSWOW64\netjoin.dll
2011-06-14 11:30:18 ----A---- C:\Windows\SYSWOW64\MSAC3ENC.DLL
2011-06-14 11:30:18 ----A---- C:\Windows\SYSWOW64\fdeploy.dll
2011-06-14 11:30:18 ----A---- C:\Windows\SYSWOW64\cryptui.dll
2011-06-14 11:30:18 ----A---- C:\Windows\SYSWOW64\azroleui.dll
2011-06-14 11:30:18 ----A---- C:\Windows\SYSWOW64\adsldp.dll
2011-06-14 11:30:18 ----A---- C:\Windows\SYSWOW64\accessibilitycpl.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\uxlib.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\tzutil.exe
2011-06-14 11:30:18 ----A---- C:\Windows\system32\systemcpl.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\sysclass.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\syncui.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\sspisrv.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\sisbkup.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\shwebsvc.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\sdcpl.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\recovery.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\recdisc.exe
2011-06-14 11:30:18 ----A---- C:\Windows\system32\OobeFldr.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\netplwiz.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\ncryptui.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\MediaMetadataHandler.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\isoburn.exe
2011-06-14 11:30:18 ----A---- C:\Windows\system32\httpapi.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\efscore.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\dsuiext.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\drivers\rdpdr.sys
2011-06-14 11:30:18 ----A---- C:\Windows\system32\drivers\mpio.sys
2011-06-14 11:30:18 ----A---- C:\Windows\system32\drivers\hwpolicy.sys
2011-06-14 11:30:18 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2011-06-14 11:30:18 ----A---- C:\Windows\system32\certcli.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\cca.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\bcdedit.exe
2011-06-14 11:30:18 ----A---- C:\Windows\system32\azroleui.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\autoplay.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\asycfilt.dll
2011-06-14 11:30:18 ----A---- C:\Windows\system32\appinfo.dll
2011-06-14 11:30:17 ----A---- C:\Windows\SYSWOW64\wusa.exe
2011-06-14 11:30:17 ----A---- C:\Windows\SYSWOW64\sud.dll
2011-06-14 11:30:17 ----A---- C:\Windows\SYSWOW64\prnfldr.dll
2011-06-14 11:30:17 ----A---- C:\Windows\SYSWOW64\photowiz.dll
2011-06-14 11:30:17 ----A---- C:\Windows\SYSWOW64\OnLineIDCpl.dll
2011-06-14 11:30:17 ----A---- C:\Windows\SYSWOW64\msieftp.dll
2011-06-14 11:30:17 ----A---- C:\Windows\SYSWOW64\MediaMetadataHandler.dll
2011-06-14 11:30:17 ----A---- C:\Windows\SYSWOW64\MCEWMDRMNDBootstrap.dll
2011-06-14 11:30:17 ----A---- C:\Windows\SYSWOW64\Faultrep.dll
2011-06-14 11:30:17 ----A---- C:\Windows\SYSWOW64\credssp.dll
2011-06-14 11:30:17 ----A---- C:\Windows\SYSWOW64\ActionCenter.dll
2011-06-14 11:30:17 ----A---- C:\Windows\system32\wlanmsm.dll
2011-06-14 11:30:17 ----A---- C:\Windows\system32\vdsutil.dll
2011-06-14 11:30:17 ----A---- C:\Windows\system32\termmgr.dll
2011-06-14 11:30:17 ----A---- C:\Windows\system32\spwizeng.dll
2011-06-14 11:30:17 ----A---- C:\Windows\system32\sdrsvc.dll
2011-06-14 11:30:17 ----A---- C:\Windows\system32\msvidc32.dll
2011-06-14 11:30:17 ----A---- C:\Windows\system32\msscp.dll
2011-06-14 11:30:17 ----A---- C:\Windows\system32\MFPlay.dll
2011-06-14 11:30:17 ----A---- C:\Windows\system32\AuxiliaryDisplayServices.dll
2011-06-14 11:30:17 ----A---- C:\Windows\system32\ActionCenterCPL.dll
2011-06-14 11:30:16 ----A---- C:\Windows\SYSWOW64\wmpmde.dll
2011-06-14 11:30:16 ----A---- C:\Windows\SYSWOW64\syncui.dll
2011-06-14 11:30:16 ----A---- C:\Windows\SYSWOW64\sisbkup.dll
2011-06-14 11:30:16 ----A---- C:\Windows\SYSWOW64\shwebsvc.dll
2011-06-14 11:30:16 ----A---- C:\Windows\SYSWOW64\odbcjt32.dll
2011-06-14 11:30:16 ----A---- C:\Windows\SYSWOW64\ntlanman.dll
2011-06-14 11:30:16 ----A---- C:\Windows\SYSWOW64\iprtrmgr.dll
2011-06-14 11:30:16 ----A---- C:\Windows\SYSWOW64\ifsutil.dll
2011-06-14 11:30:16 ----A---- C:\Windows\SYSWOW64\iasrad.dll
2011-06-14 11:30:16 ----A---- C:\Windows\SYSWOW64\ftp.exe
2011-06-14 11:30:16 ----A---- C:\Windows\SYSWOW64\efscore.dll
2011-06-14 11:30:16 ----A---- C:\Windows\SYSWOW64\dskquoui.dll
2011-06-14 11:30:16 ----A---- C:\Windows\SYSWOW64\dot3cfg.dll
2011-06-14 11:30:16 ----A---- C:\Windows\SYSWOW64\DeviceCenter.dll
2011-06-14 11:30:16 ----A---- C:\Windows\SYSWOW64\defaultlocationcpl.dll
2011-06-14 11:30:16 ----A---- C:\Windows\SYSWOW64\autoplay.dll
2011-06-14 11:30:16 ----A---- C:\Windows\SYSWOW64\ActionCenterCPL.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\wwanprotdim.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\wmdrmsdk.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\UserAccountControlSettings.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\tsgqec.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\srvcli.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\sqlcese30.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\slwga.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\sethc.exe
2011-06-14 11:30:16 ----A---- C:\Windows\system32\secur32.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\rstrui.exe
2011-06-14 11:30:16 ----A---- C:\Windows\system32\ReAgent.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\rdpd3d.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\odbctrac.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\odbccp32.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\ntlanman.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\iyuv_32.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\iTVData.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\iprtrmgr.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\drmmgrtn.dll
2011-06-14 11:30:16 ----A---- C:\Windows\system32\drivers\vmstorfl.sys
2011-06-14 11:30:16 ----A---- C:\Windows\system32\drivers\ndproxy.sys
2011-06-14 11:30:15 ----A---- C:\Windows\SYSWOW64\wmpsrcwp.dll
2011-06-14 11:30:15 ----A---- C:\Windows\SYSWOW64\systemcpl.dll
2011-06-14 11:30:15 ----A---- C:\Windows\SYSWOW64\SmartcardCredentialProvider.dll
2011-06-14 11:30:15 ----A---- C:\Windows\SYSWOW64\sethc.exe
2011-06-14 11:30:15 ----A---- C:\Windows\SYSWOW64\rtutils.dll
2011-06-14 11:30:15 ----A---- C:\Windows\SYSWOW64\riched20.dll
2011-06-14 11:30:15 ----A---- C:\Windows\SYSWOW64\OobeFldr.dll
2011-06-14 11:30:15 ----A---- C:\Windows\SYSWOW64\ntprint.dll
2011-06-14 11:30:15 ----A---- C:\Windows\SYSWOW64\nshwfp.dll
2011-06-14 11:30:15 ----A---- C:\Windows\SYSWOW64\netplwiz.dll
2011-06-14 11:30:15 ----A---- C:\Windows\SYSWOW64\NAPHLPR.DLL
2011-06-14 11:30:15 ----A---- C:\Windows\SYSWOW64\migisol.dll
2011-06-14 11:30:15 ----A---- C:\Windows\SYSWOW64\fms.dll
2011-06-14 11:30:15 ----A---- C:\Windows\SYSWOW64\blackbox.dll
2011-06-14 11:30:15 ----A---- C:\Windows\SYSWOW64\activeds.dll
2011-06-14 11:30:15 ----A---- C:\Windows\system32\wavemsp.dll
2011-06-14 11:30:15 ----A---- C:\Windows\system32\TSpkg.dll
2011-06-14 11:30:15 ----A---- C:\Windows\system32\srrstr.dll
2011-06-14 11:30:15 ----A---- C:\Windows\system32\sppnp.dll
2011-06-14 11:30:15 ----A---- C:\Windows\system32\ntprint.dll
2011-06-14 11:30:15 ----A---- C:\Windows\system32\nslookup.exe
2011-06-14 11:30:15 ----A---- C:\Windows\system32\NAPHLPR.DLL
2011-06-14 11:30:15 ----A---- C:\Windows\system32\msiexec.exe
2011-06-14 11:30:15 ----A---- C:\Windows\system32\fsquirt.exe
2011-06-14 11:30:15 ----A---- C:\Windows\system32\DevicePairingFolder.dll
2011-06-14 11:30:15 ----A---- C:\Windows\system32\certprop.dll
2011-06-14 11:30:15 ----A---- C:\Windows\system32\bcdboot.exe
2011-06-14 11:30:15 ----A---- C:\Windows\system32\acppage.dll
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\wvc.dll
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\wtsapi32.dll
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\wlanmsm.dll
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\wavemsp.dll
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\tzutil.exe
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\ReAgent.dll
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\provsvc.dll
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\ocsetup.exe
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\nshipsec.dll
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\nlaapi.dll
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\msftedit.dll
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\isoburn.exe
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\httpapi.dll
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\dsuiext.dll
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\dot3ui.dll
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\dfrgui.exe
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\cdosys.dll
2011-06-14 11:30:14 ----A---- C:\Windows\SYSWOW64\asycfilt.dll
2011-06-14 11:30:14 ----A---- C:\Windows\system32\wvc.dll
2011-06-14 11:30:14 ----A---- C:\Windows\system32\wuwebv.dll
2011-06-14 11:30:14 ----A---- C:\Windows\system32\wsqmcons.exe
2011-06-14 11:30:14 ----A---- C:\Windows\system32\wsnmp32.dll
2011-06-14 11:30:14 ----A---- C:\Windows\system32\wmpdxm.dll
2011-06-14 11:30:14 ----A---- C:\Windows\system32\wmdrmdev.dll
2011-06-14 11:30:14 ----A---- C:\Windows\system32\wkscli.dll
2011-06-14 11:30:14 ----A---- C:\Windows\system32\WinSCard.dll
2011-06-14 11:30:14 ----A---- C:\Windows\system32\WerFaultSecure.exe
2011-06-14 11:30:14 ----A---- C:\Windows\system32\remotepg.dll
2011-06-14 11:30:14 ----A---- C:\Windows\system32\PresentationSettings.exe
2011-06-14 11:30:14 ----A---- C:\Windows\system32\networkexplorer.dll
2011-06-14 11:30:14 ----A---- C:\Windows\system32\net1.exe
2011-06-14 11:30:14 ----A---- C:\Windows\system32\ftp.exe
2011-06-14 11:30:14 ----A---- C:\Windows\system32\dfrgui.exe
2011-06-14 11:30:14 ----A---- C:\Windows\system32\cdosys.dll
2011-06-14 11:30:14 ----A---- C:\Windows\system32\cabinet.dll
2011-06-14 11:30:14 ----A---- C:\Windows\system32\blackbox.dll
2011-06-14 11:30:13 ----A---- C:\Windows\twain_32.dll
2011-06-14 11:30:13 ----A---- C:\Windows\SYSWOW64\wimgapi.dll
2011-06-14 11:30:13 ----A---- C:\Windows\SYSWOW64\twext.dll
2011-06-14 11:30:13 ----A---- C:\Windows\SYSWOW64\shdocvw.dll
2011-06-14 11:30:13 ----A---- C:\Windows\SYSWOW64\setupugc.exe
2011-06-14 11:30:13 ----A---- C:\Windows\SYSWOW64\qcap.dll
2011-06-14 11:30:13 ----A---- C:\Windows\SYSWOW64\qasf.dll
2011-06-14 11:30:13 ----A---- C:\Windows\SYSWOW64\mstask.dll
2011-06-14 11:30:13 ----A---- C:\Windows\SYSWOW64\AdmTmpl.dll
2011-06-14 11:30:13 ----A---- C:\Windows\system32\WUDFPlatform.dll
2011-06-14 11:30:13 ----A---- C:\Windows\system32\unimdmat.dll
2011-06-14 11:30:13 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2011-06-14 11:30:13 ----A---- C:\Windows\system32\OpcServices.dll
2011-06-14 11:30:13 ----A---- C:\Windows\system32\msyuv.dll
2011-06-14 11:30:13 ----A---- C:\Windows\system32\msrle32.dll
2011-06-14 11:30:13 ----A---- C:\Windows\system32\mfps.dll
2011-06-14 11:30:13 ----A---- C:\Windows\system32\mapistub.dll
2011-06-14 11:30:13 ----A---- C:\Windows\system32\mapi32.dll
2011-06-14 11:30:13 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2011-06-14 11:30:12 ----A---- C:\Windows\SYSWOW64\WPDShServiceObj.dll
2011-06-14 11:30:12 ----A---- C:\Windows\SYSWOW64\wmdrmsdk.dll
2011-06-14 11:30:12 ----A---- C:\Windows\SYSWOW64\uxlib.dll
2011-06-14 11:30:12 ----A---- C:\Windows\SYSWOW64\slwga.dll
2011-06-14 11:30:12 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2011-06-14 11:30:12 ----A---- C:\Windows\SYSWOW64\nslookup.exe
2011-06-14 11:30:12 ----A---- C:\Windows\SYSWOW64\msvfw32.dll
2011-06-14 11:30:12 ----A---- C:\Windows\SYSWOW64\msscp.dll
2011-06-14 11:30:12 ----A---- C:\Windows\SYSWOW64\mciavi32.dll
2011-06-14 11:30:12 ----A---- C:\Windows\SYSWOW64\DevicePairingFolder.dll
2011-06-14 11:30:12 ----A---- C:\Windows\SYSWOW64\clusapi.dll
2011-06-14 11:30:12 ----A---- C:\Windows\SYSWOW64\audiodev.dll
2011-06-14 11:30:12 ----A---- C:\Windows\system32\wmpshell.dll
2011-06-14 11:30:12 ----A---- C:\Windows\system32\WindowsAnytimeUpgradeResults.exe
2011-06-14 11:30:12 ----A---- C:\Windows\system32\tsbyuv.dll
2011-06-14 11:30:12 ----A---- C:\Windows\system32\seclogon.dll
2011-06-14 11:30:12 ----A---- C:\Windows\system32\rdpencom.dll
2011-06-14 11:30:12 ----A---- C:\Windows\system32\perfmon.exe
2011-06-14 11:30:12 ----A---- C:\Windows\system32\muifontsetup.dll
2011-06-14 11:30:12 ----A---- C:\Windows\system32\iscsium.dll
2011-06-14 11:30:12 ----A---- C:\Windows\system32\ifsutil.dll
2011-06-14 11:30:12 ----A---- C:\Windows\system32\drivers\umbus.sys
2011-06-14 11:30:12 ----A---- C:\Windows\system32\diskraid.exe
2011-06-14 11:30:12 ----A---- C:\Windows\system32\d3d10level9.dll
2011-06-14 11:30:11 ----A---- C:\Windows\SYSWOW64\wimserv.exe
2011-06-14 11:30:11 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2011-06-14 11:30:11 ----A---- C:\Windows\SYSWOW64\remotepg.dll
2011-06-14 11:30:11 ----A---- C:\Windows\SYSWOW64\rdpencom.dll
2011-06-14 11:30:11 ----A---- C:\Windows\SYSWOW64\raschap.dll
2011-06-14 11:30:11 ----A---- C:\Windows\SYSWOW64\QUTIL.DLL
2011-06-14 11:30:11 ----A---- C:\Windows\SYSWOW64\perfmon.exe
2011-06-14 11:30:11 ----A---- C:\Windows\SYSWOW64\odbccp32.dll
2011-06-14 11:30:11 ----A---- C:\Windows\SYSWOW64\networkexplorer.dll
2011-06-14 11:30:11 ----A---- C:\Windows\SYSWOW64\NAPCRYPT.DLL
2011-06-14 11:30:11 ----A---- C:\Windows\SYSWOW64\input.dll
2011-06-14 11:30:11 ----A---- C:\Windows\SYSWOW64\drmmgrtn.dll
2011-06-14 11:30:11 ----A---- C:\Windows\SYSWOW64\diskraid.exe
2011-06-14 11:30:11 ----A---- C:\Windows\SYSWOW64\acppage.dll
2011-06-14 11:30:11 ----A---- C:\Windows\system32\wpdwcn.dll
2011-06-14 11:30:11 ----A---- C:\Windows\system32\WMADMOD.DLL
2011-06-14 11:30:11 ----A---- C:\Windows\system32\wiavideo.dll
2011-06-14 11:30:11 ----A---- C:\Windows\system32\umb.dll
2011-06-14 11:30:11 ----A---- C:\Windows\system32\tlscsp.dll
2011-06-14 11:30:11 ----A---- C:\Windows\system32\syssetup.dll
2011-06-14 11:30:11 ----A---- C:\Windows\system32\runonce.exe
2011-06-14 11:30:11 ----A---- C:\Windows\system32\raschap.dll
2011-06-14 11:30:11 ----A---- C:\Windows\system32\qasf.dll
2011-06-14 11:30:11 ----A---- C:\Windows\system32\netutils.dll
2011-06-14 11:30:11 ----A---- C:\Windows\system32\NAPCRYPT.DLL
2011-06-14 11:30:11 ----A---- C:\Windows\system32\FXSAPI.dll
2011-06-14 11:30:11 ----A---- C:\Windows\system32\dbghelp.dll
2011-06-14 11:30:11 ----A---- C:\Windows\system32\browser.dll
2011-06-14 11:30:11 ----A---- C:\Windows\system32\AzSqlExt.dll
2011-06-14 11:30:11 ----A---- C:\Windows\system32\ActionQueue.dll
2011-06-14 11:30:11 ----A---- C:\Windows\bfsvc.exe
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\wpdwcn.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\wmpshell.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\wmpdxm.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\wmdrmdev.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\vpnikeapi.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\vdsbas.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\UserAccountControlSettings.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\shacct.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\runonce.exe
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\onexui.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\olepro32.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\ocsetapi.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\msvidc32.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\msiexec.exe
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\MFPlay.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\lsmproxy.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\logagent.exe
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\iTVData.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\eapp3hst.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\dxdiagn.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\d3d10level9.dll
2011-06-14 11:30:10 ----A---- C:\Windows\SYSWOW64\bitsadmin.exe
2011-06-14 11:30:10 ----A---- C:\Windows\system32\WPDSp.dll
2011-06-14 11:30:10 ----A---- C:\Windows\system32\WMVSDECD.DLL
2011-06-14 11:30:10 ----A---- C:\Windows\system32\wmdrmnet.dll
2011-06-14 11:30:10 ----A---- C:\Windows\system32\vss_ps.dll
2011-06-14 11:30:10 ----A---- C:\Windows\system32\vdsbas.dll
2011-06-14 11:30:10 ----A---- C:\Windows\system32\tabcal.exe
2011-06-14 11:30:10 ----A---- C:\Windows\system32\shacct.dll
2011-06-14 11:30:10 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2011-06-14 11:30:10 ----A---- C:\Windows\system32\QSVRMGMT.DLL
2011-06-14 11:30:10 ----A---- C:\Windows\system32\qcap.dll
2011-06-14 11:30:10 ----A---- C:\Windows\system32\PrintIsolationProxy.dll
2011-06-14 11:30:10 ----A---- C:\Windows\system32\nltest.exe
2011-06-14 11:30:10 ----A---- C:\Windows\system32\mstask.dll
2011-06-14 11:30:10 ----A---- C:\Windows\system32\MdSched.exe
2011-06-14 11:30:10 ----A---- C:\Windows\system32\Mcx2Svc.dll
2011-06-14 11:30:10 ----A---- C:\Windows\system32\logman.exe
2011-06-14 11:30:10 ----A---- C:\Windows\system32\drivers\USBAUDIO.sys
2011-06-14 11:30:10 ----A---- C:\Windows\system32\drivers\tcpipreg.sys
2011-06-14 11:30:10 ----A---- C:\Windows\system32\drivers\rmcast.sys
2011-06-14 11:30:10 ----A---- C:\Windows\system32\cscapi.dll
2011-06-14 11:30:10 ----A---- C:\Windows\system32\bitsadmin.exe
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\WPDSp.dll
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\unimdmat.dll
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\srvcli.dll
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\sqlcese30.dll
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\rdpd3d.dll
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\QSVRMGMT.DLL
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\PortableDeviceSyncProvider.dll
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\PortableDeviceStatus.dll
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\pdh.dll
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\OpcServices.dll
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\olethk32.dll
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\odbctrac.dll
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\ncryptui.dll
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\mprapi.dll
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\logman.exe
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\iscsium.dll
2011-06-14 11:30:09 ----A---- C:\Windows\SYSWOW64\cscapi.dll
2011-06-14 11:30:09 ----A---- C:\Windows\system32\wudriver.dll
2011-06-14 11:30:09 ----A---- C:\Windows\system32\WMSPDMOD.DLL
2011-06-14 11:30:09 ----A---- C:\Windows\system32\vmictimeprovider.dll
2011-06-14 11:30:09 ----A---- C:\Windows\system32\spbcd.dll
2011-06-14 11:30:09 ----A---- C:\Windows\system32\secproc_ssp.dll
2011-06-14 11:30:09 ----A---- C:\Windows\system32\qdv.dll
2011-06-14 11:30:09 ----A---- C:\Windows\system32\PortableDeviceSyncProvider.dll
2011-06-14 11:30:09 ----A---- C:\Windows\system32\PortableDeviceStatus.dll
2011-06-14 11:30:09 ----A---- C:\Windows\system32\msnetobj.dll
2011-06-14 11:30:09 ----A---- C:\Windows\system32\fphc.dll
2011-06-14 11:30:09 ----A---- C:\Windows\system32\drivers\ndisuio.sys
2011-06-14 11:30:09 ----A---- C:\Windows\system32\dot3ui.dll
2011-06-14 11:30:09 ----A---- C:\Windows\system32\CscMig.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\WMVSDECD.DLL
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\wmdrmnet.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\WMADMOD.DLL
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\wiavideo.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\utildll.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\takeown.exe
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\sqmapi.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\sppinst.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\qdv.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\QCLIPROV.DLL
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\msyuv.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\msrle32.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\msnetobj.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\mapistub.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\mapi32.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\iyuv_32.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\fphc.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\EhStorAPI.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\dot3msm.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\cmstp.exe
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\cca.dll
2011-06-14 11:30:08 ----A---- C:\Windows\SYSWOW64\avifil32.dll
2011-06-14 11:30:08 ----A---- C:\Windows\system32\WUDFx.dll
2011-06-14 11:30:08 ----A---- C:\Windows\system32\WUDFHost.exe
2011-06-14 11:30:08 ----A---- C:\Windows\system32\WMPhoto.dll
2011-06-14 11:30:08 ----A---- C:\Windows\system32\WavDest.dll
2011-06-14 11:30:08 ----A---- C:\Windows\system32\vfwwdm32.dll
2011-06-14 11:30:08 ----A---- C:\Windows\system32\takeown.exe
2011-06-14 11:30:08 ----A---- C:\Windows\system32\shimgvw.dll
2011-06-14 11:30:08 ----A---- C:\Windows\system32\QCLIPROV.DLL
2011-06-14 11:30:08 ----A---- C:\Windows\system32\PnPUnattend.exe
2011-06-14 11:30:08 ----A---- C:\Windows\system32\nrpsrv.dll
2011-06-14 11:30:08 ----A---- C:\Windows\system32\netapi32.dll
2011-06-14 11:30:08 ----A---- C:\Windows\system32\iasrecst.dll
2011-06-14 11:30:08 ----A---- C:\Windows\system32\HotStartUserAgent.dll
2011-06-14 11:30:08 ----A---- C:\Windows\system32\EhStorAPI.dll
2011-06-14 11:30:08 ----A---- C:\Windows\system32\djoin.exe
2011-06-14 11:30:08 ----A---- C:\Windows\system32\cmstp.exe
2011-06-14 11:30:08 ----A---- C:\Windows\system32\CertPolEng.dll
2011-06-14 11:30:08 ----A---- C:\Windows\system32\amstream.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\wsnmp32.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\WMSPDMOD.DLL
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\wkscli.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\vfwwdm32.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\tsbyuv.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\spbcd.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\setupcln.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\secproc_ssp_isv.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\secproc_ssp.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\resutils.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\relog.exe
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\rastapi.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\pdhui.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\netiougc.exe
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\netbtugc.exe
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\mydocs.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\MuiUnattend.exe
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\msorcl32.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\itircl.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\iscsicli.exe
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\iasrecst.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\diskpart.exe
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\AzSqlExt.dll
2011-06-14 11:30:07 ----A---- C:\Windows\SYSWOW64\amstream.dll
2011-06-14 11:30:07 ----A---- C:\Windows\system32\wuauclt.exe
2011-06-14 11:30:07 ----A---- C:\Windows\system32\sscore.dll
2011-06-14 11:30:07 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2011-06-14 11:30:07 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2011-06-14 11:30:07 ----A---- C:\Windows\system32\relog.exe
2011-06-14 11:30:07 ----A---- C:\Windows\system32\mydocs.dll
2011-06-14 11:30:07 ----A---- C:\Windows\system32\MultiDigiMon.exe
2011-06-14 11:30:07 ----A---- C:\Windows\system32\msdmo.dll
2011-06-14 11:30:07 ----A---- C:\Windows\system32\mobsync.exe
2011-06-14 11:30:07 ----A---- C:\Windows\system32\KMSVC.DLL
2011-06-14 11:30:07 ----A---- C:\Windows\system32\itircl.dll
2011-06-14 11:30:07 ----A---- C:\Windows\system32\iscsicli.exe
2011-06-14 11:30:07 ----A---- C:\Windows\system32\fdProxy.dll
2011-06-14 11:30:07 ----A---- C:\Windows\system32\drivers\usbser.sys
2011-06-14 11:30:07 ----A---- C:\Windows\system32\drivers\pacer.sys
2011-06-14 11:30:07 ----A---- C:\Windows\system32\dot3msm.dll
2011-06-14 11:30:07 ----A---- C:\Windows\system32\diskpart.exe
2011-06-14 11:30:07 ----A---- C:\Windows\system32\BWUnpairElevated.dll
2011-06-14 11:30:07 ----A---- C:\Windows\system32\browcli.dll
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\wmpps.dll
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\WerFaultSecure.exe
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\tlscsp.dll
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\syssetup.dll
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\sppc.dll
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\spopk.dll
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\shimgvw.dll
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\secur32.dll
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp_isv.exe
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp.exe
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\ReAgentc.exe
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\netutils.dll
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\netapi32.dll
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\muifontsetup.dll
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\mobsync.exe
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\mciqtz32.dll
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\luainstall.dll
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\iccvid.dll
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\findstr.exe
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\eappgnui.dll
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\CertPolEng.dll
2011-06-14 11:30:06 ----A---- C:\Windows\SYSWOW64\cabinet.dll
2011-06-14 11:30:06 ----A---- C:\Windows\system32\wuapp.exe
2011-06-14 11:30:06 ----A---- C:\Windows\system32\wdiasqmmodule.dll
2011-06-14 11:30:06 ----A---- C:\Windows\system32\sppc.dll
2011-06-14 11:30:06 ----A---- C:\Windows\system32\spopk.dll
2011-06-14 11:30:06 ----A---- C:\Windows\system32\schedcli.dll
2011-06-14 11:30:06 ----A---- C:\Windows\system32\repair-bde.exe
2011-06-14 11:30:06 ----A---- C:\Windows\system32\RDPENCDD.dll
2011-06-14 11:30:06 ----A---- C:\Windows\system32\qprocess.exe
2011-06-14 11:30:06 ----A---- C:\Windows\system32\qappsrv.exe
2011-06-14 11:30:06 ----A---- C:\Windows\system32\onexui.dll
2011-06-14 11:30:06 ----A---- C:\Windows\system32\mciqtz32.dll
2011-06-14 11:30:06 ----A---- C:\Windows\system32\manage-bde.exe
2011-06-14 11:30:06 ----A---- C:\Windows\system32\luainstall.dll
2011-06-14 11:30:06 ----A---- C:\Windows\system32\inetmib1.dll
2011-06-14 11:30:06 ----A---- C:\Windows\system32\imagehlp.dll
2011-06-14 11:30:06 ----A---- C:\Windows\system32\choice.exe
2011-06-14 11:30:06 ----A---- C:\Windows\system32\chglogon.exe
2011-06-14 11:30:06 ----A---- C:\Windows\system32\FXSTIFF.dll
2011-06-14 11:30:06 ----A---- C:\Windows\system32\findstr.exe
2011-06-14 11:30:06 ----A---- C:\Windows\system32\eappgnui.dll
2011-06-14 11:30:06 ----A---- C:\Windows\system32\drivers\tunnel.sys
2011-06-14 11:30:06 ----A---- C:\Windows\system32\drivers\dfsc.sys
2011-06-14 11:30:05 ----A---- C:\Windows\SYSWOW64\wups.dll
2011-06-14 11:30:05 ----A---- C:\Windows\SYSWOW64\unlodctr.exe
2011-06-14 11:30:05 ----A---- C:\Windows\SYSWOW64\UIRibbonRes.dll
2011-06-14 11:30:05 ----A---- C:\Windows\SYSWOW64\rdprefdrvapi.dll
2011-06-14 11:30:05 ----A---- C:\Windows\SYSWOW64\perfts.dll
2011-06-14 11:30:05 ----A---- C:\Windows\SYSWOW64\odbcconf.dll
2011-06-14 11:30:05 ----A---- C:\Windows\SYSWOW64\msdmo.dll
2011-06-14 11:30:05 ----A---- C:\Windows\SYSWOW64\inetmib1.dll
2011-06-14 11:30:05 ----A---- C:\Windows\SYSWOW64\imm32.dll
2011-06-14 11:30:05 ----A---- C:\Windows\SYSWOW64\browcli.dll
2011-06-14 11:30:05 ----A---- C:\Windows\system32\WUDFCoinstaller.dll
2011-06-14 11:30:05 ----A---- C:\Windows\system32\wshbth.dll
2011-06-14 11:30:05 ----A---- C:\Windows\system32\vmstorfltres.dll
2011-06-14 11:30:05 ----A---- C:\Windows\system32\vmicres.dll
2011-06-14 11:30:05 ----A---- C:\Windows\system32\vmbusres.dll
2011-06-14 11:30:05 ----A---- C:\Windows\system32\UIRibbonRes.dll
2011-06-14 11:30:05 ----A---- C:\Windows\system32\tskill.exe
2011-06-14 11:30:05 ----A---- C:\Windows\system32\tsdiscon.exe
2011-06-14 11:30:05 ----A---- C:\Windows\system32\tscon.exe
2011-06-14 11:30:05 ----A---- C:\Windows\system32\TRAPI.dll
2011-06-14 11:30:05 ----A---- C:\Windows\system32\shadow.exe
2011-06-14 11:30:05 ----A---- C:\Windows\system32\rwinsta.exe
2011-06-14 11:30:05 ----A---- C:\Windows\system32\profprov.dll
2011-06-14 11:30:05 ----A---- C:\Windows\system32\odbcconf.dll
2011-06-14 11:30:05 ----A---- C:\Windows\system32\LogonUI.exe
2011-06-14 11:30:05 ----A---- C:\Windows\system32\logoff.exe
2011-06-14 11:30:05 ----A---- C:\Windows\system32\chgusr.exe
2011-06-14 11:30:05 ----A---- C:\Windows\system32\chgport.exe
2011-06-14 11:30:05 ----A---- C:\Windows\system32\FXSMON.dll
2011-06-14 11:30:05 ----A---- C:\Windows\system32\fixmapi.exe
2011-06-14 11:30:05 ----A---- C:\Windows\system32\elsTrans.dll
2011-06-14 11:30:05 ----A---- C:\Windows\system32\dsauth.dll
2011-06-14 11:30:05 ----A---- C:\Windows\system32\drivers\tdi.sys
2011-06-14 11:30:04 ----A---- C:\Windows\SYSWOW64\wshbth.dll
2011-06-14 11:30:04 ----A---- C:\Windows\SYSWOW64\TRAPI.dll
2011-06-14 11:30:04 ----A---- C:\Windows\SYSWOW64\schedcli.dll
2011-06-14 11:30:04 ----A---- C:\Windows\SYSWOW64\napdsnap.dll
2011-06-14 11:30:04 ----A---- C:\Windows\SYSWOW64\elsTrans.dll
2011-06-14 11:30:04 ----A---- C:\Windows\SYSWOW64\dsauth.dll
2011-06-14 11:30:04 ----A---- C:\Windows\SYSWOW64\cscdll.dll
2011-06-14 11:30:04 ----A---- C:\Windows\SYSWOW64\bitsperf.dll
2011-06-14 11:30:04 ----A---- C:\Windows\system32\reset.exe
2011-06-14 11:30:04 ----A---- C:\Windows\system32\rdprefdrvapi.dll
2011-06-14 11:30:04 ----A---- C:\Windows\system32\query.exe
2011-06-14 11:30:04 ----A---- C:\Windows\system32\napdsnap.dll
2011-06-14 11:30:04 ----A---- C:\Windows\system32\change.exe
2011-06-14 11:30:04 ----A---- C:\Windows\system32\FXSUNATD.exe
2011-06-14 11:30:04 ----A---- C:\Windows\system32\drivers\usbrpm.sys
2011-06-14 11:30:04 ----A---- C:\Windows\system32\drivers\acpipmi.sys
2011-06-14 11:30:04 ----A---- C:\Windows\system32\cscdll.dll
2011-06-14 11:30:04 ----A---- C:\Windows\system32\bitsperf.dll
2011-06-14 11:30:03 ----A---- C:\Windows\SYSWOW64\wsdchngr.dll
2011-06-14 11:30:03 ----A---- C:\Windows\SYSWOW64\sscore.dll
2011-06-14 11:30:03 ----A---- C:\Windows\SYSWOW64\shgina.dll
2011-06-14 11:30:03 ----A---- C:\Windows\SYSWOW64\riched32.dll
2011-06-14 11:30:03 ----A---- C:\Windows\system32\wups2.dll
2011-06-14 11:30:03 ----A---- C:\Windows\system32\wups.dll
2011-06-14 11:30:03 ----A---- C:\Windows\system32\wsdchngr.dll
2011-06-14 11:30:03 ----A---- C:\Windows\system32\shgina.dll
2011-06-14 11:30:03 ----A---- C:\Windows\system32\PJLMON.DLL
2011-06-14 11:30:02 ----A---- C:\Windows\SYSWOW64\wshirda.dll
2011-06-14 11:30:02 ----A---- C:\Windows\system32\wshirda.dll
2011-06-14 11:30:02 ----A---- C:\Windows\system32\wow64win.dll
2011-06-14 11:30:02 ----A---- C:\Windows\system32\wow64cpu.dll
2011-06-14 11:30:02 ----A---- C:\Windows\system32\vmbuspipe.dll
2011-06-14 11:30:02 ----A---- C:\Windows\system32\spwmp.dll
2011-06-14 11:30:02 ----A---- C:\Windows\system32\riched32.dll
2011-06-14 11:30:02 ----A---- C:\Windows\system32\rdpcfgex.dll
2011-06-14 11:30:02 ----A---- C:\Windows\system32\drivers\USBCAMD2.sys
2011-06-14 11:30:02 ----A---- C:\Windows\system32\drivers\kbdhid.sys
2011-06-14 11:30:02 ----A---- C:\Windows\system32\drivers\IPMIDrv.sys
2011-06-14 11:30:02 ----A---- C:\Windows\system32\drivers\hidusb.sys
2011-06-14 11:30:02 ----A---- C:\Windows\system32\drivers\CompositeBus.sys
2011-06-14 11:30:02 ----A---- C:\Windows\system32\drivers\appid.sys
2011-06-14 11:30:02 ----A---- C:\Windows\system32\browseui.dll
2011-06-14 11:30:01 ----AH---- C:\Windows\system32\api-ms-win-core-ums-l1-1-0.dll
2011-06-14 11:30:01 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2011-06-14 11:30:01 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2011-06-14 11:30:01 ----A---- C:\Windows\SYSWOW64\shunimpl.dll
2011-06-14 11:30:01 ----A---- C:\Windows\SYSWOW64\KBDTUQ.DLL
2011-06-14 11:30:01 ----A---- C:\Windows\SYSWOW64\KBDTUF.DLL
2011-06-14 11:30:01 ----A---- C:\Windows\SYSWOW64\KBDSG.DLL
2011-06-14 11:30:01 ----A---- C:\Windows\SYSWOW64\kbdlk41a.dll
2011-06-14 11:30:01 ----A---- C:\Windows\SYSWOW64\KBDGR1.DLL
2011-06-14 11:30:01 ----A---- C:\Windows\SYSWOW64\KBDGKL.DLL
2011-06-14 11:30:01 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2011-06-14 11:30:01 ----A---- C:\Windows\SYSWOW64\C_ISCII.DLL
2011-06-14 11:30:01 ----A---- C:\Windows\SYSWOW64\browseui.dll
2011-06-14 11:30:01 ----A---- C:\Windows\system32\VmdCoinstall.dll
2011-06-14 11:30:01 ----A---- C:\Windows\system32\VmbusCoinstaller.dll
2011-06-14 11:30:01 ----A---- C:\Windows\system32\shunimpl.dll
2011-06-14 11:30:01 ----A---- C:\Windows\system32\KBDTUQ.DLL
2011-06-14 11:30:01 ----A---- C:\Windows\system32\KBDTUF.DLL
2011-06-14 11:30:01 ----A---- C:\Windows\system32\KBDSG.DLL
2011-06-14 11:30:01 ----A---- C:\Windows\system32\KBDSF.DLL
2011-06-14 11:30:01 ----A---- C:\Windows\system32\KBDPO.DLL
2011-06-14 11:30:01 ----A---- C:\Windows\system32\KBDNEPR.DLL
2011-06-14 11:30:01 ----A---- C:\Windows\system32\kbdlk41a.dll
2011-06-14 11:30:01 ----A---- C:\Windows\system32\KBDINTAM.DLL
2011-06-14 11:30:01 ----A---- C:\Windows\system32\KBDINBEN.DLL
2011-06-14 11:30:01 ----A---- C:\Windows\system32\KBDGR1.DLL
2011-06-14 11:30:01 ----A---- C:\Windows\system32\KBDGKL.DLL
2011-06-14 11:30:01 ----A---- C:\Windows\system32\IcCoinstall.dll
2011-06-14 11:30:01 ----A---- C:\Windows\system32\dxmasf.dll
2011-06-14 11:30:01 ----A---- C:\Windows\system32\drivers\WUDFRd.sys
2011-06-14 11:30:01 ----A---- C:\Windows\system32\drivers\WUDFPf.sys
2011-06-14 11:30:01 ----A---- C:\Windows\system32\drivers\sffp_sd.sys
2011-06-14 11:30:01 ----A---- C:\Windows\system32\drivers\scfilter.sys
2011-06-14 11:30:01 ----A---- C:\Windows\system32\drivers\HdAudio.sys
2011-06-14 11:30:01 ----A---- C:\Windows\system32\drivers\hdaudbus.sys
2011-06-14 11:30:01 ----A---- C:\Windows\system32\drivers\cdrom.sys
2011-06-14 11:30:01 ----A---- C:\Windows\system32\C_ISCII.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\tzres.dll
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\spwizres.dll
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\pifmgr.dll
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\nlsbres.dll
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDUS.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDUGHR1.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDTURME.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDTAJIK.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDSF.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDPO.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDNEPR.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDMON.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDMAORI.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDLT1.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDINTEL.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDINTAM.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDINORI.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDINMAR.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDINKAN.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDINHIN.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDINBEN.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDGEO.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDCZ1.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDBULG.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDBLR.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\KBDBASH.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\SYSWOW64\dpnaddr.dll
2011-06-14 11:30:00 ----A---- C:\Windows\system32\wmploc.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\tzres.dll
2011-06-14 11:30:00 ----A---- C:\Windows\system32\spwizres.dll
2011-06-14 11:30:00 ----A---- C:\Windows\system32\pifmgr.dll
2011-06-14 11:30:00 ----A---- C:\Windows\system32\nlsbres.dll
2011-06-14 11:30:00 ----A---- C:\Windows\system32\KBDUS.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\KBDUGHR1.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\KBDTURME.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\KBDTAJIK.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\KBDMON.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\KBDMAORI.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\KBDLT1.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\KBDINTEL.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\KBDINORI.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\KBDINMAR.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\KBDINKAN.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\KBDINHIN.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\KBDGEO.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\KBDCZ1.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\KBDBULG.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\KBDBLR.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\KBDBASH.DLL
2011-06-14 11:30:00 ----A---- C:\Windows\system32\drivers\vms3cap.sys
2011-06-14 11:30:00 ----A---- C:\Windows\system32\drivers\VMBusHID.sys
2011-06-14 11:30:00 ----A---- C:\Windows\system32\dpnaddr.dll
2011-06-14 11:30:00 ----A---- C:\Windows\system32\BlbEvents.dll
2011-06-14 11:29:50 ----A---- C:\Windows\SYSWOW64\wdscore.dll
2011-06-14 11:29:50 ----A---- C:\Windows\SYSWOW64\printmanagement.msc
2011-06-14 11:29:50 ----A---- C:\Windows\SYSWOW64\PkgMgr.exe
2011-06-14 11:29:46 ----A---- C:\Windows\SYSWOW64\drvstore.dll
2011-06-14 11:29:46 ----A---- C:\Windows\SYSWOW64\dpx.dll
2011-06-14 11:29:44 ----A---- C:\Windows\SYSWOW64\wbemcomn.dll
2011-06-14 11:28:34 ----A---- C:\Windows\system32\wmicmiplugin.dll
2011-06-14 11:28:34 ----A---- C:\Windows\system32\wbemcomn.dll
2011-06-14 11:28:27 ----A---- C:\Windows\system32\SmiEngine.dll
2011-06-14 11:28:26 ----A---- C:\Windows\system32\PkgMgr.exe
2011-06-14 11:28:20 ----A---- C:\Windows\system32\drvstore.dll
2011-06-14 11:28:19 ----A---- C:\Windows\system32\dpx.dll
2011-06-13 10:05:56 ----D---- C:\Program Files (x86)\Valve
2011-06-12 19:55:03 ----D---- C:\Program Files (x86)\Portal
2011-06-12 17:46:54 ----D---- C:\Users\WoMec\AppData\Roaming\vlc
2011-06-10 15:12:23 ----D---- C:\Users\WoMec\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2011-06-10 15:09:26 ----D---- C:\Program Files\Common Files\PACE Anti-Piracy
2011-06-10 15:09:26 ----A---- C:\Windows\SurCode.INI
======List of files/folders modified in the last 1 months======
2011-07-04 00:49:44 ----D---- C:\Windows\Temp
2011-07-04 00:42:26 ----D---- C:\ProgramData
2011-07-04 00:42:23 ----D---- C:\ProgramData\Microsoft
2011-07-04 00:39:13 ----D---- C:\Windows\system32\config
2011-07-04 00:38:54 ----SHD---- C:\Windows\Installer
2011-07-04 00:38:46 ----D---- C:\Windows\system32\DriverStore
2011-07-04 00:38:46 ----D---- C:\Windows\system32\drivers
2011-07-04 00:38:46 ----D---- C:\Windows\system32\catroot
2011-07-04 00:38:46 ----D---- C:\Windows\inf
2011-07-04 00:38:11 ----RD---- C:\Program Files
2011-07-04 00:38:02 ----SHD---- C:\System Volume Information
2011-07-04 00:05:42 ----D---- C:\Windows\System32
2011-07-04 00:05:25 ----D---- C:\Program Files (x86)\QIP 2010
2011-07-03 23:54:22 ----D---- C:\Boot
2011-07-03 23:45:45 ----D---- C:\Windows\Prefetch
2011-07-03 23:44:18 ----D---- C:\Windows
2011-07-03 23:39:00 ----A---- C:\Windows\system.ini
2011-07-03 23:38:56 ----D---- C:\Windows\system32\drivers\etc
2011-07-03 23:38:32 ----D---- C:\Windows\SysWOW64
2011-07-03 23:38:31 ----RD---- C:\Program Files (x86)
2011-07-03 23:36:48 ----D---- C:\Windows\SYSWOW64\drivers
2011-07-03 23:36:48 ----D---- C:\Windows\AppPatch
2011-07-03 23:36:47 ----D---- C:\Program Files\Common Files
2011-07-03 23:36:47 ----D---- C:\Program Files (x86)\Common Files
2011-07-03 22:36:43 ----D---- C:\Windows\winsxs
2011-07-03 22:02:57 ----D---- C:\Program Files (x86)\totalcmd
2011-07-03 17:40:11 ----D---- C:\Users\WoMec\AppData\Roaming\uTorrent
2011-07-03 17:39:35 ----D---- C:\Windows\debug
2011-07-03 16:50:14 ----D---- C:\Windows\pss
2011-07-01 15:05:57 ----AD---- C:\Program Files (x86)\RQMONEY_1_3
2011-06-29 15:18:54 ----RSD---- C:\Windows\Fonts
2011-06-29 14:58:07 ----D---- C:\Program Files (x86)\Microsoft Office
2011-06-29 14:40:11 ----D---- C:\Windows\system32\catroot2
2011-06-27 19:37:54 ----D---- C:\Windows\rescache
2011-06-27 18:17:22 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-06-27 17:06:48 ----D---- C:\Program Files (x86)\Google
2011-06-25 14:55:35 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-06-23 16:34:40 ----D---- C:\Program Files (x86)\SpeedFan
2011-06-22 15:37:06 ----D---- C:\Program Files (x86)\Mozilla Thunderbird
2011-06-16 18:26:08 ----RSD---- C:\Windows\assembly
2011-06-16 18:26:08 ----D---- C:\Windows\Microsoft.NET
2011-06-16 10:38:14 ----D---- C:\Program Files\NVIDIA Corporation
2011-06-15 14:35:18 ----D---- C:\Users\WoMec\AppData\Roaming\Bioshock
2011-06-15 11:40:03 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2011-06-15 11:38:48 ----D---- C:\Program Files\Internet Explorer
2011-06-15 11:38:48 ----D---- C:\Program Files (x86)\Internet Explorer
2011-06-15 11:28:35 ----D---- C:\Program Files (x86)\Adobe
2011-06-15 11:25:51 ----A---- C:\Windows\system32\MRT.exe
2011-06-15 11:23:23 ----AD---- C:\Program Files\Common Files\Microsoft Shared
2011-06-15 11:01:26 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-06-15 11:01:26 ----D---- C:\Program Files (x86)\Codemasters
2011-06-15 11:00:26 ----D---- C:\Program Files (x86)\z2 Remote2PC
2011-06-15 10:59:53 ----D---- C:\Windows\WindowsMobile
2011-06-15 10:59:35 ----DC---- C:\Windows\system32\DRVSTORE
2011-06-15 10:58:32 ----D---- C:\Program Files (x86)\Nokia
2011-06-15 10:56:43 ----D---- C:\Program Files (x86)\National Instruments
2011-06-15 10:01:56 ----D---- C:\Users\WoMec\AppData\Roaming\Adobe
2011-06-15 10:01:45 ----D---- C:\Program Files\Adobe
2011-06-15 10:01:43 ----D---- C:\Program Files\Common Files\Adobe
2011-06-15 09:59:28 ----D---- C:\Program Files (x86)\MeeSoft
2011-06-14 11:48:36 ----D---- C:\Program Files (x86)\Windows Sidebar
2011-06-14 11:48:36 ----D---- C:\Program Files (x86)\Windows Portable Devices
2011-06-14 11:48:36 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2011-06-14 11:48:36 ----D---- C:\Program Files (x86)\Windows Media Player
2011-06-14 11:48:36 ----D---- C:\Program Files (x86)\Windows Mail
2011-06-14 11:48:35 ----D---- C:\Windows\servicing
2011-06-14 11:48:35 ----D---- C:\Program Files\Windows Sidebar
2011-06-14 11:48:35 ----D---- C:\Program Files\Windows Portable Devices
2011-06-14 11:48:35 ----D---- C:\Program Files\Windows Photo Viewer
2011-06-14 11:48:35 ----D---- C:\Program Files\Windows Media Player
2011-06-14 11:48:35 ----D---- C:\Program Files\Windows Mail
2011-06-14 11:48:35 ----D---- C:\Program Files\Windows Journal
2011-06-14 11:48:35 ----D---- C:\Program Files\Windows Defender
2011-06-14 11:48:35 ----D---- C:\Program Files\DVD Maker
2011-06-14 11:48:34 ----D---- C:\Windows\SYSWOW64\Setup
2011-06-14 11:48:34 ----D---- C:\Windows\SYSWOW64\oobe
2011-06-14 11:48:34 ----D---- C:\Windows\SYSWOW64\migration
2011-06-14 11:48:34 ----D---- C:\Windows\SYSWOW64\da-DK
2011-06-14 11:48:34 ----D---- C:\Windows\SYSWOW64\cs-CZ
2011-06-14 11:48:34 ----D---- C:\Windows\SYSWOW64\cs
2011-06-14 11:48:34 ----D---- C:\Windows\SYSWOW64\AdvancedInstallers
2011-06-14 11:48:34 ----D---- C:\Windows\ehome
2011-06-14 11:48:33 ----D---- C:\Windows\SYSWOW64\wbem
2011-06-14 11:48:33 ----D---- C:\Windows\SYSWOW64\sppui
2011-06-14 11:48:33 ----D---- C:\Windows\SYSWOW64\migwiz
2011-06-14 11:48:33 ----D---- C:\Windows\SYSWOW64\manifeststore
2011-06-14 11:48:33 ----D---- C:\Windows\SYSWOW64\es-ES
2011-06-14 11:48:33 ----D---- C:\Windows\SYSWOW64\Dism
2011-06-14 11:48:30 ----D---- C:\Windows\system32\sppui
2011-06-14 11:48:30 ----D---- C:\Windows\system32\Setup
2011-06-14 11:48:30 ----D---- C:\Windows\system32\oobe
2011-06-14 11:48:30 ----D---- C:\Windows\system32\migration
2011-06-14 11:48:30 ----D---- C:\Windows\system32\manifeststore
2011-06-14 11:48:30 ----D---- C:\Windows\system32\es-ES
2011-06-14 11:48:30 ----D---- C:\Windows\system32\en-US
2011-06-14 11:48:30 ----D---- C:\Windows\system32\da-DK
2011-06-14 11:48:30 ----D---- C:\Windows\system32\cs-CZ
2011-06-14 11:48:30 ----D---- C:\Windows\system32\cs
2011-06-14 11:48:30 ----D---- C:\Windows\system32\AdvancedInstallers
2011-06-14 11:48:30 ----D---- C:\Windows\PolicyDefinitions
2011-06-14 11:48:29 ----D---- C:\Windows\system32\wbem
2011-06-14 11:48:29 ----D---- C:\Windows\system32\migwiz
2011-06-14 11:48:29 ----D---- C:\Windows\system32\drivers\cs-CZ
2011-06-14 11:48:29 ----D---- C:\Windows\system32\Dism
2011-06-14 11:48:22 ----D---- C:\Windows\system32\Boot
2011-06-14 11:40:28 ----A---- C:\Windows\SYSWOW64\msclmd.dll
2011-06-14 11:40:28 ----A---- C:\Windows\system32\msclmd.dll
2011-06-14 01:01:50 ----D---- C:\Users\WoMec\AppData\Roaming\Skype
2011-06-14 00:03:22 ----D---- C:\Users\WoMec\AppData\Roaming\skypePM
2011-06-12 19:42:33 ----D---- C:\Windows\Logs
2011-06-12 19:38:45 ----D---- C:\Program Files (x86)\CCleaner
2011-06-10 17:33:40 ----D---- C:\Users\WoMec\AppData\Roaming\vlc-BackupByVLCPortable
2011-06-10 15:09:26 ----D---- C:\Users\WoMec\AppData\Roaming\PACE Anti-Piracy
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 speedfan;speedfan; C:\Windows\SysWOW64\speedfan.sys [2007-02-07 14104]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-01-30 834544]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-12-21 141264]
R1 MagicTune;MagicTune; C:\Windows\system32\drivers\MTiCtwl.sys [2008-11-04 23096]
R1 Tosrfcom;Bluetooth RFCOMM; C:\Windows\System32\Drivers\tosrfcom.sys [2009-07-28 81768]
R2 adfs;adfs; C:\Windows\system32\drivers\adfs.sys [2008-06-27 88632]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-12-21 170640]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2010-12-21 170640]
R2 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2010-12-21 50624]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-12-08 2223392]
R3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-08-20 239616]
R3 tosporte;Bluetooth COM Port; C:\Windows\system32\DRIVERS\tosporte.sys [2009-06-17 54664]
R3 tosrfbd;Bluetooth RFBUS; C:\Windows\system32\DRIVERS\tosrfbd.sys [2009-08-28 211560]
R3 Tosrfhid;Bluetooth RFHID; C:\Windows\system32\DRIVERS\Tosrfhid.sys [2009-06-19 94336]
R3 Tosrfusb;Bluetooth USB Controller; C:\Windows\system32\DRIVERS\tosrfusb.sys [2009-08-05 58744]
S1 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys []
S3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2009-09-30 121872]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-11-04 6088192]
S3 bomebus;Bome's Virtual MIDI Port Bus Service; C:\Windows\system32\DRIVERS\bomebus.sys [2009-10-15 34376]
S3 bomemidi;Bome's Virtual MIDI Port; C:\Windows\system32\drivers\bomemidi.sys [2009-10-15 30792]
S3 BthAudioHF;BthAudioHF Service; C:\Windows\system32\DRIVERS\BthAudioHF.sys [2009-12-21 52224]
S3 BthAvrcp;Bluetooth AVRCP Profile; C:\Windows\system32\DRIVERS\BthAvrcp.sys [2009-08-13 29184]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2010-11-20 552448]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2010-11-20 80384]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2007-11-21 89640]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2007-11-21 116016]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2007-11-21 33584]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2007-11-21 19760]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 cpuz130;cpuz130; \??\C:\Users\WoMec\AppData\Local\Temp\cpuz130\cpuz_x64.sys []
S3 csr_a2dp;Bluetooth AV Profile; C:\Windows\system32\drivers\bthav.sys [2009-12-21 78848]
S3 ENTECH64;ENTECH64; \??\C:\Windows\system32\DRIVERS\ENTECH64.sys [2007-08-20 12744]
S3 ksaud;Creative USB Audio Driver; C:\Windows\system32\drivers\ksaud.sys [2009-12-15 1148288]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2010-12-02 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2010-12-02 27136]
S3 NPF;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2010-06-25 35344]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys []
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 RivaTuner64;RivaTuner64; \??\C:\Program Files (x86)\RivaTuner v2.24\RivaTuner64.sys [2010-01-31 19952]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 TFsExDisk;TFsExDisk; \??\C:\Windows\System32\Drivers\TFsExDisk.sys [2009-12-14 16392]
S3 toshidpt;Bluetooth HID Port; C:\Windows\system32\drivers\Toshidpt.sys [2009-06-19 9608]
S3 tosrfbnp;Bluetooth RFBNEP; C:\Windows\System32\Drivers\tosrfbnp.sys [2009-06-19 50664]
S3 tosrfnds;Bluetooth Personal Area Network; C:\Windows\system32\DRIVERS\tosrfnds.sys [2009-07-24 26472]
S3 TosRfSnd;Bluetooth Audio; C:\Windows\system32\drivers\tosrfsnd.sys [2009-08-05 63856]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 TVICHW32;TVICHW32; \??\C:\Windows\system32\DRIVERS\TVICHW32.SYS []
S3 TVICHW64;TVICHW64; \??\C:\Windows\SysWOW64\Drivers\TVICHW64.SYS [2005-10-09 13824]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2010-12-02 9216]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2009-07-14 19968]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2010-11-20 32768]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2010-12-02 9216]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 VMnetAdapter;VMware Virtual Ethernet Adapter Driver; C:\Windows\system32\DRIVERS\vmnetadapter.sys []
S3 wceusbsh;Windows CE USB Serial Host Driver; C:\Windows\system32\DRIVERS\wceusbsh.sys [2005-03-24 119552]
S4 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-11-04 202752]
R2 Autodata Limited License Service;Autodata Limited License Service; C:\Program Files (x86)\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe [2010-04-14 72704]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-05-25 2275720]
R2 HFGService;Handsfree Headset Service; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2011-02-23 1005160]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2011-04-03 75136]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-04-16 136176]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2010-01-31 72704]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-02-03 1038088]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-02-03 655624]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-04-16 136176]
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-22 136120]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files (x86)\WinPcap\rpcapd.exe [2010-06-25 117264]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2009-07-30 192368]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-06-13 1255736]
S4 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
Re: proces firefox.exe se neukončí s vypnutím programu
Stále vidím NOD
. Takže koukejte ho dát pryč, nebo bude zle
.
Spustte combofix ještě jednou, neproběhl tak jak měl. Vidím tam ještě nějaké pozůstatky po viru.
Pokračování zítra, dobrou noc



Spustte combofix ještě jednou, neproběhl tak jak měl. Vidím tam ještě nějaké pozůstatky po viru.
Pokračování zítra, dobrou noc

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: proces firefox.exe se neukončí s vypnutím programu
Jak říkáte, pokračování zítra
... dneska už toho mám plný kecky. ... Jinak NOD mám opravdu odinstalovaný, zkusím to ješte projet ccleanerem ... poslední dobou si počítač dělá doslova co chce 


Re: proces firefox.exe se neukončí s vypnutím programu
Pak sem vložte log z combofixu
.

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: proces firefox.exe se neukončí s vypnutím programu
Tak zde slibovaný log z ComboFixu
ComboFix 11-07-03.01 - WoMec 04.07.2011 10:17:51.3.2 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.4094.2845 [GMT 2:00]
Spuštěný z: c:\users\WoMec\Downloads\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-06-04 do 2011-07-04 )))))))))))))))))))))))))))))))
.
.
2011-07-04 08:22 . 2011-07-04 08:22 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-04 08:07 . 2011-06-20 06:57 8873296 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E2B7E069-38C8-4144-98A8-19CA169B2DA0}\mpengine.dll
2011-07-04 08:07 . 2011-07-04 08:07 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-07-04 08:04 . 2011-07-04 08:05 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-07-04 08:04 . 2011-07-04 08:04 -------- d-----w- c:\programdata\NVIDIA
2011-07-03 22:48 . 2011-07-03 22:48 -------- d-----w- C:\rsit
2011-07-03 20:52 . 2011-07-03 21:02 -------- d-----w- c:\users\WoMec\AppData\Roaming\Wireshark
2011-07-03 20:36 . 2011-07-03 20:36 -------- d-----w- c:\program files\Wireshark
2011-07-03 20:18 . 2011-07-03 22:49 -------- d-----w- c:\program files\trend micro
2011-07-03 15:42 . 2011-07-03 20:24 -------- d-----w- c:\program files (x86)\Spyware Terminator
2011-07-03 15:18 . 2011-07-03 15:38 -------- d-----w- c:\users\WoMec\AppData\Roaming\ScanSpyware
2011-07-03 15:11 . 2011-07-03 21:38 -------- d-----w- c:\windows\InstallDir
2011-07-03 14:38 . 2011-07-03 14:38 -------- d-----w- c:\users\WoMec\AppData\Roaming\Malwarebytes
2011-07-03 14:37 . 2011-05-29 07:11 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-06-25 12:55 . 2011-06-25 12:55 2106216 ----a-w- c:\program files (x86)\Mozilla Firefox\D3DCompiler_43.dll
2011-06-25 12:55 . 2011-06-25 12:55 1998168 ----a-w- c:\program files (x86)\Mozilla Firefox\d3dx9_43.dll
2011-06-21 11:25 . 2011-06-21 11:25 -------- d-----w- c:\windows\C5C1C0F0D62F4DBF81D4D7EF397C228B.TMP
2011-06-15 12:52 . 2011-06-15 12:52 -------- d-----w- c:\users\WoMec\AppData\Local\Activision
2011-06-15 12:40 . 2011-06-15 12:40 -------- d-----w- c:\program files (x86)\Activision
2011-06-15 09:10 . 2011-04-27 02:40 158208 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-06-15 09:10 . 2011-04-27 02:39 289280 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-06-15 09:10 . 2011-04-27 02:39 128000 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-06-15 09:10 . 2011-05-28 03:06 3135488 ----a-w- c:\windows\system32\win32k.sys
2011-06-15 09:10 . 2011-04-25 05:33 1923968 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-06-15 09:10 . 2011-04-25 02:34 499200 ----a-w- c:\windows\system32\drivers\afd.sys
2011-06-15 09:09 . 2011-04-29 03:06 467456 ----a-w- c:\windows\system32\drivers\srv.sys
2011-06-15 09:09 . 2011-04-29 03:05 410112 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-06-15 09:09 . 2011-04-29 03:05 168448 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-06-15 09:09 . 2011-05-03 05:29 976896 ----a-w- c:\windows\system32\inetcomm.dll
2011-06-15 09:09 . 2011-05-03 04:30 741376 ----a-w- c:\windows\SysWow64\inetcomm.dll
2011-06-15 09:09 . 2011-02-25 06:22 861696 ----a-w- c:\windows\system32\oleaut32.dll
2011-06-15 09:09 . 2011-02-25 05:34 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll
2011-06-14 09:35 . 2011-06-14 09:35 -------- d-----w- c:\windows\system32\SPReview
2011-06-14 09:33 . 2011-06-14 09:33 -------- d-----w- c:\windows\system32\EventProviders
2011-06-14 09:30 . 2010-11-20 13:25 1975296 ----a-w- c:\windows\system32\CertEnroll.dll
2011-06-14 09:29 . 2010-11-20 13:32 2560 ----a-w- c:\windows\system32\drivers\cs-CZ\rdpwd.sys.mui
2011-06-14 09:29 . 2010-11-20 13:26 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\tsusbflt.sys.mui
2011-06-14 09:29 . 2010-11-20 13:32 4608 ----a-w- c:\windows\system32\drivers\cs-CZ\kbdclass.sys.mui
2011-06-14 09:29 . 2010-11-20 13:31 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\GAGP30KX.SYS.mui
2011-06-14 09:29 . 2010-11-20 12:21 189952 ----a-w- c:\windows\SysWow64\wdscore.dll
2011-06-14 09:29 . 2010-11-20 12:17 209920 ----a-w- c:\windows\SysWow64\PkgMgr.exe
2011-06-14 09:29 . 2010-11-20 12:18 323072 ----a-w- c:\windows\SysWow64\drvstore.dll
2011-06-14 09:29 . 2010-11-20 12:18 257024 ----a-w- c:\windows\SysWow64\dpx.dll
2011-06-14 09:29 . 2010-11-20 12:21 363008 ----a-w- c:\windows\SysWow64\wbemcomn.dll
2011-06-14 09:29 . 2010-11-20 12:19 606208 ----a-w- c:\windows\SysWow64\wbem\fastprox.dll
2011-06-14 09:28 . 2010-11-20 13:27 524288 ----a-w- c:\windows\system32\wmicmiplugin.dll
2011-06-14 09:28 . 2010-11-20 13:27 529408 ----a-w- c:\windows\system32\wbemcomn.dll
2011-06-14 09:28 . 2010-11-20 13:27 1225216 ----a-w- c:\windows\system32\wbem\wbemcore.dll
2011-06-14 09:28 . 2010-11-20 13:27 933376 ----a-w- c:\windows\system32\SmiEngine.dll
2011-06-14 09:28 . 2010-11-20 13:25 199168 ----a-w- c:\windows\system32\PkgMgr.exe
2011-06-14 09:28 . 2010-11-20 13:26 422912 ----a-w- c:\windows\system32\drvstore.dll
2011-06-14 09:28 . 2010-11-20 13:26 399872 ----a-w- c:\windows\system32\dpx.dll
2011-06-13 08:28 . 2011-06-13 08:28 -------- d-----w- c:\users\WoMec\AppData\Local\SKIDROW
2011-06-13 08:05 . 2011-06-13 08:31 -------- d-----w- c:\program files (x86)\Valve
2011-06-12 17:55 . 2011-06-15 07:59 -------- d-----w- c:\program files (x86)\Portal
2011-06-12 15:46 . 2011-07-03 13:31 -------- d-----w- c:\users\WoMec\AppData\Roaming\vlc
2011-06-10 13:12 . 2011-06-10 13:12 -------- d-----w- c:\users\WoMec\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2011-06-10 13:09 . 2011-06-10 13:09 -------- d-----w- c:\program files\Common Files\PACE Anti-Piracy
2011-06-10 12:31 . 2011-06-10 12:31 -------- d-----w- c:\program files (x86)\Common Files\Adobe AIR
2011-06-06 10:55 . 2011-06-06 10:55 183696 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\nppdf32.dll
2011-06-06 10:55 . 2011-06-06 10:55 183696 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-20 20:49 . 2011-05-17 10:04 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-06-14 09:40 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-06-14 09:40 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-05-30 16:22 . 2010-07-17 21:40 162816 ----a-w- c:\windows\system32\fmod.dll
2011-05-24 17:14 . 2010-01-27 15:59 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-05-18 22:33 . 2011-05-18 22:33 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-05-07 11:58 . 2011-05-07 11:58 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2011-05-07 11:58 . 2011-05-07 11:58 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2011-05-07 11:58 . 2011-05-07 11:58 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2011-05-07 11:58 . 2011-05-07 11:58 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2011-05-07 11:58 . 2011-05-07 11:58 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2011-05-07 11:58 . 2011-05-07 11:58 1126912 ----a-w- c:\windows\SysWow64\wininet.dll
2011-05-07 11:58 . 2011-05-07 11:58 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2011-05-07 11:58 . 2011-05-07 11:58 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-05-07 11:58 . 2011-05-07 11:58 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-05-07 11:58 . 2011-05-07 11:58 85504 ----a-w- c:\windows\system32\iesetup.dll
2011-05-07 11:58 . 2011-05-07 11:58 76800 ----a-w- c:\windows\system32\tdc.ocx
2011-05-07 11:58 . 2011-05-07 11:58 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2011-05-07 11:58 . 2011-05-07 11:58 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2011-05-07 11:58 . 2011-05-07 11:58 603648 ----a-w- c:\windows\system32\vbscript.dll
2011-05-07 11:58 . 2011-05-07 11:58 49664 ----a-w- c:\windows\system32\imgutil.dll
2011-05-07 11:58 . 2011-05-07 11:58 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-05-07 11:58 . 2011-05-07 11:58 448512 ----a-w- c:\windows\system32\html.iec
2011-05-07 11:58 . 2011-05-07 11:58 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2011-05-07 11:58 . 2011-05-07 11:58 367104 ----a-w- c:\windows\SysWow64\html.iec
2011-05-07 11:58 . 2011-05-07 11:58 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2011-05-07 11:58 . 2011-05-07 11:58 30720 ----a-w- c:\windows\system32\licmgr10.dll
2011-05-07 11:58 . 2011-05-07 11:58 249344 ----a-w- c:\windows\system32\webcheck.dll
2011-05-07 11:58 . 2011-05-07 11:58 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2011-05-07 11:58 . 2011-05-07 11:58 222208 ----a-w- c:\windows\system32\msls31.dll
2011-05-07 11:58 . 2011-05-07 11:58 203776 ----a-w- c:\windows\SysWow64\webcheck.dll
2011-05-07 11:58 . 2011-05-07 11:58 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2011-05-07 11:58 . 2011-05-07 11:58 165888 ----a-w- c:\windows\system32\iexpress.exe
2011-05-07 11:58 . 2011-05-07 11:58 160256 ----a-w- c:\windows\system32\wextract.exe
2011-05-07 11:58 . 2011-05-07 11:58 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2011-05-07 11:58 . 2011-05-07 11:58 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2011-05-07 11:58 . 2011-05-07 11:58 1492992 ----a-w- c:\windows\system32\inetcpl.cpl
2011-05-07 11:58 . 2011-05-07 11:58 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2011-05-07 11:58 . 2011-05-07 11:58 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2011-05-07 11:58 . 2011-05-07 11:58 1389056 ----a-w- c:\windows\system32\wininet.dll
2011-05-07 11:58 . 2011-05-07 11:58 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-05-07 11:58 . 2011-05-07 11:58 12288 ----a-w- c:\windows\system32\mshta.exe
2011-05-07 11:58 . 2011-05-07 11:58 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2011-05-07 11:58 . 2011-05-07 11:58 114176 ----a-w- c:\windows\system32\admparse.dll
2011-05-07 11:58 . 2011-05-07 11:58 111616 ----a-w- c:\windows\system32\iesysprep.dll
2011-05-07 11:58 . 2011-05-07 11:58 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2011-04-22 22:15 . 2011-05-25 06:29 27520 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2011-04-13 22:40 . 2011-04-13 22:40 4284416 ----a-w- c:\windows\SysWow64\GPhotos.scr
2011-04-09 16:55 . 2011-04-09 16:55 15453336 ----a-w- c:\windows\SysWow64\xlive.dll
2011-04-09 16:55 . 2011-04-09 16:55 13642904 ----a-w- c:\windows\SysWow64\xlivefnt.dll
2011-04-09 07:02 . 2011-05-11 09:39 5562240 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-04-09 06:58 . 2011-05-13 07:57 142336 ----a-w- c:\windows\system32\poqexec.exe
2011-04-09 06:02 . 2011-05-11 09:39 3967872 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2011-04-09 06:02 . 2011-05-11 09:39 3912576 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2011-04-09 05:56 . 2011-05-13 07:57 123904 ----a-w- c:\windows\SysWow64\poqexec.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Infium"="c:\program files (x86)\QIP 2010\qip.exem Files (x" [X]
"SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-01-07 253672]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2011-05-25 1951112]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"midi1"=myokent.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-04-16 136176]
R3 bomebus;Bome's Virtual MIDI Port Bus Service;c:\windows\system32\DRIVERS\bomebus.sys [x]
R3 bomemidi;Bome's Virtual MIDI Port;c:\windows\system32\drivers\bomemidi.sys [x]
R3 BthAudioHF;BthAudioHF Service;c:\windows\system32\DRIVERS\BthAudioHF.sys [x]
R3 BthAvrcp;Bluetooth AVRCP Profile;c:\windows\system32\DRIVERS\BthAvrcp.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 cpuz130;cpuz130;c:\users\WoMec\AppData\Local\Temp\cpuz130\cpuz_x64.sys [x]
R3 csr_a2dp;Bluetooth AV Profile;c:\windows\system32\drivers\bthav.sys [x]
R3 ENTECH64;ENTECH64;c:\windows\system32\DRIVERS\ENTECH64.sys [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-02-03 1038088]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-04-16 136176]
R3 ksaud;Creative USB Audio Driver;c:\windows\system32\drivers\ksaud.sys [x]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [x]
R3 RivaTuner64;RivaTuner64;c:\program files (x86)\RivaTuner v2.24\RivaTuner64.sys [2010-01-30 19952]
R3 TFsExDisk;TFsExDisk;c:\windows\System32\Drivers\TFsExDisk.sys [2009-12-14 16392]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TVICHW32;TVICHW32;c:\windows\system32\DRIVERS\TVICHW32.SYS [x]
R3 TVICHW64;TVICHW64;c:\windows\SysWOW64\Drivers\TVICHW64.SYS [2005-10-09 13824]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 WPRO_40_1340;WinPcap Packet Driver (WPRO_40_1340);c:\windows\system32\drivers\WPRO_40_1340.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-05-25 2275720]
S2 HFGService;Handsfree Headset Service;c:\windows\system32\svchost.exe [2009-07-14 27136]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2011-07-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-04-16 16:38]
.
2011-07-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-04-16 16:38]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-12-08 9642528]
"Creative SB Monitoring Utility"="sbavmon.dll" [2009-06-22 109056]
"MagicTuneEngine"="c:\program files (x86)\MagicTune Premium\MagicTuneEngine.exe" [2009-06-15 24064]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 660360]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\program files (x86)\Stardock\Fences\FencesMenu64.dll" [2009-10-02 134656]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
TCP: Interfaces\{6B2110FC-4F70-4EF9-9C8E-5A9E9215E9AA}: NameServer = 94.199.199.192,94.199.199.199
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - ProfilePath - c:\users\WoMec\AppData\Roaming\Mozilla\Firefox\Profiles\31kcocs3.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-Fences - c:\programdata\{A87EB928-0C6C-4071-AEF1-59E32BAEDF1B}\Fences.exe
AddRemove-Nokia PC Suite - c:\programdata\Installations\{225DB4AA-3CFF-47E8-B3C8-6DAD713E986E}\Nokia_PC_Suite_cze_web.exe
AddRemove-{10CD364B-FFCC-48BE-B469-B9622A033075} - c:\programdata\{A87EB928-0C6C-4071-AEF1-59E32BAEDF1B}\Fences.exe
AddRemove-{2AAC4085-DCBF-417B-AEBD-182197839240} - c:\programdata\{A0DFE2A5-DE68-41F3-8861-73E954C1D41D}\Traktor Setup PC.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-1965286433-519711803-1234614126-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*0*7*óNˇm\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-1965286433-519711803-1234614126-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:d9,6d,38,0c,4d,4f,ed,c5,9d,71,b8,30,07,0f,a1,66,41,43,32,99,9b,ba,e0,
85,c8,a9,e9,18,ad,9d,50,cf,1e,cf,85,ed,c3,46,8c,0c,63,b8,78,c4,b2,c7,ee,d2,\
"??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50
.
[HKEY_USERS\S-1-5-21-1965286433-519711803-1234614126-1000\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:54,68,3e,7b,cb,7d,a3,af,b5,87,26,71,8f,44,97,db,49,2f,55,8a,6d,
9a,c4,a1,c2,13,51,81,0e,b4,03,a1,f5,02,c6,64,49,e2,4a,85,72,f3,a0,07,d8,d3,\
"rkeysecu"=hex:95,e1,76,bf,79,77,29,7d,f3,2d,dd,24,f9,71,51,43
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:5a,1d,5c,b6,35,91,d0,6f,95,6d,dd,81,06,99,11,29,a4,c8,52,d9,5d,
ea,35,da,77,a3,f2,e7,6a,43,63,bd,24,64,4b,21,11,fa,d7,aa,01,d2,b8,c1,5b,51,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9f.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.9"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9f.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9f.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9f.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil9f.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil9f.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}]
@Denied: (A 2) (Everyone)
@="IFlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:5a,1d,5c,b6,35,91,d0,6f,95,6d,dd,81,06,99,11,29,a4,c8,52,d9,5d,
ea,35,da,77,a3,f2,e7,6a,43,63,bd,24,64,4b,21,11,fa,d7,aa,01,d2,b8,c1,5b,51,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2011-07-04 10:24:12
ComboFix-quarantined-files.txt 2011-07-04 08:24
.
Před spuštěním: Volných bajtů: 29 677 830 144
Po spuštění: Volných bajtů: 29 499 904 000
.
- - End Of File - - 014C00406C0C5CE3397A1A6063FB0DFE
ComboFix 11-07-03.01 - WoMec 04.07.2011 10:17:51.3.2 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.4094.2845 [GMT 2:00]
Spuštěný z: c:\users\WoMec\Downloads\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-06-04 do 2011-07-04 )))))))))))))))))))))))))))))))
.
.
2011-07-04 08:22 . 2011-07-04 08:22 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-04 08:07 . 2011-06-20 06:57 8873296 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E2B7E069-38C8-4144-98A8-19CA169B2DA0}\mpengine.dll
2011-07-04 08:07 . 2011-07-04 08:07 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-07-04 08:04 . 2011-07-04 08:05 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-07-04 08:04 . 2011-07-04 08:04 -------- d-----w- c:\programdata\NVIDIA
2011-07-03 22:48 . 2011-07-03 22:48 -------- d-----w- C:\rsit
2011-07-03 20:52 . 2011-07-03 21:02 -------- d-----w- c:\users\WoMec\AppData\Roaming\Wireshark
2011-07-03 20:36 . 2011-07-03 20:36 -------- d-----w- c:\program files\Wireshark
2011-07-03 20:18 . 2011-07-03 22:49 -------- d-----w- c:\program files\trend micro
2011-07-03 15:42 . 2011-07-03 20:24 -------- d-----w- c:\program files (x86)\Spyware Terminator
2011-07-03 15:18 . 2011-07-03 15:38 -------- d-----w- c:\users\WoMec\AppData\Roaming\ScanSpyware
2011-07-03 15:11 . 2011-07-03 21:38 -------- d-----w- c:\windows\InstallDir
2011-07-03 14:38 . 2011-07-03 14:38 -------- d-----w- c:\users\WoMec\AppData\Roaming\Malwarebytes
2011-07-03 14:37 . 2011-05-29 07:11 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-06-25 12:55 . 2011-06-25 12:55 2106216 ----a-w- c:\program files (x86)\Mozilla Firefox\D3DCompiler_43.dll
2011-06-25 12:55 . 2011-06-25 12:55 1998168 ----a-w- c:\program files (x86)\Mozilla Firefox\d3dx9_43.dll
2011-06-21 11:25 . 2011-06-21 11:25 -------- d-----w- c:\windows\C5C1C0F0D62F4DBF81D4D7EF397C228B.TMP
2011-06-15 12:52 . 2011-06-15 12:52 -------- d-----w- c:\users\WoMec\AppData\Local\Activision
2011-06-15 12:40 . 2011-06-15 12:40 -------- d-----w- c:\program files (x86)\Activision
2011-06-15 09:10 . 2011-04-27 02:40 158208 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-06-15 09:10 . 2011-04-27 02:39 289280 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-06-15 09:10 . 2011-04-27 02:39 128000 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-06-15 09:10 . 2011-05-28 03:06 3135488 ----a-w- c:\windows\system32\win32k.sys
2011-06-15 09:10 . 2011-04-25 05:33 1923968 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-06-15 09:10 . 2011-04-25 02:34 499200 ----a-w- c:\windows\system32\drivers\afd.sys
2011-06-15 09:09 . 2011-04-29 03:06 467456 ----a-w- c:\windows\system32\drivers\srv.sys
2011-06-15 09:09 . 2011-04-29 03:05 410112 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-06-15 09:09 . 2011-04-29 03:05 168448 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-06-15 09:09 . 2011-05-03 05:29 976896 ----a-w- c:\windows\system32\inetcomm.dll
2011-06-15 09:09 . 2011-05-03 04:30 741376 ----a-w- c:\windows\SysWow64\inetcomm.dll
2011-06-15 09:09 . 2011-02-25 06:22 861696 ----a-w- c:\windows\system32\oleaut32.dll
2011-06-15 09:09 . 2011-02-25 05:34 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll
2011-06-14 09:35 . 2011-06-14 09:35 -------- d-----w- c:\windows\system32\SPReview
2011-06-14 09:33 . 2011-06-14 09:33 -------- d-----w- c:\windows\system32\EventProviders
2011-06-14 09:30 . 2010-11-20 13:25 1975296 ----a-w- c:\windows\system32\CertEnroll.dll
2011-06-14 09:29 . 2010-11-20 13:32 2560 ----a-w- c:\windows\system32\drivers\cs-CZ\rdpwd.sys.mui
2011-06-14 09:29 . 2010-11-20 13:26 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\tsusbflt.sys.mui
2011-06-14 09:29 . 2010-11-20 13:32 4608 ----a-w- c:\windows\system32\drivers\cs-CZ\kbdclass.sys.mui
2011-06-14 09:29 . 2010-11-20 13:31 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\GAGP30KX.SYS.mui
2011-06-14 09:29 . 2010-11-20 12:21 189952 ----a-w- c:\windows\SysWow64\wdscore.dll
2011-06-14 09:29 . 2010-11-20 12:17 209920 ----a-w- c:\windows\SysWow64\PkgMgr.exe
2011-06-14 09:29 . 2010-11-20 12:18 323072 ----a-w- c:\windows\SysWow64\drvstore.dll
2011-06-14 09:29 . 2010-11-20 12:18 257024 ----a-w- c:\windows\SysWow64\dpx.dll
2011-06-14 09:29 . 2010-11-20 12:21 363008 ----a-w- c:\windows\SysWow64\wbemcomn.dll
2011-06-14 09:29 . 2010-11-20 12:19 606208 ----a-w- c:\windows\SysWow64\wbem\fastprox.dll
2011-06-14 09:28 . 2010-11-20 13:27 524288 ----a-w- c:\windows\system32\wmicmiplugin.dll
2011-06-14 09:28 . 2010-11-20 13:27 529408 ----a-w- c:\windows\system32\wbemcomn.dll
2011-06-14 09:28 . 2010-11-20 13:27 1225216 ----a-w- c:\windows\system32\wbem\wbemcore.dll
2011-06-14 09:28 . 2010-11-20 13:27 933376 ----a-w- c:\windows\system32\SmiEngine.dll
2011-06-14 09:28 . 2010-11-20 13:25 199168 ----a-w- c:\windows\system32\PkgMgr.exe
2011-06-14 09:28 . 2010-11-20 13:26 422912 ----a-w- c:\windows\system32\drvstore.dll
2011-06-14 09:28 . 2010-11-20 13:26 399872 ----a-w- c:\windows\system32\dpx.dll
2011-06-13 08:28 . 2011-06-13 08:28 -------- d-----w- c:\users\WoMec\AppData\Local\SKIDROW
2011-06-13 08:05 . 2011-06-13 08:31 -------- d-----w- c:\program files (x86)\Valve
2011-06-12 17:55 . 2011-06-15 07:59 -------- d-----w- c:\program files (x86)\Portal
2011-06-12 15:46 . 2011-07-03 13:31 -------- d-----w- c:\users\WoMec\AppData\Roaming\vlc
2011-06-10 13:12 . 2011-06-10 13:12 -------- d-----w- c:\users\WoMec\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2011-06-10 13:09 . 2011-06-10 13:09 -------- d-----w- c:\program files\Common Files\PACE Anti-Piracy
2011-06-10 12:31 . 2011-06-10 12:31 -------- d-----w- c:\program files (x86)\Common Files\Adobe AIR
2011-06-06 10:55 . 2011-06-06 10:55 183696 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\nppdf32.dll
2011-06-06 10:55 . 2011-06-06 10:55 183696 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-20 20:49 . 2011-05-17 10:04 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-06-14 09:40 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-06-14 09:40 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-05-30 16:22 . 2010-07-17 21:40 162816 ----a-w- c:\windows\system32\fmod.dll
2011-05-24 17:14 . 2010-01-27 15:59 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-05-18 22:33 . 2011-05-18 22:33 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-05-07 11:58 . 2011-05-07 11:58 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2011-05-07 11:58 . 2011-05-07 11:58 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2011-05-07 11:58 . 2011-05-07 11:58 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2011-05-07 11:58 . 2011-05-07 11:58 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2011-05-07 11:58 . 2011-05-07 11:58 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2011-05-07 11:58 . 2011-05-07 11:58 1126912 ----a-w- c:\windows\SysWow64\wininet.dll
2011-05-07 11:58 . 2011-05-07 11:58 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2011-05-07 11:58 . 2011-05-07 11:58 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-05-07 11:58 . 2011-05-07 11:58 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-05-07 11:58 . 2011-05-07 11:58 85504 ----a-w- c:\windows\system32\iesetup.dll
2011-05-07 11:58 . 2011-05-07 11:58 76800 ----a-w- c:\windows\system32\tdc.ocx
2011-05-07 11:58 . 2011-05-07 11:58 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2011-05-07 11:58 . 2011-05-07 11:58 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2011-05-07 11:58 . 2011-05-07 11:58 603648 ----a-w- c:\windows\system32\vbscript.dll
2011-05-07 11:58 . 2011-05-07 11:58 49664 ----a-w- c:\windows\system32\imgutil.dll
2011-05-07 11:58 . 2011-05-07 11:58 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-05-07 11:58 . 2011-05-07 11:58 448512 ----a-w- c:\windows\system32\html.iec
2011-05-07 11:58 . 2011-05-07 11:58 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2011-05-07 11:58 . 2011-05-07 11:58 367104 ----a-w- c:\windows\SysWow64\html.iec
2011-05-07 11:58 . 2011-05-07 11:58 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2011-05-07 11:58 . 2011-05-07 11:58 30720 ----a-w- c:\windows\system32\licmgr10.dll
2011-05-07 11:58 . 2011-05-07 11:58 249344 ----a-w- c:\windows\system32\webcheck.dll
2011-05-07 11:58 . 2011-05-07 11:58 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2011-05-07 11:58 . 2011-05-07 11:58 222208 ----a-w- c:\windows\system32\msls31.dll
2011-05-07 11:58 . 2011-05-07 11:58 203776 ----a-w- c:\windows\SysWow64\webcheck.dll
2011-05-07 11:58 . 2011-05-07 11:58 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2011-05-07 11:58 . 2011-05-07 11:58 165888 ----a-w- c:\windows\system32\iexpress.exe
2011-05-07 11:58 . 2011-05-07 11:58 160256 ----a-w- c:\windows\system32\wextract.exe
2011-05-07 11:58 . 2011-05-07 11:58 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2011-05-07 11:58 . 2011-05-07 11:58 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2011-05-07 11:58 . 2011-05-07 11:58 1492992 ----a-w- c:\windows\system32\inetcpl.cpl
2011-05-07 11:58 . 2011-05-07 11:58 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2011-05-07 11:58 . 2011-05-07 11:58 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2011-05-07 11:58 . 2011-05-07 11:58 1389056 ----a-w- c:\windows\system32\wininet.dll
2011-05-07 11:58 . 2011-05-07 11:58 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-05-07 11:58 . 2011-05-07 11:58 12288 ----a-w- c:\windows\system32\mshta.exe
2011-05-07 11:58 . 2011-05-07 11:58 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2011-05-07 11:58 . 2011-05-07 11:58 114176 ----a-w- c:\windows\system32\admparse.dll
2011-05-07 11:58 . 2011-05-07 11:58 111616 ----a-w- c:\windows\system32\iesysprep.dll
2011-05-07 11:58 . 2011-05-07 11:58 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2011-04-22 22:15 . 2011-05-25 06:29 27520 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2011-04-13 22:40 . 2011-04-13 22:40 4284416 ----a-w- c:\windows\SysWow64\GPhotos.scr
2011-04-09 16:55 . 2011-04-09 16:55 15453336 ----a-w- c:\windows\SysWow64\xlive.dll
2011-04-09 16:55 . 2011-04-09 16:55 13642904 ----a-w- c:\windows\SysWow64\xlivefnt.dll
2011-04-09 07:02 . 2011-05-11 09:39 5562240 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-04-09 06:58 . 2011-05-13 07:57 142336 ----a-w- c:\windows\system32\poqexec.exe
2011-04-09 06:02 . 2011-05-11 09:39 3967872 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2011-04-09 06:02 . 2011-05-11 09:39 3912576 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2011-04-09 05:56 . 2011-05-13 07:57 123904 ----a-w- c:\windows\SysWow64\poqexec.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Infium"="c:\program files (x86)\QIP 2010\qip.exem Files (x" [X]
"SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-01-07 253672]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2011-05-25 1951112]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"midi1"=myokent.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-04-16 136176]
R3 bomebus;Bome's Virtual MIDI Port Bus Service;c:\windows\system32\DRIVERS\bomebus.sys [x]
R3 bomemidi;Bome's Virtual MIDI Port;c:\windows\system32\drivers\bomemidi.sys [x]
R3 BthAudioHF;BthAudioHF Service;c:\windows\system32\DRIVERS\BthAudioHF.sys [x]
R3 BthAvrcp;Bluetooth AVRCP Profile;c:\windows\system32\DRIVERS\BthAvrcp.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 cpuz130;cpuz130;c:\users\WoMec\AppData\Local\Temp\cpuz130\cpuz_x64.sys [x]
R3 csr_a2dp;Bluetooth AV Profile;c:\windows\system32\drivers\bthav.sys [x]
R3 ENTECH64;ENTECH64;c:\windows\system32\DRIVERS\ENTECH64.sys [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-02-03 1038088]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-04-16 136176]
R3 ksaud;Creative USB Audio Driver;c:\windows\system32\drivers\ksaud.sys [x]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [x]
R3 RivaTuner64;RivaTuner64;c:\program files (x86)\RivaTuner v2.24\RivaTuner64.sys [2010-01-30 19952]
R3 TFsExDisk;TFsExDisk;c:\windows\System32\Drivers\TFsExDisk.sys [2009-12-14 16392]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TVICHW32;TVICHW32;c:\windows\system32\DRIVERS\TVICHW32.SYS [x]
R3 TVICHW64;TVICHW64;c:\windows\SysWOW64\Drivers\TVICHW64.SYS [2005-10-09 13824]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 WPRO_40_1340;WinPcap Packet Driver (WPRO_40_1340);c:\windows\system32\drivers\WPRO_40_1340.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-05-25 2275720]
S2 HFGService;Handsfree Headset Service;c:\windows\system32\svchost.exe [2009-07-14 27136]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2011-07-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-04-16 16:38]
.
2011-07-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-04-16 16:38]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-12-08 9642528]
"Creative SB Monitoring Utility"="sbavmon.dll" [2009-06-22 109056]
"MagicTuneEngine"="c:\program files (x86)\MagicTune Premium\MagicTuneEngine.exe" [2009-06-15 24064]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 660360]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\program files (x86)\Stardock\Fences\FencesMenu64.dll" [2009-10-02 134656]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
TCP: Interfaces\{6B2110FC-4F70-4EF9-9C8E-5A9E9215E9AA}: NameServer = 94.199.199.192,94.199.199.199
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - ProfilePath - c:\users\WoMec\AppData\Roaming\Mozilla\Firefox\Profiles\31kcocs3.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-Fences - c:\programdata\{A87EB928-0C6C-4071-AEF1-59E32BAEDF1B}\Fences.exe
AddRemove-Nokia PC Suite - c:\programdata\Installations\{225DB4AA-3CFF-47E8-B3C8-6DAD713E986E}\Nokia_PC_Suite_cze_web.exe
AddRemove-{10CD364B-FFCC-48BE-B469-B9622A033075} - c:\programdata\{A87EB928-0C6C-4071-AEF1-59E32BAEDF1B}\Fences.exe
AddRemove-{2AAC4085-DCBF-417B-AEBD-182197839240} - c:\programdata\{A0DFE2A5-DE68-41F3-8861-73E954C1D41D}\Traktor Setup PC.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-1965286433-519711803-1234614126-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*0*7*óNˇm\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-1965286433-519711803-1234614126-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:d9,6d,38,0c,4d,4f,ed,c5,9d,71,b8,30,07,0f,a1,66,41,43,32,99,9b,ba,e0,
85,c8,a9,e9,18,ad,9d,50,cf,1e,cf,85,ed,c3,46,8c,0c,63,b8,78,c4,b2,c7,ee,d2,\
"??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50
.
[HKEY_USERS\S-1-5-21-1965286433-519711803-1234614126-1000\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:54,68,3e,7b,cb,7d,a3,af,b5,87,26,71,8f,44,97,db,49,2f,55,8a,6d,
9a,c4,a1,c2,13,51,81,0e,b4,03,a1,f5,02,c6,64,49,e2,4a,85,72,f3,a0,07,d8,d3,\
"rkeysecu"=hex:95,e1,76,bf,79,77,29,7d,f3,2d,dd,24,f9,71,51,43
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:5a,1d,5c,b6,35,91,d0,6f,95,6d,dd,81,06,99,11,29,a4,c8,52,d9,5d,
ea,35,da,77,a3,f2,e7,6a,43,63,bd,24,64,4b,21,11,fa,d7,aa,01,d2,b8,c1,5b,51,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9f.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.9"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9f.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9f.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9f.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil9f.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil9f.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}]
@Denied: (A 2) (Everyone)
@="IFlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:5a,1d,5c,b6,35,91,d0,6f,95,6d,dd,81,06,99,11,29,a4,c8,52,d9,5d,
ea,35,da,77,a3,f2,e7,6a,43,63,bd,24,64,4b,21,11,fa,d7,aa,01,d2,b8,c1,5b,51,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2011-07-04 10:24:12
ComboFix-quarantined-files.txt 2011-07-04 08:24
.
Před spuštěním: Volných bajtů: 29 677 830 144
Po spuštění: Volných bajtů: 29 499 904 000
.
- - End Of File - - 014C00406C0C5CE3397A1A6063FB0DFE
Re: proces firefox.exe se neukončí s vypnutím programu

-otevřete si Poznámkový blok
-Do něj zkopírujte text z tohoto okénka
Kód: Vybrat vše
DDS::
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
Folder::
c:\windows\InstallDir
-po uložení uchopte vámi vytvořený skript levým myšítkem a -přesuňte ho nad ikonu Combofixu, kde ho upustíte:

-po aplikaci na Vás vypadne další log,vložte ho sem
Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou, v tom případě znovu restartujte a přitom mačkejte F8, pak zvolte Poslední známou funkční konfiguraci

http://jpshortstuff.247fixes.com/SystemLook.exe
- uložte ho na plochu a spustte.
- do okénka zkopírujte
Kód: Vybrat vše
:filefind
myokent.dll
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: proces firefox.exe se neukončí s vypnutím programu
CFLog:
ComboFix 11-07-03.04 - WoMec 04.07.2011 20:15:10.4.2 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.4094.2632 [GMT 2:00]
Spuštěný z: c:\users\WoMec\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\WoMec\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\InstallDir
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-06-04 do 2011-07-04 )))))))))))))))))))))))))))))))
.
.
2011-07-04 18:19 . 2011-07-04 18:19 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-04 08:07 . 2011-06-20 06:57 8873296 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E2B7E069-38C8-4144-98A8-19CA169B2DA0}\mpengine.dll
2011-07-04 08:07 . 2011-07-04 08:07 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-07-04 08:04 . 2011-07-04 18:12 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-07-04 08:04 . 2011-07-04 08:04 -------- d-----w- c:\programdata\NVIDIA
2011-07-03 22:48 . 2011-07-03 22:48 -------- d-----w- C:\rsit
2011-07-03 20:52 . 2011-07-03 21:02 -------- d-----w- c:\users\WoMec\AppData\Roaming\Wireshark
2011-07-03 20:36 . 2011-07-03 20:36 -------- d-----w- c:\program files\Wireshark
2011-07-03 20:18 . 2011-07-03 22:49 -------- d-----w- c:\program files\trend micro
2011-07-03 15:42 . 2011-07-03 20:24 -------- d-----w- c:\program files (x86)\Spyware Terminator
2011-07-03 15:18 . 2011-07-03 15:38 -------- d-----w- c:\users\WoMec\AppData\Roaming\ScanSpyware
2011-07-03 14:38 . 2011-07-03 14:38 -------- d-----w- c:\users\WoMec\AppData\Roaming\Malwarebytes
2011-07-03 14:37 . 2011-05-29 07:11 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-06-25 12:55 . 2011-06-25 12:55 2106216 ----a-w- c:\program files (x86)\Mozilla Firefox\D3DCompiler_43.dll
2011-06-25 12:55 . 2011-06-25 12:55 1998168 ----a-w- c:\program files (x86)\Mozilla Firefox\d3dx9_43.dll
2011-06-21 11:25 . 2011-06-21 11:25 -------- d-----w- c:\windows\C5C1C0F0D62F4DBF81D4D7EF397C228B.TMP
2011-06-15 12:52 . 2011-06-15 12:52 -------- d-----w- c:\users\WoMec\AppData\Local\Activision
2011-06-15 12:40 . 2011-06-15 12:40 -------- d-----w- c:\program files (x86)\Activision
2011-06-15 09:10 . 2011-04-27 02:40 158208 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-06-15 09:10 . 2011-04-27 02:39 289280 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-06-15 09:10 . 2011-04-27 02:39 128000 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-06-15 09:10 . 2011-05-28 03:06 3135488 ----a-w- c:\windows\system32\win32k.sys
2011-06-15 09:10 . 2011-04-25 05:33 1923968 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-06-15 09:10 . 2011-04-25 02:34 499200 ----a-w- c:\windows\system32\drivers\afd.sys
2011-06-15 09:09 . 2011-04-29 03:06 467456 ----a-w- c:\windows\system32\drivers\srv.sys
2011-06-15 09:09 . 2011-04-29 03:05 410112 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-06-15 09:09 . 2011-04-29 03:05 168448 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-06-15 09:09 . 2011-05-03 05:29 976896 ----a-w- c:\windows\system32\inetcomm.dll
2011-06-15 09:09 . 2011-05-03 04:30 741376 ----a-w- c:\windows\SysWow64\inetcomm.dll
2011-06-15 09:09 . 2011-02-25 06:22 861696 ----a-w- c:\windows\system32\oleaut32.dll
2011-06-15 09:09 . 2011-02-25 05:34 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll
2011-06-14 09:35 . 2011-06-14 09:35 -------- d-----w- c:\windows\system32\SPReview
2011-06-14 09:33 . 2011-06-14 09:33 -------- d-----w- c:\windows\system32\EventProviders
2011-06-14 09:30 . 2010-11-20 13:25 1975296 ----a-w- c:\windows\system32\CertEnroll.dll
2011-06-14 09:29 . 2010-11-20 13:32 2560 ----a-w- c:\windows\system32\drivers\cs-CZ\rdpwd.sys.mui
2011-06-14 09:29 . 2010-11-20 13:26 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\tsusbflt.sys.mui
2011-06-14 09:29 . 2010-11-20 13:32 4608 ----a-w- c:\windows\system32\drivers\cs-CZ\kbdclass.sys.mui
2011-06-14 09:29 . 2010-11-20 13:31 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\GAGP30KX.SYS.mui
2011-06-14 09:29 . 2010-11-20 12:21 189952 ----a-w- c:\windows\SysWow64\wdscore.dll
2011-06-14 09:29 . 2010-11-20 12:17 209920 ----a-w- c:\windows\SysWow64\PkgMgr.exe
2011-06-14 09:29 . 2010-11-20 12:18 323072 ----a-w- c:\windows\SysWow64\drvstore.dll
2011-06-14 09:29 . 2010-11-20 12:18 257024 ----a-w- c:\windows\SysWow64\dpx.dll
2011-06-14 09:29 . 2010-11-20 12:21 363008 ----a-w- c:\windows\SysWow64\wbemcomn.dll
2011-06-14 09:29 . 2010-11-20 12:19 606208 ----a-w- c:\windows\SysWow64\wbem\fastprox.dll
2011-06-14 09:28 . 2010-11-20 13:27 524288 ----a-w- c:\windows\system32\wmicmiplugin.dll
2011-06-14 09:28 . 2010-11-20 13:27 529408 ----a-w- c:\windows\system32\wbemcomn.dll
2011-06-14 09:28 . 2010-11-20 13:27 1225216 ----a-w- c:\windows\system32\wbem\wbemcore.dll
2011-06-14 09:28 . 2010-11-20 13:27 933376 ----a-w- c:\windows\system32\SmiEngine.dll
2011-06-14 09:28 . 2010-11-20 13:25 199168 ----a-w- c:\windows\system32\PkgMgr.exe
2011-06-14 09:28 . 2010-11-20 13:26 422912 ----a-w- c:\windows\system32\drvstore.dll
2011-06-14 09:28 . 2010-11-20 13:26 399872 ----a-w- c:\windows\system32\dpx.dll
2011-06-13 08:28 . 2011-06-13 08:28 -------- d-----w- c:\users\WoMec\AppData\Local\SKIDROW
2011-06-13 08:05 . 2011-06-13 08:31 -------- d-----w- c:\program files (x86)\Valve
2011-06-12 17:55 . 2011-06-15 07:59 -------- d-----w- c:\program files (x86)\Portal
2011-06-12 15:46 . 2011-07-03 13:31 -------- d-----w- c:\users\WoMec\AppData\Roaming\vlc
2011-06-10 13:12 . 2011-06-10 13:12 -------- d-----w- c:\users\WoMec\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2011-06-10 13:09 . 2011-06-10 13:09 -------- d-----w- c:\program files\Common Files\PACE Anti-Piracy
2011-06-10 12:31 . 2011-06-10 12:31 -------- d-----w- c:\program files (x86)\Common Files\Adobe AIR
2011-06-06 10:55 . 2011-06-06 10:55 183696 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\nppdf32.dll
2011-06-06 10:55 . 2011-06-06 10:55 183696 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-20 20:49 . 2011-05-17 10:04 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-06-14 09:40 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-06-14 09:40 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-05-30 16:22 . 2010-07-17 21:40 162816 ----a-w- c:\windows\system32\fmod.dll
2011-05-24 17:14 . 2010-01-27 15:59 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-05-18 22:33 . 2011-05-18 22:33 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-05-07 11:58 . 2011-05-07 11:58 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2011-05-07 11:58 . 2011-05-07 11:58 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2011-05-07 11:58 . 2011-05-07 11:58 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2011-05-07 11:58 . 2011-05-07 11:58 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2011-05-07 11:58 . 2011-05-07 11:58 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2011-05-07 11:58 . 2011-05-07 11:58 1126912 ----a-w- c:\windows\SysWow64\wininet.dll
2011-05-07 11:58 . 2011-05-07 11:58 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2011-05-07 11:58 . 2011-05-07 11:58 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-05-07 11:58 . 2011-05-07 11:58 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-05-07 11:58 . 2011-05-07 11:58 85504 ----a-w- c:\windows\system32\iesetup.dll
2011-05-07 11:58 . 2011-05-07 11:58 76800 ----a-w- c:\windows\system32\tdc.ocx
2011-05-07 11:58 . 2011-05-07 11:58 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2011-05-07 11:58 . 2011-05-07 11:58 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2011-05-07 11:58 . 2011-05-07 11:58 603648 ----a-w- c:\windows\system32\vbscript.dll
2011-05-07 11:58 . 2011-05-07 11:58 49664 ----a-w- c:\windows\system32\imgutil.dll
2011-05-07 11:58 . 2011-05-07 11:58 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-05-07 11:58 . 2011-05-07 11:58 448512 ----a-w- c:\windows\system32\html.iec
2011-05-07 11:58 . 2011-05-07 11:58 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2011-05-07 11:58 . 2011-05-07 11:58 367104 ----a-w- c:\windows\SysWow64\html.iec
2011-05-07 11:58 . 2011-05-07 11:58 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2011-05-07 11:58 . 2011-05-07 11:58 30720 ----a-w- c:\windows\system32\licmgr10.dll
2011-05-07 11:58 . 2011-05-07 11:58 249344 ----a-w- c:\windows\system32\webcheck.dll
2011-05-07 11:58 . 2011-05-07 11:58 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2011-05-07 11:58 . 2011-05-07 11:58 222208 ----a-w- c:\windows\system32\msls31.dll
2011-05-07 11:58 . 2011-05-07 11:58 203776 ----a-w- c:\windows\SysWow64\webcheck.dll
2011-05-07 11:58 . 2011-05-07 11:58 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2011-05-07 11:58 . 2011-05-07 11:58 165888 ----a-w- c:\windows\system32\iexpress.exe
2011-05-07 11:58 . 2011-05-07 11:58 160256 ----a-w- c:\windows\system32\wextract.exe
2011-05-07 11:58 . 2011-05-07 11:58 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2011-05-07 11:58 . 2011-05-07 11:58 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2011-05-07 11:58 . 2011-05-07 11:58 1492992 ----a-w- c:\windows\system32\inetcpl.cpl
2011-05-07 11:58 . 2011-05-07 11:58 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2011-05-07 11:58 . 2011-05-07 11:58 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2011-05-07 11:58 . 2011-05-07 11:58 1389056 ----a-w- c:\windows\system32\wininet.dll
2011-05-07 11:58 . 2011-05-07 11:58 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-05-07 11:58 . 2011-05-07 11:58 12288 ----a-w- c:\windows\system32\mshta.exe
2011-05-07 11:58 . 2011-05-07 11:58 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2011-05-07 11:58 . 2011-05-07 11:58 114176 ----a-w- c:\windows\system32\admparse.dll
2011-05-07 11:58 . 2011-05-07 11:58 111616 ----a-w- c:\windows\system32\iesysprep.dll
2011-05-07 11:58 . 2011-05-07 11:58 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2011-04-22 22:15 . 2011-05-25 06:29 27520 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2011-04-13 22:40 . 2011-04-13 22:40 4284416 ----a-w- c:\windows\SysWow64\GPhotos.scr
2011-04-09 16:55 . 2011-04-09 16:55 15453336 ----a-w- c:\windows\SysWow64\xlive.dll
2011-04-09 16:55 . 2011-04-09 16:55 13642904 ----a-w- c:\windows\SysWow64\xlivefnt.dll
2011-04-09 07:02 . 2011-05-11 09:39 5562240 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-04-09 06:58 . 2011-05-13 07:57 142336 ----a-w- c:\windows\system32\poqexec.exe
2011-04-09 06:02 . 2011-05-11 09:39 3967872 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2011-04-09 06:02 . 2011-05-11 09:39 3912576 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2011-04-09 05:56 . 2011-05-13 07:57 123904 ----a-w- c:\windows\SysWow64\poqexec.exe
.
.
((((((((((((((((((((((((((((( SnapShot@2011-07-04_08.22.11 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-01-30 12:08 . 2011-07-04 18:09 69886 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
- 2009-07-14 05:10 . 2011-07-04 08:16 46826 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-07-04 18:09 46826 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2010-01-30 09:26 . 2011-07-04 18:09 20348 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1965286433-519711803-1234614126-1000_UserData.bin
- 2010-01-27 15:43 . 2011-07-04 08:09 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-01-27 15:43 . 2011-07-04 08:25 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-01-27 15:43 . 2011-07-04 08:25 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-01-27 15:43 . 2011-07-04 08:09 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-07-04 08:09 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-07-04 08:25 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2011-07-04 08:14 . 2011-07-04 08:14 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-07-04 18:07 . 2011-07-04 18:07 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-07-04 18:07 . 2011-07-04 18:07 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-07-04 08:14 . 2011-07-04 08:14 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 05:01 . 2011-07-04 08:13 453068 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2011-07-04 09:28 453068 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2010-05-10 07:36 . 2011-07-04 09:28 15894092 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1965286433-519711803-1234614126-1000-12288.dat
- 2010-05-10 07:36 . 2011-07-04 08:13 15894092 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1965286433-519711803-1234614126-1000-12288.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Infium"="c:\program files (x86)\QIP 2010\qip.exem Files (x" [X]
"SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-01-07 253672]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2011-05-25 1951112]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"midi1"=myokent.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-04-16 136176]
R3 bomebus;Bome's Virtual MIDI Port Bus Service;c:\windows\system32\DRIVERS\bomebus.sys [x]
R3 bomemidi;Bome's Virtual MIDI Port;c:\windows\system32\drivers\bomemidi.sys [x]
R3 BthAudioHF;BthAudioHF Service;c:\windows\system32\DRIVERS\BthAudioHF.sys [x]
R3 BthAvrcp;Bluetooth AVRCP Profile;c:\windows\system32\DRIVERS\BthAvrcp.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 cpuz130;cpuz130;c:\users\WoMec\AppData\Local\Temp\cpuz130\cpuz_x64.sys [x]
R3 csr_a2dp;Bluetooth AV Profile;c:\windows\system32\drivers\bthav.sys [x]
R3 ENTECH64;ENTECH64;c:\windows\system32\DRIVERS\ENTECH64.sys [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-02-03 1038088]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-04-16 136176]
R3 ksaud;Creative USB Audio Driver;c:\windows\system32\drivers\ksaud.sys [x]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [x]
R3 RivaTuner64;RivaTuner64;c:\program files (x86)\RivaTuner v2.24\RivaTuner64.sys [2010-01-30 19952]
R3 TFsExDisk;TFsExDisk;c:\windows\System32\Drivers\TFsExDisk.sys [2009-12-14 16392]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TVICHW32;TVICHW32;c:\windows\system32\DRIVERS\TVICHW32.SYS [x]
R3 TVICHW64;TVICHW64;c:\windows\SysWOW64\Drivers\TVICHW64.SYS [2005-10-09 13824]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 WPRO_40_1340;WinPcap Packet Driver (WPRO_40_1340);c:\windows\system32\drivers\WPRO_40_1340.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-05-25 2275720]
S2 HFGService;Handsfree Headset Service;c:\windows\system32\svchost.exe [2009-07-14 27136]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2011-07-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-04-16 16:38]
.
2011-07-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-04-16 16:38]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-12-08 9642528]
"Creative SB Monitoring Utility"="sbavmon.dll" [2009-06-22 109056]
"MagicTuneEngine"="c:\program files (x86)\MagicTune Premium\MagicTuneEngine.exe" [2009-06-15 24064]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 660360]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\program files (x86)\Stardock\Fences\FencesMenu64.dll" [2009-10-02 134656]
.
------- Doplňkový sken -------
.
uLocal Page = %SystemRoot%\system32\blank.htm
mLocal Page = %SystemRoot%\system32\blank.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
TCP: Interfaces\{6B2110FC-4F70-4EF9-9C8E-5A9E9215E9AA}: NameServer = 94.199.199.192,94.199.199.199
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - ProfilePath - c:\users\WoMec\AppData\Roaming\Mozilla\Firefox\Profiles\31kcocs3.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-1965286433-519711803-1234614126-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*0*7*óNˇm\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-1965286433-519711803-1234614126-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:d9,6d,38,0c,4d,4f,ed,c5,9d,71,b8,30,07,0f,a1,66,41,43,32,99,9b,ba,e0,
85,c8,a9,e9,18,ad,9d,50,cf,1e,cf,85,ed,c3,46,8c,0c,63,b8,78,c4,b2,c7,ee,d2,\
"??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50
.
[HKEY_USERS\S-1-5-21-1965286433-519711803-1234614126-1000\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:54,68,3e,7b,cb,7d,a3,af,b5,87,26,71,8f,44,97,db,49,2f,55,8a,6d,
9a,c4,a1,c2,13,51,81,0e,b4,03,a1,f5,02,c6,64,49,e2,4a,85,72,f3,a0,07,d8,d3,\
"rkeysecu"=hex:95,e1,76,bf,79,77,29,7d,f3,2d,dd,24,f9,71,51,43
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:5a,1d,5c,b6,35,91,d0,6f,95,6d,dd,81,06,99,11,29,a4,c8,52,d9,5d,
ea,35,da,77,a3,f2,e7,6a,43,63,bd,24,64,4b,21,11,fa,d7,aa,01,d2,b8,c1,5b,51,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9f.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.9"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9f.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9f.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9f.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil9f.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil9f.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}]
@Denied: (A 2) (Everyone)
@="IFlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:5a,1d,5c,b6,35,91,d0,6f,95,6d,dd,81,06,99,11,29,a4,c8,52,d9,5d,
ea,35,da,77,a3,f2,e7,6a,43,63,bd,24,64,4b,21,11,fa,d7,aa,01,d2,b8,c1,5b,51,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2011-07-04 20:21:28
ComboFix-quarantined-files.txt 2011-07-04 18:21
ComboFix2.txt 2011-07-04 08:24
.
Před spuštěním: Volných bajtů: 29 102 448 640
Po spuštění: Volných bajtů: 29 022 601 216
.
- - End Of File - - 5E1F69AADD9C600AC950BF0A7CC5DFCE
SystemLook Log:
SystemLook 04.09.10 by jpshortstuff
Log created at 20:22 on 04/07/2011 by WoMec
Administrator - Elevation successful
WARNING: SystemLook running under WOW64. Use SystemLook_x64 for accurate results.
========== filefind ==========
Searching for "myokent.dll"
C:\Windows\System32\myokent.dll --a---- 39936 bytes [17:18 23/09/2007] [17:18 23/09/2007] 7C4C422016CB3F27B6883657495D62C0
C:\Windows\SysWOW64\myokent.dll --a---- 39936 bytes [17:18 23/09/2007] [17:18 23/09/2007] 7C4C422016CB3F27B6883657495D62C0
-= EOF =-
ComboFix 11-07-03.04 - WoMec 04.07.2011 20:15:10.4.2 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.4094.2632 [GMT 2:00]
Spuštěný z: c:\users\WoMec\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\WoMec\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\InstallDir
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-06-04 do 2011-07-04 )))))))))))))))))))))))))))))))
.
.
2011-07-04 18:19 . 2011-07-04 18:19 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-04 08:07 . 2011-06-20 06:57 8873296 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E2B7E069-38C8-4144-98A8-19CA169B2DA0}\mpengine.dll
2011-07-04 08:07 . 2011-07-04 08:07 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-07-04 08:04 . 2011-07-04 18:12 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-07-04 08:04 . 2011-07-04 08:04 -------- d-----w- c:\programdata\NVIDIA
2011-07-03 22:48 . 2011-07-03 22:48 -------- d-----w- C:\rsit
2011-07-03 20:52 . 2011-07-03 21:02 -------- d-----w- c:\users\WoMec\AppData\Roaming\Wireshark
2011-07-03 20:36 . 2011-07-03 20:36 -------- d-----w- c:\program files\Wireshark
2011-07-03 20:18 . 2011-07-03 22:49 -------- d-----w- c:\program files\trend micro
2011-07-03 15:42 . 2011-07-03 20:24 -------- d-----w- c:\program files (x86)\Spyware Terminator
2011-07-03 15:18 . 2011-07-03 15:38 -------- d-----w- c:\users\WoMec\AppData\Roaming\ScanSpyware
2011-07-03 14:38 . 2011-07-03 14:38 -------- d-----w- c:\users\WoMec\AppData\Roaming\Malwarebytes
2011-07-03 14:37 . 2011-05-29 07:11 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-06-25 12:55 . 2011-06-25 12:55 2106216 ----a-w- c:\program files (x86)\Mozilla Firefox\D3DCompiler_43.dll
2011-06-25 12:55 . 2011-06-25 12:55 1998168 ----a-w- c:\program files (x86)\Mozilla Firefox\d3dx9_43.dll
2011-06-21 11:25 . 2011-06-21 11:25 -------- d-----w- c:\windows\C5C1C0F0D62F4DBF81D4D7EF397C228B.TMP
2011-06-15 12:52 . 2011-06-15 12:52 -------- d-----w- c:\users\WoMec\AppData\Local\Activision
2011-06-15 12:40 . 2011-06-15 12:40 -------- d-----w- c:\program files (x86)\Activision
2011-06-15 09:10 . 2011-04-27 02:40 158208 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-06-15 09:10 . 2011-04-27 02:39 289280 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-06-15 09:10 . 2011-04-27 02:39 128000 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-06-15 09:10 . 2011-05-28 03:06 3135488 ----a-w- c:\windows\system32\win32k.sys
2011-06-15 09:10 . 2011-04-25 05:33 1923968 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-06-15 09:10 . 2011-04-25 02:34 499200 ----a-w- c:\windows\system32\drivers\afd.sys
2011-06-15 09:09 . 2011-04-29 03:06 467456 ----a-w- c:\windows\system32\drivers\srv.sys
2011-06-15 09:09 . 2011-04-29 03:05 410112 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-06-15 09:09 . 2011-04-29 03:05 168448 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-06-15 09:09 . 2011-05-03 05:29 976896 ----a-w- c:\windows\system32\inetcomm.dll
2011-06-15 09:09 . 2011-05-03 04:30 741376 ----a-w- c:\windows\SysWow64\inetcomm.dll
2011-06-15 09:09 . 2011-02-25 06:22 861696 ----a-w- c:\windows\system32\oleaut32.dll
2011-06-15 09:09 . 2011-02-25 05:34 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll
2011-06-14 09:35 . 2011-06-14 09:35 -------- d-----w- c:\windows\system32\SPReview
2011-06-14 09:33 . 2011-06-14 09:33 -------- d-----w- c:\windows\system32\EventProviders
2011-06-14 09:30 . 2010-11-20 13:25 1975296 ----a-w- c:\windows\system32\CertEnroll.dll
2011-06-14 09:29 . 2010-11-20 13:32 2560 ----a-w- c:\windows\system32\drivers\cs-CZ\rdpwd.sys.mui
2011-06-14 09:29 . 2010-11-20 13:26 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\tsusbflt.sys.mui
2011-06-14 09:29 . 2010-11-20 13:32 4608 ----a-w- c:\windows\system32\drivers\cs-CZ\kbdclass.sys.mui
2011-06-14 09:29 . 2010-11-20 13:31 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\GAGP30KX.SYS.mui
2011-06-14 09:29 . 2010-11-20 12:21 189952 ----a-w- c:\windows\SysWow64\wdscore.dll
2011-06-14 09:29 . 2010-11-20 12:17 209920 ----a-w- c:\windows\SysWow64\PkgMgr.exe
2011-06-14 09:29 . 2010-11-20 12:18 323072 ----a-w- c:\windows\SysWow64\drvstore.dll
2011-06-14 09:29 . 2010-11-20 12:18 257024 ----a-w- c:\windows\SysWow64\dpx.dll
2011-06-14 09:29 . 2010-11-20 12:21 363008 ----a-w- c:\windows\SysWow64\wbemcomn.dll
2011-06-14 09:29 . 2010-11-20 12:19 606208 ----a-w- c:\windows\SysWow64\wbem\fastprox.dll
2011-06-14 09:28 . 2010-11-20 13:27 524288 ----a-w- c:\windows\system32\wmicmiplugin.dll
2011-06-14 09:28 . 2010-11-20 13:27 529408 ----a-w- c:\windows\system32\wbemcomn.dll
2011-06-14 09:28 . 2010-11-20 13:27 1225216 ----a-w- c:\windows\system32\wbem\wbemcore.dll
2011-06-14 09:28 . 2010-11-20 13:27 933376 ----a-w- c:\windows\system32\SmiEngine.dll
2011-06-14 09:28 . 2010-11-20 13:25 199168 ----a-w- c:\windows\system32\PkgMgr.exe
2011-06-14 09:28 . 2010-11-20 13:26 422912 ----a-w- c:\windows\system32\drvstore.dll
2011-06-14 09:28 . 2010-11-20 13:26 399872 ----a-w- c:\windows\system32\dpx.dll
2011-06-13 08:28 . 2011-06-13 08:28 -------- d-----w- c:\users\WoMec\AppData\Local\SKIDROW
2011-06-13 08:05 . 2011-06-13 08:31 -------- d-----w- c:\program files (x86)\Valve
2011-06-12 17:55 . 2011-06-15 07:59 -------- d-----w- c:\program files (x86)\Portal
2011-06-12 15:46 . 2011-07-03 13:31 -------- d-----w- c:\users\WoMec\AppData\Roaming\vlc
2011-06-10 13:12 . 2011-06-10 13:12 -------- d-----w- c:\users\WoMec\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2011-06-10 13:09 . 2011-06-10 13:09 -------- d-----w- c:\program files\Common Files\PACE Anti-Piracy
2011-06-10 12:31 . 2011-06-10 12:31 -------- d-----w- c:\program files (x86)\Common Files\Adobe AIR
2011-06-06 10:55 . 2011-06-06 10:55 183696 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\nppdf32.dll
2011-06-06 10:55 . 2011-06-06 10:55 183696 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-20 20:49 . 2011-05-17 10:04 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-06-14 09:40 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-06-14 09:40 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-05-30 16:22 . 2010-07-17 21:40 162816 ----a-w- c:\windows\system32\fmod.dll
2011-05-24 17:14 . 2010-01-27 15:59 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-05-18 22:33 . 2011-05-18 22:33 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-05-07 11:58 . 2011-05-07 11:58 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2011-05-07 11:58 . 2011-05-07 11:58 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2011-05-07 11:58 . 2011-05-07 11:58 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2011-05-07 11:58 . 2011-05-07 11:58 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2011-05-07 11:58 . 2011-05-07 11:58 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2011-05-07 11:58 . 2011-05-07 11:58 1126912 ----a-w- c:\windows\SysWow64\wininet.dll
2011-05-07 11:58 . 2011-05-07 11:58 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2011-05-07 11:58 . 2011-05-07 11:58 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-05-07 11:58 . 2011-05-07 11:58 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-05-07 11:58 . 2011-05-07 11:58 85504 ----a-w- c:\windows\system32\iesetup.dll
2011-05-07 11:58 . 2011-05-07 11:58 76800 ----a-w- c:\windows\system32\tdc.ocx
2011-05-07 11:58 . 2011-05-07 11:58 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2011-05-07 11:58 . 2011-05-07 11:58 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2011-05-07 11:58 . 2011-05-07 11:58 603648 ----a-w- c:\windows\system32\vbscript.dll
2011-05-07 11:58 . 2011-05-07 11:58 49664 ----a-w- c:\windows\system32\imgutil.dll
2011-05-07 11:58 . 2011-05-07 11:58 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-05-07 11:58 . 2011-05-07 11:58 448512 ----a-w- c:\windows\system32\html.iec
2011-05-07 11:58 . 2011-05-07 11:58 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2011-05-07 11:58 . 2011-05-07 11:58 367104 ----a-w- c:\windows\SysWow64\html.iec
2011-05-07 11:58 . 2011-05-07 11:58 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2011-05-07 11:58 . 2011-05-07 11:58 30720 ----a-w- c:\windows\system32\licmgr10.dll
2011-05-07 11:58 . 2011-05-07 11:58 249344 ----a-w- c:\windows\system32\webcheck.dll
2011-05-07 11:58 . 2011-05-07 11:58 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2011-05-07 11:58 . 2011-05-07 11:58 222208 ----a-w- c:\windows\system32\msls31.dll
2011-05-07 11:58 . 2011-05-07 11:58 203776 ----a-w- c:\windows\SysWow64\webcheck.dll
2011-05-07 11:58 . 2011-05-07 11:58 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2011-05-07 11:58 . 2011-05-07 11:58 165888 ----a-w- c:\windows\system32\iexpress.exe
2011-05-07 11:58 . 2011-05-07 11:58 160256 ----a-w- c:\windows\system32\wextract.exe
2011-05-07 11:58 . 2011-05-07 11:58 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2011-05-07 11:58 . 2011-05-07 11:58 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2011-05-07 11:58 . 2011-05-07 11:58 1492992 ----a-w- c:\windows\system32\inetcpl.cpl
2011-05-07 11:58 . 2011-05-07 11:58 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2011-05-07 11:58 . 2011-05-07 11:58 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2011-05-07 11:58 . 2011-05-07 11:58 1389056 ----a-w- c:\windows\system32\wininet.dll
2011-05-07 11:58 . 2011-05-07 11:58 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-05-07 11:58 . 2011-05-07 11:58 12288 ----a-w- c:\windows\system32\mshta.exe
2011-05-07 11:58 . 2011-05-07 11:58 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2011-05-07 11:58 . 2011-05-07 11:58 114176 ----a-w- c:\windows\system32\admparse.dll
2011-05-07 11:58 . 2011-05-07 11:58 111616 ----a-w- c:\windows\system32\iesysprep.dll
2011-05-07 11:58 . 2011-05-07 11:58 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2011-04-22 22:15 . 2011-05-25 06:29 27520 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2011-04-13 22:40 . 2011-04-13 22:40 4284416 ----a-w- c:\windows\SysWow64\GPhotos.scr
2011-04-09 16:55 . 2011-04-09 16:55 15453336 ----a-w- c:\windows\SysWow64\xlive.dll
2011-04-09 16:55 . 2011-04-09 16:55 13642904 ----a-w- c:\windows\SysWow64\xlivefnt.dll
2011-04-09 07:02 . 2011-05-11 09:39 5562240 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-04-09 06:58 . 2011-05-13 07:57 142336 ----a-w- c:\windows\system32\poqexec.exe
2011-04-09 06:02 . 2011-05-11 09:39 3967872 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2011-04-09 06:02 . 2011-05-11 09:39 3912576 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2011-04-09 05:56 . 2011-05-13 07:57 123904 ----a-w- c:\windows\SysWow64\poqexec.exe
.
.
((((((((((((((((((((((((((((( SnapShot@2011-07-04_08.22.11 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-01-30 12:08 . 2011-07-04 18:09 69886 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
- 2009-07-14 05:10 . 2011-07-04 08:16 46826 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-07-04 18:09 46826 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2010-01-30 09:26 . 2011-07-04 18:09 20348 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1965286433-519711803-1234614126-1000_UserData.bin
- 2010-01-27 15:43 . 2011-07-04 08:09 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-01-27 15:43 . 2011-07-04 08:25 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-01-27 15:43 . 2011-07-04 08:25 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-01-27 15:43 . 2011-07-04 08:09 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-07-04 08:09 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-07-04 08:25 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2011-07-04 08:14 . 2011-07-04 08:14 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-07-04 18:07 . 2011-07-04 18:07 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-07-04 18:07 . 2011-07-04 18:07 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-07-04 08:14 . 2011-07-04 08:14 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 05:01 . 2011-07-04 08:13 453068 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2011-07-04 09:28 453068 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2010-05-10 07:36 . 2011-07-04 09:28 15894092 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1965286433-519711803-1234614126-1000-12288.dat
- 2010-05-10 07:36 . 2011-07-04 08:13 15894092 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1965286433-519711803-1234614126-1000-12288.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Infium"="c:\program files (x86)\QIP 2010\qip.exem Files (x" [X]
"SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-01-07 253672]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2011-05-25 1951112]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"midi1"=myokent.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-04-16 136176]
R3 bomebus;Bome's Virtual MIDI Port Bus Service;c:\windows\system32\DRIVERS\bomebus.sys [x]
R3 bomemidi;Bome's Virtual MIDI Port;c:\windows\system32\drivers\bomemidi.sys [x]
R3 BthAudioHF;BthAudioHF Service;c:\windows\system32\DRIVERS\BthAudioHF.sys [x]
R3 BthAvrcp;Bluetooth AVRCP Profile;c:\windows\system32\DRIVERS\BthAvrcp.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 cpuz130;cpuz130;c:\users\WoMec\AppData\Local\Temp\cpuz130\cpuz_x64.sys [x]
R3 csr_a2dp;Bluetooth AV Profile;c:\windows\system32\drivers\bthav.sys [x]
R3 ENTECH64;ENTECH64;c:\windows\system32\DRIVERS\ENTECH64.sys [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-02-03 1038088]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-04-16 136176]
R3 ksaud;Creative USB Audio Driver;c:\windows\system32\drivers\ksaud.sys [x]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [x]
R3 RivaTuner64;RivaTuner64;c:\program files (x86)\RivaTuner v2.24\RivaTuner64.sys [2010-01-30 19952]
R3 TFsExDisk;TFsExDisk;c:\windows\System32\Drivers\TFsExDisk.sys [2009-12-14 16392]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TVICHW32;TVICHW32;c:\windows\system32\DRIVERS\TVICHW32.SYS [x]
R3 TVICHW64;TVICHW64;c:\windows\SysWOW64\Drivers\TVICHW64.SYS [2005-10-09 13824]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 WPRO_40_1340;WinPcap Packet Driver (WPRO_40_1340);c:\windows\system32\drivers\WPRO_40_1340.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-05-25 2275720]
S2 HFGService;Handsfree Headset Service;c:\windows\system32\svchost.exe [2009-07-14 27136]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2011-07-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-04-16 16:38]
.
2011-07-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-04-16 16:38]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-12-08 9642528]
"Creative SB Monitoring Utility"="sbavmon.dll" [2009-06-22 109056]
"MagicTuneEngine"="c:\program files (x86)\MagicTune Premium\MagicTuneEngine.exe" [2009-06-15 24064]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 660360]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\program files (x86)\Stardock\Fences\FencesMenu64.dll" [2009-10-02 134656]
.
------- Doplňkový sken -------
.
uLocal Page = %SystemRoot%\system32\blank.htm
mLocal Page = %SystemRoot%\system32\blank.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
TCP: Interfaces\{6B2110FC-4F70-4EF9-9C8E-5A9E9215E9AA}: NameServer = 94.199.199.192,94.199.199.199
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - ProfilePath - c:\users\WoMec\AppData\Roaming\Mozilla\Firefox\Profiles\31kcocs3.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-1965286433-519711803-1234614126-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*0*7*óNˇm\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-1965286433-519711803-1234614126-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:d9,6d,38,0c,4d,4f,ed,c5,9d,71,b8,30,07,0f,a1,66,41,43,32,99,9b,ba,e0,
85,c8,a9,e9,18,ad,9d,50,cf,1e,cf,85,ed,c3,46,8c,0c,63,b8,78,c4,b2,c7,ee,d2,\
"??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50
.
[HKEY_USERS\S-1-5-21-1965286433-519711803-1234614126-1000\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:54,68,3e,7b,cb,7d,a3,af,b5,87,26,71,8f,44,97,db,49,2f,55,8a,6d,
9a,c4,a1,c2,13,51,81,0e,b4,03,a1,f5,02,c6,64,49,e2,4a,85,72,f3,a0,07,d8,d3,\
"rkeysecu"=hex:95,e1,76,bf,79,77,29,7d,f3,2d,dd,24,f9,71,51,43
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:5a,1d,5c,b6,35,91,d0,6f,95,6d,dd,81,06,99,11,29,a4,c8,52,d9,5d,
ea,35,da,77,a3,f2,e7,6a,43,63,bd,24,64,4b,21,11,fa,d7,aa,01,d2,b8,c1,5b,51,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9f.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.9"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9f.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9f.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9f.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil9f.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil9f.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}]
@Denied: (A 2) (Everyone)
@="IFlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:5a,1d,5c,b6,35,91,d0,6f,95,6d,dd,81,06,99,11,29,a4,c8,52,d9,5d,
ea,35,da,77,a3,f2,e7,6a,43,63,bd,24,64,4b,21,11,fa,d7,aa,01,d2,b8,c1,5b,51,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2011-07-04 20:21:28
ComboFix-quarantined-files.txt 2011-07-04 18:21
ComboFix2.txt 2011-07-04 08:24
.
Před spuštěním: Volných bajtů: 29 102 448 640
Po spuštění: Volných bajtů: 29 022 601 216
.
- - End Of File - - 5E1F69AADD9C600AC950BF0A7CC5DFCE
SystemLook Log:
SystemLook 04.09.10 by jpshortstuff
Log created at 20:22 on 04/07/2011 by WoMec
Administrator - Elevation successful
WARNING: SystemLook running under WOW64. Use SystemLook_x64 for accurate results.
========== filefind ==========
Searching for "myokent.dll"
C:\Windows\System32\myokent.dll --a---- 39936 bytes [17:18 23/09/2007] [17:18 23/09/2007] 7C4C422016CB3F27B6883657495D62C0
C:\Windows\SysWOW64\myokent.dll --a---- 39936 bytes [17:18 23/09/2007] [17:18 23/09/2007] 7C4C422016CB3F27B6883657495D62C0
-= EOF =-
Re: proces firefox.exe se neukončí s vypnutím programu
Otestujte na www.virustotal.com
C:\Windows\System32\myokent.dll
C:\Windows\System32\myokent.dll
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: proces firefox.exe se neukončí s vypnutím programu
File already submitted: The file sent has already been analysed by VirusTotal in the past. This is same basic info regarding the sample itself and its last analysis:
MD5: 7c4c422016cb3f27b6883657495d62c0
Date first seen: 2009-02-13 08:56:19 (UTC)
Date last seen: 2011-06-27 03:46:12 (UTC)
Detection ratio: 0/42
MD5: 7c4c422016cb3f27b6883657495d62c0
Date first seen: 2009-02-13 08:56:19 (UTC)
Date last seen: 2011-06-27 03:46:12 (UTC)
Detection ratio: 0/42