Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

haveď v notebooku

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: haveď v notebooku

#61 Příspěvek od vyosek »

Skript pro Avenger, postup jako minule

Kód: Vybrat vše

Files to delete:
C:\Documents and Settings\Michal\Application Data\346.exe
C:\Documents and Settings\Michal\Start Menu\Programs\Startup\xD.exe
C:\Documents and Settings\Michal\Application Data\Qjisii.exe
C:\DOCUMENTS AND SETTINGS\Michal\LOCAL SETTINGS\Temp\Winlogo.exe

Registry values to delete:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad | Windows Task Services

Drivers to delete:
PEVSystemStart
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Crosby.WX
Návštěvník
Návštěvník
Příspěvky: 71
Registrován: 01 lis 2008 15:41

Re: haveď v notebooku

#62 Příspěvek od Crosby.WX »

Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!

File "C:\Documents and Settings\Michal\Application Data\346.exe" deleted successfully.
File "C:\Documents and Settings\Michal\Start Menu\Programs\Startup\xD.exe" deleted successfully.

Error: file "C:\Documents and Settings\Michal\Application Data\Qjisii.exe" not found!
Deletion of file "C:\Documents and Settings\Michal\Application Data\Qjisii.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist

File "C:\DOCUMENTS AND SETTINGS\Michal\LOCAL SETTINGS\Temp\Winlogo.exe" deleted successfully.
Driver "PEVSystemStart" deleted successfully.

Error: could not delete registry value "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad|Windows Task Services"
Deletion of registry value "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad|Windows Task Services" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Completed script processing.

*******************

Finished! Terminate.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: haveď v notebooku

#63 Příspěvek od vyosek »

Zmena :???: ctfmon.exe je legitimni soubor, tim se netrapte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Crosby.WX
Návštěvník
Návštěvník
Příspěvky: 71
Registrován: 01 lis 2008 15:41

Re: haveď v notebooku

#64 Příspěvek od Crosby.WX »

No v procesoch to vyzera byť pohodka ale v ccleaneri v nástrojoch "po štarte" mám
Áno HKCU:Run Qjisii C:\Documents and Settings\Michal\Application Data\Qjisii.exe

mne sa zdá že ono sa mi to tu drži jak kliesť... ale každopádne dakujem za doterajšiu pomoc len furt mi to tu niekde trčí

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: haveď v notebooku

#65 Příspěvek od vyosek »

Skript pro OTL, log pak sem

Kód: Vybrat vše

:reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Qjisii"=-

:files
C:\Documents and Settings\Michal\Application Data\*.exe
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp

:commands
[RESETHOSTS]
[EMPTYTEMP]
[EMPTYFLASH]
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Crosby.WX
Návštěvník
Návštěvník
Příspěvky: 71
Registrován: 01 lis 2008 15:41

Re: haveď v notebooku

#66 Příspěvek od Crosby.WX »

Mam niečo zakliknúť? a "run scan" alebo "run fix" :roll: prepáčte ale pre istotu sa aj na maličkosti pytam :)

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: haveď v notebooku

#67 Příspěvek od vyosek »

Jasny, v pohode...Run Fix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Crosby.WX
Návštěvník
Návštěvník
Příspěvky: 71
Registrován: 01 lis 2008 15:41

Re: haveď v notebooku

#68 Příspěvek od Crosby.WX »

All processes killed
========== REGISTRY ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Qjisii deleted successfully.
========== FILES ==========
File\Folder C:\Documents and Settings\Michal\Application Data\*.exe not found.
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
File/Folder C:\WINDOWS\*.tmp not found.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Michal
->Temp folder emptied: 44135 bytes
->Temporary Internet Files folder emptied: 653394 bytes
->Google Chrome cache emptied: 375535987 bytes
->Flash cache emptied: 2510 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 359,00 mb


[EMPTYFLASH]

User: Administrator

User: All Users

User: Default User

User: LocalService

User: Michal
->Flash cache emptied: 0 bytes

User: NetworkService

Total Flash Files Cleaned = 0,00 mb


OTL by OldTimer - Version 3.2.31.0 log created on 01222012_200820

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: haveď v notebooku

#69 Příspěvek od vyosek »

Mel by nyni i Qjisii zmizet z CCleaneru...

Poprosim o novy log z RSIT
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Crosby.WX
Návštěvník
Návštěvník
Příspěvky: 71
Registrován: 01 lis 2008 15:41

Re: haveď v notebooku

#70 Příspěvek od Crosby.WX »

Neni tam :) Už sa tu celkom dlho so mňou trápite... nech sa pači log


Logfile of random's system information tool 1.09 (written by random/random)
Run by Michal at 2012-01-22 20:20:31
Microsoft Windows XP Professional Service Pack 3
System drive C: has 50 GB (66%) free of 76 GB
Total RAM: 447 MB (19% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:20:34, on 22. 1. 2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\acs.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Wireless Console 2\wcourier.exe
C:\Program Files\Atheros\ACU.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Michal\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Michal\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Michal\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Michal\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Michal\My Documents\Downloads\RSIT.exe
C:\Program Files\trend micro\Michal.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [Wireless Console 2] "C:\Program Files\Wireless Console 2\wcourier.exe"
O4 - HKLM\..\Run: [ACU] "C:\Program Files\Atheros\ACU.exe" -nogui
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&oslať do programu OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Atheros Configuration Service (ACS) - Atheros - C:\WINDOWS\system32\acs.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: KMService - Unknown owner - C:\WINDOWS\system32\srvany.exe

--
End of file - 4532 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-01-21 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-01-16 561552]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Wireless Console 2"=C:\Program Files\Wireless Console 2\wcourier.exe [2007-07-05 1040384]
"ACU"=C:\Program Files\Atheros\ACU.exe [2007-05-03 376921]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ACMON]
C:\Program Files\ASUS\Splendid\ACMON.exe [2007-07-10 851968]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
C:\WINDOWS\ALCWZRD.EXE [2006-05-04 2808832]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Camera ScreenSaver]
C:\WINDOWS\ASScrProlog.exe [2012-01-03 37232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Live Update]
C:\Program Files\ASUS\ASUS Live Update\ALU.exe [2007-11-30 51768]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIModeChange]
C:\WINDOWS\system32\Ati2mdxx.exe [2007-07-04 26112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATKHOTKEY]
C:\Program Files\ATK Hotkey\Hcontrol.exe [2007-08-23 229376]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
C:\WINDOWS\RTHDCPL.EXE [2006-10-30 16269312]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
C:\WINDOWS\SkyTel.EXE [2006-05-16 2879488]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
C:\WINDOWS\SOUNDMAN.EXE [2006-07-21 86016]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2006-11-10 90112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2007-07-04 118784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-01-21 4222864]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Garena Plus\Room\garena_room.exe"="C:\Program Files\Garena Plus\Room\garena_room.exe:*:Enabled:Garena"
"C:\Program Files\Microsoft Office\Office14\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office14\GROOVE.EXE:*:Enabled:Microsoft SharePoint Workspace"
"C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE:*:Enabled:Microsoft OneNote"
"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======List of files/folders created in the last 1 month======

2012-01-22 19:48:07 ----A---- C:\avenger.txt
2012-01-21 23:20:27 ----D---- C:\Avenger
2012-01-21 20:29:40 ----D---- C:\Documents and Settings\Michal\Application Data\XnView
2012-01-21 20:25:52 ----D---- C:\Program Files\XnView
2012-01-13 18:10:31 ----SD---- C:\Beruska.com29458B
2012-01-13 16:51:14 ----D---- C:\_OTL
2012-01-12 15:33:20 ----D---- C:\WINDOWS\Temp
2012-01-12 14:22:42 ----SD---- C:\Beruska.com
2012-01-12 14:21:29 ----SHD---- C:\WINDOWS\CSC
2012-01-11 22:46:18 ----A---- C:\Boot.bak
2012-01-11 22:46:13 ----RASHD---- C:\cmdcons
2012-01-11 22:44:42 ----A---- C:\WINDOWS\zip.exe
2012-01-11 22:44:42 ----A---- C:\WINDOWS\SWXCACLS.exe
2012-01-11 22:44:42 ----A---- C:\WINDOWS\SWSC.exe
2012-01-11 22:44:42 ----A---- C:\WINDOWS\SWREG.exe
2012-01-11 22:44:42 ----A---- C:\WINDOWS\sed.exe
2012-01-11 22:44:42 ----A---- C:\WINDOWS\PEV.exe
2012-01-11 22:44:42 ----A---- C:\WINDOWS\NIRCMD.exe
2012-01-11 22:44:42 ----A---- C:\WINDOWS\MBR.exe
2012-01-11 22:44:42 ----A---- C:\WINDOWS\grep.exe
2012-01-11 22:44:37 ----D---- C:\WINDOWS\ERDNT
2012-01-11 22:44:32 ----D---- C:\Qoobox
2012-01-11 18:06:54 ----A---- C:\TDSSKiller.2.7.0.0_11.01.2012_18.06.54_log.txt
2012-01-11 17:49:29 ----A---- C:\WINDOWS\system32\drivers\TrueSight.sys
2012-01-09 23:43:32 ----D---- C:\Documents and Settings\All Users\Application Data\FLEXnet
2012-01-09 23:40:10 ----A---- C:\WINDOWS\system32\BASSMOD.dll
2012-01-09 23:37:46 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2012-01-09 23:36:56 ----D---- C:\Program Files\Bonjour
2012-01-09 23:28:52 ----D---- C:\Program Files\Adobe
2012-01-09 23:28:14 ----D---- C:\Program Files\Common Files\Macrovision Shared
2012-01-09 23:27:09 ----D---- C:\Program Files\Common Files\Adobe
2012-01-09 23:05:41 ----A---- C:\WINDOWS\system32\srvany.exe
2012-01-09 23:02:21 ----D---- C:\Program Files\Common Files\DESIGNER
2012-01-09 23:02:13 ----D---- C:\Program Files\MSBuild
2012-01-09 23:00:56 ----D---- C:\Program Files\Microsoft Sync Framework
2012-01-09 22:59:56 ----D---- C:\Program Files\Microsoft Visual Studio 8
2012-01-09 22:58:08 ----D---- C:\Program Files\Microsoft Analysis Services
2012-01-09 22:57:51 ----D---- C:\WINDOWS\SHELLNEW
2012-01-09 22:57:00 ----D---- C:\Program Files\Microsoft Office
2012-01-09 22:56:58 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2012-01-09 22:56:41 ----RHD---- C:\MSOCache
2012-01-09 12:10:43 ----D---- C:\Documents and Settings\Michal\Application Data\AVG
2012-01-09 12:09:17 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2012-01-09 12:09:07 ----D---- C:\Program Files\AVG
2012-01-09 11:53:19 ----D---- C:\Program Files\trend micro
2012-01-09 11:53:16 ----D---- C:\rsit
2012-01-09 11:29:11 ----D---- C:\Documents and Settings\Michal\Application Data\Malwarebytes
2012-01-09 11:28:32 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2012-01-09 11:28:31 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2012-01-09 11:28:31 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2012-01-06 15:28:38 ----A---- C:\WINDOWS\WORDPAD.INI
2012-01-06 01:13:18 ----D---- C:\Program Files\Elaborate Bytes
2012-01-06 01:08:04 ----D---- C:\Documents and Settings\All Users\Application Data\DVD Shrink
2012-01-06 01:08:03 ----D---- C:\Program Files\DVD Shrink
2012-01-06 00:47:38 ----D---- C:\Documents and Settings\Michal\Application Data\WinRAR
2012-01-06 00:46:52 ----D---- C:\Program Files\WinRAR
2012-01-04 14:11:54 ----D---- C:\Documents and Settings\Michal\Application Data\vlc
2012-01-03 22:50:54 ----A---- C:\Documents and Settings\Michal\Application Data\room_v3.dat
2012-01-03 22:18:56 ----D---- C:\Documents and Settings\Michal\Application Data\GarenaPlus
2012-01-03 22:17:58 ----D---- C:\Program Files\Garena Plus
2012-01-03 22:17:56 ----D---- C:\Documents and Settings\All Users\Application Data\GarenaMessenger
2012-01-03 22:05:35 ----D---- C:\Documents and Settings\Michal\Application Data\TS3Client
2012-01-03 22:00:43 ----D---- C:\Program Files\TeamSpeak 3 Client
2012-01-03 21:58:29 ----A---- C:\WINDOWS\system32\XAudio2_5.dll
2012-01-03 21:58:28 ----A---- C:\WINDOWS\system32\xactengine3_5.dll
2012-01-03 21:58:27 ----A---- C:\WINDOWS\system32\D3DCompiler_42.dll
2012-01-03 21:58:24 ----A---- C:\WINDOWS\system32\d3dcsx_42.dll
2012-01-03 21:58:23 ----A---- C:\WINDOWS\system32\d3dx11_42.dll
2012-01-03 21:58:22 ----A---- C:\WINDOWS\system32\D3DX9_42.dll
2012-01-03 21:58:22 ----A---- C:\WINDOWS\system32\d3dx10_42.dll
2012-01-03 21:58:21 ----A---- C:\WINDOWS\system32\d3dx10_41.dll
2012-01-03 21:58:21 ----A---- C:\WINDOWS\system32\D3DCompiler_41.dll
2012-01-03 21:58:20 ----A---- C:\WINDOWS\system32\D3DX9_41.dll
2012-01-03 21:58:19 ----A---- C:\WINDOWS\system32\XAudio2_4.dll
2012-01-03 21:58:19 ----A---- C:\WINDOWS\system32\XAPOFX1_3.dll
2012-01-03 21:58:18 ----A---- C:\WINDOWS\system32\xactengine3_4.dll
2012-01-03 21:58:18 ----A---- C:\WINDOWS\system32\X3DAudio1_6.dll
2012-01-03 21:58:17 ----A---- C:\WINDOWS\system32\d3dx10_40.dll
2012-01-03 21:58:17 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll
2012-01-03 21:58:15 ----A---- C:\WINDOWS\system32\D3DX9_40.dll
2012-01-03 21:58:14 ----A---- C:\WINDOWS\system32\XAudio2_3.dll
2012-01-03 21:58:14 ----A---- C:\WINDOWS\system32\XAPOFX1_2.dll
2012-01-03 21:58:14 ----A---- C:\WINDOWS\system32\xactengine3_3.dll
2012-01-03 21:58:14 ----A---- C:\WINDOWS\system32\X3DAudio1_5.dll
2012-01-03 21:58:13 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2012-01-03 21:58:13 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2012-01-03 21:58:13 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
2012-01-03 21:58:12 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2012-01-03 21:58:12 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2012-01-03 21:58:11 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2012-01-03 21:58:10 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
2012-01-03 21:58:10 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
2012-01-03 21:58:09 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
2012-01-03 21:58:09 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
2012-01-03 21:58:08 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
2012-01-03 21:58:08 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
2012-01-03 21:58:07 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
2012-01-03 21:58:06 ----A---- C:\WINDOWS\system32\XAudio2_0.dll
2012-01-03 21:58:06 ----A---- C:\WINDOWS\system32\xactengine3_0.dll
2012-01-03 21:58:05 ----A---- C:\WINDOWS\system32\X3DAudio1_3.dll
2012-01-03 21:58:05 ----A---- C:\WINDOWS\system32\d3dx10_37.dll
2012-01-03 21:58:05 ----A---- C:\WINDOWS\system32\D3DCompiler_37.dll
2012-01-03 21:58:04 ----A---- C:\WINDOWS\system32\D3DX9_37.dll
2012-01-03 21:58:03 ----A---- C:\WINDOWS\system32\xactengine2_10.dll
2012-01-03 21:58:02 ----A---- C:\WINDOWS\system32\d3dx10_36.dll
2012-01-03 21:58:02 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll
2012-01-03 21:58:00 ----A---- C:\WINDOWS\system32\d3dx9_36.dll
2012-01-03 21:57:59 ----A---- C:\WINDOWS\system32\xactengine2_9.dll
2012-01-03 21:57:58 ----A---- C:\WINDOWS\system32\d3dx10_35.dll
2012-01-03 21:57:58 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll
2012-01-03 21:57:57 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
2012-01-03 21:57:56 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
2012-01-03 21:57:56 ----A---- C:\WINDOWS\system32\X3DAudio1_2.dll
2012-01-03 21:57:55 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2012-01-03 21:57:55 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2012-01-03 21:57:54 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2012-01-03 21:57:53 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2012-01-03 21:57:51 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
2012-01-03 21:57:50 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2012-01-03 21:57:50 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2012-01-03 21:57:48 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2012-01-03 21:57:48 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2012-01-03 21:57:47 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
2012-01-03 21:57:46 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
2012-01-03 21:57:45 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2012-01-03 21:57:45 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2012-01-03 21:57:45 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2012-01-03 21:57:44 ----A---- C:\WINDOWS\system32\xinput1_2.dll
2012-01-03 21:57:44 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
2012-01-03 21:57:43 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2012-01-03 21:57:43 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2012-01-03 21:57:42 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2012-01-03 21:57:30 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2012-01-03 21:57:29 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2012-01-03 21:57:29 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2012-01-03 21:57:28 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2012-01-03 21:57:25 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2012-01-03 21:57:24 ----A---- C:\WINDOWS\system32\xinput9_1_0.dll
2012-01-03 21:57:23 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2012-01-03 21:57:22 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2012-01-03 21:57:21 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2012-01-03 21:57:18 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2012-01-03 21:56:53 ----D---- C:\WINDOWS\Logs
2012-01-03 18:26:43 ----A---- C:\WINDOWS\War3Unin.dat
2012-01-03 18:26:42 ----A---- C:\WINDOWS\War3Unin.pif
2012-01-03 18:26:42 ----A---- C:\WINDOWS\War3Unin.exe
2012-01-03 18:25:27 ----D---- C:\Program Files\Warcraft III
2012-01-03 17:55:27 ----D---- C:\Program Files\VideoLAN
2012-01-03 09:43:51 ----A---- C:\WINDOWS\system32\acs.exe
2012-01-03 09:43:39 ----A---- C:\WINDOWS\system32\wsimd.sys
2012-01-03 09:43:39 ----A---- C:\WINDOWS\system32\wsimd.dll
2012-01-03 09:43:39 ----A---- C:\WINDOWS\system32\wsfwDS.dll
2012-01-03 09:43:39 ----A---- C:\WINDOWS\system32\wgapi.dll
2012-01-03 09:43:39 ----A---- C:\WINDOWS\system32\wcapiU.dll
2012-01-03 09:43:39 ----A---- C:\WINDOWS\system32\wcapi.dll
2012-01-03 09:43:39 ----A---- C:\WINDOWS\system32\dsaNac.dll
2012-01-03 09:43:39 ----A---- C:\WINDOWS\system32\dsa.dll
2012-01-03 09:43:39 ----A---- C:\WINDOWS\system32\drivers\wsimd.sys
2012-01-03 09:43:39 ----A---- C:\WINDOWS\system32\athcfg20U.dll
2012-01-03 09:43:39 ----A---- C:\WINDOWS\system32\athcfg20resU.dll
2012-01-03 09:43:39 ----A---- C:\WINDOWS\system32\athcfg20res.dll
2012-01-03 09:43:39 ----A---- C:\WINDOWS\system32\athcfg20.dll
2012-01-03 09:43:37 ----D---- C:\Program Files\Atheros
2012-01-03 09:43:28 ----A---- C:\WINDOWS\system32\drivers\ar5211.sys
2012-01-03 09:43:28 ----A---- C:\WINDOWS\system32\ar5211.sys
2012-01-03 09:43:07 ----D---- C:\Documents and Settings\All Users\Application Data\Atheros
2012-01-03 09:42:39 ----D---- C:\Program Files\Wireless Console 2
2012-01-03 09:42:08 ----A---- C:\WINDOWS\ASUS Camera ScreenSaver.exe
2012-01-03 09:42:08 ----A---- C:\WINDOWS\ASUS Camera ScreenSaver Uninstaller.exe
2012-01-03 09:42:08 ----A---- C:\WINDOWS\ASScrProlog.exe
2012-01-03 09:42:07 ----A---- C:\WINDOWS\Asus_Camera_ScreenSaver.scr
2012-01-03 09:42:06 ----D---- C:\WINDOWS\Asus_Camera_ScreenSaver dir
2012-01-03 09:42:06 ----D---- C:\Documents and Settings\Michal\Application Data\Macromedia
2012-01-03 09:42:06 ----A---- C:\WINDOWS\impborl.dll
2012-01-03 09:42:06 ----A---- C:\WINDOWS\flashax.exe
2012-01-03 09:41:45 ----A---- C:\WINDOWS\system32\ACEngSvr.exe
2012-01-03 09:40:51 ----SHD---- C:\RECYCLER
2012-01-03 09:40:12 ----D---- C:\Program Files\ASUS
2012-01-03 09:40:06 ----D---- C:\Program Files\Common Files\InstallShield
2012-01-03 09:39:11 ----D---- C:\Program Files\ATK Hotkey
2012-01-03 09:39:10 ----HD---- C:\Program Files\InstallShield Installation Information
2012-01-03 09:39:04 ----D---- C:\Documents and Settings\Michal\Application Data\InstallShield
2012-01-03 09:36:58 ----A---- C:\WINDOWS\system32\drivers\USBSTOR.SYS
2012-01-03 09:33:55 ----D---- C:\Documents and Settings\Michal\Application Data\Identities
2012-01-03 09:33:54 ----HD---- C:\Program Files\Uninstall Information
2012-01-03 09:32:12 ----ASH---- C:\Documents and Settings\Michal\Application Data\desktop.ini
2012-01-03 09:32:11 ----SD---- C:\Documents and Settings\Michal\Application Data\Microsoft
2012-01-03 09:29:09 ----D---- C:\WINDOWS\SoftwareDistribution
2012-01-03 09:29:08 ----D---- C:\WINDOWS\Prefetch
2012-01-03 09:29:07 ----SD---- C:\WINDOWS\system32\Microsoft
2012-01-03 09:29:07 ----A---- C:\WINDOWS\SchedLgU.Txt
2012-01-03 09:27:30 ----AS---- C:\WINDOWS\bootstat.dat
2012-01-03 09:25:00 ----D---- C:\WINDOWS\system32\xircom
2012-01-03 09:25:00 ----D---- C:\Program Files\xerox
2012-01-03 09:25:00 ----D---- C:\Program Files\microsoft frontpage
2012-01-03 09:24:35 ----RASH---- C:\MSDOS.SYS
2012-01-03 09:24:35 ----RASH---- C:\IO.SYS
2012-01-03 09:24:35 ----A---- C:\WINDOWS\control.ini
2012-01-03 09:24:35 ----A---- C:\CONFIG.SYS
2012-01-03 09:24:35 ----A---- C:\AUTOEXEC.BAT
2012-01-03 09:24:13 ----A---- C:\WINDOWS\system32\mapi32.dll
2012-01-03 09:23:06 ----SD---- C:\WINDOWS\Downloaded Program Files
2012-01-03 09:23:06 ----RD---- C:\WINDOWS\Offline Web Pages
2012-01-03 09:22:54 ----HD---- C:\Program Files\WindowsUpdate
2012-01-03 09:22:25 ----D---- C:\WINDOWS\system32\DirectX
2012-01-03 09:22:19 ----A---- C:\WINDOWS\system32\atrace.dll
2012-01-03 09:22:15 ----A---- C:\WINDOWS\system32\desktop.ini
2012-01-03 09:22:15 ----A---- C:\WINDOWS\desktop.ini
2012-01-03 09:22:08 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2012-01-03 09:22:07 ----A---- C:\WINDOWS\system32\acctres.dll
2012-01-03 09:22:06 ----D---- C:\Program Files\Common Files\Services
2012-01-03 09:22:04 ----SD---- C:\WINDOWS\Tasks
2012-01-03 09:22:04 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2012-01-03 09:22:03 ----D---- C:\Program Files\Common Files\MSSoap
2012-01-03 09:21:58 ----D---- C:\WINDOWS\srchasst
2012-01-03 09:21:57 ----D---- C:\WINDOWS\system32\Macromed
2012-01-03 09:21:54 ----A---- C:\WINDOWS\system32\wuweb.dll
2012-01-03 09:21:54 ----A---- C:\WINDOWS\system32\wucltui.dll
2012-01-03 09:21:54 ----A---- C:\WINDOWS\system32\wuauserv.dll
2012-01-03 09:21:53 ----A---- C:\WINDOWS\system32\wups.dll
2012-01-03 09:21:53 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2012-01-03 09:21:53 ----A---- C:\WINDOWS\system32\wuaueng.dll
2012-01-03 09:21:53 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2012-01-03 09:21:53 ----A---- C:\WINDOWS\system32\wuauclt.exe
2012-01-03 09:21:52 ----A---- C:\WINDOWS\system32\wuapi.dll
2012-01-03 09:21:52 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2012-01-03 09:21:52 ----A---- C:\WINDOWS\system32\qmgr.dll
2012-01-03 09:21:52 ----A---- C:\WINDOWS\system32\bitsprx4.dll
2012-01-03 09:21:52 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2012-01-03 09:21:52 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2012-01-03 09:21:46 ----D---- C:\Program Files\Movie Maker
2012-01-03 09:21:28 ----A---- C:\WINDOWS\system32\safrslv.dll
2012-01-03 09:21:28 ----A---- C:\WINDOWS\system32\safrdm.dll
2012-01-03 09:21:28 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2012-01-03 09:21:28 ----A---- C:\WINDOWS\system32\racpldlg.dll
2012-01-03 09:21:23 ----A---- C:\WINDOWS\system32\fltMc.exe
2012-01-03 09:21:23 ----A---- C:\WINDOWS\system32\fltlib.dll
2012-01-03 09:21:23 ----A---- C:\WINDOWS\system32\drivers\fltMgr.sys
2012-01-03 09:21:22 ----D---- C:\WINDOWS\system32\Restore
2012-01-03 09:21:22 ----A---- C:\WINDOWS\system32\srsvc.dll
2012-01-03 09:21:22 ----A---- C:\WINDOWS\system32\srrstr.dll
2012-01-03 09:21:22 ----A---- C:\WINDOWS\system32\srclient.dll
2012-01-03 09:21:22 ----A---- C:\WINDOWS\system32\drivers\sr.sys
2012-01-03 09:21:21 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2012-01-03 09:21:21 ----A---- C:\WINDOWS\system32\msconf.dll
2012-01-03 09:21:21 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2012-01-03 09:21:21 ----A---- C:\WINDOWS\system32\mnmdd.dll
2012-01-03 09:21:21 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2012-01-03 09:21:21 ----A---- C:\WINDOWS\system32\ils.dll
2012-01-03 09:21:18 ----D---- C:\Program Files\NetMeeting
2012-01-03 09:21:18 ----A---- C:\WINDOWS\system32\msoert2.dll
2012-01-03 09:21:18 ----A---- C:\WINDOWS\system32\msoeacct.dll
2012-01-03 09:21:16 ----A---- C:\WINDOWS\system32\inetres.dll
2012-01-03 09:21:16 ----A---- C:\WINDOWS\system32\inetcomm.dll
2012-01-03 09:21:13 ----D---- C:\Program Files\Outlook Express
2012-01-03 09:21:13 ----A---- C:\WINDOWS\system32\schedsvc.dll
2012-01-03 09:21:13 ----A---- C:\WINDOWS\system32\mstinit.exe
2012-01-03 09:21:13 ----A---- C:\WINDOWS\system32\mstask.dll
2012-01-03 09:21:13 ----A---- C:\WINDOWS\system32\icwphbk.dll
2012-01-03 09:21:13 ----A---- C:\WINDOWS\system32\icwdial.dll
2012-01-03 09:21:12 ----A---- C:\WINDOWS\system32\isign32.dll
2012-01-03 09:21:12 ----A---- C:\WINDOWS\system32\inetcfg.dll
2012-01-03 09:21:06 ----D---- C:\Program Files\Common Files\System
2012-01-03 09:21:00 ----D---- C:\Program Files\Internet Explorer
2012-01-03 09:20:30 ----A---- C:\WINDOWS\system32\emptyregdb.dat
2012-01-03 09:20:12 ----D---- C:\Program Files\ComPlus Applications
2012-01-03 09:20:08 ----A---- C:\WINDOWS\vbaddin.ini
2012-01-03 09:20:08 ----A---- C:\WINDOWS\vb.ini
2012-01-03 09:20:00 ----D---- C:\WINDOWS\Registration
2012-01-03 09:19:49 ----D---- C:\Program Files\Online Services
2012-01-03 09:19:48 ----D---- C:\Program Files\Windows Media Player
2012-01-03 09:19:36 ----D---- C:\Program Files\Messenger
2012-01-03 09:19:32 ----D---- C:\Program Files\MSN Gaming Zone
2012-01-03 09:19:32 ----A---- C:\WINDOWS\system32\write.exe
2012-01-03 09:19:23 ----A---- C:\WINDOWS\system32\sndvol32.exe
2012-01-03 09:19:23 ----A---- C:\WINDOWS\system32\hticons.dll
2012-01-03 09:19:23 ----A---- C:\WINDOWS\system32\avwav.dll
2012-01-03 09:19:23 ----A---- C:\WINDOWS\system32\avtapi.dll
2012-01-03 09:19:23 ----A---- C:\WINDOWS\system32\avmeter.dll
2012-01-03 09:19:22 ----A---- C:\WINDOWS\system32\winchat.exe
2012-01-03 09:19:16 ----A---- C:\WINDOWS\system32\charmap.exe
2012-01-03 09:19:16 ----A---- C:\WINDOWS\system32\getuname.dll
2012-01-03 09:19:15 ----A---- C:\WINDOWS\system32\winmine.exe
2012-01-03 09:19:15 ----A---- C:\WINDOWS\system32\sol.exe
2012-01-03 09:19:15 ----A---- C:\WINDOWS\system32\mshearts.exe
2012-01-03 09:19:15 ----A---- C:\WINDOWS\system32\calc.exe
2012-01-03 09:19:14 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2012-01-03 09:19:14 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2012-01-03 09:19:14 ----A---- C:\WINDOWS\system32\tslabels.ini
2012-01-03 09:19:14 ----A---- C:\WINDOWS\system32\tskill.exe
2012-01-03 09:19:14 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2012-01-03 09:19:14 ----A---- C:\WINDOWS\system32\tscon.exe
2012-01-03 09:19:14 ----A---- C:\WINDOWS\system32\shadow.exe
2012-01-03 09:19:14 ----A---- C:\WINDOWS\system32\rwinsta.exe
2012-01-03 09:19:14 ----A---- C:\WINDOWS\system32\reset.exe
2012-01-03 09:19:14 ----A---- C:\WINDOWS\system32\regini.exe
2012-01-03 09:19:14 ----A---- C:\WINDOWS\system32\freecell.exe
2012-01-03 09:19:13 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2012-01-03 09:19:13 ----A---- C:\WINDOWS\system32\qwinsta.exe
2012-01-03 09:19:13 ----A---- C:\WINDOWS\system32\qappsrv.exe
2012-01-03 09:19:13 ----A---- C:\WINDOWS\system32\msg.exe
2012-01-03 09:19:13 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2012-01-03 09:19:13 ----A---- C:\WINDOWS\system32\logoff.exe
2012-01-03 09:19:13 ----A---- C:\WINDOWS\system32\cdmodem.dll
2012-01-03 09:19:07 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2012-01-03 09:18:49 ----D---- C:\Program Files\MSN
2012-01-03 09:18:48 ----A---- C:\WINDOWS\system32\sndrec32.exe
2012-01-03 09:18:48 ----A---- C:\WINDOWS\system32\mplay32.exe
2012-01-03 09:18:48 ----A---- C:\WINDOWS\system32\accwiz.exe
2012-01-03 09:18:47 ----D---- C:\Program Files\Windows NT
2012-01-03 09:18:47 ----A---- C:\WINDOWS\system32\mspaint.exe
2012-01-03 09:18:47 ----A---- C:\WINDOWS\system32\hypertrm.dll
2012-01-03 09:18:46 ----A---- C:\WINDOWS\system32\spider.exe
2012-01-03 09:18:46 ----A---- C:\WINDOWS\system32\clipbrd.exe
2012-01-03 09:18:45 ----D---- C:\WINDOWS\system32\en-US
2012-01-03 09:18:45 ----A---- C:\WINDOWS\system32\tsgqec.dll
2012-01-03 09:18:45 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2012-01-03 09:18:45 ----A---- C:\WINDOWS\system32\drivers\tdtcp.sys
2012-01-03 09:18:45 ----A---- C:\WINDOWS\system32\drivers\tdpipe.sys
2012-01-03 09:18:45 ----A---- C:\WINDOWS\system32\drivers\rdpwd.sys
2012-01-03 09:18:44 ----A---- C:\WINDOWS\system32\rhttpaa.dll
2012-01-03 09:18:44 ----A---- C:\WINDOWS\system32\aaclient.dll
2012-01-03 09:18:43 ----A---- C:\WINDOWS\system32\remotepg.dll
2012-01-03 09:18:43 ----A---- C:\WINDOWS\system32\rdshost.exe
2012-01-03 09:18:43 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2012-01-03 09:18:43 ----A---- C:\WINDOWS\system32\mstscax.dll
2012-01-03 09:18:43 ----A---- C:\WINDOWS\system32\mstsc.exe
2012-01-03 09:18:42 ----A---- C:\WINDOWS\system32\termsrv.dll
2012-01-03 09:18:42 ----A---- C:\WINDOWS\system32\sessmgr.exe
2012-01-03 09:18:42 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2012-01-03 09:18:42 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2012-01-03 09:18:42 ----A---- C:\WINDOWS\system32\rdpclip.exe
2012-01-03 09:18:42 ----A---- C:\WINDOWS\system32\rdchost.dll
2012-01-03 09:18:42 ----A---- C:\WINDOWS\system32\qprocess.exe
2012-01-03 09:18:42 ----A---- C:\WINDOWS\system32\icaapi.dll
2012-01-03 09:18:41 ----D---- C:\WINDOWS\system32\MsDtc
2012-01-03 09:18:41 ----A---- C:\WINDOWS\system32\mtxoci.dll
2012-01-03 09:18:41 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2012-01-03 09:18:41 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2012-01-03 09:18:41 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2012-01-03 09:18:40 ----A---- C:\WINDOWS\system32\xolehlp.dll
2012-01-03 09:18:40 ----A---- C:\WINDOWS\system32\msdtctm.dll
2012-01-03 09:18:40 ----A---- C:\WINDOWS\system32\msdtclog.dll
2012-01-03 09:18:40 ----A---- C:\WINDOWS\system32\msdtc.exe
2012-01-03 09:18:39 ----D---- C:\WINDOWS\system32\Com
2012-01-03 09:18:39 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2012-01-03 09:18:39 ----A---- C:\WINDOWS\system32\mtxex.dll
2012-01-03 09:18:39 ----A---- C:\WINDOWS\system32\mtxdm.dll
2012-01-03 09:18:39 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2012-01-03 09:18:39 ----A---- C:\WINDOWS\system32\comrepl.dll
2012-01-03 09:18:39 ----A---- C:\WINDOWS\system32\comaddin.dll
2012-01-03 09:18:39 ----A---- C:\WINDOWS\system32\colbact.dll
2012-01-03 09:18:38 ----A---- C:\WINDOWS\system32\stclient.dll
2012-01-03 09:18:38 ----A---- C:\WINDOWS\system32\clbcatex.dll
2012-01-03 09:18:38 ----A---- C:\WINDOWS\system32\catsrvut.dll
2012-01-03 09:18:38 ----A---- C:\WINDOWS\system32\catsrvps.dll
2012-01-03 09:18:38 ----A---- C:\WINDOWS\system32\catsrv.dll
2012-01-03 09:18:37 ----A---- C:\WINDOWS\system32\comuid.dll
2012-01-03 09:18:37 ----A---- C:\WINDOWS\system32\comsvcs.dll
2012-01-03 09:18:37 ----A---- C:\WINDOWS\system32\comsnap.dll
2012-01-03 09:18:36 ----A---- C:\WINDOWS\system32\clbcatq.dll
2012-01-03 09:18:26 ----A---- C:\WINDOWS\system32\servdeps.dll
2012-01-03 09:18:26 ----A---- C:\WINDOWS\system32\mmfutil.dll
2012-01-03 09:18:26 ----A---- C:\WINDOWS\system32\licwmi.dll
2012-01-03 09:18:26 ----A---- C:\WINDOWS\system32\cmprops.dll
2012-01-03 09:18:23 ----A---- C:\WINDOWS\system32\drivers\rdpdr.sys
2012-01-03 09:18:22 ----A---- C:\WINDOWS\system32\drivers\termdd.sys
2012-01-03 01:32:04 ----D---- C:\Program Files\Microsoft.NET
2012-01-03 01:19:24 ----A---- C:\moduleName.txt
2012-01-03 01:12:52 ----A---- C:\WINDOWS\system32\h323log.txt
2012-01-03 01:10:59 ----A---- C:\WINDOWS\system32\drivers\audstub.sys
2012-01-03 01:09:51 ----A---- C:\WINDOWS\system32\drivers\redbook.sys
2012-01-03 01:08:50 ----A---- C:\WINDOWS\system32\drivers\RTL8139.sys
2012-01-03 01:08:35 ----A---- C:\WINDOWS\system32\usbui.dll
2012-01-03 01:07:59 ----A---- C:\WINDOWS\system32\drivers\compbatt.sys
2012-01-03 01:07:58 ----A---- C:\WINDOWS\system32\drivers\CmBatt.sys
2012-01-03 01:07:58 ----A---- C:\WINDOWS\system32\drivers\battc.sys
2012-01-03 01:06:36 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2012-01-03 01:06:35 ----SHD---- C:\WINDOWS\Installer
2012-01-03 01:06:34 ----D---- C:\Program Files\Common Files\ODBC
2012-01-03 01:06:34 ----A---- C:\WINDOWS\ODBCINST.INI
2012-01-03 01:06:30 ----D---- C:\Program Files\Common Files\SpeechEngines
2012-01-03 01:06:29 ----RD---- C:\Program Files
2012-01-03 01:06:29 ----D---- C:\Program Files\Common Files\Microsoft Shared
2012-01-03 01:06:29 ----D---- C:\Program Files\Common Files
2012-01-03 01:06:26 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2012-01-03 01:06:26 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2012-01-03 01:06:26 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2012-01-03 01:06:24 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2012-01-03 01:06:24 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2012-01-03 01:06:24 ----RA---- C:\WINDOWS\system32\kbdur.dll
2012-01-03 01:06:24 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2012-01-03 01:06:24 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2012-01-03 01:06:24 ----RA---- C:\WINDOWS\system32\kbdru.dll
2012-01-03 01:06:24 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2012-01-03 01:06:24 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2012-01-03 01:06:24 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2012-01-03 01:06:24 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2012-01-03 01:06:24 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2012-01-03 01:06:24 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2012-01-03 01:06:22 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2012-01-03 01:06:22 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2012-01-03 01:06:22 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2012-01-03 01:06:22 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2012-01-03 01:06:22 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2012-01-03 01:06:22 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2012-01-03 01:06:22 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2012-01-03 01:06:21 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2012-01-03 01:06:21 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2012-01-03 01:06:21 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2012-01-03 01:06:21 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2012-01-03 01:06:20 ----RA---- C:\WINDOWS\system32\kbdest.dll
2012-01-03 01:06:19 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2012-01-03 01:06:19 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2012-01-03 01:06:19 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2012-01-03 01:06:19 ----RA---- C:\WINDOWS\system32\kbdro.dll
2012-01-03 01:06:19 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2012-01-03 01:06:19 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2012-01-03 01:06:19 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2012-01-03 01:06:19 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2012-01-03 01:06:19 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
2012-01-03 01:06:19 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
2012-01-03 01:06:19 ----RA---- C:\WINDOWS\system32\kbdcz.dll
2012-01-03 01:06:19 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2012-01-03 01:06:19 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2012-01-03 01:06:13 ----A---- C:\WINDOWS\system32\spxcoins.dll
2012-01-03 01:06:13 ----A---- C:\WINDOWS\system32\irclass.dll
2012-01-03 01:06:13 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2012-01-03 01:06:13 ----A---- C:\WINDOWS\system32\dgsetup.dll
2012-01-03 01:06:13 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2012-01-03 01:06:11 ----A---- C:\WINDOWS\TASKMAN.EXE
2012-01-03 01:06:10 ----A---- C:\WINDOWS\system32\drivers\irenum.sys
2012-01-03 01:06:10 ----A---- C:\WINDOWS\system32\batt.dll
2012-01-03 01:06:09 ----A---- C:\WINDOWS\NOTEPAD.EXE
2012-01-03 01:06:06 ----A---- C:\WINDOWS\system32\storprop.dll
2012-01-03 01:05:55 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
2012-01-03 01:05:36 ----D---- C:\WINDOWS\system32\CatRoot2
2012-01-03 01:05:36 ----D---- C:\WINDOWS\system32\CatRoot
2012-01-03 01:05:30 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2012-01-03 01:04:58 ----SHD---- C:\System Volume Information
2012-01-03 01:04:58 ----D---- C:\Documents and Settings
2012-01-03 01:04:57 ----A---- C:\WINDOWS\system32\FNTCACHE.DAT
2012-01-03 01:03:57 ----RASH---- C:\boot.ini
2012-01-03 01:03:33 ----D---- C:\Documents and Settings\Michal\Application Data\Adobe
2012-01-03 00:59:11 ----D---- C:\Program Files\CCleaner
2012-01-03 00:58:29 ----RSHDC---- C:\WINDOWS\system32\dllcache
2012-01-03 00:58:29 ----RSD---- C:\WINDOWS\Fonts
2012-01-03 00:58:29 ----RD---- C:\WINDOWS\Web
2012-01-03 00:58:29 ----HD---- C:\WINDOWS\inf
2012-01-03 00:58:29 ----D---- C:\WINDOWS\WinSxS
2012-01-03 00:58:29 ----D---- C:\WINDOWS\twain_32
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\wins
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\wbem
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\usmt
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\spool
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\ShellExt
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\Setup
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\scripting
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\ras
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\oobe
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\npp
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\mui
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\inetsrv
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\IME
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\icsxml
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\ias
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\export
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\en
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\drivers\etc
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\drivers\disdn
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\drivers
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\dhcp
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\config
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\3com_dmi
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\3076
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\2052
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\1054
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\1042
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\1041
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\1037
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\1033
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\1031
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\1028
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\1025
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system
2012-01-03 00:58:29 ----D---- C:\WINDOWS\security
2012-01-03 00:58:29 ----D---- C:\WINDOWS\Resources
2012-01-03 00:58:29 ----D---- C:\WINDOWS\repair
2012-01-03 00:58:29 ----D---- C:\WINDOWS\Provisioning
2012-01-03 00:58:29 ----D---- C:\WINDOWS\pchealth
2012-01-03 00:58:29 ----D---- C:\WINDOWS\PeerNet
2012-01-03 00:58:29 ----D---- C:\WINDOWS\NLDRV
2012-01-03 00:58:29 ----D---- C:\WINDOWS\Network Diagnostic
2012-01-03 00:58:29 ----D---- C:\WINDOWS\mui
2012-01-03 00:58:29 ----D---- C:\WINDOWS\msapps
2012-01-03 00:58:29 ----D---- C:\WINDOWS\msagent
2012-01-03 00:58:29 ----D---- C:\WINDOWS\Media
2012-01-03 00:58:29 ----D---- C:\WINDOWS\L2Schemas
2012-01-03 00:58:29 ----D---- C:\WINDOWS\java
2012-01-03 00:58:29 ----D---- C:\WINDOWS\ime
2012-01-03 00:58:29 ----D---- C:\WINDOWS\Help
2012-01-03 00:58:29 ----D---- C:\WINDOWS\ehome
2012-01-03 00:58:29 ----D---- C:\WINDOWS\Driver Cache
2012-01-03 00:58:29 ----D---- C:\WINDOWS\Debug
2012-01-03 00:58:29 ----D---- C:\WINDOWS\Cursors
2012-01-03 00:58:29 ----D---- C:\WINDOWS\Connection Wizard
2012-01-03 00:58:29 ----D---- C:\WINDOWS\Config
2012-01-03 00:58:29 ----D---- C:\WINDOWS\AppPatch
2012-01-03 00:58:29 ----D---- C:\WINDOWS\addins
2012-01-03 00:58:29 ----D---- C:\WINDOWS
2012-01-03 00:58:28 ----ASH---- C:\pagefile.sys
2012-01-03 00:49:23 ----RSD---- C:\WINDOWS\assembly
2012-01-03 00:48:59 ----D---- C:\WINDOWS\Microsoft.NET
2012-01-03 00:48:05 ----D---- C:\Program Files\ATI Technologies
2012-01-03 00:45:57 ----A---- C:\WINDOWS\system32\snymsico.dll
2012-01-03 00:45:57 ----A---- C:\WINDOWS\system32\drivers\risdptsk.sys
2012-01-03 00:45:57 ----A---- C:\WINDOWS\system32\drivers\rimsptsk.sys
2012-01-03 00:45:20 ----D---- C:\WINDOWS\system32\ReinstallBackups
2012-01-03 00:45:14 ----A---- C:\WINDOWS\system32\drivers\Rtnicxp.sys
2012-01-03 00:45:13 ----D---- C:\WINDOWS\OPTIONS
2012-01-03 00:44:31 ----A---- C:\WINDOWS\system32\drivers\splitter.sys
2012-01-03 00:44:28 ----A---- C:\WINDOWS\system32\drivers\wdmaud.sys
2012-01-03 00:44:25 ----A---- C:\WINDOWS\system32\drivers\DMusic.sys
2012-01-03 00:44:24 ----A---- C:\WINDOWS\system32\ChCfg.exe
2012-01-03 00:44:21 ----A---- C:\WINDOWS\system32\drivers\swmidi.sys
2012-01-03 00:44:19 ----A---- C:\WINDOWS\system32\drivers\aec.sys
2012-01-03 00:44:17 ----A---- C:\WINDOWS\system32\drivers\kmixer.sys
2012-01-03 00:44:15 ----A---- C:\WINDOWS\system32\drivers\drmkaud.sys
2012-01-03 00:44:13 ----A---- C:\WINDOWS\system32\drivers\sysaudio.sys
2012-01-03 00:44:11 ----A---- C:\WINDOWS\system32\drivers\MSKSSRV.sys
2012-01-03 00:44:09 ----A---- C:\WINDOWS\system32\drivers\MSPQM.sys
2012-01-03 00:44:05 ----A---- C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2012-01-03 00:43:59 ----D---- C:\WINDOWS\system32\RTCOM
2012-01-03 00:43:56 ----A---- C:\WINDOWS\system32\ksuser.dll
2012-01-03 00:43:56 ----A---- C:\WINDOWS\system32\drivers\portcls.sys
2012-01-03 00:43:56 ----A---- C:\WINDOWS\system32\drivers\drmk.sys
2012-01-03 00:43:52 ----A---- C:\WINDOWS\SoundMan.exe
2012-01-03 00:43:52 ----A---- C:\WINDOWS\SkyTel.exe
2012-01-03 00:43:52 ----A---- C:\WINDOWS\RtlUpd.exe
2012-01-03 00:43:51 ----A---- C:\WINDOWS\RTLCPL.exe
2012-01-03 00:43:50 ----A---- C:\WINDOWS\system32\drivers\RtkHDAud.Sys
2012-01-03 00:43:49 ----D---- C:\Program Files\Realtek
2012-01-03 00:43:49 ----A---- C:\WINDOWS\RTHDCPL.exe
2012-01-03 00:43:49 ----A---- C:\WINDOWS\MicCal.exe
2012-01-03 00:43:49 ----A---- C:\WINDOWS\alcwzrd.exe
2012-01-03 00:43:49 ----A---- C:\WINDOWS\Alcmtr.exe
2012-01-03 00:43:45 ----A---- C:\WINDOWS\RtlExUpd.dll

======List of files/folders modified in the last 1 month======

2012-01-09 22:58:57 ----A---- C:\WINDOWS\win.ini
2012-01-03 09:23:55 ----ASH---- C:\WINDOWS\fonts\desktop.ini
2012-01-03 01:12:18 ----A---- C:\WINDOWS\system.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 risdptsk;risdptsk; C:\WINDOWS\system32\DRIVERS\risdptsk.sys [2005-07-14 27904]
R1 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2010-12-16 31088]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-08-18 12032]
R3 AR5211;Atheros Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\ar5211.sys [2007-05-02 546976]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2007-07-04 2304000]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-11-03 4394496]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-18 12160]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ATKACPI.sys [2007-08-24 5760]
R3 rimsptsk;rimsptsk; C:\WINDOWS\system32\DRIVERS\rimsptsk.sys [2005-07-12 51328]
R3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2006-12-14 85120]
R3 WSIMD;wsimd Service; C:\WINDOWS\system32\DRIVERS\wsimd.sys [2007-03-28 57024]
S3 GGSAFERDriver;GGSAFER Driver; \??\C:\Program Files\Garena Plus\Room\safedrv.sys []
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2008-04-13 20992]
S3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2008-04-13 79232]
S3 TrueSight;TrueSight; \??\c:\windows\system32\drivers\TrueSight.sys []
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ACS;Atheros Configuration Service; C:\WINDOWS\system32\acs.exe [2007-05-03 364629]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2007-07-04 483328]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 KMService;KMService; C:\WINDOWS\system32\srvany.exe [2003-04-18 8192]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2012-01-09 654848]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2010-01-21 30963576]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: haveď v notebooku

#71 Příspěvek od vyosek »

Nainstalujte Avast Free, pac bez zabezpeni je to na kkta...Jinak log uz vypada cisty, pokud nejsou problemy, tak budem uklizet
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Crosby.WX
Návštěvník
Návštěvník
Příspěvky: 71
Registrován: 01 lis 2008 15:41

Re: haveď v notebooku

#72 Příspěvek od Crosby.WX »

Už sa sťahuje :) tak zatiaľ to vyzera byť oukej, môžme upratať

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: haveď v notebooku

#73 Příspěvek od vyosek »

:arrow: Odinstalujte Combofix
  • Prejmenujte ComboFix na Uninstall
  • Spustte jej
  • Tohle smaze Combofix a jeho slozky
:arrow: T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner (viz muj podpis)
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: Doporucuji provest defragmentaci disku
  • Nejjednodussi (ale nejmene ucinny) zpusob je pomoci utility ve windowsech
    • Kliknete na Tento pocitac, dale na disk kliknete pravym tlacitkem, vyberte Vlastnosti
    • prepnete se do zalozky Nastroje
    • Nyni vidite pomucky Defragmentace - spustte ji kliknutim na Defragmentovat
    • Toto provedte se vsemi disky
  • Dalsi moznosti (a mnou doporucenou) je pres programek Defraggler http://www.stahuj.centrum.cz/utility_a_ ... efraggler/
    • Program stahnete, nainstalujte (dejte fajfku pryc u yahoo toolbaru) a spustte
    • Kliknete na Analyzovat
    • Pokud je ve sloupci Fragmentováno vice jak 5%, doporucuji provest defragmentaci (klik na Defragmentovat)
    • Postup provedte se vsemi disky
  • Posledni moznost je pres jednoduchy programek JKDefrag http://www.stahuj.centrum.cz/utility_a_ ... /jkdefrag/
    • Vyhodou programku je, ze se neinstaluje
    • Staci tedy jen stahnout dle verze vaseho OS a rozbalit
    • Nasledne spustit pomoci souboru JKDefrag pripadne JKDefrag64
    • Probehne analyza disku a nasledne i defragmentace
:arrow: Nainstalujte Avast pokud nemate

:arrow: Dejte (snad uz posledni :D ) novy log z RSIT
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Crosby.WX
Návštěvník
Návštěvník
Příspěvky: 71
Registrován: 01 lis 2008 15:41

Re: haveď v notebooku

#74 Příspěvek od Crosby.WX »

Logfile of random's system information tool 1.09 (written by random/random)
Run by Michal at 2012-01-22 21:19:03
Microsoft Windows XP Professional Service Pack 3
System drive C: has 50 GB (66%) free of 76 GB
Total RAM: 447 MB (17% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:19:11, on 22. 1. 2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Wireless Console 2\wcourier.exe
C:\Program Files\Atheros\ACU.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Michal\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Michal\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Michal\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Michal\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Michal\My Documents\Downloads\RSIT.exe
C:\Program Files\trend micro\Michal.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [Wireless Console 2] "C:\Program Files\Wireless Console 2\wcourier.exe"
O4 - HKLM\..\Run: [ACU] "C:\Program Files\Atheros\ACU.exe" -nogui
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&oslať do programu OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Atheros Configuration Service (ACS) - Atheros - C:\WINDOWS\system32\acs.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: KMService - Unknown owner - C:\WINDOWS\system32\srvany.exe

--
End of file - 4824 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-01-21 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-01-16 561552]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Wireless Console 2"=C:\Program Files\Wireless Console 2\wcourier.exe [2007-07-05 1040384]
"ACU"=C:\Program Files\Atheros\ACU.exe [2007-05-03 376921]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-11-28 3744552]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ACMON]
C:\Program Files\ASUS\Splendid\ACMON.exe [2007-07-10 851968]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
C:\WINDOWS\ALCWZRD.EXE [2006-05-04 2808832]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Camera ScreenSaver]
C:\WINDOWS\ASScrProlog.exe [2012-01-03 37232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Live Update]
C:\Program Files\ASUS\ASUS Live Update\ALU.exe [2007-11-30 51768]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIModeChange]
C:\WINDOWS\system32\Ati2mdxx.exe [2007-07-04 26112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATKHOTKEY]
C:\Program Files\ATK Hotkey\Hcontrol.exe [2007-08-23 229376]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
C:\WINDOWS\RTHDCPL.EXE [2006-10-30 16269312]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
C:\WINDOWS\SkyTel.EXE [2006-05-16 2879488]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
C:\WINDOWS\SOUNDMAN.EXE [2006-07-21 86016]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2006-11-10 90112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2007-07-04 118784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-01-21 4222864]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Garena Plus\Room\garena_room.exe"="C:\Program Files\Garena Plus\Room\garena_room.exe:*:Enabled:Garena"
"C:\Program Files\Microsoft Office\Office14\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office14\GROOVE.EXE:*:Enabled:Microsoft SharePoint Workspace"
"C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE:*:Enabled:Microsoft OneNote"
"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======List of files/folders created in the last 1 month======

2012-01-22 21:19:03 ----D---- C:\rsit
2012-01-22 20:39:45 ----A---- C:\WINDOWS\system32\drivers\aswSP.sys
2012-01-22 20:39:45 ----A---- C:\WINDOWS\system32\drivers\aswFsBlk.sys
2012-01-22 20:39:41 ----A---- C:\WINDOWS\system32\drivers\aswTdi.sys
2012-01-22 20:39:41 ----A---- C:\WINDOWS\system32\drivers\aswRdr.sys
2012-01-22 20:39:40 ----A---- C:\WINDOWS\system32\drivers\aswSnx.sys
2012-01-22 20:39:38 ----A---- C:\WINDOWS\system32\drivers\aswmon2.sys
2012-01-22 20:39:38 ----A---- C:\WINDOWS\system32\drivers\aswmon.sys
2012-01-22 20:39:37 ----A---- C:\WINDOWS\system32\drivers\aavmker4.sys
2012-01-22 20:39:18 ----SHD---- C:\Config.Msi
2012-01-22 20:38:57 ----A---- C:\WINDOWS\avastSS.scr
2012-01-22 20:38:56 ----A---- C:\WINDOWS\system32\aswBoot.exe
2012-01-22 20:38:33 ----D---- C:\Documents and Settings\All Users\Application Data\AVAST Software
2012-01-22 20:38:32 ----D---- C:\Program Files\AVAST Software
2012-01-21 20:29:40 ----D---- C:\Documents and Settings\Michal\Application Data\XnView
2012-01-21 20:25:52 ----D---- C:\Program Files\XnView
2012-01-12 15:33:20 ----D---- C:\WINDOWS\Temp
2012-01-12 14:21:29 ----SHD---- C:\WINDOWS\CSC
2012-01-11 22:46:18 ----A---- C:\Boot.bak
2012-01-11 22:46:13 ----RASHD---- C:\cmdcons
2012-01-11 17:49:29 ----A---- C:\WINDOWS\system32\drivers\TrueSight.sys
2012-01-09 23:43:32 ----D---- C:\Documents and Settings\All Users\Application Data\FLEXnet
2012-01-09 23:40:10 ----A---- C:\WINDOWS\system32\BASSMOD.dll
2012-01-09 23:37:46 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2012-01-09 23:36:56 ----D---- C:\Program Files\Bonjour
2012-01-09 23:28:52 ----D---- C:\Program Files\Adobe
2012-01-09 23:28:14 ----D---- C:\Program Files\Common Files\Macrovision Shared
2012-01-09 23:27:09 ----D---- C:\Program Files\Common Files\Adobe
2012-01-09 23:05:41 ----A---- C:\WINDOWS\system32\srvany.exe
2012-01-09 23:02:21 ----D---- C:\Program Files\Common Files\DESIGNER
2012-01-09 23:02:13 ----D---- C:\Program Files\MSBuild
2012-01-09 23:00:56 ----D---- C:\Program Files\Microsoft Sync Framework
2012-01-09 22:59:56 ----D---- C:\Program Files\Microsoft Visual Studio 8
2012-01-09 22:58:08 ----D---- C:\Program Files\Microsoft Analysis Services
2012-01-09 22:57:51 ----D---- C:\WINDOWS\SHELLNEW
2012-01-09 22:57:00 ----D---- C:\Program Files\Microsoft Office
2012-01-09 22:56:58 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2012-01-09 22:56:41 ----RHD---- C:\MSOCache
2012-01-09 12:10:43 ----D---- C:\Documents and Settings\Michal\Application Data\AVG
2012-01-09 12:09:17 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2012-01-09 12:09:07 ----D---- C:\Program Files\AVG
2012-01-09 11:53:19 ----D---- C:\Program Files\trend micro
2012-01-09 11:29:11 ----D---- C:\Documents and Settings\Michal\Application Data\Malwarebytes
2012-01-09 11:28:32 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2012-01-09 11:28:31 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2012-01-09 11:28:31 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2012-01-06 15:28:38 ----A---- C:\WINDOWS\WORDPAD.INI
2012-01-06 01:13:18 ----D---- C:\Program Files\Elaborate Bytes
2012-01-06 01:08:04 ----D---- C:\Documents and Settings\All Users\Application Data\DVD Shrink
2012-01-06 01:08:03 ----D---- C:\Program Files\DVD Shrink
2012-01-06 00:47:38 ----D---- C:\Documents and Settings\Michal\Application Data\WinRAR
2012-01-06 00:46:52 ----D---- C:\Program Files\WinRAR
2012-01-04 14:11:54 ----D---- C:\Documents and Settings\Michal\Application Data\vlc
2012-01-03 22:50:54 ----A---- C:\Documents and Settings\Michal\Application Data\room_v3.dat
2012-01-03 22:18:56 ----D---- C:\Documents and Settings\Michal\Application Data\GarenaPlus
2012-01-03 22:17:58 ----D---- C:\Program Files\Garena Plus
2012-01-03 22:17:56 ----D---- C:\Documents and Settings\All Users\Application Data\GarenaMessenger
2012-01-03 22:05:35 ----D---- C:\Documents and Settings\Michal\Application Data\TS3Client
2012-01-03 22:00:43 ----D---- C:\Program Files\TeamSpeak 3 Client
2012-01-03 21:58:29 ----A---- C:\WINDOWS\system32\XAudio2_5.dll
2012-01-03 21:58:28 ----A---- C:\WINDOWS\system32\xactengine3_5.dll
2012-01-03 21:58:27 ----A---- C:\WINDOWS\system32\D3DCompiler_42.dll
2012-01-03 21:58:24 ----A---- C:\WINDOWS\system32\d3dcsx_42.dll
2012-01-03 21:58:23 ----A---- C:\WINDOWS\system32\d3dx11_42.dll
2012-01-03 21:58:22 ----A---- C:\WINDOWS\system32\D3DX9_42.dll
2012-01-03 21:58:22 ----A---- C:\WINDOWS\system32\d3dx10_42.dll
2012-01-03 21:58:21 ----A---- C:\WINDOWS\system32\d3dx10_41.dll
2012-01-03 21:58:21 ----A---- C:\WINDOWS\system32\D3DCompiler_41.dll
2012-01-03 21:58:20 ----A---- C:\WINDOWS\system32\D3DX9_41.dll
2012-01-03 21:58:19 ----A---- C:\WINDOWS\system32\XAudio2_4.dll
2012-01-03 21:58:19 ----A---- C:\WINDOWS\system32\XAPOFX1_3.dll
2012-01-03 21:58:18 ----A---- C:\WINDOWS\system32\xactengine3_4.dll
2012-01-03 21:58:18 ----A---- C:\WINDOWS\system32\X3DAudio1_6.dll
2012-01-03 21:58:17 ----A---- C:\WINDOWS\system32\d3dx10_40.dll
2012-01-03 21:58:17 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll
2012-01-03 21:58:15 ----A---- C:\WINDOWS\system32\D3DX9_40.dll
2012-01-03 21:58:14 ----A---- C:\WINDOWS\system32\XAudio2_3.dll
2012-01-03 21:58:14 ----A---- C:\WINDOWS\system32\XAPOFX1_2.dll
2012-01-03 21:58:14 ----A---- C:\WINDOWS\system32\xactengine3_3.dll
2012-01-03 21:58:14 ----A---- C:\WINDOWS\system32\X3DAudio1_5.dll
2012-01-03 21:58:13 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2012-01-03 21:58:13 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2012-01-03 21:58:13 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
2012-01-03 21:58:12 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2012-01-03 21:58:12 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2012-01-03 21:58:11 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2012-01-03 21:58:10 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
2012-01-03 21:58:10 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
2012-01-03 21:58:09 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
2012-01-03 21:58:09 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
2012-01-03 21:58:08 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
2012-01-03 21:58:08 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
2012-01-03 21:58:07 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
2012-01-03 21:58:06 ----A---- C:\WINDOWS\system32\XAudio2_0.dll
2012-01-03 21:58:06 ----A---- C:\WINDOWS\system32\xactengine3_0.dll
2012-01-03 21:58:05 ----A---- C:\WINDOWS\system32\X3DAudio1_3.dll
2012-01-03 21:58:05 ----A---- C:\WINDOWS\system32\d3dx10_37.dll
2012-01-03 21:58:05 ----A---- C:\WINDOWS\system32\D3DCompiler_37.dll
2012-01-03 21:58:04 ----A---- C:\WINDOWS\system32\D3DX9_37.dll
2012-01-03 21:58:03 ----A---- C:\WINDOWS\system32\xactengine2_10.dll
2012-01-03 21:58:02 ----A---- C:\WINDOWS\system32\d3dx10_36.dll
2012-01-03 21:58:02 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll
2012-01-03 21:58:00 ----A---- C:\WINDOWS\system32\d3dx9_36.dll
2012-01-03 21:57:59 ----A---- C:\WINDOWS\system32\xactengine2_9.dll
2012-01-03 21:57:58 ----A---- C:\WINDOWS\system32\d3dx10_35.dll
2012-01-03 21:57:58 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll
2012-01-03 21:57:57 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
2012-01-03 21:57:56 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
2012-01-03 21:57:56 ----A---- C:\WINDOWS\system32\X3DAudio1_2.dll
2012-01-03 21:57:55 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2012-01-03 21:57:55 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2012-01-03 21:57:54 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2012-01-03 21:57:53 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2012-01-03 21:57:51 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
2012-01-03 21:57:50 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2012-01-03 21:57:50 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2012-01-03 21:57:48 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2012-01-03 21:57:48 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2012-01-03 21:57:47 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
2012-01-03 21:57:46 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
2012-01-03 21:57:45 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2012-01-03 21:57:45 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2012-01-03 21:57:45 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2012-01-03 21:57:44 ----A---- C:\WINDOWS\system32\xinput1_2.dll
2012-01-03 21:57:44 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
2012-01-03 21:57:43 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2012-01-03 21:57:43 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2012-01-03 21:57:42 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2012-01-03 21:57:30 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2012-01-03 21:57:29 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2012-01-03 21:57:29 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2012-01-03 21:57:28 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2012-01-03 21:57:25 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2012-01-03 21:57:24 ----A---- C:\WINDOWS\system32\xinput9_1_0.dll
2012-01-03 21:57:23 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2012-01-03 21:57:22 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2012-01-03 21:57:21 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2012-01-03 21:57:18 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2012-01-03 21:56:53 ----D---- C:\WINDOWS\Logs
2012-01-03 18:26:43 ----A---- C:\WINDOWS\War3Unin.dat
2012-01-03 18:26:42 ----A---- C:\WINDOWS\War3Unin.pif
2012-01-03 18:26:42 ----A---- C:\WINDOWS\War3Unin.exe
2012-01-03 18:25:27 ----D---- C:\Program Files\Warcraft III
2012-01-03 17:55:27 ----D---- C:\Program Files\VideoLAN
2012-01-03 09:43:51 ----A---- C:\WINDOWS\system32\acs.exe
2012-01-03 09:43:39 ----A---- C:\WINDOWS\system32\wsimd.sys
2012-01-03 09:43:39 ----A---- C:\WINDOWS\system32\wsimd.dll
2012-01-03 09:43:39 ----A---- C:\WINDOWS\system32\wsfwDS.dll
2012-01-03 09:43:39 ----A---- C:\WINDOWS\system32\wgapi.dll
2012-01-03 09:43:39 ----A---- C:\WINDOWS\system32\wcapiU.dll
2012-01-03 09:43:39 ----A---- C:\WINDOWS\system32\wcapi.dll
2012-01-03 09:43:39 ----A---- C:\WINDOWS\system32\dsaNac.dll
2012-01-03 09:43:39 ----A---- C:\WINDOWS\system32\dsa.dll
2012-01-03 09:43:39 ----A---- C:\WINDOWS\system32\drivers\wsimd.sys
2012-01-03 09:43:39 ----A---- C:\WINDOWS\system32\athcfg20U.dll
2012-01-03 09:43:39 ----A---- C:\WINDOWS\system32\athcfg20resU.dll
2012-01-03 09:43:39 ----A---- C:\WINDOWS\system32\athcfg20res.dll
2012-01-03 09:43:39 ----A---- C:\WINDOWS\system32\athcfg20.dll
2012-01-03 09:43:37 ----D---- C:\Program Files\Atheros
2012-01-03 09:43:28 ----A---- C:\WINDOWS\system32\drivers\ar5211.sys
2012-01-03 09:43:28 ----A---- C:\WINDOWS\system32\ar5211.sys
2012-01-03 09:43:07 ----D---- C:\Documents and Settings\All Users\Application Data\Atheros
2012-01-03 09:42:39 ----D---- C:\Program Files\Wireless Console 2
2012-01-03 09:42:08 ----A---- C:\WINDOWS\ASUS Camera ScreenSaver.exe
2012-01-03 09:42:08 ----A---- C:\WINDOWS\ASUS Camera ScreenSaver Uninstaller.exe
2012-01-03 09:42:08 ----A---- C:\WINDOWS\ASScrProlog.exe
2012-01-03 09:42:07 ----A---- C:\WINDOWS\Asus_Camera_ScreenSaver.scr
2012-01-03 09:42:06 ----D---- C:\WINDOWS\Asus_Camera_ScreenSaver dir
2012-01-03 09:42:06 ----D---- C:\Documents and Settings\Michal\Application Data\Macromedia
2012-01-03 09:42:06 ----A---- C:\WINDOWS\impborl.dll
2012-01-03 09:42:06 ----A---- C:\WINDOWS\flashax.exe
2012-01-03 09:41:45 ----A---- C:\WINDOWS\system32\ACEngSvr.exe
2012-01-03 09:40:51 ----SHD---- C:\RECYCLER
2012-01-03 09:40:12 ----D---- C:\Program Files\ASUS
2012-01-03 09:40:06 ----D---- C:\Program Files\Common Files\InstallShield
2012-01-03 09:39:11 ----D---- C:\Program Files\ATK Hotkey
2012-01-03 09:39:10 ----HD---- C:\Program Files\InstallShield Installation Information
2012-01-03 09:39:04 ----D---- C:\Documents and Settings\Michal\Application Data\InstallShield
2012-01-03 09:36:58 ----A---- C:\WINDOWS\system32\drivers\USBSTOR.SYS
2012-01-03 09:33:55 ----D---- C:\Documents and Settings\Michal\Application Data\Identities
2012-01-03 09:33:54 ----HD---- C:\Program Files\Uninstall Information
2012-01-03 09:32:12 ----ASH---- C:\Documents and Settings\Michal\Application Data\desktop.ini
2012-01-03 09:32:11 ----SD---- C:\Documents and Settings\Michal\Application Data\Microsoft
2012-01-03 09:29:09 ----D---- C:\WINDOWS\SoftwareDistribution
2012-01-03 09:29:08 ----D---- C:\WINDOWS\Prefetch
2012-01-03 09:29:07 ----SD---- C:\WINDOWS\system32\Microsoft
2012-01-03 09:29:07 ----N---- C:\WINDOWS\SchedLgU.Txt
2012-01-03 09:27:30 ----AS---- C:\WINDOWS\bootstat.dat
2012-01-03 09:25:00 ----D---- C:\WINDOWS\system32\xircom
2012-01-03 09:25:00 ----D---- C:\Program Files\xerox
2012-01-03 09:25:00 ----D---- C:\Program Files\microsoft frontpage
2012-01-03 09:24:35 ----RASH---- C:\MSDOS.SYS
2012-01-03 09:24:35 ----RASH---- C:\IO.SYS
2012-01-03 09:24:35 ----A---- C:\WINDOWS\control.ini
2012-01-03 09:24:35 ----A---- C:\CONFIG.SYS
2012-01-03 09:24:13 ----A---- C:\WINDOWS\system32\mapi32.dll
2012-01-03 09:23:06 ----SD---- C:\WINDOWS\Downloaded Program Files
2012-01-03 09:23:06 ----RD---- C:\WINDOWS\Offline Web Pages
2012-01-03 09:22:54 ----HD---- C:\Program Files\WindowsUpdate
2012-01-03 09:22:25 ----D---- C:\WINDOWS\system32\DirectX
2012-01-03 09:22:19 ----A---- C:\WINDOWS\system32\atrace.dll
2012-01-03 09:22:15 ----A---- C:\WINDOWS\system32\desktop.ini
2012-01-03 09:22:15 ----A---- C:\WINDOWS\desktop.ini
2012-01-03 09:22:08 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2012-01-03 09:22:07 ----A---- C:\WINDOWS\system32\acctres.dll
2012-01-03 09:22:06 ----D---- C:\Program Files\Common Files\Services
2012-01-03 09:22:04 ----SD---- C:\WINDOWS\Tasks
2012-01-03 09:22:04 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2012-01-03 09:22:03 ----D---- C:\Program Files\Common Files\MSSoap
2012-01-03 09:21:58 ----D---- C:\WINDOWS\srchasst
2012-01-03 09:21:57 ----D---- C:\WINDOWS\system32\Macromed
2012-01-03 09:21:54 ----A---- C:\WINDOWS\system32\wuweb.dll
2012-01-03 09:21:54 ----A---- C:\WINDOWS\system32\wucltui.dll
2012-01-03 09:21:54 ----A---- C:\WINDOWS\system32\wuauserv.dll
2012-01-03 09:21:53 ----A---- C:\WINDOWS\system32\wups.dll
2012-01-03 09:21:53 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2012-01-03 09:21:53 ----A---- C:\WINDOWS\system32\wuaueng.dll
2012-01-03 09:21:53 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2012-01-03 09:21:53 ----A---- C:\WINDOWS\system32\wuauclt.exe
2012-01-03 09:21:52 ----A---- C:\WINDOWS\system32\wuapi.dll
2012-01-03 09:21:52 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2012-01-03 09:21:52 ----A---- C:\WINDOWS\system32\qmgr.dll
2012-01-03 09:21:52 ----A---- C:\WINDOWS\system32\bitsprx4.dll
2012-01-03 09:21:52 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2012-01-03 09:21:52 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2012-01-03 09:21:46 ----D---- C:\Program Files\Movie Maker
2012-01-03 09:21:28 ----A---- C:\WINDOWS\system32\safrslv.dll
2012-01-03 09:21:28 ----A---- C:\WINDOWS\system32\safrdm.dll
2012-01-03 09:21:28 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2012-01-03 09:21:28 ----A---- C:\WINDOWS\system32\racpldlg.dll
2012-01-03 09:21:23 ----A---- C:\WINDOWS\system32\fltMc.exe
2012-01-03 09:21:23 ----A---- C:\WINDOWS\system32\fltlib.dll
2012-01-03 09:21:23 ----A---- C:\WINDOWS\system32\drivers\fltMgr.sys
2012-01-03 09:21:22 ----D---- C:\WINDOWS\system32\Restore
2012-01-03 09:21:22 ----A---- C:\WINDOWS\system32\srsvc.dll
2012-01-03 09:21:22 ----A---- C:\WINDOWS\system32\srrstr.dll
2012-01-03 09:21:22 ----A---- C:\WINDOWS\system32\srclient.dll
2012-01-03 09:21:22 ----A---- C:\WINDOWS\system32\drivers\sr.sys
2012-01-03 09:21:21 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2012-01-03 09:21:21 ----A---- C:\WINDOWS\system32\msconf.dll
2012-01-03 09:21:21 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2012-01-03 09:21:21 ----A---- C:\WINDOWS\system32\mnmdd.dll
2012-01-03 09:21:21 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2012-01-03 09:21:21 ----A---- C:\WINDOWS\system32\ils.dll
2012-01-03 09:21:18 ----D---- C:\Program Files\NetMeeting
2012-01-03 09:21:18 ----A---- C:\WINDOWS\system32\msoert2.dll
2012-01-03 09:21:18 ----A---- C:\WINDOWS\system32\msoeacct.dll
2012-01-03 09:21:16 ----A---- C:\WINDOWS\system32\inetres.dll
2012-01-03 09:21:16 ----A---- C:\WINDOWS\system32\inetcomm.dll
2012-01-03 09:21:13 ----D---- C:\Program Files\Outlook Express
2012-01-03 09:21:13 ----A---- C:\WINDOWS\system32\schedsvc.dll
2012-01-03 09:21:13 ----A---- C:\WINDOWS\system32\mstinit.exe
2012-01-03 09:21:13 ----A---- C:\WINDOWS\system32\mstask.dll
2012-01-03 09:21:13 ----A---- C:\WINDOWS\system32\icwphbk.dll
2012-01-03 09:21:13 ----A---- C:\WINDOWS\system32\icwdial.dll
2012-01-03 09:21:12 ----A---- C:\WINDOWS\system32\isign32.dll
2012-01-03 09:21:12 ----A---- C:\WINDOWS\system32\inetcfg.dll
2012-01-03 09:21:06 ----D---- C:\Program Files\Common Files\System
2012-01-03 09:21:00 ----D---- C:\Program Files\Internet Explorer
2012-01-03 09:20:30 ----A---- C:\WINDOWS\system32\emptyregdb.dat
2012-01-03 09:20:12 ----D---- C:\Program Files\ComPlus Applications
2012-01-03 09:20:08 ----A---- C:\WINDOWS\vbaddin.ini
2012-01-03 09:20:08 ----A---- C:\WINDOWS\vb.ini
2012-01-03 09:20:00 ----D---- C:\WINDOWS\Registration
2012-01-03 09:19:49 ----D---- C:\Program Files\Online Services
2012-01-03 09:19:48 ----D---- C:\Program Files\Windows Media Player
2012-01-03 09:19:36 ----D---- C:\Program Files\Messenger
2012-01-03 09:19:32 ----D---- C:\Program Files\MSN Gaming Zone
2012-01-03 09:19:32 ----A---- C:\WINDOWS\system32\write.exe
2012-01-03 09:19:23 ----A---- C:\WINDOWS\system32\sndvol32.exe
2012-01-03 09:19:23 ----A---- C:\WINDOWS\system32\hticons.dll
2012-01-03 09:19:23 ----A---- C:\WINDOWS\system32\avwav.dll
2012-01-03 09:19:23 ----A---- C:\WINDOWS\system32\avtapi.dll
2012-01-03 09:19:23 ----A---- C:\WINDOWS\system32\avmeter.dll
2012-01-03 09:19:22 ----A---- C:\WINDOWS\system32\winchat.exe
2012-01-03 09:19:16 ----A---- C:\WINDOWS\system32\charmap.exe
2012-01-03 09:19:16 ----A---- C:\WINDOWS\system32\getuname.dll
2012-01-03 09:19:15 ----A---- C:\WINDOWS\system32\winmine.exe
2012-01-03 09:19:15 ----A---- C:\WINDOWS\system32\sol.exe
2012-01-03 09:19:15 ----A---- C:\WINDOWS\system32\mshearts.exe
2012-01-03 09:19:15 ----A---- C:\WINDOWS\system32\calc.exe
2012-01-03 09:19:14 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2012-01-03 09:19:14 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2012-01-03 09:19:14 ----A---- C:\WINDOWS\system32\tslabels.ini
2012-01-03 09:19:14 ----A---- C:\WINDOWS\system32\tskill.exe
2012-01-03 09:19:14 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2012-01-03 09:19:14 ----A---- C:\WINDOWS\system32\tscon.exe
2012-01-03 09:19:14 ----A---- C:\WINDOWS\system32\shadow.exe
2012-01-03 09:19:14 ----A---- C:\WINDOWS\system32\rwinsta.exe
2012-01-03 09:19:14 ----A---- C:\WINDOWS\system32\reset.exe
2012-01-03 09:19:14 ----A---- C:\WINDOWS\system32\regini.exe
2012-01-03 09:19:14 ----A---- C:\WINDOWS\system32\freecell.exe
2012-01-03 09:19:13 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2012-01-03 09:19:13 ----A---- C:\WINDOWS\system32\qwinsta.exe
2012-01-03 09:19:13 ----A---- C:\WINDOWS\system32\qappsrv.exe
2012-01-03 09:19:13 ----A---- C:\WINDOWS\system32\msg.exe
2012-01-03 09:19:13 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2012-01-03 09:19:13 ----A---- C:\WINDOWS\system32\logoff.exe
2012-01-03 09:19:13 ----A---- C:\WINDOWS\system32\cdmodem.dll
2012-01-03 09:19:07 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2012-01-03 09:18:49 ----D---- C:\Program Files\MSN
2012-01-03 09:18:48 ----A---- C:\WINDOWS\system32\sndrec32.exe
2012-01-03 09:18:48 ----A---- C:\WINDOWS\system32\mplay32.exe
2012-01-03 09:18:48 ----A---- C:\WINDOWS\system32\accwiz.exe
2012-01-03 09:18:47 ----D---- C:\Program Files\Windows NT
2012-01-03 09:18:47 ----A---- C:\WINDOWS\system32\mspaint.exe
2012-01-03 09:18:47 ----A---- C:\WINDOWS\system32\hypertrm.dll
2012-01-03 09:18:46 ----A---- C:\WINDOWS\system32\spider.exe
2012-01-03 09:18:46 ----A---- C:\WINDOWS\system32\clipbrd.exe
2012-01-03 09:18:45 ----D---- C:\WINDOWS\system32\en-US
2012-01-03 09:18:45 ----A---- C:\WINDOWS\system32\tsgqec.dll
2012-01-03 09:18:45 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2012-01-03 09:18:45 ----A---- C:\WINDOWS\system32\drivers\tdtcp.sys
2012-01-03 09:18:45 ----A---- C:\WINDOWS\system32\drivers\tdpipe.sys
2012-01-03 09:18:45 ----A---- C:\WINDOWS\system32\drivers\rdpwd.sys
2012-01-03 09:18:44 ----A---- C:\WINDOWS\system32\rhttpaa.dll
2012-01-03 09:18:44 ----A---- C:\WINDOWS\system32\aaclient.dll
2012-01-03 09:18:43 ----A---- C:\WINDOWS\system32\remotepg.dll
2012-01-03 09:18:43 ----A---- C:\WINDOWS\system32\rdshost.exe
2012-01-03 09:18:43 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2012-01-03 09:18:43 ----A---- C:\WINDOWS\system32\mstscax.dll
2012-01-03 09:18:43 ----A---- C:\WINDOWS\system32\mstsc.exe
2012-01-03 09:18:42 ----A---- C:\WINDOWS\system32\termsrv.dll
2012-01-03 09:18:42 ----A---- C:\WINDOWS\system32\sessmgr.exe
2012-01-03 09:18:42 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2012-01-03 09:18:42 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2012-01-03 09:18:42 ----A---- C:\WINDOWS\system32\rdpclip.exe
2012-01-03 09:18:42 ----A---- C:\WINDOWS\system32\rdchost.dll
2012-01-03 09:18:42 ----A---- C:\WINDOWS\system32\qprocess.exe
2012-01-03 09:18:42 ----A---- C:\WINDOWS\system32\icaapi.dll
2012-01-03 09:18:41 ----D---- C:\WINDOWS\system32\MsDtc
2012-01-03 09:18:41 ----A---- C:\WINDOWS\system32\mtxoci.dll
2012-01-03 09:18:41 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2012-01-03 09:18:41 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2012-01-03 09:18:41 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2012-01-03 09:18:40 ----A---- C:\WINDOWS\system32\xolehlp.dll
2012-01-03 09:18:40 ----A---- C:\WINDOWS\system32\msdtctm.dll
2012-01-03 09:18:40 ----A---- C:\WINDOWS\system32\msdtclog.dll
2012-01-03 09:18:40 ----A---- C:\WINDOWS\system32\msdtc.exe
2012-01-03 09:18:39 ----D---- C:\WINDOWS\system32\Com
2012-01-03 09:18:39 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2012-01-03 09:18:39 ----A---- C:\WINDOWS\system32\mtxex.dll
2012-01-03 09:18:39 ----A---- C:\WINDOWS\system32\mtxdm.dll
2012-01-03 09:18:39 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2012-01-03 09:18:39 ----A---- C:\WINDOWS\system32\comrepl.dll
2012-01-03 09:18:39 ----A---- C:\WINDOWS\system32\comaddin.dll
2012-01-03 09:18:39 ----A---- C:\WINDOWS\system32\colbact.dll
2012-01-03 09:18:38 ----A---- C:\WINDOWS\system32\stclient.dll
2012-01-03 09:18:38 ----A---- C:\WINDOWS\system32\clbcatex.dll
2012-01-03 09:18:38 ----A---- C:\WINDOWS\system32\catsrvut.dll
2012-01-03 09:18:38 ----A---- C:\WINDOWS\system32\catsrvps.dll
2012-01-03 09:18:38 ----A---- C:\WINDOWS\system32\catsrv.dll
2012-01-03 09:18:37 ----A---- C:\WINDOWS\system32\comuid.dll
2012-01-03 09:18:37 ----A---- C:\WINDOWS\system32\comsvcs.dll
2012-01-03 09:18:37 ----A---- C:\WINDOWS\system32\comsnap.dll
2012-01-03 09:18:36 ----A---- C:\WINDOWS\system32\clbcatq.dll
2012-01-03 09:18:26 ----A---- C:\WINDOWS\system32\servdeps.dll
2012-01-03 09:18:26 ----A---- C:\WINDOWS\system32\mmfutil.dll
2012-01-03 09:18:26 ----A---- C:\WINDOWS\system32\licwmi.dll
2012-01-03 09:18:26 ----A---- C:\WINDOWS\system32\cmprops.dll
2012-01-03 09:18:23 ----A---- C:\WINDOWS\system32\drivers\rdpdr.sys
2012-01-03 09:18:22 ----A---- C:\WINDOWS\system32\drivers\termdd.sys
2012-01-03 01:32:04 ----D---- C:\Program Files\Microsoft.NET
2012-01-03 01:19:24 ----A---- C:\moduleName.txt
2012-01-03 01:12:52 ----A---- C:\WINDOWS\system32\h323log.txt
2012-01-03 01:10:59 ----A---- C:\WINDOWS\system32\drivers\audstub.sys
2012-01-03 01:09:51 ----A---- C:\WINDOWS\system32\drivers\redbook.sys
2012-01-03 01:08:50 ----A---- C:\WINDOWS\system32\drivers\RTL8139.sys
2012-01-03 01:08:35 ----A---- C:\WINDOWS\system32\usbui.dll
2012-01-03 01:07:59 ----A---- C:\WINDOWS\system32\drivers\compbatt.sys
2012-01-03 01:07:58 ----A---- C:\WINDOWS\system32\drivers\CmBatt.sys
2012-01-03 01:07:58 ----A---- C:\WINDOWS\system32\drivers\battc.sys
2012-01-03 01:06:36 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2012-01-03 01:06:35 ----SHD---- C:\WINDOWS\Installer
2012-01-03 01:06:34 ----D---- C:\Program Files\Common Files\ODBC
2012-01-03 01:06:34 ----A---- C:\WINDOWS\ODBCINST.INI
2012-01-03 01:06:30 ----D---- C:\Program Files\Common Files\SpeechEngines
2012-01-03 01:06:29 ----RD---- C:\Program Files
2012-01-03 01:06:29 ----D---- C:\Program Files\Common Files\Microsoft Shared
2012-01-03 01:06:29 ----D---- C:\Program Files\Common Files
2012-01-03 01:06:26 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2012-01-03 01:06:26 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2012-01-03 01:06:26 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2012-01-03 01:06:24 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2012-01-03 01:06:24 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2012-01-03 01:06:24 ----RA---- C:\WINDOWS\system32\kbdur.dll
2012-01-03 01:06:24 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2012-01-03 01:06:24 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2012-01-03 01:06:24 ----RA---- C:\WINDOWS\system32\kbdru.dll
2012-01-03 01:06:24 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2012-01-03 01:06:24 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2012-01-03 01:06:24 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2012-01-03 01:06:24 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2012-01-03 01:06:24 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2012-01-03 01:06:24 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2012-01-03 01:06:22 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2012-01-03 01:06:22 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2012-01-03 01:06:22 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2012-01-03 01:06:22 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2012-01-03 01:06:22 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2012-01-03 01:06:22 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2012-01-03 01:06:22 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2012-01-03 01:06:21 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2012-01-03 01:06:21 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2012-01-03 01:06:21 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2012-01-03 01:06:21 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2012-01-03 01:06:20 ----RA---- C:\WINDOWS\system32\kbdest.dll
2012-01-03 01:06:19 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2012-01-03 01:06:19 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2012-01-03 01:06:19 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2012-01-03 01:06:19 ----RA---- C:\WINDOWS\system32\kbdro.dll
2012-01-03 01:06:19 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2012-01-03 01:06:19 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2012-01-03 01:06:19 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2012-01-03 01:06:19 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2012-01-03 01:06:19 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
2012-01-03 01:06:19 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
2012-01-03 01:06:19 ----RA---- C:\WINDOWS\system32\kbdcz.dll
2012-01-03 01:06:19 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2012-01-03 01:06:19 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2012-01-03 01:06:13 ----A---- C:\WINDOWS\system32\spxcoins.dll
2012-01-03 01:06:13 ----A---- C:\WINDOWS\system32\irclass.dll
2012-01-03 01:06:13 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2012-01-03 01:06:13 ----A---- C:\WINDOWS\system32\dgsetup.dll
2012-01-03 01:06:13 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2012-01-03 01:06:11 ----A---- C:\WINDOWS\TASKMAN.EXE
2012-01-03 01:06:10 ----A---- C:\WINDOWS\system32\drivers\irenum.sys
2012-01-03 01:06:10 ----A---- C:\WINDOWS\system32\batt.dll
2012-01-03 01:06:09 ----A---- C:\WINDOWS\NOTEPAD.EXE
2012-01-03 01:06:06 ----A---- C:\WINDOWS\system32\storprop.dll
2012-01-03 01:05:55 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
2012-01-03 01:05:36 ----D---- C:\WINDOWS\system32\CatRoot2
2012-01-03 01:05:36 ----D---- C:\WINDOWS\system32\CatRoot
2012-01-03 01:05:30 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2012-01-03 01:04:58 ----SHD---- C:\System Volume Information
2012-01-03 01:04:58 ----D---- C:\Documents and Settings
2012-01-03 01:04:57 ----A---- C:\WINDOWS\system32\FNTCACHE.DAT
2012-01-03 01:03:57 ----RASH---- C:\boot.ini
2012-01-03 01:03:33 ----D---- C:\Documents and Settings\Michal\Application Data\Adobe
2012-01-03 00:59:11 ----D---- C:\Program Files\CCleaner
2012-01-03 00:58:29 ----RSHDC---- C:\WINDOWS\system32\dllcache
2012-01-03 00:58:29 ----RSD---- C:\WINDOWS\Fonts
2012-01-03 00:58:29 ----RD---- C:\WINDOWS\Web
2012-01-03 00:58:29 ----HD---- C:\WINDOWS\inf
2012-01-03 00:58:29 ----D---- C:\WINDOWS\WinSxS
2012-01-03 00:58:29 ----D---- C:\WINDOWS\twain_32
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\wins
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\wbem
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\usmt
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\spool
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\ShellExt
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\Setup
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\scripting
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\ras
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\oobe
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\npp
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\mui
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\inetsrv
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\IME
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\icsxml
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\ias
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\export
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\en
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\drivers\etc
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\drivers\disdn
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\drivers
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\dhcp
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\config
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\3com_dmi
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\3076
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\2052
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\1054
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\1042
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\1041
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\1037
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\1033
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\1031
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\1028
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32\1025
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system32
2012-01-03 00:58:29 ----D---- C:\WINDOWS\system
2012-01-03 00:58:29 ----D---- C:\WINDOWS\security
2012-01-03 00:58:29 ----D---- C:\WINDOWS\Resources
2012-01-03 00:58:29 ----D---- C:\WINDOWS\repair
2012-01-03 00:58:29 ----D---- C:\WINDOWS\Provisioning
2012-01-03 00:58:29 ----D---- C:\WINDOWS\pchealth
2012-01-03 00:58:29 ----D---- C:\WINDOWS\PeerNet
2012-01-03 00:58:29 ----D---- C:\WINDOWS\NLDRV
2012-01-03 00:58:29 ----D---- C:\WINDOWS\Network Diagnostic
2012-01-03 00:58:29 ----D---- C:\WINDOWS\mui
2012-01-03 00:58:29 ----D---- C:\WINDOWS\msapps
2012-01-03 00:58:29 ----D---- C:\WINDOWS\msagent
2012-01-03 00:58:29 ----D---- C:\WINDOWS\Media
2012-01-03 00:58:29 ----D---- C:\WINDOWS\L2Schemas
2012-01-03 00:58:29 ----D---- C:\WINDOWS\java
2012-01-03 00:58:29 ----D---- C:\WINDOWS\ime
2012-01-03 00:58:29 ----D---- C:\WINDOWS\Help
2012-01-03 00:58:29 ----D---- C:\WINDOWS\ehome
2012-01-03 00:58:29 ----D---- C:\WINDOWS\Driver Cache
2012-01-03 00:58:29 ----D---- C:\WINDOWS\Debug
2012-01-03 00:58:29 ----D---- C:\WINDOWS\Cursors
2012-01-03 00:58:29 ----D---- C:\WINDOWS\Connection Wizard
2012-01-03 00:58:29 ----D---- C:\WINDOWS\Config
2012-01-03 00:58:29 ----D---- C:\WINDOWS\AppPatch
2012-01-03 00:58:29 ----D---- C:\WINDOWS\addins
2012-01-03 00:58:29 ----D---- C:\WINDOWS
2012-01-03 00:58:28 ----ASH---- C:\pagefile.sys
2012-01-03 00:49:23 ----RSD---- C:\WINDOWS\assembly
2012-01-03 00:48:59 ----D---- C:\WINDOWS\Microsoft.NET
2012-01-03 00:48:05 ----D---- C:\Program Files\ATI Technologies
2012-01-03 00:45:57 ----A---- C:\WINDOWS\system32\snymsico.dll
2012-01-03 00:45:57 ----A---- C:\WINDOWS\system32\drivers\risdptsk.sys
2012-01-03 00:45:57 ----A---- C:\WINDOWS\system32\drivers\rimsptsk.sys
2012-01-03 00:45:20 ----D---- C:\WINDOWS\system32\ReinstallBackups
2012-01-03 00:45:14 ----A---- C:\WINDOWS\system32\drivers\Rtnicxp.sys
2012-01-03 00:45:13 ----D---- C:\WINDOWS\OPTIONS
2012-01-03 00:44:31 ----A---- C:\WINDOWS\system32\drivers\splitter.sys
2012-01-03 00:44:28 ----A---- C:\WINDOWS\system32\drivers\wdmaud.sys
2012-01-03 00:44:25 ----A---- C:\WINDOWS\system32\drivers\DMusic.sys
2012-01-03 00:44:24 ----A---- C:\WINDOWS\system32\ChCfg.exe
2012-01-03 00:44:21 ----A---- C:\WINDOWS\system32\drivers\swmidi.sys
2012-01-03 00:44:19 ----A---- C:\WINDOWS\system32\drivers\aec.sys
2012-01-03 00:44:17 ----A---- C:\WINDOWS\system32\drivers\kmixer.sys
2012-01-03 00:44:15 ----A---- C:\WINDOWS\system32\drivers\drmkaud.sys
2012-01-03 00:44:13 ----A---- C:\WINDOWS\system32\drivers\sysaudio.sys
2012-01-03 00:44:11 ----A---- C:\WINDOWS\system32\drivers\MSKSSRV.sys
2012-01-03 00:44:09 ----A---- C:\WINDOWS\system32\drivers\MSPQM.sys
2012-01-03 00:44:05 ----A---- C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2012-01-03 00:43:59 ----D---- C:\WINDOWS\system32\RTCOM
2012-01-03 00:43:56 ----A---- C:\WINDOWS\system32\ksuser.dll
2012-01-03 00:43:56 ----A---- C:\WINDOWS\system32\drivers\portcls.sys
2012-01-03 00:43:56 ----A---- C:\WINDOWS\system32\drivers\drmk.sys
2012-01-03 00:43:52 ----A---- C:\WINDOWS\SoundMan.exe
2012-01-03 00:43:52 ----A---- C:\WINDOWS\SkyTel.exe
2012-01-03 00:43:52 ----A---- C:\WINDOWS\RtlUpd.exe
2012-01-03 00:43:51 ----A---- C:\WINDOWS\RTLCPL.exe
2012-01-03 00:43:50 ----A---- C:\WINDOWS\system32\drivers\RtkHDAud.Sys
2012-01-03 00:43:49 ----D---- C:\Program Files\Realtek
2012-01-03 00:43:49 ----A---- C:\WINDOWS\RTHDCPL.exe
2012-01-03 00:43:49 ----A---- C:\WINDOWS\MicCal.exe
2012-01-03 00:43:49 ----A---- C:\WINDOWS\alcwzrd.exe
2012-01-03 00:43:49 ----A---- C:\WINDOWS\Alcmtr.exe
2012-01-03 00:43:45 ----A---- C:\WINDOWS\RtlExUpd.dll

======List of files/folders modified in the last 1 month======

2012-01-09 22:58:57 ----A---- C:\WINDOWS\win.ini
2012-01-03 09:23:55 ----ASH---- C:\WINDOWS\fonts\desktop.ini
2012-01-03 01:12:18 ----A---- C:\WINDOWS\system.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 risdptsk;risdptsk; C:\WINDOWS\system32\DRIVERS\risdptsk.sys [2005-07-14 27904]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2011-11-28 30808]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2011-11-28 34392]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2011-11-28 435032]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2011-11-28 314456]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2011-11-28 52952]
R1 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2010-12-16 31088]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-08-18 12032]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2011-11-28 20568]
R2 aswMon2;aswMon2; C:\WINDOWS\system32\drivers\aswMon2.sys [2011-11-28 111320]
R3 AR5211;Atheros Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\ar5211.sys [2007-05-02 546976]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2007-07-04 2304000]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-11-03 4394496]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-18 12160]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ATKACPI.sys [2007-08-24 5760]
R3 rimsptsk;rimsptsk; C:\WINDOWS\system32\DRIVERS\rimsptsk.sys [2005-07-12 51328]
R3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2006-12-14 85120]
R3 WSIMD;wsimd Service; C:\WINDOWS\system32\DRIVERS\wsimd.sys [2007-03-28 57024]
S3 GGSAFERDriver;GGSAFER Driver; \??\C:\Program Files\Garena Plus\Room\safedrv.sys []
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2008-04-13 20992]
S3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2008-04-13 79232]
S3 TrueSight;TrueSight; \??\c:\windows\system32\drivers\TrueSight.sys []
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ACS;Atheros Configuration Service; C:\WINDOWS\system32\acs.exe [2007-05-03 364629]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2007-07-04 483328]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-11-28 44768]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 KMService;KMService; C:\WINDOWS\system32\srvany.exe [2003-04-18 8192]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2012-01-09 654848]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2010-01-21 30963576]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: haveď v notebooku

#75 Příspěvek od vyosek »

Log jiz vypada cisty a v poradku :)
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět