2/3
Logfile of random's system information tool 1.09 (written by random/random)
Run by jku at 2012-01-09 23:39:15
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 52 GB (51%) free of 102 GB
Total RAM: 766 MB (42% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:39:33, on 9.1.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Privacyware\Privatefirewall 7.0\pfsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Nero\Update\NASvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe
C:\Program Files\Privacyware\Privatefirewall 7.0\PFGUI.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Orbitdownloader\orbitdm.exe
C:\Program Files\Orbitdownloader\orbitnet.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Tracker Software\PDF-XChange 4\pdfSaver4.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\SW léčení havěti\RSIT.exe
C:\Program Files\trend micro\jku.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: PXCIEaddin - {42DFA04F-0F16-418e-B80C-AB97A5AFAD39} - C:\Program Files\Tracker Software\PDF-XChange 4\PXCIEAddin4.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Ukazatel S-Rank - {EA837F48-5AD1-443E-AE34-FFE03CBF3099} - C:\Program Files\Seznam.cz\bin\core.4.dll
O3 - Toolbar: PDFXChange 4.0 IE Plugin - {42DFA04F-0F16-418e-B80C-AB97A5AFAD39} - C:\Program Files\Tracker Software\PDF-XChange 4\PXCIEAddin4.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [PMBVolumeWatcher] C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe
O4 - HKLM\..\Run: [Privatefirewall] C:\Program Files\Privacyware\Privatefirewall 7.0\PFGUI.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Orbit.lnk = C:\Program Files\Orbitdownloader\orbitdm.exe
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) -
https://www-secure.symantec.com/techsup ... gctlsr.cab
O16 - DPF: {4ADC518E-B607-11D4-B395-0001020F4519} (SigVer Class) -
https://ib24.csob.cz/Comp/signer.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Realtime Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - SOURCENEXT - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @C:\Program Files\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files\Nero\Update\NASvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Privacyware network service (PFNet) - Privacyware/PWI, Inc. - C:\Program Files\Privacyware\Privatefirewall 7.0\pfsvc.exe
O23 - Service: PMBDeviceInfoProvider - Sony Corporation - C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
O23 - Service: R - Sonic Solutions - (no file)
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
--
End of file - 8757 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\User_Feed_Synchronization-{4E3DCB0F-41BA-4BF4-89E9-EA3720277B16}.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{5B6E2DB4-1981-49F5-9E0C-6B46A7E62FC0}.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{A8327517-6FF4-40F3-9209-669F18CE4BE8}.job
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\jku\Data aplikací\Mozilla\Firefox\Profiles\gu996aoq.default
prefs.js - "browser.startup.homepage" - "About:Blank"
prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}:6.0.30,
jqs@sun.com:1.0, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.25"
prefs.js - "keyword.URL" - "
http://search.mywebsearch.com/mywebsear ... searchfor="
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"
jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf]
"Description"=
"Path"=C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@SmileyCentral_1v.com/Plugin]
"Description"=SmileyCentral Plugin
"Path"=
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}
C:\Program Files\Mozilla Firefox\components\
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
components.list
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
GPSDGeolocationProvider.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsFormAutoComplete.js
nsHandlerService.js
nsHelperAppDlg.js
nsILegitCheckPlugin.xpt
nsINIProcessor.js
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesAutoComplete.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUpdateServiceStub.js
nsUpdateTimerManager.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js
C:\Program Files\Mozilla Firefox\plugins\
np-mswmp.dll
np32dsw.dll
npdeployJava1.dll
npLegitCheckPlugin.dll
npnul32.dll
npPDFXCviewNPPlugin.dll
ShockwavePlugin.class
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt
C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
yahoo.xml
C:\Documents and Settings\jku\Data aplikací\Mozilla\Firefox\Profiles\gu996aoq.default\extensions\
{20a82645-c095-46ed-80e3-08825760534b}
C:\Documents and Settings\jku\Data aplikací\Mozilla\Firefox\Profiles\gu996aoq.default\searchplugins\
SmileyCentral_1v.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000123B4-9B42-4900-B3F7-F4B073EFC214}]
Octh Class - C:\Program Files\Orbitdownloader\orbitcth.dll [2011-06-28 241464]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{42DFA04F-0F16-418e-B80C-AB97A5AFAD39}]
PDFXChange 4.0 IE Plugin - C:\Program Files\Tracker Software\PDF-XChange 4\PXCIEAddin4.dll [2009-12-30 422168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2012-01-02 325408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2012-01-02 42272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2012-01-02 79648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA837F48-5AD1-443E-AE34-FFE03CBF3099}]
Ukazatel S-Rank - C:\Program Files\Seznam.cz\bin\core.4.dll [2011-12-12 1151520]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{42DFA04F-0F16-418e-B80C-AB97A5AFAD39} - PDFXChange 4.0 IE Plugin - C:\Program Files\Tracker Software\PDF-XChange 4\PXCIEAddin4.dll [2009-12-30 422168]
{C55BBCD6-41AD-48AD-9953-3609C48EACC7} - Grab Pro - C:\Program Files\Orbitdownloader\GrabPro.dll [2011-06-28 696000]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2006-10-22 7700480]
"nwiz"=nwiz.exe /install []
"RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2003-10-31 32768]
"UnlockerAssistant"=C:\Program Files\Unlocker\UnlockerAssistant.exe [2010-07-04 17408]
"Acronis Scheduler2 Service"=C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe [2011-08-20 403096]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2011-12-15 258512]
"PMBVolumeWatcher"=C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe [2011-08-24 651832]
"Privatefirewall"=C:\Program Files\Privacyware\Privatefirewall 7.0\PFGUI.exe [2011-02-09 2973192]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2004-10-21 77824]
"AlcWzrd"=C:\WINDOWS\ALCWZRD.EXE [2004-10-21 2744832]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-06-09 254696]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2006-10-22 86016]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2011-12-24 460872]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-11-10 3514176]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
C:\WINDOWS\ALCWZRD.EXE [2004-10-21 2744832]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE
Orbit.lnk - C:\Program Files\Orbitdownloader\orbitdm.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2009-01-30 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PFNet]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
"BackupNoCDBurning"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\Orbitdownloader\orbitdm.exe"="C:\Program Files\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit"
"C:\Program Files\Orbitdownloader\orbitnet.exe"="C:\Program Files\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit"
"C:\Program Files\Internet Explorer\iexplore.exe"="C:\Program Files\Internet Explorer\iexplore.exe:*:Disabled:Internet Explorer"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"VIDC.MPG4"=mpg4c32.dll
"VIDC.MP42"=mpg4c32.dll
"wave1"=serwvdrv.dll
"VIDC.WMV3"=wmv9vcm.dll
"vidc.dvsd"=mcdvd_32.dll
"vidc.mjpg"=pvmjpg30.dll
"msacm.lameacm"=lameACM.acm
"msacm.ac3acm"=ac3acm.acm
"wave"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"midi"=wdmaud.drv
"vidc.I420"=msh263.drv
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
======List of files/folders created in the last 3 months======
2012-01-09 23:39:15 ----D---- C:\rsit
2012-01-09 22:52:00 ----D---- C:\Program Files\Piranha Bytes
2012-01-07 19:44:19 ----A---- C:\RootkitReveal.txt
2012-01-06 20:20:36 ----D---- C:\Program Files\Orbitdownloader
2012-01-05 19:26:51 ----D---- C:\Documents and Settings\jku\Data aplikací\Malwarebytes
2012-01-05 19:26:37 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2012-01-05 19:26:36 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2012-01-05 19:26:36 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2012-01-04 21:40:47 ----A---- C:\PF_PortTrackingLog_21_40_39.txt
2012-01-04 21:32:09 ----A---- C:\Ad-ware report.txt
2012-01-03 20:48:41 ----A---- C:\log.txt
2012-01-03 20:09:11 ----A---- C:\Boot.bak
2012-01-03 20:09:07 ----RASHD---- C:\cmdcons
2012-01-03 19:47:50 ----D---- C:\Qoobox
2012-01-03 14:57:54 ----SHD---- C:\RECYCLER
2012-01-03 00:31:37 ----HDC---- C:\WINDOWS\$NtUninstallKB2345886$
2012-01-03 00:26:47 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2012-01-03 00:18:21 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2012-01-02 21:33:44 ----D---- C:\Program Files\trend micro
2012-01-02 20:20:20 ----A---- C:\WINDOWS\system32\NVUNINST.EXE
2012-01-02 20:19:57 ----D---- C:\Program Files\nVidia
2012-01-02 20:01:18 ----D---- C:\Documents and Settings\All Users\Data aplikací\NVIDIA
2012-01-02 20:00:55 ----D---- C:\Documents and Settings\All Users\Data aplikací\Sun
2012-01-02 20:00:28 ----A---- C:\WINDOWS\system32\javaws.exe
2012-01-02 20:00:28 ----A---- C:\WINDOWS\system32\javaw.exe
2012-01-02 20:00:28 ----A---- C:\WINDOWS\system32\java.exe
2012-01-02 20:00:28 ----A---- C:\WINDOWS\system32\deployJava1.dll
2012-01-02 14:52:42 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2012-01-02 14:48:15 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2012-01-02 14:44:56 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2012-01-02 14:44:39 ----HDC---- C:\WINDOWS\$NtUninstallKB2387149$
2012-01-02 14:44:23 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2012-01-02 14:44:07 ----HDC---- C:\WINDOWS\$NtUninstallKB2479943$
2012-01-02 14:43:51 ----HDC---- C:\WINDOWS\$NtUninstallKB2567680$
2012-01-02 14:43:35 ----HDC---- C:\WINDOWS\$NtUninstallKB2564958$
2012-01-02 14:43:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2478971$
2012-01-02 14:43:05 ----HDC---- C:\WINDOWS\$NtUninstallKB2544893-v2$
2012-01-02 14:38:56 ----HDC---- C:\WINDOWS\$NtUninstallKB2536276-v2$
2012-01-02 14:38:38 ----HDC---- C:\WINDOWS\$NtUninstallKB2296011$
2012-01-02 14:38:20 ----HDC---- C:\WINDOWS\$NtUninstallKB2115168$
2012-01-02 14:37:54 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2012-01-02 14:37:26 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2012-01-02 14:37:04 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2012-01-02 14:36:44 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2012-01-02 14:36:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2443105$
2012-01-02 14:36:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$
2012-01-02 14:35:51 ----HDC---- C:\WINDOWS\$NtUninstallKB2639417$
2012-01-02 14:35:36 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2012-01-02 14:35:20 ----HDC---- C:\WINDOWS\$NtUninstallKB2481109$
2012-01-02 14:35:04 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2012-01-02 14:34:50 ----HDC---- C:\WINDOWS\$NtUninstallKB2485663$
2012-01-02 14:34:36 ----HDC---- C:\WINDOWS\$NtUninstallKB2440591$
2012-01-02 14:34:19 ----HDC---- C:\WINDOWS\$NtUninstallKB982132$
2012-01-02 14:34:04 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2012-01-02 14:33:49 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2012-01-02 14:33:28 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2012-01-02 14:33:05 ----HDC---- C:\WINDOWS\$NtUninstallKB2507938$
2012-01-02 14:32:46 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2012-01-02 14:32:25 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2012-01-02 14:32:12 ----HDC---- C:\WINDOWS\$NtUninstallKB2476490$
2012-01-02 14:31:58 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2012-01-02 14:31:40 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2012-01-02 14:31:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2347290$
2012-01-02 14:31:10 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2012-01-02 14:30:53 ----HDC---- C:\WINDOWS\$NtUninstallKB2641690$
2012-01-02 14:30:35 ----HDC---- C:\WINDOWS\$NtUninstallKB2483185$
2012-01-02 14:30:17 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2012-01-02 14:30:02 ----HDC---- C:\WINDOWS\$NtUninstallKB2079403$
2012-01-02 14:29:47 ----HDC---- C:\WINDOWS\$NtUninstallKB2624667$
2012-01-02 14:24:35 ----HDC---- C:\WINDOWS\$NtUninstallKB979687$
2012-01-02 14:24:20 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2012-01-02 14:24:07 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2012-01-02 14:23:51 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2012-01-02 14:23:37 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2012-01-02 14:23:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2592799$
2012-01-02 14:23:11 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2012-01-02 14:22:51 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2012-01-02 14:22:38 ----HDC---- C:\WINDOWS\$NtUninstallKB2570222$
2012-01-02 14:22:25 ----HDC---- C:\WINDOWS\$NtUninstallKB2535512$
2012-01-02 14:22:12 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2012-01-02 14:21:54 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2012-01-02 14:21:35 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2012-01-02 14:21:16 ----HDC---- C:\WINDOWS\$NtUninstallKB2412687$
2012-01-02 14:16:58 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2012-01-02 14:16:39 ----HDC---- C:\WINDOWS\$NtUninstallKB2570947$
2012-01-02 14:16:23 ----HDC---- C:\WINDOWS\$NtUninstallKB980436$
2012-01-02 14:16:07 ----HDC---- C:\WINDOWS\$NtUninstallKB981322$
2012-01-02 14:15:51 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2012-01-02 14:15:29 ----HDC---- C:\WINDOWS\$NtUninstallKB2507618$
2012-01-02 14:15:12 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2012-01-02 14:14:42 ----HDC---- C:\WINDOWS\$NtUninstallKB2419632$
2012-01-02 14:14:28 ----HDC---- C:\WINDOWS\$NtUninstallKB2508429$
2012-01-02 14:14:15 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2012-01-02 14:13:58 ----HDC---- C:\WINDOWS\$NtUninstallKB971029$
2012-01-02 14:13:45 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
2012-01-02 14:13:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2506212$
2012-01-02 14:13:12 ----HDC---- C:\WINDOWS\$NtUninstallKB2633952$
2012-01-02 14:13:03 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2012-01-02 14:12:43 ----HDC---- C:\WINDOWS\$NtUninstallKB2619339$
2012-01-02 14:12:30 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2012-01-02 14:12:18 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2012-01-02 14:12:06 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2012-01-02 14:11:54 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2012-01-02 14:11:42 ----HDC---- C:\WINDOWS\$NtUninstallKB981997$
2012-01-02 14:11:29 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2012-01-02 14:11:16 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2012-01-02 14:11:01 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2012-01-02 14:07:19 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2012-01-02 14:06:14 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2012-01-02 14:06:00 ----HDC---- C:\WINDOWS\$NtUninstallKB2509553$
2012-01-02 14:05:37 ----HDC---- C:\WINDOWS\$NtUninstallKB982665$
2012-01-02 14:05:26 ----HDC---- C:\WINDOWS\$NtUninstallKB2541763$
2012-01-02 14:05:01 ----HDC---- C:\WINDOWS\$NtUninstallKB2478960$
2012-01-02 14:04:50 ----HDC---- C:\WINDOWS\$NtUninstallKB2393802$
2012-01-02 14:04:36 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2012-01-02 14:04:25 ----HDC---- C:\WINDOWS\$NtUninstallKB2620712$
2012-01-02 14:04:14 ----HDC---- C:\WINDOWS\$NtUninstallKB2566454$
2012-01-02 14:04:01 ----HDC---- C:\WINDOWS\$NtUninstallKB2633171$
2012-01-02 14:03:49 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2012-01-02 14:03:36 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2012-01-02 14:03:25 ----HDC---- C:\WINDOWS\$NtUninstallKB2423089$
2012-01-02 14:03:03 ----HDC---- C:\WINDOWS\$NtUninstallKB2360937$
2012-01-02 13:38:15 ----A---- C:\WINDOWS\system32\wups2.dll
2012-01-02 13:18:08 ----D---- C:\Program Files\Seznam.cz
2012-01-02 13:18:06 ----HD---- C:\WINDOWS\msdownld.tmp
2012-01-02 12:59:39 ----D---- C:\WINDOWS\Prefetch
2012-01-02 09:00:41 ----D---- C:\Program Files\Online Services
2012-01-02 09:00:34 ----D---- C:\Program Files\Common Files\Services
2012-01-02 08:59:25 ----D---- C:\Program Files\ComPlus Applications
2012-01-02 03:24:27 ----ASH---- C:\pagefile.sys
2012-01-02 02:30:44 ----A---- C:\WINDOWS\system32\spxcoins.dll
2012-01-02 02:30:44 ----A---- C:\WINDOWS\system32\irclass.dll
2012-01-02 02:22:30 ----A---- C:\WINDOWS\system32\winshfhc.dll
2012-01-02 02:22:30 ----A---- C:\WINDOWS\system32\blastcln.exe
2012-01-02 02:22:29 ----A---- C:\WINDOWS\system32\wmvdmoe2.dll
2012-01-02 02:22:29 ----A---- C:\WINDOWS\system32\wmvdmod.dll
2012-01-02 02:22:29 ----A---- C:\WINDOWS\system32\WMVCore.dll
2012-01-02 02:22:29 ----A---- C:\WINDOWS\system32\wmstream.dll
2012-01-02 02:22:29 ----A---- C:\WINDOWS\system32\wmspdmoe.dll
2012-01-02 02:22:29 ----A---- C:\WINDOWS\system32\wmspdmod.dll
2012-01-02 02:22:29 ----A---- C:\WINDOWS\system32\wmsdmoe2.dll
2012-01-02 02:22:29 ----A---- C:\WINDOWS\system32\wmsdmoe.dll
2012-01-02 02:22:29 ----A---- C:\WINDOWS\system32\wmsdmod.dll
2012-01-02 02:22:29 ----A---- C:\WINDOWS\system32\wmpui.dll
2012-01-02 02:22:29 ----A---- C:\WINDOWS\system32\wmpshell.dll
2012-01-02 02:22:29 ----A---- C:\WINDOWS\system32\wmploc.dll
2012-01-02 02:22:29 ----A---- C:\WINDOWS\system32\wmpdxm.dll
2012-01-02 02:22:29 ----A---- C:\WINDOWS\system32\wmpcore.dll
2012-01-02 02:22:29 ----A---- C:\WINDOWS\system32\wmpcd.dll
2012-01-02 02:22:29 ----A---- C:\WINDOWS\system32\wmpasf.dll
2012-01-02 02:22:29 ----A---- C:\WINDOWS\system32\wmp.dll
2012-01-02 02:22:29 ----A---- C:\WINDOWS\system32\WMNetmgr.dll
2012-01-02 02:22:29 ----A---- C:\WINDOWS\system32\wmidx.dll
2012-01-02 02:22:29 ----A---- C:\WINDOWS\system32\wmerror.dll
2012-01-02 02:22:29 ----A---- C:\WINDOWS\system32\wmdmps.dll
2012-01-02 02:22:29 ----A---- C:\WINDOWS\system32\wmdmlog.dll
2012-01-02 02:22:29 ----A---- C:\WINDOWS\system32\wmasf.dll
2012-01-02 02:22:29 ----A---- C:\WINDOWS\system32\wmadmoe.dll
2012-01-02 02:22:29 ----A---- C:\WINDOWS\system32\wmadmod.dll
2012-01-02 02:22:29 ----A---- C:\WINDOWS\system32\strmdll.dll
2012-01-02 02:22:29 ----A---- C:\WINDOWS\system32\shmedia.dll
2012-01-02 02:22:29 ----A---- C:\WINDOWS\system32\mswmdm.dll
2012-01-02 02:22:29 ----A---- C:\WINDOWS\system32\msscp.dll
2012-01-02 02:22:29 ----A---- C:\WINDOWS\system32\mspmsnsv.dll
2012-01-02 02:22:28 ----A---- C:\WINDOWS\system32\mspmsp.dll
2012-01-02 02:22:28 ----A---- C:\WINDOWS\system32\msnetobj.dll
2012-01-02 02:22:28 ----A---- C:\WINDOWS\system32\msdxmlc.dll
2012-01-02 02:22:28 ----A---- C:\WINDOWS\system32\mpg4dmod.dll
2012-01-02 02:22:28 ----A---- C:\WINDOWS\system32\mp4sdmod.dll
2012-01-02 02:22:28 ----A---- C:\WINDOWS\system32\mp43dmod.dll
2012-01-02 02:22:28 ----A---- C:\WINDOWS\system32\logagent.exe
2012-01-02 02:22:28 ----A---- C:\WINDOWS\system32\laprxy.dll
2012-01-02 02:22:28 ----A---- C:\WINDOWS\system32\dxmasf.dll
2012-01-02 02:22:28 ----A---- C:\WINDOWS\system32\drmv2clt.dll
2012-01-02 02:22:28 ----A---- C:\WINDOWS\system32\drmstor.dll
2012-01-02 02:22:28 ----A---- C:\WINDOWS\system32\drmclien.dll
2012-01-02 02:22:28 ----A---- C:\WINDOWS\system32\cewmdm.dll
2012-01-02 02:22:28 ----A---- C:\WINDOWS\system32\blackbox.dll
2012-01-02 02:22:28 ----A---- C:\WINDOWS\system32\asferror.dll
2012-01-02 02:22:26 ----A---- C:\WINDOWS\vmmreg32.dll
2012-01-02 02:22:26 ----A---- C:\WINDOWS\system32\xmllite.dll
2012-01-02 02:22:26 ----A---- C:\WINDOWS\system32\wlanapi.dll
2012-01-02 02:22:26 ----A---- C:\WINDOWS\system32\vga64k.dll
2012-01-02 02:22:26 ----A---- C:\WINDOWS\system32\vga256.dll
2012-01-02 02:22:26 ----A---- C:\WINDOWS\system32\tspkg.dll
2012-01-02 02:22:26 ----A---- C:\WINDOWS\system32\osuninst.exe
2012-01-02 02:22:26 ----A---- C:\WINDOWS\system32\drivers\update.sys
2012-01-02 02:22:25 ----A---- C:\WINDOWS\system32\tourstart.exe
2012-01-02 02:22:25 ----A---- C:\WINDOWS\system32\spnpinst.exe
2012-01-02 02:22:25 ----A---- C:\WINDOWS\system32\pentnt.exe
2012-01-02 02:22:25 ----A---- C:\WINDOWS\system32\odtext32.dll
2012-01-02 02:22:25 ----A---- C:\WINDOWS\system32\odpdx32.dll
2012-01-02 02:22:25 ----A---- C:\WINDOWS\system32\odfox32.dll
2012-01-02 02:22:25 ----A---- C:\WINDOWS\system32\odexl32.dll
2012-01-02 02:22:24 ----RASH---- C:\NTDETECT.COM
2012-01-02 02:22:24 ----A---- C:\WINDOWS\system32\oddbse32.dll
2012-01-02 02:22:24 ----A---- C:\WINDOWS\system32\msxbde40.dll
2012-01-02 02:22:24 ----A---- C:\WINDOWS\system32\msvcrt20.dll
2012-01-02 02:22:24 ----A---- C:\WINDOWS\system32\mstext40.dll
2012-01-02 02:22:24 ----A---- C:\WINDOWS\system32\msrepl40.dll
2012-01-02 02:22:24 ----A---- C:\WINDOWS\system32\msrecr40.dll
2012-01-02 02:22:24 ----A---- C:\WINDOWS\system32\msrd2x40.dll
2012-01-02 02:22:24 ----A---- C:\WINDOWS\system32\msrclr40.dll
2012-01-02 02:22:24 ----A---- C:\WINDOWS\system32\msr2cenu.dll
2012-01-02 02:22:24 ----A---- C:\WINDOWS\system32\msr2c.dll
2012-01-02 02:22:24 ----A---- C:\WINDOWS\system32\mspbde40.dll
2012-01-02 02:22:24 ----A---- C:\WINDOWS\system32\msltus40.dll
2012-01-02 02:22:24 ----A---- C:\WINDOWS\system32\msexch40.dll
2012-01-02 02:22:24 ----A---- C:\WINDOWS\system32\msexcl40.dll
2012-01-02 02:22:23 ----A---- C:\WINDOWS\system32\migpwd.exe
2012-01-02 02:22:23 ----A---- C:\WINDOWS\system32\lnkstub.exe
2012-01-02 02:22:23 ----A---- C:\WINDOWS\system32\krnl386.exe
2012-01-02 02:22:23 ----A---- C:\WINDOWS\system32\ir50_qcx.dll
2012-01-02 02:22:23 ----A---- C:\WINDOWS\system32\ir50_qc.dll
2012-01-02 02:22:23 ----A---- C:\WINDOWS\system32\ir50_32.dll
2012-01-02 02:22:23 ----A---- C:\WINDOWS\system32\ir41_qcx.dll
2012-01-02 02:22:23 ----A---- C:\WINDOWS\system32\ir41_qc.dll
2012-01-02 02:22:23 ----A---- C:\WINDOWS\system32\drivers\mnmdd.sys
2012-01-02 02:22:23 ----A---- C:\WINDOWS\system32\d3dramp.dll
2012-01-02 02:22:23 ----A---- C:\WINDOWS\system32\ctl3d32.dll
2012-01-02 02:22:22 ----A---- C:\WINDOWS\system32\xpsp3res.dll
2012-01-02 02:22:22 ----A---- C:\WINDOWS\system32\xpsp2res.dll
2012-01-02 02:22:22 ----A---- C:\WINDOWS\system32\xpsp1res.dll
2012-01-02 02:22:22 ----A---- C:\WINDOWS\system32\xpob2res.dll
2012-01-02 02:22:22 ----A---- C:\WINDOWS\system32\wshcs.dll
2012-01-02 02:22:22 ----A---- C:\WINDOWS\system32\wmerrCSY.dll
2012-01-02 02:22:22 ----A---- C:\WINDOWS\system32\vbscs.dll
2012-01-02 02:22:22 ----A---- C:\WINDOWS\system32\scrrncs.dll
2012-01-02 02:22:22 ----A---- C:\WINDOWS\system32\scocs.dll
2012-01-02 02:22:22 ----A---- C:\WINDOWS\system32\perfi005.dat
2012-01-02 02:22:22 ----A---- C:\WINDOWS\system32\perfd005.dat
2012-01-02 02:22:22 ----A---- C:\WINDOWS\system32\mfc42loc.dll
2012-01-02 02:22:22 ----A---- C:\WINDOWS\system32\mfc40loc.dll
2012-01-02 02:22:22 ----A---- C:\WINDOWS\system32\jscs.dll
2012-01-02 02:22:22 ----A---- C:\WINDOWS\system32\edit.com
2012-01-02 02:22:21 ----A---- C:\WINDOWS\system32\kbdycl.dll
2012-01-02 02:22:21 ----A---- C:\WINDOWS\system32\kbdycc.dll
2012-01-02 02:22:21 ----A---- C:\WINDOWS\system32\kbduzb.dll
2012-01-02 02:22:21 ----A---- C:\WINDOWS\system32\kbdtuq.dll
2012-01-02 02:22:21 ----A---- C:\WINDOWS\system32\kbdtuf.dll
2012-01-02 02:22:21 ----A---- C:\WINDOWS\system32\kbdtat.dll
2012-01-02 02:22:21 ----A---- C:\WINDOWS\system32\kbdsl1.dll
2012-01-02 02:22:21 ----A---- C:\WINDOWS\system32\kbdsl.dll
2012-01-02 02:22:21 ----A---- C:\WINDOWS\system32\kbdru1.dll
2012-01-02 02:22:21 ----A---- C:\WINDOWS\system32\kbdru.dll
2012-01-02 02:22:21 ----A---- C:\WINDOWS\system32\kbdro.dll
2012-01-02 02:22:20 ----A---- C:\WINDOWS\system32\msutb.dll
2012-01-02 02:22:20 ----A---- C:\WINDOWS\system32\mslbui.dll
2012-01-02 02:22:20 ----A---- C:\WINDOWS\system32\MSIMTF.dll
2012-01-02 02:22:20 ----A---- C:\WINDOWS\system32\MSCTFP.dll
2012-01-02 02:22:20 ----A---- C:\WINDOWS\system32\MSCTF.dll
2012-01-02 02:22:20 ----A---- C:\WINDOWS\system32\kbdpash.dll
2012-01-02 02:22:20 ----A---- C:\WINDOWS\system32\kbdnepr.dll
2012-01-02 02:22:20 ----A---- C:\WINDOWS\system32\kbdinmal.dll
2012-01-02 02:22:20 ----A---- C:\WINDOWS\system32\kbdinben.dll
2012-01-02 02:22:20 ----A---- C:\WINDOWS\system32\kbdinbe1.dll
2012-01-02 02:22:20 ----A---- C:\WINDOWS\system32\ctfmon.exe
2012-01-02 02:22:18 ----A---- C:\WINDOWS\system32\zipfldr.dll
2012-01-02 02:22:18 ----A---- C:\WINDOWS\system32\xmlprovi.dll
2012-01-02 02:22:18 ----A---- C:\WINDOWS\system32\xmlprov.dll
2012-01-02 02:22:18 ----A---- C:\WINDOWS\system32\xenroll.dll
2012-01-02 02:22:18 ----A---- C:\WINDOWS\system32\xcopy.exe
2012-01-02 02:22:18 ----A---- C:\WINDOWS\system32\xactsrv.dll
2012-01-02 02:22:18 ----A---- C:\WINDOWS\system32\wzcdlg.dll
2012-01-02 02:22:18 ----A---- C:\WINDOWS\system32\wupdmgr.exe
2012-01-02 02:22:18 ----A---- C:\WINDOWS\system32\wtsapi32.dll
2012-01-02 02:22:18 ----A---- C:\WINDOWS\system32\wstdecod.dll
2012-01-02 02:22:18 ----A---- C:\WINDOWS\system32\wsock32.dll
2012-01-02 02:22:18 ----A---- C:\WINDOWS\system32\wsnmp32.dll
2012-01-02 02:22:18 ----A---- C:\WINDOWS\system32\wshtcpip.dll
2012-01-02 02:22:18 ----A---- C:\WINDOWS\system32\WshRm.dll
2012-01-02 02:22:18 ----A---- C:\WINDOWS\system32\wshnetbs.dll
2012-01-02 02:22:18 ----A---- C:\WINDOWS\system32\wshisn.dll
2012-01-02 02:22:18 ----A---- C:\WINDOWS\system32\wship6.dll
2012-01-02 02:22:18 ----A---- C:\WINDOWS\system32\wshext.dll
2012-01-02 02:22:18 ----A---- C:\WINDOWS\system32\wshcon.dll
2012-01-02 02:22:18 ----A---- C:\WINDOWS\system32\wshatm.dll
2012-01-02 02:22:18 ----A---- C:\WINDOWS\system32\wsecedit.dll
2012-01-02 02:22:18 ----A---- C:\WINDOWS\system32\wscsvc.dll
2012-01-02 02:22:18 ----A---- C:\WINDOWS\system32\wscript.exe
2012-01-02 02:22:17 ----A---- C:\WINDOWS\winhlp32.exe
2012-01-02 02:22:17 ----A---- C:\WINDOWS\winhelp.exe
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\wscntfy.exe
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\ws2help.dll
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\ws2_32.dll
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\wpnpinst.exe
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\wpabaln.exe
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\wowexec.exe
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\wowdeb.exe
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\wow32.dll
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\wmphoto.dll
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\wmiscmgr.dll
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\wmiprop.dll
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\wmi.dll
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\wlnotify.dll
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\wldap32.dll
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\wkssvc.dll
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\winver.exe
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\wintrust.dll
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\winstrm.dll
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\winsta.dll
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\winsrv.dll
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\winspool.exe
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\winsock.dll
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\winscard.dll
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\winrnr.dll
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\winntbbu.dll
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\winnls.dll
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\winmsd.exe
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\winmm.dll
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\winlogon.exe
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\winipsec.dll
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\wininet.dll
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\winhttp.dll
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\winhlp32.exe
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\winfax.dll
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\windowscodecsext.dll
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\windowscodecs.dll
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\winbrand.dll
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\win87em.dll
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\win32spl.dll
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\win32k.sys
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\win.com
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\wifeman.dll
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\wiavusd.dll
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\wiavideo.dll
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\wiashext.dll
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\drivers\ws2ifsl.sys
2012-01-02 02:22:17 ----A---- C:\WINDOWS\system32\drivers\wmilib.sys
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\wiaservc.dll
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\wiascr.dll
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\wiadss.dll
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\wiadefui.dll
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\wiaacmgr.exe
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\wextract.exe
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\webvw.dll
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\webcheck.dll
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\webhits.dll
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\webclnt.dll
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\wdigest.dll
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\wavemsp.dll
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\watchdog.sys
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\w32topl.dll
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\w32tm.exe
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\w32time.dll
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\vwipxspx.exe
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\vwipxspx.dll
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\vssvc.exe
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\vssapi.dll
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\vssadmin.exe
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\vss_ps.dll
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\vjoy.dll
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\vga.dll
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\version.dll
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\verifier.exe
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\verifier.dll
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\verclsid.exe
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\ver.dll
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\vdmredir.dll
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\vdmdbg.dll
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\vcdex.dll
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\drivers\wanarp.sys
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\drivers\volsnap.sys
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\drivers\videoprt.sys
2012-01-02 02:22:16 ----A---- C:\WINDOWS\system32\drivers\vga.sys
2012-01-02 02:22:15 ----A---- C:\WINDOWS\twunk_32.exe
2012-01-02 02:22:15 ----A---- C:\WINDOWS\twunk_16.exe
2012-01-02 02:22:15 ----A---- C:\WINDOWS\twain_32.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\twain.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\w3ssl.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\vbscript.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\vbajet32.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\uxtheme.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\utilman.exe
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\utildll.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\usp10.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\userinit.exe
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\userenv.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\user32.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\user.exe
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\usbmon.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\urlmon.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\url.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\ureg.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\ups.exe
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\upnpui.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\upnphost.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\upnpcont.exe
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\upnp.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\untfs.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\unlodctr.exe
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\uniplat.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\unimdmat.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\umpnpmgr.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\umdmxfrm.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\umandlg.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\ulib.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\ufat.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\udhisapi.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\tzchange.exe
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\typeperf.exe
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\typelib.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\txflog.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\twext.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\tsddd.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\tsd32.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\tsappcmp.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\trkwks.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\tree.com
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\traffic.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\tracert6.exe
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\tracert.exe
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\tracerpt.exe
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\toolhelp.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\tlntsvr.exe
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\tlntadmn.exe
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\osuninst.dll
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\drivers\usb8023.sys
2012-01-02 02:22:15 ----A---- C:\WINDOWS\system32\drivers\udfs.sys
2012-01-02 02:22:14 ----A---- C:\WINDOWS\taskman.exe
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\tlntsvrp.dll
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\tlntsess.exe
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\themeui.dll
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\tftp.exe
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\termmgr.dll
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\telnet.exe
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\tcpsvcs.exe
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\tcpmonui.dll
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\tcpmon.ini
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\tcpmon.dll
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\tcpmib.dll
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\tcmsetup.exe
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\taskmgr.exe
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\taskman.exe
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\tasklist.exe
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\taskkill.exe
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\tapiui.dll
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\tapisrv.dll
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\tapiperf.dll
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\tapi32.dll
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\tapi3.dll
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\tapi.dll
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\t2embed.dll
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\systray.exe
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\systeminfo.exe
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\syssetup.dll
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\sysocmgr.exe
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\syskey.exe
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\sysinv.dll
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\sysedit.exe
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\syncui.dll
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\synceng.dll
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\syncapp.exe
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\sxs.dll
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\swprv.dll
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\svchost.exe
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\svcpack.dll
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\subst.exe
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\strmfilt.dll
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\storage.dll
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\stobject.dll
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\stimon.exe
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\sti_ci.dll
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\sti.dll
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\sstext3d.scr
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\ssstars.scr
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\sspipes.scr
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\ssmyst.scr
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\ssmypics.scr
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\ssmarque.scr
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\ssflwbox.scr
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\drivers\tdi.sys
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\drivers\tcpip6.sys
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2012-01-02 02:22:14 ----A---- C:\WINDOWS\system32\drivers\tape.sys
2012-01-02 02:22:13 ----A---- C:\WINDOWS\system32\ssdpsrv.dll
2012-01-02 02:22:13 ----A---- C:\WINDOWS\system32\ssdpapi.dll
2012-01-02 02:22:13 ----A---- C:\WINDOWS\system32\ssbezier.scr
2012-01-02 02:22:13 ----A---- C:\WINDOWS\system32\ss3dfo.scr
2012-01-02 02:22:13 ----A---- C:\WINDOWS\system32\srvsvc.dll
2012-01-02 02:22:13 ----A---- C:\WINDOWS\system32\sqlwoa.dll
2012-01-02 02:22:13 ----A---- C:\WINDOWS\system32\sqlwid.dll
2012-01-02 02:22:13 ----A---- C:\WINDOWS\system32\sqlunirl.dll
2012-01-02 02:22:13 ----A---- C:\WINDOWS\system32\sqlsrv32.dll
2012-01-02 02:22:13 ----A---- C:\WINDOWS\system32\sprestrt.exe
2012-01-02 02:22:13 ----A---- C:\WINDOWS\system32\spoolsv.exe
2012-01-02 02:22:13 ----A---- C:\WINDOWS\system32\spoolss.dll
2012-01-02 02:22:13 ----A---- C:\WINDOWS\system32\spiisupd.exe
2012-01-02 02:22:13 ----A---- C:\WINDOWS\system32\drivers\srv.sys
2012-01-02 02:22:12 ----A---- C:\WINDOWS\system32\sort.exe
2012-01-02 02:22:12 ----A---- C:\WINDOWS\system32\softpub.dll
2012-01-02 02:22:12 ----A---- C:\WINDOWS\system32\snmpsnap.dll
2012-01-02 02:22:12 ----A---- C:\WINDOWS\system32\snmpapi.dll
2012-01-02 02:22:12 ----A---- C:\WINDOWS\system32\smss.exe
2012-01-02 02:22:12 ----A---- C:\WINDOWS\system32\smlogsvc.exe
2012-01-02 02:22:12 ----A---- C:\WINDOWS\system32\smlogcfg.dll
2012-01-02 02:22:12 ----A---- C:\WINDOWS\system32\smbinst.exe
2012-01-02 02:22:12 ----A---- C:\WINDOWS\system32\slbrccsp.dll
2012-01-02 02:22:12 ----A---- C:\WINDOWS\system32\slbiop.dll
2012-01-02 02:22:12 ----A---- C:\WINDOWS\system32\slbcsp.dll
2012-01-02 02:22:12 ----A---- C:\WINDOWS\system32\slayerxp.dll
2012-01-02 02:22:12 ----A---- C:\WINDOWS\system32\skeys.exe
2012-01-02 02:22:12 ----A---- C:\WINDOWS\system32\skdll.dll
2012-01-02 02:22:12 ----A---- C:\WINDOWS\system32\drivers\smclib.sys
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\sisbkup.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\sigverif.exe
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\sigtab.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\schtasks.exe
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\schannel.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\shutdown.exe
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\shsvcs.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\shscrap.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\shrpubw.exe
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\shmgrate.exe
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\shlwapi.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\shimgvw.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\shimeng.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\shgina.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\shfolder.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\shell32.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\shell.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\shdocvw.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\shdoclc.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\share.exe
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\sfmapi.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\sfcfiles.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\sfc_os.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\sfc.exe
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\sfc.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\setver.exe
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\setupn.exe
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\setupdll.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\setupapi.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\setup.exe
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\sethc.exe
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\serwvdrv.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\services.msc
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\services.exe
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\serialui.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\senscfg.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\sensapi.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\sens.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\sendmail.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\sendcmsg.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\security.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\secur32.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\secupd.dat
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\secpol.msc
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\seclogon.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\secedit.exe
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\sdpblb.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\sdbinst.exe
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\scrrun.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\scrobj.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\scrnsave.scr
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\scriptpw.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\scredir.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\sclgntfy.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\scesrv.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\scecli.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\sccsccp.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\sccbase.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\scardsvr.exe
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\scardssp.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\scarddlg.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\sc.exe
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\sbeio.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\sbe.dll
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\savedump.exe
2012-01-02 02:22:11 ----A---- C:\WINDOWS\system32\drivers\secdrv.sys
2012-01-02 02:22:10 ----R---- C:\WINDOWS\system32\rsop.msc
2012-01-02 02:22:10 ----N---- C:\WINDOWS\regedit.exe
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\samsrv.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\samlib.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\runonce.exe
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rundll32.exe
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\runas.exe
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rtutils.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rtm.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rtipxmib.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rtcshare.exe
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rsvpsp.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rsvpperf.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rsvpmsg.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rsvp.ini
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rsvp.exe
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rsopprov.exe
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rsnotify.exe
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rsmui.exe
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rsmsink.exe
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rsmps.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rsm.exe
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rshx32.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rsh.exe
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rsfsaps.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rsaenh.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rpcss.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rpcrt4.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rpcns4.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\routetab.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\routemon.exe
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\route.exe
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rnr20.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\riched32.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\riched20.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rexec.exe
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\resutils.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\replace.exe
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rend.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\relog.exe
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\regwizc.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\regwiz.exe
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\regsvr32.exe
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\regsvc.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\regedt32.exe
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\regapi.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\reg.exe
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\redir.exe
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\recover.exe
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rdpdd.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rcp.exe
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rcimlby.exe
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rcbdyctl.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rastls.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rastapi.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rasser.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rassapi.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rasrad.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rasqec.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rasppp.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rasphone.exe
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rasmxs.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rasmontr.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rasmans.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rasman.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\raschap.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rasdlg.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rasdial.exe
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rasctrs.ini
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rasctrs.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rasautou.exe
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rasauto.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rasapi32.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\rasadhlp.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\qutil.dll
2012-01-02 02:22:10 ----A---- C:\WINDOWS\system32\query.dll