Stránka 1 z 2

Facebook vír

Napsal: 29 říj 2011 21:30
od ceasare
Áno aj ja som jeden z tých užívatelov čo naleteli na neaktuálny adobe flash :(

Tu je log.Prosim o kazdú radu a pomoc.Vopred velmi pekne dakujem!!!

Ak to nevadí uložil som subor na uloz.to

http://www.uloz.to/10808794/log-rar

Re: Facebook vír

Napsal: 29 říj 2011 21:37
od vyosek
Zdravim a pekny vecer preji :)

:arrow: Vlozte mi log prosim sem - klidne jej rozdelte do vice prispevku - lepe se lusti

:arrow: Stahnete RogueKiller http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
  • Ukoncete vsechny programy
  • Pokud pouzivate Win Vista ci W7, kliknete na RogueKiller pravym a dejte Run As Administrator ci Spustit jako spravce
  • Zvolte moznost 2 a potvrte enterem
  • Utilita provede svou cinnost a da log - ten sem vlozte
  • Nyni znovu, ale zvolte moznost 3 a pote jeste 4 - logy opet vlozte
PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix

Re: Facebook vír

Napsal: 29 říj 2011 21:40
od ceasare
Logfile of random's system information tool 1.09 (written by random/random)
Run by Tomino at 2011-10-29 22:17:45
Microsoft Windows 7 Ultimate
System drive C: has 36 GB (36%) free of 100 GB
Total RAM: 3959 MB (49% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:18:10, on 29. 10. 2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16869)
Boot mode: Normal

Running processes:
C:\Program Files\IObit\Smart Defrag 2\SmartDefrag.exe
C:\Program Files\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Guard.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe
C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanionInfo.exe
C:\Program Files\Stardock\ObjectDockPlus2\ObjectDock.exe
C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\IObit\Advanced SystemCare 4\PMonitor.exe
C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe
C:\Program Files\IObit\Advanced SystemCare 4\ASC.exe
C:\Program Files (x86)\Opera\opera.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files\trend micro\Tomino.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: SearchHook Class - {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll
R3 - URLSearchHook: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - (no file)
O2 - BHO: uTorrentBar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll
O3 - Toolbar: Nero Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [BCU] "C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe"
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [NBAgent] "C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE -startup
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [Google Update] "C:\Users\Tomino\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Sony Ericsson PC Companion] "C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" /Background
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Advanced SystemCare 4] "C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-4042068987-915908620-2276306216-1001\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-4042068987-915908620-2276306216-1001\..\Run: [Sony Ericsson PC Companion] "C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" /Background (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-4042068987-915908620-2276306216-1001\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDockPlus2\ObjectDock.exe
O4 - Global Startup: Rainmeter.lnk = C:\Program Files\Rainmeter\Rainmeter.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GRA32A~1.DLL
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - (no file)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Advanced SystemCare Service (AdvancedSystemCareService) - IObit - C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
O23 - Service: Ashampoo HDD Control 2 Service (AHDDC2) - Unknown owner - C:\Program Files\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Service.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AppleChargerSrv - Unknown owner - C:\Windows\system32\AppleChargerSrv.exe (file missing)
O23 - Service: Browser Configuration Utility Service (BCUService) - DeviceVM, Inc. - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe
O23 - Service: Defragmentation-Service (DfSdkS) - mst software GmbH, Germany - C:\Program Files\Ashampoo\Ashampoo HDD Control 2\DfSdkS64.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - Unknown owner - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMF Service (IMFservice) - IObit - C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Sony Ericsson PCCompanion - Avanquest Software - C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11289 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Service.exe"
"C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\Windows\system32\sppsvc.exe
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"taskhost.exe"
taskeng.exe {3F02228D-DF81-44B2-A81D-E266D727BCF5}
"C:\Program Files\IObit\Smart Defrag 2\SmartDefrag.exe" /STARTUP
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Guard.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" /Background
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files\Rainmeter\Rainmeter.exe"
"C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanionInfo.exe"
"C:\Program Files\Stardock\ObjectDockPlus2\ObjectDock.exe"
"C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart
"C:\Program Files\PowerISO\PWRISOVM.EXE" -startup
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Stardock\ObjectDockPlus2\Dock64.exe"
"C:\Program Files\Stardock\ObjectDockPlus2\ObjectDockTray.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe"
"C:\Program Files\IObit\Advanced SystemCare 4\PMonitor.exe"
"C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe"
"C:\Program Files\IObit\Advanced SystemCare 4\ASC.exe"
"C:\Program Files (x86)\Opera\opera.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\AUDIODG.EXE 0x350
"C:\Program Files (x86)\Skype\Phone\Skype.exe"
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\System32\svchost.exe -k swprv
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe17_ Global\UsGthrCtrlFltPipeMssGthrPipe17 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 512 516 524 65536 520
"C:\Users\Tomino\Desktop\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4042068987-915908620-2276306216-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4042068987-915908620-2276306216-1000UA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Tomino\AppData\Roaming\Mozilla\Firefox\Profiles\ihu3m3g2.default

prefs.js - "keyword.URL" - "http://search.yahoo.com/search?ei=utf-8 ... &ilc=12&p="

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml

C:\Users\Tomino\AppData\Roaming\Mozilla\Firefox\Profiles\ihu3m3g2.default\extensions\
{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-09-05 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
uTorrentBar Toolbar - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll [2011-05-09 176936]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Nero Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2010-02-04 1197448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - uTorrentBar Toolbar - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll [2011-05-09 176936]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Nero Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2010-02-04 1197448]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Ashampoo HDD-Control 2 Guard"=C:\Program Files\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Guard.exe [2011-09-22 3775904]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2011-08-26 12681320]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2011-09-08 4030008]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"=C:\Program Files\uTorrent\uTorrent.exe [2011-10-20 641400]
"Google Update"=C:\Users\Tomino\AppData\Local\Google\Update\GoogleUpdate.exe [2011-10-13 136176]
"Sony Ericsson PC Companion"=C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe [2011-07-25 433360]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2011-09-26 17353352]
"Advanced SystemCare 4"=C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe [2011-08-09 417112]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"BCU"=C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe [2009-10-15 375000]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2009-10-02 284696]
"NBAgent"=C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe [2010-03-26 1234216]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
"PWRISOVM.EXE"=C:\Program Files\PowerISO\PWRISOVM.EXE [2011-06-15 307200]
"amd_dc_opt"=C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [2008-07-22 77824]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Rainmeter.lnk - C:\Program Files\Rainmeter\Rainmeter.exe

C:\Users\Tomino\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Stardock ObjectDock.lnk - C:\Program Files\Stardock\ObjectDockPlus2\ObjectDock.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
ObjectDockShellExt - {1984D045-52CF-49cd-DB77-08F378FEA4DB} - C:\Program Files\Stardock\ObjectDockPlus2\ODMenu64.dll [2010-03-24 633200]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableSecureUIAPaths"=0
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

Re: Facebook vír

Napsal: 29 říj 2011 21:41
od ceasare
======List of files/folders created in the last 1 month======

2011-10-29 22:17:46 ----D---- C:\Program Files\trend micro
2011-10-29 22:17:45 ----D---- C:\rsit
2011-10-29 17:15:40 ----D---- C:\ProgramData\ESET
2011-10-29 17:15:40 ----D---- C:\Program Files\ESET
2011-10-29 17:07:37 ----D---- C:\Users\Tomino\AppData\Roaming\Malwarebytes
2011-10-29 17:07:24 ----D---- C:\ProgramData\Malwarebytes
2011-10-29 17:07:20 ----A---- C:\Windows\system32\drivers\mbam.sys
2011-10-29 16:34:24 ----D---- C:\Program Files\SUPERAntiSpyware
2011-10-29 16:23:55 ----HD---- C:\Windows\update.tray-15-0-lnk
2011-10-29 16:23:55 ----HD---- C:\Windows\update.tray-15-0
2011-10-29 16:16:33 ----HD---- C:\Windows\update.tray-7-0-lnk
2011-10-29 16:16:33 ----HD---- C:\Windows\update.tray-7-0
2011-10-29 16:14:34 ----A---- C:\Windows\system32\drivers\aswSP.sys
2011-10-29 16:14:34 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2011-10-29 16:14:34 ----A---- C:\Windows\system32\drivers\aswRdr.sys
2011-10-29 16:14:34 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2011-10-29 16:14:33 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2011-10-29 16:14:32 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2011-10-29 16:14:31 ----A---- C:\Windows\system32\aswBoot.exe
2011-10-29 16:14:15 ----A---- C:\Windows\SYSWOW64\aswBoot.exe
2011-10-29 16:14:15 ----A---- C:\Windows\avastSS.scr
2011-10-29 13:16:11 ----D---- C:\Windows\ufa
2011-10-29 13:16:11 ----D---- C:\Windows\phoenix
2011-10-29 13:16:02 ----A---- C:\Windows\iecheck_iplist.txt
2011-10-29 13:15:28 ----A---- C:\Windows\btc_client_iplist.txt
2011-10-29 13:15:19 ----HD---- C:\Windows\update.2
2011-10-29 13:15:01 ----A---- C:\Windows\unrar.exe
2011-10-29 13:14:58 ----HD---- C:\Windows\update.5.0
2011-10-29 13:14:32 ----D---- C:\Windows\av_ico
2011-10-29 13:14:26 ----A---- C:\Windows\iplist.txt
2011-10-29 13:13:57 ----A---- C:\Windows\front_ip_list.txt
2011-10-29 09:15:34 ----HD---- C:\Windows\update.1
2011-10-29 09:15:33 ----HD---- C:\Windows\update.tray-2-0-lnk
2011-10-29 09:15:33 ----HD---- C:\Windows\update.tray-2-0
2011-10-29 09:04:25 ----A---- C:\Windows\winlog-ids.txt
2011-10-29 09:04:25 ----A---- C:\Windows\winlog-dirs.txt
2011-10-26 10:54:03 ----A---- C:\Windows\system32\nvhdap64.dll
2011-10-26 10:54:03 ----A---- C:\Windows\system32\nvhdagenco6420102.dll
2011-10-26 10:54:03 ----A---- C:\Windows\system32\drivers\nvhda64v.sys
2011-10-26 10:54:00 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2011-10-26 10:54:00 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2011-10-26 10:54:00 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2011-10-26 10:54:00 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2011-10-26 10:54:00 ----A---- C:\Windows\SYSWOW64\nvcuvenc.dll
2011-10-26 10:54:00 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2011-10-26 10:54:00 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2011-10-26 10:54:00 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2011-10-26 10:54:00 ----A---- C:\Windows\system32\OpenCL.dll
2011-10-26 10:54:00 ----A---- C:\Windows\system32\nvoglv64.dll
2011-10-26 10:54:00 ----A---- C:\Windows\system32\nvd3dumx.dll
2011-10-26 10:54:00 ----A---- C:\Windows\system32\nvcuvid.dll
2011-10-26 10:54:00 ----A---- C:\Windows\system32\nvcuvenc.dll
2011-10-26 10:54:00 ----A---- C:\Windows\system32\nvcuda.dll
2011-10-26 10:54:00 ----A---- C:\Windows\system32\nvcompiler.dll
2011-10-26 10:54:00 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2011-10-26 08:29:24 ----D---- C:\Windows\SYSWOW64\RTCOM
2011-10-26 08:28:57 ----A---- C:\Windows\system32\WavesGUILib.dll
2011-10-26 08:28:56 ----A---- C:\Windows\system32\SRSWOW64.dll
2011-10-26 08:28:56 ----A---- C:\Windows\system32\SRSTSX64.dll
2011-10-26 08:28:56 ----A---- C:\Windows\system32\SRSTSH64.dll
2011-10-26 08:28:56 ----A---- C:\Windows\system32\SRSHP64.dll
2011-10-26 08:28:54 ----A---- C:\Windows\system32\RtPgEx64.dll
2011-10-26 08:28:54 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2011-10-26 08:28:53 ----A---- C:\Windows\system32\drivers\RTKVHD64.sys
2011-10-26 08:28:52 ----A---- C:\Windows\system32\RtkCfg64.dll
2011-10-26 08:28:51 ----A---- C:\Windows\system32\RtkAPO64.dll
2011-10-26 08:28:51 ----A---- C:\Windows\system32\RtkApi64.dll
2011-10-26 08:28:51 ----A---- C:\Windows\system32\RTEEP64A.dll
2011-10-26 08:28:51 ----A---- C:\Windows\system32\RTEEL64A.dll
2011-10-26 08:28:51 ----A---- C:\Windows\system32\RTEEG64A.dll
2011-10-26 08:28:51 ----A---- C:\Windows\system32\RTEED64A.dll
2011-10-26 08:28:51 ----A---- C:\Windows\system32\RTCOM64.dll
2011-10-26 08:28:50 ----A---- C:\Windows\system32\RP3DHT64.dll
2011-10-26 08:28:50 ----A---- C:\Windows\system32\RP3DAA64.dll
2011-10-26 08:28:50 ----A---- C:\Windows\system32\RCoInst64.dll
2011-10-26 08:28:48 ----A---- C:\Windows\system32\MBWrp64.dll
2011-10-26 08:28:47 ----A---- C:\Windows\system32\MBppld64.dll
2011-10-26 08:28:47 ----A---- C:\Windows\system32\MBPPCn64.dll
2011-10-26 08:28:47 ----A---- C:\Windows\system32\MBAPO64.dll
2011-10-26 08:28:46 ----A---- C:\Windows\SYSWOW64\MBAPO32.dll
2011-10-26 08:28:44 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2011-10-26 08:28:44 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2011-10-26 08:28:24 ----A---- C:\Windows\system32\FMAPO64.dll
2011-10-26 08:28:16 ----A---- C:\Windows\system32\AERTAR64.dll
2011-10-26 08:28:16 ----A---- C:\Windows\system32\AERTAC64.dll
2011-10-25 08:55:59 ----D---- C:\Program Files\Battlefield 3
2011-10-24 21:53:45 ----D---- C:\Program Files (x86)\Tajemství šesti moří
2011-10-24 21:48:32 ----D---- C:\ProgramData\DivoGames
2011-10-24 21:47:55 ----D---- C:\Program Files (x86)\Poklady starověké sluje
2011-10-24 21:41:49 ----D---- C:\Program Files (x86)\Spidla
2011-10-24 21:35:02 ----D---- C:\Program Files (x86)\Táta hrdina
2011-10-24 21:31:24 ----D---- C:\Users\Tomino\AppData\Roaming\NVIDIA
2011-10-24 21:30:55 ----D---- C:\Program Files (x86)\Ledové Drahokamy
2011-10-23 00:28:12 ----D---- C:\ProgramData\Playrix Entertainment
2011-10-23 00:26:02 ----D---- C:\Program Files (x86)\LeeGT-Games
2011-10-19 21:46:55 ----D---- C:\Program Files (x86)\Microsoft Works
2011-10-19 21:46:16 ----D---- C:\Program Files (x86)\Microsoft Visual Studio
2011-10-19 21:45:44 ----D---- C:\Windows\PCHEALTH
2011-10-19 21:44:10 ----D---- C:\Program Files\Microsoft Office
2011-10-19 21:44:04 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 8
2011-10-19 21:43:17 ----D---- C:\Program Files (x86)\Microsoft Office
2011-10-19 21:43:15 ----D---- C:\ProgramData\Microsoft Help
2011-10-19 20:57:50 ----D---- C:\ProgramData\Sony Ericsson
2011-10-19 20:57:50 ----D---- C:\Program Files (x86)\Sony Ericsson
2011-10-19 20:50:17 ----D---- C:\Users\Tomino\AppData\Roaming\Rainmeter
2011-10-19 20:49:17 ----D---- C:\Program Files\Rainmeter
2011-10-19 05:57:44 ----N---- C:\bootsqm.dat
2011-10-18 20:41:48 ----D---- C:\Program Files\Activision
2011-10-17 14:44:11 ----A---- C:\Windows\SYSWOW64\winver.exe
2011-10-17 14:44:11 ----A---- C:\Windows\SYSWOW64\user32.dll
2011-10-17 14:44:11 ----A---- C:\Windows\SYSWOW64\systemcpl.dll
2011-10-17 14:44:11 ----A---- C:\Windows\SYSWOW64\sppcomapi.dll
2011-10-17 14:44:11 ----A---- C:\Windows\SYSWOW64\slmgr.vbs
2011-10-16 15:59:19 ----D---- C:\Program Files\SlySoft
2011-10-16 15:56:37 ----D---- C:\ProgramData\Elaborate Bytes
2011-10-16 15:47:57 ----D---- C:\Program Files\Elaborate Bytes
2011-10-16 14:46:55 ----D---- C:\Program Files (x86)\AMD
2011-10-16 14:17:05 ----D---- C:\Program Files\PowerISO
2011-10-16 14:17:05 ----A---- C:\Windows\system32\drivers\scdemu.sys
2011-10-16 14:14:51 ----D---- C:\Program Files\Common Files\Adobe
2011-10-16 14:13:17 ----D---- C:\Program Files\Adobe
2011-10-16 09:24:04 ----D---- C:\Users\Tomino\AppData\Roaming\ERS G-Studio
2011-10-16 09:03:29 ----D---- C:\Program Files\Kouzelny morsky svet 3 - Dobrodruzstvi v Atlantide
2011-10-15 21:22:21 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2011-10-15 21:22:21 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2011-10-15 21:22:21 ----A---- C:\Windows\system32\XAudio2_7.dll
2011-10-15 21:22:21 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2011-10-15 21:22:20 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2011-10-15 21:22:20 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2011-10-15 21:22:20 ----A---- C:\Windows\system32\xactengine3_7.dll
2011-10-15 21:22:20 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2011-10-15 21:22:18 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2011-10-15 21:22:18 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2011-10-15 21:22:18 ----A---- C:\Windows\system32\d3dx11_43.dll
2011-10-15 21:22:18 ----A---- C:\Windows\system32\d3dcsx_43.dll
2011-10-15 21:22:17 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2011-10-15 21:22:17 ----A---- C:\Windows\system32\d3dx10_43.dll
2011-10-15 21:22:16 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2011-10-15 21:22:16 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2011-10-15 21:22:16 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2011-10-15 21:22:16 ----A---- C:\Windows\system32\XAudio2_6.dll
2011-10-15 21:22:16 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2011-10-15 21:22:16 ----A---- C:\Windows\system32\D3DX9_43.dll
2011-10-15 21:22:15 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2011-10-15 21:22:15 ----A---- C:\Windows\system32\xactengine3_6.dll
2011-10-15 21:22:14 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2011-10-15 21:22:14 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2011-10-15 21:22:13 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2011-10-15 21:22:13 ----A---- C:\Windows\system32\XAudio2_5.dll
2011-10-15 21:22:12 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2011-10-15 21:22:12 ----A---- C:\Windows\system32\xactengine3_5.dll
2011-10-15 21:22:12 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2011-10-15 21:22:11 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2011-10-15 21:22:11 ----A---- C:\Windows\system32\d3dcsx_42.dll
2011-10-15 21:22:10 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2011-10-15 21:22:10 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2011-10-15 21:22:10 ----A---- C:\Windows\system32\d3dx11_42.dll
2011-10-15 21:22:10 ----A---- C:\Windows\system32\d3dx10_42.dll
2011-10-15 21:22:09 ----A---- C:\Windows\system32\D3DX9_42.dll
2011-10-15 21:22:08 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2011-10-15 21:22:08 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2011-10-15 21:22:08 ----A---- C:\Windows\system32\d3dx10_41.dll
2011-10-15 21:22:08 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2011-10-15 21:22:07 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2011-10-15 21:22:07 ----A---- C:\Windows\system32\D3DX9_41.dll
2011-10-15 21:22:06 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2011-10-15 21:22:06 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2011-10-15 21:22:05 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2011-10-15 21:22:05 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2011-10-15 21:22:05 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2011-10-15 21:22:05 ----A---- C:\Windows\system32\XAudio2_4.dll
2011-10-15 21:22:05 ----A---- C:\Windows\system32\xactengine3_4.dll
2011-10-15 21:22:05 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2011-10-15 21:22:04 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2011-10-15 21:22:04 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2011-10-15 21:22:04 ----A---- C:\Windows\system32\d3dx10_40.dll
2011-10-15 21:22:04 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2011-10-15 21:22:03 ----A---- C:\Windows\system32\D3DX9_40.dll
2011-10-15 21:22:02 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2011-10-15 21:22:02 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2011-10-15 21:22:02 ----A---- C:\Windows\system32\XAudio2_3.dll
2011-10-15 21:22:02 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2011-10-15 21:22:01 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2011-10-15 21:22:01 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2011-10-15 21:22:01 ----A---- C:\Windows\system32\xactengine3_3.dll
2011-10-15 21:22:01 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2011-10-15 21:22:00 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2011-10-15 21:22:00 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2011-10-15 21:22:00 ----A---- C:\Windows\system32\XAudio2_2.dll
2011-10-15 21:22:00 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2011-10-15 21:21:59 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2011-10-15 21:21:59 ----A---- C:\Windows\system32\xactengine3_2.dll
2011-10-15 21:21:58 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2011-10-15 21:21:58 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2011-10-15 21:21:58 ----A---- C:\Windows\system32\d3dx10_39.dll
2011-10-15 21:21:58 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2011-10-15 21:21:57 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2011-10-15 21:21:57 ----A---- C:\Windows\system32\D3DX9_39.dll
2011-10-15 21:21:56 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2011-10-15 21:21:56 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2011-10-15 21:21:56 ----A---- C:\Windows\system32\XAudio2_1.dll
2011-10-15 21:21:56 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2011-10-15 21:21:55 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2011-10-15 21:21:55 ----A---- C:\Windows\system32\xactengine3_1.dll
2011-10-15 21:21:54 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2011-10-15 21:21:54 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2011-10-15 21:21:54 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2011-10-15 21:21:54 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2011-10-15 21:21:54 ----A---- C:\Windows\system32\d3dx10_38.dll
2011-10-15 21:21:54 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2011-10-15 21:21:53 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2011-10-15 21:21:53 ----A---- C:\Windows\system32\D3DX9_38.dll
2011-10-15 21:21:52 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2011-10-15 21:21:52 ----A---- C:\Windows\system32\XAudio2_0.dll
2011-10-15 21:21:51 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2011-10-15 21:21:51 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2011-10-15 21:21:51 ----A---- C:\Windows\system32\xactengine3_0.dll
2011-10-15 21:21:51 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2011-10-15 21:21:48 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2011-10-15 21:21:48 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2011-10-15 21:21:48 ----A---- C:\Windows\system32\d3dx10_37.dll
2011-10-15 21:21:48 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2011-10-15 21:21:47 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2011-10-15 21:21:47 ----A---- C:\Windows\system32\D3DX9_37.dll
2011-10-15 21:21:46 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2011-10-15 21:21:46 ----A---- C:\Windows\system32\xactengine2_10.dll
2011-10-15 21:21:45 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2011-10-15 21:21:45 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2011-10-15 21:21:45 ----A---- C:\Windows\system32\d3dx10_36.dll
2011-10-15 21:21:45 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2011-10-15 21:21:44 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2011-10-15 21:21:44 ----A---- C:\Windows\system32\d3dx9_36.dll
2011-10-15 21:21:43 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2011-10-15 21:21:43 ----A---- C:\Windows\system32\xactengine2_9.dll
2011-10-15 21:21:42 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2011-10-15 21:21:42 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2011-10-15 21:21:42 ----A---- C:\Windows\system32\d3dx10_35.dll
2011-10-15 21:21:42 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2011-10-15 21:21:41 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2011-10-15 21:21:41 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2011-10-15 21:21:41 ----A---- C:\Windows\system32\xactengine2_8.dll
2011-10-15 21:21:41 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2011-10-15 21:21:41 ----A---- C:\Windows\system32\d3dx9_35.dll
2011-10-15 21:21:40 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2011-10-15 21:21:40 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2011-10-15 21:21:40 ----A---- C:\Windows\system32\d3dx10_34.dll
2011-10-15 21:21:40 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2011-10-15 21:21:39 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2011-10-15 21:21:39 ----A---- C:\Windows\system32\xinput1_3.dll
2011-10-15 21:21:39 ----A---- C:\Windows\system32\d3dx9_34.dll
2011-10-15 21:21:38 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2011-10-15 21:21:38 ----A---- C:\Windows\system32\xactengine2_7.dll
2011-10-15 21:21:37 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2011-10-15 21:21:37 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2011-10-15 21:21:37 ----A---- C:\Windows\system32\d3dx10_33.dll
2011-10-15 21:21:37 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2011-10-15 21:21:36 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2011-10-15 21:21:36 ----A---- C:\Windows\system32\d3dx9_33.dll
2011-10-15 21:21:35 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2011-10-15 21:21:35 ----A---- C:\Windows\system32\xactengine2_6.dll
2011-10-15 21:21:33 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2011-10-15 21:21:33 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2011-10-15 21:21:33 ----A---- C:\Windows\system32\xactengine2_5.dll
2011-10-15 21:21:33 ----A---- C:\Windows\system32\d3dx10.dll
2011-10-15 21:21:32 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2011-10-15 21:21:32 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2011-10-15 21:21:32 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2011-10-15 21:21:32 ----A---- C:\Windows\system32\xactengine2_4.dll
2011-10-15 21:21:32 ----A---- C:\Windows\system32\x3daudio1_1.dll
2011-10-15 21:21:32 ----A---- C:\Windows\system32\d3dx9_32.dll
2011-10-15 21:21:30 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2011-10-15 21:21:30 ----A---- C:\Windows\system32\d3dx9_31.dll
2011-10-15 21:21:29 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2011-10-15 21:21:29 ----A---- C:\Windows\system32\xactengine2_3.dll
2011-10-15 21:21:28 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2011-10-15 21:21:28 ----A---- C:\Windows\system32\xinput1_2.dll
2011-10-15 21:21:27 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2011-10-15 21:21:27 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2011-10-15 21:21:27 ----A---- C:\Windows\system32\xinput1_1.dll
2011-10-15 21:21:27 ----A---- C:\Windows\system32\xactengine2_2.dll
2011-10-15 21:21:25 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2011-10-15 21:21:25 ----A---- C:\Windows\system32\xactengine2_1.dll
2011-10-15 21:21:21 ----A---- C:\Windows\system32\d3dx9_30.dll
2011-10-15 21:21:20 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2011-10-15 21:21:20 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2011-10-15 21:21:20 ----A---- C:\Windows\system32\xactengine2_0.dll
2011-10-15 21:21:20 ----A---- C:\Windows\system32\x3daudio1_0.dll
2011-10-15 21:21:19 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2011-10-15 21:21:19 ----A---- C:\Windows\system32\d3dx9_29.dll
2011-10-15 21:21:18 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2011-10-15 21:21:18 ----A---- C:\Windows\system32\d3dx9_28.dll
2011-10-15 21:21:17 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2011-10-15 21:21:17 ----A---- C:\Windows\system32\d3dx9_27.dll
2011-10-15 21:21:16 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2011-10-15 21:21:16 ----A---- C:\Windows\system32\d3dx9_26.dll
2011-10-15 21:21:12 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2011-10-15 21:21:12 ----A---- C:\Windows\system32\d3dx9_25.dll
2011-10-15 21:21:10 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2011-10-15 21:21:10 ----A---- C:\Windows\system32\d3dx9_24.dll
2011-10-15 21:16:33 ----D---- C:\Windows\SYSWOW64\directx
2011-10-15 12:10:09 ----D---- C:\Users\Tomino\AppData\Roaming\md studio
2011-10-15 12:05:30 ----D---- C:\Program Files\Bato
2011-10-15 11:23:53 ----D---- C:\ProgramData\DVD Shrink
2011-10-15 11:23:52 ----D---- C:\Program Files\DVD Shrink
2011-10-15 06:44:22 ----D---- C:\Windows\SYSWOW64\Wat
2011-10-15 06:44:22 ----D---- C:\Windows\system32\Wat
2011-10-15 00:54:52 ----A---- C:\Windows\SYSWOW64\nvStreaming.exe
2011-10-14 12:46:07 ----D---- C:\Users\Tomino\AppData\Roaming\dvdcss
2011-10-14 09:12:39 ----D---- C:\Users\Tomino\AppData\Roaming\Vso
2011-10-14 09:12:13 ----A---- C:\Windows\SYSWOW64\wvc1dmod.dll
2011-10-14 09:12:13 ----A---- C:\Windows\SYSWOW64\vp7vfw.dll
2011-10-14 09:12:13 ----A---- C:\Windows\SYSWOW64\sipr3260.dll
2011-10-14 09:12:13 ----A---- C:\Windows\SYSWOW64\Pncrt.dll
2011-10-14 09:12:13 ----A---- C:\Windows\SYSWOW64\drv43260.dll
2011-10-14 09:12:13 ----A---- C:\Windows\SYSWOW64\drv33260.dll
2011-10-14 09:12:13 ----A---- C:\Windows\SYSWOW64\drv23260.dll
2011-10-14 09:12:13 ----A---- C:\Windows\SYSWOW64\cook3260.dll
2011-10-14 09:12:12 ----D---- C:\Program Files (x86)\VSO
2011-10-14 09:12:11 ----D---- C:\Program Files\VSO
2011-10-14 00:50:08 ----D---- C:\Program Files (x86)\Adobe
2011-10-14 00:49:14 ----D---- C:\ProgramData\Adobe
2011-10-14 00:04:30 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2011-10-14 00:04:30 ----A---- C:\Windows\system32\msv1_0.dll
2011-10-13 23:59:16 ----D---- C:\Program Files (x86)\MSXML 4.0
2011-10-13 23:57:31 ----A---- C:\Windows\system32\browserchoice.exe
2011-10-13 14:12:40 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2011-10-13 14:12:40 ----A---- C:\Windows\system32\kerberos.dll
2011-10-13 14:12:35 ----A---- C:\Windows\SYSWOW64\tzres.dll
2011-10-13 14:12:35 ----A---- C:\Windows\system32\tzres.dll
2011-10-13 14:12:01 ----A---- C:\Windows\SYSWOW64\odbcjt32.dll
2011-10-13 14:12:01 ----A---- C:\Windows\system32\odbctrac.dll
2011-10-13 14:12:01 ----A---- C:\Windows\system32\odbccu32.dll
2011-10-13 14:12:01 ----A---- C:\Windows\system32\odbccr32.dll
2011-10-13 14:12:01 ----A---- C:\Windows\system32\odbccp32.dll
2011-10-13 14:12:00 ----A---- C:\Windows\SYSWOW64\odbccp32.dll
2011-10-13 14:11:59 ----A---- C:\Windows\SYSWOW64\odbctrac.dll
2011-10-13 14:11:59 ----A---- C:\Windows\SYSWOW64\odbccu32.dll
2011-10-13 14:11:59 ----A---- C:\Windows\SYSWOW64\odbccr32.dll
2011-10-13 14:11:57 ----A---- C:\Windows\SYSWOW64\asycfilt.dll
2011-10-13 14:11:57 ----A---- C:\Windows\system32\drivers\dfsc.sys
2011-10-13 14:11:57 ----A---- C:\Windows\system32\asycfilt.dll
2011-10-13 14:11:52 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2011-10-13 14:11:52 ----A---- C:\Windows\system32\poqexec.exe
2011-10-13 14:11:50 ----A---- C:\Windows\system32\CPFilters.dll
2011-10-13 14:11:48 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2011-10-13 14:11:48 ----A---- C:\Windows\SYSWOW64\CPFilters.dll
2011-10-13 14:11:48 ----A---- C:\Windows\system32\sbe.dll
2011-10-13 14:11:48 ----A---- C:\Windows\system32\EncDec.dll
2011-10-13 14:11:47 ----A---- C:\Windows\SYSWOW64\sbe.dll
2011-10-13 14:11:44 ----A---- C:\Windows\SYSWOW64\t2embed.dll
2011-10-13 14:11:44 ----A---- C:\Windows\system32\t2embed.dll
2011-10-13 14:11:42 ----A---- C:\Windows\system32\ole32.dll
2011-10-13 14:11:41 ----A---- C:\Windows\SYSWOW64\ole32.dll
2011-10-13 14:11:39 ----A---- C:\Windows\SYSWOW64\taskschd.dll
2011-10-13 14:11:39 ----A---- C:\Windows\system32\wmicmiplugin.dll
2011-10-13 14:11:39 ----A---- C:\Windows\system32\taskschd.dll
2011-10-13 14:11:39 ----A---- C:\Windows\system32\taskeng.exe
2011-10-13 14:11:39 ----A---- C:\Windows\system32\taskcomp.dll
2011-10-13 14:11:39 ----A---- C:\Windows\system32\schedsvc.dll
2011-10-13 14:11:38 ----A---- C:\Windows\system32\schtasks.exe
2011-10-13 14:11:37 ----A---- C:\Windows\SYSWOW64\taskeng.exe
2011-10-13 14:11:37 ----A---- C:\Windows\SYSWOW64\taskcomp.dll
2011-10-13 14:11:37 ----A---- C:\Windows\SYSWOW64\StructuredQuery.dll
2011-10-13 14:11:37 ----A---- C:\Windows\SYSWOW64\schtasks.exe
2011-10-13 14:11:37 ----A---- C:\Windows\system32\StructuredQuery.dll
2011-10-13 14:11:35 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2011-10-13 14:11:35 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-10-13 14:11:35 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2011-10-13 14:11:33 ----A---- C:\Windows\system32\drivers\afd.sys
2011-10-13 14:11:27 ----A---- C:\Windows\system32\CertEnroll.dll
2011-10-13 14:11:26 ----A---- C:\Windows\SYSWOW64\CertEnroll.dll
2011-10-13 14:11:14 ----A---- C:\Windows\system32\shell32.dll
2011-10-13 14:11:11 ----A---- C:\Windows\SYSWOW64\shell32.dll
2011-10-13 14:11:03 ----A---- C:\Windows\system32\win32k.sys
2011-10-13 14:10:57 ----A---- C:\Windows\SYSWOW64\schannel.dll
2011-10-13 14:10:57 ----A---- C:\Windows\system32\schannel.dll
2011-10-13 14:10:57 ----A---- C:\Windows\system32\comctl32.dll
2011-10-13 14:10:55 ----A---- C:\Windows\SYSWOW64\comctl32.dll
2011-10-13 14:10:55 ----A---- C:\Windows\system32\jscript.dll
2011-10-13 14:10:54 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2011-10-13 14:10:54 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-10-13 14:10:54 ----A---- C:\Windows\system32\vbscript.dll
2011-10-13 14:10:52 ----A---- C:\Windows\SYSWOW64\explorer.exe
2011-10-13 14:10:52 ----A---- C:\Windows\system32\winlogon.exe
2011-10-13 14:10:52 ----A---- C:\Windows\explorer.exe
2011-10-13 14:10:51 ----A---- C:\Windows\system32\mfc42u.dll
2011-10-13 14:10:51 ----A---- C:\Windows\system32\mfc42.dll
2011-10-13 14:10:50 ----A---- C:\Windows\SYSWOW64\mfc42u.dll
2011-10-13 14:10:50 ----A---- C:\Windows\SYSWOW64\mfc42.dll
2011-10-13 14:10:44 ----A---- C:\Windows\system32\ieframe.dll
2011-10-13 14:10:41 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-10-13 14:10:39 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-10-13 14:10:39 ----A---- C:\Windows\system32\mshtml.dll
2011-10-13 14:10:39 ----A---- C:\Windows\system32\iertutil.dll
2011-10-13 14:10:37 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-10-13 14:10:36 ----A---- C:\Windows\system32\urlmon.dll
2011-10-13 14:10:35 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-10-13 14:10:35 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-10-13 14:10:35 ----A---- C:\Windows\system32\wininet.dll
2011-10-13 14:10:33 ----A---- C:\Windows\SYSWOW64\mstime.dll
2011-10-13 14:10:33 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2011-10-13 14:10:33 ----A---- C:\Windows\system32\mstime.dll
2011-10-13 14:10:33 ----A---- C:\Windows\system32\msfeeds.dll
2011-10-13 14:10:32 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2011-10-13 14:10:32 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2011-10-13 14:10:32 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2011-10-13 14:10:32 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-10-13 14:10:32 ----A---- C:\Windows\system32\licmgr10.dll
2011-10-13 14:10:32 ----A---- C:\Windows\system32\iepeers.dll
2011-10-13 14:10:32 ----A---- C:\Windows\system32\iedkcs32.dll
2011-10-13 14:10:31 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2011-10-13 14:10:31 ----A---- C:\Windows\system32\url.dll
2011-10-13 14:10:31 ----A---- C:\Windows\system32\mshtmled.dll
2011-10-13 14:10:30 ----A---- C:\Windows\SYSWOW64\url.dll
2011-10-13 14:10:30 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-10-13 14:10:30 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2011-10-13 14:10:30 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2011-10-13 14:10:30 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-10-13 14:10:30 ----A---- C:\Windows\system32\msfeedssync.exe
2011-10-13 14:10:30 ----A---- C:\Windows\system32\jsproxy.dll
2011-10-13 14:10:30 ----A---- C:\Windows\system32\ieui.dll
2011-10-13 14:09:49 ----A---- C:\Windows\SYSWOW64\rtutils.dll
2011-10-13 14:09:49 ----A---- C:\Windows\system32\rtutils.dll
2011-10-13 14:09:39 ----A---- C:\Windows\system32\spoolsv.exe
2011-10-13 14:09:38 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2011-10-13 14:09:38 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2011-10-13 14:09:38 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2011-10-13 14:09:38 ----A---- C:\Windows\system32\fontsub.dll
2011-10-13 14:09:38 ----A---- C:\Windows\system32\atmlib.dll
2011-10-13 14:09:38 ----A---- C:\Windows\system32\atmfd.dll
2011-10-13 14:09:36 ----A---- C:\Windows\SYSWOW64\webio.dll
2011-10-13 14:09:36 ----A---- C:\Windows\system32\webio.dll
2011-10-13 14:09:35 ----A---- C:\Windows\SYSWOW64\iccvid.dll
2011-10-13 14:09:09 ----A---- C:\Windows\SYSWOW64\dnscacheugc.exe
2011-10-13 14:09:09 ----A---- C:\Windows\SYSWOW64\dnsapi.dll
2011-10-13 14:09:09 ----A---- C:\Windows\system32\dnsrslvr.dll
2011-10-13 14:09:09 ----A---- C:\Windows\system32\dnscacheugc.exe
2011-10-13 14:09:09 ----A---- C:\Windows\system32\dnsapi.dll
2011-10-13 14:09:07 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-10-13 14:09:07 ----A---- C:\Windows\system32\cdd.dll
2011-10-13 14:08:48 ----A---- C:\Windows\SYSWOW64\wmpmde.dll
2011-10-13 14:08:48 ----A---- C:\Windows\system32\wmpmde.dll
2011-10-13 14:08:47 ----A---- C:\Windows\SYSWOW64\quartz.dll
2011-10-13 14:08:47 ----A---- C:\Windows\SYSWOW64\msvidc32.dll
2011-10-13 14:08:47 ----A---- C:\Windows\SYSWOW64\mciavi32.dll
2011-10-13 14:08:47 ----A---- C:\Windows\SYSWOW64\avifil32.dll
2011-10-13 14:08:47 ----A---- C:\Windows\system32\tsbyuv.dll
2011-10-13 14:08:47 ----A---- C:\Windows\system32\quartz.dll
2011-10-13 14:08:47 ----A---- C:\Windows\system32\msyuv.dll
2011-10-13 14:08:47 ----A---- C:\Windows\system32\msvidc32.dll
2011-10-13 14:08:47 ----A---- C:\Windows\system32\msrle32.dll
2011-10-13 14:08:47 ----A---- C:\Windows\system32\iyuv_32.dll
2011-10-13 14:08:46 ----A---- C:\Windows\SYSWOW64\tsbyuv.dll
2011-10-13 14:08:46 ----A---- C:\Windows\SYSWOW64\msyuv.dll
2011-10-13 14:08:46 ----A---- C:\Windows\SYSWOW64\msrle32.dll
2011-10-13 14:08:46 ----A---- C:\Windows\SYSWOW64\iyuv_32.dll
2011-10-13 14:08:45 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-10-13 14:08:45 ----A---- C:\Windows\system32\drivers\srv.sys
2011-10-13 14:08:44 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-10-13 14:08:43 ----A---- C:\Windows\SYSWOW64\psisdecd.dll
2011-10-13 14:08:43 ----A---- C:\Windows\system32\psisdecd.dll
2011-10-13 14:08:39 ----A---- C:\Windows\system32\ntdll.dll
2011-10-13 14:08:38 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2011-10-13 14:08:25 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2011-10-13 14:08:25 ----A---- C:\Windows\system32\msxml3.dll
2011-10-13 14:08:22 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2011-10-13 14:08:22 ----A---- C:\Windows\SYSWOW64\secur32.dll
2011-10-13 14:08:22 ----A---- C:\Windows\system32\lsasrv.dll
2011-10-13 14:08:22 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2011-10-13 14:07:43 ----A---- C:\Windows\system32\winresume.exe
2011-10-13 14:07:43 ----A---- C:\Windows\system32\winload.exe
2011-10-13 14:07:42 ----A---- C:\Windows\system32\kdusb.dll
2011-10-13 14:07:42 ----A---- C:\Windows\system32\kdcom.dll
2011-10-13 14:07:42 ----A---- C:\Windows\system32\kd1394.dll
2011-10-13 14:07:38 ----A---- C:\Windows\SYSWOW64\mfc40u.dll
2011-10-13 14:07:38 ----A---- C:\Windows\SYSWOW64\mfc40.dll
2011-10-13 14:07:32 ----A---- C:\Windows\SYSWOW64\msasn1.dll
2011-10-13 14:07:32 ----A---- C:\Windows\system32\msasn1.dll
2011-10-13 14:07:31 ----A---- C:\Windows\system32\KernelBase.dll
2011-10-13 14:07:30 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2011-10-13 14:07:30 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2011-10-13 14:07:30 ----A---- C:\Windows\system32\wow64win.dll
2011-10-13 14:07:30 ----A---- C:\Windows\system32\wow64.dll
2011-10-13 14:07:30 ----A---- C:\Windows\system32\winsrv.dll
2011-10-13 14:07:30 ----A---- C:\Windows\system32\kernel32.dll
2011-10-13 14:07:30 ----A---- C:\Windows\system32\conhost.exe
2011-10-13 14:07:29 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-10-13 14:07:29 ----A---- C:\Windows\SYSWOW64\setup16.exe
2011-10-13 14:07:29 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2011-10-13 14:07:29 ----A---- C:\Windows\system32\ntvdm64.dll
2011-10-13 14:07:28 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2011-10-13 14:07:28 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2011-10-13 14:07:28 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2011-10-13 14:07:28 ----A---- C:\Windows\SYSWOW64\wow32.dll
2011-10-13 14:07:28 ----A---- C:\Windows\SYSWOW64\instnm.exe
2011-10-13 14:07:28 ----A---- C:\Windows\system32\wow64cpu.dll
2011-10-13 14:07:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2011-10-13 14:07:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2011-10-13 14:07:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2011-10-13 14:07:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-10-13 14:07:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2011-10-13 14:07:27 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-10-13 14:07:27 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-10-13 14:07:27 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-10-13 14:07:27 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-10-13 14:07:27 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2011-10-13 14:07:27 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2011-10-13 14:07:27 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-10-13 14:07:27 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2011-10-13 14:07:27 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2011-10-13 14:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2011-10-13 14:07:25 ----A---- C:\Windows\SYSWOW64\user.exe
2011-10-13 14:07:06 ----A---- C:\Windows\system32\umpnpmgr.dll
2011-10-13 14:07:05 ----A---- C:\Windows\SYSWOW64\drvinst.exe
2011-10-13 14:07:05 ----A---- C:\Windows\SYSWOW64\devrtl.dll
2011-10-13 14:07:05 ----A---- C:\Windows\SYSWOW64\devobj.dll
2011-10-13 14:07:05 ----A---- C:\Windows\SYSWOW64\cfgmgr32.dll
2011-10-13 14:07:02 ----A---- C:\Windows\system32\mstscax.dll
2011-10-13 14:07:01 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2011-10-13 14:07:01 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2011-10-13 14:07:01 ----A---- C:\Windows\system32\mstsc.exe
2011-10-13 14:06:54 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-10-13 14:06:44 ----A---- C:\Windows\system32\wmp.dll
2011-10-13 14:06:42 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2011-10-13 14:06:42 ----A---- C:\Windows\SYSWOW64\wmp.dll
2011-10-13 14:06:41 ----A---- C:\Windows\system32\wmploc.DLL
2011-10-13 14:06:27 ----A---- C:\Windows\system32\FXSCOVER.exe
2011-10-13 14:06:26 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2011-10-13 14:06:26 ----A---- C:\Windows\system32\inetcomm.dll
2011-10-13 14:06:24 ----A---- C:\Windows\system32\consent.exe
2011-10-13 14:06:22 ----A---- C:\Windows\system32\drivers\bowser.sys
2011-10-13 14:06:21 ----A---- C:\Windows\system32\oleaut32.dll
2011-10-13 14:06:21 ----A---- C:\Windows\system32\oleacc.dll
2011-10-13 14:06:20 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2011-10-13 14:06:20 ----A---- C:\Windows\SYSWOW64\oleacc.dll
2011-10-13 14:06:18 ----A---- C:\Windows\system32\odbc32.dll
2011-10-13 14:06:17 ----A---- C:\Windows\SYSWOW64\odbc32.dll
2011-10-13 14:06:04 ----A---- C:\Windows\SYSWOW64\sscore.dll
2011-10-13 14:06:04 ----A---- C:\Windows\system32\srvsvc.dll
2011-10-13 14:06:02 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-10-13 14:06:00 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2011-10-13 14:06:00 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2011-10-13 12:30:37 ----D---- C:\Program Files\Audiograbber
2011-10-13 08:14:23 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2011-10-13 08:09:56 ----A---- C:\Windows\SYSWOW64\PresentationHostProxy.dll
2011-10-13 08:09:56 ----A---- C:\Windows\SYSWOW64\PresentationHost.exe
2011-10-13 08:09:56 ----A---- C:\Windows\SYSWOW64\netfxperf.dll
2011-10-13 08:09:56 ----A---- C:\Windows\SYSWOW64\mscoree.dll
2011-10-13 08:09:56 ----A---- C:\Windows\SYSWOW64\dfshim.dll
2011-10-13 08:09:56 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2011-10-13 08:09:56 ----A---- C:\Windows\system32\PresentationHost.exe
2011-10-13 08:09:56 ----A---- C:\Windows\system32\netfxperf.dll
2011-10-13 08:09:56 ----A---- C:\Windows\system32\mscoree.dll
2011-10-13 08:09:56 ----A---- C:\Windows\system32\dfshim.dll
2011-10-13 08:06:14 ----D---- C:\Program Files\Ant Movie Catalog
2011-10-13 01:32:47 ----D---- C:\Users\Tomino\AppData\Roaming\vlc
2011-10-13 01:03:36 ----D---- C:\Program Files\Thoosje
2011-10-13 00:49:17 ----D---- C:\Program Files\Cesta za dobrodružstvím - Kouzelné obrazy
2011-10-13 00:48:16 ----D---- C:\Program Files\Filipova dobrodružství - Na stopě rodinným pokladům
2011-10-13 00:47:41 ----D---- C:\Program Files\Feng Šuej Mahjong
2011-10-13 00:46:57 ----D---- C:\Program Files\Egyptský míč
2011-10-13 00:46:23 ----D---- C:\Program Files\Dobrý farmář
2011-10-13 00:44:26 ----D---- C:\Program Files\Alex Kočičák
2011-10-13 00:43:53 ----D---- C:\Program Files\Alenka 2 - Kouzelná země
2011-10-13 00:42:32 ----D---- C:\Program Files\Ledova kralovna 3 - Vrani carodejka
2011-10-13 00:41:18 ----D---- C:\Program Files\Zachraň Kamarády!
2011-10-13 00:40:45 ----D---- C:\Program Files\Výprava do Květinové země
2011-10-13 00:40:14 ----D---- C:\Program Files\Polární dobrodružství 2
2011-10-13 00:39:41 ----D---- C:\Program Files\Nádherná zahrada
2011-10-13 00:39:06 ----D---- C:\Program Files\Mořské dobrodružství
2011-10-13 00:38:14 ----D---- C:\Program Files\Medvěd Míša - Zakletý hrad
2011-10-13 00:37:39 ----D---- C:\Program Files\Medvěd Míša - Cesta kolem světa
2011-10-13 00:36:33 ----D---- C:\Program Files\Medvěd Míša ve vesmíru
2011-10-13 00:27:57 ----D---- C:\Users\Tomino\AppData\Roaming\Nero
2011-10-13 00:22:03 ----D---- C:\Program Files\Mozilla Firefox
2011-10-13 00:05:55 ----D---- C:\ProgramData\Nero
2011-10-13 00:05:22 ----D---- C:\Program Files (x86)\Nero
2011-10-12 23:58:19 ----D---- C:\Program Files (x86)\Ask.com
2011-10-12 23:57:39 ----D---- C:\Program Files (x86)\Microsoft.NET
2011-10-12 23:57:19 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2011-10-12 23:57:01 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2011-10-12 23:56:43 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2011-10-12 23:56:25 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2011-10-12 23:56:07 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2011-10-12 23:55:49 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2011-10-12 23:45:59 ----A---- C:\Windows\system32\SmartDefragBootTime.exe
2011-10-12 23:45:59 ----A---- C:\Windows\system32\drivers\SmartDefragDriver.sys
2011-10-12 23:45:47 ----D---- C:\ProgramData\IObit
2011-10-12 23:45:16 ----D---- C:\Program Files (x86)\IObit Toolbar
2011-10-12 23:45:16 ----D---- C:\Program Files (x86)\Application Updater
2011-10-12 23:43:55 ----D---- C:\Users\Tomino\AppData\Roaming\IObit
2011-10-12 23:43:53 ----D---- C:\Program Files\IObit
2011-10-12 23:42:56 ----A---- C:\Windows\system32\DfSdkBt.exe
2011-10-12 23:42:53 ----D---- C:\Program Files\Ashampoo
2011-10-12 23:40:44 ----D---- C:\Program Files\Media Player Classic - Home Cinema
2011-10-12 23:39:39 ----D---- C:\Program Files\VideoLAN
2011-10-12 23:38:31 ----D---- C:\Program Files\TNod User & Password Finder
2011-10-12 23:37:42 ----A---- C:\Windows\system32\drivers\netio.sys
2011-10-12 23:12:33 ----D---- C:\Users\Tomino\AppData\Roaming\URSoft
2011-10-12 23:12:33 ----AD---- C:\ProgramData\TEMP
2011-10-12 23:12:31 ----D---- C:\Program Files\Your Uninstaller! 7
2011-10-12 23:03:28 ----D---- C:\Users\Tomino\AppData\Roaming\Stardock
2011-10-12 23:02:53 ----HDC---- C:\ProgramData\{0F4A7EFE-5950-4389-BF36-1E625D72456B}
2011-10-12 23:02:53 ----D---- C:\ProgramData\Stardock
2011-10-12 23:02:52 ----D---- C:\Program Files\Stardock
2011-10-12 22:57:28 ----D---- C:\Program Files (x86)\Conduit
2011-10-12 22:57:27 ----D---- C:\Program Files (x86)\uTorrentBar
2011-10-12 22:57:22 ----D---- C:\Program Files\uTorrent
2011-10-12 22:56:30 ----D---- C:\Users\Tomino\AppData\Roaming\uTorrent
2011-10-12 22:55:59 ----A---- C:\Program Files\zipnew.dat
2011-10-12 22:55:59 ----A---- C:\Program Files\rarnew.dat
2011-10-12 22:55:57 ----D---- C:\Program Files\Formats
2011-10-12 22:55:57 ----A---- C:\Program Files\WinRAR.exe
2011-10-12 22:55:57 ----A---- C:\Program Files\WhatsNew.txt
2011-10-12 22:55:57 ----A---- C:\Program Files\UnrarSrc.txt
2011-10-12 22:55:57 ----A---- C:\Program Files\UnRAR.exe
2011-10-12 22:55:57 ----A---- C:\Program Files\Uninstall.exe
2011-10-12 22:55:57 ----A---- C:\Program Files\TechNote.txt
2011-10-12 22:55:57 ----A---- C:\Program Files\ReadMe.txt
2011-10-12 22:55:57 ----A---- C:\Program Files\RarExt64.dll
2011-10-12 22:55:57 ----A---- C:\Program Files\RarExt.dll
2011-10-12 22:55:57 ----A---- C:\Program Files\Rar.txt
2011-10-12 22:55:57 ----A---- C:\Program Files\Rar.exe
2011-10-12 22:55:57 ----A---- C:\Program Files\License.txt
2011-10-12 22:55:35 ----D---- C:\Users\Tomino\AppData\Roaming\WinRAR
2011-10-12 22:55:31 ----D---- C:\Program Files (x86)\WinRAR
2011-10-12 22:55:25 ----D---- C:\Program Files\7-Zip
2011-10-12 22:37:07 ----D---- C:\Windows\Panther
2011-10-12 22:36:39 ----D---- C:\Windows\system32\OEM
2011-10-12 22:36:26 ----RD---- C:\Hry E
2011-10-12 22:29:15 ----D---- C:\Windows.old
2011-10-12 21:02:24 ----D---- C:\Users\Tomino\AppData\Roaming\Skype
2011-10-12 21:02:21 ----RD---- C:\Program Files (x86)\Skype
2011-10-12 21:02:19 ----D---- C:\ProgramData\Skype
2011-10-12 16:19:21 ----D---- C:\ProgramData\Aliasworlds
2011-10-12 16:10:37 ----D---- C:\Program Files (x86)\Mořské dobrodružství
2011-10-12 16:07:09 ----D---- C:\Users\Tomino\AppData\Roaming\SecretIslandEng
2011-10-12 16:03:28 ----D---- C:\Program Files (x86)\Katčin Rybí krámek
2011-10-12 16:00:34 ----D---- C:\ProgramData\Friday's games
2011-10-12 16:00:25 ----D---- C:\Program Files (x86)\Nádherná zahrada
2011-10-12 15:56:24 ----D---- C:\Users\Tomino\AppData\Roaming\Alawar
2011-10-12 15:56:14 ----D---- C:\Program Files (x86)\Zachraň Kamarády!
2011-10-12 15:55:33 ----D---- C:\Program Files (x86)\Výprava do Květinové země
2011-10-12 15:55:01 ----D---- C:\ProgramData\Alawar Stargaze
2011-10-12 15:54:54 ----D---- C:\Program Files (x86)\Polární dobrodružství 2
2011-10-12 15:47:29 ----D---- C:\Program Files (x86)\Bambulky
2011-10-12 15:45:41 ----D---- C:\Users\Tomino\AppData\Roaming\EleFun Games
2011-10-12 15:38:57 ----D---- C:\Users\Tomino\AppData\Roaming\Špidla Data Processing, s.r.o
2011-10-12 15:38:57 ----D---- C:\ProgramData\Špidla Data Processing, s.r.o
2011-10-12 15:38:49 ----D---- C:\Program Files (x86)\Filipova dobrodružství - Na stopě rodinným pokladům
2011-10-12 15:35:04 ----D---- C:\ProgramData\VirtualFarm
2011-10-12 15:29:59 ----D---- C:\Users\Tomino\AppData\Roaming\V-Games
2011-10-12 15:19:25 ----D---- C:\ProgramData\Alex Gordon
2011-10-12 15:19:17 ----D---- C:\ProgramData\AlawarWrapper
2011-10-12 15:16:43 ----D---- C:\Users\Tomino\AppData\Roaming\URSE Games
2011-10-12 15:16:22 ----D---- C:\Program Files (x86)\Ledova kralovna 3 - Vrani carodejka
2011-10-12 14:54:35 ----D---- C:\Users\Tomino\AppData\Roaming\Artogon
2011-10-12 14:54:29 ----D---- C:\Program Files (x86)\Cesta za dobrodruzstvim - Nadesel cas
2011-10-12 14:18:13 ----D---- C:\Users\Tomino\AppData\Roaming\Mozilla
2011-10-12 14:06:42 ----D---- C:\Users\Tomino\AppData\Roaming\Macromedia
2011-10-12 14:06:42 ----D---- C:\Users\Tomino\AppData\Roaming\Adobe
2011-10-12 14:06:41 ----D---- C:\Windows\SYSWOW64\Macromed
2011-10-12 13:31:56 ----D---- C:\Users\Tomino\AppData\Roaming\Intel Corporation
2011-10-12 13:23:18 ----A---- C:\Windows\GVTDrv64.sys
2011-10-12 13:23:03 ----A---- C:\Windows\gdrv.sys
2011-10-12 13:22:42 ----D---- C:\ProgramData\NVIDIA
2011-10-12 13:22:40 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2011-10-12 13:21:44 ----A---- C:\Windows\system32\nvvsvc.exe
2011-10-12 13:21:44 ----A---- C:\Windows\system32\nvsvcr.dll
2011-10-12 13:21:44 ----A---- C:\Windows\system32\nvsvc64.dll
2011-10-12 13:21:44 ----A---- C:\Windows\system32\nvshext.dll
2011-10-12 13:21:44 ----A---- C:\Windows\system32\nvmctray.dll
2011-10-12 13:21:44 ----A---- C:\Windows\system32\nvcpl.dll
2011-10-12 13:21:44 ----A---- C:\Windows\system32\easyupdatusapiu64.dll
2011-10-12 13:21:36 ----D---- C:\ProgramData\NVIDIA Corporation
2011-10-12 13:21:04 ----A---- C:\Windows\system32\nvhdagenco642040.dll
2011-10-12 13:21:03 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2011-10-12 13:21:03 ----A---- C:\Windows\system32\nvwgf2umx.dll
2011-10-12 13:21:03 ----A---- C:\Windows\system32\nvgenco64.dll
2011-10-12 13:21:03 ----A---- C:\Windows\system32\nvdispco64.dll
2011-10-12 13:21:03 ----A---- C:\Windows\system32\nvapi64.dll
2011-10-12 13:17:33 ----D---- C:\Program Files\NVIDIA Corporation
2011-10-12 13:11:29 ----N---- C:\Windows\system32\MpSigStub.exe
2011-10-12 13:09:47 ----D---- C:\Program Files\SuperOvladac
2011-10-12 13:06:13 ----D---- C:\Users\Tomino\AppData\Roaming\Opera
2011-10-12 13:06:11 ----D---- C:\Program Files (x86)\Opera
2011-10-12 13:03:32 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2011-10-12 13:03:32 ----A---- C:\Windows\system32\wintrust.dll
2011-10-12 13:03:31 ----A---- C:\Windows\SYSWOW64\cabview.dll
2011-10-12 13:03:31 ----A---- C:\Windows\system32\cabview.dll
2011-10-12 13:02:03 ----D---- C:\Program Files\GIGABYTE
2011-10-12 13:02:03 ----D---- C:\Program Files (x86)\GIGABYTE
2011-10-12 13:02:03 ----A---- C:\Windows\system32\drivers\AppleCharger.sys
2011-10-12 13:02:03 ----A---- C:\Windows\system32\AppleChargerSrv.exe
2011-10-12 13:01:30 ----A---- C:\Windows\system32\drivers\iaStor.sys
2011-10-12 13:01:28 ----D---- C:\Users\Tomino\AppData\Roaming\InstallShield
2011-10-12 13:01:27 ----D---- C:\ProgramData\InstallShield
2011-10-12 13:00:57 ----A---- C:\Windows\system32\RTNUninst64.dll
2011-10-12 13:00:57 ----A---- C:\Windows\system32\RtNicProp64.dll
2011-10-12 13:00:57 ----A---- C:\Windows\system32\drivers\Rt64win7.sys
2011-10-12 13:00:21 ----D---- C:\Program Files\Realtek
2011-10-12 12:59:52 ----D---- C:\Program Files (x86)\Realtek
2011-10-12 12:59:51 ----HD---- C:\Program Files (x86)\Temp
2011-10-12 12:59:51 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-10-12 12:59:49 ----A---- C:\Windows\RtlExUpd.dll
2011-10-12 12:59:39 ----A---- C:\Windows\SYSWOW64\log.txt
2011-10-12 12:58:57 ----D---- C:\Program Files (x86)\Intel
2011-10-12 12:58:57 ----A---- C:\Windows\SYSWOW64\CSVer.dll
2011-10-12 12:58:42 ----HD---- C:\Program Files (x86)\DeviceVM
2011-10-12 12:58:36 ----SHD---- C:\Windows\Installer
2011-10-12 12:58:10 ----A---- C:\Windows\GSetup.ini
2011-10-12 12:54:20 ----D---- C:\Users\Tomino\AppData\Roaming\Identities
2011-10-12 12:54:03 ----SD---- C:\Users\Tomino\AppData\Roaming\Microsoft
2011-10-12 12:54:03 ----D---- C:\Users\Tomino\AppData\Roaming\Media Center Programs
2011-10-12 12:41:03 ----D---- C:\Windows\SoftwareDistribution
2011-10-12 12:38:20 ----D---- C:\Windows\Prefetch

======List of files/folders modified in the last 1 month======

2011-10-29 22:17:46 ----RD---- C:\Program Files
2011-10-29 22:17:23 ----D---- C:\Windows\Temp
2011-10-29 22:13:01 ----HD---- C:\ProgramData
2011-10-29 22:13:01 ----D---- C:\Windows\Tasks
2011-10-29 22:13:01 ----D---- C:\Windows\system32\Tasks
2011-10-29 22:12:37 ----D---- C:\Windows\system32\catroot2
2011-10-29 22:12:29 ----SHD---- C:\System Volume Information
2011-10-29 21:17:19 ----D---- C:\Windows\System32
2011-10-29 21:17:19 ----D---- C:\Windows\inf
2011-10-29 21:17:19 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-10-29 21:16:41 ----D---- C:\Windows
2011-10-29 21:02:59 ----D---- C:\Windows\system32\config
2011-10-29 20:44:21 ----D---- C:\Windows\system32\NDF
2011-10-29 20:28:12 ----D---- C:\Config.Msi
2011-10-29 20:00:56 ----D---- C:\Windows\SYSWOW64\drivers
2011-10-29 17:17:13 ----D---- C:\Windows\system32\DriverStore
2011-10-29 17:17:13 ----D---- C:\Windows\system32\drivers
2011-10-29 17:17:13 ----D---- C:\Windows\system32\catroot
2011-10-29 16:14:32 ----D---- C:\Windows\SysWOW64
2011-10-29 13:16:18 ----D---- C:\Windows\system32\drivers\etc
2011-10-24 21:53:45 ----RD---- C:\Program Files (x86)
2011-10-24 15:55:03 ----D---- C:\Windows\LiveKernelReports
2011-10-24 07:46:11 ----D---- C:\Windows\Logs
2011-10-19 21:47:58 ----RSD---- C:\Windows\assembly
2011-10-19 21:47:53 ----D---- C:\Windows\winsxs
2011-10-19 21:46:42 ----D---- C:\Program Files (x86)\MSBuild
2011-10-19 21:46:16 ----D---- C:\Program Files (x86)\Common Files
2011-10-19 21:46:12 ----D---- C:\Windows\ShellNew
2011-10-19 21:45:54 ----RSD---- C:\Windows\Fonts
2011-10-19 21:45:44 ----SD---- C:\ProgramData\Microsoft
2011-10-19 21:45:05 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-10-19 21:43:50 ----A---- C:\Windows\win.ini
2011-10-19 20:59:53 ----D---- C:\Windows\system32\drivers\UMDF
2011-10-19 04:39:09 ----D---- C:\Windows\debug
2011-10-17 14:37:35 ----D---- C:\Windows\SYSWOW64\oobe
2011-10-17 05:41:26 ----D---- C:\Windows\rescache
2011-10-17 01:07:32 ----D---- C:\Windows\system32\wdi
2011-10-16 14:14:51 ----D---- C:\Program Files\Common Files
2011-10-15 21:21:04 ----D---- C:\Windows\Microsoft.NET
2011-10-14 00:15:23 ----D---- C:\Windows\SYSWOW64\sk-SK
2011-10-14 00:15:23 ----D---- C:\Windows\SYSWOW64\en-US
2011-10-14 00:15:23 ----D---- C:\Windows\SYSWOW64\cs-CZ
2011-10-14 00:15:23 ----D---- C:\Windows\system32\sk-SK
2011-10-14 00:15:23 ----D---- C:\Windows\system32\en-US
2011-10-14 00:15:23 ----D---- C:\Windows\system32\cs-CZ
2011-10-14 00:15:17 ----D---- C:\Windows\ehome
2011-10-14 00:15:15 ----D---- C:\Program Files\Windows Mail
2011-10-14 00:15:15 ----D---- C:\Program Files (x86)\Windows Mail
2011-10-14 00:15:13 ----D---- C:\Program Files\Internet Explorer
2011-10-14 00:15:13 ----D---- C:\Program Files (x86)\Internet Explorer
2011-10-14 00:15:12 ----D---- C:\Windows\SYSWOW64\migration
2011-10-14 00:15:12 ----D---- C:\Windows\system32\migration
2011-10-14 00:15:04 ----D---- C:\Windows\system32\Boot
2011-10-14 00:15:03 ----D---- C:\Windows\AppPatch
2011-10-14 00:15:01 ----D---- C:\Program Files\Windows Media Player
2011-10-14 00:15:01 ----D---- C:\Program Files (x86)\Windows Media Player
2011-10-13 01:03:52 ----D---- C:\Windows\system32\oobe
2011-10-13 00:55:03 ----A---- C:\Windows\system32\uxtheme.dll
2011-10-13 00:55:00 ----A---- C:\Windows\system32\themeui.dll
2011-10-13 00:54:58 ----A---- C:\Windows\system32\themeservice.dll
2011-10-12 13:22:42 ----RD---- C:\Users
2011-10-12 13:21:43 ----D---- C:\Windows\Help
2011-10-12 13:02:03 ----D---- C:\Windows\Downloaded Program Files
2011-10-12 13:00:04 ----D---- C:\Windows\system32\restore
2011-10-12 12:54:17 ----SHD---- C:\$Recycle.Bin
2011-10-12 12:52:37 ----D---- C:\Windows\Setup
2011-10-12 12:52:09 ----SHD---- C:\Recovery
2011-10-12 12:52:09 ----D---- C:\Windows\system32\Recovery
2011-10-12 12:47:59 ----D---- C:\Windows\system32\CodeIntegrity
2011-10-12 12:41:00 ----D---- C:\Windows\system32\sysprep
2011-10-12 12:38:44 ----D---- C:\Windows\CSC

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2009-10-02 537112]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 SmartDefragDriver;SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [2010-11-26 17720]
R1 AppleCharger;AppleCharger; C:\Windows\system32\DRIVERS\AppleCharger.sys [2010-04-27 21544]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2011-08-04 146432]
R1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2011-06-15 93240]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2011-08-09 202576]
R2 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2007-01-27 13520]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2011-08-04 137144]
R3 AnyDVD;AnyDVD; C:\Windows\System32\Drivers\AnyDVD.sys [2007-01-27 53960]
R3 ElbyDelay;ElbyDelay; C:\Windows\System32\Drivers\ElbyDelay.sys [2006-12-14 14032]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2011-08-30 3069032]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2011-07-08 174184]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2010-03-04 346144]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2011-10-12 25640]
S3 GVTDrv64;GVTDrv64; \??\C:\Windows\GVTDrv64.sys [2011-10-12 30528]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
S3 s1039bus;Sony Ericsson Device 1039 driver (WDM); C:\Windows\system32\DRIVERS\s1039bus.sys [2010-03-01 127600]
S3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s1039mdfl.sys [2010-03-01 19568]
S3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s1039mdm.sys [2010-03-01 161904]
S3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s1039mgmt.sys [2010-03-01 141424]
S3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS); C:\Windows\system32\DRIVERS\s1039nd5.sys [2010-03-01 34416]
S3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s1039obex.sys [2010-03-01 137328]
S3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM); C:\Windows\system32\DRIVERS\s1039unic.sys [2010-03-01 158320]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R2 AdvancedSystemCareService;Advanced SystemCare Service; C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe [2011-08-09 328536]
R2 AHDDC2;Ashampoo HDD Control 2 Service; C:\Program Files\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Service.exe [2011-09-22 1515936]
R2 BCUService;Browser Configuration Utility Service; C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2009-10-15 223464]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2011-09-08 974944]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-10-02 13336]
R2 IMFservice;IMF Service; C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe [2011-07-20 820568]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2009-09-30 268824]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2011-10-15 1640768]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-15 2253120]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-15 381248]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-09-30 2320920]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 AppleChargerSrv;AppleChargerSrv; C:\Windows\system32\AppleChargerSrv.exe [2010-04-06 31272]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 DfSdkS;Defragmentation-Service; C:\Program Files\Ashampoo\Ashampoo HDD Control 2\DfSdkS64.exe [2009-08-24 544768]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe []
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion; C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-06-29 155344]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-10-15 1255736]
S4 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]

-----------------EOF-----------------

Re: Facebook vír

Napsal: 29 říj 2011 22:18
od ceasare
Takze tu su logi od roguekiller

moznost 2

RogueKiller V6.1.5 [10/29/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: hxxp://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User: Tomino [Admin rights]
Mode: Remove -- Date : 10/29/2011 22:50:34

Bad processes: 0

Registry Entries: 3
[HJ] HKLM\[...]\System : EnableLUA (0) -> REPLACED ()
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED ()
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED ()

Particular Files / Folders:

Driver: [NOT LOADED]

HOSTS File:
127.0.0.1 localhost
127.0.0.1 facebook.com
127.0.0.1 www.facebook.com
127.0.0.1 af-za.facebook.com
127.0.0.1 az-az.facebook.com
127.0.0.1 id-id.facebook.com
127.0.0.1 ms-my.facebook.com
127.0.0.1 bs-ba.facebook.com
127.0.0.1 ca-es.facebook.com
127.0.0.1 cs-cz.facebook.com
127.0.0.1 cy-gb.facebook.com
127.0.0.1 da-dk.facebook.com
127.0.0.1 de-de.facebook.com
127.0.0.1 et-ee.facebook.com
127.0.0.1 en-gb.facebook.com
127.0.0.1 es-la.facebook.com
127.0.0.1 eo-eo.facebook.com
127.0.0.1 eu-es.facebook.com
127.0.0.1 tl-ph.facebook.com
127.0.0.1 fo-fo.facebook.com
[...]


Finished : << RKreport[1].txt >>
RKreport[1].txt

možnosť 3

RogueKiller V6.1.5 [10/29/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: hxxp://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User: Tomino [Admin rights]
Mode: HOSTSFix -- Date : 10/29/2011 22:51:09

Bad processes: 0

Driver: [NOT LOADED]

HOSTS File:
127.0.0.1 localhost
127.0.0.1 facebook.com
127.0.0.1 www.facebook.com
127.0.0.1 af-za.facebook.com
127.0.0.1 az-az.facebook.com
127.0.0.1 id-id.facebook.com
127.0.0.1 ms-my.facebook.com
127.0.0.1 bs-ba.facebook.com
127.0.0.1 ca-es.facebook.com
127.0.0.1 cs-cz.facebook.com
127.0.0.1 cy-gb.facebook.com
127.0.0.1 da-dk.facebook.com
127.0.0.1 de-de.facebook.com
127.0.0.1 et-ee.facebook.com
127.0.0.1 en-gb.facebook.com
127.0.0.1 es-la.facebook.com
127.0.0.1 eo-eo.facebook.com
127.0.0.1 eu-es.facebook.com
127.0.0.1 tl-ph.facebook.com
127.0.0.1 fo-fo.facebook.com
[...]


Resetted HOSTS:
127.0.0.1 localhost

Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt


možnosť 4

RogueKiller V6.1.5 [10/29/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: hxxp://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User: Tomino [Admin rights]
Mode: ProxyFix -- Date : 10/29/2011 22:51:25

Bad processes: 0

Driver: [NOT LOADED]

Registry Entries: 0

Finished : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt

Re: Facebook vír

Napsal: 29 říj 2011 22:19
od ceasare
Log z Combofix

ComboFix 11-10-29.05 - Tomino . 10. 2011 22:55:39.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.421.1051.18.3959.2245 [GMT 2:00]
Running from: c:\users\Tomino\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Tomino\AppData\Local\Temp\SAS3113.tmp
c:\windows\phoenix
c:\windows\phoenix\kernels\phatk\__init__.py
c:\windows\phoenix\kernels\phatk\__init__.pyc
c:\windows\phoenix\kernels\phatk\BFIPatcher.py
c:\windows\phoenix\kernels\phatk\BFIPatcher.pyc
c:\windows\phoenix\kernels\phatk\kernel.cl
c:\windows\phoenix\kernels\poclbm\__init__.py
c:\windows\phoenix\kernels\poclbm\__init__.pyc
c:\windows\phoenix\kernels\poclbm\BFIPatcher.py
c:\windows\phoenix\kernels\poclbm\BFIPatcher.pyc
c:\windows\phoenix\kernels\poclbm\kernel.cl
c:\windows\phoenix\phoenix.exe
c:\windows\update.1
c:\windows\update.2
c:\windows\update.5.0
.
.
((((((((((((((((((((((((( Files Created from 2011-09-28 to 2011-10-29 )))))))))))))))))))))))))))))))
.
.
2011-10-29 21:03 . 2011-10-29 21:03 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-10-29 20:17 . 2011-10-29 20:18 -------- d-----w- c:\program files\trend micro
2011-10-29 20:17 . 2011-10-29 20:29 -------- d-----w- C:\rsit
2011-10-29 15:15 . 2011-10-29 15:15 -------- d-----w- c:\program files\ESET
2011-10-29 15:07 . 2011-10-29 15:07 -------- d-----w- c:\programdata\Malwarebytes
2011-10-29 15:07 . 2011-08-31 15:00 25416 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-10-29 14:34 . 2011-10-29 20:13 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-10-29 14:23 . 2011-10-29 14:44 -------- d--h--w- c:\windows\update.tray-15-0
2011-10-29 14:23 . 2011-10-29 14:23 -------- d--h--w- c:\windows\update.tray-15-0-lnk
2011-10-29 14:16 . 2011-10-29 18:32 -------- d--h--w- c:\windows\update.tray-7-0-lnk
2011-10-29 14:16 . 2011-10-29 14:44 -------- d--h--w- c:\windows\update.tray-7-0
2011-10-29 14:14 . 2011-01-05 16:12 489552 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-10-29 14:14 . 2011-01-05 16:12 272976 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-10-29 14:14 . 2011-01-05 16:08 29264 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-10-29 14:14 . 2011-01-05 16:08 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-10-29 14:14 . 2011-01-05 16:11 51792 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-10-29 14:14 . 2011-01-05 16:08 62032 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-10-29 14:14 . 2011-01-05 16:19 237168 ----a-w- c:\windows\system32\aswBoot.exe
2011-10-29 14:14 . 2011-01-05 16:19 38848 ----a-w- c:\windows\avastSS.scr
2011-10-29 14:14 . 2011-01-05 16:19 188216 ----a-w- c:\windows\SysWow64\aswBoot.exe
2011-10-29 11:16 . 2011-10-29 14:52 -------- d-----w- c:\windows\ufa
2011-10-29 11:15 . 2011-10-29 11:16 246272 ----a-w- c:\windows\unrar.exe
2011-10-29 11:14 . 2011-10-29 14:26 -------- d-----w- c:\windows\av_ico
2011-10-29 07:15 . 2011-10-29 18:15 -------- d--h--w- c:\windows\update.tray-2-0-lnk
2011-10-29 07:15 . 2011-10-29 14:44 -------- d--h--w- c:\windows\update.tray-2-0
2011-10-26 06:29 . 2011-10-26 06:29 -------- d-----w- c:\windows\SysWow64\RTCOM
2011-10-25 06:55 . 2011-10-25 07:36 -------- d-----w- c:\program files\Battlefield 3
2011-10-24 19:53 . 2011-10-24 19:53 -------- d-----w- c:\program files (x86)\Tajemství šesti moří
2011-10-24 19:48 . 2011-10-24 19:48 -------- d-----w- c:\programdata\DivoGames
2011-10-24 19:47 . 2011-10-24 19:48 -------- d-----w- c:\program files (x86)\Poklady starověké sluje
2011-10-24 19:41 . 2011-10-24 19:41 -------- d-----w- c:\program files (x86)\Spidla
2011-10-24 19:35 . 2011-10-24 19:37 -------- d-----w- c:\program files (x86)\Táta hrdina
2011-10-24 19:30 . 2011-10-24 19:31 -------- d-----w- c:\program files (x86)\Ledové Drahokamy
2011-10-22 22:28 . 2011-10-22 22:28 -------- d-----w- c:\programdata\Playrix Entertainment
2011-10-22 22:26 . 2011-10-22 22:26 -------- d-----w- c:\program files (x86)\LeeGT-Games
2011-10-19 19:46 . 2011-10-19 19:46 -------- d-----w- c:\program files (x86)\Microsoft Works
2011-10-19 19:45 . 2011-10-19 19:45 -------- d-----w- c:\windows\PCHEALTH
2011-10-19 19:44 . 2011-10-19 19:44 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 8
2011-10-19 19:43 . 2011-10-19 19:48 -------- d-----w- c:\programdata\Microsoft Help
2011-10-19 18:57 . 2011-10-19 18:57 -------- d-----w- c:\programdata\Sony Ericsson
2011-10-19 18:57 . 2011-10-19 18:57 -------- d-----w- c:\program files (x86)\Sony Ericsson
2011-10-19 18:49 . 2011-10-19 18:50 -------- d-----w- c:\program files\Rainmeter
2011-10-18 18:41 . 2011-10-22 17:09 -------- d-----w- c:\program files\Activision
2011-10-17 12:44 . 2011-10-17 12:44 2048 ----a-w- c:\windows\SysWow64\winver.exe
2011-10-17 12:44 . 2011-10-17 12:44 833024 ----a-w- c:\windows\SysWow64\user32.dll
2011-10-17 12:44 . 2011-10-17 12:44 410624 ----a-w- c:\windows\SysWow64\systemcpl.dll
2011-10-17 12:44 . 2011-10-17 12:44 1536 ----a-w- c:\windows\SysWow64\sppcomapi.dll
2011-10-17 12:44 . 2011-10-17 12:44 113543 ----a-w- c:\windows\SysWow64\slmgr.vbs
2011-10-16 13:59 . 2011-10-16 13:59 -------- d-----w- c:\program files\SlySoft
2011-10-16 13:56 . 2011-10-16 13:56 -------- d-----w- c:\programdata\Elaborate Bytes
2011-10-16 13:47 . 2011-10-16 13:47 -------- d-----w- c:\program files\Elaborate Bytes
2011-10-16 12:46 . 2011-10-16 12:46 -------- d-----w- c:\program files (x86)\AMD
2011-10-16 12:17 . 2011-10-16 12:17 -------- d-----w- c:\program files\PowerISO
2011-10-16 12:17 . 2011-06-15 08:30 93240 ----a-w- c:\windows\system32\drivers\scdemu.sys
2011-10-16 12:14 . 2011-10-16 12:14 -------- d-----w- c:\program files\Common Files\Adobe
2011-10-16 07:03 . 2011-10-16 07:03 -------- d-----w- c:\program files\Kouzelny morsky svet 3 - Dobrodruzstvi v Atlantide
2011-10-15 19:21 . 2008-07-31 08:41 238088 ----a-w- c:\windows\SysWow64\xactengine3_2.dll
2011-10-15 10:05 . 2011-10-15 10:09 -------- d-----w- c:\program files\Bato
2011-10-15 09:23 . 2011-10-15 09:23 -------- d-----w- c:\programdata\DVD Shrink
2011-10-15 09:23 . 2011-10-15 09:23 -------- d-----w- c:\program files\DVD Shrink
2011-10-15 04:44 . 2011-10-15 04:44 -------- d-----w- c:\windows\SysWow64\Wat
2011-10-15 04:44 . 2011-10-15 04:44 -------- d-----w- c:\windows\system32\Wat
2011-10-14 22:54 . 2011-10-14 22:54 321856 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2011-10-14 07:12 . 2010-02-09 14:37 65602 ----a-w- c:\windows\SysWow64\cook3260.dll
2011-10-14 07:12 . 2010-02-09 14:37 626688 ----a-w- c:\windows\SysWow64\vp7vfw.dll
2011-10-14 07:12 . 2010-02-09 14:37 217127 ----a-w- c:\windows\SysWow64\drv43260.dll
2011-10-14 07:12 . 2010-02-09 14:37 208935 ----a-w- c:\windows\SysWow64\drv33260.dll
2011-10-14 07:12 . 2010-02-09 14:37 176165 ----a-w- c:\windows\SysWow64\drv23260.dll
2011-10-14 07:12 . 2010-02-09 14:37 1184984 ----a-w- c:\windows\SysWow64\wvc1dmod.dll
2011-10-14 07:12 . 2010-02-09 14:37 102439 ----a-w- c:\windows\SysWow64\sipr3260.dll
2011-10-14 07:12 . 2011-10-14 07:12 -------- d-----w- c:\program files (x86)\VSO
2011-10-14 07:12 . 2011-10-14 07:12 -------- d-----w- c:\program files\VSO
2011-10-14 06:17 . 2011-09-21 07:00 9049936 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7CDFC904-F5B8-4ED4-8060-60432DD6B53C}\mpengine.dll
2011-10-13 22:55 . 2011-10-18 15:55 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2011-10-13 22:50 . 2011-10-13 22:50 -------- d-----w- c:\program files (x86)\Common Files\Adobe AIR
2011-10-13 22:04 . 2009-09-10 06:28 311808 ----a-w- c:\windows\system32\msv1_0.dll
2011-10-13 22:04 . 2009-09-10 05:52 257024 ----a-w- c:\windows\SysWow64\msv1_0.dll
2011-10-13 21:59 . 2011-10-13 21:59 -------- d-----w- c:\program files (x86)\MSXML 4.0
2011-10-13 21:57 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2011-10-13 12:12 . 2010-12-18 06:11 714752 ----a-w- c:\windows\system32\kerberos.dll
2011-10-13 12:12 . 2010-12-18 05:29 541184 ----a-w- c:\windows\SysWow64\kerberos.dll
2011-10-13 12:12 . 2011-07-09 05:14 2048 ----a-w- c:\windows\system32\tzres.dll
2011-10-13 12:12 . 2011-07-09 04:30 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-10-13 12:12 . 2011-06-15 09:58 212992 ----a-w- c:\windows\system32\odbctrac.dll
2011-10-13 12:12 . 2011-06-15 09:58 163840 ----a-w- c:\windows\system32\odbccp32.dll
2011-10-13 12:12 . 2011-06-15 09:58 106496 ----a-w- c:\windows\system32\odbccu32.dll
2011-10-13 12:12 . 2011-06-15 09:58 106496 ----a-w- c:\windows\system32\odbccr32.dll
2011-10-13 12:12 . 2011-06-15 09:58 126976 ----a-w- c:\program files\Common Files\System\Ole DB\msdaosp.dll
2011-10-13 12:12 . 2011-06-15 09:04 319488 ----a-w- c:\windows\SysWow64\odbcjt32.dll
2011-10-13 12:12 . 2011-06-15 09:04 122880 ----a-w- c:\windows\SysWow64\odbccp32.dll
2011-10-13 12:10 . 2010-08-21 06:36 340992 ----a-w- c:\windows\system32\schannel.dll
2011-10-13 12:09 . 2010-06-19 06:53 52224 ----a-w- c:\windows\system32\rtutils.dll
2011-10-13 12:08 . 2010-08-21 06:38 1024512 ----a-w- c:\windows\system32\wmpmde.dll
2011-10-13 12:07 . 2011-02-05 12:41 640896 ----a-w- c:\windows\system32\winload.efi
2011-10-13 12:06 . 2011-06-21 06:27 1896832 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-10-13 10:30 . 2011-10-13 10:30 -------- d-----w- c:\program files\Audiograbber
2011-10-13 06:09 . 2009-11-25 19:47 49472 ----a-w- c:\windows\SysWow64\netfxperf.dll
2011-10-13 06:09 . 2009-11-25 19:47 297808 ----a-w- c:\windows\SysWow64\mscoree.dll
2011-10-13 06:09 . 2009-11-25 19:47 99176 ----a-w- c:\windows\SysWow64\PresentationHostProxy.dll
2011-10-13 06:09 . 2009-11-25 19:47 48960 ----a-w- c:\windows\system32\netfxperf.dll
2011-10-13 06:09 . 2009-11-25 19:47 295264 ----a-w- c:\windows\SysWow64\PresentationHost.exe
2011-10-13 06:09 . 2009-11-25 19:47 1130824 ----a-w- c:\windows\SysWow64\dfshim.dll
2011-10-13 06:09 . 2009-11-25 19:47 109912 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2011-10-13 06:09 . 2009-11-25 19:47 444752 ----a-w- c:\windows\system32\mscoree.dll
2011-10-13 06:09 . 2009-11-25 19:47 320352 ----a-w- c:\windows\system32\PresentationHost.exe
2011-10-13 06:09 . 2009-11-25 19:47 1942856 ----a-w- c:\windows\system32\dfshim.dll
2011-10-13 06:06 . 2011-10-13 06:06 -------- d-----w- c:\program files\Ant Movie Catalog
2011-10-12 23:03 . 2011-10-12 23:03 -------- d-----w- c:\program files\Thoosje
2011-10-12 22:55 . 2009-07-14 01:41 332288 ----a-w- c:\windows\system32\uxtheme.dll.backup
2011-10-12 22:55 . 2009-07-14 01:41 2851328 ----a-w- c:\windows\system32\themeui.dll.backup
2011-10-12 22:54 . 2009-07-14 01:41 44544 ----a-w- c:\windows\system32\themeservice.dll.backup
2011-10-12 22:49 . 2011-10-13 15:40 -------- d-----w- c:\program files\Cesta za dobrodružstvím - Kouzelné obrazy
2011-10-12 22:48 . 2011-10-12 22:48 -------- d-----w- c:\program files\Filipova dobrodružství - Na stopě rodinným pokladům
2011-10-12 22:47 . 2011-10-12 22:47 -------- d-----w- c:\program files\Feng Šuej Mahjong
2011-10-12 22:46 . 2011-10-14 09:19 -------- d-----w- c:\program files\Egyptský míč
2011-10-12 22:46 . 2011-10-12 22:46 -------- d-----w- c:\program files\Dobrý farmář
2011-10-12 22:44 . 2011-10-12 22:44 -------- d-----w- c:\program files\Alex Kočičák
2011-10-12 22:43 . 2011-10-12 22:44 -------- d-----w- c:\program files\Alenka 2 - Kouzelná země
2011-10-12 22:42 . 2011-10-12 22:43 -------- d-----w- c:\program files\Ledova kralovna 3 - Vrani carodejka
2011-10-12 22:41 . 2011-10-20 11:11 -------- d-----w- c:\program files\Zachraň Kamarády!
2011-10-12 22:40 . 2011-10-12 22:40 -------- d-----w- c:\program files\Výprava do Květinové země
2011-10-12 22:40 . 2011-10-18 23:26 -------- d-----w- c:\program files\Polární dobrodružství 2
2011-10-12 22:39 . 2011-10-12 22:39 -------- d-----w- c:\program files\Nádherná zahrada
2011-10-12 22:39 . 2011-10-12 22:39 -------- d-----w- c:\program files\Mořské dobrodružství
2011-10-12 22:38 . 2011-10-12 22:38 -------- d-----w- c:\program files\Medvěd Míša - Zakletý hrad
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-12 22:55 . 2009-07-13 23:55 332288 ----a-w- c:\windows\system32\uxtheme.dll
2011-10-12 22:55 . 2009-07-13 23:54 2851328 ----a-w- c:\windows\system32\themeui.dll
2011-10-12 22:54 . 2009-07-13 23:54 44544 ----a-w- c:\windows\system32\themeservice.dll
2011-08-09 11:57 . 2011-08-09 11:57 202576 ----a-w- c:\windows\system32\drivers\eamonm.sys
2011-08-04 07:20 . 2011-08-04 07:20 146432 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2011-08-04 07:20 . 2011-08-04 07:20 137144 ----a-w- c:\windows\system32\drivers\epfwwfpr.sys
2011-08-12 06:34 . 2011-10-12 22:22 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2010-11-20 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
[7] 2009-07-14 . 72D7B3EA16946E8F0CF7458150031CC6 . 1008640 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[-] 2009-07-14 . E573BD9AB55C8E333C202B9E255F972E . 1008640 . . [6.1.7600.16385] .. c:\windows\system32\user32.dll
.
[-] 2011-10-17 . 2C9CC9F492CA596B1B9FC1AE5E916356 . 833024 . . [6.1.7600.16385] .. c:\windows\SysWOW64\user32.dll
[7] 2010-11-20 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[7] 2009-07-14 . E8B0FFC209E504CB7E79FC24E6C085F0 . 833024 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\prxtbuTor.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
2011-05-09 09:49 176936 ----a-w- c:\program files (x86)\uTorrentBar\prxtbuTor.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-02-04 14:50 1197448 ----a-w- c:\program files (x86)\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\prxtbuTor.dll" [2011-05-09 176936]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files (x86)\Ask.com\GenericAskToolbar.dll" [2010-02-04 1197448]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2011-10-20 641400]
"Sony Ericsson PC Companion"="c:\program files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" [2011-07-25 433360]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-09-26 17353352]
"Advanced SystemCare 4"="c:\program files\IObit\Advanced SystemCare 4\ASCTray.exe" [2011-08-09 417112]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"BCU"="c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe" [2009-10-15 375000]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2009-10-02 284696]
"NBAgent"="c:\program files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" [2010-03-26 1234216]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2011-06-15 307200]
"amd_dc_opt"="c:\program files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
.
c:\users\Tomino\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDockPlus2\ObjectDock.exe [2011-10-12 4142448]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Rainmeter.lnk - c:\program files\Rainmeter\Rainmeter.exe [2010-6-13 113664]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
"DisableThumbnailCache"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe [x]
R3 DfSdkS;Defragmentation-Service;c:\program files\Ashampoo\Ashampoo HDD Control 2\DfSdkS64.exe [2009-08-24 544768]
R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys [2011-10-12 30528]
R3 s1039bus;Sony Ericsson Device 1039 driver (WDM);c:\windows\system32\DRIVERS\s1039bus.sys [x]
R3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s1039mdfl.sys [x]
R3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s1039mdm.sys [x]
R3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s1039mgmt.sys [x]
R3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS);c:\windows\system32\DRIVERS\s1039nd5.sys [x]
R3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s1039obex.sys [x]
R3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM);c:\windows\system32\DRIVERS\s1039unic.sys [x]
R3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-06-29 155344]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys [x]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\IObit\Advanced SystemCare 4\ASCService.exe [2011-08-09 328536]
S2 AHDDC2;Ashampoo HDD Control 2 Service;c:\program files\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Service.exe [2011-09-22 1515936]
S2 BCUService;Browser Configuration Utility Service;c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2009-10-15 223464]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2011-09-08 974944]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-10-02 13336]
S2 IMFservice;IMF Service;c:\program files\IObit\IObit Malware Fighter\IMFsrv.exe [2011-07-20 820568]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-15 2253120]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-14 381248]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-09-30 2320920]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4042068987-915908620-2276306216-1000Core.job
- c:\users\Tomino\AppData\Local\Google\Update\GoogleUpdate.exe [2011-10-12 22:22]
.
2011-10-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4042068987-915908620-2276306216-1000UA.job
- c:\users\Tomino\AppData\Local\Google\Update\GoogleUpdate.exe [2011-10-12 22:22]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ashampoo HDD-Control 2 Guard"="c:\program files\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Guard.exe" [2011-09-22 3775904]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-08-26 12681320]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-09-08 4030008]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984D045-52CF-49cd-DB77-08F378FEA4DB}"= "c:\program files\Stardock\ObjectDockPlus2\ODMenu64.dll" [2010-03-24 633200]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 80.242.44.36 80.242.44.85
FF - ProfilePath - c:\users\Tomino\AppData\Roaming\Mozilla\Firefox\Profiles\ihu3m3g2.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=utf-8&fr=greentree_ff1&type=685749&ilc=12&p=
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - c:\program files\Alwil Software\Avast5\ashShA64.dll
AddRemove-avast5 - c:\program files\Alwil Software\Avast5\aswRunDll.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files\IObit\Smart Defrag 2\SmartDefrag.exe
c:\program files\IObit\Advanced SystemCare 4\PMonitor.exe
c:\program files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanionInfo.exe
.
**************************************************************************
.
Completion time: 2011-10-29 23:14:21 - machine was rebooted
ComboFix-quarantined-files.txt 2011-10-29 21:14
.
Pre-Run: 37 186 691 072 bytes free
Post-Run: 37 014 114 304 bytes free
.
- - End Of File - - 0ED9DA0D6749D3E426DA4A4731311697

Re: Facebook vír

Napsal: 30 říj 2011 07:28
od ceasare
Všetko v pohode?

Re: Facebook vír

Napsal: 30 říj 2011 10:52
od vyosek
:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    Folder::
    c:\windows\update.tray-15-0
    c:\windows\update.tray-15-0-lnk
    c:\windows\update.tray-7-0-lnk
    c:\windows\update.tray-7-0c:\windows\ufa
    c:\windows\av_ico
    c:\windows\update.tray-2-0-lnk
    c:\windows\update.tray-2-0
    c:\program files (x86)\uTorrentBar
    c:\program files (x86)\Ask.com
    c:\program files\IObit
    
    File::
    c:\windows\unrar.exe
    c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4042068987-915908620-2276306216-1000Core.job
    c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4042068987-915908620-2276306216-1000UA.job
    
    Restore::
    c:\windows\system32\user32.dll
    c:\windows\SysWOW64\user32.dll
    
    Registry::
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"=-
    [-HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
    [-HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
    [-HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
    "{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"=-
    "{D4027C7F-154A-4066-A1AD-4243D8127440}"= -
    [-HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
    [-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
    [-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "uTorrent"=-
    "Sony Ericsson PC Companion"=-
    "Skype"=-
    "Advanced SystemCare 4"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "NBAgent"=-
    "Adobe ARM"=-
    "PWRISOVM.EXE"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "FirewallOverride"=dword:00000000
    "DisableThumbnailCache"=dword:00000000
    
    Driver::
    AdvancedSystemCareService
    
    Firefox::
    FF - ProfilePath - c:\users\Tomino\AppData\Roaming\Mozilla\Firefox\Profiles\ihu3m3g2.default\
    FF - prefs.js: browser.search.selectedEngine - Yahoo
    FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=utf-8 ... &ilc=12&p=
    
    RegLock::
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    
    Reboot::
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci

Re: Facebook vír

Napsal: 30 říj 2011 11:59
od ceasare
ComboFix 11-10-30.01 - Tomino . 10. 2011 11:42:47.2.4 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.421.1051.18.3959.2082 [GMT 1:00]
Running from: c:\users\Tomino\Desktop\ComboFix.exe
Command switches used :: c:\users\Tomino\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4042068987-915908620-2276306216-1000Core.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4042068987-915908620-2276306216-1000UA.job"
"c:\windows\unrar.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Ask.com
c:\program files (x86)\Ask.com\cobrand.ico
c:\program files (x86)\Ask.com\config.xml
c:\program files (x86)\Ask.com\favicon.ico
c:\program files (x86)\Ask.com\GenericAskToolbar.dll
c:\program files (x86)\Ask.com\mupcfg.xml
c:\program files (x86)\Ask.com\SaUpdate.exe
c:\program files (x86)\Ask.com\UpdateTask.exe
c:\program files (x86)\uTorrentBar
c:\program files (x86)\uTorrentBar\GottenAppsContextMenu.xml
c:\program files (x86)\uTorrentBar\ldrtbuTor.dll
c:\program files (x86)\uTorrentBar\OtherAppsContextMenu.xml
c:\program files (x86)\uTorrentBar\prxtbuTor.dll
c:\program files (x86)\uTorrentBar\SharedAppsContextMenu.xml
c:\program files (x86)\uTorrentBar\tbuTor.dll
c:\program files (x86)\uTorrentBar\toolbar.cfg
c:\program files (x86)\uTorrentBar\ToolbarContextMenu.xml
c:\program files (x86)\uTorrentBar\uninstall.exe
c:\program files (x86)\uTorrentBar\uTorrentBarToolbarHelper.exe
c:\program files\IObit
c:\program files\IObit\Advanced SystemCare 4\About.dll
c:\program files\IObit\Advanced SystemCare 4\ASC.exe
c:\program files\IObit\Advanced SystemCare 4\ASCInit.exe
c:\program files\IObit\Advanced SystemCare 4\ASCService.exe
c:\program files\IObit\Advanced SystemCare 4\ASCTray.exe
c:\program files\IObit\Advanced SystemCare 4\ASCv4ComputerMenu.dll
c:\program files\IObit\Advanced SystemCare 4\ASCv4ComputerMenu_64.dll
c:\program files\IObit\Advanced SystemCare 4\ASCv4ExtMenu.dll
c:\program files\IObit\Advanced SystemCare 4\ASCv4ExtMenu_64.dll
c:\program files\IObit\Advanced SystemCare 4\AutoCare.exe
c:\program files\IObit\Advanced SystemCare 4\AutoSweep.exe
c:\program files\IObit\Advanced SystemCare 4\AutoUpdate.exe
c:\program files\IObit\Advanced SystemCare 4\cxLibraryD12.bpl
c:\program files\IObit\Advanced SystemCare 4\datastate.dll
c:\program files\IObit\Advanced SystemCare 4\Def.dbd
c:\program files\IObit\Advanced SystemCare 4\DiskMap.dll
c:\program files\IObit\Advanced SystemCare 4\DiskScan.exe
c:\program files\IObit\Advanced SystemCare 4\DiskScan.log
c:\program files\IObit\Advanced SystemCare 4\DriverData.db
c:\program files\IObit\Advanced SystemCare 4\dxBarD12.bpl
c:\program files\IObit\Advanced SystemCare 4\dxComnD12.bpl
c:\program files\IObit\Advanced SystemCare 4\dxCoreD12.bpl
c:\program files\IObit\Advanced SystemCare 4\dxDockingD12.bpl
c:\program files\IObit\Advanced SystemCare 4\dxGDIPlusD12.bpl
c:\program files\IObit\Advanced SystemCare 4\dxSkinOffice2007BlueD12.bpl
c:\program files\IObit\Advanced SystemCare 4\dxSkinsCoreD12.bpl
c:\program files\IObit\Advanced SystemCare 4\dxThemeD12.bpl
c:\program files\IObit\Advanced SystemCare 4\Error_Log.txt
c:\program files\IObit\Advanced SystemCare 4\EULA.rtf
c:\program files\IObit\Advanced SystemCare 4\fav.ico
c:\program files\IObit\Advanced SystemCare 4\FfSweep.dll
c:\program files\IObit\Advanced SystemCare 4\Freeware\FreeSoftwareDownload\DefragSetup.exe
c:\program files\IObit\Advanced SystemCare 4\Freeware\FreeSoftwareDownload\GameBoosterSetup.exe
c:\program files\IObit\Advanced SystemCare 4\Freeware\FreeSoftwareDownload\IObitMalwareFighterSetup.exe
c:\program files\IObit\Advanced SystemCare 4\help.html
c:\program files\IObit\Advanced SystemCare 4\ChangeType.exe
c:\program files\IObit\Advanced SystemCare 4\checkinfo.txt
c:\program files\IObit\Advanced SystemCare 4\images\dcScreen.png
c:\program files\IObit\Advanced SystemCare 4\images\dcScreen2.png
c:\program files\IObit\Advanced SystemCare 4\images\icon-dc.png
c:\program files\IObit\Advanced SystemCare 4\images\icon-qc.png
c:\program files\IObit\Advanced SystemCare 4\images\icon-tb.png
c:\program files\IObit\Advanced SystemCare 4\images\icon-tbox.png
c:\program files\IObit\Advanced SystemCare 4\images\main.png
c:\program files\IObit\Advanced SystemCare 4\images\mainPro.png
c:\program files\IObit\Advanced SystemCare 4\images\toolboxscreen.png
c:\program files\IObit\Advanced SystemCare 4\images\turboboost.png
c:\program files\IObit\Advanced SystemCare 4\IObitCommunities.exe
c:\program files\IObit\Advanced SystemCare 4\Language\Arabic.lng
c:\program files\IObit\Advanced SystemCare 4\Language\Belarusian.lng
c:\program files\IObit\Advanced SystemCare 4\Language\Bulgarian.lng
c:\program files\IObit\Advanced SystemCare 4\Language\Czech.lng
c:\program files\IObit\Advanced SystemCare 4\Language\Danish.lng
c:\program files\IObit\Advanced SystemCare 4\Language\Dutch.lng
c:\program files\IObit\Advanced SystemCare 4\Language\English.lng
c:\program files\IObit\Advanced SystemCare 4\Language\French.lng
c:\program files\IObit\Advanced SystemCare 4\Language\German.lng
c:\program files\IObit\Advanced SystemCare 4\Language\Greek.lng
c:\program files\IObit\Advanced SystemCare 4\Language\Hungarian.lng
c:\program files\IObit\Advanced SystemCare 4\Language\ChineseSimp.lng
c:\program files\IObit\Advanced SystemCare 4\Language\ChineseTrad.lng
c:\program files\IObit\Advanced SystemCare 4\Language\Italian.lng
c:\program files\IObit\Advanced SystemCare 4\Language\Japanese.lng
c:\program files\IObit\Advanced SystemCare 4\Language\Korean.lng
c:\program files\IObit\Advanced SystemCare 4\Language\Polish.lng
c:\program files\IObit\Advanced SystemCare 4\Language\Portuguese(PT-BR).lng
c:\program files\IObit\Advanced SystemCare 4\Language\Russian.lng
c:\program files\IObit\Advanced SystemCare 4\Language\Serbian.lng
c:\program files\IObit\Advanced SystemCare 4\Language\Spanish.lng
c:\program files\IObit\Advanced SystemCare 4\Language\Swedish.lng
c:\program files\IObit\Advanced SystemCare 4\Language\Turkish.lng
c:\program files\IObit\Advanced SystemCare 4\Language\Vietnamese.lng
c:\program files\IObit\Advanced SystemCare 4\LatestNews\imagenews.png
c:\program files\IObit\Advanced SystemCare 4\LatestNews\LatestNews.ini
c:\program files\IObit\Advanced SystemCare 4\License.dat
c:\program files\IObit\Advanced SystemCare 4\LicenseConverter.exe
c:\program files\IObit\Advanced SystemCare 4\NtfsData.dll
c:\program files\IObit\Advanced SystemCare 4\OFCommon.dll
c:\program files\IObit\Advanced SystemCare 4\OFCommon3.dll
c:\program files\IObit\Advanced SystemCare 4\PMonitor.exe
c:\program files\IObit\Advanced SystemCare 4\Register.exe
c:\program files\IObit\Advanced SystemCare 4\RescueCenter.exe
c:\program files\IObit\Advanced SystemCare 4\rtl120.bpl
c:\program files\IObit\Advanced SystemCare 4\Scan.dll
c:\program files\IObit\Advanced SystemCare 4\services.ini
c:\program files\IObit\Advanced SystemCare 4\sqlite3.dll
c:\program files\IObit\Advanced SystemCare 4\StartMenu.exe
c:\program files\IObit\Advanced SystemCare 4\Suc10_RegistryCleaner.exe
c:\program files\IObit\Advanced SystemCare 4\Suc11_PrivacySweeper.exe
c:\program files\IObit\Advanced SystemCare 4\Suc12_Uninstal.exe
c:\program files\IObit\Advanced SystemCare 4\Suc13_DiskCleaner.exe
c:\program files\IObit\Advanced SystemCare 4\Suc14_FileShredder.exe
c:\program files\IObit\Advanced SystemCare 4\Sun10_ClonedFilesScanner.exe
c:\program files\IObit\Advanced SystemCare 4\Sun11_DiskExplorer.exe
c:\program files\IObit\Advanced SystemCare 4\Sun12_SystemInformation.exe
c:\program files\IObit\Advanced SystemCare 4\Sun13_EmptyFoldersScanner.exe
c:\program files\IObit\Advanced SystemCare 4\Sun14_SystemControl.exe
c:\program files\IObit\Advanced SystemCare 4\Suo10_SmartRAM.exe
c:\program files\IObit\Advanced SystemCare 4\Suo11_InternetBooster.exe
c:\program files\IObit\Advanced SystemCare 4\Suo12_StartupManager.exe
c:\program files\IObit\Advanced SystemCare 4\Suo13_RegistryDefrag.exe
c:\program files\IObit\Advanced SystemCare 4\Suo14_SmartDefrag.exe
c:\program files\IObit\Advanced SystemCare 4\Suo15_GameBooster.exe
c:\program files\IObit\Advanced SystemCare 4\Sur10_Undelete.exe
c:\program files\IObit\Advanced SystemCare 4\Sur11_ShortcutFixer.exe
c:\program files\IObit\Advanced SystemCare 4\Sur12_DiskDoctor.exe
c:\program files\IObit\Advanced SystemCare 4\Sur13_WinFix.exe
c:\program files\IObit\Advanced SystemCare 4\Sur14_IEHelper.exe
c:\program files\IObit\Advanced SystemCare 4\Sus10_SecurityHolesScanner.exe
c:\program files\IObit\Advanced SystemCare 4\Sus11_ProcessManager.exe
c:\program files\IObit\Advanced SystemCare 4\Sus12_DriverManager.exe
c:\program files\IObit\Advanced SystemCare 4\Sus13_IMF.exe
c:\program files\IObit\Advanced SystemCare 4\taskMgr.dll
c:\program files\IObit\Advanced SystemCare 4\TaskSchedule.exe
c:\program files\IObit\Advanced SystemCare 4\TBconfig.ini
c:\program files\IObit\Advanced SystemCare 4\TbFfSweep.dll
c:\program files\IObit\Advanced SystemCare 4\TbFileSweep.dll
c:\program files\IObit\Advanced SystemCare 4\Test.log
c:\program files\IObit\Advanced SystemCare 4\ToolBox.exe
c:\program files\IObit\Advanced SystemCare 4\Toolbox_Language\Arabic.lng
c:\program files\IObit\Advanced SystemCare 4\Toolbox_Language\Belarusian.lng
c:\program files\IObit\Advanced SystemCare 4\Toolbox_Language\Bulgarian.lng
c:\program files\IObit\Advanced SystemCare 4\Toolbox_Language\Czech.lng
c:\program files\IObit\Advanced SystemCare 4\Toolbox_Language\English.lng
c:\program files\IObit\Advanced SystemCare 4\Toolbox_Language\French.lng
c:\program files\IObit\Advanced SystemCare 4\Toolbox_Language\German.lng
c:\program files\IObit\Advanced SystemCare 4\Toolbox_Language\Hungarian.lng
c:\program files\IObit\Advanced SystemCare 4\Toolbox_Language\ChineseSimp.lng
c:\program files\IObit\Advanced SystemCare 4\Toolbox_Language\ChineseTrad.lng
c:\program files\IObit\Advanced SystemCare 4\Toolbox_Language\Italian.lng
c:\program files\IObit\Advanced SystemCare 4\Toolbox_Language\Japanese.lng
c:\program files\IObit\Advanced SystemCare 4\Toolbox_Language\Korean.lng
c:\program files\IObit\Advanced SystemCare 4\Toolbox_Language\Polish.lng
c:\program files\IObit\Advanced SystemCare 4\Toolbox_Language\Russian.lng
c:\program files\IObit\Advanced SystemCare 4\Toolbox_Language\Serbian.lng
c:\program files\IObit\Advanced SystemCare 4\Toolbox_Language\Spanish.lng
c:\program files\IObit\Advanced SystemCare 4\Toolbox_Language\Turkish.lng
c:\program files\IObit\Advanced SystemCare 4\Toolbox_Language\Vietnamese.lng
c:\program files\IObit\Advanced SystemCare 4\Toolbox_UI\img\btn-bg.png
c:\program files\IObit\Advanced SystemCare 4\Toolbox_UI\img\menu-bg.png
c:\program files\IObit\Advanced SystemCare 4\Toolbox_UI\Index.html
c:\program files\IObit\Advanced SystemCare 4\Toolbox_UI\js\jquery-1.4.2.min.js
c:\program files\IObit\Advanced SystemCare 4\Toolbox_UI\Recently.html
c:\program files\IObit\Advanced SystemCare 4\TurboBoost.exe
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\Btn_Back_Disable.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\Btn_Back_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\Btn_Back_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\Btn_Back_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\Btn_BackBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\Btn_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\Btn_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\Btn_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\BtnStop_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\BtnStop_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\BtnStop_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\btnUpgradeDown.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\btnUpgradeNormal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\btnUpgradeOver.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\CareBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\CareWorkBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\Close_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\Close_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\CheckBox_Checked.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\CheckBox_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\Img_Error.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\Img_NoProblem.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\Layout.ini
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\Main_Shade.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\Min_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\Min_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\More_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\More_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\Preview.jpg
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\ProgressBarBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\ProgressBarInnerBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\ProgressBarInnerLeft.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\ProgressBarInnerMid.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\ProgressBarInnerRight.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\Rescue_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\Rescue_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\ScannerBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\ScanningBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\Skin_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\Skin_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\TopBar.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\TrackBar.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\TrackBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\appimages\UpgraudD.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\css\css.css
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\images\clear.gif
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\images\dailycare.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\images\deepcare.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\images\halo.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\images\hints.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\images\MainBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\images\quickcare.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\images\shadow.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\images\tip215.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\images\toolBox.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\images\toolboxs.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\images\transparent.gif
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\images\turboboostoff.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\images\turbobooston.png
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\js\action.js
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\js\action1.js
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\js\jquery-1.4.2.js
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\js\jquery.easing.1.3.js
c:\program files\IObit\Advanced SystemCare 4\UI\Asia\main.html
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\Btn_Back_Disable.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\Btn_Back_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\Btn_Back_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\Btn_Back_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\Btn_BackBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\Btn_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\Btn_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\Btn_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\BtnStop_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\BtnStop_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\BtnStop_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\btnUpgradeDown.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\btnUpgradeNormal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\btnUpgradeOver.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\CareBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\CareWorkBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\Close_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\Close_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\halo.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\CheckBox_Checked.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\CheckBox_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\Img_Error.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\Img_NoProblem.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\Layout.ini
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\Main_Shade.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\Min_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\Min_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\More_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\More_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\Preview.jpg
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\ProgressBarBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\ProgressBarInnerBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\ProgressBarInnerLeft.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\ProgressBarInnerMid.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\ProgressBarInnerRight.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\Rescue_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\Rescue_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\ScannerBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\ScanningBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\Setting_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\Setting_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\shadow.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\Skin_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\Skin_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\tip215.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\TopBar.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\TrackBar.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\TrackBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\appimages\UpgraudD.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\css\css.css
c:\program files\IObit\Advanced SystemCare 4\UI\Black\images\clear.gif
c:\program files\IObit\Advanced SystemCare 4\UI\Black\images\dailycare.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\images\deepcare.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\images\halo.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\images\hints.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\images\MainBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\images\quickcare.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\images\shadow.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\images\tip215.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\images\toolBox.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\images\toolboxs.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\images\transparent.gif
c:\program files\IObit\Advanced SystemCare 4\UI\Black\images\turboboostoff.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\images\turbobooston.png
c:\program files\IObit\Advanced SystemCare 4\UI\Black\js\action.js
c:\program files\IObit\Advanced SystemCare 4\UI\Black\js\action1.js
c:\program files\IObit\Advanced SystemCare 4\UI\Black\js\jquery-1.4.2.js
c:\program files\IObit\Advanced SystemCare 4\UI\Black\js\jquery.easing.1.3.js
c:\program files\IObit\Advanced SystemCare 4\UI\Black\main.html
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\Btn_Back_Disable.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\Btn_Back_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\Btn_Back_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\Btn_Back_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\Btn_BackBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\Btn_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\Btn_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\Btn_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\BtnStop_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\BtnStop_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\BtnStop_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\CareBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\CareWorkBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\Close_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\Close_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\CheckBox_Checked.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\CheckBox_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\Img_Error.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\Img_NoProblem.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\Layout.ini
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\Main_Shade.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\Min_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\Min_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\More_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\More_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\Preview.jpg
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\ProgressBarBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\ProgressBarInnerBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\ProgressBarInnerLeft.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\ProgressBarInnerMid.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\ProgressBarInnerRight.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\Rescue_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\Rescue_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\ScannerBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\ScanningBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\Skin_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\Skin_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\TopBar.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\TrackBar.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\appimages\TrackBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\css\css.css
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\images\clear.gif
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\images\deepcare.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\images\MainBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\images\quickcare.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\images\tip215.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\images\toolBox.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\images\transparent.gif
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\images\turboboostoff.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\images\turbobooston.png
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\js\action.js
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\js\action1.js
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\js\jquery-1.4.2.js
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\js\jquery.easing.1.3.js
c:\program files\IObit\Advanced SystemCare 4\UI\Blue\main.html
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\Btn_Back_Disable.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\Btn_Back_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\Btn_Back_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\Btn_Back_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\Btn_BackBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\Btn_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\Btn_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\Btn_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\BtnStop_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\BtnStop_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\BtnStop_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\btnUpgradeDown.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\btnUpgradeNormal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\btnUpgradeOver.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\CareBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\CareWorkBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\Close_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\Close_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\CheckBox_Checked.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\CheckBox_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\Img_Error.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\Img_NoProblem.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\Layout.ini
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\Main_Shade.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\Min_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\Min_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\More_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\More_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\Preview.jpg
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\ProgressBarBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\ProgressBarInnerBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\ProgressBarInnerLeft.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\ProgressBarInnerMid.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\ProgressBarInnerRight.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\Rescue_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\Rescue_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\ScannerBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\ScanningBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\Skin_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\Skin_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\TopBar.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\TrackBar.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\TrackBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\appimages\UpgraudD.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\css\css.css
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\images\clear.gif
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\images\dailycare.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\images\deepcare.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\images\halo.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\images\hints.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\images\MainBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\images\quickcare.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\images\shadow.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\images\tip215.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\images\toolBox.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\images\toolboxs.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\images\transparent.gif
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\images\turboboostoff.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\images\turbobooston.png
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\js\action.js
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\js\action1.js
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\js\jquery-1.4.2.js
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\js\jquery.easing.1.3.js
c:\program files\IObit\Advanced SystemCare 4\UI\Cute\main.html
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\Btn_Back_Disable.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\Btn_Back_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\Btn_Back_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\Btn_Back_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\Btn_BackBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\Btn_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\Btn_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\Btn_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\BtnStop_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\BtnStop_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\BtnStop_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\CareBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\CareWorkBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\Close_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\Close_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\CheckBox_Checked.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\CheckBox_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\Img_Error.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\Img_NoProblem.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\Layout.ini
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\Main_Shade.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\Min_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\Min_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\More_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\More_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\Preview.jpg
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\ProgressBarBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\ProgressBarInnerBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\ProgressBarInnerLeft.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\ProgressBarInnerMid.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\ProgressBarInnerRight.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\Rescue_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\Rescue_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\ScannerBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\ScanningBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\Skin_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\Skin_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\TopBar.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\TrackBar.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\appimages\TrackBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\css\css.css
c:\program files\IObit\Advanced SystemCare 4\UI\Default\images\clear.gif
c:\program files\IObit\Advanced SystemCare 4\UI\Default\images\dailycare.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\images\deepcare.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\images\halo.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\images\hints.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\images\MainBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\images\quickcare.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\images\shadow.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\images\tip215.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\images\toolBox.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\images\toolboxs.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\images\transparent.gif
c:\program files\IObit\Advanced SystemCare 4\UI\Default\images\turboboostoff.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\images\turbobooston.png
c:\program files\IObit\Advanced SystemCare 4\UI\Default\js\action.js
c:\program files\IObit\Advanced SystemCare 4\UI\Default\js\action1.js
c:\program files\IObit\Advanced SystemCare 4\UI\Default\js\jquery-1.4.2.js
c:\program files\IObit\Advanced SystemCare 4\UI\Default\js\jquery.easing.1.3.js
c:\program files\IObit\Advanced SystemCare 4\UI\Default\main.html
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\Btn_Back_Disable.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\Btn_Back_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\Btn_Back_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\Btn_Back_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\Btn_BackBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\Btn_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\Btn_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\Btn_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\BtnStop_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\BtnStop_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\BtnStop_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\btnUpgradeDown.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\btnUpgradeNormal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\btnUpgradeOver.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\CareBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\CareWorkBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\Close_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\Close_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\halo.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\CheckBox_Checked.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\CheckBox_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\Img_Error.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\Img_NoProblem.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\Layout.ini
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\Main_Shade.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\Min_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\Min_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\More_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\More_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\Preview.jpg
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\ProgressBarBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\ProgressBarInnerBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\ProgressBarInnerLeft.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\ProgressBarInnerMid.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\ProgressBarInnerRight.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\Rescue_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\Rescue_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\ScannerBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\ScanningBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\shadow.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\Skin_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\Skin_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\tip215.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\TopBar.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\TrackBar.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\TrackBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\appimages\UpgraudD.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\css\css.css
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\images\CareBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\images\clear.gif
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\images\dailycare.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\images\deepcare.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\images\halo.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\images\hints.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\images\MainBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\images\quickcare.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\images\shadow.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\images\tip215.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\images\toolBox.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\images\toolboxs.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\images\transparent.gif
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\images\turboboostoff.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\images\turbobooston.png
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\js\action.js
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\js\action1.js
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\js\jquery-1.4.2.js
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\js\jquery.easing.1.3.js
c:\program files\IObit\Advanced SystemCare 4\UI\Flat\main.html
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\Btn_Back_Disable.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\Btn_Back_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\Btn_Back_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\Btn_Back_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\Btn_BackBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\Btn_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\Btn_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\Btn_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\BtnStop_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\BtnStop_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\BtnStop_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\btnUpgradeDown.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\btnUpgradeNormal.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\btnUpgradeOver.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\CareBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\CareWorkBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\Close_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\Close_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\CheckBox_Checked.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\CheckBox_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\Img_Error.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\Img_NoProblem.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\Layout.ini
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\Main_Shade.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\Min_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\Min_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\More_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\More_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\Preview.jpg
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\ProgressBarBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\ProgressBarInnerBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\ProgressBarInnerLeft.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\ProgressBarInnerMid.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\ProgressBarInnerRight.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\Rescue_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\Rescue_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\ScannerBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\ScanningBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\Skin_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\Skin_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\TopBar.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\TrackBar.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\TrackBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\appimages\UpgraudD.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\css\css.css
c:\program files\IObit\Advanced SystemCare 4\UI\China\images\clear.gif
c:\program files\IObit\Advanced SystemCare 4\UI\China\images\dailycare.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\images\deepcare.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\images\halo.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\images\hints.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\images\MainBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\images\quickcare.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\images\shadow.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\images\tip215.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\images\toolBox.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\images\toolboxs.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\images\transparent.gif
c:\program files\IObit\Advanced SystemCare 4\UI\China\images\turboboostoff.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\images\turbobooston.png
c:\program files\IObit\Advanced SystemCare 4\UI\China\js\action.js
c:\program files\IObit\Advanced SystemCare 4\UI\China\js\action1.js
c:\program files\IObit\Advanced SystemCare 4\UI\China\js\jquery-1.4.2.js
c:\program files\IObit\Advanced SystemCare 4\UI\China\js\jquery.easing.1.3.js
c:\program files\IObit\Advanced SystemCare 4\UI\China\main.html
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\Btn_Back_Disable.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\Btn_Back_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\Btn_Back_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\Btn_Back_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\Btn_BackBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\Btn_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\Btn_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\Btn_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\BtnStop_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\BtnStop_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\BtnStop_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\CareBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\CareWorkBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\Close_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\Close_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\halo.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\CheckBox_Checked.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\CheckBox_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\Img_Error.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\Img_NoProblem.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\Layout.ini
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\Main_Shade.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\Min_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\Min_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\More_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\More_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\Preview.jpg
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\ProgressBarBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\ProgressBarInnerBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\ProgressBarInnerLeft.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\ProgressBarInnerMid.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\ProgressBarInnerRight.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\Rescue_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\Rescue_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\ScannerBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\ScanningBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\shadow.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\Skin_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\Skin_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\tip215.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\TopBar.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\TrackBar.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\TrackBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\appimages\UpgraudD.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\css\css.css
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\images\clear.gif
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\images\deepcare.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\images\halo.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\images\Main_Shade.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\images\MainBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\images\quickcare.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\images\shadow.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\images\tip215.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\images\toolBox.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\images\toolboxs.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\images\transparent.gif
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\images\turboboostoff.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\images\turbobooston.png
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\js\action.js
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\js\action1.js
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\js\jquery-1.4.2.js
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\js\jquery.easing.1.3.js
c:\program files\IObit\Advanced SystemCare 4\UI\Maya\main.html
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\Btn_Back_Disable.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\Btn_Back_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\Btn_Back_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\Btn_Back_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\Btn_BackBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\Btn_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\Btn_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\Btn_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\BtnStop_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\BtnStop_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\BtnStop_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\CareBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\CareWorkBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\Close_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\Close_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\CheckBox_Checked.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\CheckBox_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\Img_Error.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\Img_NoProblem.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\Layout.ini
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\Main_Shade.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\Min_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\Min_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\More_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\More_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\Preview.jpg
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\ProgressBarBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\ProgressBarInnerBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\ProgressBarInnerLeft.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\ProgressBarInnerMid.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\ProgressBarInnerRight.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\Rescue_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\Rescue_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\ScannerBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\ScanningBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\Skin_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\Skin_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\TopBar.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\TrackBar.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\appimages\TrackBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\css\css.css
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\images\clear.gif
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\images\deepcare.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\images\MainBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\images\quickcare.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\images\tip215.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\images\toolBox.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\images\transparent.gif
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\images\turboboostoff.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\images\turbobooston.png
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\js\action.js
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\js\action1.js
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\js\jquery-1.4.2.js
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\js\jquery.easing.1.3.js
c:\program files\IObit\Advanced SystemCare 4\UI\Metal\main.html
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\Btn_Back_Disable.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\Btn_Back_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\Btn_Back_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\Btn_Back_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\Btn_BackBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\Btn_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\Btn_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\Btn_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\BtnStop_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\BtnStop_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\BtnStop_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\CareBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\CareWorkBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\Close_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\Close_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\CheckBox_Checked.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\CheckBox_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\Img_Error.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\Img_NoProblem.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\Layout.ini
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\Main_Shade.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\Min_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\Min_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\More_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\More_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\Preview.jpg
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\ProgressBarBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\ProgressBarInnerBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\ProgressBarInnerLeft.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\ProgressBarInnerMid.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\ProgressBarInnerRight.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\Rescue_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\Rescue_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\ScannerBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\ScanningBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\Skin_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\Skin_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\TopBar.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\TrackBar.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\appimages\TrackBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\css\css.css
c:\program files\IObit\Advanced SystemCare 4\UI\Office\images\clear.gif
c:\program files\IObit\Advanced SystemCare 4\UI\Office\images\deepcare.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\images\MainBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\images\quickcare.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\images\tip215.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\images\toolBox.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\images\transparent.gif
c:\program files\IObit\Advanced SystemCare 4\UI\Office\images\turboboostoff.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\images\turbobooston.png
c:\program files\IObit\Advanced SystemCare 4\UI\Office\js\action.js
c:\program files\IObit\Advanced SystemCare 4\UI\Office\js\action1.js
c:\program files\IObit\Advanced SystemCare 4\UI\Office\js\jquery-1.4.2.js
c:\program files\IObit\Advanced SystemCare 4\UI\Office\js\jquery.easing.1.3.js
c:\program files\IObit\Advanced SystemCare 4\UI\Office\main.html
c:\program files\IObit\Advanced SystemCare 4\UI\Public\js\action.js
c:\program files\IObit\Advanced SystemCare 4\UI\Public\js\jquery-1.4.2.js
c:\program files\IObit\Advanced SystemCare 4\UI\Public\js\jquery.easing.1.3.js
c:\program files\IObit\Advanced SystemCare 4\UI\Public\upgrade\btnMLDown.png
c:\program files\IObit\Advanced SystemCare 4\UI\Public\upgrade\btnMLNormal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Public\upgrade\btnMLOver.png
c:\program files\IObit\Advanced SystemCare 4\UI\Public\upgrade\btnUpgradeDown.png
c:\program files\IObit\Advanced SystemCare 4\UI\Public\upgrade\btnUpgradeNormal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Public\upgrade\btnUpgradeOver.png
c:\program files\IObit\Advanced SystemCare 4\UI\Public\upgrade\Upgrade_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Public\upgrade\Upgrade_Over.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\Btn_Back_Disable.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\Btn_Back_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\Btn_Back_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\Btn_Back_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\Btn_BackBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\Btn_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\Btn_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\Btn_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\BtnStop_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\BtnStop_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\BtnStop_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\btnUpgradeDown.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\btnUpgradeNormal.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\btnUpgradeOver.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\CareBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\CareWorkBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\Close_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\Close_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\halo.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\CheckBox_Checked.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\CheckBox_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\Img_Error.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\Img_NoProblem.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\Layout.ini
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\Main_Shade.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\Min_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\Min_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\More_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\More_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\Preview.jpg
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\ProgressBarBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\ProgressBarInnerBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\ProgressBarInnerLeft.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\ProgressBarInnerMid.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\ProgressBarInnerRight.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\Rescue_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\Rescue_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\ScannerBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\ScanningBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\shadow.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\Skin_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\Skin_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\tip215.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\TopBar.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\TrackBar.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\TrackBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\appimages\UpgraudD.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\css\css.css
c:\program files\IObit\Advanced SystemCare 4\UI\White\images\clear.gif
c:\program files\IObit\Advanced SystemCare 4\UI\White\images\deepcare.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\images\halo.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\images\MainBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\images\quickcare.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\images\shadow.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\images\tip215.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\images\toolBox.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\images\toolboxs.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\images\transparent.gif
c:\program files\IObit\Advanced SystemCare 4\UI\White\images\turboboostoff.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\images\turbobooston.png
c:\program files\IObit\Advanced SystemCare 4\UI\White\js\action.js
c:\program files\IObit\Advanced SystemCare 4\UI\White\js\action1.js
c:\program files\IObit\Advanced SystemCare 4\UI\White\js\jquery-1.4.2.js
c:\program files\IObit\Advanced SystemCare 4\UI\White\js\jquery.easing.1.3.js
c:\program files\IObit\Advanced SystemCare 4\UI\White\main.html
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\Btn_Back_Disable.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\Btn_Back_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\Btn_Back_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\Btn_Back_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\Btn_BackBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\Btn_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\Btn_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\Btn_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\BtnStop_Down.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\BtnStop_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\BtnStop_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\btnUpgradeDown.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\btnUpgradeNormal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\btnUpgradeOver.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\CareBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\CareWorkBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\Close_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\Close_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\halo.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\CheckBox_Checked.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\CheckBox_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\Img_Error.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\Img_NoProblem.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\Layout.ini
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\Main_Shade.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\Min_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\Min_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\More_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\More_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\Preview.jpg
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\ProgressBarBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\ProgressBarInnerBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\ProgressBarInnerLeft.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\ProgressBarInnerMid.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\ProgressBarInnerRight.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\Rescue_Move.png

Re: Facebook vír

Napsal: 30 říj 2011 12:00
od ceasare
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\Rescue_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\ScannerBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\ScanningBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\shadow.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\Skin_Move.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\Skin_Normal.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\tip215.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\TopBar.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\TrackBar.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\appimages\TrackBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\css\css.css
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\images\btnUpgradeDown.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\images\clear.gif
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\images\dailycare.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\images\deepcare.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\images\halo.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\images\hints.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\images\MainBG.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\images\quickcare.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\images\shadow.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\images\tip215.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\images\toolBox.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\images\toolboxs.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\images\transparent.gif
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\images\turboboostoff.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\images\turbobooston.png
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\js\action.js
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\js\action1.js
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\js\jquery-1.4.2.js
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\js\jquery.easing.1.3.js
c:\program files\IObit\Advanced SystemCare 4\UI\Wood\main.html
c:\program files\IObit\Advanced SystemCare 4\UnDelete.dll
c:\program files\IObit\Advanced SystemCare 4\unins000.dat
c:\program files\IObit\Advanced SystemCare 4\unins000.exe
c:\program files\IObit\Advanced SystemCare 4\unins000.msg
c:\program files\IObit\Advanced SystemCare 4\Update History.txt
c:\program files\IObit\Advanced SystemCare 4\Update\Update.Ini
c:\program files\IObit\Advanced SystemCare 4\UpdateHistory.txt
c:\program files\IObit\Advanced SystemCare 4\UPdateTest.log
c:\program files\IObit\Advanced SystemCare 4\vcl120.bpl
c:\program files\IObit\Advanced SystemCare 4\vclx120.bpl
c:\program files\IObit\Advanced SystemCare 4\Wizard.exe
c:\program files\IObit\Game Booster\AutoUpdate.exe
c:\program files\IObit\Game Booster\Boost.exe
c:\program files\IObit\Game Booster\GameBooster.exe
c:\program files\IObit\Game Booster\gbinit.exe
c:\program files\IObit\Game Booster\gbtray.exe
c:\program files\IObit\Game Booster\Language\Arabic.lng
c:\program files\IObit\Game Booster\Language\Catalan.lng
c:\program files\IObit\Game Booster\Language\Croatian.lng
c:\program files\IObit\Game Booster\Language\Czech.lng
c:\program files\IObit\Game Booster\Language\Dansk.lng
c:\program files\IObit\Game Booster\Language\Dutch.lng
c:\program files\IObit\Game Booster\Language\English.lng
c:\program files\IObit\Game Booster\Language\Finnish.lng
c:\program files\IObit\Game Booster\Language\French.lng
c:\program files\IObit\Game Booster\Language\German.lng
c:\program files\IObit\Game Booster\Language\Hungarian.lng
c:\program files\IObit\Game Booster\Language\ChineseSimp.lng
c:\program files\IObit\Game Booster\Language\ChineseTrad.lng
c:\program files\IObit\Game Booster\Language\Indonesian.lng
c:\program files\IObit\Game Booster\Language\Italian.lng
c:\program files\IObit\Game Booster\Language\Japanese.lng
c:\program files\IObit\Game Booster\Language\Korean.lng
c:\program files\IObit\Game Booster\Language\Polish.lng
c:\program files\IObit\Game Booster\Language\Portuguese(BRAZIL).lng
c:\program files\IObit\Game Booster\Language\Romanian.lng
c:\program files\IObit\Game Booster\Language\Russian.lng
c:\program files\IObit\Game Booster\Language\Slovenian.lng
c:\program files\IObit\Game Booster\Language\Spanish.lng
c:\program files\IObit\Game Booster\Language\Swedish.lng
c:\program files\IObit\Game Booster\Language\Turkish.lng
c:\program files\IObit\Game Booster\license.dat
c:\program files\IObit\Game Booster\PowerConfig.dll
c:\program files\IObit\Game Booster\rtl120.bpl
c:\program files\IObit\Game Booster\sqlite3.dll
c:\program files\IObit\Game Booster\taskMgr.dll
c:\program files\IObit\Game Booster\TaskSchedule.exe
c:\program files\IObit\Game Booster\unins000.dat
c:\program files\IObit\Game Booster\unins000.exe
c:\program files\IObit\Game Booster\unins000.msg
c:\program files\IObit\Game Booster\vcl120.bpl
c:\program files\IObit\Game Booster\vclx120.bpl
c:\program files\IObit\IObit Malware Fighter\BlueBirdInit.exe
c:\program files\IObit\IObit Malware Fighter\datastate.dll
c:\program files\IObit\IObit Malware Fighter\db\core000.def
c:\program files\IObit\IObit Malware Fighter\db\core001.def
c:\program files\IObit\IObit Malware Fighter\db\core002.def
c:\program files\IObit\IObit Malware Fighter\db\core003.def
c:\program files\IObit\IObit Malware Fighter\db\core004.def
c:\program files\IObit\IObit Malware Fighter\db\core005.def
c:\program files\IObit\IObit Malware Fighter\db\core006.def
c:\program files\IObit\IObit Malware Fighter\db\core007.def
c:\program files\IObit\IObit Malware Fighter\db\core008.def
c:\program files\IObit\IObit Malware Fighter\db\core009.def
c:\program files\IObit\IObit Malware Fighter\db\core010.def
c:\program files\IObit\IObit Malware Fighter\db\core011.def
c:\program files\IObit\IObit Malware Fighter\db\core012.def
c:\program files\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys
c:\program files\IObit\IObit Malware Fighter\Drivers\win7_amd64\RegFilter.sys
c:\program files\IObit\IObit Malware Fighter\Drivers\win7_amd64\UrlFilter.sys
c:\program files\IObit\IObit Malware Fighter\Drivers\win7_ia64\FileMonitor.sys
c:\program files\IObit\IObit Malware Fighter\Drivers\win7_ia64\RegFilter.sys
c:\program files\IObit\IObit Malware Fighter\Drivers\win7_ia64\UrlFilter.sys
c:\program files\IObit\IObit Malware Fighter\Drivers\win7_x86\FileMonitor.sys
c:\program files\IObit\IObit Malware Fighter\Drivers\win7_x86\RegFilter.sys
c:\program files\IObit\IObit Malware Fighter\Drivers\win7_x86\UrlFilter.sys
c:\program files\IObit\IObit Malware Fighter\Drivers\wlh_amd64\FileMonitor.sys
c:\program files\IObit\IObit Malware Fighter\Drivers\wlh_amd64\RegFilter.sys
c:\program files\IObit\IObit Malware Fighter\Drivers\wlh_amd64\UrlFilter.sys
c:\program files\IObit\IObit Malware Fighter\Drivers\wlh_ia64\FileMonitor.sys
c:\program files\IObit\IObit Malware Fighter\Drivers\wlh_ia64\RegFilter.sys
c:\program files\IObit\IObit Malware Fighter\Drivers\wlh_ia64\UrlFilter.sys
c:\program files\IObit\IObit Malware Fighter\Drivers\wlh_x86\FileMonitor.sys
c:\program files\IObit\IObit Malware Fighter\Drivers\wlh_x86\RegFilter.sys
c:\program files\IObit\IObit Malware Fighter\Drivers\wlh_x86\UrlFilter.sys
c:\program files\IObit\IObit Malware Fighter\Drivers\wnet_amd64\FileMonitor.sys
c:\program files\IObit\IObit Malware Fighter\Drivers\wnet_amd64\RegFilter.sys
c:\program files\IObit\IObit Malware Fighter\Drivers\wnet_amd64\UrlFilter.sys
c:\program files\IObit\IObit Malware Fighter\Drivers\wnet_ia64\FileMonitor.sys
c:\program files\IObit\IObit Malware Fighter\Drivers\wnet_ia64\RegFilter.sys
c:\program files\IObit\IObit Malware Fighter\Drivers\wnet_ia64\UrlFilter.sys
c:\program files\IObit\IObit Malware Fighter\Drivers\wnet_x86\FileMonitor.sys
c:\program files\IObit\IObit Malware Fighter\Drivers\wnet_x86\RegFilter.sys
c:\program files\IObit\IObit Malware Fighter\Drivers\wnet_x86\UrlFilter.sys
c:\program files\IObit\IObit Malware Fighter\Drivers\wxp_ia64\UrlFilter.sys
c:\program files\IObit\IObit Malware Fighter\Drivers\wxp_x86\FileMonitor.sys
c:\program files\IObit\IObit Malware Fighter\Drivers\wxp_x86\RegFilter.sys
c:\program files\IObit\IObit Malware Fighter\Drivers\wxp_x86\UrlFilter.sys
c:\program files\IObit\IObit Malware Fighter\EULA.rtf
c:\program files\IObit\IObit Malware Fighter\FileMonitor.dll
c:\program files\IObit\IObit Malware Fighter\help\help.html
c:\program files\IObit\IObit Malware Fighter\help\img\cloud.png
c:\program files\IObit\IObit Malware Fighter\help\img\main-cloud.png
c:\program files\IObit\IObit Malware Fighter\help\img\main-free.png
c:\program files\IObit\IObit Malware Fighter\help\img\main-pro.png
c:\program files\IObit\IObit Malware Fighter\help\img\main-protect.png
c:\program files\IObit\IObit Malware Fighter\help\img\main-scan.png
c:\program files\IObit\IObit Malware Fighter\help\img\overview.png
c:\program files\IObit\IObit Malware Fighter\help\img\protect.png
c:\program files\IObit\IObit Malware Fighter\help\img\scan.png
c:\program files\IObit\IObit Malware Fighter\IMF.exe
c:\program files\IObit\IObit Malware Fighter\IMFShellExt.dll
c:\program files\IObit\IObit Malware Fighter\IMFsrv.exe
c:\program files\IObit\IObit Malware Fighter\IMFUpdater.exe
c:\program files\IObit\IObit Malware Fighter\IntegrateFilter.dll
c:\program files\IObit\IObit Malware Fighter\IObitUninstal.exe
c:\program files\IObit\IObit Malware Fighter\Language\Arabic.lng
c:\program files\IObit\IObit Malware Fighter\Language\Czech.lng
c:\program files\IObit\IObit Malware Fighter\Language\English.lng
c:\program files\IObit\IObit Malware Fighter\Language\French.lng
c:\program files\IObit\IObit Malware Fighter\Language\German.lng
c:\program files\IObit\IObit Malware Fighter\Language\Hungarian.lng
c:\program files\IObit\IObit Malware Fighter\Language\ChineseSimp.lng
c:\program files\IObit\IObit Malware Fighter\Language\ChineseTrad.lng
c:\program files\IObit\IObit Malware Fighter\Language\Italian.lng
c:\program files\IObit\IObit Malware Fighter\Language\Japanese.lng
c:\program files\IObit\IObit Malware Fighter\Language\Korean.lng
c:\program files\IObit\IObit Malware Fighter\Language\Latvian.lng
c:\program files\IObit\IObit Malware Fighter\Language\Polish.lng
c:\program files\IObit\IObit Malware Fighter\Language\Portuguese(PT-BR).lng
c:\program files\IObit\IObit Malware Fighter\Language\Russian.lng
c:\program files\IObit\IObit Malware Fighter\Language\Serbian.lng
c:\program files\IObit\IObit Malware Fighter\Language\Spanish.lng
c:\program files\IObit\IObit Malware Fighter\Language\Swedish.lng
c:\program files\IObit\IObit Malware Fighter\Language\Turkish.lng
c:\program files\IObit\IObit Malware Fighter\Language\Vietnamese.lng
c:\program files\IObit\IObit Malware Fighter\license.dat
c:\program files\IObit\IObit Malware Fighter\Quarantine Zone\info.db
c:\program files\IObit\IObit Malware Fighter\RegFilter.dll
c:\program files\IObit\IObit Malware Fighter\rtl120.bpl
c:\program files\IObit\IObit Malware Fighter\Scan.dll
c:\program files\IObit\IObit Malware Fighter\StartMenu.exe
c:\program files\IObit\IObit Malware Fighter\taskmgr.dll
c:\program files\IObit\IObit Malware Fighter\TaskSchedule.exe
c:\program files\IObit\IObit Malware Fighter\unins000.dat
c:\program files\IObit\IObit Malware Fighter\unins000.exe
c:\program files\IObit\IObit Malware Fighter\unins000.msg
c:\program files\IObit\IObit Malware Fighter\unrar.dll
c:\program files\IObit\IObit Malware Fighter\URLFilter.dll
c:\program files\IObit\IObit Malware Fighter\vcl120.bpl
c:\program files\IObit\IObit Malware Fighter\vclx120.bpl
c:\program files\IObit\IObit Malware Fighter\zlibwapi.dll
c:\program files\IObit\Smart Defrag 2\drivers\win7_x64\SmartDefragBootTime.exe
c:\program files\IObit\Smart Defrag 2\drivers\win7_x64\SmartDefragDriver.sys
c:\program files\IObit\Smart Defrag 2\drivers\win7_x86\SmartDefragBootTime.exe
c:\program files\IObit\Smart Defrag 2\drivers\win7_x86\SmartDefragDriver.sys
c:\program files\IObit\Smart Defrag 2\drivers\wlh_x64\SmartDefragBootTime.exe
c:\program files\IObit\Smart Defrag 2\drivers\wlh_x64\SmartDefragDriver.sys
c:\program files\IObit\Smart Defrag 2\drivers\wlh_x86\SmartDefragBootTime.exe
c:\program files\IObit\Smart Defrag 2\drivers\wlh_x86\SmartDefragDriver.sys
c:\program files\IObit\Smart Defrag 2\drivers\wnet_x64\SmartDefragBootTime.exe
c:\program files\IObit\Smart Defrag 2\drivers\wnet_x64\SmartDefragDriver.sys
c:\program files\IObit\Smart Defrag 2\drivers\wnet_x86\SmartDefragBootTime.exe
c:\program files\IObit\Smart Defrag 2\drivers\wnet_x86\SmartDefragDriver.sys
c:\program files\IObit\Smart Defrag 2\drivers\wxp_x64\SmartDefragBootTime.exe
c:\program files\IObit\Smart Defrag 2\drivers\wxp_x64\SmartDefragDriver.sys
c:\program files\IObit\Smart Defrag 2\drivers\wxp_x86\SmartDefragBootTime.exe
c:\program files\IObit\Smart Defrag 2\drivers\wxp_x86\SmartDefragDriver.sys
c:\program files\IObit\Smart Defrag 2\EULA.rtf
c:\program files\IObit\Smart Defrag 2\Help\Images\001.jpg
c:\program files\IObit\Smart Defrag 2\Help\Images\002.jpg
c:\program files\IObit\Smart Defrag 2\Help\Images\003.jpg
c:\program files\IObit\Smart Defrag 2\Help\Images\004.jpg
c:\program files\IObit\Smart Defrag 2\Help\Images\005.jpg
c:\program files\IObit\Smart Defrag 2\Help\Images\006.jpg
c:\program files\IObit\Smart Defrag 2\Help\Images\007.jpg
c:\program files\IObit\Smart Defrag 2\Help\Images\008.jpg
c:\program files\IObit\Smart Defrag 2\Help\Images\009.jpg
c:\program files\IObit\Smart Defrag 2\Help\Index.html
c:\program files\IObit\Smart Defrag 2\Language\Albanian.lng
c:\program files\IObit\Smart Defrag 2\Language\Arabic.lng
c:\program files\IObit\Smart Defrag 2\Language\Bulgarian.lng
c:\program files\IObit\Smart Defrag 2\Language\Czech.lng
c:\program files\IObit\Smart Defrag 2\Language\Danish.lng
c:\program files\IObit\Smart Defrag 2\Language\Dutch.lng
c:\program files\IObit\Smart Defrag 2\Language\English.lng
c:\program files\IObit\Smart Defrag 2\Language\Finnish.lng
c:\program files\IObit\Smart Defrag 2\Language\Flemish.lng
c:\program files\IObit\Smart Defrag 2\Language\French.lng
c:\program files\IObit\Smart Defrag 2\Language\Georgian.lng
c:\program files\IObit\Smart Defrag 2\Language\German.lng
c:\program files\IObit\Smart Defrag 2\Language\Greek.lng
c:\program files\IObit\Smart Defrag 2\Language\Hebrew.lng
c:\program files\IObit\Smart Defrag 2\Language\Hungarian.lng
c:\program files\IObit\Smart Defrag 2\Language\ChineseSimp.lng
c:\program files\IObit\Smart Defrag 2\Language\ChineseTrad.lng
c:\program files\IObit\Smart Defrag 2\Language\Indonesia.lng
c:\program files\IObit\Smart Defrag 2\Language\Italian.lng
c:\program files\IObit\Smart Defrag 2\Language\Japanese.lng
c:\program files\IObit\Smart Defrag 2\Language\Korean.lng
c:\program files\IObit\Smart Defrag 2\Language\Kurdish.lng
c:\program files\IObit\Smart Defrag 2\Language\Malay.lng
c:\program files\IObit\Smart Defrag 2\Language\Malayalam.lng
c:\program files\IObit\Smart Defrag 2\Language\Norwegian.lng
c:\program files\IObit\Smart Defrag 2\Language\Polish.lng
c:\program files\IObit\Smart Defrag 2\Language\Portuguese(Brazil).lng
c:\program files\IObit\Smart Defrag 2\Language\Portuguese(Portugal).lng
c:\program files\IObit\Smart Defrag 2\Language\Romanian.lng
c:\program files\IObit\Smart Defrag 2\Language\Russian.lng
c:\program files\IObit\Smart Defrag 2\Language\Serbian.lng
c:\program files\IObit\Smart Defrag 2\Language\Slovak.lng
c:\program files\IObit\Smart Defrag 2\Language\Slovenian.lng
c:\program files\IObit\Smart Defrag 2\Language\Spanish.lng
c:\program files\IObit\Smart Defrag 2\Language\Swedish.lng
c:\program files\IObit\Smart Defrag 2\Language\Turkish.lng
c:\program files\IObit\Smart Defrag 2\Language\Vietnamese.lng
c:\program files\IObit\Smart Defrag 2\LatestNews\LatestNews.ini
c:\program files\IObit\Smart Defrag 2\NtfsData.dll
c:\program files\IObit\Smart Defrag 2\rtl120.bpl
c:\program files\IObit\Smart Defrag 2\SDDriverMgr.dll
c:\program files\IObit\Smart Defrag 2\SDInit.exe
c:\program files\IObit\Smart Defrag 2\Skins\Black\Add_Left.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Add_Middle.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Add_Right.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Add_Shadow.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Analyze_Disable.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Analyze_Focus.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Analyze_Hot.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Analyze_Normal.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Center.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Close_Hot.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Close_Normal.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\ColumnDivider.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\ColumnHeader.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Corner_Bottom_Left.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Corner_Bottom_Right.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Corner_Top_Left.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Corner_Top_Right.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Defrag_Disable.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Defrag_Focus.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Defrag_Hot.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Defrag_Normal.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Defrag_Option_Disable.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Defrag_Option_Focus.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Defrag_Option_Hot.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Defrag_Option_Normal.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Frame_Bottom.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Frame_Left.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Frame_Left_Top.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Frame_Right.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Frame_Right_Top.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Frame_Top.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Hide.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Checkbox_Disable.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Checkbox_Checked.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Checkbox_Unchecked.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Item_Selected.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Layout.ini
c:\program files\IObit\Smart Defrag 2\Skins\Black\line.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Logo.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Maximize_Hot.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Maximize_Normal.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Minimize_Hot.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Minimize_Normal.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\News_Left.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\News_Middle.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\News_Right.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Page_Body.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Pause_Disable.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Pause_Focus.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Pause_Hot.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Pause_Normal.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Progress_Bg_Left.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Progress_Bg_Middle.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Progress_Bg_Right.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Progress_Fg_Left.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Progress_Fg_Middle.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Progress_Fg_Right.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Restore_Hot.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Restore_Normal.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Setting_Text_Shadow.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Show.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Statistics.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Stop_Disable.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Stop_Focus.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Stop_Hot.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Stop_Normal.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Tab_Focus.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Tab_Hot.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Tab_Normal.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Title.png
c:\program files\IObit\Smart Defrag 2\Skins\Black\Top.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Add_Left.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Add_Middle.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Add_Right.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Add_Shadow.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Analyze_Disable.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Analyze_Focus.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Analyze_Hot.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Analyze_Normal.png
c:\program files\IObit\Smart Defrag 2\Skins\White\center.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Close_Hot.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Close_Normal.png
c:\program files\IObit\Smart Defrag 2\Skins\White\ColumnDivider.png
c:\program files\IObit\Smart Defrag 2\Skins\White\ColumnHeader.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Corner_Bottom_Left.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Corner_Bottom_Right.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Corner_Top_Left.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Corner_Top_Right.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Defrag_Disable.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Defrag_Focus.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Defrag_Hot.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Defrag_Normal.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Defrag_Option_Disable.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Defrag_Option_Focus.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Defrag_Option_Hot.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Defrag_Option_Normal.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Frame_Bottom.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Frame_Left.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Frame_Left_Top.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Frame_Right.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Frame_Right_Top.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Frame_Top.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Hide.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Checkbox_Disable.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Checkbox_Checked.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Checkbox_Unchecked.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Item_Selected.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Layout.ini
c:\program files\IObit\Smart Defrag 2\Skins\White\line.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Logo.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Maximize_Hot.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Maximize_Normal.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Minimize_Hot.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Minimize_Normal.png
c:\program files\IObit\Smart Defrag 2\Skins\White\News_Left.png
c:\program files\IObit\Smart Defrag 2\Skins\White\News_Middle.png
c:\program files\IObit\Smart Defrag 2\Skins\White\News_Right.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Page_Body.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Pause_Disable.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Pause_Focus.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Pause_Hot.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Pause_Normal.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Progress_Bg_Left.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Progress_Bg_Middle.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Progress_Bg_Right.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Progress_Fg_Left.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Progress_Fg_Middle.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Progress_Fg_Right.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Restore_Hot.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Restore_Normal.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Setting_Text_Shadow.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Show.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Statistics.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Stop_Disable.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Stop_Focus.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Stop_Hot.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Stop_Normal.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Tab_Focus.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Tab_Hot.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Tab_Normal.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Title.png
c:\program files\IObit\Smart Defrag 2\Skins\White\Top.png
c:\program files\IObit\Smart Defrag 2\SmartDefrag.exe
c:\program files\IObit\Smart Defrag 2\taskMgr.dll
c:\program files\IObit\Smart Defrag 2\unins000.dat
c:\program files\IObit\Smart Defrag 2\unins000.exe
c:\program files\IObit\Smart Defrag 2\unins000.msg
c:\program files\IObit\Smart Defrag 2\vcl120.bpl
c:\program files\IObit\Smart Defrag 2\vclx120.bpl
c:\program files\TNod User & Password Finder\TNODUP.exe
c:\program files\Uninstall.exe
c:\users\Tomino\AppData\Roaming\vso_ts_preview.xml
c:\users\UpdatusUser\Desktop\weather.lnk
c:\windows\av_ico
c:\windows\av_ico\ico_avast_desktop.ico
c:\windows\av_ico\ico_avast_start.ico
c:\windows\av_ico\ico_defender_start.ico
c:\windows\av_ico\ico_NOD_AV_START.ico
c:\windows\av_ico\ico_NOD_SYSINSP.ico
c:\windows\av_ico\ico_NOD_SYSRESC.ico
c:\windows\av_ico\ico_NOD_TXT.ico
c:\windows\av_ico\ico_NOD_UNINSTALL.ico
c:\windows\btc_client_iplist.txt
c:\windows\front_ip_list.txt
c:\windows\geoiplist
c:\windows\geoiplist.rar
c:\windows\iecheck_iplist.txt
c:\windows\info1
c:\windows\iplist.txt
c:\windows\loader2.exe_ok
c:\windows\phoenix.rar
c:\windows\rpcminer.rar
c:\windows\system32\drivers\etc\HSTS~1
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4042068987-915908620-2276306216-1000Core.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4042068987-915908620-2276306216-1000UA.job
c:\windows\ufa.rar
c:\windows\unrar.exe
c:\windows\update.tray-15-0-lnk
c:\windows\update.tray-15-0-lnk\svchost.exe
c:\windows\update.tray-15-0
c:\windows\update.tray-2-0-lnk
c:\windows\update.tray-2-0
c:\windows\update.tray-7-0-lnk
c:\windows\winlog-dirs.txt
c:\windows\winlog-ids.txt
.
Infected copy of c:\windows\SysWOW64\user32.dll was found and disinfected
Restored copy from - c:\windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_AdvancedSystemCareService
-------\Service_IMFservice
-------\Service_IMFservice
.
.
((((((((((((((((((((((((( Files Created from 2011-09-28 to 2011-10-30 )))))))))))))))))))))))))))))))
.
.
2011-10-30 10:49 . 2011-10-30 10:49 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-10-29 20:17 . 2011-10-29 20:18 -------- d-----w- c:\program files\trend micro
2011-10-29 20:17 . 2011-10-29 20:29 -------- d-----w- C:\rsit
2011-10-29 15:15 . 2011-10-29 15:15 -------- d-----w- c:\program files\ESET
2011-10-29 15:07 . 2011-10-29 15:07 -------- d-----w- c:\programdata\Malwarebytes
2011-10-29 15:07 . 2011-08-31 15:00 25416 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-10-29 14:34 . 2011-10-29 20:13 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-10-29 14:16 . 2011-10-29 14:44 -------- d--h--w- c:\windows\update.tray-7-0
2011-10-29 14:14 . 2011-01-05 16:12 489552 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-10-29 14:14 . 2011-01-05 16:12 272976 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-10-29 14:14 . 2011-01-05 16:08 29264 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-10-29 14:14 . 2011-01-05 16:08 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-10-29 14:14 . 2011-01-05 16:11 51792 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-10-29 14:14 . 2011-01-05 16:08 62032 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-10-29 14:14 . 2011-01-05 16:19 237168 ----a-w- c:\windows\system32\aswBoot.exe
2011-10-29 14:14 . 2011-01-05 16:19 38848 ----a-w- c:\windows\avastSS.scr
2011-10-29 14:14 . 2011-01-05 16:19 188216 ----a-w- c:\windows\SysWow64\aswBoot.exe
2011-10-29 11:16 . 2011-10-29 14:52 -------- d-----w- c:\windows\ufa
2011-10-26 06:29 . 2011-10-26 06:29 -------- d-----w- c:\windows\SysWow64\RTCOM
2011-10-25 06:55 . 2011-10-25 07:36 -------- d-----w- c:\program files\Battlefield 3
2011-10-24 19:53 . 2011-10-24 19:53 -------- d-----w- c:\program files (x86)\Tajemství šesti moří
2011-10-24 19:48 . 2011-10-24 19:48 -------- d-----w- c:\programdata\DivoGames
2011-10-24 19:47 . 2011-10-24 19:48 -------- d-----w- c:\program files (x86)\Poklady starověké sluje
2011-10-24 19:41 . 2011-10-24 19:41 -------- d-----w- c:\program files (x86)\Spidla
2011-10-24 19:35 . 2011-10-24 19:37 -------- d-----w- c:\program files (x86)\Táta hrdina
2011-10-24 19:30 . 2011-10-24 19:31 -------- d-----w- c:\program files (x86)\Ledové Drahokamy
2011-10-22 22:28 . 2011-10-22 22:28 -------- d-----w- c:\programdata\Playrix Entertainment
2011-10-22 22:26 . 2011-10-22 22:26 -------- d-----w- c:\program files (x86)\LeeGT-Games
2011-10-19 19:46 . 2011-10-19 19:46 -------- d-----w- c:\program files (x86)\Microsoft Works
2011-10-19 19:45 . 2011-10-19 19:45 -------- d-----w- c:\windows\PCHEALTH
2011-10-19 19:44 . 2011-10-19 19:44 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 8
2011-10-19 19:43 . 2011-10-19 19:48 -------- d-----w- c:\programdata\Microsoft Help
2011-10-19 18:57 . 2011-10-19 18:57 -------- d-----w- c:\programdata\Sony Ericsson
2011-10-19 18:57 . 2011-10-19 18:57 -------- d-----w- c:\program files (x86)\Sony Ericsson
2011-10-19 18:49 . 2011-10-19 18:50 -------- d-----w- c:\program files\Rainmeter
2011-10-18 18:41 . 2011-10-22 17:09 -------- d-----w- c:\program files\Activision
2011-10-17 12:44 . 2011-10-17 12:44 2048 ----a-w- c:\windows\SysWow64\winver.exe
2011-10-17 12:44 . 2011-10-17 12:44 410624 ----a-w- c:\windows\SysWow64\systemcpl.dll
2011-10-17 12:44 . 2011-10-17 12:44 1536 ----a-w- c:\windows\SysWow64\sppcomapi.dll
2011-10-17 12:44 . 2011-10-17 12:44 113543 ----a-w- c:\windows\SysWow64\slmgr.vbs
2011-10-17 12:44 . 2010-11-20 12:08 833024 ----a-w- c:\windows\SysWow64\user32.dll
2011-10-16 13:59 . 2011-10-16 13:59 -------- d-----w- c:\program files\SlySoft
2011-10-16 13:56 . 2011-10-16 13:56 -------- d-----w- c:\programdata\Elaborate Bytes
2011-10-16 13:47 . 2011-10-16 13:47 -------- d-----w- c:\program files\Elaborate Bytes
2011-10-16 12:46 . 2011-10-16 12:46 -------- d-----w- c:\program files (x86)\AMD
2011-10-16 12:17 . 2011-10-16 12:17 -------- d-----w- c:\program files\PowerISO
2011-10-16 12:17 . 2011-06-15 08:30 93240 ----a-w- c:\windows\system32\drivers\scdemu.sys
2011-10-16 12:14 . 2011-10-16 12:14 -------- d-----w- c:\program files\Common Files\Adobe
2011-10-16 07:03 . 2011-10-16 07:03 -------- d-----w- c:\program files\Kouzelny morsky svet 3 - Dobrodruzstvi v Atlantide
2011-10-15 19:21 . 2008-07-31 08:41 238088 ----a-w- c:\windows\SysWow64\xactengine3_2.dll
2011-10-15 10:05 . 2011-10-15 10:09 -------- d-----w- c:\program files\Bato
2011-10-15 09:23 . 2011-10-15 09:23 -------- d-----w- c:\programdata\DVD Shrink
2011-10-15 09:23 . 2011-10-15 09:23 -------- d-----w- c:\program files\DVD Shrink
2011-10-15 04:44 . 2011-10-15 04:44 -------- d-----w- c:\windows\SysWow64\Wat
2011-10-15 04:44 . 2011-10-15 04:44 -------- d-----w- c:\windows\system32\Wat
2011-10-14 22:54 . 2011-10-14 22:54 321856 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2011-10-14 07:12 . 2010-02-09 14:37 65602 ----a-w- c:\windows\SysWow64\cook3260.dll
2011-10-14 07:12 . 2010-02-09 14:37 626688 ----a-w- c:\windows\SysWow64\vp7vfw.dll
2011-10-14 07:12 . 2010-02-09 14:37 217127 ----a-w- c:\windows\SysWow64\drv43260.dll
2011-10-14 07:12 . 2010-02-09 14:37 208935 ----a-w- c:\windows\SysWow64\drv33260.dll
2011-10-14 07:12 . 2010-02-09 14:37 176165 ----a-w- c:\windows\SysWow64\drv23260.dll
2011-10-14 07:12 . 2010-02-09 14:37 1184984 ----a-w- c:\windows\SysWow64\wvc1dmod.dll
2011-10-14 07:12 . 2010-02-09 14:37 102439 ----a-w- c:\windows\SysWow64\sipr3260.dll
2011-10-14 07:12 . 2011-10-14 07:12 -------- d-----w- c:\program files (x86)\VSO
2011-10-14 07:12 . 2011-10-14 07:12 -------- d-----w- c:\program files\VSO
2011-10-14 06:17 . 2011-09-21 07:00 9049936 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7CDFC904-F5B8-4ED4-8060-60432DD6B53C}\mpengine.dll
2011-10-13 22:55 . 2011-10-18 15:55 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2011-10-13 22:50 . 2011-10-13 22:50 -------- d-----w- c:\program files (x86)\Common Files\Adobe AIR
2011-10-13 22:04 . 2009-09-10 06:28 311808 ----a-w- c:\windows\system32\msv1_0.dll
2011-10-13 22:04 . 2009-09-10 05:52 257024 ----a-w- c:\windows\SysWow64\msv1_0.dll
2011-10-13 21:59 . 2011-10-13 21:59 -------- d-----w- c:\program files (x86)\MSXML 4.0
2011-10-13 21:57 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2011-10-13 12:12 . 2010-12-18 06:11 714752 ----a-w- c:\windows\system32\kerberos.dll
2011-10-13 12:12 . 2010-12-18 05:29 541184 ----a-w- c:\windows\SysWow64\kerberos.dll
2011-10-13 12:12 . 2011-07-09 05:14 2048 ----a-w- c:\windows\system32\tzres.dll
2011-10-13 12:12 . 2011-07-09 04:30 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-10-13 12:12 . 2011-06-15 09:58 212992 ----a-w- c:\windows\system32\odbctrac.dll
2011-10-13 12:12 . 2011-06-15 09:58 163840 ----a-w- c:\windows\system32\odbccp32.dll
2011-10-13 12:12 . 2011-06-15 09:58 106496 ----a-w- c:\windows\system32\odbccu32.dll
2011-10-13 12:12 . 2011-06-15 09:58 106496 ----a-w- c:\windows\system32\odbccr32.dll
2011-10-13 12:12 . 2011-06-15 09:58 126976 ----a-w- c:\program files\Common Files\System\Ole DB\msdaosp.dll
2011-10-13 12:12 . 2011-06-15 09:04 319488 ----a-w- c:\windows\SysWow64\odbcjt32.dll
2011-10-13 12:12 . 2011-06-15 09:04 122880 ----a-w- c:\windows\SysWow64\odbccp32.dll
2011-10-13 12:10 . 2010-08-21 06:36 340992 ----a-w- c:\windows\system32\schannel.dll
2011-10-13 12:09 . 2010-06-19 06:53 52224 ----a-w- c:\windows\system32\rtutils.dll
2011-10-13 12:08 . 2010-08-21 06:38 1024512 ----a-w- c:\windows\system32\wmpmde.dll
2011-10-13 12:07 . 2011-02-05 12:41 640896 ----a-w- c:\windows\system32\winload.efi
2011-10-13 12:06 . 2011-06-21 06:27 1896832 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-10-13 10:30 . 2011-10-13 10:30 -------- d-----w- c:\program files\Audiograbber
2011-10-13 06:09 . 2009-11-25 19:47 49472 ----a-w- c:\windows\SysWow64\netfxperf.dll
2011-10-13 06:09 . 2009-11-25 19:47 297808 ----a-w- c:\windows\SysWow64\mscoree.dll
2011-10-13 06:09 . 2009-11-25 19:47 99176 ----a-w- c:\windows\SysWow64\PresentationHostProxy.dll
2011-10-13 06:09 . 2009-11-25 19:47 48960 ----a-w- c:\windows\system32\netfxperf.dll
2011-10-13 06:09 . 2009-11-25 19:47 295264 ----a-w- c:\windows\SysWow64\PresentationHost.exe
2011-10-13 06:09 . 2009-11-25 19:47 1130824 ----a-w- c:\windows\SysWow64\dfshim.dll
2011-10-13 06:09 . 2009-11-25 19:47 109912 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2011-10-13 06:09 . 2009-11-25 19:47 444752 ----a-w- c:\windows\system32\mscoree.dll
2011-10-13 06:09 . 2009-11-25 19:47 320352 ----a-w- c:\windows\system32\PresentationHost.exe
2011-10-13 06:09 . 2009-11-25 19:47 1942856 ----a-w- c:\windows\system32\dfshim.dll
2011-10-13 06:06 . 2011-10-13 06:06 -------- d-----w- c:\program files\Ant Movie Catalog
2011-10-12 23:03 . 2011-10-12 23:03 -------- d-----w- c:\program files\Thoosje
2011-10-12 22:55 . 2009-07-14 01:41 332288 ----a-w- c:\windows\system32\uxtheme.dll.backup
2011-10-12 22:55 . 2009-07-14 01:41 2851328 ----a-w- c:\windows\system32\themeui.dll.backup
2011-10-12 22:54 . 2009-07-14 01:41 44544 ----a-w- c:\windows\system32\themeservice.dll.backup
2011-10-12 22:49 . 2011-10-13 15:40 -------- d-----w- c:\program files\Cesta za dobrodružstvím - Kouzelné obrazy
2011-10-12 22:48 . 2011-10-12 22:48 -------- d-----w- c:\program files\Filipova dobrodružství - Na stopě rodinným pokladům
2011-10-12 22:47 . 2011-10-12 22:47 -------- d-----w- c:\program files\Feng Šuej Mahjong
2011-10-12 22:46 . 2011-10-14 09:19 -------- d-----w- c:\program files\Egyptský míč
2011-10-12 22:46 . 2011-10-12 22:46 -------- d-----w- c:\program files\Dobrý farmář
2011-10-12 22:44 . 2011-10-12 22:44 -------- d-----w- c:\program files\Alex Kočičák
2011-10-12 22:43 . 2011-10-12 22:44 -------- d-----w- c:\program files\Alenka 2 - Kouzelná země
2011-10-12 22:42 . 2011-10-12 22:43 -------- d-----w- c:\program files\Ledova kralovna 3 - Vrani carodejka
2011-10-12 22:41 . 2011-10-20 11:11 -------- d-----w- c:\program files\Zachraň Kamarády!
2011-10-12 22:40 . 2011-10-12 22:40 -------- d-----w- c:\program files\Výprava do Květinové země
2011-10-12 22:40 . 2011-10-18 23:26 -------- d-----w- c:\program files\Polární dobrodružství 2
2011-10-12 22:39 . 2011-10-12 22:39 -------- d-----w- c:\program files\Nádherná zahrada
2011-10-12 22:39 . 2011-10-12 22:39 -------- d-----w- c:\program files\Mořské dobrodružství
2011-10-12 22:38 . 2011-10-12 22:38 -------- d-----w- c:\program files\Medvěd Míša - Zakletý hrad
2011-10-12 22:37 . 2011-10-13 08:06 -------- d-----w- c:\program files\Medvěd Míša - Cesta kolem světa
2011-10-12 22:36 . 2011-10-12 22:36 -------- d-----w- c:\program files\Medvěd Míša ve vesmíru
2011-10-12 22:05 . 2011-10-12 22:05 -------- d-----w- c:\programdata\Nero
2011-10-12 22:05 . 2011-10-12 22:06 -------- d-----w- c:\program files (x86)\Common Files\Nero
2011-10-12 22:05 . 2011-10-12 22:05 -------- d-----w- c:\program files (x86)\Nero
2011-10-12 21:57 . 2011-10-13 06:11 -------- d-----w- c:\program files (x86)\Microsoft.NET
2011-10-12 21:57 . 2009-09-04 15:29 1974616 ----a-w- c:\windows\SysWow64\D3DCompiler_42.dll
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-12 22:55 . 2009-07-13 23:55 332288 ----a-w- c:\windows\system32\uxtheme.dll
2011-10-12 22:55 . 2009-07-13 23:54 2851328 ----a-w- c:\windows\system32\themeui.dll
2011-10-12 22:54 . 2009-07-13 23:54 44544 ----a-w- c:\windows\system32\themeservice.dll
2011-08-09 11:57 . 2011-08-09 11:57 202576 ----a-w- c:\windows\system32\drivers\eamonm.sys
2011-08-04 07:20 . 2011-08-04 07:20 146432 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2011-08-04 07:20 . 2011-08-04 07:20 137144 ----a-w- c:\windows\system32\drivers\epfwwfpr.sys
2011-08-12 06:34 . 2011-10-12 22:22 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2010-11-20 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
[7] 2009-07-14 . 72D7B3EA16946E8F0CF7458150031CC6 . 1008640 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[-] 2009-07-14 . E573BD9AB55C8E333C202B9E255F972E . 1008640 . . [6.1.7600.16385] .. c:\windows\system32\user32.dll
.
((((((((((((((((((((((((((((( SnapShot@2011-10-29_21.07.53 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-10-12 11:37 . 2011-10-30 05:37 31986 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-10-30 10:53 30510 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2011-10-12 10:51 . 2011-10-29 18:41 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-10-12 10:51 . 2011-10-30 00:30 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-10-12 10:51 . 2011-10-29 18:41 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2011-10-12 10:51 . 2011-10-30 00:30 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-10-29 18:41 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-10-30 00:30 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-10-17 04:06 . 2011-10-30 10:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-10-17 04:06 . 2011-10-29 19:18 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-10-17 04:06 . 2011-10-30 10:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2011-10-17 04:06 . 2011-10-29 19:18 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-10-16 23:07 . 2011-10-30 04:29 3290 c:\windows\system32\wdi\ERCQueuedResolutions.dat
+ 2011-10-12 10:55 . 2011-10-30 10:53 6446 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4042068987-915908620-2276306216-1000_UserData.bin
- 2011-10-29 21:06 . 2011-10-29 21:06 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-10-30 10:51 . 2011-10-30 10:51 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-10-30 10:51 . 2011-10-30 10:51 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-10-29 21:06 . 2011-10-29 21:06 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-14 02:36 . 2011-10-30 08:12 652096 c:\windows\system32\perfh009.dat
- 2009-07-14 02:36 . 2011-10-29 19:17 652096 c:\windows\system32\perfh009.dat
+ 2009-07-26 18:41 . 2011-10-30 08:12 658244 c:\windows\system32\perfh005.dat
- 2009-07-26 18:41 . 2011-10-29 19:17 658244 c:\windows\system32\perfh005.dat
+ 2009-07-14 02:36 . 2011-10-30 08:12 121028 c:\windows\system32\perfc009.dat
- 2009-07-14 02:36 . 2011-10-29 19:17 121028 c:\windows\system32\perfc009.dat
+ 2009-07-26 18:41 . 2011-10-30 08:12 139930 c:\windows\system32\perfc005.dat
- 2009-07-26 18:41 . 2011-10-29 19:17 139930 c:\windows\system32\perfc005.dat
- 2009-07-14 05:12 . 2011-10-24 19:53 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-07-14 05:12 . 2011-10-30 00:30 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2009-07-14 02:34 . 2011-10-29 19:02 10485760 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-07-14 02:34 . 2011-10-30 05:45 10485760 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"BCU"="c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe" [2009-10-15 375000]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2009-10-02 284696]
"amd_dc_opt"="c:\program files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
.
c:\users\Tomino\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDockPlus2\ObjectDock.exe [2011-10-12 4142448]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Rainmeter.lnk - c:\program files\Rainmeter\Rainmeter.exe [2010-6-13 113664]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe [x]
R3 DfSdkS;Defragmentation-Service;c:\program files\Ashampoo\Ashampoo HDD Control 2\DfSdkS64.exe [2009-08-24 544768]
R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys [2011-10-12 30528]
R3 s1039bus;Sony Ericsson Device 1039 driver (WDM);c:\windows\system32\DRIVERS\s1039bus.sys [x]
R3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s1039mdfl.sys [x]
R3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s1039mdm.sys [x]
R3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s1039mgmt.sys [x]
R3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS);c:\windows\system32\DRIVERS\s1039nd5.sys [x]
R3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s1039obex.sys [x]
R3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM);c:\windows\system32\DRIVERS\s1039unic.sys [x]
R3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-06-29 155344]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys [x]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 AHDDC2;Ashampoo HDD Control 2 Service;c:\program files\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Service.exe [2011-09-22 1515936]
S2 BCUService;Browser Configuration Utility Service;c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2009-10-15 223464]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2011-09-08 974944]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-10-02 13336]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-15 2253120]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-14 381248]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-09-30 2320920]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
c:\program files\Alwil Software\Avast5\ashShA64.dll [BU]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ashampoo HDD-Control 2 Guard"="c:\program files\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Guard.exe" [2011-09-22 3775904]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-08-26 12681320]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-09-08 4030008]
"combofix"="c:\combofix\CF4312.3XE" [2009-07-14 344576]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984D045-52CF-49cd-DB77-08F378FEA4DB}"= "c:\program files\Stardock\ObjectDockPlus2\ODMenu64.dll" [2010-03-24 633200]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 80.242.44.36 80.242.44.85
FF - ProfilePath - c:\users\Tomino\AppData\Roaming\Mozilla\Firefox\Profiles\ihu3m3g2.default\
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-IMFservice
AddRemove-Advanced SystemCare 4_is1 - c:\program files\IObit\Advanced SystemCare 4\unins000.exe
AddRemove-Game Booster_is1 - c:\program files\IObit\Game Booster\unins000.exe
AddRemove-IObit Malware Fighter_is1 - c:\program files\IObit\IObit Malware Fighter\unins000.exe
AddRemove-Smart Defrag 2_is1 - c:\program files\IObit\Smart Defrag 2\unins000.exe
AddRemove-uTorrentBar Toolbar - c:\program files (x86)\uTorrentBar\uninstall.exe
AddRemove-WinRAR archiver - c:\program files\uninstall.exe
.
.
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Completion time: 2011-10-30 11:56:57 - machine was rebooted
ComboFix-quarantined-files.txt 2011-10-30 10:56
ComboFix2.txt 2011-10-29 21:14
.
Pre-Run: 36 172 197 888 bytes free
Post-Run: 35 935 133 696 bytes free
.
- - End Of File - - 816086C0E5FFD367DBC6F422A65524B3

Re: Facebook vír

Napsal: 30 říj 2011 12:00
od ceasare
Tu je log z combofix

Re: Facebook vír

Napsal: 30 říj 2011 14:45
od vyosek
Jeste jeden skript - postup je stejny

Kód: Vybrat vše

KillAll::

Folder::
c:\windows\update.tray-7-0
c:\windows\ufa

Restore::
c:\windows\system32\user32.dll

Reboot::

Re: Facebook vír

Napsal: 30 říj 2011 21:35
od ceasare
ComboFix 11-10-30.03 - Tomino . 10. 2011 21:20:07.3.4 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.421.1051.18.3959.2961 [GMT 1:00]
Running from: c:\users\Tomino\Desktop\ComboFix.exe
Command switches used :: c:\users\Tomino\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\ufa
c:\windows\update.tray-7-0
.
.
((((((((((((((((((((((((( Files Created from 2011-09-28 to 2011-10-30 )))))))))))))))))))))))))))))))
.
.
2011-10-30 20:25 . 2011-10-30 20:25 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-10-29 20:17 . 2011-10-29 20:18 -------- d-----w- c:\program files\trend micro
2011-10-29 20:17 . 2011-10-29 20:29 -------- d-----w- C:\rsit
2011-10-29 15:15 . 2011-10-29 15:15 -------- d-----w- c:\program files\ESET
2011-10-29 15:07 . 2011-10-29 15:07 -------- d-----w- c:\programdata\Malwarebytes
2011-10-29 15:07 . 2011-08-31 15:00 25416 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-10-29 14:34 . 2011-10-29 20:13 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-10-29 14:14 . 2011-01-05 16:12 489552 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-10-29 14:14 . 2011-01-05 16:12 272976 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-10-29 14:14 . 2011-01-05 16:08 29264 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-10-29 14:14 . 2011-01-05 16:08 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-10-29 14:14 . 2011-01-05 16:11 51792 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-10-29 14:14 . 2011-01-05 16:08 62032 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-10-29 14:14 . 2011-01-05 16:19 237168 ----a-w- c:\windows\system32\aswBoot.exe
2011-10-29 14:14 . 2011-01-05 16:19 38848 ----a-w- c:\windows\avastSS.scr
2011-10-29 14:14 . 2011-01-05 16:19 188216 ----a-w- c:\windows\SysWow64\aswBoot.exe
2011-10-26 06:29 . 2011-10-26 06:29 -------- d-----w- c:\windows\SysWow64\RTCOM
2011-10-25 06:55 . 2011-10-25 07:36 -------- d-----w- c:\program files\Battlefield 3
2011-10-24 19:53 . 2011-10-24 19:53 -------- d-----w- c:\program files (x86)\Tajemství šesti moří
2011-10-24 19:48 . 2011-10-24 19:48 -------- d-----w- c:\programdata\DivoGames
2011-10-24 19:47 . 2011-10-24 19:48 -------- d-----w- c:\program files (x86)\Poklady starověké sluje
2011-10-24 19:41 . 2011-10-24 19:41 -------- d-----w- c:\program files (x86)\Spidla
2011-10-24 19:35 . 2011-10-24 19:37 -------- d-----w- c:\program files (x86)\Táta hrdina
2011-10-24 19:30 . 2011-10-24 19:31 -------- d-----w- c:\program files (x86)\Ledové Drahokamy
2011-10-22 22:28 . 2011-10-22 22:28 -------- d-----w- c:\programdata\Playrix Entertainment
2011-10-22 22:26 . 2011-10-22 22:26 -------- d-----w- c:\program files (x86)\LeeGT-Games
2011-10-19 19:46 . 2011-10-19 19:46 -------- d-----w- c:\program files (x86)\Microsoft Works
2011-10-19 19:45 . 2011-10-19 19:45 -------- d-----w- c:\windows\PCHEALTH
2011-10-19 19:44 . 2011-10-19 19:44 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 8
2011-10-19 19:43 . 2011-10-19 19:48 -------- d-----w- c:\programdata\Microsoft Help
2011-10-19 18:57 . 2011-10-19 18:57 -------- d-----w- c:\programdata\Sony Ericsson
2011-10-19 18:57 . 2011-10-19 18:57 -------- d-----w- c:\program files (x86)\Sony Ericsson
2011-10-19 18:49 . 2011-10-19 18:50 -------- d-----w- c:\program files\Rainmeter
2011-10-18 18:41 . 2011-10-22 17:09 -------- d-----w- c:\program files\Activision
2011-10-17 12:44 . 2011-10-17 12:44 2048 ----a-w- c:\windows\SysWow64\winver.exe
2011-10-17 12:44 . 2011-10-17 12:44 410624 ----a-w- c:\windows\SysWow64\systemcpl.dll
2011-10-17 12:44 . 2011-10-17 12:44 1536 ----a-w- c:\windows\SysWow64\sppcomapi.dll
2011-10-17 12:44 . 2011-10-17 12:44 113543 ----a-w- c:\windows\SysWow64\slmgr.vbs
2011-10-17 12:44 . 2010-11-20 12:08 833024 ----a-w- c:\windows\SysWow64\user32.dll
2011-10-16 13:59 . 2011-10-16 13:59 -------- d-----w- c:\program files\SlySoft
2011-10-16 13:56 . 2011-10-16 13:56 -------- d-----w- c:\programdata\Elaborate Bytes
2011-10-16 13:47 . 2011-10-16 13:47 -------- d-----w- c:\program files\Elaborate Bytes
2011-10-16 12:46 . 2011-10-16 12:46 -------- d-----w- c:\program files (x86)\AMD
2011-10-16 12:17 . 2011-10-16 12:17 -------- d-----w- c:\program files\PowerISO
2011-10-16 12:17 . 2011-06-15 08:30 93240 ----a-w- c:\windows\system32\drivers\scdemu.sys
2011-10-16 12:14 . 2011-10-16 12:14 -------- d-----w- c:\program files\Common Files\Adobe
2011-10-16 07:03 . 2011-10-16 07:03 -------- d-----w- c:\program files\Kouzelny morsky svet 3 - Dobrodruzstvi v Atlantide
2011-10-15 19:21 . 2008-07-31 08:41 238088 ----a-w- c:\windows\SysWow64\xactengine3_2.dll
2011-10-15 10:05 . 2011-10-15 10:09 -------- d-----w- c:\program files\Bato
2011-10-15 09:23 . 2011-10-15 09:23 -------- d-----w- c:\programdata\DVD Shrink
2011-10-15 09:23 . 2011-10-15 09:23 -------- d-----w- c:\program files\DVD Shrink
2011-10-15 04:44 . 2011-10-15 04:44 -------- d-----w- c:\windows\SysWow64\Wat
2011-10-15 04:44 . 2011-10-15 04:44 -------- d-----w- c:\windows\system32\Wat
2011-10-14 22:54 . 2011-10-14 22:54 321856 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2011-10-14 07:12 . 2010-02-09 14:37 65602 ----a-w- c:\windows\SysWow64\cook3260.dll
2011-10-14 07:12 . 2010-02-09 14:37 626688 ----a-w- c:\windows\SysWow64\vp7vfw.dll
2011-10-14 07:12 . 2010-02-09 14:37 217127 ----a-w- c:\windows\SysWow64\drv43260.dll
2011-10-14 07:12 . 2010-02-09 14:37 208935 ----a-w- c:\windows\SysWow64\drv33260.dll
2011-10-14 07:12 . 2010-02-09 14:37 176165 ----a-w- c:\windows\SysWow64\drv23260.dll
2011-10-14 07:12 . 2010-02-09 14:37 1184984 ----a-w- c:\windows\SysWow64\wvc1dmod.dll
2011-10-14 07:12 . 2010-02-09 14:37 102439 ----a-w- c:\windows\SysWow64\sipr3260.dll
2011-10-14 07:12 . 2011-10-14 07:12 -------- d-----w- c:\program files (x86)\VSO
2011-10-14 07:12 . 2011-10-14 07:12 -------- d-----w- c:\program files\VSO
2011-10-14 06:17 . 2011-09-21 07:00 9049936 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7CDFC904-F5B8-4ED4-8060-60432DD6B53C}\mpengine.dll
2011-10-13 22:55 . 2011-10-18 15:55 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2011-10-13 22:50 . 2011-10-13 22:50 -------- d-----w- c:\program files (x86)\Common Files\Adobe AIR
2011-10-13 22:04 . 2009-09-10 06:28 311808 ----a-w- c:\windows\system32\msv1_0.dll
2011-10-13 22:04 . 2009-09-10 05:52 257024 ----a-w- c:\windows\SysWow64\msv1_0.dll
2011-10-13 21:59 . 2011-10-13 21:59 -------- d-----w- c:\program files (x86)\MSXML 4.0
2011-10-13 21:57 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2011-10-13 12:12 . 2010-12-18 06:11 714752 ----a-w- c:\windows\system32\kerberos.dll
2011-10-13 12:12 . 2010-12-18 05:29 541184 ----a-w- c:\windows\SysWow64\kerberos.dll
2011-10-13 12:12 . 2011-07-09 05:14 2048 ----a-w- c:\windows\system32\tzres.dll
2011-10-13 12:12 . 2011-07-09 04:30 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-10-13 12:12 . 2011-06-15 09:58 212992 ----a-w- c:\windows\system32\odbctrac.dll
2011-10-13 12:12 . 2011-06-15 09:58 163840 ----a-w- c:\windows\system32\odbccp32.dll
2011-10-13 12:12 . 2011-06-15 09:58 106496 ----a-w- c:\windows\system32\odbccu32.dll
2011-10-13 12:12 . 2011-06-15 09:58 106496 ----a-w- c:\windows\system32\odbccr32.dll
2011-10-13 12:12 . 2011-06-15 09:58 126976 ----a-w- c:\program files\Common Files\System\Ole DB\msdaosp.dll
2011-10-13 12:12 . 2011-06-15 09:04 319488 ----a-w- c:\windows\SysWow64\odbcjt32.dll
2011-10-13 12:12 . 2011-06-15 09:04 122880 ----a-w- c:\windows\SysWow64\odbccp32.dll
2011-10-13 12:10 . 2010-08-21 06:36 340992 ----a-w- c:\windows\system32\schannel.dll
2011-10-13 12:09 . 2010-06-19 06:53 52224 ----a-w- c:\windows\system32\rtutils.dll
2011-10-13 12:08 . 2010-08-21 06:38 1024512 ----a-w- c:\windows\system32\wmpmde.dll
2011-10-13 12:07 . 2011-02-05 12:41 640896 ----a-w- c:\windows\system32\winload.efi
2011-10-13 12:06 . 2011-06-21 06:27 1896832 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-10-13 10:30 . 2011-10-13 10:30 -------- d-----w- c:\program files\Audiograbber
2011-10-13 06:09 . 2009-11-25 19:47 49472 ----a-w- c:\windows\SysWow64\netfxperf.dll
2011-10-13 06:09 . 2009-11-25 19:47 297808 ----a-w- c:\windows\SysWow64\mscoree.dll
2011-10-13 06:09 . 2009-11-25 19:47 99176 ----a-w- c:\windows\SysWow64\PresentationHostProxy.dll
2011-10-13 06:09 . 2009-11-25 19:47 48960 ----a-w- c:\windows\system32\netfxperf.dll
2011-10-13 06:09 . 2009-11-25 19:47 295264 ----a-w- c:\windows\SysWow64\PresentationHost.exe
2011-10-13 06:09 . 2009-11-25 19:47 1130824 ----a-w- c:\windows\SysWow64\dfshim.dll
2011-10-13 06:09 . 2009-11-25 19:47 109912 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2011-10-13 06:09 . 2009-11-25 19:47 444752 ----a-w- c:\windows\system32\mscoree.dll
2011-10-13 06:09 . 2009-11-25 19:47 320352 ----a-w- c:\windows\system32\PresentationHost.exe
2011-10-13 06:09 . 2009-11-25 19:47 1942856 ----a-w- c:\windows\system32\dfshim.dll
2011-10-13 06:06 . 2011-10-13 06:06 -------- d-----w- c:\program files\Ant Movie Catalog
2011-10-12 23:03 . 2011-10-12 23:03 -------- d-----w- c:\program files\Thoosje
2011-10-12 22:55 . 2009-07-14 01:41 332288 ----a-w- c:\windows\system32\uxtheme.dll.backup
2011-10-12 22:55 . 2009-07-14 01:41 2851328 ----a-w- c:\windows\system32\themeui.dll.backup
2011-10-12 22:54 . 2009-07-14 01:41 44544 ----a-w- c:\windows\system32\themeservice.dll.backup
2011-10-12 22:49 . 2011-10-13 15:40 -------- d-----w- c:\program files\Cesta za dobrodružstvím - Kouzelné obrazy
2011-10-12 22:48 . 2011-10-12 22:48 -------- d-----w- c:\program files\Filipova dobrodružství - Na stopě rodinným pokladům
2011-10-12 22:47 . 2011-10-12 22:47 -------- d-----w- c:\program files\Feng Šuej Mahjong
2011-10-12 22:46 . 2011-10-14 09:19 -------- d-----w- c:\program files\Egyptský míč
2011-10-12 22:46 . 2011-10-12 22:46 -------- d-----w- c:\program files\Dobrý farmář
2011-10-12 22:44 . 2011-10-12 22:44 -------- d-----w- c:\program files\Alex Kočičák
2011-10-12 22:43 . 2011-10-12 22:44 -------- d-----w- c:\program files\Alenka 2 - Kouzelná země
2011-10-12 22:42 . 2011-10-12 22:43 -------- d-----w- c:\program files\Ledova kralovna 3 - Vrani carodejka
2011-10-12 22:41 . 2011-10-20 11:11 -------- d-----w- c:\program files\Zachraň Kamarády!
2011-10-12 22:40 . 2011-10-12 22:40 -------- d-----w- c:\program files\Výprava do Květinové země
2011-10-12 22:40 . 2011-10-18 23:26 -------- d-----w- c:\program files\Polární dobrodružství 2
2011-10-12 22:39 . 2011-10-12 22:39 -------- d-----w- c:\program files\Nádherná zahrada
2011-10-12 22:39 . 2011-10-12 22:39 -------- d-----w- c:\program files\Mořské dobrodružství
2011-10-12 22:38 . 2011-10-12 22:38 -------- d-----w- c:\program files\Medvěd Míša - Zakletý hrad
2011-10-12 22:37 . 2011-10-13 08:06 -------- d-----w- c:\program files\Medvěd Míša - Cesta kolem světa
2011-10-12 22:36 . 2011-10-12 22:36 -------- d-----w- c:\program files\Medvěd Míša ve vesmíru
2011-10-12 22:05 . 2011-10-12 22:05 -------- d-----w- c:\programdata\Nero
2011-10-12 22:05 . 2011-10-12 22:06 -------- d-----w- c:\program files (x86)\Common Files\Nero
2011-10-12 22:05 . 2011-10-12 22:05 -------- d-----w- c:\program files (x86)\Nero
2011-10-12 21:57 . 2011-10-13 06:11 -------- d-----w- c:\program files (x86)\Microsoft.NET
2011-10-12 21:57 . 2009-09-04 15:29 1974616 ----a-w- c:\windows\SysWow64\D3DCompiler_42.dll
2011-10-12 21:57 . 2009-09-04 15:29 1892184 ----a-w- c:\windows\SysWow64\D3DX9_42.dll
2011-10-12 21:56 . 2008-10-15 04:22 4379984 ----a-w- c:\windows\SysWow64\D3DX9_40.dll
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-12 22:55 . 2009-07-13 23:55 332288 ----a-w- c:\windows\system32\uxtheme.dll
2011-10-12 22:55 . 2009-07-13 23:54 2851328 ----a-w- c:\windows\system32\themeui.dll
2011-10-12 22:54 . 2009-07-13 23:54 44544 ----a-w- c:\windows\system32\themeservice.dll
2011-08-09 11:57 . 2011-08-09 11:57 202576 ----a-w- c:\windows\system32\drivers\eamonm.sys
2011-08-04 07:20 . 2011-08-04 07:20 146432 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2011-08-04 07:20 . 2011-08-04 07:20 137144 ----a-w- c:\windows\system32\drivers\epfwwfpr.sys
2011-08-12 06:34 . 2011-10-12 22:22 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2010-11-20 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
[7] 2009-07-14 . 72D7B3EA16946E8F0CF7458150031CC6 . 1008640 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[-] 2009-07-14 . E573BD9AB55C8E333C202B9E255F972E . 1008640 . . [6.1.7600.16385] .. c:\windows\system32\user32.dll
.
((((((((((((((((((((((((((((( SnapShot@2011-10-29_21.07.53 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-10-12 11:37 . 2011-10-30 20:29 32192 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-10-30 20:29 30534 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2011-10-12 10:51 . 2011-10-29 18:41 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-10-12 10:51 . 2011-10-30 00:30 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-10-12 10:51 . 2011-10-29 18:41 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2011-10-12 10:51 . 2011-10-30 00:30 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-10-29 18:41 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-10-30 00:30 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-10-17 04:06 . 2011-10-30 20:00 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-10-17 04:06 . 2011-10-29 19:18 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-10-17 04:06 . 2011-10-30 20:00 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2011-10-17 04:06 . 2011-10-29 19:18 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-10-16 23:07 . 2011-10-30 04:29 3290 c:\windows\system32\wdi\ERCQueuedResolutions.dat
+ 2011-10-12 10:55 . 2011-10-30 10:53 6446 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4042068987-915908620-2276306216-1000_UserData.bin
- 2011-10-29 21:06 . 2011-10-29 21:06 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-10-30 20:27 . 2011-10-30 20:27 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-10-30 20:27 . 2011-10-30 20:27 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-10-29 21:06 . 2011-10-29 21:06 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-14 02:36 . 2011-10-30 12:49 652096 c:\windows\system32\perfh009.dat
- 2009-07-14 02:36 . 2011-10-29 19:17 652096 c:\windows\system32\perfh009.dat
+ 2009-07-26 18:41 . 2011-10-30 12:49 658244 c:\windows\system32\perfh005.dat
- 2009-07-26 18:41 . 2011-10-29 19:17 658244 c:\windows\system32\perfh005.dat
+ 2009-07-14 02:36 . 2011-10-30 12:49 121028 c:\windows\system32\perfc009.dat
- 2009-07-14 02:36 . 2011-10-29 19:17 121028 c:\windows\system32\perfc009.dat
+ 2009-07-26 18:41 . 2011-10-30 12:49 139930 c:\windows\system32\perfc005.dat
- 2009-07-26 18:41 . 2011-10-29 19:17 139930 c:\windows\system32\perfc005.dat
- 2009-07-14 05:12 . 2011-10-24 19:53 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-07-14 05:12 . 2011-10-30 00:30 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2009-07-14 02:34 . 2011-10-29 19:02 10485760 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-07-14 02:34 . 2011-10-30 12:00 10485760 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2011-10-20 641400]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"BCU"="c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe" [2009-10-15 375000]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2009-10-02 284696]
"amd_dc_opt"="c:\program files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
.
c:\users\Tomino\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDockPlus2\ObjectDock.exe [2011-10-12 4142448]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Rainmeter.lnk - c:\program files\Rainmeter\Rainmeter.exe [2010-6-13 113664]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe [x]
R3 DfSdkS;Defragmentation-Service;c:\program files\Ashampoo\Ashampoo HDD Control 2\DfSdkS64.exe [2009-08-24 544768]
R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys [2011-10-12 30528]
R3 s1039bus;Sony Ericsson Device 1039 driver (WDM);c:\windows\system32\DRIVERS\s1039bus.sys [x]
R3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s1039mdfl.sys [x]
R3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s1039mdm.sys [x]
R3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s1039mgmt.sys [x]
R3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS);c:\windows\system32\DRIVERS\s1039nd5.sys [x]
R3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s1039obex.sys [x]
R3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM);c:\windows\system32\DRIVERS\s1039unic.sys [x]
R3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-06-29 155344]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys [x]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 AHDDC2;Ashampoo HDD Control 2 Service;c:\program files\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Service.exe [2011-09-22 1515936]
S2 BCUService;Browser Configuration Utility Service;c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2009-10-15 223464]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2011-09-08 974944]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-10-02 13336]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-15 2253120]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-14 381248]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-09-30 2320920]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
c:\program files\Alwil Software\Avast5\ashShA64.dll [BU]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ashampoo HDD-Control 2 Guard"="c:\program files\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Guard.exe" [2011-09-22 3775904]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-08-26 12681320]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-09-08 4030008]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984D045-52CF-49cd-DB77-08F378FEA4DB}"= "c:\program files\Stardock\ObjectDockPlus2\ODMenu64.dll" [2010-03-24 633200]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 80.242.44.36 80.242.44.85
FF - ProfilePath - c:\users\Tomino\AppData\Roaming\Mozilla\Firefox\Profiles\ihu3m3g2.default\
.
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Completion time: 2011-10-30 21:34:00 - machine was rebooted
ComboFix-quarantined-files.txt 2011-10-30 20:34
ComboFix2.txt 2011-10-30 10:56
ComboFix3.txt 2011-10-29 21:14
.
Pre-Run: 35 978 760 192 bytes free
Post-Run: 35 922 300 928 bytes free
.
- - End Of File - - 769C056C77D919F8552A0C5EC7F08619

Re: Facebook vír

Napsal: 31 říj 2011 09:57
od vyosek
:arrow: Odinstalujte Combofix
  • Prejmenujte ComboFix na Uninstall
  • Spustte jej
  • Tohle smaze Combofix a jeho slozky
:arrow: T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: v nouzovem rezimu (restart PC, mackat F8, zvolit Stav nouze s praci v siti) projedte PC temito utilitami, at se zbavime zbytku antiviru co tam mate :arrow: Stahnete Ccleaner (viz muj podpis)
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: Nainstalujte zabezpeceni PC - Avast, Aviru ci MSE

:arrow: Dejte novy log z RSIT a napiste co PC

Re: Facebook vír

Napsal: 31 říj 2011 16:16
od ceasare
Log z RSIT

Logfile of random's system information tool 1.09 (written by random/random)
Run by Tomino at 2011-10-31 16:15:01
Microsoft Windows 7 Ultimate
System drive C: has 39 GB (39%) free of 100 GB
Total RAM: 3959 MB (72% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:15:08, on 31. 10. 2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16869)
Boot mode: Normal

Running processes:
C:\Program Files\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Guard.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Stardock\ObjectDockPlus2\ObjectDock.exe
C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\trend micro\Tomino.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: SearchHook Class - {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - (no file)
O4 - HKLM\..\Run: [BCU] "C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe"
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKUS\S-1-5-21-4042068987-915908620-2276306216-1001\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-4042068987-915908620-2276306216-1001\..\Run: [Google Update] "C:\Users\Tomino\AppData\Local\Google\Update\GoogleUpdate.exe" /c (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-4042068987-915908620-2276306216-1001\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-4042068987-915908620-2276306216-1001\..\Run: [Advanced SystemCare 4] C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-4042068987-915908620-2276306216-1001\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-4042068987-915908620-2276306216-1001\..\Run: [Sony Ericsson PC Companion] "C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" /Background (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-4042068987-915908620-2276306216-1001\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDockPlus2\ObjectDock.exe
O4 - Global Startup: Rainmeter.lnk = C:\Program Files\Rainmeter\Rainmeter.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GRA32A~1.DLL
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - (no file)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Ashampoo HDD Control 2 Service (AHDDC2) - Unknown owner - C:\Program Files\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Service.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AppleChargerSrv - Unknown owner - C:\Windows\system32\AppleChargerSrv.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Browser Configuration Utility Service (BCUService) - DeviceVM, Inc. - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe
O23 - Service: Defragmentation-Service (DfSdkS) - mst software GmbH, Germany - C:\Program Files\Ashampoo\Ashampoo HDD Control 2\DfSdkS64.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Sony Ericsson PCCompanion - Avanquest Software - C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9040 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\AUDIODG.EXE 0x2cc
C:\Windows\system32\svchost.exe -k LocalService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Service.exe"
"C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\Windows\system32\sppsvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"taskhost.exe"
taskeng.exe {8E83C082-59A9-43A5-A44F-F1FFF67316F1}
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Guard.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED
"C:\Program Files\Rainmeter\Rainmeter.exe"
"C:\Program Files\Stardock\ObjectDockPlus2\ObjectDock.exe"
"C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files\Alwil Software\Avast5\AvastUI.exe" /nogui
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files\Stardock\ObjectDockPlus2\Dock64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files\Stardock\ObjectDockPlus2\ObjectDockTray.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 512 516 524 65536 520
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Users\Tomino\Desktop\RSITx64.exe"

=========Mozilla firefox=========

ProfilePath - C:\Users\Tomino\AppData\Roaming\Mozilla\Firefox\Profiles\ihu3m3g2.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml

C:\Users\Tomino\AppData\Roaming\Mozilla\Firefox\Profiles\ihu3m3g2.default\extensions\
{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-09-05 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-26 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Ashampoo HDD-Control 2 Guard"=C:\Program Files\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Guard.exe [2011-09-22 3775904]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2011-08-26 12681320]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"=C:\Program Files\uTorrent\uTorrent.exe [2011-10-20 641400]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"BCU"=C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe [2009-10-15 375000]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2009-10-02 284696]
"amd_dc_opt"=C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [2008-07-22 77824]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-26 31016]
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2011-01-05 3396624]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Rainmeter.lnk - C:\Program Files\Rainmeter\Rainmeter.exe

C:\Users\Tomino\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Stardock ObjectDock.lnk - C:\Program Files\Stardock\ObjectDockPlus2\ObjectDock.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2009-07-14 290304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
ObjectDockShellExt - {1984D045-52CF-49cd-DB77-08F378FEA4DB} - C:\Program Files\Stardock\ObjectDockPlus2\ODMenu64.dll [2010-03-24 633200]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-26 2210608]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableSecureUIAPaths"=0
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2011-10-31 16:15:01 ----D---- C:\rsit
2011-10-31 16:06:40 ----D---- C:\ProgramData\Alwil Software
2011-10-31 16:06:40 ----D---- C:\Program Files\Alwil Software
2011-10-31 16:00:41 ----D---- C:\Program Files\CCleaner
2011-10-31 15:09:23 ----D---- C:\ProgramData\Hewlett-Packard
2011-10-31 04:20:23 ----SHD---- C:\$RECYCLE.BIN
2011-10-30 21:25:54 ----D---- C:\Windows\temp
2011-10-29 21:53:05 ----D---- C:\Windows\ERDNT
2011-10-29 21:17:46 ----D---- C:\Program Files\trend micro
2011-10-29 16:07:37 ----D---- C:\Users\Tomino\AppData\Roaming\Malwarebytes
2011-10-29 16:07:24 ----D---- C:\ProgramData\Malwarebytes
2011-10-29 16:07:20 ----A---- C:\Windows\system32\drivers\mbam.sys
2011-10-29 15:34:24 ----D---- C:\Program Files\SUPERAntiSpyware
2011-10-29 15:14:34 ----A---- C:\Windows\system32\drivers\aswSP.sys
2011-10-29 15:14:34 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2011-10-29 15:14:34 ----A---- C:\Windows\system32\drivers\aswRdr.sys
2011-10-29 15:14:34 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2011-10-29 15:14:33 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2011-10-29 15:14:32 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2011-10-29 15:14:31 ----A---- C:\Windows\system32\aswBoot.exe
2011-10-29 15:14:15 ----A---- C:\Windows\SYSWOW64\aswBoot.exe
2011-10-29 15:14:15 ----A---- C:\Windows\avastSS.scr
2011-10-26 09:54:03 ----A---- C:\Windows\system32\nvhdap64.dll
2011-10-26 09:54:03 ----A---- C:\Windows\system32\nvhdagenco6420102.dll
2011-10-26 09:54:03 ----A---- C:\Windows\system32\drivers\nvhda64v.sys
2011-10-26 09:54:00 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2011-10-26 09:54:00 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2011-10-26 09:54:00 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2011-10-26 09:54:00 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2011-10-26 09:54:00 ----A---- C:\Windows\SYSWOW64\nvcuvenc.dll
2011-10-26 09:54:00 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2011-10-26 09:54:00 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2011-10-26 09:54:00 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2011-10-26 09:54:00 ----A---- C:\Windows\system32\OpenCL.dll
2011-10-26 09:54:00 ----A---- C:\Windows\system32\nvoglv64.dll
2011-10-26 09:54:00 ----A---- C:\Windows\system32\nvd3dumx.dll
2011-10-26 09:54:00 ----A---- C:\Windows\system32\nvcuvid.dll
2011-10-26 09:54:00 ----A---- C:\Windows\system32\nvcuvenc.dll
2011-10-26 09:54:00 ----A---- C:\Windows\system32\nvcuda.dll
2011-10-26 09:54:00 ----A---- C:\Windows\system32\nvcompiler.dll
2011-10-26 09:54:00 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2011-10-26 07:29:24 ----D---- C:\Windows\SYSWOW64\RTCOM
2011-10-26 07:28:57 ----A---- C:\Windows\system32\WavesGUILib.dll
2011-10-26 07:28:56 ----A---- C:\Windows\system32\SRSWOW64.dll
2011-10-26 07:28:56 ----A---- C:\Windows\system32\SRSTSX64.dll
2011-10-26 07:28:56 ----A---- C:\Windows\system32\SRSTSH64.dll
2011-10-26 07:28:56 ----A---- C:\Windows\system32\SRSHP64.dll
2011-10-26 07:28:54 ----A---- C:\Windows\system32\RtPgEx64.dll
2011-10-26 07:28:54 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2011-10-26 07:28:53 ----A---- C:\Windows\system32\drivers\RTKVHD64.sys
2011-10-26 07:28:52 ----A---- C:\Windows\system32\RtkCfg64.dll
2011-10-26 07:28:51 ----A---- C:\Windows\system32\RtkAPO64.dll
2011-10-26 07:28:51 ----A---- C:\Windows\system32\RtkApi64.dll
2011-10-26 07:28:51 ----A---- C:\Windows\system32\RTEEP64A.dll
2011-10-26 07:28:51 ----A---- C:\Windows\system32\RTEEL64A.dll
2011-10-26 07:28:51 ----A---- C:\Windows\system32\RTEEG64A.dll
2011-10-26 07:28:51 ----A---- C:\Windows\system32\RTEED64A.dll
2011-10-26 07:28:51 ----A---- C:\Windows\system32\RTCOM64.dll
2011-10-26 07:28:50 ----A---- C:\Windows\system32\RP3DHT64.dll
2011-10-26 07:28:50 ----A---- C:\Windows\system32\RP3DAA64.dll
2011-10-26 07:28:50 ----A---- C:\Windows\system32\RCoInst64.dll
2011-10-26 07:28:48 ----A---- C:\Windows\system32\MBWrp64.dll
2011-10-26 07:28:47 ----A---- C:\Windows\system32\MBppld64.dll
2011-10-26 07:28:47 ----A---- C:\Windows\system32\MBPPCn64.dll
2011-10-26 07:28:47 ----A---- C:\Windows\system32\MBAPO64.dll
2011-10-26 07:28:46 ----A---- C:\Windows\SYSWOW64\MBAPO32.dll
2011-10-26 07:28:44 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2011-10-26 07:28:44 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2011-10-26 07:28:24 ----A---- C:\Windows\system32\FMAPO64.dll
2011-10-26 07:28:16 ----A---- C:\Windows\system32\AERTAR64.dll
2011-10-26 07:28:16 ----A---- C:\Windows\system32\AERTAC64.dll
2011-10-25 07:55:59 ----D---- C:\Program Files\Battlefield 3
2011-10-24 20:53:45 ----D---- C:\Program Files (x86)\Tajemství šesti moří
2011-10-24 20:48:32 ----D---- C:\ProgramData\DivoGames
2011-10-24 20:47:55 ----D---- C:\Program Files (x86)\Poklady starověké sluje
2011-10-24 20:41:49 ----D---- C:\Program Files (x86)\Spidla
2011-10-24 20:35:02 ----D---- C:\Program Files (x86)\Táta hrdina
2011-10-24 20:31:24 ----D---- C:\Users\Tomino\AppData\Roaming\NVIDIA
2011-10-24 20:30:55 ----D---- C:\Program Files (x86)\Ledové Drahokamy
2011-10-22 23:28:12 ----D---- C:\ProgramData\Playrix Entertainment
2011-10-22 23:26:02 ----D---- C:\Program Files (x86)\LeeGT-Games
2011-10-19 20:46:55 ----D---- C:\Program Files (x86)\Microsoft Works
2011-10-19 20:46:16 ----D---- C:\Program Files (x86)\Microsoft Visual Studio
2011-10-19 20:45:44 ----D---- C:\Windows\PCHEALTH
2011-10-19 20:44:10 ----D---- C:\Program Files\Microsoft Office
2011-10-19 20:44:04 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 8
2011-10-19 20:43:17 ----D---- C:\Program Files (x86)\Microsoft Office
2011-10-19 20:43:15 ----D---- C:\ProgramData\Microsoft Help
2011-10-19 19:57:50 ----D---- C:\ProgramData\Sony Ericsson
2011-10-19 19:57:50 ----D---- C:\Program Files (x86)\Sony Ericsson
2011-10-19 19:50:17 ----D---- C:\Users\Tomino\AppData\Roaming\Rainmeter
2011-10-19 19:49:17 ----D---- C:\Program Files\Rainmeter
2011-10-18 19:41:48 ----D---- C:\Program Files\Activision
2011-10-17 13:44:11 ----A---- C:\Windows\SYSWOW64\winver.exe
2011-10-17 13:44:11 ----A---- C:\Windows\SYSWOW64\user32.dll
2011-10-17 13:44:11 ----A---- C:\Windows\SYSWOW64\systemcpl.dll
2011-10-17 13:44:11 ----A---- C:\Windows\SYSWOW64\sppcomapi.dll
2011-10-17 13:44:11 ----A---- C:\Windows\SYSWOW64\slmgr.vbs
2011-10-16 14:59:19 ----D---- C:\Program Files\SlySoft
2011-10-16 14:56:37 ----D---- C:\ProgramData\Elaborate Bytes
2011-10-16 14:47:57 ----D---- C:\Program Files\Elaborate Bytes
2011-10-16 13:46:55 ----D---- C:\Program Files (x86)\AMD
2011-10-16 13:17:05 ----D---- C:\Program Files\PowerISO
2011-10-16 13:17:05 ----A---- C:\Windows\system32\drivers\scdemu.sys
2011-10-16 13:14:51 ----D---- C:\Program Files\Common Files\Adobe
2011-10-16 13:13:17 ----D---- C:\Program Files\Adobe
2011-10-16 08:24:04 ----D---- C:\Users\Tomino\AppData\Roaming\ERS G-Studio
2011-10-16 08:03:29 ----D---- C:\Program Files\Kouzelny morsky svet 3 - Dobrodruzstvi v Atlantide
2011-10-15 20:22:21 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2011-10-15 20:22:21 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2011-10-15 20:22:21 ----A---- C:\Windows\system32\XAudio2_7.dll
2011-10-15 20:22:21 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2011-10-15 20:22:20 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2011-10-15 20:22:20 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2011-10-15 20:22:20 ----A---- C:\Windows\system32\xactengine3_7.dll
2011-10-15 20:22:20 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2011-10-15 20:22:18 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2011-10-15 20:22:18 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2011-10-15 20:22:18 ----A---- C:\Windows\system32\d3dx11_43.dll
2011-10-15 20:22:18 ----A---- C:\Windows\system32\d3dcsx_43.dll
2011-10-15 20:22:17 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2011-10-15 20:22:17 ----A---- C:\Windows\system32\d3dx10_43.dll
2011-10-15 20:22:16 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2011-10-15 20:22:16 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2011-10-15 20:22:16 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2011-10-15 20:22:16 ----A---- C:\Windows\system32\XAudio2_6.dll
2011-10-15 20:22:16 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2011-10-15 20:22:16 ----A---- C:\Windows\system32\D3DX9_43.dll
2011-10-15 20:22:15 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2011-10-15 20:22:15 ----A---- C:\Windows\system32\xactengine3_6.dll
2011-10-15 20:22:14 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2011-10-15 20:22:14 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2011-10-15 20:22:13 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2011-10-15 20:22:13 ----A---- C:\Windows\system32\XAudio2_5.dll
2011-10-15 20:22:12 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2011-10-15 20:22:12 ----A---- C:\Windows\system32\xactengine3_5.dll
2011-10-15 20:22:12 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2011-10-15 20:22:11 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2011-10-15 20:22:11 ----A---- C:\Windows\system32\d3dcsx_42.dll
2011-10-15 20:22:10 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2011-10-15 20:22:10 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2011-10-15 20:22:10 ----A---- C:\Windows\system32\d3dx11_42.dll
2011-10-15 20:22:10 ----A---- C:\Windows\system32\d3dx10_42.dll
2011-10-15 20:22:09 ----A---- C:\Windows\system32\D3DX9_42.dll
2011-10-15 20:22:08 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2011-10-15 20:22:08 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2011-10-15 20:22:08 ----A---- C:\Windows\system32\d3dx10_41.dll
2011-10-15 20:22:08 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2011-10-15 20:22:07 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2011-10-15 20:22:07 ----A---- C:\Windows\system32\D3DX9_41.dll
2011-10-15 20:22:06 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2011-10-15 20:22:06 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2011-10-15 20:22:05 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2011-10-15 20:22:05 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2011-10-15 20:22:05 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2011-10-15 20:22:05 ----A---- C:\Windows\system32\XAudio2_4.dll
2011-10-15 20:22:05 ----A---- C:\Windows\system32\xactengine3_4.dll
2011-10-15 20:22:05 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2011-10-15 20:22:04 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2011-10-15 20:22:04 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2011-10-15 20:22:04 ----A---- C:\Windows\system32\d3dx10_40.dll
2011-10-15 20:22:04 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2011-10-15 20:22:03 ----A---- C:\Windows\system32\D3DX9_40.dll
2011-10-15 20:22:02 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2011-10-15 20:22:02 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2011-10-15 20:22:02 ----A---- C:\Windows\system32\XAudio2_3.dll
2011-10-15 20:22:02 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2011-10-15 20:22:01 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2011-10-15 20:22:01 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2011-10-15 20:22:01 ----A---- C:\Windows\system32\xactengine3_3.dll
2011-10-15 20:22:01 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2011-10-15 20:22:00 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2011-10-15 20:22:00 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2011-10-15 20:22:00 ----A---- C:\Windows\system32\XAudio2_2.dll
2011-10-15 20:22:00 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2011-10-15 20:21:59 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2011-10-15 20:21:59 ----A---- C:\Windows\system32\xactengine3_2.dll
2011-10-15 20:21:58 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2011-10-15 20:21:58 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2011-10-15 20:21:58 ----A---- C:\Windows\system32\d3dx10_39.dll
2011-10-15 20:21:58 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2011-10-15 20:21:57 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2011-10-15 20:21:57 ----A---- C:\Windows\system32\D3DX9_39.dll
2011-10-15 20:21:56 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2011-10-15 20:21:56 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2011-10-15 20:21:56 ----A---- C:\Windows\system32\XAudio2_1.dll
2011-10-15 20:21:56 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2011-10-15 20:21:55 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2011-10-15 20:21:55 ----A---- C:\Windows\system32\xactengine3_1.dll
2011-10-15 20:21:54 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2011-10-15 20:21:54 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2011-10-15 20:21:54 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2011-10-15 20:21:54 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2011-10-15 20:21:54 ----A---- C:\Windows\system32\d3dx10_38.dll
2011-10-15 20:21:54 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2011-10-15 20:21:53 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2011-10-15 20:21:53 ----A---- C:\Windows\system32\D3DX9_38.dll
2011-10-15 20:21:52 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2011-10-15 20:21:52 ----A---- C:\Windows\system32\XAudio2_0.dll
2011-10-15 20:21:51 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2011-10-15 20:21:51 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2011-10-15 20:21:51 ----A---- C:\Windows\system32\xactengine3_0.dll
2011-10-15 20:21:51 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2011-10-15 20:21:48 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2011-10-15 20:21:48 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2011-10-15 20:21:48 ----A---- C:\Windows\system32\d3dx10_37.dll
2011-10-15 20:21:48 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2011-10-15 20:21:47 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2011-10-15 20:21:47 ----A---- C:\Windows\system32\D3DX9_37.dll
2011-10-15 20:21:46 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2011-10-15 20:21:46 ----A---- C:\Windows\system32\xactengine2_10.dll
2011-10-15 20:21:45 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2011-10-15 20:21:45 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2011-10-15 20:21:45 ----A---- C:\Windows\system32\d3dx10_36.dll
2011-10-15 20:21:45 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2011-10-15 20:21:44 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2011-10-15 20:21:44 ----A---- C:\Windows\system32\d3dx9_36.dll
2011-10-15 20:21:43 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2011-10-15 20:21:43 ----A---- C:\Windows\system32\xactengine2_9.dll
2011-10-15 20:21:42 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2011-10-15 20:21:42 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2011-10-15 20:21:42 ----A---- C:\Windows\system32\d3dx10_35.dll
2011-10-15 20:21:42 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2011-10-15 20:21:41 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2011-10-15 20:21:41 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2011-10-15 20:21:41 ----A---- C:\Windows\system32\xactengine2_8.dll
2011-10-15 20:21:41 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2011-10-15 20:21:41 ----A---- C:\Windows\system32\d3dx9_35.dll
2011-10-15 20:21:40 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2011-10-15 20:21:40 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2011-10-15 20:21:40 ----A---- C:\Windows\system32\d3dx10_34.dll
2011-10-15 20:21:40 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2011-10-15 20:21:39 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2011-10-15 20:21:39 ----A---- C:\Windows\system32\xinput1_3.dll
2011-10-15 20:21:39 ----A---- C:\Windows\system32\d3dx9_34.dll
2011-10-15 20:21:38 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2011-10-15 20:21:38 ----A---- C:\Windows\system32\xactengine2_7.dll
2011-10-15 20:21:37 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2011-10-15 20:21:37 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2011-10-15 20:21:37 ----A---- C:\Windows\system32\d3dx10_33.dll
2011-10-15 20:21:37 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2011-10-15 20:21:36 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2011-10-15 20:21:36 ----A---- C:\Windows\system32\d3dx9_33.dll
2011-10-15 20:21:35 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2011-10-15 20:21:35 ----A---- C:\Windows\system32\xactengine2_6.dll
2011-10-15 20:21:33 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2011-10-15 20:21:33 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2011-10-15 20:21:33 ----A---- C:\Windows\system32\xactengine2_5.dll
2011-10-15 20:21:33 ----A---- C:\Windows\system32\d3dx10.dll
2011-10-15 20:21:32 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2011-10-15 20:21:32 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2011-10-15 20:21:32 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2011-10-15 20:21:32 ----A---- C:\Windows\system32\xactengine2_4.dll
2011-10-15 20:21:32 ----A---- C:\Windows\system32\x3daudio1_1.dll
2011-10-15 20:21:32 ----A---- C:\Windows\system32\d3dx9_32.dll
2011-10-15 20:21:30 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2011-10-15 20:21:30 ----A---- C:\Windows\system32\d3dx9_31.dll
2011-10-15 20:21:29 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2011-10-15 20:21:29 ----A---- C:\Windows\system32\xactengine2_3.dll
2011-10-15 20:21:28 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2011-10-15 20:21:28 ----A---- C:\Windows\system32\xinput1_2.dll
2011-10-15 20:21:27 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2011-10-15 20:21:27 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2011-10-15 20:21:27 ----A---- C:\Windows\system32\xinput1_1.dll
2011-10-15 20:21:27 ----A---- C:\Windows\system32\xactengine2_2.dll
2011-10-15 20:21:25 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2011-10-15 20:21:25 ----A---- C:\Windows\system32\xactengine2_1.dll
2011-10-15 20:21:21 ----A---- C:\Windows\system32\d3dx9_30.dll
2011-10-15 20:21:20 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2011-10-15 20:21:20 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2011-10-15 20:21:20 ----A---- C:\Windows\system32\xactengine2_0.dll
2011-10-15 20:21:20 ----A---- C:\Windows\system32\x3daudio1_0.dll
2011-10-15 20:21:19 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2011-10-15 20:21:19 ----A---- C:\Windows\system32\d3dx9_29.dll
2011-10-15 20:21:18 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2011-10-15 20:21:18 ----A---- C:\Windows\system32\d3dx9_28.dll
2011-10-15 20:21:17 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2011-10-15 20:21:17 ----A---- C:\Windows\system32\d3dx9_27.dll
2011-10-15 20:21:16 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2011-10-15 20:21:16 ----A---- C:\Windows\system32\d3dx9_26.dll
2011-10-15 20:21:12 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2011-10-15 20:21:12 ----A---- C:\Windows\system32\d3dx9_25.dll
2011-10-15 20:21:10 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2011-10-15 20:21:10 ----A---- C:\Windows\system32\d3dx9_24.dll
2011-10-15 20:16:33 ----D---- C:\Windows\SYSWOW64\directx
2011-10-15 11:10:09 ----D---- C:\Users\Tomino\AppData\Roaming\md studio
2011-10-15 11:05:30 ----D---- C:\Program Files\Bato
2011-10-15 10:23:53 ----D---- C:\ProgramData\DVD Shrink
2011-10-15 10:23:52 ----D---- C:\Program Files\DVD Shrink
2011-10-15 05:44:22 ----D---- C:\Windows\SYSWOW64\Wat
2011-10-15 05:44:22 ----D---- C:\Windows\system32\Wat
2011-10-14 23:54:52 ----A---- C:\Windows\SYSWOW64\nvStreaming.exe
2011-10-14 11:46:07 ----D---- C:\Users\Tomino\AppData\Roaming\dvdcss
2011-10-14 08:12:39 ----D---- C:\Users\Tomino\AppData\Roaming\Vso
2011-10-14 08:12:13 ----A---- C:\Windows\SYSWOW64\wvc1dmod.dll
2011-10-14 08:12:13 ----A---- C:\Windows\SYSWOW64\vp7vfw.dll
2011-10-14 08:12:13 ----A---- C:\Windows\SYSWOW64\sipr3260.dll
2011-10-14 08:12:13 ----A---- C:\Windows\SYSWOW64\Pncrt.dll
2011-10-14 08:12:13 ----A---- C:\Windows\SYSWOW64\drv43260.dll
2011-10-14 08:12:13 ----A---- C:\Windows\SYSWOW64\drv33260.dll
2011-10-14 08:12:13 ----A---- C:\Windows\SYSWOW64\drv23260.dll
2011-10-14 08:12:13 ----A---- C:\Windows\SYSWOW64\cook3260.dll
2011-10-14 08:12:12 ----D---- C:\Program Files (x86)\VSO
2011-10-14 08:12:11 ----D---- C:\Program Files\VSO
2011-10-13 23:50:08 ----D---- C:\Program Files (x86)\Adobe
2011-10-13 23:49:14 ----D---- C:\ProgramData\Adobe
2011-10-13 23:04:30 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2011-10-13 23:04:30 ----A---- C:\Windows\system32\msv1_0.dll
2011-10-13 22:59:16 ----D---- C:\Program Files (x86)\MSXML 4.0
2011-10-13 22:57:31 ----A---- C:\Windows\system32\browserchoice.exe
2011-10-13 13:12:40 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2011-10-13 13:12:40 ----A---- C:\Windows\system32\kerberos.dll
2011-10-13 13:12:35 ----A---- C:\Windows\SYSWOW64\tzres.dll
2011-10-13 13:12:35 ----A---- C:\Windows\system32\tzres.dll
2011-10-13 13:12:01 ----A---- C:\Windows\SYSWOW64\odbcjt32.dll
2011-10-13 13:12:01 ----A---- C:\Windows\system32\odbctrac.dll
2011-10-13 13:12:01 ----A---- C:\Windows\system32\odbccu32.dll
2011-10-13 13:12:01 ----A---- C:\Windows\system32\odbccr32.dll
2011-10-13 13:12:01 ----A---- C:\Windows\system32\odbccp32.dll
2011-10-13 13:12:00 ----A---- C:\Windows\SYSWOW64\odbccp32.dll
2011-10-13 13:11:59 ----A---- C:\Windows\SYSWOW64\odbctrac.dll
2011-10-13 13:11:59 ----A---- C:\Windows\SYSWOW64\odbccu32.dll
2011-10-13 13:11:59 ----A---- C:\Windows\SYSWOW64\odbccr32.dll
2011-10-13 13:11:57 ----A---- C:\Windows\SYSWOW64\asycfilt.dll
2011-10-13 13:11:57 ----A---- C:\Windows\system32\drivers\dfsc.sys
2011-10-13 13:11:57 ----A---- C:\Windows\system32\asycfilt.dll
2011-10-13 13:11:52 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2011-10-13 13:11:52 ----A---- C:\Windows\system32\poqexec.exe
2011-10-13 13:11:50 ----A---- C:\Windows\system32\CPFilters.dll
2011-10-13 13:11:48 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2011-10-13 13:11:48 ----A---- C:\Windows\SYSWOW64\CPFilters.dll
2011-10-13 13:11:48 ----A---- C:\Windows\system32\sbe.dll
2011-10-13 13:11:48 ----A---- C:\Windows\system32\EncDec.dll
2011-10-13 13:11:47 ----A---- C:\Windows\SYSWOW64\sbe.dll
2011-10-13 13:11:44 ----A---- C:\Windows\SYSWOW64\t2embed.dll
2011-10-13 13:11:44 ----A---- C:\Windows\system32\t2embed.dll
2011-10-13 13:11:42 ----A---- C:\Windows\system32\ole32.dll
2011-10-13 13:11:41 ----A---- C:\Windows\SYSWOW64\ole32.dll
2011-10-13 13:11:39 ----A---- C:\Windows\SYSWOW64\taskschd.dll
2011-10-13 13:11:39 ----A---- C:\Windows\system32\wmicmiplugin.dll
2011-10-13 13:11:39 ----A---- C:\Windows\system32\taskschd.dll
2011-10-13 13:11:39 ----A---- C:\Windows\system32\taskeng.exe
2011-10-13 13:11:39 ----A---- C:\Windows\system32\taskcomp.dll
2011-10-13 13:11:39 ----A---- C:\Windows\system32\schedsvc.dll
2011-10-13 13:11:38 ----A---- C:\Windows\system32\schtasks.exe
2011-10-13 13:11:37 ----A---- C:\Windows\SYSWOW64\taskeng.exe
2011-10-13 13:11:37 ----A---- C:\Windows\SYSWOW64\taskcomp.dll
2011-10-13 13:11:37 ----A---- C:\Windows\SYSWOW64\StructuredQuery.dll
2011-10-13 13:11:37 ----A---- C:\Windows\SYSWOW64\schtasks.exe
2011-10-13 13:11:37 ----A---- C:\Windows\system32\StructuredQuery.dll
2011-10-13 13:11:35 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2011-10-13 13:11:35 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-10-13 13:11:35 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2011-10-13 13:11:33 ----A---- C:\Windows\system32\drivers\afd.sys
2011-10-13 13:11:27 ----A---- C:\Windows\system32\CertEnroll.dll
2011-10-13 13:11:26 ----A---- C:\Windows\SYSWOW64\CertEnroll.dll
2011-10-13 13:11:14 ----A---- C:\Windows\system32\shell32.dll
2011-10-13 13:11:11 ----A---- C:\Windows\SYSWOW64\shell32.dll
2011-10-13 13:11:03 ----A---- C:\Windows\system32\win32k.sys
2011-10-13 13:10:57 ----A---- C:\Windows\SYSWOW64\schannel.dll
2011-10-13 13:10:57 ----A---- C:\Windows\system32\schannel.dll
2011-10-13 13:10:57 ----A---- C:\Windows\system32\comctl32.dll
2011-10-13 13:10:55 ----A---- C:\Windows\SYSWOW64\comctl32.dll
2011-10-13 13:10:55 ----A---- C:\Windows\system32\jscript.dll
2011-10-13 13:10:54 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2011-10-13 13:10:54 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-10-13 13:10:54 ----A---- C:\Windows\system32\vbscript.dll
2011-10-13 13:10:52 ----A---- C:\Windows\SYSWOW64\explorer.exe
2011-10-13 13:10:52 ----A---- C:\Windows\system32\winlogon.exe
2011-10-13 13:10:52 ----A---- C:\Windows\explorer.exe
2011-10-13 13:10:51 ----A---- C:\Windows\system32\mfc42u.dll
2011-10-13 13:10:51 ----A---- C:\Windows\system32\mfc42.dll
2011-10-13 13:10:50 ----A---- C:\Windows\SYSWOW64\mfc42u.dll
2011-10-13 13:10:50 ----A---- C:\Windows\SYSWOW64\mfc42.dll
2011-10-13 13:10:44 ----A---- C:\Windows\system32\ieframe.dll
2011-10-13 13:10:41 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-10-13 13:10:39 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-10-13 13:10:39 ----A---- C:\Windows\system32\mshtml.dll
2011-10-13 13:10:39 ----A---- C:\Windows\system32\iertutil.dll
2011-10-13 13:10:37 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-10-13 13:10:36 ----A---- C:\Windows\system32\urlmon.dll
2011-10-13 13:10:35 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-10-13 13:10:35 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-10-13 13:10:35 ----A---- C:\Windows\system32\wininet.dll
2011-10-13 13:10:33 ----A---- C:\Windows\SYSWOW64\mstime.dll
2011-10-13 13:10:33 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2011-10-13 13:10:33 ----A---- C:\Windows\system32\mstime.dll
2011-10-13 13:10:33 ----A---- C:\Windows\system32\msfeeds.dll
2011-10-13 13:10:32 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2011-10-13 13:10:32 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2011-10-13 13:10:32 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2011-10-13 13:10:32 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-10-13 13:10:32 ----A---- C:\Windows\system32\licmgr10.dll
2011-10-13 13:10:32 ----A---- C:\Windows\system32\iepeers.dll
2011-10-13 13:10:32 ----A---- C:\Windows\system32\iedkcs32.dll
2011-10-13 13:10:31 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2011-10-13 13:10:31 ----A---- C:\Windows\system32\url.dll
2011-10-13 13:10:31 ----A---- C:\Windows\system32\mshtmled.dll
2011-10-13 13:10:30 ----A---- C:\Windows\SYSWOW64\url.dll
2011-10-13 13:10:30 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-10-13 13:10:30 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2011-10-13 13:10:30 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2011-10-13 13:10:30 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-10-13 13:10:30 ----A---- C:\Windows\system32\msfeedssync.exe
2011-10-13 13:10:30 ----A---- C:\Windows\system32\jsproxy.dll
2011-10-13 13:10:30 ----A---- C:\Windows\system32\ieui.dll
2011-10-13 13:09:49 ----A---- C:\Windows\SYSWOW64\rtutils.dll
2011-10-13 13:09:49 ----A---- C:\Windows\system32\rtutils.dll
2011-10-13 13:09:39 ----A---- C:\Windows\system32\spoolsv.exe
2011-10-13 13:09:38 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2011-10-13 13:09:38 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2011-10-13 13:09:38 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2011-10-13 13:09:38 ----A---- C:\Windows\system32\fontsub.dll
2011-10-13 13:09:38 ----A---- C:\Windows\system32\atmlib.dll
2011-10-13 13:09:38 ----A---- C:\Windows\system32\atmfd.dll
2011-10-13 13:09:36 ----A---- C:\Windows\SYSWOW64\webio.dll
2011-10-13 13:09:36 ----A---- C:\Windows\system32\webio.dll
2011-10-13 13:09:35 ----A---- C:\Windows\SYSWOW64\iccvid.dll
2011-10-13 13:09:09 ----A---- C:\Windows\SYSWOW64\dnscacheugc.exe
2011-10-13 13:09:09 ----A---- C:\Windows\SYSWOW64\dnsapi.dll
2011-10-13 13:09:09 ----A---- C:\Windows\system32\dnsrslvr.dll
2011-10-13 13:09:09 ----A---- C:\Windows\system32\dnscacheugc.exe
2011-10-13 13:09:09 ----A---- C:\Windows\system32\dnsapi.dll
2011-10-13 13:09:07 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-10-13 13:09:07 ----A---- C:\Windows\system32\cdd.dll
2011-10-13 13:08:48 ----A---- C:\Windows\SYSWOW64\wmpmde.dll
2011-10-13 13:08:48 ----A---- C:\Windows\system32\wmpmde.dll
2011-10-13 13:08:47 ----A---- C:\Windows\SYSWOW64\quartz.dll
2011-10-13 13:08:47 ----A---- C:\Windows\SYSWOW64\msvidc32.dll
2011-10-13 13:08:47 ----A---- C:\Windows\SYSWOW64\mciavi32.dll
2011-10-13 13:08:47 ----A---- C:\Windows\SYSWOW64\avifil32.dll
2011-10-13 13:08:47 ----A---- C:\Windows\system32\tsbyuv.dll
2011-10-13 13:08:47 ----A---- C:\Windows\system32\quartz.dll
2011-10-13 13:08:47 ----A---- C:\Windows\system32\msyuv.dll
2011-10-13 13:08:47 ----A---- C:\Windows\system32\msvidc32.dll
2011-10-13 13:08:47 ----A---- C:\Windows\system32\msrle32.dll
2011-10-13 13:08:47 ----A---- C:\Windows\system32\iyuv_32.dll
2011-10-13 13:08:46 ----A---- C:\Windows\SYSWOW64\tsbyuv.dll
2011-10-13 13:08:46 ----A---- C:\Windows\SYSWOW64\msyuv.dll
2011-10-13 13:08:46 ----A---- C:\Windows\SYSWOW64\msrle32.dll
2011-10-13 13:08:46 ----A---- C:\Windows\SYSWOW64\iyuv_32.dll
2011-10-13 13:08:45 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-10-13 13:08:45 ----A---- C:\Windows\system32\drivers\srv.sys
2011-10-13 13:08:44 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-10-13 13:08:43 ----A---- C:\Windows\SYSWOW64\psisdecd.dll
2011-10-13 13:08:43 ----A---- C:\Windows\system32\psisdecd.dll
2011-10-13 13:08:39 ----A---- C:\Windows\system32\ntdll.dll
2011-10-13 13:08:38 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2011-10-13 13:08:25 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2011-10-13 13:08:25 ----A---- C:\Windows\system32\msxml3.dll
2011-10-13 13:08:22 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2011-10-13 13:08:22 ----A---- C:\Windows\SYSWOW64\secur32.dll
2011-10-13 13:08:22 ----A---- C:\Windows\system32\lsasrv.dll
2011-10-13 13:08:22 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2011-10-13 13:07:43 ----A---- C:\Windows\system32\winresume.exe
2011-10-13 13:07:43 ----A---- C:\Windows\system32\winload.exe
2011-10-13 13:07:42 ----A---- C:\Windows\system32\kdusb.dll
2011-10-13 13:07:42 ----A---- C:\Windows\system32\kdcom.dll
2011-10-13 13:07:42 ----A---- C:\Windows\system32\kd1394.dll
2011-10-13 13:07:38 ----A---- C:\Windows\SYSWOW64\mfc40u.dll
2011-10-13 13:07:38 ----A---- C:\Windows\SYSWOW64\mfc40.dll
2011-10-13 13:07:32 ----A---- C:\Windows\SYSWOW64\msasn1.dll
2011-10-13 13:07:32 ----A---- C:\Windows\system32\msasn1.dll
2011-10-13 13:07:31 ----A---- C:\Windows\system32\KernelBase.dll
2011-10-13 13:07:30 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2011-10-13 13:07:30 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2011-10-13 13:07:30 ----A---- C:\Windows\system32\wow64win.dll
2011-10-13 13:07:30 ----A---- C:\Windows\system32\wow64.dll
2011-10-13 13:07:30 ----A---- C:\Windows\system32\winsrv.dll
2011-10-13 13:07:30 ----A---- C:\Windows\system32\kernel32.dll
2011-10-13 13:07:30 ----A---- C:\Windows\system32\conhost.exe
2011-10-13 13:07:29 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-10-13 13:07:29 ----A---- C:\Windows\SYSWOW64\setup16.exe
2011-10-13 13:07:29 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2011-10-13 13:07:29 ----A---- C:\Windows\system32\ntvdm64.dll
2011-10-13 13:07:28 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2011-10-13 13:07:28 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2011-10-13 13:07:28 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2011-10-13 13:07:28 ----A---- C:\Windows\SYSWOW64\wow32.dll
2011-10-13 13:07:28 ----A---- C:\Windows\SYSWOW64\instnm.exe
2011-10-13 13:07:28 ----A---- C:\Windows\system32\wow64cpu.dll
2011-10-13 13:07:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2011-10-13 13:07:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2011-10-13 13:07:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2011-10-13 13:07:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-10-13 13:07:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2011-10-13 13:07:27 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-10-13 13:07:27 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-10-13 13:07:27 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-10-13 13:07:27 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-10-13 13:07:27 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2011-10-13 13:07:27 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2011-10-13 13:07:27 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-10-13 13:07:27 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2011-10-13 13:07:27 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2011-10-13 13:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2011-10-13 13:07:25 ----A---- C:\Windows\SYSWOW64\user.exe
2011-10-13 13:07:06 ----A---- C:\Windows\system32\umpnpmgr.dll
2011-10-13 13:07:05 ----A---- C:\Windows\SYSWOW64\drvinst.exe
2011-10-13 13:07:05 ----A---- C:\Windows\SYSWOW64\devrtl.dll
2011-10-13 13:07:05 ----A---- C:\Windows\SYSWOW64\devobj.dll
2011-10-13 13:07:05 ----A---- C:\Windows\SYSWOW64\cfgmgr32.dll
2011-10-13 13:07:02 ----A---- C:\Windows\system32\mstscax.dll
2011-10-13 13:07:01 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2011-10-13 13:07:01 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2011-10-13 13:07:01 ----A---- C:\Windows\system32\mstsc.exe
2011-10-13 13:06:54 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-10-13 13:06:44 ----A---- C:\Windows\system32\wmp.dll
2011-10-13 13:06:42 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2011-10-13 13:06:42 ----A---- C:\Windows\SYSWOW64\wmp.dll
2011-10-13 13:06:41 ----A---- C:\Windows\system32\wmploc.DLL
2011-10-13 13:06:27 ----A---- C:\Windows\system32\FXSCOVER.exe
2011-10-13 13:06:26 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2011-10-13 13:06:26 ----A---- C:\Windows\system32\inetcomm.dll
2011-10-13 13:06:24 ----A---- C:\Windows\system32\consent.exe
2011-10-13 13:06:22 ----A---- C:\Windows\system32\drivers\bowser.sys
2011-10-13 13:06:21 ----A---- C:\Windows\system32\oleaut32.dll
2011-10-13 13:06:21 ----A---- C:\Windows\system32\oleacc.dll
2011-10-13 13:06:20 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2011-10-13 13:06:20 ----A---- C:\Windows\SYSWOW64\oleacc.dll
2011-10-13 13:06:18 ----A---- C:\Windows\system32\odbc32.dll
2011-10-13 13:06:17 ----A---- C:\Windows\SYSWOW64\odbc32.dll
2011-10-13 13:06:04 ----A---- C:\Windows\SYSWOW64\sscore.dll
2011-10-13 13:06:04 ----A---- C:\Windows\system32\srvsvc.dll
2011-10-13 13:06:02 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-10-13 13:06:00 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2011-10-13 13:06:00 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2011-10-13 11:30:37 ----D---- C:\Program Files\Audiograbber
2011-10-13 07:14:23 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2011-10-13 07:09:56 ----A---- C:\Windows\SYSWOW64\PresentationHostProxy.dll
2011-10-13 07:09:56 ----A---- C:\Windows\SYSWOW64\PresentationHost.exe
2011-10-13 07:09:56 ----A---- C:\Windows\SYSWOW64\netfxperf.dll
2011-10-13 07:09:56 ----A---- C:\Windows\SYSWOW64\mscoree.dll
2011-10-13 07:09:56 ----A---- C:\Windows\SYSWOW64\dfshim.dll
2011-10-13 07:09:56 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2011-10-13 07:09:56 ----A---- C:\Windows\system32\PresentationHost.exe
2011-10-13 07:09:56 ----A---- C:\Windows\system32\netfxperf.dll
2011-10-13 07:09:56 ----A---- C:\Windows\system32\mscoree.dll
2011-10-13 07:09:56 ----A---- C:\Windows\system32\dfshim.dll
2011-10-13 07:06:14 ----D---- C:\Program Files\Ant Movie Catalog
2011-10-13 00:32:47 ----D---- C:\Users\Tomino\AppData\Roaming\vlc
2011-10-13 00:03:36 ----D---- C:\Program Files\Thoosje
2011-10-12 23:49:17 ----D---- C:\Program Files\Cesta za dobrodružstvím - Kouzelné obrazy
2011-10-12 23:48:16 ----D---- C:\Program Files\Filipova dobrodružství - Na stopě rodinným pokladům
2011-10-12 23:47:41 ----D---- C:\Program Files\Feng Šuej Mahjong
2011-10-12 23:46:57 ----D---- C:\Program Files\Egyptský míč
2011-10-12 23:46:23 ----D---- C:\Program Files\Dobrý farmář
2011-10-12 23:44:26 ----D---- C:\Program Files\Alex Kočičák
2011-10-12 23:43:53 ----D---- C:\Program Files\Alenka 2 - Kouzelná země
2011-10-12 23:42:32 ----D---- C:\Program Files\Ledova kralovna 3 - Vrani carodejka
2011-10-12 23:41:18 ----D---- C:\Program Files\Zachraň Kamarády!
2011-10-12 23:40:45 ----D---- C:\Program Files\Výprava do Květinové země
2011-10-12 23:40:14 ----D---- C:\Program Files\Polární dobrodružství 2
2011-10-12 23:39:41 ----D---- C:\Program Files\Nádherná zahrada
2011-10-12 23:39:06 ----D---- C:\Program Files\Mořské dobrodružství
2011-10-12 23:38:14 ----D---- C:\Program Files\Medvěd Míša - Zakletý hrad
2011-10-12 23:37:39 ----D---- C:\Program Files\Medvěd Míša - Cesta kolem světa
2011-10-12 23:36:33 ----D---- C:\Program Files\Medvěd Míša ve vesmíru
2011-10-12 23:27:57 ----D---- C:\Users\Tomino\AppData\Roaming\Nero
2011-10-12 23:22:03 ----D---- C:\Program Files\Mozilla Firefox
2011-10-12 23:05:55 ----D---- C:\ProgramData\Nero
2011-10-12 23:05:22 ----D---- C:\Program Files (x86)\Nero
2011-10-12 22:57:39 ----D---- C:\Program Files (x86)\Microsoft.NET
2011-10-12 22:57:19 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2011-10-12 22:57:01 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2011-10-12 22:56:43 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2011-10-12 22:56:25 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2011-10-12 22:56:07 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2011-10-12 22:55:49 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2011-10-12 22:45:59 ----A---- C:\Windows\system32\SmartDefragBootTime.exe
2011-10-12 22:45:59 ----A---- C:\Windows\system32\drivers\SmartDefragDriver.sys
2011-10-12 22:45:47 ----D---- C:\ProgramData\IObit
2011-10-12 22:45:16 ----D---- C:\Program Files (x86)\IObit Toolbar
2011-10-12 22:45:16 ----D---- C:\Program Files (x86)\Application Updater
2011-10-12 22:43:55 ----D---- C:\Users\Tomino\AppData\Roaming\IObit
2011-10-12 22:42:56 ----A---- C:\Windows\system32\DfSdkBt.exe
2011-10-12 22:42:53 ----D---- C:\Program Files\Ashampoo
2011-10-12 22:40:44 ----D---- C:\Program Files\Media Player Classic - Home Cinema
2011-10-12 22:39:39 ----D---- C:\Program Files\VideoLAN
2011-10-12 22:38:31 ----D---- C:\Program Files\TNod User & Password Finder
2011-10-12 22:37:42 ----A---- C:\Windows\system32\drivers\netio.sys
2011-10-12 22:12:33 ----D---- C:\Users\Tomino\AppData\Roaming\URSoft
2011-10-12 22:12:33 ----AD---- C:\ProgramData\TEMP
2011-10-12 22:12:31 ----D---- C:\Program Files\Your Uninstaller! 7
2011-10-12 22:03:28 ----D---- C:\Users\Tomino\AppData\Roaming\Stardock
2011-10-12 22:02:53 ----HDC---- C:\ProgramData\{0F4A7EFE-5950-4389-BF36-1E625D72456B}
2011-10-12 22:02:53 ----D---- C:\ProgramData\Stardock
2011-10-12 22:02:52 ----D---- C:\Program Files\Stardock
2011-10-12 21:57:28 ----D---- C:\Program Files (x86)\Conduit
2011-10-12 21:57:22 ----D---- C:\Program Files\uTorrent
2011-10-12 21:56:30 ----D---- C:\Users\Tomino\AppData\Roaming\uTorrent
2011-10-12 21:55:59 ----A---- C:\Program Files\zipnew.dat
2011-10-12 21:55:59 ----A---- C:\Program Files\rarnew.dat
2011-10-12 21:55:57 ----D---- C:\Program Files\Formats
2011-10-12 21:55:57 ----A---- C:\Program Files\WinRAR.exe
2011-10-12 21:55:57 ----A---- C:\Program Files\WhatsNew.txt
2011-10-12 21:55:57 ----A---- C:\Program Files\UnrarSrc.txt
2011-10-12 21:55:57 ----A---- C:\Program Files\UnRAR.exe
2011-10-12 21:55:57 ----A---- C:\Program Files\TechNote.txt
2011-10-12 21:55:57 ----A---- C:\Program Files\ReadMe.txt
2011-10-12 21:55:57 ----A---- C:\Program Files\RarExt64.dll
2011-10-12 21:55:57 ----A---- C:\Program Files\RarExt.dll
2011-10-12 21:55:57 ----A---- C:\Program Files\Rar.txt
2011-10-12 21:55:57 ----A---- C:\Program Files\Rar.exe
2011-10-12 21:55:57 ----A---- C:\Program Files\License.txt
2011-10-12 21:55:35 ----D---- C:\Users\Tomino\AppData\Roaming\WinRAR
2011-10-12 21:55:31 ----D---- C:\Program Files (x86)\WinRAR
2011-10-12 21:55:25 ----D---- C:\Program Files\7-Zip
2011-10-12 21:37:07 ----D---- C:\Windows\Panther
2011-10-12 21:36:39 ----D---- C:\Windows\system32\OEM
2011-10-12 21:36:26 ----RD---- C:\Hry E
2011-10-12 21:29:15 ----D---- C:\Windows.old
2011-10-12 20:02:24 ----D---- C:\Users\Tomino\AppData\Roaming\Skype
2011-10-12 20:02:21 ----RD---- C:\Program Files (x86)\Skype
2011-10-12 20:02:19 ----D---- C:\ProgramData\Skype
2011-10-12 15:19:21 ----D---- C:\ProgramData\Aliasworlds
2011-10-12 15:10:37 ----D---- C:\Program Files (x86)\Mořské dobrodružství
2011-10-12 15:07:09 ----D---- C:\Users\Tomino\AppData\Roaming\SecretIslandEng
2011-10-12 15:03:28 ----D---- C:\Program Files (x86)\Katčin Rybí krámek
2011-10-12 15:00:34 ----D---- C:\ProgramData\Friday's games
2011-10-12 15:00:25 ----D---- C:\Program Files (x86)\Nádherná zahrada
2011-10-12 14:56:24 ----D---- C:\Users\Tomino\AppData\Roaming\Alawar
2011-10-12 14:56:14 ----D---- C:\Program Files (x86)\Zachraň Kamarády!
2011-10-12 14:55:33 ----D---- C:\Program Files (x86)\Výprava do Květinové země
2011-10-12 14:55:01 ----D---- C:\ProgramData\Alawar Stargaze
2011-10-12 14:54:54 ----D---- C:\Program Files (x86)\Polární dobrodružství 2
2011-10-12 14:47:29 ----D---- C:\Program Files (x86)\Bambulky
2011-10-12 14:45:41 ----D---- C:\Users\Tomino\AppData\Roaming\EleFun Games
2011-10-12 14:38:57 ----D---- C:\Users\Tomino\AppData\Roaming\Špidla Data Processing, s.r.o
2011-10-12 14:38:57 ----D---- C:\ProgramData\Špidla Data Processing, s.r.o
2011-10-12 14:38:49 ----D---- C:\Program Files (x86)\Filipova dobrodružství - Na stopě rodinným pokladům
2011-10-12 14:35:04 ----D---- C:\ProgramData\VirtualFarm
2011-10-12 14:29:59 ----D---- C:\Users\Tomino\AppData\Roaming\V-Games
2011-10-12 14:19:25 ----D---- C:\ProgramData\Alex Gordon
2011-10-12 14:19:17 ----D---- C:\ProgramData\AlawarWrapper
2011-10-12 14:16:43 ----D---- C:\Users\Tomino\AppData\Roaming\URSE Games
2011-10-12 14:16:22 ----D---- C:\Program Files (x86)\Ledova kralovna 3 - Vrani carodejka
2011-10-12 13:54:35 ----D---- C:\Users\Tomino\AppData\Roaming\Artogon
2011-10-12 13:54:29 ----D---- C:\Program Files (x86)\Cesta za dobrodruzstvim - Nadesel cas
2011-10-12 13:18:13 ----D---- C:\Users\Tomino\AppData\Roaming\Mozilla
2011-10-12 13:06:42 ----D---- C:\Users\Tomino\AppData\Roaming\Macromedia
2011-10-12 13:06:42 ----D---- C:\Users\Tomino\AppData\Roaming\Adobe
2011-10-12 13:06:41 ----D---- C:\Windows\SYSWOW64\Macromed
2011-10-12 12:31:56 ----D---- C:\Users\Tomino\AppData\Roaming\Intel Corporation
2011-10-12 12:23:18 ----A---- C:\Windows\GVTDrv64.sys
2011-10-12 12:23:03 ----A---- C:\Windows\gdrv.sys
2011-10-12 12:22:42 ----D---- C:\ProgramData\NVIDIA
2011-10-12 12:22:40 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2011-10-12 12:21:44 ----A---- C:\Windows\system32\nvvsvc.exe
2011-10-12 12:21:44 ----A---- C:\Windows\system32\nvsvcr.dll
2011-10-12 12:21:44 ----A---- C:\Windows\system32\nvsvc64.dll
2011-10-12 12:21:44 ----A---- C:\Windows\system32\nvshext.dll
2011-10-12 12:21:44 ----A---- C:\Windows\system32\nvmctray.dll
2011-10-12 12:21:44 ----A---- C:\Windows\system32\nvcpl.dll
2011-10-12 12:21:44 ----A---- C:\Windows\system32\easyupdatusapiu64.dll
2011-10-12 12:21:36 ----D---- C:\ProgramData\NVIDIA Corporation
2011-10-12 12:21:04 ----A---- C:\Windows\system32\nvhdagenco642040.dll
2011-10-12 12:21:03 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2011-10-12 12:21:03 ----A---- C:\Windows\system32\nvwgf2umx.dll
2011-10-12 12:21:03 ----A---- C:\Windows\system32\nvgenco64.dll
2011-10-12 12:21:03 ----A---- C:\Windows\system32\nvdispco64.dll
2011-10-12 12:21:03 ----A---- C:\Windows\system32\nvapi64.dll
2011-10-12 12:17:33 ----D---- C:\Program Files\NVIDIA Corporation
2011-10-12 12:11:29 ----N---- C:\Windows\system32\MpSigStub.exe
2011-10-12 12:09:47 ----D---- C:\Program Files\SuperOvladac
2011-10-12 12:06:13 ----D---- C:\Users\Tomino\AppData\Roaming\Opera
2011-10-12 12:06:11 ----D---- C:\Program Files (x86)\Opera
2011-10-12 12:03:32 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2011-10-12 12:03:32 ----A---- C:\Windows\system32\wintrust.dll
2011-10-12 12:03:31 ----A---- C:\Windows\SYSWOW64\cabview.dll
2011-10-12 12:03:31 ----A---- C:\Windows\system32\cabview.dll
2011-10-12 12:02:03 ----D---- C:\Program Files\GIGABYTE
2011-10-12 12:02:03 ----D---- C:\Program Files (x86)\GIGABYTE
2011-10-12 12:02:03 ----A---- C:\Windows\system32\drivers\AppleCharger.sys
2011-10-12 12:02:03 ----A---- C:\Windows\system32\AppleChargerSrv.exe
2011-10-12 12:01:30 ----A---- C:\Windows\system32\drivers\iaStor.sys
2011-10-12 12:01:28 ----D---- C:\Users\Tomino\AppData\Roaming\InstallShield
2011-10-12 12:01:27 ----D---- C:\ProgramData\InstallShield
2011-10-12 12:00:57 ----A---- C:\Windows\system32\RTNUninst64.dll
2011-10-12 12:00:57 ----A---- C:\Windows\system32\RtNicProp64.dll
2011-10-12 12:00:57 ----A---- C:\Windows\system32\drivers\Rt64win7.sys
2011-10-12 12:00:21 ----D---- C:\Program Files\Realtek
2011-10-12 11:59:52 ----D---- C:\Program Files (x86)\Realtek
2011-10-12 11:59:51 ----HD---- C:\Program Files (x86)\Temp
2011-10-12 11:59:51 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-10-12 11:59:49 ----A---- C:\Windows\RtlExUpd.dll
2011-10-12 11:59:39 ----A---- C:\Windows\SYSWOW64\log.txt
2011-10-12 11:58:57 ----D---- C:\Program Files (x86)\Intel
2011-10-12 11:58:57 ----A---- C:\Windows\SYSWOW64\CSVer.dll
2011-10-12 11:58:42 ----HD---- C:\Program Files (x86)\DeviceVM
2011-10-12 11:58:36 ----SHD---- C:\Windows\Installer
2011-10-12 11:58:10 ----A---- C:\Windows\GSetup.ini
2011-10-12 11:54:20 ----D---- C:\Users\Tomino\AppData\Roaming\Identities
2011-10-12 11:54:03 ----SD---- C:\Users\Tomino\AppData\Roaming\Microsoft
2011-10-12 11:54:03 ----D---- C:\Users\Tomino\AppData\Roaming\Media Center Programs
2011-10-12 11:41:03 ----D---- C:\Windows\SoftwareDistribution
2011-10-12 11:38:20 ----D---- C:\Windows\Prefetch

======List of files/folders modified in the last 1 month======

2011-10-31 16:12:49 ----D---- C:\Windows
2011-10-31 16:06:54 ----D---- C:\Config.Msi
2011-10-31 16:06:40 ----RD---- C:\Program Files
2011-10-31 16:06:40 ----D---- C:\ProgramData
2011-10-31 16:06:38 ----SHD---- C:\System Volume Information
2011-10-31 16:01:39 ----D---- C:\Windows\inf
2011-10-31 15:59:12 ----D---- C:\Windows\System32
2011-10-31 15:59:12 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-10-31 15:43:25 ----D---- C:\Windows\system32\DriverStore
2011-10-31 15:43:25 ----D---- C:\Windows\system32\drivers
2011-10-31 15:43:25 ----D---- C:\Windows\system32\catroot
2011-10-31 07:00:04 ----D---- C:\Windows\system32\config
2011-10-30 21:28:08 ----A---- C:\Windows\system.ini
2011-10-30 21:27:51 ----D---- C:\Windows\system32\drivers\etc
2011-10-30 21:23:12 ----D---- C:\Windows\SYSWOW64\drivers
2011-10-30 21:23:12 ----D---- C:\Windows\SysWOW64
2011-10-30 21:23:12 ----D---- C:\Windows\AppPatch
2011-10-30 21:23:11 ----D---- C:\Program Files\Common Files
2011-10-30 21:23:11 ----D---- C:\Program Files (x86)\Common Files
2011-10-30 11:49:13 ----RD---- C:\Program Files (x86)
2011-10-30 11:49:12 ----D---- C:\Windows\Tasks
2011-10-29 22:09:03 ----D---- C:\Windows\system32\wdi
2011-10-29 21:13:01 ----D---- C:\Windows\system32\Tasks
2011-10-29 21:12:37 ----D---- C:\Windows\system32\catroot2
2011-10-29 19:44:21 ----D---- C:\Windows\system32\NDF
2011-10-24 14:55:03 ----D---- C:\Windows\LiveKernelReports
2011-10-24 06:46:11 ----D---- C:\Windows\Logs
2011-10-19 20:47:58 ----RSD---- C:\Windows\assembly
2011-10-19 20:47:53 ----D---- C:\Windows\winsxs
2011-10-19 20:46:42 ----D---- C:\Program Files (x86)\MSBuild
2011-10-19 20:46:12 ----D---- C:\Windows\ShellNew
2011-10-19 20:45:54 ----RSD---- C:\Windows\Fonts
2011-10-19 20:45:44 ----SD---- C:\ProgramData\Microsoft
2011-10-19 20:45:05 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-10-19 20:43:50 ----A---- C:\Windows\win.ini
2011-10-19 19:59:53 ----D---- C:\Windows\system32\drivers\UMDF
2011-10-19 03:39:09 ----D---- C:\Windows\debug
2011-10-17 13:37:35 ----D---- C:\Windows\SYSWOW64\oobe
2011-10-17 04:41:26 ----D---- C:\Windows\rescache
2011-10-15 20:21:04 ----D---- C:\Windows\Microsoft.NET
2011-10-13 23:15:23 ----D---- C:\Windows\SYSWOW64\sk-SK
2011-10-13 23:15:23 ----D---- C:\Windows\SYSWOW64\en-US
2011-10-13 23:15:23 ----D---- C:\Windows\SYSWOW64\cs-CZ
2011-10-13 23:15:23 ----D---- C:\Windows\system32\sk-SK
2011-10-13 23:15:23 ----D---- C:\Windows\system32\en-US
2011-10-13 23:15:23 ----D---- C:\Windows\system32\cs-CZ
2011-10-13 23:15:17 ----D---- C:\Windows\ehome
2011-10-13 23:15:15 ----D---- C:\Program Files\Windows Mail
2011-10-13 23:15:15 ----D---- C:\Program Files (x86)\Windows Mail
2011-10-13 23:15:13 ----D---- C:\Program Files\Internet Explorer
2011-10-13 23:15:13 ----D---- C:\Program Files (x86)\Internet Explorer
2011-10-13 23:15:12 ----D---- C:\Windows\SYSWOW64\migration
2011-10-13 23:15:12 ----D---- C:\Windows\system32\migration
2011-10-13 23:15:04 ----D---- C:\Windows\system32\Boot
2011-10-13 23:15:01 ----D---- C:\Program Files\Windows Media Player
2011-10-13 23:15:01 ----D---- C:\Program Files (x86)\Windows Media Player
2011-10-13 00:03:52 ----D---- C:\Windows\system32\oobe
2011-10-12 23:55:03 ----A---- C:\Windows\system32\uxtheme.dll
2011-10-12 23:55:00 ----A---- C:\Windows\system32\themeui.dll
2011-10-12 23:54:58 ----A---- C:\Windows\system32\themeservice.dll
2011-10-12 12:22:42 ----RD---- C:\Users
2011-10-12 12:21:43 ----D---- C:\Windows\Help
2011-10-12 12:02:03 ----D---- C:\Windows\Downloaded Program Files
2011-10-12 12:00:04 ----D---- C:\Windows\system32\restore
2011-10-12 11:52:37 ----D---- C:\Windows\Setup
2011-10-12 11:52:09 ----D---- C:\Windows\system32\Recovery
2011-10-12 11:52:09 ----D---- C:\Recovery
2011-10-12 11:47:59 ----D---- C:\Windows\system32\CodeIntegrity
2011-10-12 11:41:00 ----D---- C:\Windows\system32\sysprep
2011-10-12 11:38:44 ----D---- C:\Windows\CSC

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2009-10-02 537112]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 SmartDefragDriver;SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [2010-11-26 17720]
R1 AppleCharger;AppleCharger; C:\Windows\system32\DRIVERS\AppleCharger.sys [2010-04-27 21544]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2011-06-15 93240]
R2 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2007-01-27 13520]
R3 AnyDVD;AnyDVD; C:\Windows\System32\Drivers\AnyDVD.sys [2007-01-27 53960]
R3 ElbyDelay;ElbyDelay; C:\Windows\System32\Drivers\ElbyDelay.sys [2006-12-14 14032]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2011-08-30 3069032]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2011-07-08 174184]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2010-03-04 346144]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2011-10-12 25640]
S3 GVTDrv64;GVTDrv64; \??\C:\Windows\GVTDrv64.sys [2011-10-12 30528]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
S3 s1039bus;Sony Ericsson Device 1039 driver (WDM); C:\Windows\system32\DRIVERS\s1039bus.sys [2010-03-01 127600]
S3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s1039mdfl.sys [2010-03-01 19568]
S3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s1039mdm.sys [2010-03-01 161904]
S3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s1039mgmt.sys [2010-03-01 141424]
S3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s1039obex.sys [2010-03-01 137328]
S3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM); C:\Windows\system32\DRIVERS\s1039unic.sys [2010-03-01 158320]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R2 AHDDC2;Ashampoo HDD Control 2 Service; C:\Program Files\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Service.exe [2011-09-22 1515936]
R2 BCUService;Browser Configuration Utility Service; C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2009-10-15 223464]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-10-02 13336]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2009-09-30 268824]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2011-10-15 1640768]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-15 2253120]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-14 381248]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-09-30 2320920]
S2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-01-05 40384]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 AppleChargerSrv;AppleChargerSrv; C:\Windows\system32\AppleChargerSrv.exe [2010-04-06 31272]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 DfSdkS;Defragmentation-Service; C:\Program Files\Ashampoo\Ashampoo HDD Control 2\DfSdkS64.exe [2009-08-24 544768]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-26 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion; C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-06-29 155344]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-10-15 1255736]
S4 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]

-----------------EOF-----------------