Stránka 1 z 1

Roguekiller

Napsal: 25 pro 2011 11:32
od Peelie
Chcel som sa presvedcit,ci mi v PC pri zapinani nestartuju nejake skodlive procesy,tak som dal scan Roguekillera,lebo som o nom cital aku ma funkciu.Vysiel mi tento log,tak poprosim o kontrolu.


RogueKiller V6.2.0 [12/12/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: Administrator [Admin rights]
Mode: Remove -- Date : 12/25/2011 11:29:42

¤¤¤ Bad processes: 0 ¤¤¤

¤¤¤ Registry Entries: 4 ¤¤¤
[HJ] HKLM\[...]\Security Center : AntiVirusDisableNotify (1) -> REPLACED (0)
[HJ] HKLM\[...]\Security Center : FirewallDisableNotify (1) -> REPLACED (0)
[HJ] HKLM\[...]\Security Center : UpdatesDisableNotify (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver: [LOADED] ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 localhost


¤¤¤ MBR Check: ¤¤¤
--- User ---
[MBR] c19fbaad75c3804c08f89899cac19cd8
[BSP] b7c3167f484395319bc8616e6b9cc7ba : MBR Code unknown
Partition table:
0 - [ACTIVE] NTFS [VISIBLE] Offset (sectors): 63 | Size: 31453 Mo
1 - [XXXXXX] UNKNW [VISIBLE] Offset (sectors): 61432560 | Size: 288616 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

Finished : << RKreport[1].txt >>
RKreport[1].txt

Re: Roguekiller

Napsal: 25 pro 2011 11:37
od Rudy
Lépe bude, když dáte nejprve log RSIT: http://www.viry.cz/forum/viewtopic.php?f=13&t=105895 . Dál uvidíme.

Re: Roguekiller

Napsal: 25 pro 2011 13:50
od Peelie
Run by Administrator at 2011-12-25 13:50:15
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 21 GB (70%) free of 30 GB
Total RAM: 1534 MB (73% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:50:17, on 25.12.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Administrator\Local Settings\Application Data\Opera\Opera\temporary_downloads\RSIT (1).exe
C:\Program Files\trend micro\Administrator.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe /installquiet
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-1614895754-1454471165-1177238915-1005\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'UpdatusUser')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Realtime Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe

--
End of file - 5911 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-11-14 3843232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-11-27 35840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-11-27 73728]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2011-10-19 258512]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2011-10-08 16744256]
"NvMediaCenter"=NvMCTray.dll,NvTaskbarInit -login []
"nwiz"=C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2011-10-08 1632360]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2005-11-11 90112]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-09-07 37296]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-03-30 937920]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2011-10-13 17351304]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
C:\PROGRA~1\WINDOW~2\WINDOW~1.EXE [2009-01-03 128000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-11 239496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-19 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2008-05-27 304128]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe"="C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe:*:Enabled:Daemonu.exe"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"E:\Program Files\GameSpy Arcade\Aphex.exe"="E:\Program Files\GameSpy Arcade\Aphex.exe:*:Enabled:GameSpy Arcade"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"VIDC.XVID"=xvidvfw.dll
"VIDC.YV12"=yv12vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.lameacm"=lameACM.acm
"VIDC.FFDS"=ff_vfw.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv

======List of files/folders created in the last 1 month======

2011-12-25 13:48:29 ----D---- C:\Program Files\trend micro
2011-12-25 13:48:28 ----D---- C:\rsit
2011-12-16 15:24:36 ----D---- C:\Program Files\Common Files\Adobe
2011-12-16 15:24:36 ----D---- C:\Program Files\Adobe
2011-12-16 15:24:24 ----SHD---- C:\Config.Msi
2011-12-04 00:10:58 ----D---- C:\Documents and Settings\Administrator\Application Data\Media Player Classic
2011-11-30 22:51:26 ----D---- C:\WINDOWS\Minidump
2011-11-29 15:22:37 ----D---- C:\Documents and Settings\Administrator\Application Data\WinRAR
2011-11-28 18:24:08 ----D---- C:\Program Files\Common Files\DirectX
2011-11-28 18:23:54 ----A---- C:\WINDOWS\system32\CmdLineExt.dll
2011-11-27 23:51:25 ----SHD---- C:\RECYCLER
2011-11-27 21:38:17 ----D---- C:\Documents and Settings\Administrator\Application Data\Skype
2011-11-27 21:38:09 ----RD---- C:\Program Files\Skype
2011-11-27 21:38:03 ----D---- C:\Documents and Settings\All Users\Application Data\Skype
2011-11-27 18:01:07 ----D---- C:\Documents and Settings\Administrator\Application Data\Macromedia
2011-11-27 18:01:07 ----D---- C:\Documents and Settings\Administrator\Application Data\Adobe
2011-11-27 18:00:50 ----D---- C:\Documents and Settings\All Users\Application Data\McAfee
2011-11-27 17:35:58 ----D---- C:\Documents and Settings\Administrator\Application Data\Opera
2011-11-27 12:12:18 ----D---- C:\Documents and Settings\Administrator\Application Data\Windows Search
2011-11-27 12:08:59 ----D---- C:\WINDOWS\pss
2011-11-27 12:04:51 ----A---- C:\WINDOWS\system32\WMErrSKY.dll
2011-11-27 12:04:49 ----D---- C:\WINDOWS\system32\1051
2011-11-27 11:59:45 ----A---- C:\WINDOWS\system32\ChCfg.exe
2011-11-27 11:59:41 ----A---- C:\WINDOWS\system32\drivers\splitter.sys
2011-11-27 11:59:40 ----A---- C:\WINDOWS\system32\drivers\wdmaud.sys
2011-11-27 11:59:39 ----A---- C:\WINDOWS\system32\drivers\DMusic.sys
2011-11-27 11:59:37 ----A---- C:\WINDOWS\system32\drivers\swmidi.sys
2011-11-27 11:59:36 ----A---- C:\WINDOWS\system32\drivers\aec.sys
2011-11-27 11:59:35 ----A---- C:\WINDOWS\system32\drivers\kmixer.sys
2011-11-27 11:59:33 ----A---- C:\WINDOWS\system32\drivers\drmkaud.sys
2011-11-27 11:59:32 ----A---- C:\WINDOWS\system32\drivers\sysaudio.sys
2011-11-27 11:59:31 ----A---- C:\WINDOWS\system32\drivers\MSKSSRV.sys
2011-11-27 11:59:29 ----A---- C:\WINDOWS\system32\drivers\MSPQM.sys
2011-11-27 11:59:28 ----A---- C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2011-11-27 11:59:23 ----A---- C:\WINDOWS\system32\drivers\portcls.sys
2011-11-27 11:59:22 ----A---- C:\WINDOWS\system32\ksuser.dll
2011-11-27 11:59:22 ----A---- C:\WINDOWS\system32\drivers\drmk.sys
2011-11-27 11:59:15 ----D---- C:\Program Files\Realtek AC97
2011-11-27 11:59:15 ----A---- C:\WINDOWS\system32\RTLCPL.exe
2011-11-27 11:59:14 ----A---- C:\WINDOWS\system32\RtlCPAPI.dll
2011-11-27 11:59:14 ----A---- C:\WINDOWS\system32\drivers\alcxwdm.sys
2011-11-27 11:59:14 ----A---- C:\WINDOWS\soundman.exe
2011-11-27 11:59:13 ----HD---- C:\Program Files\InstallShield Installation Information
2011-11-27 11:59:13 ----A---- C:\WINDOWS\alcupd.exe
2011-11-27 11:59:13 ----A---- C:\WINDOWS\Alcrmv.exe
2011-11-27 11:58:30 ----A---- C:\WINDOWS\system32\CapabilityTable.exe
2011-11-27 11:58:23 ----N---- C:\WINDOWS\system32\nvuide.exe
2011-11-27 11:58:23 ----D---- C:\WINDOWS\system32\ReinstallBackups
2011-11-27 11:58:10 ----A---- C:\WINDOWS\system32\nvunrm.exe
2011-11-27 11:58:10 ----A---- C:\WINDOWS\system32\drivers\nvtcp.sys
2011-11-27 11:58:09 ----A---- C:\WINDOWS\system32\nvusmb.exe
2011-11-27 11:57:29 ----A---- C:\WINDOWS\system32\NVUNINST.EXE
2011-11-27 11:57:20 ----D---- C:\Program Files\Common Files\InstallShield
2011-11-27 11:56:56 ----D---- C:\Documents and Settings\All Users\Application Data\NVIDIA
2011-11-27 11:56:52 ----D---- C:\Documents and Settings\All Users\Application Data\NVIDIA Corporation
2011-11-27 11:56:41 ----A---- C:\WINDOWS\system32\nvrszht.dll
2011-11-27 11:56:41 ----A---- C:\WINDOWS\system32\nvrszhc.dll
2011-11-27 11:56:41 ----A---- C:\WINDOWS\system32\nvrstr.dll
2011-11-27 11:56:41 ----A---- C:\WINDOWS\system32\nvrsth.dll
2011-11-27 11:56:41 ----A---- C:\WINDOWS\system32\nvrssv.dll
2011-11-27 11:56:41 ----A---- C:\WINDOWS\system32\nvrssl.dll
2011-11-27 11:56:41 ----A---- C:\WINDOWS\system32\nvrssk.dll
2011-11-27 11:56:41 ----A---- C:\WINDOWS\system32\nvrsru.dll
2011-11-27 11:56:41 ----A---- C:\WINDOWS\system32\nvrsptb.dll
2011-11-27 11:56:40 ----A---- C:\WINDOWS\system32\nvsvc32.exe
2011-11-27 11:56:40 ----A---- C:\WINDOWS\system32\nvrspt.dll
2011-11-27 11:56:40 ----A---- C:\WINDOWS\system32\nvrspl.dll
2011-11-27 11:56:40 ----A---- C:\WINDOWS\system32\nvrsno.dll
2011-11-27 11:56:40 ----A---- C:\WINDOWS\system32\nvrsnl.dll
2011-11-27 11:56:40 ----A---- C:\WINDOWS\system32\nvrsko.dll
2011-11-27 11:56:40 ----A---- C:\WINDOWS\system32\nvrsja.dll
2011-11-27 11:56:40 ----A---- C:\WINDOWS\system32\nvrsit.dll
2011-11-27 11:56:40 ----A---- C:\WINDOWS\system32\nvrshu.dll
2011-11-27 11:56:40 ----A---- C:\WINDOWS\system32\nvrshe.dll
2011-11-27 11:56:40 ----A---- C:\WINDOWS\system32\nvrsfr.dll
2011-11-27 11:56:40 ----A---- C:\WINDOWS\system32\nvrsfi.dll
2011-11-27 11:56:40 ----A---- C:\WINDOWS\system32\nvrsesm.dll
2011-11-27 11:56:40 ----A---- C:\WINDOWS\system32\nvrses.dll
2011-11-27 11:56:40 ----A---- C:\WINDOWS\system32\nvrseng.dll
2011-11-27 11:56:40 ----A---- C:\WINDOWS\system32\nvrsel.dll
2011-11-27 11:56:40 ----A---- C:\WINDOWS\system32\nvrsde.dll
2011-11-27 11:56:40 ----A---- C:\WINDOWS\system32\nvrsda.dll
2011-11-27 11:56:40 ----A---- C:\WINDOWS\system32\nvrscs.dll
2011-11-27 11:56:40 ----A---- C:\WINDOWS\system32\nvrsar.dll
2011-11-27 11:56:40 ----A---- C:\WINDOWS\system32\nvmctray.dll
2011-11-27 11:56:40 ----A---- C:\WINDOWS\system32\nvcpl.dll
2011-11-27 11:56:40 ----A---- C:\WINDOWS\system32\nvcolor.exe
2011-11-27 11:56:35 ----A---- C:\WINDOWS\system32\nvwddi.dll
2011-11-27 11:56:35 ----A---- C:\WINDOWS\system32\easyupdatusapiu.dll
2011-11-27 11:56:13 ----A---- C:\WINDOWS\system32\OpenCL.dll
2011-11-27 11:56:13 ----A---- C:\WINDOWS\system32\nvoglnt.dll
2011-11-27 11:56:13 ----A---- C:\WINDOWS\system32\nvgenco32.dll
2011-11-27 11:56:13 ----A---- C:\WINDOWS\system32\nvdispco32.dll
2011-11-27 11:56:12 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2011-11-27 11:56:12 ----A---- C:\WINDOWS\system32\nvcuvenc.dll
2011-11-27 11:56:12 ----A---- C:\WINDOWS\system32\nvcuda.dll
2011-11-27 11:56:12 ----A---- C:\WINDOWS\system32\nvcompiler.dll
2011-11-27 11:56:12 ----A---- C:\WINDOWS\system32\nvapi.dll
2011-11-27 11:56:12 ----A---- C:\WINDOWS\system32\nv4_disp.dll
2011-11-27 11:56:12 ----A---- C:\WINDOWS\system32\drivers\nv4_mini.sys
2011-11-27 11:55:33 ----D---- C:\Program Files\NVIDIA Corporation
2011-11-27 11:54:50 ----D---- C:\NVIDIA
2011-11-27 11:48:21 ----A---- C:\WINDOWS\system32\h323log.txt
2011-11-27 11:48:10 ----D---- C:\Documents and Settings\Administrator\Application Data\Ashampoo
2011-11-27 11:47:30 ----D---- C:\Documents and Settings\All Users\Application Data\ashampoo
2011-11-27 11:45:03 ----D---- C:\totalcmd
2011-11-27 11:45:03 ----D---- C:\Documents and Settings\Administrator\Application Data\GHISLER
2011-11-27 11:45:03 ----A---- C:\WINDOWS\UC.PIF
2011-11-27 11:45:03 ----A---- C:\WINDOWS\RAR.PIF
2011-11-27 11:45:03 ----A---- C:\WINDOWS\PKZIP.PIF
2011-11-27 11:45:03 ----A---- C:\WINDOWS\PKUNZIP.PIF
2011-11-27 11:45:03 ----A---- C:\WINDOWS\NOCLOSE.PIF
2011-11-27 11:45:03 ----A---- C:\WINDOWS\LHA.PIF
2011-11-27 11:45:03 ----A---- C:\WINDOWS\ARJ.PIF
2011-11-27 11:43:35 ----D---- C:\Documents and Settings\Administrator\Application Data\Avira
2011-11-27 11:38:05 ----A---- C:\WINDOWS\system32\drivers\ssmdrv.sys
2011-11-27 11:38:04 ----A---- C:\WINDOWS\system32\drivers\avkmgr.sys
2011-11-27 11:38:04 ----A---- C:\WINDOWS\system32\drivers\avipbb.sys
2011-11-27 11:38:04 ----A---- C:\WINDOWS\system32\drivers\avgntflt.sys
2011-11-27 11:38:03 ----D---- C:\Program Files\Avira
2011-11-27 11:38:03 ----D---- C:\Documents and Settings\All Users\Application Data\Avira
2011-11-27 11:36:52 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2011-11-27 11:35:58 ----D---- C:\Program Files\Opera
2011-11-27 11:35:40 ----A---- C:\WINDOWS\system32\unrar.dll
2011-11-27 11:35:40 ----A---- C:\WINDOWS\avisplitter.ini
2011-11-27 11:35:39 ----A---- C:\WINDOWS\system32\yv12vfw.dll
2011-11-27 11:35:39 ----A---- C:\WINDOWS\system32\xvidvfw.dll
2011-11-27 11:35:39 ----A---- C:\WINDOWS\system32\xvidcore.dll
2011-11-27 11:35:37 ----A---- C:\WINDOWS\system32\ff_vfw.dll
2011-11-27 11:35:35 ----D---- C:\Program Files\K-Lite Codec Pack
2011-11-27 11:35:28 ----D---- C:\Documents and Settings\Administrator\Application Data\vlc
2011-11-27 11:35:03 ----D---- C:\Program Files\VideoLAN
2011-11-27 11:34:25 ----D---- C:\Program Files\Winamp Detect
2011-11-27 11:34:18 ----N---- C:\WINDOWS\system32\drivers\PxHelp20.sys
2011-11-27 11:34:18 ----N---- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2011-11-27 11:34:17 ----N---- C:\WINDOWS\system32\vxblock.dll
2011-11-27 11:34:17 ----N---- C:\WINDOWS\system32\pxwave.dll
2011-11-27 11:34:17 ----N---- C:\WINDOWS\system32\pxsfs.dll
2011-11-27 11:34:17 ----N---- C:\WINDOWS\system32\pxmas.dll
2011-11-27 11:34:17 ----N---- C:\WINDOWS\system32\pxinsa64.exe
2011-11-27 11:34:17 ----N---- C:\WINDOWS\system32\pxhpinst.exe
2011-11-27 11:34:17 ----N---- C:\WINDOWS\system32\pxdrv.dll
2011-11-27 11:34:17 ----N---- C:\WINDOWS\system32\pxcpya64.exe
2011-11-27 11:34:17 ----N---- C:\WINDOWS\system32\pxafs.dll
2011-11-27 11:34:17 ----N---- C:\WINDOWS\system32\px.dll
2011-11-27 11:34:17 ----N---- C:\WINDOWS\system32\drivers\cdralw2k.sys
2011-11-27 11:34:17 ----D---- C:\Program Files\Winamp
2011-11-27 11:34:17 ----D---- C:\Documents and Settings\Administrator\Application Data\Winamp
2011-11-27 11:31:32 ----D---- C:\Program Files\WinRAR
2011-11-27 11:30:41 ----A---- C:\WINDOWS\system32\drivers\USBSTOR.SYS
2011-11-27 11:25:18 ----A---- C:\WINDOWS\system32\drivers\audstub.sys
2011-11-27 11:24:50 ----A---- C:\WINDOWS\system32\drivers\redbook.sys
2011-11-27 11:24:03 ----A---- C:\WINDOWS\system32\usbui.dll
2011-11-27 11:22:56 ----SHD---- C:\WINDOWS\Installer
2011-11-27 11:22:56 ----D---- C:\Program Files\Common Files\ODBC
2011-11-27 11:22:56 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-11-27 11:22:56 ----A---- C:\WINDOWS\ODBCINST.INI
2011-11-27 11:22:53 ----D---- C:\Program Files\Common Files\SpeechEngines
2011-11-27 11:22:53 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-11-27 11:22:52 ----RD---- C:\Program Files
2011-11-27 11:22:52 ----D---- C:\Program Files\Common Files
2011-11-27 11:22:50 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2011-11-27 11:22:50 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2011-11-27 11:22:50 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2011-11-27 11:22:48 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2011-11-27 11:22:48 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2011-11-27 11:22:48 ----RA---- C:\WINDOWS\system32\kbdur.dll
2011-11-27 11:22:48 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2011-11-27 11:22:48 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2011-11-27 11:22:48 ----RA---- C:\WINDOWS\system32\kbdru.dll
2011-11-27 11:22:48 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2011-11-27 11:22:48 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2011-11-27 11:22:48 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2011-11-27 11:22:48 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2011-11-27 11:22:48 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2011-11-27 11:22:48 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2011-11-27 11:22:46 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2011-11-27 11:22:46 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2011-11-27 11:22:46 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2011-11-27 11:22:46 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2011-11-27 11:22:46 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2011-11-27 11:22:46 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2011-11-27 11:22:46 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2011-11-27 11:22:45 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2011-11-27 11:22:45 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2011-11-27 11:22:45 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2011-11-27 11:22:45 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2011-11-27 11:22:45 ----RA---- C:\WINDOWS\system32\kbdest.dll
2011-11-27 11:22:44 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2011-11-27 11:22:44 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2011-11-27 11:22:44 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2011-11-27 11:22:44 ----RA---- C:\WINDOWS\system32\kbdro.dll
2011-11-27 11:22:44 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2011-11-27 11:22:44 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2011-11-27 11:22:44 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2011-11-27 11:22:44 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2011-11-27 11:22:44 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
2011-11-27 11:22:44 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
2011-11-27 11:22:44 ----RA---- C:\WINDOWS\system32\kbdcz.dll
2011-11-27 11:22:44 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2011-11-27 11:22:44 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2011-11-27 11:22:39 ----A---- C:\WINDOWS\system32\spxcoins.dll
2011-11-27 11:22:39 ----A---- C:\WINDOWS\system32\irclass.dll
2011-11-27 11:22:39 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2011-11-27 11:22:39 ----A---- C:\WINDOWS\system32\dgsetup.dll
2011-11-27 11:22:39 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2011-11-27 11:22:37 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2011-11-27 11:22:37 ----A---- C:\WINDOWS\TASKMAN.EXE
2011-11-27 11:22:37 ----A---- C:\WINDOWS\system32\drivers\irenum.sys
2011-11-27 11:22:37 ----A---- C:\WINDOWS\system32\batt.dll
2011-11-27 11:22:37 ----A---- C:\WINDOWS\NOTEPAD.EXE
2011-11-27 11:22:36 ----A---- C:\WINDOWS\system32\storprop.dll
2011-11-27 11:22:30 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
2011-11-27 11:22:12 ----D---- C:\WINDOWS\system32\CatRoot2
2011-11-27 11:22:12 ----D---- C:\WINDOWS\system32\CatRoot
2011-11-27 11:22:07 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2011-11-27 11:21:54 ----A---- C:\WINDOWS\setuplog.txt
2011-11-27 11:21:51 ----SHD---- C:\System Volume Information
2011-11-27 11:21:51 ----D---- C:\Documents and Settings
2011-11-27 11:21:51 ----A---- C:\WINDOWS\system32\FNTCACHE.DAT
2011-11-27 11:21:07 ----SH---- C:\boot.ini
2011-11-27 11:17:52 ----SD---- C:\WINDOWS\Offline Web Pages
2011-11-27 11:17:52 ----SD---- C:\WINDOWS\Downloaded Program Files
2011-11-27 11:17:52 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-11-27 11:17:52 ----RSD---- C:\WINDOWS\Fonts
2011-11-27 11:17:52 ----RD---- C:\WINDOWS\Web
2011-11-27 11:17:52 ----HD---- C:\WINDOWS\inf
2011-11-27 11:17:52 ----D---- C:\WINDOWS\WinSxS
2011-11-27 11:17:52 ----D---- C:\WINDOWS\WBEM
2011-11-27 11:17:52 ----D---- C:\WINDOWS\twain_32
2011-11-27 11:17:52 ----D---- C:\WINDOWS\Temp
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\wins
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\wbem
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\usmt
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\spool
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\ShellExt
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\Setup
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\scripting
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\ras
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\oobe
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\npp
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\mui
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\inetsrv
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\IME
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\icsxml
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\ias
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\export
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\en-US
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\en
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\drivers\UMDF
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\drivers\etc
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\drivers\disdn
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\drivers
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\dhcp
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\config
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\3com_dmi
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\3076
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\2052
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\1054
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\1042
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\1041
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\1037
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\1033
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\1031
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\1028
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32\1025
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system32
2011-11-27 11:17:52 ----D---- C:\WINDOWS\system
2011-11-27 11:17:52 ----D---- C:\WINDOWS\security
2011-11-27 11:17:52 ----D---- C:\WINDOWS\Resources
2011-11-27 11:17:52 ----D---- C:\WINDOWS\repair
2011-11-27 11:17:52 ----D---- C:\WINDOWS\Provisioning
2011-11-27 11:17:52 ----D---- C:\WINDOWS\pchealth
2011-11-27 11:17:52 ----D---- C:\WINDOWS\PeerNet
2011-11-27 11:17:52 ----D---- C:\WINDOWS\NLDRV
2011-11-27 11:17:52 ----D---- C:\WINDOWS\Network Diagnostic
2011-11-27 11:17:52 ----D---- C:\WINDOWS\mui
2011-11-27 11:17:52 ----D---- C:\WINDOWS\msapps
2011-11-27 11:17:52 ----D---- C:\WINDOWS\msagent
2011-11-27 11:17:52 ----D---- C:\WINDOWS\Media
2011-11-27 11:17:52 ----D---- C:\WINDOWS\L2Schemas
2011-11-27 11:17:52 ----D---- C:\WINDOWS\java
2011-11-27 11:17:52 ----D---- C:\WINDOWS\ime
2011-11-27 11:17:52 ----D---- C:\WINDOWS\Help
2011-11-27 11:17:52 ----D---- C:\WINDOWS\ehome
2011-11-27 11:17:52 ----D---- C:\WINDOWS\Driver Cache
2011-11-27 11:17:52 ----D---- C:\WINDOWS\Debug
2011-11-27 11:17:52 ----D---- C:\WINDOWS\Cursors
2011-11-27 11:17:52 ----D---- C:\WINDOWS\Connection Wizard
2011-11-27 11:17:52 ----D---- C:\WINDOWS\Config
2011-11-27 11:17:52 ----D---- C:\WINDOWS\AppPatch
2011-11-27 11:17:52 ----D---- C:\WINDOWS\addins
2011-11-27 11:17:52 ----D---- C:\WINDOWS
2011-11-27 11:17:52 ----ASH---- C:\pagefile.sys
2011-11-27 11:13:38 ----A---- C:\WINDOWS\system32\mdimon.dll
2011-11-27 11:12:03 ----D---- C:\Program Files\Microsoft Works
2011-11-27 11:11:42 ----D---- C:\Program Files\Microsoft Visual Studio
2011-11-27 11:11:42 ----D---- C:\Program Files\Common Files\DESIGNER
2011-11-27 11:11:19 ----D---- C:\Program Files\Microsoft.NET
2011-11-27 11:09:23 ----D---- C:\Program Files\Microsoft Visual Studio 8
2011-11-27 11:08:52 ----D---- C:\WINDOWS\SHELLNEW
2011-11-27 11:08:41 ----D---- C:\Program Files\Microsoft Office
2011-11-27 11:08:41 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2011-11-27 11:08:27 ----RHD---- C:\MSOCache
2011-11-27 11:06:21 ----D---- C:\Documents and Settings\Administrator\Application Data\Windows Desktop Search
2011-11-27 11:06:04 ----A---- C:\WINDOWS\system32\wmpns.dll
2011-11-27 11:06:01 ----D---- C:\Documents and Settings\Administrator\Application Data\Identities
2011-11-27 11:05:59 ----HD---- C:\Program Files\Uninstall Information
2011-11-27 11:05:46 ----ASH---- C:\Documents and Settings\Administrator\Application Data\desktop.ini
2011-11-27 11:05:45 ----SD---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2011-11-27 11:05:38 ----D---- C:\WINDOWS\Prefetch
2011-11-27 11:05:37 ----SD---- C:\WINDOWS\system32\Microsoft
2011-11-27 11:05:37 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-11-27 11:04:35 ----AS---- C:\WINDOWS\bootstat.dat
2011-11-27 11:02:16 ----D---- C:\WINDOWS\system32\xircom
2011-11-27 11:02:16 ----D---- C:\Program Files\xerox
2011-11-27 11:02:16 ----D---- C:\Program Files\microsoft frontpage
2011-11-27 11:02:02 ----A---- C:\WINDOWS\system32\javaws.exe
2011-11-27 11:02:02 ----A---- C:\WINDOWS\system32\javaw.exe
2011-11-27 11:02:02 ----A---- C:\WINDOWS\system32\java.exe
2011-11-27 11:02:02 ----A---- C:\WINDOWS\system32\deploytk.dll
2011-11-27 11:01:54 ----D---- C:\Program Files\Java
2011-11-27 10:58:48 ----D---- C:\WINDOWS\system32\XPSViewer
2011-11-27 10:58:48 ----D---- C:\Program Files\MSBuild
2011-11-27 10:58:45 ----D---- C:\Program Files\Reference Assemblies
2011-11-27 10:58:37 ----N---- C:\WINDOWS\system32\spmsg.dll
2011-11-27 10:57:19 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2011-11-27 10:57:15 ----N---- C:\WINDOWS\system32\prntvpt.dll
2011-11-27 10:56:26 ----RASH---- C:\MSDOS.SYS
2011-11-27 10:56:26 ----RASH---- C:\IO.SYS
2011-11-27 10:56:26 ----A---- C:\WINDOWS\control.ini
2011-11-27 10:56:26 ----A---- C:\CONFIG.SYS
2011-11-27 10:56:26 ----A---- C:\AUTOEXEC.BAT
2011-11-27 10:56:04 ----A---- C:\WINDOWS\OEWABLog.txt
2011-11-27 10:56:01 ----A---- C:\WINDOWS\system32\mapi32.dll
2011-11-27 10:54:59 ----HD---- C:\Program Files\WindowsUpdate
2011-11-27 10:54:44 ----D---- C:\Program Files\Windows Media Connect 2
2011-11-27 10:54:30 ----D---- C:\WINDOWS\system32\DirectX
2011-11-27 10:54:21 ----A---- C:\WINDOWS\system32\atrace.dll
2011-11-27 10:54:19 ----A---- C:\WINDOWS\system32\desktop.ini
2011-11-27 10:54:19 ----A---- C:\WINDOWS\desktop.ini
2011-11-27 10:54:13 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2011-11-27 10:54:12 ----D---- C:\Program Files\Common Files\Services
2011-11-27 10:54:12 ----A---- C:\WINDOWS\system32\acctres.dll
2011-11-27 10:54:09 ----SD---- C:\WINDOWS\Tasks
2011-11-27 10:54:09 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2011-11-27 10:54:08 ----D---- C:\Program Files\Common Files\MSSoap
2011-11-27 10:54:02 ----D---- C:\WINDOWS\srchasst
2011-11-27 10:54:00 ----D---- C:\WINDOWS\system32\Macromed
2011-11-27 10:53:58 ----A---- C:\WINDOWS\system32\wuweb.dll
2011-11-27 10:53:58 ----A---- C:\WINDOWS\system32\wucltui.dll
2011-11-27 10:53:57 ----A---- C:\WINDOWS\system32\wups.dll
2011-11-27 10:53:57 ----A---- C:\WINDOWS\system32\wuauserv.dll
2011-11-27 10:53:57 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2011-11-27 10:53:57 ----A---- C:\WINDOWS\system32\wuaueng.dll
2011-11-27 10:53:57 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2011-11-27 10:53:57 ----A---- C:\WINDOWS\system32\wuauclt.exe
2011-11-27 10:53:56 ----A---- C:\WINDOWS\system32\wuapi.dll
2011-11-27 10:53:56 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2011-11-27 10:53:56 ----A---- C:\WINDOWS\system32\qmgr.dll
2011-11-27 10:53:56 ----A---- C:\WINDOWS\system32\bitsprx4.dll
2011-11-27 10:53:56 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2011-11-27 10:53:56 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2011-11-27 10:53:52 ----D---- C:\Program Files\Movie Maker
2011-11-27 10:53:35 ----A---- C:\WINDOWS\system32\safrslv.dll
2011-11-27 10:53:35 ----A---- C:\WINDOWS\system32\safrdm.dll
2011-11-27 10:53:35 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2011-11-27 10:53:35 ----A---- C:\WINDOWS\system32\racpldlg.dll
2011-11-27 10:53:31 ----A---- C:\WINDOWS\system32\fltMc.exe
2011-11-27 10:53:31 ----A---- C:\WINDOWS\system32\fltlib.dll
2011-11-27 10:53:30 ----D---- C:\WINDOWS\system32\Restore
2011-11-27 10:53:30 ----A---- C:\WINDOWS\system32\srsvc.dll
2011-11-27 10:53:30 ----A---- C:\WINDOWS\system32\srrstr.dll
2011-11-27 10:53:30 ----A---- C:\WINDOWS\system32\srclient.dll
2011-11-27 10:53:30 ----A---- C:\WINDOWS\system32\drivers\sr.sys
2011-11-27 10:53:30 ----A---- C:\WINDOWS\system32\drivers\fltMgr.sys
2011-11-27 10:53:29 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2011-11-27 10:53:29 ----A---- C:\WINDOWS\system32\msconf.dll
2011-11-27 10:53:29 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2011-11-27 10:53:29 ----A---- C:\WINDOWS\system32\mnmdd.dll
2011-11-27 10:53:29 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2011-11-27 10:53:29 ----A---- C:\WINDOWS\system32\ils.dll
2011-11-27 10:53:26 ----D---- C:\Program Files\NetMeeting
2011-11-27 10:53:26 ----A---- C:\WINDOWS\system32\msoert2.dll
2011-11-27 10:53:26 ----A---- C:\WINDOWS\system32\msoeacct.dll
2011-11-27 10:53:25 ----A---- C:\WINDOWS\system32\inetres.dll
2011-11-27 10:53:24 ----A---- C:\WINDOWS\system32\inetcomm.dll
2011-11-27 10:53:22 ----D---- C:\Program Files\Outlook Express
2011-11-27 10:53:22 ----A---- C:\WINDOWS\system32\schedsvc.dll
2011-11-27 10:53:22 ----A---- C:\WINDOWS\system32\mstinit.exe
2011-11-27 10:53:22 ----A---- C:\WINDOWS\system32\mstask.dll
2011-11-27 10:53:22 ----A---- C:\WINDOWS\system32\isign32.dll
2011-11-27 10:53:22 ----A---- C:\WINDOWS\system32\inetcfg.dll
2011-11-27 10:53:22 ----A---- C:\WINDOWS\system32\icwphbk.dll
2011-11-27 10:53:22 ----A---- C:\WINDOWS\system32\icwdial.dll
2011-11-27 10:53:16 ----D---- C:\Program Files\Common Files\System
2011-11-27 10:52:46 ----RSD---- C:\WINDOWS\assembly
2011-11-27 10:52:38 ----D---- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2011-11-27 10:52:14 ----A---- C:\WINDOWS\system32\emptyregdb.dat
2011-11-27 10:52:07 ----D---- C:\Program Files\ComPlus Applications
2011-11-27 10:52:05 ----A---- C:\WINDOWS\vbaddin.ini
2011-11-27 10:52:05 ----A---- C:\WINDOWS\vb.ini
2011-11-27 10:52:02 ----D---- C:\WINDOWS\Registration
2011-11-27 10:51:57 ----D---- C:\Program Files\Online Services
2011-11-27 10:51:49 ----D---- C:\Program Files\Windows Media Player
2011-11-27 10:51:45 ----A---- C:\WINDOWS\system32\Bliss.scr
2011-11-27 10:51:40 ----A---- C:\WINDOWS\system32\xpssvcs.dll
2011-11-27 10:51:37 ----A---- C:\WINDOWS\system32\winUsbCoinstaller.dll
2011-11-27 10:51:37 ----A---- C:\WINDOWS\system32\WdfCoInstaller01007.dll
2011-11-27 10:51:36 ----A---- C:\WINDOWS\system32\WUDFUpdate_01007.dll
2011-11-27 10:51:35 ----D---- C:\WINDOWS\system32\DRM
2011-11-27 10:51:35 ----A---- C:\WINDOWS\system32\SecProc_ssp_isv.dll
2011-11-27 10:51:35 ----A---- C:\WINDOWS\system32\imapi2fs.dll
2011-11-27 10:51:35 ----A---- C:\WINDOWS\system32\imapi2.dll
2011-11-27 10:51:34 ----A---- C:\WINDOWS\system32\SecProc_ssp.dll
2011-11-27 10:51:34 ----A---- C:\WINDOWS\system32\RmActivate_ssp_isv.exe
2011-11-27 10:51:34 ----A---- C:\WINDOWS\system32\RmActivate_ssp.exe
2011-11-27 10:51:34 ----A---- C:\WINDOWS\system32\RmActivate_isv.exe
2011-11-27 10:51:33 ----A---- C:\WINDOWS\system32\SecProc_isv.dll
2011-11-27 10:51:33 ----A---- C:\WINDOWS\system32\SecProc.dll
2011-11-27 10:51:33 ----A---- C:\WINDOWS\system32\RmActivate.exe
2011-11-27 10:51:33 ----A---- C:\WINDOWS\system32\msdrm.dll
2011-11-27 10:51:32 ----A---- C:\WINDOWS\system32\UncRes.dll
2011-11-27 10:51:32 ----A---- C:\WINDOWS\system32\UncPH.dll
2011-11-27 10:51:32 ----A---- C:\WINDOWS\system32\UncNE.dll
2011-11-27 10:51:32 ----A---- C:\WINDOWS\system32\UncDMS.dll
2011-11-27 10:51:32 ----A---- C:\WINDOWS\system32\UncCplExt.dll
2011-11-27 10:51:32 ----A---- C:\WINDOWS\system32\oephRes.dll
2011-11-27 10:51:32 ----A---- C:\WINDOWS\system32\oeph.dll
2011-11-27 10:51:27 ----D---- C:\Program Files\Windows Desktop Search
2011-11-27 10:51:26 ----D---- C:\WINDOWS\system32\GroupPolicy
2011-11-27 10:51:25 ----A---- C:\WINDOWS\system32\srchadmin.dll
2011-11-27 10:51:25 ----A---- C:\WINDOWS\system32\propsys.dll
2011-11-27 10:51:24 ----A---- C:\WINDOWS\system32\xmlfilter.dll
2011-11-27 10:51:24 ----A---- C:\WINDOWS\system32\rtffilt.dll
2011-11-27 10:51:24 ----A---- C:\WINDOWS\system32\msshsq.dll
2011-11-27 10:51:24 ----A---- C:\WINDOWS\system32\msshooks.dll
2011-11-27 10:51:24 ----A---- C:\WINDOWS\system32\idxcntrs.ini
2011-11-27 10:51:23 ----A---- C:\WINDOWS\system32\tquery.dll
2011-11-27 10:51:23 ----A---- C:\WINDOWS\system32\msscb.dll
2011-11-27 10:51:23 ----A---- C:\WINDOWS\system32\gthrctr.ini
2011-11-27 10:51:23 ----A---- C:\WINDOWS\system32\gsrvctr.ini
2011-11-27 10:51:22 ----A---- C:\WINDOWS\system32\propdefs.dll
2011-11-27 10:51:22 ----A---- C:\WINDOWS\system32\msstrc.dll
2011-11-27 10:51:22 ----A---- C:\WINDOWS\system32\mssrch.dll
2011-11-27 10:51:22 ----A---- C:\WINDOWS\system32\mssprxy.dll
2011-11-27 10:51:22 ----A---- C:\WINDOWS\system32\mssphtb.dll
2011-11-27 10:51:21 ----A---- C:\WINDOWS\system32\searchprotocolhost.exe
2011-11-27 10:51:21 ----A---- C:\WINDOWS\system32\searchindexer.exe
2011-11-27 10:51:21 ----A---- C:\WINDOWS\system32\searchfilterhost.exe
2011-11-27 10:51:21 ----A---- C:\WINDOWS\system32\mssph.dll
2011-11-27 10:51:21 ----A---- C:\WINDOWS\system32\mssitlb.dll
2011-11-27 10:51:21 ----A---- C:\WINDOWS\system32\msscntrs.dll
2011-11-27 10:51:20 ----A---- C:\WINDOWS\system32\msxml4r.dll
2011-11-27 10:51:19 ----D---- C:\Program Files\MSXML 4.0
2011-11-27 10:51:19 ----A---- C:\WINDOWS\system32\msxml4.dll
2011-11-27 10:51:12 ----A---- C:\WINDOWS\system32\xinput9_1_0.dll
2011-11-27 10:51:12 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2011-11-27 10:51:12 ----A---- C:\WINDOWS\system32\xinput1_2.dll
2011-11-27 10:51:12 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2011-11-27 10:51:12 ----A---- C:\WINDOWS\system32\XAudio2_4.dll
2011-11-27 10:51:11 ----A---- C:\WINDOWS\system32\XAudio2_3.dll
2011-11-27 10:51:11 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2011-11-27 10:51:11 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
2011-11-27 10:51:11 ----A---- C:\WINDOWS\system32\XAudio2_0.dll
2011-11-27 10:51:11 ----A---- C:\WINDOWS\system32\XAPOFX1_3.dll
2011-11-27 10:51:11 ----A---- C:\WINDOWS\system32\XAPOFX1_2.dll
2011-11-27 10:51:10 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2011-11-27 10:51:10 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
2011-11-27 10:51:10 ----A---- C:\WINDOWS\system32\xactengine3_4.dll
2011-11-27 10:51:10 ----A---- C:\WINDOWS\system32\xactengine3_3.dll
2011-11-27 10:51:10 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
2011-11-27 10:51:10 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
2011-11-27 10:51:10 ----A---- C:\WINDOWS\system32\xactengine3_0.dll
2011-11-27 10:51:10 ----A---- C:\WINDOWS\system32\xactengine2_9.dll
2011-11-27 10:51:10 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
2011-11-27 10:51:10 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
2011-11-27 10:51:09 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2011-11-27 10:51:09 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
2011-11-27 10:51:09 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2011-11-27 10:51:09 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
2011-11-27 10:51:09 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2011-11-27 10:51:09 ----A---- C:\WINDOWS\system32\xactengine2_10.dll
2011-11-27 10:51:09 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2011-11-27 10:51:09 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2011-11-27 10:51:08 ----A---- C:\WINDOWS\system32\X3DAudio1_6.dll
2011-11-27 10:51:08 ----A---- C:\WINDOWS\system32\X3DAudio1_5.dll
2011-11-27 10:51:08 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
2011-11-27 10:51:08 ----A---- C:\WINDOWS\system32\X3DAudio1_3.dll
2011-11-27 10:51:08 ----A---- C:\WINDOWS\system32\X3DAudio1_2.dll
2011-11-27 10:51:08 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2011-11-27 10:51:08 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2011-11-27 10:51:07 ----A---- C:\WINDOWS\system32\D3DX9_41.dll
2011-11-27 10:51:06 ----A---- C:\WINDOWS\system32\D3DX9_40.dll
2011-11-27 10:51:05 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2011-11-27 10:51:05 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
2011-11-27 10:51:04 ----A---- C:\WINDOWS\system32\D3DX9_37.dll
2011-11-27 10:51:03 ----A---- C:\WINDOWS\system32\d3dx9_36.dll
2011-11-27 10:51:02 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
2011-11-27 10:51:01 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2011-11-27 10:51:01 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2011-11-27 10:51:00 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
2011-11-27 10:50:59 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2011-11-27 10:50:59 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2011-11-27 10:50:58 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2011-11-27 10:50:57 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2011-11-27 10:50:57 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2011-11-27 10:50:56 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2011-11-27 10:50:56 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2011-11-27 10:50:55 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2011-11-27 10:50:55 ----A---- C:\WINDOWS\system32\d3dx10_41.dll
2011-11-27 10:50:55 ----A---- C:\WINDOWS\system32\d3dx10_40.dll
2011-11-27 10:50:54 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2011-11-27 10:50:54 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
2011-11-27 10:50:54 ----A---- C:\WINDOWS\system32\d3dx10_37.dll
2011-11-27 10:50:54 ----A---- C:\WINDOWS\system32\d3dx10_36.dll
2011-11-27 10:50:54 ----A---- C:\WINDOWS\system32\d3dx10_35.dll
2011-11-27 10:50:54 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2011-11-27 10:50:53 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2011-11-27 10:50:53 ----A---- C:\WINDOWS\system32\D3DCompiler_41.dll
2011-11-27 10:50:52 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll
2011-11-27 10:50:52 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2011-11-27 10:50:51 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
2011-11-27 10:50:51 ----A---- C:\WINDOWS\system32\D3DCompiler_37.dll
2011-11-27 10:50:51 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll
2011-11-27 10:50:50 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll
2011-11-27 10:50:50 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2011-11-27 10:50:49 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2011-11-27 10:50:40 ----D---- C:\WINDOWS\system32\windowspowershell
2011-11-27 10:50:32 ----D---- C:\WINDOWS\SoftwareDistribution
2011-11-27 10:50:32 ----D---- C:\Program Files\Microsoft Silverlight
2011-11-27 10:50:32 ----A---- C:\WINDOWS\system32\muweb.dll
2011-11-27 10:50:32 ----A---- C:\WINDOWS\system32\mucltui.dll
2011-11-27 10:50:31 ----A---- C:\WINDOWS\system32\WgaTray.exe
2011-11-27 10:50:31 ----A---- C:\WINDOWS\system32\WgaLogon.dll
2011-11-27 10:50:31 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2011-11-27 10:50:31 ----A---- C:\WINDOWS\system32\MicrosoftUpdateCatalogWebControl.dll
2011-11-27 10:50:30 ----D---- C:\WINDOWS\system32\PreInstall
2011-11-27 10:50:21 ----A---- C:\WINDOWS\system32\netfxperf.dll
2011-11-27 10:50:19 ----D---- C:\Program Files\Internet Explorer
2011-11-27 10:50:10 ----D---- C:\WINDOWS\Microsoft.NET
2011-11-27 10:50:06 ----D---- C:\Program Files\Messenger
2011-11-27 10:50:03 ----D---- C:\Program Files\MSN Gaming Zone
2011-11-27 10:50:03 ----A---- C:\WINDOWS\system32\write.exe
2011-11-27 10:49:55 ----A---- C:\WINDOWS\system32\sndvol32.exe
2011-11-27 10:49:55 ----A---- C:\WINDOWS\system32\hticons.dll
2011-11-27 10:49:55 ----A---- C:\WINDOWS\system32\avwav.dll
2011-11-27 10:49:55 ----A---- C:\WINDOWS\system32\avtapi.dll
2011-11-27 10:49:55 ----A---- C:\WINDOWS\system32\avmeter.dll
2011-11-27 10:49:54 ----A---- C:\WINDOWS\system32\winchat.exe
2011-11-27 10:49:49 ----A---- C:\WINDOWS\system32\charmap.exe
2011-11-27 10:49:49 ----A---- C:\WINDOWS\system32\getuname.dll
2011-11-27 10:49:49 ----A---- C:\WINDOWS\system32\calc.exe
2011-11-27 10:49:48 ----A---- C:\WINDOWS\system32\winmine.exe
2011-11-27 10:49:48 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2011-11-27 10:49:48 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2011-11-27 10:49:48 ----A---- C:\WINDOWS\system32\tskill.exe
2011-11-27 10:49:48 ----A---- C:\WINDOWS\system32\sol.exe
2011-11-27 10:49:48 ----A---- C:\WINDOWS\system32\reset.exe
2011-11-27 10:49:48 ----A---- C:\WINDOWS\system32\mshearts.exe
2011-11-27 10:49:48 ----A---- C:\WINDOWS\system32\freecell.exe
2011-11-27 10:49:47 ----A---- C:\WINDOWS\system32\tslabels.ini
2011-11-27 10:49:47 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2011-11-27 10:49:47 ----A---- C:\WINDOWS\system32\tscon.exe
2011-11-27 10:49:47 ----A---- C:\WINDOWS\system32\shadow.exe
2011-11-27 10:49:47 ----A---- C:\WINDOWS\system32\rwinsta.exe
2011-11-27 10:49:47 ----A---- C:\WINDOWS\system32\regini.exe
2011-11-27 10:49:47 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2011-11-27 10:49:47 ----A---- C:\WINDOWS\system32\qwinsta.exe
2011-11-27 10:49:47 ----A---- C:\WINDOWS\system32\qappsrv.exe
2011-11-27 10:49:47 ----A---- C:\WINDOWS\system32\msg.exe
2011-11-27 10:49:47 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2011-11-27 10:49:47 ----A---- C:\WINDOWS\system32\logoff.exe
2011-11-27 10:49:47 ----A---- C:\WINDOWS\system32\cdmodem.dll
2011-11-27 10:49:42 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2011-11-27 10:49:33 ----D---- C:\Program Files\MSN
2011-11-27 10:49:32 ----D---- C:\Program Files\Windows NT
2011-11-27 10:49:32 ----A---- C:\WINDOWS\system32\sndrec32.exe
2011-11-27 10:49:32 ----A---- C:\WINDOWS\system32\mspaint.exe
2011-11-27 10:49:32 ----A---- C:\WINDOWS\system32\mplay32.exe
2011-11-27 10:49:32 ----A---- C:\WINDOWS\system32\hypertrm.dll
2011-11-27 10:49:32 ----A---- C:\WINDOWS\system32\accwiz.exe
2011-11-27 10:49:31 ----A---- C:\WINDOWS\system32\spider.exe
2011-11-27 10:49:31 ----A---- C:\WINDOWS\system32\drivers\tdtcp.sys
2011-11-27 10:49:31 ----A---- C:\WINDOWS\system32\clipbrd.exe
2011-11-27 10:49:30 ----A---- C:\WINDOWS\system32\tsgqec.dll
2011-11-27 10:49:30 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2011-11-27 10:49:30 ----A---- C:\WINDOWS\system32\rhttpaa.dll
2011-11-27 10:49:30 ----A---- C:\WINDOWS\system32\drivers\tdpipe.sys
2011-11-27 10:49:30 ----A---- C:\WINDOWS\system32\drivers\rdpwd.sys
2011-11-27 10:49:30 ----A---- C:\WINDOWS\system32\aaclient.dll
2011-11-27 10:49:29 ----A---- C:\WINDOWS\system32\termsrv.dll
2011-11-27 10:49:29 ----A---- C:\WINDOWS\system32\sessmgr.exe
2011-11-27 10:49:29 ----A---- C:\WINDOWS\system32\remotepg.dll
2011-11-27 10:49:29 ----A---- C:\WINDOWS\system32\rdshost.exe
2011-11-27 10:49:29 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2011-11-27 10:49:29 ----A---- C:\WINDOWS\system32\rdchost.dll
2011-11-27 10:49:29 ----A---- C:\WINDOWS\system32\mstscax.dll
2011-11-27 10:49:29 ----A---- C:\WINDOWS\system32\mstsc.exe
2011-11-27 10:49:28 ----D---- C:\WINDOWS\system32\MsDtc
2011-11-27 10:49:28 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2011-11-27 10:49:28 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2011-11-27 10:49:28 ----A---- C:\WINDOWS\system32\rdpclip.exe
2011-11-27 10:49:28 ----A---- C:\WINDOWS\system32\qprocess.exe
2011-11-27 10:49:28 ----A---- C:\WINDOWS\system32\mtxoci.dll
2011-11-27 10:49:28 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2011-11-27 10:49:28 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2011-11-27 10:49:28 ----A---- C:\WINDOWS\system32\icaapi.dll
2011-11-27 10:49:28 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2011-11-27 10:49:27 ----A---- C:\WINDOWS\system32\xolehlp.dll
2011-11-27 10:49:27 ----A---- C:\WINDOWS\system32\msdtctm.dll
2011-11-27 10:49:27 ----A---- C:\WINDOWS\system32\msdtclog.dll
2011-11-27 10:49:27 ----A---- C:\WINDOWS\system32\msdtc.exe
2011-11-27 10:49:27 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2011-11-27 10:49:26 ----D---- C:\WINDOWS\system32\Com
2011-11-27 10:49:26 ----A---- C:\WINDOWS\system32\stclient.dll
2011-11-27 10:49:26 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2011-11-27 10:49:26 ----A---- C:\WINDOWS\system32\mtxex.dll
2011-11-27 10:49:26 ----A---- C:\WINDOWS\system32\mtxdm.dll
2011-11-27 10:49:26 ----A---- C:\WINDOWS\system32\comrepl.dll
2011-11-27 10:49:26 ----A---- C:\WINDOWS\system32\comaddin.dll
2011-11-27 10:49:26 ----A---- C:\WINDOWS\system32\colbact.dll
2011-11-27 10:49:26 ----A---- C:\WINDOWS\system32\clbcatex.dll
2011-11-27 10:49:26 ----A---- C:\WINDOWS\system32\catsrvps.dll
2011-11-27 10:49:25 ----A---- C:\WINDOWS\system32\comuid.dll
2011-11-27 10:49:25 ----A---- C:\WINDOWS\system32\comsvcs.dll
2011-11-27 10:49:25 ----A---- C:\WINDOWS\system32\comsnap.dll
2011-11-27 10:49:25 ----A---- C:\WINDOWS\system32\clbcatq.dll
2011-11-27 10:49:25 ----A---- C:\WINDOWS\system32\catsrvut.dll
2011-11-27 10:49:25 ----A---- C:\WINDOWS\system32\catsrv.dll
2011-11-27 10:49:19 ----A---- C:\WINDOWS\system32\servdeps.dll
2011-11-27 10:49:19 ----A---- C:\WINDOWS\system32\mmfutil.dll
2011-11-27 10:49:19 ----A---- C:\WINDOWS\system32\licwmi.dll
2011-11-27 10:49:19 ----A---- C:\WINDOWS\system32\cmprops.dll
2011-11-27 10:49:13 ----A---- C:\WINDOWS\system32\drivers\termdd.sys
2011-11-27 10:49:13 ----A---- C:\WINDOWS\system32\drivers\rdpdr.sys

======List of files/folders modified in the last 1 month======

2011-11-27 12:09:05 ----A---- C:\WINDOWS\win.ini
2011-11-27 12:09:05 ----A---- C:\WINDOWS\system.ini
2011-11-27 10:55:41 ----ASH---- C:\WINDOWS\fonts\desktop.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 nvata;nvata; C:\WINDOWS\system32\DRIVERS\nvata.sys [2006-04-24 100736]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-04-28 44944]
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2011-12-08 134856]
R1 avkmgr;avkmgr; C:\WINDOWS\system32\DRIVERS\avkmgr.sys [2011-10-19 36000]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2010-06-17 28520]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2011-10-19 74640]
R2 rspndr;Link-Layer Topology Discovery Responder; C:\WINDOWS\system32\DRIVERS\rspndr.sys [2008-05-29 62848]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-12-02 3841856]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2011-10-08 12791488]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2006-02-17 34176]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2006-02-17 13056]
S3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-04-14 12160]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 exFat;exFat; C:\WINDOWS\system32\drivers\exFat.sys [2008-09-29 133632]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirService;Avira Realtime Protection; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2011-10-19 110032]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2011-10-19 86224]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-11-27 152984]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]
R2 NVSvc;NVIDIA Driver Helper Service; C:\WINDOWS\system32\nvsvc32.exe [2011-10-08 298304]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-08 2253120]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-30 46104]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-30 881664]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-30 132096]

-----------------EOF-----------------

Re: Roguekiller

Napsal: 25 pro 2011 17:54
od Rudy
Toto vypadá OK. Ještě poprosím o sken GMER: http://www.viry.cz/forum/viewtopic.php?f=29&t=62878 . Dejte oba logy.

Re: Roguekiller

Napsal: 25 pro 2011 21:18
od Peelie
Ospravedlnujem sa logy GMERU teraz robit nebudem aj z casovych dovodov,PC ide dobre. Ak by boli problemy hodim sem logy.Inak diky.

Re: Roguekiller

Napsal: 25 pro 2011 21:47
od Rudy
Ok. Nemáte zač. Pokud by něco bylo špatně, potom už jen rootkity. Gmer je detekční utilita pro rootkity.