prosím o kontrolu logu - trojský kůn - fake email česke p.
Napsal: 10 pro 2013 13:44
počítač jsem nechal projet ESET NOD32 ANTIVIRUS
Protokol o kontrole
Verze virové databáze: 9152 (20131209)
Datum: 10.12.2013 Čas: 9:02:54
Testované disky, adresáře a soubory: Operační paměť;C:\Boot sektor;D:\Boot sektor;C:\;D:\
Operační paměť » OnekeySupport.exe(2992) - varianta infiltrace Win32/Spy.Hesperbot.C trojský kůň - vyléčen smazáním [1]
Operační paměť » explorer.exe(2680) - varianta infiltrace Win32/Spy.Hesperbot.C trojský kůň - vyléčen smazáním [1]
Operační paměť » IAStorIcon.exe(3828) - varianta infiltrace Win32/Spy.Hesperbot.C trojský kůň - vyléčen smazáním [1]
Operační paměť » VM331_STI.EXE(3896) - varianta infiltrace Win32/Spy.Hesperbot.C trojský kůň - vyléčen smazáním [1]
Operační paměť » jusched.exe(3576) - varianta infiltrace Win32/Spy.Hesperbot.C trojský kůň - vyléčen smazáním [1]
Operační paměť » Skype.exe(3064) - varianta infiltrace Win32/Spy.Hesperbot.C trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.C trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » TOTALCMD.EXE(2272) - varianta infiltrace Win32/Spy.Hesperbot.C trojský kůň - vyléčen smazáním [1]
C:\hiberfil.sys - chyba při otevírání [4]
C:\pagefile.sys - chyba při otevírání [4]
C:\###Radost###\OOo_3.3.0_Win_x86_install_cs.exe » NSIS » openofficeorg1.cab » CAB » testtar.tar » TAR » - poškozený archiv
Kontrola přerušena uživatelem!
Počet zkontrolovaných objektů: 5157
Počet nalezených hrozeb: 29
Počet vyléčených objektů: 29
Čas ukončení: 9:04:12 Celkový čas diagnostiky: 78 sek (00:01:18)
Poznámky:
[1] Objekt byl smazán, obsahoval pouze škodlivý kód.
[4] Objekt nelze otevřít ke čtení. Je využíván jinou aplikací (nebo operačním systémem), která ho otevřela výhradně pro sebe.
Logfile of random's system information tool 1.09 (written by random/random)
Run by Sema at 2013-12-10 13:21:32
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 23 GB (5%) free of 432 GB
Total RAM: 3959 MB (54% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:21:39, on 10.12.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16736)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\USB Camera\VM331_STI.EXE
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\totalcmd\TOTALCMD.EXE
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Users\Sema\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2AALCLP9\RSIT.exe
C:\Program Files (x86)\trend micro\Sema.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [331BigDog] C:\Program Files (x86)\USB Camera\VM331_STI.EXE
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\3.0"
O4 - HKLM\..\Run: [UpdateP2GShortCut] "C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Dropbox.lnk = C:\Users\Sema\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Moveslink for Movestick Mini.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files (x86)\ICQ7.7\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files (x86)\ICQ7.7\ICQ.exe
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
O23 - Service: CrossLoop Service (CrossLoopService) - CrossLoop Inc - C:\Users\Sema\AppData\Local\CrossLoop\CrossLoopService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: KMService - Unknown owner - C:\windows\system32\srvany.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\windows\system32\nvvsvc.exe (file missing)
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe
O23 - Service: PnkBstrA - Unknown owner - C:\windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TightVNC Server (tvnserver) - GlavSoft LLC. - C:\Users\Sema\AppData\Local\CrossLoop\tvnserver.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 13576 bytes
======Scheduled tasks folder======
C:\windows\tasks\Adobe Flash Player Updater.job
C:\windows\tasks\GoogleUpdateTaskMachineCore.job
C:\windows\tasks\GoogleUpdateTaskMachineUA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Sema\AppData\Roaming\Mozilla\Firefox\Profiles\ekkcdbr4.default
prefs.js - "browser.search.suggest.enabled" - false
prefs.js - "browser.startup.homepage" - "http://www.google.cz/"
prefs.js - "extensions.enabledItems" - "{0b457cAA-602d-484a-8fe7-c1d894a011ba}:0.88, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.117 Plugin
"Path"=C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.25.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\windows\SysWOW64\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
C:\Program Files (x86)\Mozilla Firefox\extensions\
{AB2CE124-6272-4b12-94A9-7303C7397BD1}
{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
C:\Program Files (x86)\Mozilla Firefox\plugins\
nppdf32.dll
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
mall-cz.xml
C:\Users\Sema\AppData\Roaming\Mozilla\Firefox\Profiles\ekkcdbr4.default\extensions\
battlefieldplay4free@ea.com
{0b457cAA-602d-484a-8fe7-c1d894a011ba}
C:\Users\Sema\AppData\Roaming\Mozilla\Firefox\Profiles\ekkcdbr4.default\searchplugins\
daemon-search.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2012-08-16 4171424]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-10-08 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-11-22 1242504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-12-21 561552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-10-08 171944]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2010-03-03 284696]
"331BigDog"=C:\Program Files (x86)\USB Camera\VM331_STI.EXE [2010-01-15 536576]
"UCam_Menu"=C:\Program Files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe [2009-05-19 222504]
"UpdateP2GShortCut"=C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [2008-12-03 218408]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"NeroFilterCheck"=C:\windows\system32\NeroCheck.exe [2004-02-13 155648]
"avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2013-11-26 683576]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-03-12 253816]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Pando Media Booster"=C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [2013-01-09 3093624]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files (x86)\Lenovo\Bluetooth Software\BTTray.exe
Moveslink for Movestick Mini.lnk - C:\windows\Installer\{4D036ACA-DFDF-41B2-A680-E0D736F3E947}\_22A9010B636AF7A61D8E03.exe
C:\Users\Sema\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Sema\AppData\Roaming\Dropbox\bin\Dropbox.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2012-08-16 4171424]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=3
"EnableLUA"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\SysWOW64\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"msacm.clmp3enc"=C:\PROGRA~2\Lenovo\Power2Go\CLMP3Enc.ACM
"msacm.siren"=sirenacm.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2013-12-10 13:21:33 ----D---- C:\Program Files (x86)\trend micro
2013-12-10 13:21:32 ----D---- C:\rsit
2013-12-10 11:40:58 ----D---- C:\windows\agen
2013-12-10 11:40:48 ----D---- C:\windows\smyf
2013-12-10 11:40:32 ----D---- C:\windows\urox
2013-12-10 11:40:22 ----D---- C:\windows\owaz
2013-12-10 11:40:11 ----D---- C:\windows\ivwr
2013-12-10 11:39:56 ----D---- C:\windows\ozpk
2013-12-10 11:39:45 ----D---- C:\windows\okrh
2013-12-10 11:39:30 ----D---- C:\windows\rmew
2013-12-10 11:39:25 ----D---- C:\windows\oxur
2013-12-10 11:39:04 ----D---- C:\windows\tpij
2013-12-10 11:38:49 ----D---- C:\windows\kdip
2013-12-10 11:38:39 ----D---- C:\windows\urux
2013-12-10 11:38:13 ----D---- C:\windows\wtik
2013-12-10 11:37:57 ----D---- C:\windows\ybsh
2013-12-10 11:37:32 ----D---- C:\windows\fxwg
2013-12-10 11:36:56 ----D---- C:\windows\dbom
2013-12-10 11:36:40 ----D---- C:\windows\wsib
2013-12-10 11:36:30 ----D---- C:\windows\rsok
2013-12-10 11:36:04 ----D---- C:\windows\ntob
2013-12-10 11:35:38 ----D---- C:\windows\ojjd
2013-12-10 11:34:47 ----D---- C:\windows\ipwx
2013-12-10 11:34:42 ----D---- C:\windows\avid
2013-12-10 11:34:31 ----D---- C:\windows\itym
2013-12-10 11:34:21 ----D---- C:\windows\ucug
2013-12-10 11:34:16 ----D---- C:\windows\nzek
2013-12-10 11:34:10 ----D---- C:\windows\jsot
2013-12-10 11:33:34 ----D---- C:\windows\ykyq
2013-12-10 11:33:19 ----D---- C:\windows\kwiw
2013-12-10 11:33:04 ----D---- C:\windows\orux
2013-12-10 11:32:53 ----D---- C:\windows\zfyt
2013-12-10 11:32:27 ----D---- C:\windows\uces
2013-12-10 11:32:22 ----D---- C:\windows\xmoz
2013-12-10 11:32:07 ----D---- C:\windows\ocph
2013-12-10 11:32:02 ----D---- C:\windows\ebek
2013-12-10 11:31:57 ----D---- C:\windows\icfc
2013-12-10 11:31:31 ----D---- C:\windows\oqep
2013-12-10 11:31:00 ----D---- C:\windows\snap
2013-12-10 11:30:24 ----D---- C:\windows\dvev
2013-12-10 11:29:43 ----D---- C:\windows\mbib
2013-12-10 11:29:23 ----D---- C:\windows\axap
2013-12-10 11:29:07 ----D---- C:\windows\orud
2013-12-10 11:28:37 ----D---- C:\windows\ojoj
2013-12-10 11:28:32 ----D---- C:\windows\yzih
2013-12-10 11:28:06 ----D---- C:\windows\avov
2013-12-10 11:27:51 ----D---- C:\windows\ejap
2013-12-10 11:27:45 ----D---- C:\windows\whys
2013-12-10 11:27:04 ----D---- C:\windows\lgep
2013-12-10 11:26:59 ----D---- C:\windows\igkj
2013-12-10 11:26:41 ----D---- C:\windows\nzlf
2013-12-10 11:26:19 ----D---- C:\windows\fdig
2013-12-10 11:26:14 ----D---- C:\windows\esut
2013-12-10 11:25:49 ----D---- C:\windows\tmmc
2013-12-10 11:25:18 ----D---- C:\windows\qzjt
2013-12-10 11:25:12 ----D---- C:\windows\ogsn
2013-12-10 11:24:39 ----D---- C:\windows\gxox
2013-12-10 11:23:53 ----D---- C:\windows\arod
2013-12-10 11:23:47 ----D---- C:\windows\insg
2013-12-10 11:23:23 ----D---- C:\windows\enon
2013-12-10 11:23:06 ----D---- C:\windows\ahfw
2013-12-10 11:23:00 ----D---- C:\windows\wcak
2013-12-10 11:22:47 ----D---- C:\windows\acyf
2013-12-10 11:22:41 ----D---- C:\windows\shaw
2013-12-10 11:22:20 ----D---- C:\windows\efdw
2013-12-10 11:21:28 ----D---- C:\windows\aqfj
2013-12-10 11:21:13 ----D---- C:\windows\yhyb
2013-12-10 11:20:52 ----D---- C:\windows\gqeg
2013-12-10 11:19:56 ----D---- C:\windows\atyk
2013-12-10 11:19:45 ----D---- C:\windows\erod
2013-12-10 11:19:09 ----D---- C:\windows\exej
2013-12-10 11:18:59 ----D---- C:\windows\igih
2013-12-10 11:18:49 ----D---- C:\windows\otoh
2013-12-10 11:18:43 ----D---- C:\windows\krbg
2013-12-10 11:18:27 ----D---- C:\windows\rfow
2013-12-10 11:18:16 ----D---- C:\windows\lhdt
2013-12-10 11:18:01 ----D---- C:\windows\tbks
2013-12-10 11:17:51 ----D---- C:\windows\ibys
2013-12-10 11:17:45 ----D---- C:\windows\zjap
2013-12-10 11:17:40 ----D---- C:\windows\lhot
2013-12-10 11:17:30 ----D---- C:\windows\adon
2013-12-10 11:17:20 ----D---- C:\windows\osum
2013-12-10 11:16:49 ----D---- C:\windows\ipir
2013-12-10 11:16:18 ----D---- C:\windows\qkow
2013-12-10 11:16:13 ----D---- C:\windows\ltuz
2013-12-10 11:16:08 ----D---- C:\windows\nhum
2013-12-10 11:15:58 ----D---- C:\windows\alaj
2013-12-10 11:15:32 ----D---- C:\windows\ezut
2013-12-10 11:15:27 ----D---- C:\windows\snyl
2013-12-10 11:15:01 ----D---- C:\windows\owug
2013-12-10 11:14:46 ----D---- C:\windows\axal
2013-12-10 11:13:54 ----D---- C:\windows\vded
2013-12-10 11:13:29 ----D---- C:\windows\udux
2013-12-10 11:13:18 ----D---- C:\windows\mkat
2013-12-10 11:12:11 ----D---- C:\windows\yqcd
2013-12-10 11:11:20 ----D---- C:\windows\izys
2013-12-10 11:11:04 ----D---- C:\windows\uxur
2013-12-10 11:10:49 ----D---- C:\windows\yxif
2013-12-10 11:10:44 ----D---- C:\windows\owjm
2013-12-10 11:10:38 ----D---- C:\windows\mgyr
2013-12-10 11:09:22 ----D---- C:\windows\ujej
2013-12-10 11:08:45 ----D---- C:\windows\ibiw
2013-12-10 11:08:35 ----D---- C:\windows\ahys
2013-12-10 11:08:25 ----D---- C:\windows\etyc
2013-12-10 11:08:03 ----D---- C:\windows\ocoh
2013-12-10 11:07:47 ----D---- C:\windows\edun
2013-12-10 11:07:37 ----D---- C:\windows\unqn
2013-12-10 11:07:16 ----D---- C:\windows\uguc
2013-12-10 11:07:01 ----D---- C:\windows\uxrd
2013-12-10 11:06:55 ----D---- C:\windows\qfuh
2013-12-10 11:06:45 ----D---- C:\windows\lbuc
2013-12-10 11:06:40 ----D---- C:\windows\ezrf
2013-12-10 11:06:35 ----D---- C:\windows\cqin
2013-12-10 11:06:30 ----D---- C:\windows\jdun
2013-12-10 11:06:25 ----D---- C:\windows\ywbz
2013-12-10 11:05:49 ----D---- C:\windows\eqdg
2013-12-10 11:05:44 ----D---- C:\windows\yqwn
2013-12-10 11:05:28 ----D---- C:\windows\ehrc
2013-12-10 11:05:23 ----D---- C:\windows\ebut
2013-12-10 11:04:52 ----D---- C:\windows\bsas
2013-12-10 11:04:22 ----D---- C:\windows\udun
2013-12-10 11:03:35 ----D---- C:\windows\dmoz
2013-12-10 11:03:30 ----D---- C:\windows\atav
2013-12-10 11:03:10 ----D---- C:\windows\usqk
2013-12-10 11:02:59 ----D---- C:\windows\yvar
2013-12-10 11:02:15 ----D---- C:\windows\zmyc
2013-12-10 11:01:54 ----D---- C:\windows\ijap
2013-12-10 11:01:23 ----D---- C:\windows\mxag
2013-12-10 11:00:53 ----D---- C:\windows\abts
2013-12-10 11:00:12 ----D---- C:\windows\ojex
2013-12-10 10:59:56 ----D---- C:\windows\hlyr
2013-12-10 10:59:46 ----D---- C:\windows\yxcl
2013-12-10 10:58:55 ----D---- C:\windows\uceb
2013-12-10 10:58:09 ----D---- C:\windows\utvs
2013-12-10 10:58:04 ----D---- C:\windows\hnap
2013-12-10 10:57:48 ----D---- C:\windows\orrn
2013-12-10 10:57:22 ----D---- C:\windows\ilyn
2013-12-10 10:57:17 ----D---- C:\windows\kpbj
2013-12-10 10:56:46 ----D---- C:\windows\hvyj
2013-12-10 10:56:36 ----D---- C:\windows\ufns
2013-12-10 10:56:31 ----D---- C:\windows\engn
2013-12-10 10:56:05 ----D---- C:\windows\ufrz
2013-12-10 10:55:59 ----D---- C:\windows\ocjw
2013-12-10 10:55:44 ----D---- C:\windows\ymic
2013-12-10 10:55:34 ----D---- C:\windows\bwab
2013-12-10 10:55:28 ----D---- C:\windows\pjqd
2013-12-10 10:55:23 ----D---- C:\windows\qder
2013-12-10 10:55:18 ----D---- C:\windows\fzth
2013-12-10 10:55:08 ----D---- C:\windows\szib
2013-12-10 10:55:03 ----D---- C:\windows\hwyw
2013-12-10 10:54:42 ----D---- C:\windows\ondj
2013-12-10 10:54:32 ----D---- C:\windows\iqfj
2013-12-10 10:54:16 ----D---- C:\windows\bhaz
2013-12-10 10:53:40 ----D---- C:\windows\lfos
2013-12-10 10:53:35 ----D---- C:\windows\ivix
2013-12-10 10:53:25 ----D---- C:\windows\ewgk
2013-12-10 10:53:15 ----D---- C:\windows\okuf
2013-12-10 10:53:09 ----D---- C:\windows\ynkq
2013-12-10 10:53:04 ----D---- C:\windows\ugvq
2013-12-10 10:52:54 ----D---- C:\windows\vqol
2013-12-10 10:52:49 ----D---- C:\windows\osot
2013-12-10 10:52:39 ----D---- C:\windows\efgs
2013-12-10 10:52:33 ----D---- C:\windows\xkuz
2013-12-10 10:52:13 ----D---- C:\windows\tdyv
2013-12-10 10:51:57 ----D---- C:\windows\axag
2013-12-10 10:51:16 ----D---- C:\windows\wsiw
2013-12-10 10:51:11 ----D---- C:\windows\oxej
2013-12-10 10:51:01 ----D---- C:\windows\ewpt
2013-12-10 10:50:30 ----D---- C:\windows\ivhn
2013-12-10 10:50:24 ----D---- C:\windows\tlij
2013-12-10 10:50:19 ----D---- C:\windows\ekuz
2013-12-10 10:49:43 ----D---- C:\windows\ulgq
2013-12-10 10:49:27 ----D---- C:\windows\gzok
2013-12-10 10:49:06 ----D---- C:\windows\qmit
2013-12-10 10:48:50 ----D---- C:\windows\ehef
2013-12-10 10:48:45 ----D---- C:\windows\esnf
2013-12-10 10:48:40 ----D---- C:\windows\idap
2013-12-10 10:48:35 ----D---- C:\windows\rkqs
2013-12-10 10:48:29 ----D---- C:\windows\ixal
2013-12-10 10:48:19 ----D---- C:\windows\acym
2013-12-10 10:48:09 ----D---- C:\windows\ithk
2013-12-10 10:48:04 ----D---- C:\windows\udex
2013-12-10 10:47:43 ----D---- C:\windows\ebqt
2013-12-10 10:47:38 ----D---- C:\windows\udon
2013-12-10 10:47:33 ----D---- C:\windows\zbih
2013-12-10 10:47:28 ----D---- C:\windows\ifkk
2013-12-10 10:47:22 ----D---- C:\windows\ecus
2013-12-10 10:47:07 ----D---- C:\windows\unrs
2013-12-10 10:47:02 ----D---- C:\windows\odjj
2013-12-10 10:46:46 ----D---- C:\windows\xpug
2013-12-10 10:46:35 ----D---- C:\windows\ylul
2013-12-10 10:46:25 ----D---- C:\windows\qwof
2013-12-10 10:45:49 ----D---- C:\windows\ekes
2013-12-10 10:45:43 ----D---- C:\windows\ofos
2013-12-10 10:45:38 ----D---- C:\windows\ypyr
2013-12-10 10:45:23 ----D---- C:\windows\aqbx
2013-12-10 10:45:12 ----D---- C:\windows\ymqb
2013-12-10 10:44:57 ----D---- C:\windows\emgz
2013-12-10 10:44:16 ----D---- C:\windows\cqyn
2013-12-10 10:44:00 ----D---- C:\windows\fxil
2013-12-10 10:43:55 ----D---- C:\windows\ycmm
2013-12-10 10:43:24 ----D---- C:\windows\nqoq
2013-12-10 10:43:08 ----D---- C:\windows\ybah
2013-12-10 10:43:03 ----D---- C:\windows\kftc
2013-12-10 10:42:47 ----D---- C:\windows\ivad
2013-12-10 10:42:37 ----D---- C:\windows\eqep
2013-12-10 10:42:11 ----D---- C:\windows\urov
2013-12-10 10:42:06 ----D---- C:\windows\kqhn
2013-12-10 10:42:00 ----D---- C:\windows\esxt
2013-12-10 10:41:55 ----D---- C:\windows\hnav
2013-12-10 10:41:45 ----D---- C:\windows\tkik
2013-12-10 10:41:40 ----D---- C:\windows\ahwh
2013-12-10 10:40:58 ----D---- C:\windows\ocqw
2013-12-10 10:40:07 ----D---- C:\windows\qkez
2013-12-10 10:39:41 ----D---- C:\windows\orvd
2013-12-10 10:39:35 ----D---- C:\windows\ybiw
2013-12-10 10:39:30 ----D---- C:\windows\egul
2013-12-10 10:39:20 ----D---- C:\windows\twtw
2013-12-10 10:38:54 ----D---- C:\windows\bfaf
2013-12-10 10:38:23 ----D---- C:\windows\xfuw
2013-12-10 10:38:03 ----D---- C:\windows\uzlf
2013-12-10 10:37:47 ----D---- C:\windows\iciq
2013-12-10 10:36:50 ----D---- C:\windows\ivid
2013-12-10 10:36:24 ----D---- C:\windows\yleq
2013-12-10 10:36:19 ----D---- C:\windows\ublt
2013-12-10 09:06:51 ----D---- C:\Program Files (x86)\ESET
2013-12-10 08:28:46 ----D---- C:\windows\ehkh
2013-12-10 08:28:24 ----D---- C:\windows\uvog
2013-12-10 08:28:12 ----D---- C:\windows\atim
2013-12-10 08:27:41 ----D---- C:\windows\vsof
2013-12-09 21:01:30 ----D---- C:\windows\ewvf
2013-12-09 21:01:25 ----D---- C:\windows\ypmj
2013-12-09 21:01:05 ----D---- C:\windows\mjiq
2013-12-09 21:00:59 ----D---- C:\windows\dwof
2013-12-09 21:00:49 ----D---- C:\windows\yqfx
2013-12-09 21:00:44 ----D---- C:\windows\idbp
2013-12-09 21:00:19 ----D---- C:\windows\uzdc
2013-12-09 20:59:53 ----D---- C:\windows\awcs
2013-12-09 20:59:43 ----D---- C:\windows\ijyq
2013-12-09 20:58:57 ----D---- C:\windows\gveq
2013-12-09 20:58:47 ----D---- C:\windows\emub
2013-12-09 20:58:26 ----D---- C:\windows\itwc
2013-12-09 20:58:01 ----D---- C:\windows\ojed
2013-12-09 20:57:46 ----D---- C:\windows\ukew
2013-12-09 20:57:35 ----D---- C:\windows\lfrz
2013-12-09 20:57:20 ----D---- C:\windows\ahah
2013-12-09 20:56:39 ----D---- C:\windows\wqmn
2013-12-09 20:56:34 ----D---- C:\windows\utew
2013-12-09 20:56:24 ----D---- C:\windows\jcqw
2013-12-09 20:56:19 ----D---- C:\windows\inig
2013-12-09 20:56:14 ----D---- C:\windows\htac
2013-12-09 20:55:58 ----D---- C:\windows\unel
2013-12-09 20:55:33 ----D---- C:\windows\evep
2013-12-09 20:55:18 ----D---- C:\windows\qcus
2013-12-09 20:55:12 ----D---- C:\windows\ezof
2013-12-09 20:55:07 ----D---- C:\windows\ivaj
2013-12-09 20:55:02 ----D---- C:\windows\awis
2013-12-09 20:54:57 ----D---- C:\windows\ggul
2013-12-09 20:54:47 ----D---- C:\windows\abkw
2013-12-09 20:54:42 ----D---- C:\windows\uxgn
2013-12-09 20:54:32 ----D---- C:\windows\dlog
2013-12-09 20:54:27 ----D---- C:\windows\hbiw
2013-12-09 20:54:11 ----D---- C:\windows\yqtd
2013-12-09 20:53:56 ----D---- C:\windows\jxer
2013-12-09 20:53:46 ----D---- C:\windows\akam
2013-12-09 20:53:35 ----D---- C:\windows\yzab
2013-12-09 20:53:30 ----D---- C:\windows\eroj
2013-12-09 20:53:20 ----D---- C:\windows\ykam
2013-12-09 20:53:05 ----D---- C:\windows\shyb
2013-12-09 20:52:44 ----D---- C:\windows\ogug
2013-12-09 20:52:29 ----D---- C:\windows\hdyp
2013-12-09 20:52:19 ----D---- C:\windows\fpar
2013-12-09 20:51:53 ----D---- C:\windows\ezum
2013-12-09 20:51:43 ----D---- C:\windows\tmyk
2013-12-09 20:51:18 ----D---- C:\windows\imsf
2013-12-09 20:51:13 ----D---- C:\windows\tsyb
2013-12-09 20:50:52 ----D---- C:\windows\yriv
2013-12-09 20:50:16 ----D---- C:\windows\wncl
2013-12-09 20:49:51 ----D---- C:\windows\rzpr
2013-12-09 20:49:20 ----D---- C:\windows\onrr
2013-12-09 20:48:55 ----D---- C:\windows\mtyc
2013-12-09 20:48:14 ----D---- C:\windows\umrs
2013-12-09 20:48:04 ----D---- C:\windows\spaj
2013-12-09 20:47:54 ----D---- C:\windows\htim
2013-12-09 20:47:18 ----D---- C:\windows\ajig
2013-12-09 20:46:57 ----D---- C:\windows\yrsp
2013-12-09 20:46:52 ----D---- C:\windows\dset
2013-12-09 20:46:42 ----D---- C:\windows\bcyc
2013-12-09 20:46:32 ----D---- C:\windows\ovep
2013-12-09 20:46:06 ----D---- C:\windows\xnod
2013-12-09 20:45:41 ----D---- C:\windows\xsef
2013-12-09 20:45:36 ----D---- C:\windows\ykcc
2013-12-09 20:45:31 ----D---- C:\windows\ysiz
2013-12-09 20:45:21 ----D---- C:\windows\kniq
2013-12-09 20:45:00 ----D---- C:\windows\oxrd
2013-12-09 20:44:55 ----D---- C:\windows\azws
2013-12-09 20:44:35 ----D---- C:\windows\idil
2013-12-09 20:44:30 ----D---- C:\windows\ylyn
2013-12-09 20:44:19 ----D---- C:\windows\olol
2013-12-09 20:44:14 ----D---- C:\windows\jvov
2013-12-09 20:44:09 ----D---- C:\windows\pjoj
2013-12-09 20:43:38 ----D---- C:\windows\ihkh
2013-12-09 20:43:33 ----D---- C:\windows\nduj
2013-12-09 20:43:23 ----D---- C:\windows\glqp
2013-12-09 20:43:13 ----D---- C:\windows\uxed
2013-12-09 20:43:08 ----D---- C:\windows\elvv
2013-12-09 20:43:03 ----D---- C:\windows\amtt
2013-12-09 20:42:53 ----D---- C:\windows\alar
2013-12-09 20:42:37 ----D---- C:\windows\ukeb
2013-12-09 20:42:22 ----D---- C:\windows\oxuj
2013-12-09 20:42:12 ----D---- C:\windows\oveg
2013-12-09 20:41:41 ----D---- C:\windows\lcnw
2013-12-09 20:41:16 ----D---- C:\windows\rjuj
2013-12-09 20:41:05 ----D---- C:\windows\edoq
2013-12-09 20:40:55 ----D---- C:\windows\epjl
2013-12-09 20:40:35 ----D---- C:\windows\ecuz
2013-12-09 20:40:25 ----D---- C:\windows\sshh
2013-12-09 20:40:19 ----D---- C:\windows\hhiz
2013-12-09 20:40:04 ----D---- C:\windows\yxiq
2013-12-09 20:39:33 ----D---- C:\windows\ydkl
2013-12-09 20:39:28 ----D---- C:\windows\iqsd
2013-12-09 20:39:23 ----D---- C:\windows\xcow
2013-12-09 20:39:18 ----D---- C:\windows\inav
2013-12-09 20:38:37 ----D---- C:\windows\epql
2013-12-09 20:38:22 ----D---- C:\windows\djud
2013-12-09 20:37:57 ----D---- C:\windows\awts
2013-12-09 20:37:46 ----D---- C:\windows\zsyh
2013-12-09 20:37:41 ----D---- C:\windows\opql
2013-12-09 20:37:05 ----D---- C:\windows\hsyw
2013-12-09 20:36:45 ----D---- C:\windows\ehov
2013-12-09 20:36:35 ----D---- C:\windows\ufeb
2013-12-09 20:36:25 ----D---- C:\windows\ixyv
2013-12-09 20:36:20 ----D---- C:\windows\ivyn
2013-12-09 20:36:04 ----D---- C:\windows\amfk
2013-12-09 20:35:54 ----D---- C:\windows\dlop
2013-12-09 20:35:49 ----D---- C:\windows\acyk
2013-12-09 20:35:44 ----D---- C:\windows\vrex
2013-12-09 20:35:29 ----D---- C:\windows\exdx
2013-12-09 20:35:18 ----D---- C:\windows\efus
2013-12-09 20:35:08 ----D---- C:\windows\ydig
2013-12-09 20:34:58 ----D---- C:\windows\yvbx
2013-12-09 20:34:22 ----D---- C:\windows\amak
2013-12-09 20:34:17 ----D---- C:\windows\edxn
2013-12-09 20:34:07 ----D---- C:\windows\obgc
2013-12-09 20:33:52 ----D---- C:\windows\wtyf
2013-12-09 20:33:46 ----D---- C:\windows\edlx
2013-12-09 20:33:21 ----D---- C:\windows\vven
2013-12-09 20:33:16 ----D---- C:\windows\ttat
2013-12-09 20:33:06 ----D---- C:\windows\abib
2013-12-09 20:32:55 ----D---- C:\windows\arfl
2013-12-09 20:32:50 ----D---- C:\windows\gzot
2013-12-09 20:32:40 ----D---- C:\windows\iktk
2013-12-09 20:32:15 ----D---- C:\windows\cpar
2013-12-09 20:31:54 ----D---- C:\windows\utez
2013-12-09 20:31:49 ----D---- C:\windows\hril
2013-12-09 20:31:44 ----D---- C:\windows\ewok
2013-12-09 20:31:39 ----D---- C:\windows\oxex
2013-12-09 20:31:29 ----D---- C:\windows\uveq
2013-12-09 20:31:13 ----D---- C:\windows\epol
2013-12-09 20:31:08 ----D---- C:\windows\cfym
2013-12-09 20:30:38 ----D---- C:\windows\otuh
2013-12-09 20:30:17 ----D---- C:\windows\ikyf
2013-12-09 20:29:47 ----D---- C:\windows\upol
2013-12-09 20:29:21 ----D---- C:\windows\ypsr
2013-12-09 20:29:01 ----D---- C:\windows\ahtb
2013-12-09 20:28:30 ----D---- C:\windows\gcoh
2013-12-09 20:28:25 ----D---- C:\windows\mdyq
2013-12-09 20:28:20 ----D---- C:\windows\hvij
2013-12-09 20:27:59 ----D---- C:\windows\asib
2013-12-09 20:27:29 ----D---- C:\windows\ocow
2013-12-09 20:27:08 ----D---- C:\windows\yhcr
2013-12-09 20:26:58 ----D---- C:\windows\oxor
2013-12-09 20:26:53 ----D---- C:\windows\qrux
2013-12-09 20:26:43 ----D---- C:\windows\ihas
2013-12-09 20:26:38 ----D---- C:\windows\lqul
2013-12-09 20:26:33 ----D---- C:\windows\pbot
2013-12-09 20:26:22 ----D---- C:\windows\hsab
2013-12-09 20:25:37 ----D---- C:\windows\fwiw
2013-12-09 20:25:31 ----D---- C:\windows\uxgr
2013-12-09 20:25:26 ----D---- C:\windows\ifif
2013-12-09 20:24:56 ----D---- C:\windows\usek
2013-12-09 20:24:51 ----D---- C:\windows\apij
2013-12-09 20:24:40 ----D---- C:\windows\asyh
2013-12-09 20:24:35 ----D---- C:\windows\epeg
2013-12-09 20:24:20 ----D---- C:\windows\ezxk
2013-12-09 20:24:10 ----D---- C:\windows\udap
2013-12-09 20:23:54 ----D---- C:\windows\uvvl
2013-12-09 20:23:14 ----D---- C:\windows\onux
2013-12-09 20:22:58 ----D---- C:\windows\odej
2013-12-09 20:22:17 ----D---- C:\windows\gcob
2013-12-09 20:22:12 ----D---- C:\windows\ecdz
2013-12-09 20:21:57 ----D---- C:\windows\orod
2013-12-09 20:21:52 ----D---- C:\windows\ysyh
2013-12-09 20:21:42 ----D---- C:\windows\aqkn
2013-12-09 20:21:37 ----D---- C:\windows\mdaq
2013-12-09 20:21:31 ----D---- C:\windows\irsp
2013-12-09 20:20:56 ----D---- C:\windows\xjud
2013-12-09 20:20:35 ----D---- C:\windows\esdt
2013-12-09 20:20:15 ----D---- C:\windows\etdh
2013-12-09 20:20:10 ----D---- C:\windows\gqeq
2013-12-09 20:19:55 ----D---- C:\windows\ovoq
2013-12-09 20:19:19 ----D---- C:\windows\eqrj
2013-12-09 20:19:14 ----D---- C:\windows\dpug
2013-12-09 20:18:58 ----D---- C:\windows\pkoh
2013-12-09 20:18:53 ----D---- C:\windows\knaq
2013-12-09 20:18:48 ----D---- C:\windows\nsef
2013-12-09 20:18:38 ----D---- C:\windows\equq
2013-12-09 20:17:06 ----D---- C:\windows\otjz
2013-12-09 20:17:01 ----D---- C:\windows\fjyp
2013-12-09 20:16:10 ----D---- C:\windows\yzyh
2013-12-09 20:15:44 ----D---- C:\windows\ikit
2013-12-09 20:15:39 ----D---- C:\windows\ujur
2013-12-09 20:15:19 ----D---- C:\windows\ihyh
2013-12-09 20:15:09 ----D---- C:\windows\ipad
2013-12-09 20:14:43 ----D---- C:\windows\inyg
2013-12-09 20:14:08 ----D---- C:\windows\rnux
2013-12-09 20:13:57 ----D---- C:\windows\yryg
2013-12-09 20:13:47 ----D---- C:\windows\avyr
2013-12-09 20:13:37 ----D---- C:\windows\osrc
2013-12-09 20:13:01 ----D---- C:\windows\ycfc
2013-12-09 20:12:36 ----D---- C:\windows\aniw
2013-12-09 20:12:31 ----D---- C:\windows\usum
2013-12-09 20:11:55 ----D---- C:\windows\ihiw
2013-12-09 20:11:29 ----D---- C:\windows\ecow
2013-12-09 20:11:04 ----D---- C:\windows\gwec
2013-12-09 20:10:49 ----D---- C:\windows\oguq
2013-12-09 20:10:43 ----D---- C:\windows\xjdr
2013-12-09 20:10:33 ----D---- C:\windows\etow
2013-12-09 20:10:18 ----D---- C:\windows\hbiz
2013-12-09 20:10:13 ----D---- C:\windows\akaf
2013-12-09 20:10:03 ----D---- C:\windows\alin
2013-12-09 20:09:52 ----D---- C:\windows\bdil
2013-12-09 20:09:17 ----D---- C:\windows\jvug
2013-12-09 20:09:12 ----D---- C:\windows\imac
2013-12-09 20:09:06 ----D---- C:\windows\ixiq
2013-12-09 20:08:51 ----D---- C:\windows\uhls
2013-12-09 20:08:46 ----D---- C:\windows\ptoh
2013-12-09 20:08:21 ----D---- C:\windows\ejed
2013-12-09 20:08:15 ----D---- C:\windows\mbab
2013-12-09 20:08:05 ----D---- C:\windows\umob
2013-12-09 20:07:30 ----D---- C:\windows\lgeg
2013-12-09 20:07:24 ----D---- C:\windows\ycck
2013-12-09 20:07:14 ----D---- C:\windows\nkgw
2013-12-09 20:07:09 ----D---- C:\windows\ixyp
2013-12-09 20:06:49 ----D---- C:\windows\ucos
2013-12-09 20:06:44 ----D---- C:\windows\ycig
2013-12-09 20:06:18 ----D---- C:\windows\vkuh
2013-12-09 20:06:13 ----D---- C:\windows\efes
2013-12-09 20:06:08 ----D---- C:\windows\azok
2013-12-09 20:05:58 ----D---- C:\windows\icsk
2013-12-09 20:05:53 ----D---- C:\windows\exux
2013-12-09 20:05:47 ----D---- C:\windows\abys
2013-12-09 20:05:42 ----D---- C:\windows\lluq
2013-12-09 20:05:27 ----D---- C:\windows\yhys
2013-12-09 20:05:17 ----D---- C:\windows\uruj
2013-12-09 20:05:12 ----D---- C:\windows\yqij
2013-12-09 20:04:51 ----D---- C:\windows\dtob
2013-12-09 20:03:50 ----D---- C:\windows\ojrj
2013-12-09 20:03:40 ----D---- C:\windows\gvuq
2013-12-09 20:03:35 ----D---- C:\windows\ywiz
2013-12-09 20:03:25 ----D---- C:\windows\msyz
2013-12-09 20:03:19 ----D---- C:\windows\osem
2013-12-09 20:02:59 ----D---- C:\windows\uwvf
2013-12-09 20:02:44 ----D---- C:\windows\ubqm
2013-12-09 20:02:28 ----D---- C:\windows\avyx
2013-12-09 20:02:13 ----D---- C:\windows\evoq
2013-12-09 20:02:03 ----D---- C:\windows\ahiz
2013-12-09 20:01:53 ----D---- C:\windows\yvix
2013-12-09 20:01:37 ----D---- C:\windows\iqix
2013-12-09 20:00:57 ----D---- C:\windows\afyf
2013-12-09 20:00:46 ----D---- C:\windows\zhis
2013-12-09 20:00:31 ----D---- C:\windows\ufoz
2013-12-09 20:00:05 ----D---- C:\windows\etes
2013-12-09 20:00:00 ----D---- C:\windows\sxyq
2013-12-09 19:59:40 ----D---- C:\windows\anil
2013-12-09 19:59:35 ----D---- C:\windows\ilwd
2013-12-09 19:59:20 ----D---- C:\windows\slyj
2013-12-09 19:59:09 ----D---- C:\windows\uzof
2013-12-09 19:59:04 ----D---- C:\windows\dzuk
2013-12-09 19:58:59 ----D---- C:\windows\ypcr
2013-12-09 19:58:34 ----D---- C:\windows\jvol
2013-12-09 19:58:29 ----D---- C:\windows\yfyt
2013-12-09 19:58:08 ----D---- C:\windows\ihib
2013-12-09 19:57:48 ----D---- C:\windows\ugug
2013-12-09 19:57:27 ----D---- C:\windows\upeq
2013-12-09 19:57:07 ----D---- C:\windows\ifwk
2013-12-09 19:56:57 ----D---- C:\windows\asab
2013-12-09 19:56:52 ----D---- C:\windows\bthc
2013-12-09 19:56:31 ----D---- C:\windows\oxod
2013-12-09 19:56:26 ----D---- C:\windows\awwb
2013-12-09 19:56:21 ----D---- C:\windows\ellg
2013-12-09 19:55:35 ----D---- C:\windows\ocob
2013-12-09 19:55:09 ----D---- C:\windows\agaj
2013-12-09 19:54:54 ----D---- C:\windows\yvad
2013-12-09 19:54:44 ----D---- C:\windows\wryl
2013-12-09 19:53:43 ----D---- C:\windows\ykyt
2013-12-09 19:53:22 ----D---- C:\windows\elol
2013-12-09 19:53:07 ----D---- C:\windows\kpix
2013-12-09 19:53:02 ----D---- C:\windows\owet
2013-12-09 19:52:57 ----D---- C:\windows\efuh
2013-12-09 19:52:11 ----D---- C:\windows\obqm
2013-12-09 19:51:35 ----D---- C:\windows\wwis
2013-12-09 19:51:30 ----D---- C:\windows\ycym
2013-12-09 19:51:25 ----D---- C:\windows\ejex
2013-12-09 19:51:10 ----D---- C:\windows\uxer
2013-12-09 19:51:05 ----D---- C:\windows\khiz
2013-12-09 19:50:49 ----D---- C:\windows\ojux
2013-12-09 19:50:44 ----D---- C:\windows\ywaw
2013-12-09 19:50:34 ----D---- C:\windows\ifft
2013-12-09 19:49:58 ----D---- C:\windows\evdl
2013-12-09 19:49:48 ----D---- C:\windows\yscw
2013-12-09 19:49:43 ----D---- C:\windows\uljv
2013-12-09 19:49:28 ----D---- C:\windows\awah
2013-12-09 19:49:23 ----D---- C:\windows\awys
2013-12-09 19:49:17 ----D---- C:\windows\opeg
2013-12-09 19:49:12 ----D---- C:\windows\zkyf
2013-12-09 19:49:07 ----D---- C:\windows\oron
2013-12-09 19:49:02 ----D---- C:\windows\bjtl
2013-12-09 19:48:52 ----D---- C:\windows\ylan
2013-12-09 19:48:31 ----D---- C:\windows\odod
2013-12-09 19:48:11 ----D---- C:\windows\idag
2013-12-09 19:47:51 ----D---- C:\windows\llel
2013-12-09 19:47:00 ----D---- C:\windows\klij
2013-12-09 19:46:44 ----D---- C:\windows\ucgb
2013-12-09 19:46:39 ----D---- C:\windows\ecoz
2013-12-09 19:46:29 ----D---- C:\windows\urun
2013-12-09 19:46:19 ----D---- C:\windows\ojod
2013-12-09 19:46:09 ----D---- C:\windows\igyr
2013-12-09 19:45:53 ----D---- C:\windows\jnor
2013-12-09 19:45:43 ----D---- C:\windows\epup
2013-12-09 19:45:33 ----D---- C:\windows\ipax
2013-12-09 19:45:28 ----D---- C:\windows\pmeh
2013-12-09 19:45:12 ----D---- C:\windows\axil
2013-12-09 19:44:57 ----D---- C:\windows\hhyh
2013-12-09 19:44:42 ----D---- C:\windows\ukgw
2013-12-09 19:44:37 ----D---- C:\windows\yjfq
2013-12-09 19:44:21 ----D---- C:\windows\bdag
2013-12-09 19:44:16 ----D---- C:\windows\mbem
2013-12-09 19:44:06 ----D---- C:\windows\jjon
2013-12-09 19:44:01 ----D---- C:\windows\wwah
2013-12-09 19:43:56 ----D---- C:\windows\nzok
2013-12-09 19:43:25 ----D---- C:\windows\agsr
2013-12-09 19:43:15 ----D---- C:\windows\gsoc
2013-12-09 19:43:05 ----D---- C:\windows\uqqv
2013-12-09 19:43:00 ----D---- C:\windows\attm
2013-12-09 19:42:49 ----D---- C:\windows\ahhs
2013-12-09 19:42:39 ----D---- C:\windows\uxex
2013-12-09 19:42:29 ----D---- C:\windows\yjyq
2013-12-09 19:42:14 ----D---- C:\windows\ibhb
2013-12-09 19:42:09 ----D---- C:\windows\abmb
2013-12-09 19:41:53 ----D---- C:\windows\obok
2013-12-09 19:41:48 ----D---- C:\windows\uleg
2013-12-09 19:41:43 ----D---- C:\windows\ugep
2013-12-09 19:41:38 ----D---- C:\windows\iczf
2013-12-09 19:41:33 ----D---- C:\windows\iwyz
2013-12-09 19:41:18 ----D---- C:\windows\dprv
2013-12-09 19:41:07 ----D---- C:\windows\ivyr
2013-12-09 19:40:47 ----D---- C:\windows\ywyh
2013-12-09 19:40:42 ----D---- C:\windows\olqp
2013-12-09 19:40:37 ----D---- C:\windows\rdux
2013-12-09 19:40:32 ----D---- C:\windows\ivyd
2013-12-09 19:40:21 ----D---- C:\windows\otuz
2013-12-09 19:40:06 ----D---- C:\windows\oqeq
2013-12-09 19:40:01 ----D---- C:\windows\nded
2013-12-09 19:39:56 ----D---- C:\windows\isbs
2013-12-09 19:39:51 ----D---- C:\windows\plog
2013-12-09 19:39:41 ----D---- C:\windows\adsq
2013-12-09 19:39:30 ----D---- C:\windows\ygyr
2013-12-09 19:39:15 ----D---- C:\windows\uqup
2013-12-09 19:39:00 ----D---- C:\windows\smac
2013-12-09 19:38:44 ----D---- C:\windows\ynyk
2013-12-09 19:38:39 ----D---- C:\windows\dblt
2013-12-09 19:38:34 ----D---- C:\windows\ecew
2013-12-09 19:38:19 ----D---- C:\windows\mzah
2013-12-09 19:38:04 ----D---- C:\windows\yxip
2013-12-09 19:37:28 ----D---- C:\windows\qpgl
2013-12-09 19:37:13 ----D---- C:\windows\eluq
2013-12-09 19:37:07 ----D---- C:\windows\fcic
2013-12-09 19:36:57 ----D---- C:\windows\ysis
2013-12-09 19:36:52 ----D---- C:\windows\uqol
2013-12-09 19:36:42 ----D---- C:\windows\zhiw
2013-12-09 19:36:37 ----D---- C:\windows\ynwq
2013-12-09 19:36:32 ----D---- C:\windows\ohef
2013-12-09 19:36:22 ----D---- C:\windows\ugeg
2013-12-09 19:36:11 ----D---- C:\windows\xlol
2013-12-09 19:36:01 ----D---- C:\windows\awkb
2013-12-09 19:35:56 ----D---- C:\windows\ogog
2013-12-09 19:35:51 ----D---- C:\windows\hcic
2013-12-09 19:35:46 ----D---- C:\windows\eqod
2013-12-09 19:35:31 ----D---- C:\windows\gpeq
2013-12-09 19:35:25 ----D---- C:\windows\fsis
2013-12-09 19:35:20 ----D---- C:\windows\dpeq
2013-12-09 19:35:05 ----D---- C:\windows\nzef
2013-12-09 19:35:00 ----D---- C:\windows\ywih
2013-12-09 19:34:45 ----D---- C:\windows\ythc
2013-12-09 19:34:29 ----D---- C:\windows\ozlk
2013-12-09 19:33:59 ----D---- C:\windows\ojor
2013-12-09 19:33:33 ----D---- C:\windows\lgup
2013-12-09 19:33:23 ----D---- C:\windows\uhet
2013-12-09 19:33:03 ----D---- C:\windows\okow
2013-12-09 19:32:58 ----D---- C:\windows\gwuk
2013-12-09 19:32:27 ----D---- C:\windows\hdig
2013-12-09 19:32:17 ----D---- C:\windows\enud
2013-12-09 19:32:12 ----D---- C:\windows\wkym
2013-12-09 19:32:01 ----D---- C:\windows\uned
2013-12-09 19:31:56 ----D---- C:\windows\agiz
2013-12-09 19:31:46 ----D---- C:\windows\arip
2013-12-09 19:31:36 ----D---- C:\windows\uwqc
2013-12-09 19:31:31 ----D---- C:\windows\hpir
2013-12-09 19:31:15 ----D---- C:\windows\ygar
2013-12-09 19:30:50 ----D---- C:\windows\aziw
2013-12-09 19:30:45 ----D---- C:\windows\aqyj
2013-12-09 19:30:14 ----D---- C:\windows\ulov
2013-12-09 19:29:54 ----D---- C:\windows\ovuq
2013-12-09 19:29:39 ----D---- C:\windows\yrkv
2013-12-09 19:29:33 ----D---- C:\windows\qbuc
2013-12-09 19:29:13 ----D---- C:\windows\yxal
2013-12-09 19:29:08 ----D---- C:\windows\aniv
2013-12-09 19:28:58 ----D---- C:\windows\mkyc
2013-12-09 19:28:53 ----D---- C:\windows\ukdb
2013-12-09 19:28:48 ----D---- C:\windows\mjal
2013-12-09 19:28:42 ----D---- C:\windows\osok
2013-12-09 19:28:37 ----D---- C:\windows\ddod
2013-12-09 19:28:22 ----D---- C:\windows\edjj
2013-12-09 19:28:17 ----D---- C:\windows\iwhz
2013-12-09 19:28:07 ----D---- C:\windows\ebet
2013-12-09 19:27:57 ----D---- C:\windows\ekew
2013-12-09 19:27:41 ----D---- C:\windows\ezem
2013-12-09 19:27:31 ----D---- C:\windows\okob
2013-12-09 19:27:21 ----D---- C:\windows\ibmb
2013-12-09 19:27:16 ----D---- C:\windows\upep
2013-12-09 19:27:11 ----D---- C:\windows\iwtw
2013-12-09 19:27:05 ----D---- C:\windows\rqup
2013-12-09 19:27:00 ----D---- C:\windows\ehom
2013-12-09 19:26:45 ----D---- C:\windows\tnig
2013-12-09 19:26:35 ----D---- C:\windows\okjs
2013-12-09 19:26:25 ----D---- C:\windows\ehrk
2013-12-09 19:26:20 ----D---- C:\windows\kqyd
2013-12-09 19:26:09 ----D---- C:\windows\kbyb
2013-12-09 19:25:29 ----D---- C:\windows\yfim
2013-12-09 19:25:18 ----D---- C:\windows\imyf
2013-12-09 19:25:13 ----D---- C:\windows\jrox
2013-12-09 19:25:03 ----D---- C:\windows\ynaq
2013-12-09 19:24:48 ----D---- C:\windows\khfs
2013-12-09 19:24:32 ----D---- C:\windows\ysak
2013-12-09 19:24:27 ----D---- C:\windows\fcac
2013-12-09 19:24:17 ----D---- C:\windows\zwaw
2013-12-09 19:24:12 ----D---- C:\windows\yjzl
2013-12-09 19:24:07 ----D---- C:\windows\anaq
2013-12-09 19:23:57 ----D---- C:\windows\isiz
2013-12-09 19:23:41 ----D---- C:\windows\asyw
2013-12-09 19:23:21 ----D---- C:\windows\ocrs
2013-12-09 19:23:06 ----D---- C:\windows\wkak
2013-12-09 19:23:00 ----D---- C:\windows\lrej
2013-12-09 19:22:35 ----D---- C:\windows\efuf
2013-12-09 19:22:15 ----D---- C:\windows\assw
2013-12-09 19:22:04 ----D---- C:\windows\ofuz
2013-12-09 19:21:24 ----D---- C:\windows\lwot
2013-12-09 19:21:18 ----D---- C:\windows\ygir
2013-12-09 19:21:03 ----D---- C:\windows\ugpv
2013-12-09 19:20:58 ----D---- C:\windows\akfm
2013-12-09 19:20:43 ----D---- C:\windows\yhaw
2013-12-09 19:20:22 ----D---- C:\windows\icam
2013-12-09 19:20:17 ----D---- C:\windows\ibaw
2013-12-09 19:20:07 ----D---- C:\windows\qwuk
2013-12-09 19:20:02 ----D---- C:\windows\ugog
2013-12-09 19:19:47 ----D---- C:\windows\jpeg
2013-12-09 19:19:36 ----D---- C:\windows\abah
2013-12-09 19:19:26 ----D---- C:\windows\ybab
2013-12-09 19:18:51 ----D---- C:\windows\qmos
2013-12-09 19:18:45 ----D---- C:\windows\inwq
2013-12-09 19:18:40 ----D---- C:\windows\xzem
2013-12-09 19:18:05 ----D---- C:\windows\lbec
2013-12-09 19:17:59 ----D---- C:\windows\qmus
2013-12-09 19:17:44 ----D---- C:\windows\iwyh
2013-12-09 19:17:39 ----D---- C:\windows\uqnl
2013-12-09 19:17:34 ----D---- C:\windows\bkyt
2013-12-09 19:17:14 ----D---- C:\windows\osec
2013-12-09 19:16:53 ----D---- C:\windows\ufuh
2013-12-09 19:16:48 ----D---- C:\windows\ixiv
2013-12-09 19:16:43 ----D---- C:\windows\epel
2013-12-09 19:16:28 ----D---- C:\windows\etqz
2013-12-09 19:16:22 ----D---- C:\windows\ydav
2013-12-09 19:16:17 ----D---- C:\windows\uhem
2013-12-09 19:16:12 ----D---- C:\windows\iraq
2013-12-09 19:16:07 ----D---- C:\windows\ocdz
2013-12-09 19:15:21 ----D---- C:\windows\avmr
2013-12-09 19:15:11 ----D---- C:\windows\acaf
2013-12-09 19:15:06 ----D---- C:\windows\uvug
2013-12-09 19:15:01 ----D---- C:\windows\upoq
2013-12-09 19:14:35 ----D---- C:\windows\rhof
2013-12-09 19:14:30 ----D---- C:\windows\iqkn
2013-12-09 19:14:25 ----D---- C:\windows\ehot
2013-12-09 19:14:20 ----D---- C:\windows\rmuz
2013-12-09 19:14:10 ----D---- C:\windows\urum
2013-12-09 19:13:54 ----D---- C:\windows\onej
2013-12-09 19:13:44 ----D---- C:\windows\ogoq
2013-12-09 19:13:34 ----D---- C:\windows\axyq
2013-12-09 19:13:24 ----D---- C:\windows\iteh
2013-12-09 19:13:14 ----D---- C:\windows\ibih
2013-12-09 19:13:08 ----D---- C:\windows\jvrg
2013-12-09 19:12:58 ----D---- C:\windows\ilkd
2013-12-09 19:12:38 ----D---- C:\windows\amyf
2013-12-09 19:12:28 ----D---- C:\windows\ubem
2013-12-09 19:12:17 ----D---- C:\windows\qkrz
2013-12-09 19:12:07 ----D---- C:\windows\ynag
2013-12-09 19:11:42 ----D---- C:\windows\yfsm
2013-12-09 19:11:26 ----D---- C:\windows\lluv
2013-12-09 19:11:16 ----D---- C:\windows\whis
2013-12-09 19:10:41 ----D---- C:\windows\elev
2013-12-09 19:10:20 ----D---- C:\windows\jfuw
2013-12-09 19:10:00 ----D---- C:\windows\ecuh
2013-12-09 19:09:44 ----D---- C:\windows\qgel
2013-12-09 19:09:24 ----D---- C:\windows\kxiq
2013-12-09 19:09:19 ----D---- C:\windows\oroj
2013-12-09 19:09:09 ----D---- C:\windows\ybys
2013-12-09 19:09:04 ----D---- C:\windows\ypij
2013-12-09 19:08:23 ----D---- C:\windows\wvyd
2013-12-09 19:08:13 ----D---- C:\windows\uspm
2013-12-09 19:08:02 ----D---- C:\windows\ityf
2013-12-09 19:07:57 ----D---- C:\windows\gjux
2013-12-09 19:07:42 ----D---- C:\windows\aqax
2013-12-09 19:07:37 ----D---- C:\windows\axzg
2013-12-09 19:07:16 ----D---- C:\windows\iqax
2013-12-09 19:06:56 ----D---- C:\windows\okoh
2013-12-09 19:06:51 ----D---- C:\windows\inyl
2013-12-09 19:06:46 ----D---- C:\windows\oqof
2013-12-09 19:06:36 ----D---- C:\windows\ujod
2013-12-09 19:06:30 ----D---- C:\windows\hbaz
2013-12-09 19:06:00 ----D---- C:\windows\ypkx
2013-12-09 19:05:55 ----D---- C:\windows\abaw
2013-12-09 19:05:44 ----D---- C:\windows\adyl
2013-12-09 19:05:34 ----D---- C:\windows\gvul
2013-12-09 19:05:14 ----D---- C:\windows\yxiv
2013-12-09 19:05:09 ----D---- C:\windows\ezom
2013-12-09 19:04:53 ----D---- C:\windows\uvdl
2013-12-09 19:04:33 ----D---- C:\windows\otob
2013-12-09 19:04:23 ----D---- C:\windows\qsxm
2013-12-09 19:04:13 ----D---- C:\windows\azsz
2013-12-09 19:04:08 ----D---- C:\windows\lqev
2013-12-09 19:03:57 ----D---- C:\windows\jjux
2013-12-09 19:03:52 ----D---- C:\windows\eleq
2013-12-09 19:03:47 ----D---- C:\windows\itik
2013-12-09 19:03:42 ----D---- C:\windows\exrd
2013-12-09 19:03:32 ----D---- C:\windows\rfeb
2013-12-09 19:03:22 ----D---- C:\windows\ssys
2013-12-09 19:03:16 ----D---- C:\windows\opog
2013-12-09 19:03:06 ----D---- C:\windows\ewec
2013-12-09 19:02:31 ----D---- C:\windows\ifsm
2013-12-09 19:02:25 ----D---- C:\windows\yhis
2013-12-09 19:02:20 ----D---- C:\windows\ovxg
2013-12-09 19:02:10 ----D---- C:\windows\dteb
2013-12-09 19:02:05 ----D---- C:\windows\irtq
2013-12-09 19:02:00 ----D---- C:\windows\nkos
2013-12-09 19:01:50 ----D---- C:\windows\iqzr
2013-12-09 19:01:34 ----D---- C:\windows\ilax
2013-12-09 19:00:33 ----D---- C:\windows\yqid
2013-12-09 19:00:23 ----D---- C:\windows\fgaj
2013-12-09 18:59:37 ----D---- C:\windows\ewrm
2013-12-09 18:59:27 ----D---- C:\windows\qgeg
2013-12-09 18:59:17 ----D---- C:\windows\onjn
2013-12-09 18:58:46 ----D---- C:\windows\amyt
2013-12-09 18:58:31 ----D---- C:\windows\jwok
2013-12-09 18:58:26 ----D---- C:\windows\aqhx
2013-12-09 18:58:21 ----D---- C:\windows\omgz
2013-12-09 18:58:16 ----D---- C:\windows\ubdk
2013-12-09 18:58:00 ----D---- C:\windows\ppog
2013-12-09 18:57:55 ----D---- C:\windows\ymyt
2013-12-09 18:57:50 ----D---- C:\windows\ecez
2013-12-09 18:57:40 ----D---- C:\windows\ixkp
2013-12-09 18:57:30 ----D---- C:\windows\ukpz
2013-12-09 18:57:24 ----D---- C:\windows\ijyv
2013-12-09 18:57:14 ----D---- C:\windows\ekpz
2013-12-09 18:56:54 ----D---- C:\windows\ihfw
2013-12-09 18:56:39 ----D---- C:\windows\kvij
2013-12-09 18:56:23 ----D---- C:\windows\agan
2013-12-09 18:56:18 ----D---- C:\windows\ufob
2013-12-09 18:55:58 ----D---- C:\windows\ipaj
2013-12-09 18:55:53 ----D---- C:\windows\owjc
2013-12-09 18:55:47 ----D---- C:\windows\ecph
2013-12-09 18:55:37 ----D---- C:\windows\eqov
2013-12-09 18:55:32 ----D---- C:\windows\tkyk
2013-12-09 18:55:27 ----D---- C:\windows\udoj
2013-12-09 18:55:17 ----D---- C:\windows\yfik
2013-12-09 18:55:12 ----D---- C:\windows\oqul
2013-12-09 18:55:02 ----D---- C:\windows\ejgr
2013-12-09 18:54:51 ----D---- C:\windows\idsq
2013-12-09 18:54:31 ----D---- C:\windows\jmos
2013-12-09 18:54:16 ----D---- C:\windows\ipyj
2013-12-09 18:54:11 ----D---- C:\windows\yrag
2013-12-09 18:54:05 ----D---- C:\windows\psjk
2013-12-09 18:54:00 ----D---- C:\windows\afak
2013-12-09 18:53:55 ----D---- C:\windows\upug
2013-12-09 18:53:45 ----D---- C:\windows\isaw
2013-12-09 18:53:35 ----D---- C:\windows\afik
2013-12-09 18:53:14 ----D---- C:\windows\orpr
2013-12-09 18:52:44 ----D---- C:\windows\yqyf
2013-12-09 18:52:39 ----D---- C:\windows\otub
2013-12-09 18:52:34 ----D---- C:\windows\osvt
2013-12-09 18:52:28 ----D---- C:\windows\slad
2013-12-09 18:52:23 ----D---- C:\windows\epop
2013-12-09 18:52:18 ----D---- C:\windows\ifat
2013-12-09 18:52:08 ----D---- C:\windows\emnz
2013-12-09 18:51:58 ----D---- C:\windows\yrwv
2013-12-09 18:51:53 ----D---- C:\windows\kral
2013-12-09 18:51:43 ----D---- C:\windows\qzem
2013-12-09 18:51:37 ----D---- C:\windows\esek
2013-12-09 18:51:27 ----D---- C:\windows\asah
2013-12-09 18:51:17 ----D---- C:\windows\ickt
2013-12-09 18:50:46 ----D---- C:\windows\jcph
2013-12-09 18:50:26 ----D---- C:\windows\upoj
2013-12-09 18:50:11 ----D---- C:\windows\hzaw
2013-12-09 18:49:50 ----D---- C:\windows\jqov
2013-12-09 18:49:04 ----D---- C:\windows\ufpb
2013-12-09 18:48:59 ----D---- C:\windows\tfkc
2013-12-09 18:48:44 ----D---- C:\windows\utej
2013-12-09 18:48:34 ----D---- C:\windows\yqix
2013-12-09 18:48:24 ----D---- C:\windows\ifam
2013-12-09 18:48:18 ----D---- C:\windows\drux
2013-12-09 18:48:08 ----D---- C:\windows\lxun
2013-12-09 18:47:48 ----D---- C:\windows\afim
2013-12-09 18:47:32 ----D---- C:\windows\akat
2013-12-09 18:47:17 ----D---- C:\windows\elpl
2013-12-09 18:46:57 ----D---- C:\windows\cmtf
2013-12-09 18:46:41 ----D---- C:\windows\cbah
2013-12-09 18:46:36 ----D---- C:\windows\owdf
2013-12-09 18:46:31 ----D---- C:\windows\igyx
2013-12-09 18:46:21 ----D---- C:\windows\uzuc
2013-12-09 18:46:16 ----D---- C:\windows\mvyj
2013-12-09 18:45:30 ----D---- C:\windows\ykwf
2013-12-09 18:45:25 ----D---- C:\windows\asas
2013-12-09 18:45:15 ----D---- C:\windows\itit
2013-12-09 18:45:10 ----D---- C:\windows\afsm
2013-12-09 18:45:04 ----D---- C:\windows\onvj
2013-12-09 18:44:59 ----D---- C:\windows\ugdq
2013-12-09 18:44:54 ----D---- C:\windows\adav
2013-12-09 18:44:49 ----D---- C:\windows\hlir
2013-12-09 18:44:39 ----D---- C:\windows\otos
2013-12-09 18:44:29 ----D---- C:\windows\ikif
2013-12-09 18:44:08 ----D---- C:\windows\ymhc
2013-12-09 18:44:03 ----D---- C:\windows\umej
2013-12-09 18:43:58 ----D---- C:\windows\ynap
2013-12-09 18:43:22 ----D---- C:\windows\lren
2013-12-09 18:43:12 ----D---- C:\windows\evev
2013-12-09 18:43:07 ----D---- C:\windows\oded
2013-12-09 18:43:02 ----D---- C:\windows\chas
2013-12-09 18:42:57 ----D---- C:\windows\evug
2013-12-09 18:42:36 ----D---- C:\windows\amit
2013-12-09 18:42:26 ----D---- C:\windows\ywyb
2013-12-09 18:42:21 ----D---- C:\windows\atat
2013-12-09 18:42:16 ----D---- C:\windows\qrud
2013-12-09 18:41:56 ----D---- C:\windows\awzs
2013-12-09 18:41:51 ----D---- C:\windows\egql
2013-12-09 18:41:35 ----D---- C:\windows\axwp
2013-12-09 18:41:15 ----D---- C:\windows\ebok
2013-12-09 18:41:10 ----D---- C:\windows\omuz
2013-12-09 18:41:05 ----D---- C:\windows\avax
2013-12-09 18:41:00 ----D---- C:\windows\ukuh
2013-12-09 18:40:44 ----D---- C:\windows\ivin
2013-12-09 18:40:39 ----D---- C:\windows\lkeb
2013-12-09 18:40:19 ----D---- C:\windows\xset
2013-12-09 18:40:14 ----D---- C:\windows\utus
2013-12-09 18:40:09 ----D---- C:\windows\adag
2013-12-09 18:39:58 ----D---- C:\windows\uror
2013-12-09 18:39:53 ----D---- C:\windows\ulol
2013-12-09 18:39:43 ----D---- C:\windows\pzoc
2013-12-09 18:39:33 ----D---- C:\windows\yxfv
2013-12-09 18:39:02 ----D---- C:\windows\ekuw
2013-12-09 18:38:21 ----D---- C:\windows\afyk
2013-12-09 18:38:06 ----D---- C:\windows\amic
2013-12-09 18:38:01 ----D---- C:\windows\arox
2013-12-09 18:37:46 ----D---- C:\windows\oxoj
2013-12-09 18:37:35 ----D---- C:\windows\imyc
2013-12-09 18:37:30 ----D---- C:\windows\enox
2013-12-09 18:37:20 ----D---- C:\windows\uzef
2013-12-09 18:37:05 ----D---- C:\windows\oset
2013-12-09 18:36:29 ----D---- C:\windows\atkc
2013-12-09 18:36:14 ----D---- C:\windows\epeq
2013-12-09 18:36:09 ----D---- C:\windows\afft
2013-12-09 18:35:59 ----D---- C:\windows\pdgj
2013-12-09 18:35:53 ----D---- C:\windows\tsfh
2013-12-09 18:35:48 ----D---- C:\windows\uner
2013-12-09 18:35:33 ----D---- C:\windows\rzot
2013-12-09 18:35:28 ----D---- C:\windows\omxs
2013-12-09 18:35:13 ----D---- C:\windows\ypyx
2013-12-09 18:35:07 ----D---- C:\windows\mhyb
2013-12-09 18:34:47 ----D---- C:\windows\ocub
2013-12-09 18:34:32 ----D---- C:\windows\ugup
2013-12-09 18:34:22 ----D---- C:\windows\omus
2013-12-09 18:34:16 ----D---- C:\windows\ynip
2013-12-09 18:34:06 ----D---- C:\windows\ehuf
2013-12-09 18:33:56 ----D---- C:\windows\ekeh
2013-12-09 18:33:41 ----D---- C:\windows\ylyj
2013-12-09 18:33:36 ----D---- C:\windows\emez
2013-12-09 18:32:50 ----D---- C:\windows\evvl
2013-12-09 18:32:34 ----D---- C:\windows\uhec
2013-12-09 18:32:29 ----D---- C:\windows\mryp
2013-12-09 18:32:24 ----D---- C:\windows\usok
2013-12-09 18:32:14 ----D---- C:\windows\izah
2013-12-09 18:31:54 ----D---- C:\windows\ydip
2013-12-09 18:31:49 ----D---- C:\windows\ehuk
2013-12-09 18:31:43 ----D---- C:\windows\pguv
2013-12-09 18:31:38 ----D---- C:\windows\ytak
2013-12-09 18:31:18 ----D---- C:\windows\ynal
2013-12-09 18:30:57 ----D---- C:\windows\ezec
2013-12-09 18:30:52 ----D---- C:\windows\ypyd
2013-12-09 18:30:47 ----D---- C:\windows\axav
2013-12-09 18:30:42 ----D---- C:\windows\okos
2013-12-09 18:30:32 ----D---- C:\windows\yqmx
2013-12-09 18:30:01 ----D---- C:\windows\lsok
2013-12-09 18:29:56 ----D---- C:\windows\alan
2013-12-09 18:29:46 ----D---- C:\windows\apyx
2013-12-09 18:29:41 ----D---- C:\windows\ictf
2013-12-09 18:29:36 ----D---- C:\windows\nrex
2013-12-09 18:29:15 ----D---- C:\windows\ikak
2013-12-09 18:29:00 ----D---- C:\windows\ipid
2013-12-09 18:28:55 ----D---- C:\windows\umes
2013-12-09 18:28:45 ----D---- C:\windows\ibab
2013-12-09 18:28:40 ----D---- C:\windows\iriv
2013-12-09 18:28:35 ----D---- C:\windows\ozut
2013-12-09 18:28:30 ----D---- C:\windows\iqhn
2013-12-09 18:28:24 ----D---- C:\windows\rfus
2013-12-09 18:28:14 ----D---- C:\windows\afzc
2013-12-09 18:27:33 ----D---- C:\windows\ihis
2013-12-09 18:27:23 ----D---- C:\windows\ulug
2013-12-09 18:27:13 ----D---- C:\windows\ljod
2013-12-09 18:27:08 ----D---- C:\windows\ckyf
2013-12-09 18:27:03 ----D---- C:\windows\nxoj
2013-12-09 18:26:58 ----D---- C:\windows\wbyz
2013-12-09 18:26:53 ----D---- C:\windows\ttit
2013-12-09 18:26:47 ----D---- C:\windows\oxux
2013-12-09 18:26:42 ----D---- C:\windows\iziz
2013-12-09 18:26:17 ----D---- C:\windows\stat
2013-12-09 18:26:12 ----D---- C:\windows\ejej
2013-12-09 18:26:02 ----D---- C:\windows\dtos
2013-12-09 18:25:51 ----D---- C:\windows\uhef
2013-12-09 18:25:46 ----D---- C:\windows\gqwn
2013-12-09 18:25:41 ----D---- C:\windows\acim
2013-12-09 18:25:36 ----D---- C:\windows\ybyz
2013-12-09 18:25:26 ----D---- C:\windows\atac
2013-12-09 18:25:21 ----D---- C:\windows\yvaj
2013-12-09 18:25:05 ----D---- C:\windows\hpax
2013-12-09 18:25:00 ----D---- C:\windows\etus
2013-12-09 18:24:40 ----D---- C:\windows\emus
2013-12-09 18:24:35 ----D---- C:\windows\ytkc
2013-12-09 18:24:20 ----D---- C:\windows\opop
2013-12-09 18:24:14 ----D---- C:\windows\odoj
2013-12-09 18:24:04 ----D---- C:\windows\emoz
2013-12-09 18:23:59 ----D---- C:\windows\tqyx
2013-12-09 18:23:39 ----D---- C:\windows\ozlf
2013-12-09 18:23:28 ----D---- C:\windows\yphj
2013-12-09 18:23:23 ----D---- C:\windows\jkew
2013-12-09 18:23:13 ----D---- C:\windows\lgop
2013-12-09 18:22:58 ----D---- C:\windows\uxld
2013-12-09 18:22:32 ----D---- C:\windows\ddox
2013-12-09 18:22:27 ----D---- C:\windows\hhyb
2013-12-09 18:22:22 ----D---- C:\windows\yrzq
2013-12-09 18:22:17 ----D---- C:\windows\wgyr
2013-12-09 18:22:12 ----D---- C:\windows\okuh
2013-12-09 18:22:02 ----D---- C:\windows\ebec
2013-12-09 18:21:57 ----D---- C:\windows\oklh
2013-12-09 18:21:31 ----D---- C:\windows\ijag
2013-12-09 18:21:21 ----D---- C:\windows\ucuh
2013-12-09 18:21:11 ----D---- C:\windows\olev
2013-12-09 18:20:55 ----D---- C:\windows\uqop
2013-12-09 18:20:45 ----D---- C:\windows\agyj
2013-12-09 18:20:40 ----D---- C:\windows\inip
2013-12-09 18:20:35 ----D---- C:\windows\amkm
2013-12-09 18:20:20 ----D---- C:\windows\ikyk
2013-12-09 18:20:09 ----D---- C:\windows\ekoh
2013-12-09 18:19:54 ----D---- C:\windows\gmuh
2013-12-09 18:19:39 ----D---- C:\windows\ejuj
2013-12-09 18:19:34 ----D---- C:\windows\ahaz
2013-12-09 18:19:13 ----D---- C:\windows\gdgd
2013-12-09 18:19:03 ----D---- C:\windows\ycak
2013-12-09 18:18:53 ----D---- C:\windows\yhms
2013-12-09 18:18:29 ----D---- C:\windows\ubeg
2013-12-09 18:18:20 ----D---- C:\windows\eteb
2013-12-09 18:18:10 ----D---- C:\windows\omob
2013-12-09 18:18:02 ----D---- C:\windows\ydfp
2013-12-09 18:17:48 ----D---- C:\windows\abab
2013-12-09 18:17:29 ----D---- C:\windows\ehoc
2013-12-09 18:17:19 ----D---- C:\windows\jqog
2013-12-09 18:16:56 ----D---- C:\windows\fmaf
2013-12-09 18:16:35 ----D---- C:\windows\yhwh
2013-12-09 18:16:25 ----D---- C:\windows\wnyq
2013-12-09 18:16:04 ----D---- C:\windows\yvyx
2013-12-09 18:15:59 ----D---- C:\windows\ezus
2013-12-09 18:15:54 ----D---- C:\windows\ilsx
2013-12-09 18:15:49 ----D---- C:\windows\tlin
2013-12-09 18:15:44 ----D---- C:\windows\okeb
2013-12-09 18:15:39 ----D---- C:\windows\ammc
2013-12-09 18:15:34 ----D---- C:\windows\udur
2013-12-09 18:15:28 ----D---- C:\windows\uzet
2013-12-09 18:15:18 ----D---- C:\windows\idyv
2013-12-09 18:14:48 ----D---- C:\windows\uhoc
2013-12-09 18:14:37 ----D---- C:\windows\agij
2013-12-09 18:14:27 ----D---- C:\windows\svar
2013-12-09 18:14:17 ----D---- C:\windows\aqan
2013-12-09 18:14:12 ----D---- C:\windows\ucuz
2013-12-09 18:14:07 ----D---- C:\windows\pwuc
2013-12-09 18:13:46 ----D---- C:\windows\xnrd
2013-12-09 18:13:36 ----D---- C:\windows\idyq
2013-12-09 18:13:26 ----D---- C:\windows\ocus
2013-12-09 18:13:21 ----D---- C:\windows\owuk
2013-12-09 18:13:10 ----D---- C:\windows\ysiw
2013-12-09 18:13:05 ----D---- C:\windows\ytat
2013-12-09 18:13:00 ----D---- C:\windows\oder
2013-12-09 18:12:55 ----D---- C:\windows\rhok
2013-12-09 18:12:50 ----D---- C:\windows\apid
2013-12-09 18:12:40 ----D---- C:\windows\rrdd
2013-12-09 18:12:30 ----D---- C:\windows\isyw
2013-12-09 18:12:04 ----D---- C:\windows\utos
2013-12-09 18:11:49 ----D---- C:\windows\efos
2013-12-09 18:11:23 ----D---- C:\windows\zkac
2013-12-09 18:11:07 ----D---- C:\windows\rsoc
2013-12-09 18:11:02 ----D---- C:\windows\ajaq
2013-12-09 18:10:57 ----D---- C:\windows\umuh
2013-12-09 18:10:47 ----D---- C:\windows\odnd
2013-12-09 18:10:31 ----D---- C:\windows\ajav
2013-12-09 18:10:20 ----D---- C:\windows\umym
2013-12-09 18:10:10 ----D---- C:\windows\ekez
2013-12-09 18:10:00 ----D---- C:\windows\kxyq
2013-12-09 18:09:49 ----D---- C:\windows\ilin
2013-12-09 18:09:34 ----D---- C:\windows\ydil
2013-12-09 18:09:24 ----D---- C:\windows\ovog
2013-12-09 18:09:14 ----D---- C:\windows\icik
2013-12-09 18:09:08 ----D---- C:\windows\rxjr
2013-12-09 18:09:03 ----D---- C:\windows\azyw
2013-12-09 18:08:48 ----D---- C:\windows\unud
2013-12-09 18:08:37 ----D---- C:\windows\erpr
2013-12-09 18:08:27 ----D---- C:\windows\scyt
2013-12-09 18:08:22 ----D---- C:\windows\ygit
2013-12-09 18:08:11 ----D---- C:\windows\ocew
2013-12-09 18:07:51 ----D---- C:\windows\uqgl
2013-12-09 18:07:30 ----D---- C:\windows\uzjt
2013-12-09 18:07:14 ----D---- C:\windows\iftc
Protokol o kontrole
Verze virové databáze: 9152 (20131209)
Datum: 10.12.2013 Čas: 9:02:54
Testované disky, adresáře a soubory: Operační paměť;C:\Boot sektor;D:\Boot sektor;C:\;D:\
Operační paměť » OnekeySupport.exe(2992) - varianta infiltrace Win32/Spy.Hesperbot.C trojský kůň - vyléčen smazáním [1]
Operační paměť » explorer.exe(2680) - varianta infiltrace Win32/Spy.Hesperbot.C trojský kůň - vyléčen smazáním [1]
Operační paměť » IAStorIcon.exe(3828) - varianta infiltrace Win32/Spy.Hesperbot.C trojský kůň - vyléčen smazáním [1]
Operační paměť » VM331_STI.EXE(3896) - varianta infiltrace Win32/Spy.Hesperbot.C trojský kůň - vyléčen smazáním [1]
Operační paměť » jusched.exe(3576) - varianta infiltrace Win32/Spy.Hesperbot.C trojský kůň - vyléčen smazáním [1]
Operační paměť » Skype.exe(3064) - varianta infiltrace Win32/Spy.Hesperbot.C trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.C trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » iexplore.exe(5832) - varianta infiltrace Win32/Spy.Hesperbot.H trojský kůň - vyléčen smazáním [1]
Operační paměť » TOTALCMD.EXE(2272) - varianta infiltrace Win32/Spy.Hesperbot.C trojský kůň - vyléčen smazáním [1]
C:\hiberfil.sys - chyba při otevírání [4]
C:\pagefile.sys - chyba při otevírání [4]
C:\###Radost###\OOo_3.3.0_Win_x86_install_cs.exe » NSIS » openofficeorg1.cab » CAB » testtar.tar » TAR » - poškozený archiv
Kontrola přerušena uživatelem!
Počet zkontrolovaných objektů: 5157
Počet nalezených hrozeb: 29
Počet vyléčených objektů: 29
Čas ukončení: 9:04:12 Celkový čas diagnostiky: 78 sek (00:01:18)
Poznámky:
[1] Objekt byl smazán, obsahoval pouze škodlivý kód.
[4] Objekt nelze otevřít ke čtení. Je využíván jinou aplikací (nebo operačním systémem), která ho otevřela výhradně pro sebe.
Logfile of random's system information tool 1.09 (written by random/random)
Run by Sema at 2013-12-10 13:21:32
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 23 GB (5%) free of 432 GB
Total RAM: 3959 MB (54% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:21:39, on 10.12.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16736)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\USB Camera\VM331_STI.EXE
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\totalcmd\TOTALCMD.EXE
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Users\Sema\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2AALCLP9\RSIT.exe
C:\Program Files (x86)\trend micro\Sema.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [331BigDog] C:\Program Files (x86)\USB Camera\VM331_STI.EXE
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\3.0"
O4 - HKLM\..\Run: [UpdateP2GShortCut] "C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Dropbox.lnk = C:\Users\Sema\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Moveslink for Movestick Mini.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files (x86)\ICQ7.7\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files (x86)\ICQ7.7\ICQ.exe
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
O23 - Service: CrossLoop Service (CrossLoopService) - CrossLoop Inc - C:\Users\Sema\AppData\Local\CrossLoop\CrossLoopService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: KMService - Unknown owner - C:\windows\system32\srvany.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\windows\system32\nvvsvc.exe (file missing)
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe
O23 - Service: PnkBstrA - Unknown owner - C:\windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TightVNC Server (tvnserver) - GlavSoft LLC. - C:\Users\Sema\AppData\Local\CrossLoop\tvnserver.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 13576 bytes
======Scheduled tasks folder======
C:\windows\tasks\Adobe Flash Player Updater.job
C:\windows\tasks\GoogleUpdateTaskMachineCore.job
C:\windows\tasks\GoogleUpdateTaskMachineUA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Sema\AppData\Roaming\Mozilla\Firefox\Profiles\ekkcdbr4.default
prefs.js - "browser.search.suggest.enabled" - false
prefs.js - "browser.startup.homepage" - "http://www.google.cz/"
prefs.js - "extensions.enabledItems" - "{0b457cAA-602d-484a-8fe7-c1d894a011ba}:0.88, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.117 Plugin
"Path"=C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.25.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\windows\SysWOW64\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
C:\Program Files (x86)\Mozilla Firefox\extensions\
{AB2CE124-6272-4b12-94A9-7303C7397BD1}
{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
C:\Program Files (x86)\Mozilla Firefox\plugins\
nppdf32.dll
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
mall-cz.xml
C:\Users\Sema\AppData\Roaming\Mozilla\Firefox\Profiles\ekkcdbr4.default\extensions\
battlefieldplay4free@ea.com
{0b457cAA-602d-484a-8fe7-c1d894a011ba}
C:\Users\Sema\AppData\Roaming\Mozilla\Firefox\Profiles\ekkcdbr4.default\searchplugins\
daemon-search.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2012-08-16 4171424]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-10-08 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-11-22 1242504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-12-21 561552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-10-08 171944]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2010-03-03 284696]
"331BigDog"=C:\Program Files (x86)\USB Camera\VM331_STI.EXE [2010-01-15 536576]
"UCam_Menu"=C:\Program Files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe [2009-05-19 222504]
"UpdateP2GShortCut"=C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [2008-12-03 218408]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"NeroFilterCheck"=C:\windows\system32\NeroCheck.exe [2004-02-13 155648]
"avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2013-11-26 683576]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-03-12 253816]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Pando Media Booster"=C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [2013-01-09 3093624]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files (x86)\Lenovo\Bluetooth Software\BTTray.exe
Moveslink for Movestick Mini.lnk - C:\windows\Installer\{4D036ACA-DFDF-41B2-A680-E0D736F3E947}\_22A9010B636AF7A61D8E03.exe
C:\Users\Sema\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Sema\AppData\Roaming\Dropbox\bin\Dropbox.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2012-08-16 4171424]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=3
"EnableLUA"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\SysWOW64\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"msacm.clmp3enc"=C:\PROGRA~2\Lenovo\Power2Go\CLMP3Enc.ACM
"msacm.siren"=sirenacm.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2013-12-10 13:21:33 ----D---- C:\Program Files (x86)\trend micro
2013-12-10 13:21:32 ----D---- C:\rsit
2013-12-10 11:40:58 ----D---- C:\windows\agen
2013-12-10 11:40:48 ----D---- C:\windows\smyf
2013-12-10 11:40:32 ----D---- C:\windows\urox
2013-12-10 11:40:22 ----D---- C:\windows\owaz
2013-12-10 11:40:11 ----D---- C:\windows\ivwr
2013-12-10 11:39:56 ----D---- C:\windows\ozpk
2013-12-10 11:39:45 ----D---- C:\windows\okrh
2013-12-10 11:39:30 ----D---- C:\windows\rmew
2013-12-10 11:39:25 ----D---- C:\windows\oxur
2013-12-10 11:39:04 ----D---- C:\windows\tpij
2013-12-10 11:38:49 ----D---- C:\windows\kdip
2013-12-10 11:38:39 ----D---- C:\windows\urux
2013-12-10 11:38:13 ----D---- C:\windows\wtik
2013-12-10 11:37:57 ----D---- C:\windows\ybsh
2013-12-10 11:37:32 ----D---- C:\windows\fxwg
2013-12-10 11:36:56 ----D---- C:\windows\dbom
2013-12-10 11:36:40 ----D---- C:\windows\wsib
2013-12-10 11:36:30 ----D---- C:\windows\rsok
2013-12-10 11:36:04 ----D---- C:\windows\ntob
2013-12-10 11:35:38 ----D---- C:\windows\ojjd
2013-12-10 11:34:47 ----D---- C:\windows\ipwx
2013-12-10 11:34:42 ----D---- C:\windows\avid
2013-12-10 11:34:31 ----D---- C:\windows\itym
2013-12-10 11:34:21 ----D---- C:\windows\ucug
2013-12-10 11:34:16 ----D---- C:\windows\nzek
2013-12-10 11:34:10 ----D---- C:\windows\jsot
2013-12-10 11:33:34 ----D---- C:\windows\ykyq
2013-12-10 11:33:19 ----D---- C:\windows\kwiw
2013-12-10 11:33:04 ----D---- C:\windows\orux
2013-12-10 11:32:53 ----D---- C:\windows\zfyt
2013-12-10 11:32:27 ----D---- C:\windows\uces
2013-12-10 11:32:22 ----D---- C:\windows\xmoz
2013-12-10 11:32:07 ----D---- C:\windows\ocph
2013-12-10 11:32:02 ----D---- C:\windows\ebek
2013-12-10 11:31:57 ----D---- C:\windows\icfc
2013-12-10 11:31:31 ----D---- C:\windows\oqep
2013-12-10 11:31:00 ----D---- C:\windows\snap
2013-12-10 11:30:24 ----D---- C:\windows\dvev
2013-12-10 11:29:43 ----D---- C:\windows\mbib
2013-12-10 11:29:23 ----D---- C:\windows\axap
2013-12-10 11:29:07 ----D---- C:\windows\orud
2013-12-10 11:28:37 ----D---- C:\windows\ojoj
2013-12-10 11:28:32 ----D---- C:\windows\yzih
2013-12-10 11:28:06 ----D---- C:\windows\avov
2013-12-10 11:27:51 ----D---- C:\windows\ejap
2013-12-10 11:27:45 ----D---- C:\windows\whys
2013-12-10 11:27:04 ----D---- C:\windows\lgep
2013-12-10 11:26:59 ----D---- C:\windows\igkj
2013-12-10 11:26:41 ----D---- C:\windows\nzlf
2013-12-10 11:26:19 ----D---- C:\windows\fdig
2013-12-10 11:26:14 ----D---- C:\windows\esut
2013-12-10 11:25:49 ----D---- C:\windows\tmmc
2013-12-10 11:25:18 ----D---- C:\windows\qzjt
2013-12-10 11:25:12 ----D---- C:\windows\ogsn
2013-12-10 11:24:39 ----D---- C:\windows\gxox
2013-12-10 11:23:53 ----D---- C:\windows\arod
2013-12-10 11:23:47 ----D---- C:\windows\insg
2013-12-10 11:23:23 ----D---- C:\windows\enon
2013-12-10 11:23:06 ----D---- C:\windows\ahfw
2013-12-10 11:23:00 ----D---- C:\windows\wcak
2013-12-10 11:22:47 ----D---- C:\windows\acyf
2013-12-10 11:22:41 ----D---- C:\windows\shaw
2013-12-10 11:22:20 ----D---- C:\windows\efdw
2013-12-10 11:21:28 ----D---- C:\windows\aqfj
2013-12-10 11:21:13 ----D---- C:\windows\yhyb
2013-12-10 11:20:52 ----D---- C:\windows\gqeg
2013-12-10 11:19:56 ----D---- C:\windows\atyk
2013-12-10 11:19:45 ----D---- C:\windows\erod
2013-12-10 11:19:09 ----D---- C:\windows\exej
2013-12-10 11:18:59 ----D---- C:\windows\igih
2013-12-10 11:18:49 ----D---- C:\windows\otoh
2013-12-10 11:18:43 ----D---- C:\windows\krbg
2013-12-10 11:18:27 ----D---- C:\windows\rfow
2013-12-10 11:18:16 ----D---- C:\windows\lhdt
2013-12-10 11:18:01 ----D---- C:\windows\tbks
2013-12-10 11:17:51 ----D---- C:\windows\ibys
2013-12-10 11:17:45 ----D---- C:\windows\zjap
2013-12-10 11:17:40 ----D---- C:\windows\lhot
2013-12-10 11:17:30 ----D---- C:\windows\adon
2013-12-10 11:17:20 ----D---- C:\windows\osum
2013-12-10 11:16:49 ----D---- C:\windows\ipir
2013-12-10 11:16:18 ----D---- C:\windows\qkow
2013-12-10 11:16:13 ----D---- C:\windows\ltuz
2013-12-10 11:16:08 ----D---- C:\windows\nhum
2013-12-10 11:15:58 ----D---- C:\windows\alaj
2013-12-10 11:15:32 ----D---- C:\windows\ezut
2013-12-10 11:15:27 ----D---- C:\windows\snyl
2013-12-10 11:15:01 ----D---- C:\windows\owug
2013-12-10 11:14:46 ----D---- C:\windows\axal
2013-12-10 11:13:54 ----D---- C:\windows\vded
2013-12-10 11:13:29 ----D---- C:\windows\udux
2013-12-10 11:13:18 ----D---- C:\windows\mkat
2013-12-10 11:12:11 ----D---- C:\windows\yqcd
2013-12-10 11:11:20 ----D---- C:\windows\izys
2013-12-10 11:11:04 ----D---- C:\windows\uxur
2013-12-10 11:10:49 ----D---- C:\windows\yxif
2013-12-10 11:10:44 ----D---- C:\windows\owjm
2013-12-10 11:10:38 ----D---- C:\windows\mgyr
2013-12-10 11:09:22 ----D---- C:\windows\ujej
2013-12-10 11:08:45 ----D---- C:\windows\ibiw
2013-12-10 11:08:35 ----D---- C:\windows\ahys
2013-12-10 11:08:25 ----D---- C:\windows\etyc
2013-12-10 11:08:03 ----D---- C:\windows\ocoh
2013-12-10 11:07:47 ----D---- C:\windows\edun
2013-12-10 11:07:37 ----D---- C:\windows\unqn
2013-12-10 11:07:16 ----D---- C:\windows\uguc
2013-12-10 11:07:01 ----D---- C:\windows\uxrd
2013-12-10 11:06:55 ----D---- C:\windows\qfuh
2013-12-10 11:06:45 ----D---- C:\windows\lbuc
2013-12-10 11:06:40 ----D---- C:\windows\ezrf
2013-12-10 11:06:35 ----D---- C:\windows\cqin
2013-12-10 11:06:30 ----D---- C:\windows\jdun
2013-12-10 11:06:25 ----D---- C:\windows\ywbz
2013-12-10 11:05:49 ----D---- C:\windows\eqdg
2013-12-10 11:05:44 ----D---- C:\windows\yqwn
2013-12-10 11:05:28 ----D---- C:\windows\ehrc
2013-12-10 11:05:23 ----D---- C:\windows\ebut
2013-12-10 11:04:52 ----D---- C:\windows\bsas
2013-12-10 11:04:22 ----D---- C:\windows\udun
2013-12-10 11:03:35 ----D---- C:\windows\dmoz
2013-12-10 11:03:30 ----D---- C:\windows\atav
2013-12-10 11:03:10 ----D---- C:\windows\usqk
2013-12-10 11:02:59 ----D---- C:\windows\yvar
2013-12-10 11:02:15 ----D---- C:\windows\zmyc
2013-12-10 11:01:54 ----D---- C:\windows\ijap
2013-12-10 11:01:23 ----D---- C:\windows\mxag
2013-12-10 11:00:53 ----D---- C:\windows\abts
2013-12-10 11:00:12 ----D---- C:\windows\ojex
2013-12-10 10:59:56 ----D---- C:\windows\hlyr
2013-12-10 10:59:46 ----D---- C:\windows\yxcl
2013-12-10 10:58:55 ----D---- C:\windows\uceb
2013-12-10 10:58:09 ----D---- C:\windows\utvs
2013-12-10 10:58:04 ----D---- C:\windows\hnap
2013-12-10 10:57:48 ----D---- C:\windows\orrn
2013-12-10 10:57:22 ----D---- C:\windows\ilyn
2013-12-10 10:57:17 ----D---- C:\windows\kpbj
2013-12-10 10:56:46 ----D---- C:\windows\hvyj
2013-12-10 10:56:36 ----D---- C:\windows\ufns
2013-12-10 10:56:31 ----D---- C:\windows\engn
2013-12-10 10:56:05 ----D---- C:\windows\ufrz
2013-12-10 10:55:59 ----D---- C:\windows\ocjw
2013-12-10 10:55:44 ----D---- C:\windows\ymic
2013-12-10 10:55:34 ----D---- C:\windows\bwab
2013-12-10 10:55:28 ----D---- C:\windows\pjqd
2013-12-10 10:55:23 ----D---- C:\windows\qder
2013-12-10 10:55:18 ----D---- C:\windows\fzth
2013-12-10 10:55:08 ----D---- C:\windows\szib
2013-12-10 10:55:03 ----D---- C:\windows\hwyw
2013-12-10 10:54:42 ----D---- C:\windows\ondj
2013-12-10 10:54:32 ----D---- C:\windows\iqfj
2013-12-10 10:54:16 ----D---- C:\windows\bhaz
2013-12-10 10:53:40 ----D---- C:\windows\lfos
2013-12-10 10:53:35 ----D---- C:\windows\ivix
2013-12-10 10:53:25 ----D---- C:\windows\ewgk
2013-12-10 10:53:15 ----D---- C:\windows\okuf
2013-12-10 10:53:09 ----D---- C:\windows\ynkq
2013-12-10 10:53:04 ----D---- C:\windows\ugvq
2013-12-10 10:52:54 ----D---- C:\windows\vqol
2013-12-10 10:52:49 ----D---- C:\windows\osot
2013-12-10 10:52:39 ----D---- C:\windows\efgs
2013-12-10 10:52:33 ----D---- C:\windows\xkuz
2013-12-10 10:52:13 ----D---- C:\windows\tdyv
2013-12-10 10:51:57 ----D---- C:\windows\axag
2013-12-10 10:51:16 ----D---- C:\windows\wsiw
2013-12-10 10:51:11 ----D---- C:\windows\oxej
2013-12-10 10:51:01 ----D---- C:\windows\ewpt
2013-12-10 10:50:30 ----D---- C:\windows\ivhn
2013-12-10 10:50:24 ----D---- C:\windows\tlij
2013-12-10 10:50:19 ----D---- C:\windows\ekuz
2013-12-10 10:49:43 ----D---- C:\windows\ulgq
2013-12-10 10:49:27 ----D---- C:\windows\gzok
2013-12-10 10:49:06 ----D---- C:\windows\qmit
2013-12-10 10:48:50 ----D---- C:\windows\ehef
2013-12-10 10:48:45 ----D---- C:\windows\esnf
2013-12-10 10:48:40 ----D---- C:\windows\idap
2013-12-10 10:48:35 ----D---- C:\windows\rkqs
2013-12-10 10:48:29 ----D---- C:\windows\ixal
2013-12-10 10:48:19 ----D---- C:\windows\acym
2013-12-10 10:48:09 ----D---- C:\windows\ithk
2013-12-10 10:48:04 ----D---- C:\windows\udex
2013-12-10 10:47:43 ----D---- C:\windows\ebqt
2013-12-10 10:47:38 ----D---- C:\windows\udon
2013-12-10 10:47:33 ----D---- C:\windows\zbih
2013-12-10 10:47:28 ----D---- C:\windows\ifkk
2013-12-10 10:47:22 ----D---- C:\windows\ecus
2013-12-10 10:47:07 ----D---- C:\windows\unrs
2013-12-10 10:47:02 ----D---- C:\windows\odjj
2013-12-10 10:46:46 ----D---- C:\windows\xpug
2013-12-10 10:46:35 ----D---- C:\windows\ylul
2013-12-10 10:46:25 ----D---- C:\windows\qwof
2013-12-10 10:45:49 ----D---- C:\windows\ekes
2013-12-10 10:45:43 ----D---- C:\windows\ofos
2013-12-10 10:45:38 ----D---- C:\windows\ypyr
2013-12-10 10:45:23 ----D---- C:\windows\aqbx
2013-12-10 10:45:12 ----D---- C:\windows\ymqb
2013-12-10 10:44:57 ----D---- C:\windows\emgz
2013-12-10 10:44:16 ----D---- C:\windows\cqyn
2013-12-10 10:44:00 ----D---- C:\windows\fxil
2013-12-10 10:43:55 ----D---- C:\windows\ycmm
2013-12-10 10:43:24 ----D---- C:\windows\nqoq
2013-12-10 10:43:08 ----D---- C:\windows\ybah
2013-12-10 10:43:03 ----D---- C:\windows\kftc
2013-12-10 10:42:47 ----D---- C:\windows\ivad
2013-12-10 10:42:37 ----D---- C:\windows\eqep
2013-12-10 10:42:11 ----D---- C:\windows\urov
2013-12-10 10:42:06 ----D---- C:\windows\kqhn
2013-12-10 10:42:00 ----D---- C:\windows\esxt
2013-12-10 10:41:55 ----D---- C:\windows\hnav
2013-12-10 10:41:45 ----D---- C:\windows\tkik
2013-12-10 10:41:40 ----D---- C:\windows\ahwh
2013-12-10 10:40:58 ----D---- C:\windows\ocqw
2013-12-10 10:40:07 ----D---- C:\windows\qkez
2013-12-10 10:39:41 ----D---- C:\windows\orvd
2013-12-10 10:39:35 ----D---- C:\windows\ybiw
2013-12-10 10:39:30 ----D---- C:\windows\egul
2013-12-10 10:39:20 ----D---- C:\windows\twtw
2013-12-10 10:38:54 ----D---- C:\windows\bfaf
2013-12-10 10:38:23 ----D---- C:\windows\xfuw
2013-12-10 10:38:03 ----D---- C:\windows\uzlf
2013-12-10 10:37:47 ----D---- C:\windows\iciq
2013-12-10 10:36:50 ----D---- C:\windows\ivid
2013-12-10 10:36:24 ----D---- C:\windows\yleq
2013-12-10 10:36:19 ----D---- C:\windows\ublt
2013-12-10 09:06:51 ----D---- C:\Program Files (x86)\ESET
2013-12-10 08:28:46 ----D---- C:\windows\ehkh
2013-12-10 08:28:24 ----D---- C:\windows\uvog
2013-12-10 08:28:12 ----D---- C:\windows\atim
2013-12-10 08:27:41 ----D---- C:\windows\vsof
2013-12-09 21:01:30 ----D---- C:\windows\ewvf
2013-12-09 21:01:25 ----D---- C:\windows\ypmj
2013-12-09 21:01:05 ----D---- C:\windows\mjiq
2013-12-09 21:00:59 ----D---- C:\windows\dwof
2013-12-09 21:00:49 ----D---- C:\windows\yqfx
2013-12-09 21:00:44 ----D---- C:\windows\idbp
2013-12-09 21:00:19 ----D---- C:\windows\uzdc
2013-12-09 20:59:53 ----D---- C:\windows\awcs
2013-12-09 20:59:43 ----D---- C:\windows\ijyq
2013-12-09 20:58:57 ----D---- C:\windows\gveq
2013-12-09 20:58:47 ----D---- C:\windows\emub
2013-12-09 20:58:26 ----D---- C:\windows\itwc
2013-12-09 20:58:01 ----D---- C:\windows\ojed
2013-12-09 20:57:46 ----D---- C:\windows\ukew
2013-12-09 20:57:35 ----D---- C:\windows\lfrz
2013-12-09 20:57:20 ----D---- C:\windows\ahah
2013-12-09 20:56:39 ----D---- C:\windows\wqmn
2013-12-09 20:56:34 ----D---- C:\windows\utew
2013-12-09 20:56:24 ----D---- C:\windows\jcqw
2013-12-09 20:56:19 ----D---- C:\windows\inig
2013-12-09 20:56:14 ----D---- C:\windows\htac
2013-12-09 20:55:58 ----D---- C:\windows\unel
2013-12-09 20:55:33 ----D---- C:\windows\evep
2013-12-09 20:55:18 ----D---- C:\windows\qcus
2013-12-09 20:55:12 ----D---- C:\windows\ezof
2013-12-09 20:55:07 ----D---- C:\windows\ivaj
2013-12-09 20:55:02 ----D---- C:\windows\awis
2013-12-09 20:54:57 ----D---- C:\windows\ggul
2013-12-09 20:54:47 ----D---- C:\windows\abkw
2013-12-09 20:54:42 ----D---- C:\windows\uxgn
2013-12-09 20:54:32 ----D---- C:\windows\dlog
2013-12-09 20:54:27 ----D---- C:\windows\hbiw
2013-12-09 20:54:11 ----D---- C:\windows\yqtd
2013-12-09 20:53:56 ----D---- C:\windows\jxer
2013-12-09 20:53:46 ----D---- C:\windows\akam
2013-12-09 20:53:35 ----D---- C:\windows\yzab
2013-12-09 20:53:30 ----D---- C:\windows\eroj
2013-12-09 20:53:20 ----D---- C:\windows\ykam
2013-12-09 20:53:05 ----D---- C:\windows\shyb
2013-12-09 20:52:44 ----D---- C:\windows\ogug
2013-12-09 20:52:29 ----D---- C:\windows\hdyp
2013-12-09 20:52:19 ----D---- C:\windows\fpar
2013-12-09 20:51:53 ----D---- C:\windows\ezum
2013-12-09 20:51:43 ----D---- C:\windows\tmyk
2013-12-09 20:51:18 ----D---- C:\windows\imsf
2013-12-09 20:51:13 ----D---- C:\windows\tsyb
2013-12-09 20:50:52 ----D---- C:\windows\yriv
2013-12-09 20:50:16 ----D---- C:\windows\wncl
2013-12-09 20:49:51 ----D---- C:\windows\rzpr
2013-12-09 20:49:20 ----D---- C:\windows\onrr
2013-12-09 20:48:55 ----D---- C:\windows\mtyc
2013-12-09 20:48:14 ----D---- C:\windows\umrs
2013-12-09 20:48:04 ----D---- C:\windows\spaj
2013-12-09 20:47:54 ----D---- C:\windows\htim
2013-12-09 20:47:18 ----D---- C:\windows\ajig
2013-12-09 20:46:57 ----D---- C:\windows\yrsp
2013-12-09 20:46:52 ----D---- C:\windows\dset
2013-12-09 20:46:42 ----D---- C:\windows\bcyc
2013-12-09 20:46:32 ----D---- C:\windows\ovep
2013-12-09 20:46:06 ----D---- C:\windows\xnod
2013-12-09 20:45:41 ----D---- C:\windows\xsef
2013-12-09 20:45:36 ----D---- C:\windows\ykcc
2013-12-09 20:45:31 ----D---- C:\windows\ysiz
2013-12-09 20:45:21 ----D---- C:\windows\kniq
2013-12-09 20:45:00 ----D---- C:\windows\oxrd
2013-12-09 20:44:55 ----D---- C:\windows\azws
2013-12-09 20:44:35 ----D---- C:\windows\idil
2013-12-09 20:44:30 ----D---- C:\windows\ylyn
2013-12-09 20:44:19 ----D---- C:\windows\olol
2013-12-09 20:44:14 ----D---- C:\windows\jvov
2013-12-09 20:44:09 ----D---- C:\windows\pjoj
2013-12-09 20:43:38 ----D---- C:\windows\ihkh
2013-12-09 20:43:33 ----D---- C:\windows\nduj
2013-12-09 20:43:23 ----D---- C:\windows\glqp
2013-12-09 20:43:13 ----D---- C:\windows\uxed
2013-12-09 20:43:08 ----D---- C:\windows\elvv
2013-12-09 20:43:03 ----D---- C:\windows\amtt
2013-12-09 20:42:53 ----D---- C:\windows\alar
2013-12-09 20:42:37 ----D---- C:\windows\ukeb
2013-12-09 20:42:22 ----D---- C:\windows\oxuj
2013-12-09 20:42:12 ----D---- C:\windows\oveg
2013-12-09 20:41:41 ----D---- C:\windows\lcnw
2013-12-09 20:41:16 ----D---- C:\windows\rjuj
2013-12-09 20:41:05 ----D---- C:\windows\edoq
2013-12-09 20:40:55 ----D---- C:\windows\epjl
2013-12-09 20:40:35 ----D---- C:\windows\ecuz
2013-12-09 20:40:25 ----D---- C:\windows\sshh
2013-12-09 20:40:19 ----D---- C:\windows\hhiz
2013-12-09 20:40:04 ----D---- C:\windows\yxiq
2013-12-09 20:39:33 ----D---- C:\windows\ydkl
2013-12-09 20:39:28 ----D---- C:\windows\iqsd
2013-12-09 20:39:23 ----D---- C:\windows\xcow
2013-12-09 20:39:18 ----D---- C:\windows\inav
2013-12-09 20:38:37 ----D---- C:\windows\epql
2013-12-09 20:38:22 ----D---- C:\windows\djud
2013-12-09 20:37:57 ----D---- C:\windows\awts
2013-12-09 20:37:46 ----D---- C:\windows\zsyh
2013-12-09 20:37:41 ----D---- C:\windows\opql
2013-12-09 20:37:05 ----D---- C:\windows\hsyw
2013-12-09 20:36:45 ----D---- C:\windows\ehov
2013-12-09 20:36:35 ----D---- C:\windows\ufeb
2013-12-09 20:36:25 ----D---- C:\windows\ixyv
2013-12-09 20:36:20 ----D---- C:\windows\ivyn
2013-12-09 20:36:04 ----D---- C:\windows\amfk
2013-12-09 20:35:54 ----D---- C:\windows\dlop
2013-12-09 20:35:49 ----D---- C:\windows\acyk
2013-12-09 20:35:44 ----D---- C:\windows\vrex
2013-12-09 20:35:29 ----D---- C:\windows\exdx
2013-12-09 20:35:18 ----D---- C:\windows\efus
2013-12-09 20:35:08 ----D---- C:\windows\ydig
2013-12-09 20:34:58 ----D---- C:\windows\yvbx
2013-12-09 20:34:22 ----D---- C:\windows\amak
2013-12-09 20:34:17 ----D---- C:\windows\edxn
2013-12-09 20:34:07 ----D---- C:\windows\obgc
2013-12-09 20:33:52 ----D---- C:\windows\wtyf
2013-12-09 20:33:46 ----D---- C:\windows\edlx
2013-12-09 20:33:21 ----D---- C:\windows\vven
2013-12-09 20:33:16 ----D---- C:\windows\ttat
2013-12-09 20:33:06 ----D---- C:\windows\abib
2013-12-09 20:32:55 ----D---- C:\windows\arfl
2013-12-09 20:32:50 ----D---- C:\windows\gzot
2013-12-09 20:32:40 ----D---- C:\windows\iktk
2013-12-09 20:32:15 ----D---- C:\windows\cpar
2013-12-09 20:31:54 ----D---- C:\windows\utez
2013-12-09 20:31:49 ----D---- C:\windows\hril
2013-12-09 20:31:44 ----D---- C:\windows\ewok
2013-12-09 20:31:39 ----D---- C:\windows\oxex
2013-12-09 20:31:29 ----D---- C:\windows\uveq
2013-12-09 20:31:13 ----D---- C:\windows\epol
2013-12-09 20:31:08 ----D---- C:\windows\cfym
2013-12-09 20:30:38 ----D---- C:\windows\otuh
2013-12-09 20:30:17 ----D---- C:\windows\ikyf
2013-12-09 20:29:47 ----D---- C:\windows\upol
2013-12-09 20:29:21 ----D---- C:\windows\ypsr
2013-12-09 20:29:01 ----D---- C:\windows\ahtb
2013-12-09 20:28:30 ----D---- C:\windows\gcoh
2013-12-09 20:28:25 ----D---- C:\windows\mdyq
2013-12-09 20:28:20 ----D---- C:\windows\hvij
2013-12-09 20:27:59 ----D---- C:\windows\asib
2013-12-09 20:27:29 ----D---- C:\windows\ocow
2013-12-09 20:27:08 ----D---- C:\windows\yhcr
2013-12-09 20:26:58 ----D---- C:\windows\oxor
2013-12-09 20:26:53 ----D---- C:\windows\qrux
2013-12-09 20:26:43 ----D---- C:\windows\ihas
2013-12-09 20:26:38 ----D---- C:\windows\lqul
2013-12-09 20:26:33 ----D---- C:\windows\pbot
2013-12-09 20:26:22 ----D---- C:\windows\hsab
2013-12-09 20:25:37 ----D---- C:\windows\fwiw
2013-12-09 20:25:31 ----D---- C:\windows\uxgr
2013-12-09 20:25:26 ----D---- C:\windows\ifif
2013-12-09 20:24:56 ----D---- C:\windows\usek
2013-12-09 20:24:51 ----D---- C:\windows\apij
2013-12-09 20:24:40 ----D---- C:\windows\asyh
2013-12-09 20:24:35 ----D---- C:\windows\epeg
2013-12-09 20:24:20 ----D---- C:\windows\ezxk
2013-12-09 20:24:10 ----D---- C:\windows\udap
2013-12-09 20:23:54 ----D---- C:\windows\uvvl
2013-12-09 20:23:14 ----D---- C:\windows\onux
2013-12-09 20:22:58 ----D---- C:\windows\odej
2013-12-09 20:22:17 ----D---- C:\windows\gcob
2013-12-09 20:22:12 ----D---- C:\windows\ecdz
2013-12-09 20:21:57 ----D---- C:\windows\orod
2013-12-09 20:21:52 ----D---- C:\windows\ysyh
2013-12-09 20:21:42 ----D---- C:\windows\aqkn
2013-12-09 20:21:37 ----D---- C:\windows\mdaq
2013-12-09 20:21:31 ----D---- C:\windows\irsp
2013-12-09 20:20:56 ----D---- C:\windows\xjud
2013-12-09 20:20:35 ----D---- C:\windows\esdt
2013-12-09 20:20:15 ----D---- C:\windows\etdh
2013-12-09 20:20:10 ----D---- C:\windows\gqeq
2013-12-09 20:19:55 ----D---- C:\windows\ovoq
2013-12-09 20:19:19 ----D---- C:\windows\eqrj
2013-12-09 20:19:14 ----D---- C:\windows\dpug
2013-12-09 20:18:58 ----D---- C:\windows\pkoh
2013-12-09 20:18:53 ----D---- C:\windows\knaq
2013-12-09 20:18:48 ----D---- C:\windows\nsef
2013-12-09 20:18:38 ----D---- C:\windows\equq
2013-12-09 20:17:06 ----D---- C:\windows\otjz
2013-12-09 20:17:01 ----D---- C:\windows\fjyp
2013-12-09 20:16:10 ----D---- C:\windows\yzyh
2013-12-09 20:15:44 ----D---- C:\windows\ikit
2013-12-09 20:15:39 ----D---- C:\windows\ujur
2013-12-09 20:15:19 ----D---- C:\windows\ihyh
2013-12-09 20:15:09 ----D---- C:\windows\ipad
2013-12-09 20:14:43 ----D---- C:\windows\inyg
2013-12-09 20:14:08 ----D---- C:\windows\rnux
2013-12-09 20:13:57 ----D---- C:\windows\yryg
2013-12-09 20:13:47 ----D---- C:\windows\avyr
2013-12-09 20:13:37 ----D---- C:\windows\osrc
2013-12-09 20:13:01 ----D---- C:\windows\ycfc
2013-12-09 20:12:36 ----D---- C:\windows\aniw
2013-12-09 20:12:31 ----D---- C:\windows\usum
2013-12-09 20:11:55 ----D---- C:\windows\ihiw
2013-12-09 20:11:29 ----D---- C:\windows\ecow
2013-12-09 20:11:04 ----D---- C:\windows\gwec
2013-12-09 20:10:49 ----D---- C:\windows\oguq
2013-12-09 20:10:43 ----D---- C:\windows\xjdr
2013-12-09 20:10:33 ----D---- C:\windows\etow
2013-12-09 20:10:18 ----D---- C:\windows\hbiz
2013-12-09 20:10:13 ----D---- C:\windows\akaf
2013-12-09 20:10:03 ----D---- C:\windows\alin
2013-12-09 20:09:52 ----D---- C:\windows\bdil
2013-12-09 20:09:17 ----D---- C:\windows\jvug
2013-12-09 20:09:12 ----D---- C:\windows\imac
2013-12-09 20:09:06 ----D---- C:\windows\ixiq
2013-12-09 20:08:51 ----D---- C:\windows\uhls
2013-12-09 20:08:46 ----D---- C:\windows\ptoh
2013-12-09 20:08:21 ----D---- C:\windows\ejed
2013-12-09 20:08:15 ----D---- C:\windows\mbab
2013-12-09 20:08:05 ----D---- C:\windows\umob
2013-12-09 20:07:30 ----D---- C:\windows\lgeg
2013-12-09 20:07:24 ----D---- C:\windows\ycck
2013-12-09 20:07:14 ----D---- C:\windows\nkgw
2013-12-09 20:07:09 ----D---- C:\windows\ixyp
2013-12-09 20:06:49 ----D---- C:\windows\ucos
2013-12-09 20:06:44 ----D---- C:\windows\ycig
2013-12-09 20:06:18 ----D---- C:\windows\vkuh
2013-12-09 20:06:13 ----D---- C:\windows\efes
2013-12-09 20:06:08 ----D---- C:\windows\azok
2013-12-09 20:05:58 ----D---- C:\windows\icsk
2013-12-09 20:05:53 ----D---- C:\windows\exux
2013-12-09 20:05:47 ----D---- C:\windows\abys
2013-12-09 20:05:42 ----D---- C:\windows\lluq
2013-12-09 20:05:27 ----D---- C:\windows\yhys
2013-12-09 20:05:17 ----D---- C:\windows\uruj
2013-12-09 20:05:12 ----D---- C:\windows\yqij
2013-12-09 20:04:51 ----D---- C:\windows\dtob
2013-12-09 20:03:50 ----D---- C:\windows\ojrj
2013-12-09 20:03:40 ----D---- C:\windows\gvuq
2013-12-09 20:03:35 ----D---- C:\windows\ywiz
2013-12-09 20:03:25 ----D---- C:\windows\msyz
2013-12-09 20:03:19 ----D---- C:\windows\osem
2013-12-09 20:02:59 ----D---- C:\windows\uwvf
2013-12-09 20:02:44 ----D---- C:\windows\ubqm
2013-12-09 20:02:28 ----D---- C:\windows\avyx
2013-12-09 20:02:13 ----D---- C:\windows\evoq
2013-12-09 20:02:03 ----D---- C:\windows\ahiz
2013-12-09 20:01:53 ----D---- C:\windows\yvix
2013-12-09 20:01:37 ----D---- C:\windows\iqix
2013-12-09 20:00:57 ----D---- C:\windows\afyf
2013-12-09 20:00:46 ----D---- C:\windows\zhis
2013-12-09 20:00:31 ----D---- C:\windows\ufoz
2013-12-09 20:00:05 ----D---- C:\windows\etes
2013-12-09 20:00:00 ----D---- C:\windows\sxyq
2013-12-09 19:59:40 ----D---- C:\windows\anil
2013-12-09 19:59:35 ----D---- C:\windows\ilwd
2013-12-09 19:59:20 ----D---- C:\windows\slyj
2013-12-09 19:59:09 ----D---- C:\windows\uzof
2013-12-09 19:59:04 ----D---- C:\windows\dzuk
2013-12-09 19:58:59 ----D---- C:\windows\ypcr
2013-12-09 19:58:34 ----D---- C:\windows\jvol
2013-12-09 19:58:29 ----D---- C:\windows\yfyt
2013-12-09 19:58:08 ----D---- C:\windows\ihib
2013-12-09 19:57:48 ----D---- C:\windows\ugug
2013-12-09 19:57:27 ----D---- C:\windows\upeq
2013-12-09 19:57:07 ----D---- C:\windows\ifwk
2013-12-09 19:56:57 ----D---- C:\windows\asab
2013-12-09 19:56:52 ----D---- C:\windows\bthc
2013-12-09 19:56:31 ----D---- C:\windows\oxod
2013-12-09 19:56:26 ----D---- C:\windows\awwb
2013-12-09 19:56:21 ----D---- C:\windows\ellg
2013-12-09 19:55:35 ----D---- C:\windows\ocob
2013-12-09 19:55:09 ----D---- C:\windows\agaj
2013-12-09 19:54:54 ----D---- C:\windows\yvad
2013-12-09 19:54:44 ----D---- C:\windows\wryl
2013-12-09 19:53:43 ----D---- C:\windows\ykyt
2013-12-09 19:53:22 ----D---- C:\windows\elol
2013-12-09 19:53:07 ----D---- C:\windows\kpix
2013-12-09 19:53:02 ----D---- C:\windows\owet
2013-12-09 19:52:57 ----D---- C:\windows\efuh
2013-12-09 19:52:11 ----D---- C:\windows\obqm
2013-12-09 19:51:35 ----D---- C:\windows\wwis
2013-12-09 19:51:30 ----D---- C:\windows\ycym
2013-12-09 19:51:25 ----D---- C:\windows\ejex
2013-12-09 19:51:10 ----D---- C:\windows\uxer
2013-12-09 19:51:05 ----D---- C:\windows\khiz
2013-12-09 19:50:49 ----D---- C:\windows\ojux
2013-12-09 19:50:44 ----D---- C:\windows\ywaw
2013-12-09 19:50:34 ----D---- C:\windows\ifft
2013-12-09 19:49:58 ----D---- C:\windows\evdl
2013-12-09 19:49:48 ----D---- C:\windows\yscw
2013-12-09 19:49:43 ----D---- C:\windows\uljv
2013-12-09 19:49:28 ----D---- C:\windows\awah
2013-12-09 19:49:23 ----D---- C:\windows\awys
2013-12-09 19:49:17 ----D---- C:\windows\opeg
2013-12-09 19:49:12 ----D---- C:\windows\zkyf
2013-12-09 19:49:07 ----D---- C:\windows\oron
2013-12-09 19:49:02 ----D---- C:\windows\bjtl
2013-12-09 19:48:52 ----D---- C:\windows\ylan
2013-12-09 19:48:31 ----D---- C:\windows\odod
2013-12-09 19:48:11 ----D---- C:\windows\idag
2013-12-09 19:47:51 ----D---- C:\windows\llel
2013-12-09 19:47:00 ----D---- C:\windows\klij
2013-12-09 19:46:44 ----D---- C:\windows\ucgb
2013-12-09 19:46:39 ----D---- C:\windows\ecoz
2013-12-09 19:46:29 ----D---- C:\windows\urun
2013-12-09 19:46:19 ----D---- C:\windows\ojod
2013-12-09 19:46:09 ----D---- C:\windows\igyr
2013-12-09 19:45:53 ----D---- C:\windows\jnor
2013-12-09 19:45:43 ----D---- C:\windows\epup
2013-12-09 19:45:33 ----D---- C:\windows\ipax
2013-12-09 19:45:28 ----D---- C:\windows\pmeh
2013-12-09 19:45:12 ----D---- C:\windows\axil
2013-12-09 19:44:57 ----D---- C:\windows\hhyh
2013-12-09 19:44:42 ----D---- C:\windows\ukgw
2013-12-09 19:44:37 ----D---- C:\windows\yjfq
2013-12-09 19:44:21 ----D---- C:\windows\bdag
2013-12-09 19:44:16 ----D---- C:\windows\mbem
2013-12-09 19:44:06 ----D---- C:\windows\jjon
2013-12-09 19:44:01 ----D---- C:\windows\wwah
2013-12-09 19:43:56 ----D---- C:\windows\nzok
2013-12-09 19:43:25 ----D---- C:\windows\agsr
2013-12-09 19:43:15 ----D---- C:\windows\gsoc
2013-12-09 19:43:05 ----D---- C:\windows\uqqv
2013-12-09 19:43:00 ----D---- C:\windows\attm
2013-12-09 19:42:49 ----D---- C:\windows\ahhs
2013-12-09 19:42:39 ----D---- C:\windows\uxex
2013-12-09 19:42:29 ----D---- C:\windows\yjyq
2013-12-09 19:42:14 ----D---- C:\windows\ibhb
2013-12-09 19:42:09 ----D---- C:\windows\abmb
2013-12-09 19:41:53 ----D---- C:\windows\obok
2013-12-09 19:41:48 ----D---- C:\windows\uleg
2013-12-09 19:41:43 ----D---- C:\windows\ugep
2013-12-09 19:41:38 ----D---- C:\windows\iczf
2013-12-09 19:41:33 ----D---- C:\windows\iwyz
2013-12-09 19:41:18 ----D---- C:\windows\dprv
2013-12-09 19:41:07 ----D---- C:\windows\ivyr
2013-12-09 19:40:47 ----D---- C:\windows\ywyh
2013-12-09 19:40:42 ----D---- C:\windows\olqp
2013-12-09 19:40:37 ----D---- C:\windows\rdux
2013-12-09 19:40:32 ----D---- C:\windows\ivyd
2013-12-09 19:40:21 ----D---- C:\windows\otuz
2013-12-09 19:40:06 ----D---- C:\windows\oqeq
2013-12-09 19:40:01 ----D---- C:\windows\nded
2013-12-09 19:39:56 ----D---- C:\windows\isbs
2013-12-09 19:39:51 ----D---- C:\windows\plog
2013-12-09 19:39:41 ----D---- C:\windows\adsq
2013-12-09 19:39:30 ----D---- C:\windows\ygyr
2013-12-09 19:39:15 ----D---- C:\windows\uqup
2013-12-09 19:39:00 ----D---- C:\windows\smac
2013-12-09 19:38:44 ----D---- C:\windows\ynyk
2013-12-09 19:38:39 ----D---- C:\windows\dblt
2013-12-09 19:38:34 ----D---- C:\windows\ecew
2013-12-09 19:38:19 ----D---- C:\windows\mzah
2013-12-09 19:38:04 ----D---- C:\windows\yxip
2013-12-09 19:37:28 ----D---- C:\windows\qpgl
2013-12-09 19:37:13 ----D---- C:\windows\eluq
2013-12-09 19:37:07 ----D---- C:\windows\fcic
2013-12-09 19:36:57 ----D---- C:\windows\ysis
2013-12-09 19:36:52 ----D---- C:\windows\uqol
2013-12-09 19:36:42 ----D---- C:\windows\zhiw
2013-12-09 19:36:37 ----D---- C:\windows\ynwq
2013-12-09 19:36:32 ----D---- C:\windows\ohef
2013-12-09 19:36:22 ----D---- C:\windows\ugeg
2013-12-09 19:36:11 ----D---- C:\windows\xlol
2013-12-09 19:36:01 ----D---- C:\windows\awkb
2013-12-09 19:35:56 ----D---- C:\windows\ogog
2013-12-09 19:35:51 ----D---- C:\windows\hcic
2013-12-09 19:35:46 ----D---- C:\windows\eqod
2013-12-09 19:35:31 ----D---- C:\windows\gpeq
2013-12-09 19:35:25 ----D---- C:\windows\fsis
2013-12-09 19:35:20 ----D---- C:\windows\dpeq
2013-12-09 19:35:05 ----D---- C:\windows\nzef
2013-12-09 19:35:00 ----D---- C:\windows\ywih
2013-12-09 19:34:45 ----D---- C:\windows\ythc
2013-12-09 19:34:29 ----D---- C:\windows\ozlk
2013-12-09 19:33:59 ----D---- C:\windows\ojor
2013-12-09 19:33:33 ----D---- C:\windows\lgup
2013-12-09 19:33:23 ----D---- C:\windows\uhet
2013-12-09 19:33:03 ----D---- C:\windows\okow
2013-12-09 19:32:58 ----D---- C:\windows\gwuk
2013-12-09 19:32:27 ----D---- C:\windows\hdig
2013-12-09 19:32:17 ----D---- C:\windows\enud
2013-12-09 19:32:12 ----D---- C:\windows\wkym
2013-12-09 19:32:01 ----D---- C:\windows\uned
2013-12-09 19:31:56 ----D---- C:\windows\agiz
2013-12-09 19:31:46 ----D---- C:\windows\arip
2013-12-09 19:31:36 ----D---- C:\windows\uwqc
2013-12-09 19:31:31 ----D---- C:\windows\hpir
2013-12-09 19:31:15 ----D---- C:\windows\ygar
2013-12-09 19:30:50 ----D---- C:\windows\aziw
2013-12-09 19:30:45 ----D---- C:\windows\aqyj
2013-12-09 19:30:14 ----D---- C:\windows\ulov
2013-12-09 19:29:54 ----D---- C:\windows\ovuq
2013-12-09 19:29:39 ----D---- C:\windows\yrkv
2013-12-09 19:29:33 ----D---- C:\windows\qbuc
2013-12-09 19:29:13 ----D---- C:\windows\yxal
2013-12-09 19:29:08 ----D---- C:\windows\aniv
2013-12-09 19:28:58 ----D---- C:\windows\mkyc
2013-12-09 19:28:53 ----D---- C:\windows\ukdb
2013-12-09 19:28:48 ----D---- C:\windows\mjal
2013-12-09 19:28:42 ----D---- C:\windows\osok
2013-12-09 19:28:37 ----D---- C:\windows\ddod
2013-12-09 19:28:22 ----D---- C:\windows\edjj
2013-12-09 19:28:17 ----D---- C:\windows\iwhz
2013-12-09 19:28:07 ----D---- C:\windows\ebet
2013-12-09 19:27:57 ----D---- C:\windows\ekew
2013-12-09 19:27:41 ----D---- C:\windows\ezem
2013-12-09 19:27:31 ----D---- C:\windows\okob
2013-12-09 19:27:21 ----D---- C:\windows\ibmb
2013-12-09 19:27:16 ----D---- C:\windows\upep
2013-12-09 19:27:11 ----D---- C:\windows\iwtw
2013-12-09 19:27:05 ----D---- C:\windows\rqup
2013-12-09 19:27:00 ----D---- C:\windows\ehom
2013-12-09 19:26:45 ----D---- C:\windows\tnig
2013-12-09 19:26:35 ----D---- C:\windows\okjs
2013-12-09 19:26:25 ----D---- C:\windows\ehrk
2013-12-09 19:26:20 ----D---- C:\windows\kqyd
2013-12-09 19:26:09 ----D---- C:\windows\kbyb
2013-12-09 19:25:29 ----D---- C:\windows\yfim
2013-12-09 19:25:18 ----D---- C:\windows\imyf
2013-12-09 19:25:13 ----D---- C:\windows\jrox
2013-12-09 19:25:03 ----D---- C:\windows\ynaq
2013-12-09 19:24:48 ----D---- C:\windows\khfs
2013-12-09 19:24:32 ----D---- C:\windows\ysak
2013-12-09 19:24:27 ----D---- C:\windows\fcac
2013-12-09 19:24:17 ----D---- C:\windows\zwaw
2013-12-09 19:24:12 ----D---- C:\windows\yjzl
2013-12-09 19:24:07 ----D---- C:\windows\anaq
2013-12-09 19:23:57 ----D---- C:\windows\isiz
2013-12-09 19:23:41 ----D---- C:\windows\asyw
2013-12-09 19:23:21 ----D---- C:\windows\ocrs
2013-12-09 19:23:06 ----D---- C:\windows\wkak
2013-12-09 19:23:00 ----D---- C:\windows\lrej
2013-12-09 19:22:35 ----D---- C:\windows\efuf
2013-12-09 19:22:15 ----D---- C:\windows\assw
2013-12-09 19:22:04 ----D---- C:\windows\ofuz
2013-12-09 19:21:24 ----D---- C:\windows\lwot
2013-12-09 19:21:18 ----D---- C:\windows\ygir
2013-12-09 19:21:03 ----D---- C:\windows\ugpv
2013-12-09 19:20:58 ----D---- C:\windows\akfm
2013-12-09 19:20:43 ----D---- C:\windows\yhaw
2013-12-09 19:20:22 ----D---- C:\windows\icam
2013-12-09 19:20:17 ----D---- C:\windows\ibaw
2013-12-09 19:20:07 ----D---- C:\windows\qwuk
2013-12-09 19:20:02 ----D---- C:\windows\ugog
2013-12-09 19:19:47 ----D---- C:\windows\jpeg
2013-12-09 19:19:36 ----D---- C:\windows\abah
2013-12-09 19:19:26 ----D---- C:\windows\ybab
2013-12-09 19:18:51 ----D---- C:\windows\qmos
2013-12-09 19:18:45 ----D---- C:\windows\inwq
2013-12-09 19:18:40 ----D---- C:\windows\xzem
2013-12-09 19:18:05 ----D---- C:\windows\lbec
2013-12-09 19:17:59 ----D---- C:\windows\qmus
2013-12-09 19:17:44 ----D---- C:\windows\iwyh
2013-12-09 19:17:39 ----D---- C:\windows\uqnl
2013-12-09 19:17:34 ----D---- C:\windows\bkyt
2013-12-09 19:17:14 ----D---- C:\windows\osec
2013-12-09 19:16:53 ----D---- C:\windows\ufuh
2013-12-09 19:16:48 ----D---- C:\windows\ixiv
2013-12-09 19:16:43 ----D---- C:\windows\epel
2013-12-09 19:16:28 ----D---- C:\windows\etqz
2013-12-09 19:16:22 ----D---- C:\windows\ydav
2013-12-09 19:16:17 ----D---- C:\windows\uhem
2013-12-09 19:16:12 ----D---- C:\windows\iraq
2013-12-09 19:16:07 ----D---- C:\windows\ocdz
2013-12-09 19:15:21 ----D---- C:\windows\avmr
2013-12-09 19:15:11 ----D---- C:\windows\acaf
2013-12-09 19:15:06 ----D---- C:\windows\uvug
2013-12-09 19:15:01 ----D---- C:\windows\upoq
2013-12-09 19:14:35 ----D---- C:\windows\rhof
2013-12-09 19:14:30 ----D---- C:\windows\iqkn
2013-12-09 19:14:25 ----D---- C:\windows\ehot
2013-12-09 19:14:20 ----D---- C:\windows\rmuz
2013-12-09 19:14:10 ----D---- C:\windows\urum
2013-12-09 19:13:54 ----D---- C:\windows\onej
2013-12-09 19:13:44 ----D---- C:\windows\ogoq
2013-12-09 19:13:34 ----D---- C:\windows\axyq
2013-12-09 19:13:24 ----D---- C:\windows\iteh
2013-12-09 19:13:14 ----D---- C:\windows\ibih
2013-12-09 19:13:08 ----D---- C:\windows\jvrg
2013-12-09 19:12:58 ----D---- C:\windows\ilkd
2013-12-09 19:12:38 ----D---- C:\windows\amyf
2013-12-09 19:12:28 ----D---- C:\windows\ubem
2013-12-09 19:12:17 ----D---- C:\windows\qkrz
2013-12-09 19:12:07 ----D---- C:\windows\ynag
2013-12-09 19:11:42 ----D---- C:\windows\yfsm
2013-12-09 19:11:26 ----D---- C:\windows\lluv
2013-12-09 19:11:16 ----D---- C:\windows\whis
2013-12-09 19:10:41 ----D---- C:\windows\elev
2013-12-09 19:10:20 ----D---- C:\windows\jfuw
2013-12-09 19:10:00 ----D---- C:\windows\ecuh
2013-12-09 19:09:44 ----D---- C:\windows\qgel
2013-12-09 19:09:24 ----D---- C:\windows\kxiq
2013-12-09 19:09:19 ----D---- C:\windows\oroj
2013-12-09 19:09:09 ----D---- C:\windows\ybys
2013-12-09 19:09:04 ----D---- C:\windows\ypij
2013-12-09 19:08:23 ----D---- C:\windows\wvyd
2013-12-09 19:08:13 ----D---- C:\windows\uspm
2013-12-09 19:08:02 ----D---- C:\windows\ityf
2013-12-09 19:07:57 ----D---- C:\windows\gjux
2013-12-09 19:07:42 ----D---- C:\windows\aqax
2013-12-09 19:07:37 ----D---- C:\windows\axzg
2013-12-09 19:07:16 ----D---- C:\windows\iqax
2013-12-09 19:06:56 ----D---- C:\windows\okoh
2013-12-09 19:06:51 ----D---- C:\windows\inyl
2013-12-09 19:06:46 ----D---- C:\windows\oqof
2013-12-09 19:06:36 ----D---- C:\windows\ujod
2013-12-09 19:06:30 ----D---- C:\windows\hbaz
2013-12-09 19:06:00 ----D---- C:\windows\ypkx
2013-12-09 19:05:55 ----D---- C:\windows\abaw
2013-12-09 19:05:44 ----D---- C:\windows\adyl
2013-12-09 19:05:34 ----D---- C:\windows\gvul
2013-12-09 19:05:14 ----D---- C:\windows\yxiv
2013-12-09 19:05:09 ----D---- C:\windows\ezom
2013-12-09 19:04:53 ----D---- C:\windows\uvdl
2013-12-09 19:04:33 ----D---- C:\windows\otob
2013-12-09 19:04:23 ----D---- C:\windows\qsxm
2013-12-09 19:04:13 ----D---- C:\windows\azsz
2013-12-09 19:04:08 ----D---- C:\windows\lqev
2013-12-09 19:03:57 ----D---- C:\windows\jjux
2013-12-09 19:03:52 ----D---- C:\windows\eleq
2013-12-09 19:03:47 ----D---- C:\windows\itik
2013-12-09 19:03:42 ----D---- C:\windows\exrd
2013-12-09 19:03:32 ----D---- C:\windows\rfeb
2013-12-09 19:03:22 ----D---- C:\windows\ssys
2013-12-09 19:03:16 ----D---- C:\windows\opog
2013-12-09 19:03:06 ----D---- C:\windows\ewec
2013-12-09 19:02:31 ----D---- C:\windows\ifsm
2013-12-09 19:02:25 ----D---- C:\windows\yhis
2013-12-09 19:02:20 ----D---- C:\windows\ovxg
2013-12-09 19:02:10 ----D---- C:\windows\dteb
2013-12-09 19:02:05 ----D---- C:\windows\irtq
2013-12-09 19:02:00 ----D---- C:\windows\nkos
2013-12-09 19:01:50 ----D---- C:\windows\iqzr
2013-12-09 19:01:34 ----D---- C:\windows\ilax
2013-12-09 19:00:33 ----D---- C:\windows\yqid
2013-12-09 19:00:23 ----D---- C:\windows\fgaj
2013-12-09 18:59:37 ----D---- C:\windows\ewrm
2013-12-09 18:59:27 ----D---- C:\windows\qgeg
2013-12-09 18:59:17 ----D---- C:\windows\onjn
2013-12-09 18:58:46 ----D---- C:\windows\amyt
2013-12-09 18:58:31 ----D---- C:\windows\jwok
2013-12-09 18:58:26 ----D---- C:\windows\aqhx
2013-12-09 18:58:21 ----D---- C:\windows\omgz
2013-12-09 18:58:16 ----D---- C:\windows\ubdk
2013-12-09 18:58:00 ----D---- C:\windows\ppog
2013-12-09 18:57:55 ----D---- C:\windows\ymyt
2013-12-09 18:57:50 ----D---- C:\windows\ecez
2013-12-09 18:57:40 ----D---- C:\windows\ixkp
2013-12-09 18:57:30 ----D---- C:\windows\ukpz
2013-12-09 18:57:24 ----D---- C:\windows\ijyv
2013-12-09 18:57:14 ----D---- C:\windows\ekpz
2013-12-09 18:56:54 ----D---- C:\windows\ihfw
2013-12-09 18:56:39 ----D---- C:\windows\kvij
2013-12-09 18:56:23 ----D---- C:\windows\agan
2013-12-09 18:56:18 ----D---- C:\windows\ufob
2013-12-09 18:55:58 ----D---- C:\windows\ipaj
2013-12-09 18:55:53 ----D---- C:\windows\owjc
2013-12-09 18:55:47 ----D---- C:\windows\ecph
2013-12-09 18:55:37 ----D---- C:\windows\eqov
2013-12-09 18:55:32 ----D---- C:\windows\tkyk
2013-12-09 18:55:27 ----D---- C:\windows\udoj
2013-12-09 18:55:17 ----D---- C:\windows\yfik
2013-12-09 18:55:12 ----D---- C:\windows\oqul
2013-12-09 18:55:02 ----D---- C:\windows\ejgr
2013-12-09 18:54:51 ----D---- C:\windows\idsq
2013-12-09 18:54:31 ----D---- C:\windows\jmos
2013-12-09 18:54:16 ----D---- C:\windows\ipyj
2013-12-09 18:54:11 ----D---- C:\windows\yrag
2013-12-09 18:54:05 ----D---- C:\windows\psjk
2013-12-09 18:54:00 ----D---- C:\windows\afak
2013-12-09 18:53:55 ----D---- C:\windows\upug
2013-12-09 18:53:45 ----D---- C:\windows\isaw
2013-12-09 18:53:35 ----D---- C:\windows\afik
2013-12-09 18:53:14 ----D---- C:\windows\orpr
2013-12-09 18:52:44 ----D---- C:\windows\yqyf
2013-12-09 18:52:39 ----D---- C:\windows\otub
2013-12-09 18:52:34 ----D---- C:\windows\osvt
2013-12-09 18:52:28 ----D---- C:\windows\slad
2013-12-09 18:52:23 ----D---- C:\windows\epop
2013-12-09 18:52:18 ----D---- C:\windows\ifat
2013-12-09 18:52:08 ----D---- C:\windows\emnz
2013-12-09 18:51:58 ----D---- C:\windows\yrwv
2013-12-09 18:51:53 ----D---- C:\windows\kral
2013-12-09 18:51:43 ----D---- C:\windows\qzem
2013-12-09 18:51:37 ----D---- C:\windows\esek
2013-12-09 18:51:27 ----D---- C:\windows\asah
2013-12-09 18:51:17 ----D---- C:\windows\ickt
2013-12-09 18:50:46 ----D---- C:\windows\jcph
2013-12-09 18:50:26 ----D---- C:\windows\upoj
2013-12-09 18:50:11 ----D---- C:\windows\hzaw
2013-12-09 18:49:50 ----D---- C:\windows\jqov
2013-12-09 18:49:04 ----D---- C:\windows\ufpb
2013-12-09 18:48:59 ----D---- C:\windows\tfkc
2013-12-09 18:48:44 ----D---- C:\windows\utej
2013-12-09 18:48:34 ----D---- C:\windows\yqix
2013-12-09 18:48:24 ----D---- C:\windows\ifam
2013-12-09 18:48:18 ----D---- C:\windows\drux
2013-12-09 18:48:08 ----D---- C:\windows\lxun
2013-12-09 18:47:48 ----D---- C:\windows\afim
2013-12-09 18:47:32 ----D---- C:\windows\akat
2013-12-09 18:47:17 ----D---- C:\windows\elpl
2013-12-09 18:46:57 ----D---- C:\windows\cmtf
2013-12-09 18:46:41 ----D---- C:\windows\cbah
2013-12-09 18:46:36 ----D---- C:\windows\owdf
2013-12-09 18:46:31 ----D---- C:\windows\igyx
2013-12-09 18:46:21 ----D---- C:\windows\uzuc
2013-12-09 18:46:16 ----D---- C:\windows\mvyj
2013-12-09 18:45:30 ----D---- C:\windows\ykwf
2013-12-09 18:45:25 ----D---- C:\windows\asas
2013-12-09 18:45:15 ----D---- C:\windows\itit
2013-12-09 18:45:10 ----D---- C:\windows\afsm
2013-12-09 18:45:04 ----D---- C:\windows\onvj
2013-12-09 18:44:59 ----D---- C:\windows\ugdq
2013-12-09 18:44:54 ----D---- C:\windows\adav
2013-12-09 18:44:49 ----D---- C:\windows\hlir
2013-12-09 18:44:39 ----D---- C:\windows\otos
2013-12-09 18:44:29 ----D---- C:\windows\ikif
2013-12-09 18:44:08 ----D---- C:\windows\ymhc
2013-12-09 18:44:03 ----D---- C:\windows\umej
2013-12-09 18:43:58 ----D---- C:\windows\ynap
2013-12-09 18:43:22 ----D---- C:\windows\lren
2013-12-09 18:43:12 ----D---- C:\windows\evev
2013-12-09 18:43:07 ----D---- C:\windows\oded
2013-12-09 18:43:02 ----D---- C:\windows\chas
2013-12-09 18:42:57 ----D---- C:\windows\evug
2013-12-09 18:42:36 ----D---- C:\windows\amit
2013-12-09 18:42:26 ----D---- C:\windows\ywyb
2013-12-09 18:42:21 ----D---- C:\windows\atat
2013-12-09 18:42:16 ----D---- C:\windows\qrud
2013-12-09 18:41:56 ----D---- C:\windows\awzs
2013-12-09 18:41:51 ----D---- C:\windows\egql
2013-12-09 18:41:35 ----D---- C:\windows\axwp
2013-12-09 18:41:15 ----D---- C:\windows\ebok
2013-12-09 18:41:10 ----D---- C:\windows\omuz
2013-12-09 18:41:05 ----D---- C:\windows\avax
2013-12-09 18:41:00 ----D---- C:\windows\ukuh
2013-12-09 18:40:44 ----D---- C:\windows\ivin
2013-12-09 18:40:39 ----D---- C:\windows\lkeb
2013-12-09 18:40:19 ----D---- C:\windows\xset
2013-12-09 18:40:14 ----D---- C:\windows\utus
2013-12-09 18:40:09 ----D---- C:\windows\adag
2013-12-09 18:39:58 ----D---- C:\windows\uror
2013-12-09 18:39:53 ----D---- C:\windows\ulol
2013-12-09 18:39:43 ----D---- C:\windows\pzoc
2013-12-09 18:39:33 ----D---- C:\windows\yxfv
2013-12-09 18:39:02 ----D---- C:\windows\ekuw
2013-12-09 18:38:21 ----D---- C:\windows\afyk
2013-12-09 18:38:06 ----D---- C:\windows\amic
2013-12-09 18:38:01 ----D---- C:\windows\arox
2013-12-09 18:37:46 ----D---- C:\windows\oxoj
2013-12-09 18:37:35 ----D---- C:\windows\imyc
2013-12-09 18:37:30 ----D---- C:\windows\enox
2013-12-09 18:37:20 ----D---- C:\windows\uzef
2013-12-09 18:37:05 ----D---- C:\windows\oset
2013-12-09 18:36:29 ----D---- C:\windows\atkc
2013-12-09 18:36:14 ----D---- C:\windows\epeq
2013-12-09 18:36:09 ----D---- C:\windows\afft
2013-12-09 18:35:59 ----D---- C:\windows\pdgj
2013-12-09 18:35:53 ----D---- C:\windows\tsfh
2013-12-09 18:35:48 ----D---- C:\windows\uner
2013-12-09 18:35:33 ----D---- C:\windows\rzot
2013-12-09 18:35:28 ----D---- C:\windows\omxs
2013-12-09 18:35:13 ----D---- C:\windows\ypyx
2013-12-09 18:35:07 ----D---- C:\windows\mhyb
2013-12-09 18:34:47 ----D---- C:\windows\ocub
2013-12-09 18:34:32 ----D---- C:\windows\ugup
2013-12-09 18:34:22 ----D---- C:\windows\omus
2013-12-09 18:34:16 ----D---- C:\windows\ynip
2013-12-09 18:34:06 ----D---- C:\windows\ehuf
2013-12-09 18:33:56 ----D---- C:\windows\ekeh
2013-12-09 18:33:41 ----D---- C:\windows\ylyj
2013-12-09 18:33:36 ----D---- C:\windows\emez
2013-12-09 18:32:50 ----D---- C:\windows\evvl
2013-12-09 18:32:34 ----D---- C:\windows\uhec
2013-12-09 18:32:29 ----D---- C:\windows\mryp
2013-12-09 18:32:24 ----D---- C:\windows\usok
2013-12-09 18:32:14 ----D---- C:\windows\izah
2013-12-09 18:31:54 ----D---- C:\windows\ydip
2013-12-09 18:31:49 ----D---- C:\windows\ehuk
2013-12-09 18:31:43 ----D---- C:\windows\pguv
2013-12-09 18:31:38 ----D---- C:\windows\ytak
2013-12-09 18:31:18 ----D---- C:\windows\ynal
2013-12-09 18:30:57 ----D---- C:\windows\ezec
2013-12-09 18:30:52 ----D---- C:\windows\ypyd
2013-12-09 18:30:47 ----D---- C:\windows\axav
2013-12-09 18:30:42 ----D---- C:\windows\okos
2013-12-09 18:30:32 ----D---- C:\windows\yqmx
2013-12-09 18:30:01 ----D---- C:\windows\lsok
2013-12-09 18:29:56 ----D---- C:\windows\alan
2013-12-09 18:29:46 ----D---- C:\windows\apyx
2013-12-09 18:29:41 ----D---- C:\windows\ictf
2013-12-09 18:29:36 ----D---- C:\windows\nrex
2013-12-09 18:29:15 ----D---- C:\windows\ikak
2013-12-09 18:29:00 ----D---- C:\windows\ipid
2013-12-09 18:28:55 ----D---- C:\windows\umes
2013-12-09 18:28:45 ----D---- C:\windows\ibab
2013-12-09 18:28:40 ----D---- C:\windows\iriv
2013-12-09 18:28:35 ----D---- C:\windows\ozut
2013-12-09 18:28:30 ----D---- C:\windows\iqhn
2013-12-09 18:28:24 ----D---- C:\windows\rfus
2013-12-09 18:28:14 ----D---- C:\windows\afzc
2013-12-09 18:27:33 ----D---- C:\windows\ihis
2013-12-09 18:27:23 ----D---- C:\windows\ulug
2013-12-09 18:27:13 ----D---- C:\windows\ljod
2013-12-09 18:27:08 ----D---- C:\windows\ckyf
2013-12-09 18:27:03 ----D---- C:\windows\nxoj
2013-12-09 18:26:58 ----D---- C:\windows\wbyz
2013-12-09 18:26:53 ----D---- C:\windows\ttit
2013-12-09 18:26:47 ----D---- C:\windows\oxux
2013-12-09 18:26:42 ----D---- C:\windows\iziz
2013-12-09 18:26:17 ----D---- C:\windows\stat
2013-12-09 18:26:12 ----D---- C:\windows\ejej
2013-12-09 18:26:02 ----D---- C:\windows\dtos
2013-12-09 18:25:51 ----D---- C:\windows\uhef
2013-12-09 18:25:46 ----D---- C:\windows\gqwn
2013-12-09 18:25:41 ----D---- C:\windows\acim
2013-12-09 18:25:36 ----D---- C:\windows\ybyz
2013-12-09 18:25:26 ----D---- C:\windows\atac
2013-12-09 18:25:21 ----D---- C:\windows\yvaj
2013-12-09 18:25:05 ----D---- C:\windows\hpax
2013-12-09 18:25:00 ----D---- C:\windows\etus
2013-12-09 18:24:40 ----D---- C:\windows\emus
2013-12-09 18:24:35 ----D---- C:\windows\ytkc
2013-12-09 18:24:20 ----D---- C:\windows\opop
2013-12-09 18:24:14 ----D---- C:\windows\odoj
2013-12-09 18:24:04 ----D---- C:\windows\emoz
2013-12-09 18:23:59 ----D---- C:\windows\tqyx
2013-12-09 18:23:39 ----D---- C:\windows\ozlf
2013-12-09 18:23:28 ----D---- C:\windows\yphj
2013-12-09 18:23:23 ----D---- C:\windows\jkew
2013-12-09 18:23:13 ----D---- C:\windows\lgop
2013-12-09 18:22:58 ----D---- C:\windows\uxld
2013-12-09 18:22:32 ----D---- C:\windows\ddox
2013-12-09 18:22:27 ----D---- C:\windows\hhyb
2013-12-09 18:22:22 ----D---- C:\windows\yrzq
2013-12-09 18:22:17 ----D---- C:\windows\wgyr
2013-12-09 18:22:12 ----D---- C:\windows\okuh
2013-12-09 18:22:02 ----D---- C:\windows\ebec
2013-12-09 18:21:57 ----D---- C:\windows\oklh
2013-12-09 18:21:31 ----D---- C:\windows\ijag
2013-12-09 18:21:21 ----D---- C:\windows\ucuh
2013-12-09 18:21:11 ----D---- C:\windows\olev
2013-12-09 18:20:55 ----D---- C:\windows\uqop
2013-12-09 18:20:45 ----D---- C:\windows\agyj
2013-12-09 18:20:40 ----D---- C:\windows\inip
2013-12-09 18:20:35 ----D---- C:\windows\amkm
2013-12-09 18:20:20 ----D---- C:\windows\ikyk
2013-12-09 18:20:09 ----D---- C:\windows\ekoh
2013-12-09 18:19:54 ----D---- C:\windows\gmuh
2013-12-09 18:19:39 ----D---- C:\windows\ejuj
2013-12-09 18:19:34 ----D---- C:\windows\ahaz
2013-12-09 18:19:13 ----D---- C:\windows\gdgd
2013-12-09 18:19:03 ----D---- C:\windows\ycak
2013-12-09 18:18:53 ----D---- C:\windows\yhms
2013-12-09 18:18:29 ----D---- C:\windows\ubeg
2013-12-09 18:18:20 ----D---- C:\windows\eteb
2013-12-09 18:18:10 ----D---- C:\windows\omob
2013-12-09 18:18:02 ----D---- C:\windows\ydfp
2013-12-09 18:17:48 ----D---- C:\windows\abab
2013-12-09 18:17:29 ----D---- C:\windows\ehoc
2013-12-09 18:17:19 ----D---- C:\windows\jqog
2013-12-09 18:16:56 ----D---- C:\windows\fmaf
2013-12-09 18:16:35 ----D---- C:\windows\yhwh
2013-12-09 18:16:25 ----D---- C:\windows\wnyq
2013-12-09 18:16:04 ----D---- C:\windows\yvyx
2013-12-09 18:15:59 ----D---- C:\windows\ezus
2013-12-09 18:15:54 ----D---- C:\windows\ilsx
2013-12-09 18:15:49 ----D---- C:\windows\tlin
2013-12-09 18:15:44 ----D---- C:\windows\okeb
2013-12-09 18:15:39 ----D---- C:\windows\ammc
2013-12-09 18:15:34 ----D---- C:\windows\udur
2013-12-09 18:15:28 ----D---- C:\windows\uzet
2013-12-09 18:15:18 ----D---- C:\windows\idyv
2013-12-09 18:14:48 ----D---- C:\windows\uhoc
2013-12-09 18:14:37 ----D---- C:\windows\agij
2013-12-09 18:14:27 ----D---- C:\windows\svar
2013-12-09 18:14:17 ----D---- C:\windows\aqan
2013-12-09 18:14:12 ----D---- C:\windows\ucuz
2013-12-09 18:14:07 ----D---- C:\windows\pwuc
2013-12-09 18:13:46 ----D---- C:\windows\xnrd
2013-12-09 18:13:36 ----D---- C:\windows\idyq
2013-12-09 18:13:26 ----D---- C:\windows\ocus
2013-12-09 18:13:21 ----D---- C:\windows\owuk
2013-12-09 18:13:10 ----D---- C:\windows\ysiw
2013-12-09 18:13:05 ----D---- C:\windows\ytat
2013-12-09 18:13:00 ----D---- C:\windows\oder
2013-12-09 18:12:55 ----D---- C:\windows\rhok
2013-12-09 18:12:50 ----D---- C:\windows\apid
2013-12-09 18:12:40 ----D---- C:\windows\rrdd
2013-12-09 18:12:30 ----D---- C:\windows\isyw
2013-12-09 18:12:04 ----D---- C:\windows\utos
2013-12-09 18:11:49 ----D---- C:\windows\efos
2013-12-09 18:11:23 ----D---- C:\windows\zkac
2013-12-09 18:11:07 ----D---- C:\windows\rsoc
2013-12-09 18:11:02 ----D---- C:\windows\ajaq
2013-12-09 18:10:57 ----D---- C:\windows\umuh
2013-12-09 18:10:47 ----D---- C:\windows\odnd
2013-12-09 18:10:31 ----D---- C:\windows\ajav
2013-12-09 18:10:20 ----D---- C:\windows\umym
2013-12-09 18:10:10 ----D---- C:\windows\ekez
2013-12-09 18:10:00 ----D---- C:\windows\kxyq
2013-12-09 18:09:49 ----D---- C:\windows\ilin
2013-12-09 18:09:34 ----D---- C:\windows\ydil
2013-12-09 18:09:24 ----D---- C:\windows\ovog
2013-12-09 18:09:14 ----D---- C:\windows\icik
2013-12-09 18:09:08 ----D---- C:\windows\rxjr
2013-12-09 18:09:03 ----D---- C:\windows\azyw
2013-12-09 18:08:48 ----D---- C:\windows\unud
2013-12-09 18:08:37 ----D---- C:\windows\erpr
2013-12-09 18:08:27 ----D---- C:\windows\scyt
2013-12-09 18:08:22 ----D---- C:\windows\ygit
2013-12-09 18:08:11 ----D---- C:\windows\ocew
2013-12-09 18:07:51 ----D---- C:\windows\uqgl
2013-12-09 18:07:30 ----D---- C:\windows\uzjt
2013-12-09 18:07:14 ----D---- C:\windows\iftc