mozila a vyskakujuce reklamy
Napsal: 26 úno 2010 16:38
ahojte moj problem spociva v tom ze mi vyskakuju reklamy ,ale nie v novom okne ale v aktulnom ktore používam , je jedno na akej stranke som (v nastaveniach ich mam vypnute)
Logfile of random's system information tool 1.06 (written by random/random)
Run by Esperian at 2010-02-26 16:22:59
Microsoft® Windows Vista™ Home Basic Service Pack 2
System drive C: has 60 GB (57%) free of 105 GB
Total RAM: 1790 MB (42% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:23:29, on 26. 2. 2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.Exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Ares\Ares.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Crawler\CToolbar.exe
C:\Users\Esperian\Downloads\RSIT.exe
C:\Program Files\trend micro\Esperian.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... io&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatche ... tbid=60347
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dymasearch.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... io&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... io&pf=cnnb
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: dymanet - {0ac89f42-45b9-ab77-69e4-ce07c5a93ec7} - C:\Windows\system32\9bde048a-7ed2-a7ef-69ec-5aec1d017869.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\ctbr.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [B2C_AGENT] C:\ProgramData\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [SpywareTerminatorUpdate] "C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\ctbr.dll
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: Služba Google Update (gupdate1caa5b117bd44c5) (gupdate1caa5b117bd44c5) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 7911 bytes
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\HPCeeScheduleForEsperian.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-23 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0ac89f42-45b9-ab77-69e4-ce07c5a93ec7}]
dymanet - C:\Windows\system32\9bde048a-7ed2-a7ef-69ec-5aec1d017869.dll [2010-01-30 1935360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
C:\PROGRA~1\Crawler\ctbr.dll [2010-01-29 1230184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll [2008-02-22 509328]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2010-01-03 1019128]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
{4B3803EA-5230-4DC3-A7FC-33638F3D3542} - &Crawler Toolbar - C:\PROGRA~1\Crawler\ctbr.dll [2010-01-29 1230184]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-04-17 1049896]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"MSSE"=c:\Program Files\Microsoft Security Essentials\msseces.exe [2009-09-13 1048392]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2010-01-26 2166784]
"B2C_AGENT"=C:\ProgramData\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe [2009-06-15 182208]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-11-10 417792]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2009-07-23 13797920]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-06-27 152872]
"ares"=C:\Program Files\Ares\Ares.exe [2010-01-22 1011712]
"SpywareTerminatorUpdate"=C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [2010-01-26 3037696]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883840]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2007-05-11 40048]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
C:\Program Files\Ares\Ares.exe [2010-01-22 1011712]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-04-15 70912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2006-12-10 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2008-04-15 488752]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
C:\Program Files\ICQ7.0\ICQ.exe [2010-01-12 133368]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2008-02-26 2289664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\MSN Messenger\MsnMsgr.Exe /background []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl.exe]
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2008-03-14 202032]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
C:\Program Files\HP\QuickPlay\QPService.exe [2008-04-01 468264]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe [2009-10-09 25623336]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdate]
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [2010-01-26 3037696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe [2008-02-22 144784]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UCam_Menu]
C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [2007-12-24 222504]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2007-01-02 210520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Esperian^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Stardock ObjectDock.lnk]
C:\PROGRA~1\Stardock\OBJECT~1\OBJECT~1.EXE [2007-04-30 3450608]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======List of files/folders created in the last 1 months======
2010-02-26 16:22:59 ----D---- C:\rsit
2010-02-26 16:22:59 ----D---- C:\Program Files\trend micro
2010-02-26 14:31:48 ----D---- C:\Program Files\Crawler
2010-02-24 11:36:48 ----A---- C:\Windows\system32\tzres.dll
2010-02-24 11:36:17 ----A---- C:\Windows\system32\secproc_isv.dll
2010-02-24 11:36:16 ----A---- C:\Windows\system32\secproc.dll
2010-02-24 11:36:14 ----A---- C:\Windows\system32\RMActivate_isv.exe
2010-02-24 11:36:13 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2010-02-24 11:36:13 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2010-02-24 11:36:13 ----A---- C:\Windows\system32\RMActivate.exe
2010-02-24 11:36:12 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2010-02-24 11:36:12 ----A---- C:\Windows\system32\secproc_ssp.dll
2010-02-24 11:36:12 ----A---- C:\Windows\system32\msdrm.dll
2010-02-24 11:36:10 ----A---- C:\Windows\system32\gameux.dll
2010-02-24 11:36:08 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2010-02-24 11:36:08 ----A---- C:\Windows\system32\Apphlpdm.dll
2010-02-21 02:27:24 ----D---- C:\Program Files\SopCast
2010-02-18 19:00:33 ----D---- C:\72c92e84267b60dea49239
2010-02-16 20:38:44 ----A---- C:\Windows\CmdPrint.INI
2010-02-16 18:48:47 ----A---- C:\Windows\NeroDigital.ini
2010-02-16 18:34:58 ----D---- C:\ProgramData\InstallShield
2010-02-16 18:34:46 ----D---- C:\Users\Esperian\AppData\Roaming\Corel
2010-02-16 18:33:20 ----D---- C:\Program Files\Common Files\Corel
2010-02-16 18:29:23 ----D---- C:\Program Files\Corel
2010-02-14 18:31:28 ----A---- C:\Windows\system32\NCTImageFile.dll
2010-02-14 18:31:22 ----A---- C:\Windows\system32\NCTVideoView.dll
2010-02-14 18:31:19 ----A---- C:\Windows\system32\NCTVideoFile.dll
2010-02-14 18:31:15 ----A---- C:\Windows\system32\NCTQuickTimeFile.dll
2010-02-14 18:31:14 ----A---- C:\Windows\system32\NCTRMFile.dll
2010-02-14 18:31:11 ----A---- C:\Windows\system32\NCTWMVFile.dll
2010-02-14 18:31:03 ----A---- C:\Windows\system32\NCTVideoCoreM.dll
2010-02-14 18:30:56 ----A---- C:\Windows\system32\NCTAVIFile.dll
2010-02-14 18:30:55 ----A---- C:\Windows\system32\NCTVideoCompress.dll
2010-02-14 18:30:55 ----A---- C:\Windows\system32\NCTAudioFormatSettings3.dll
2010-02-14 18:30:54 ----A---- C:\Windows\system32\NCTAudioCompress3.dll
2010-02-14 18:30:53 ----A---- C:\Windows\system32\NCTAudioCompress2.dll
2010-02-14 18:30:53 ----A---- C:\Windows\system32\msvcr70.dll
2010-02-14 18:30:53 ----A---- C:\Windows\system32\msvcp70.dll
2010-02-14 18:30:52 ----A---- C:\Windows\system32\lame_enc.dll
2010-02-14 18:30:45 ----D---- C:\Windows\system32\RMBin
2010-02-14 18:30:45 ----A---- C:\Windows\system32\viscomwave.dll
2010-02-14 18:30:45 ----A---- C:\Windows\system32\viscomqtenc.dll
2010-02-14 18:30:45 ----A---- C:\Windows\system32\SkinCrafter.dll
2010-02-14 18:30:44 ----A---- C:\Windows\system32\viscomqtde.dll
2010-02-14 18:30:37 ----D---- C:\Program Files\A-one Video Convertor
2010-02-14 17:45:05 ----A---- C:\Windows\system32\0dbfcd86-827d-ea0f-cfa6-5a8c9fbfbfa2.exe
2010-02-12 18:20:20 ----D---- C:\Users\Esperian\AppData\Roaming\ABBYY
2010-02-12 18:16:50 ----D---- C:\Program Files\ABBYY FineReader 8.0 Professional Edition
2010-02-12 18:06:07 ----D---- C:\temp
2010-02-12 17:08:31 ----D---- C:\Program Files\Microsoft Silverlight
2010-02-12 17:07:56 ----DC---- C:\Windows\system32\DRVSTORE
2010-02-12 17:06:30 ----D---- C:\Program Files\Microsoft Sync Framework
2010-02-12 17:04:29 ----A---- C:\Windows\system32\d3dx9_32.dll
2010-02-12 17:04:12 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2010-02-12 17:02:08 ----D---- C:\Program Files\Microsoft
2010-02-12 17:01:37 ----D---- C:\Program Files\Windows Live SkyDrive
2010-02-12 17:01:23 ----D---- C:\Program Files\Windows Live
2010-02-12 16:51:10 ----D---- C:\Program Files\Common Files\Windows Live
2010-02-10 19:59:36 ----D---- C:\Users\Esperian\AppData\Roaming\foobar2000
2010-02-10 19:58:59 ----D---- C:\Program Files\foobar2000
2010-02-10 07:36:31 ----A---- C:\Windows\system32\ntoskrnl.exe
2010-02-10 07:36:31 ----A---- C:\Windows\system32\ntkrnlpa.exe
2010-02-10 07:36:15 ----A---- C:\Windows\system32\quartz.dll
2010-02-10 07:36:13 ----A---- C:\Windows\system32\tsbyuv.dll
2010-02-10 07:36:13 ----A---- C:\Windows\system32\msyuv.dll
2010-02-10 07:36:13 ----A---- C:\Windows\system32\msvidc32.dll
2010-02-10 07:36:13 ----A---- C:\Windows\system32\msrle32.dll
2010-02-10 07:36:12 ----A---- C:\Windows\system32\iyuv_32.dll
2010-02-10 07:36:11 ----A---- C:\Windows\system32\mciavi32.dll
2010-02-10 07:36:10 ----A---- C:\Windows\system32\msvfw32.dll
2010-02-10 07:36:10 ----A---- C:\Windows\system32\avifil32.dll
2010-02-08 21:07:24 ----D---- C:\Users\Esperian\AppData\Roaming\Opera
2010-02-08 21:04:00 ----D---- C:\Program Files\Opera
2010-02-07 20:32:06 ----D---- C:\Users\Esperian\AppData\Roaming\CyberLink
2010-02-07 15:54:16 ----D---- C:\ProgramData\Apple Computer
2010-02-07 15:54:16 ----D---- C:\Program Files\QuickTime
2010-02-07 15:53:08 ----D---- C:\Program Files\Common Files\Apple
2010-02-07 15:52:48 ----D---- C:\Program Files\Apple Software Update
2010-02-07 15:52:47 ----D---- C:\ProgramData\Apple
2010-02-05 19:05:42 ----D---- C:\Program Files\DIFX
2010-02-05 19:05:19 ----D---- C:\Program Files\infineon
2010-02-05 19:03:59 ----D---- C:\Program Files\LG Electronics
2010-02-05 19:02:08 ----D---- C:\KP500
2010-02-05 19:01:05 ----A---- C:\Windows\system32\lgAxconfig.ini
2010-02-05 19:01:05 ----A---- C:\Windows\system32\CommonDL.dll
2010-02-05 19:00:50 ----D---- C:\ProgramData\LGMOBILEAX
2010-02-04 20:53:32 ----D---- C:\Users\Esperian\AppData\Roaming\DivX
2010-02-04 16:46:21 ----D---- C:\Program Files\Common Files\PX Storage Engine
2010-02-04 16:45:10 ----D---- C:\Program Files\Google
2010-02-04 16:45:10 ----D---- C:\Program Files\Common Files\DivX Shared
2010-02-04 16:45:09 ----D---- C:\Program Files\DivX
2010-01-31 21:20:21 ----D---- C:\Program Files\Paint.NET
2010-01-30 11:55:32 ----A---- C:\Windows\system32\9bde048a-7ed2-a7ef-69ec-5aec1d017869.dll
2010-01-29 16:56:45 ----D---- C:\Program Files\Windows Portable Devices
2010-01-29 16:52:15 ----A---- C:\Windows\system32\UIAnimation.dll
2010-01-29 16:52:13 ----A---- C:\Windows\system32\UIRibbonRes.dll
2010-01-29 16:52:12 ----A---- C:\Windows\system32\UIRibbon.dll
2010-01-29 16:51:33 ----A---- C:\Windows\system32\WMPhoto.dll
2010-01-29 16:51:30 ----A---- C:\Windows\system32\cdd.dll
2010-01-29 16:51:28 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll
2010-01-29 16:51:28 ----A---- C:\Windows\system32\d3d10warp.dll
2010-01-29 16:51:27 ----A---- C:\Windows\system32\XpsRasterService.dll
2010-01-29 16:51:27 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2010-01-29 16:51:27 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2010-01-29 16:51:27 ----A---- C:\Windows\system32\WindowsCodecs.dll
2010-01-29 16:51:27 ----A---- C:\Windows\system32\dxdiagn.dll
2010-01-29 16:51:27 ----A---- C:\Windows\system32\d2d1.dll
2010-01-29 16:51:26 ----A---- C:\Windows\system32\xpsservices.dll
2010-01-29 16:51:26 ----A---- C:\Windows\system32\XpsPrint.dll
2010-01-29 16:51:26 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
2010-01-29 16:51:26 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
2010-01-29 16:51:26 ----A---- C:\Windows\system32\OpcServices.dll
2010-01-29 16:51:26 ----A---- C:\Windows\system32\dxdiag.exe
2010-01-29 16:51:25 ----A---- C:\Windows\system32\FntCache.dll
2010-01-29 16:51:25 ----A---- C:\Windows\system32\dxgi.dll
2010-01-29 16:51:25 ----A---- C:\Windows\system32\DWrite.dll
2010-01-29 16:51:25 ----A---- C:\Windows\system32\d3d11.dll
2010-01-29 16:51:25 ----A---- C:\Windows\system32\d3d10level9.dll
2010-01-29 16:51:25 ----A---- C:\Windows\system32\d3d10core.dll
2010-01-29 16:51:25 ----A---- C:\Windows\system32\d3d10_1core.dll
2010-01-29 16:51:25 ----A---- C:\Windows\system32\d3d10_1.dll
2010-01-29 16:51:25 ----A---- C:\Windows\system32\d3d10.dll
2010-01-29 16:50:46 ----A---- C:\Windows\system32\WPDShextAutoplay.exe
2010-01-29 16:50:46 ----A---- C:\Windows\system32\BthMtpContextHandler.dll
2010-01-29 16:50:45 ----A---- C:\Windows\system32\wpdbusenum.dll
2010-01-29 16:50:40 ----A---- C:\Windows\system32\PortableDeviceConnectApi.dll
2010-01-29 16:50:34 ----A---- C:\Windows\system32\wpdshext.dll
2010-01-29 16:50:34 ----A---- C:\Windows\system32\wpd_ci.dll
2010-01-29 16:50:33 ----A---- C:\Windows\system32\WPDSp.dll
2010-01-29 16:50:33 ----A---- C:\Windows\system32\WPDShServiceObj.dll
2010-01-29 16:50:33 ----A---- C:\Windows\system32\PortableDeviceWMDRM.dll
2010-01-29 16:50:33 ----A---- C:\Windows\system32\PortableDeviceTypes.dll
2010-01-29 16:50:33 ----A---- C:\Windows\system32\PortableDeviceClassExtension.dll
2010-01-29 16:50:33 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2010-01-29 16:49:31 ----A---- C:\Windows\system32\oleaccrc.dll
2010-01-29 16:49:30 ----A---- C:\Windows\system32\UIAutomationCore.dll
2010-01-29 16:49:30 ----A---- C:\Windows\system32\oleacc.dll
2010-01-29 13:05:16 ----D---- C:\Users\Esperian\AppData\Roaming\Media Player Classic
2010-01-28 18:59:48 ----D---- C:\Windows\system32\vi-VN
2010-01-28 18:59:48 ----D---- C:\Windows\system32\eu-ES
2010-01-28 18:59:48 ----D---- C:\Windows\system32\ca-ES
2010-01-28 18:33:39 ----D---- C:\Windows\system32\SPReview
2010-01-28 18:16:37 ----A---- C:\Windows\system32\scavenge.dll
2010-01-28 18:16:07 ----A---- C:\Windows\system32\compcln.exe
2010-01-28 18:05:04 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2010-01-28 18:05:04 ----A---- C:\Windows\system32\SearchIndexer.exe
2010-01-28 18:05:04 ----A---- C:\Windows\system32\SearchFilterHost.exe
2010-01-28 18:05:03 ----A---- C:\Windows\system32\sdohlp.dll
2010-01-28 18:05:03 ----A---- C:\Windows\system32\sdclt.exe
2010-01-28 18:05:03 ----A---- C:\Windows\system32\rtffilt.dll
2010-01-28 18:05:03 ----A---- C:\Windows\system32\rsaenh.dll
2010-01-28 18:05:02 ----A---- C:\Windows\system32\samlib.dll
2010-01-28 18:05:02 ----A---- C:\Windows\system32\rtutils.dll
2010-01-28 18:05:02 ----A---- C:\Windows\system32\riched20.dll
2010-01-28 18:05:01 ----A---- C:\Windows\system32\scrrun.dll
2010-01-28 18:05:01 ----A---- C:\Windows\system32\rpchttp.dll
2010-01-28 18:05:01 ----A---- C:\Windows\system32\rpcss.dll
2010-01-28 18:05:00 ----A---- C:\Windows\system32\SCardSvr.dll
2010-01-28 18:05:00 ----A---- C:\Windows\system32\scansetting.dll
2010-01-28 18:05:00 ----A---- C:\Windows\system32\samsrv.dll
2010-01-28 18:04:57 ----A---- C:\Windows\system32\schedsvc.dll
2010-01-28 18:04:57 ----A---- C:\Windows\system32\scrobj.dll
2010-01-28 18:04:57 ----A---- C:\Windows\system32\scksp.dll
2010-01-28 18:04:57 ----A---- C:\Windows\system32\scesrv.dll
2010-01-28 18:04:57 ----A---- C:\Windows\system32\scecli.dll
2010-01-28 18:04:55 ----A---- C:\Windows\system32\perfdisk.dll
2010-01-28 18:04:55 ----A---- C:\Windows\system32\PerfCenterCPL.dll
2010-01-28 18:04:55 ----A---- C:\Windows\system32\pdh.dll
2010-01-28 18:04:55 ----A---- C:\Windows\system32\pcaui.dll
2010-01-28 18:04:55 ----A---- C:\Windows\system32\p2psvc.dll
2010-01-28 18:04:55 ----A---- C:\Windows\system32\P2PGraph.dll
2010-01-28 18:04:54 ----A---- C:\Windows\system32\powercpl.dll
2010-01-28 18:04:54 ----A---- C:\Windows\system32\PNPXAssoc.dll
2010-01-28 18:04:54 ----A---- C:\Windows\system32\PnPutil.exe
2010-01-28 18:04:54 ----A---- C:\Windows\system32\PnPUnattend.exe
2010-01-28 18:04:54 ----A---- C:\Windows\system32\pnpui.dll
2010-01-28 18:04:54 ----A---- C:\Windows\system32\pnpsetup.dll
2010-01-28 18:04:54 ----A---- C:\Windows\system32\pnidui.dll
2010-01-28 18:04:53 ----A---- C:\Windows\system32\pidgenx.dll
2010-01-28 18:04:53 ----A---- C:\Windows\system32\photowiz.dll
2010-01-28 18:04:52 ----A---- C:\Windows\system32\PkgMgr.exe
2010-01-28 18:04:52 ----A---- C:\Windows\system32\ntdll.dll
2010-01-28 18:04:52 ----A---- C:\Windows\system32\nslookup.exe
2010-01-28 18:04:51 ----A---- C:\Windows\system32\NlsLexicons0009.dll
2010-01-28 18:04:50 ----A---- C:\Windows\system32\oleaut32.dll
2010-01-28 18:04:50 ----A---- C:\Windows\system32\ole32.dll
2010-01-28 18:04:50 ----A---- C:\Windows\system32\offfilt.dll
2010-01-28 18:04:50 ----A---- C:\Windows\system32\odbc32.dll
2010-01-28 18:04:50 ----A---- C:\Windows\system32\NlsLexicons0007.dll
2010-01-28 18:04:50 ----A---- C:\Windows\system32\nlhtml.dll
2010-01-28 18:04:49 ----A---- C:\Windows\system32\osk.exe
2010-01-28 18:04:49 ----A---- C:\Windows\system32\oobefldr.dll
2010-01-28 18:04:49 ----A---- C:\Windows\system32\onex.dll
2010-01-28 18:04:49 ----A---- C:\Windows\system32\olepro32.dll
2010-01-28 18:04:49 ----A---- C:\Windows\system32\oleprn.dll
2010-01-28 18:04:49 ----A---- C:\Windows\system32\odbccp32.dll
2010-01-28 18:04:49 ----A---- C:\Windows\system32\odbcconf.dll
2010-01-28 18:04:48 ----A---- C:\Windows\system32\rasgcw.dll
2010-01-28 18:04:48 ----A---- C:\Windows\system32\rasdlg.dll
2010-01-28 18:04:48 ----A---- C:\Windows\system32\rasdial.exe
2010-01-28 18:04:48 ----A---- C:\Windows\system32\ocsetup.exe
2010-01-28 18:04:48 ----A---- C:\Windows\system32\occache.dll
2010-01-28 18:04:48 ----A---- C:\Windows\system32\ntprint.dll
2010-01-28 18:04:48 ----A---- C:\Windows\system32\ntmarta.dll
2010-01-28 18:04:47 ----A---- C:\Windows\system32\rastapi.dll
2010-01-28 18:04:47 ----A---- C:\Windows\system32\rasppp.dll
2010-01-28 18:04:47 ----A---- C:\Windows\system32\rasplap.dll
2010-01-28 18:04:47 ----A---- C:\Windows\system32\rasmontr.dll
2010-01-28 18:04:47 ----A---- C:\Windows\system32\rasmans.dll
2010-01-28 18:04:47 ----A---- C:\Windows\system32\raschap.dll
2010-01-28 18:04:47 ----A---- C:\Windows\system32\rasdiag.dll
2010-01-28 18:04:47 ----A---- C:\Windows\system32\rasapi32.dll
2010-01-28 18:04:47 ----A---- C:\Windows\system32\Query.dll
2010-01-28 18:04:47 ----A---- C:\Windows\system32\qedit.dll
2010-01-28 18:04:46 ----A---- C:\Windows\system32\RelMon.dll
2010-01-28 18:04:46 ----A---- C:\Windows\system32\rekeywiz.exe
2010-01-28 18:04:46 ----A---- C:\Windows\system32\regsvc.dll
2010-01-28 18:04:46 ----A---- C:\Windows\system32\RacEngn.dll
2010-01-28 18:04:46 ----A---- C:\Windows\system32\qmgr.dll
2010-01-28 18:04:45 ----A---- C:\Windows\system32\regapi.dll
2010-01-28 18:04:45 ----A---- C:\Windows\system32\reg.exe
2010-01-28 18:04:45 ----A---- C:\Windows\system32\rdpwsx.dll
2010-01-28 18:04:45 ----A---- C:\Windows\system32\rdpencom.dll
2010-01-28 18:04:44 ----A---- C:\Windows\system32\prnntfy.dll
2010-01-28 18:04:44 ----A---- C:\Windows\system32\printui.dll
2010-01-28 18:04:44 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
2010-01-28 18:04:44 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2010-01-28 18:04:44 ----A---- C:\Windows\system32\PresentationHost.exe
2010-01-28 18:04:43 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2010-01-28 18:04:43 ----A---- C:\Windows\system32\powrprof.dll
2010-01-28 18:04:42 ----A---- C:\Windows\system32\puiapi.dll
2010-01-28 18:04:41 ----A---- C:\Windows\system32\qdvd.dll
2010-01-28 18:04:41 ----A---- C:\Windows\system32\QAGENTRT.DLL
2010-01-28 18:04:41 ----A---- C:\Windows\system32\propsys.dll
2010-01-28 18:04:41 ----A---- C:\Windows\system32\propdefs.dll
2010-01-28 18:04:41 ----A---- C:\Windows\system32\profsvc.dll
2010-01-28 18:04:40 ----A---- C:\Windows\system32\psisdecd.dll
2010-01-28 18:04:40 ----A---- C:\Windows\system32\PSHED.DLL
2010-01-28 18:04:39 ----A---- C:\Windows\system32\sendmail.dll
2010-01-28 18:04:38 ----A---- C:\Windows\system32\shlwapi.dll
2010-01-28 18:04:38 ----A---- C:\Windows\system32\shell32.dll
2010-01-28 18:04:38 ----A---- C:\Windows\system32\shdocvw.dll
2010-01-28 18:04:38 ----A---- C:\Windows\system32\sethc.exe
2010-01-28 18:04:38 ----A---- C:\Windows\system32\services.exe
2010-01-28 18:04:37 ----A---- C:\Windows\system32\setupapi.dll
2010-01-28 18:04:33 ----A---- C:\Windows\system32\eapphost.dll
2010-01-28 18:04:33 ----A---- C:\Windows\system32\eappgnui.dll
2010-01-28 18:04:32 ----A---- C:\Windows\system32\EhStorAPI.dll
2010-01-28 18:04:32 ----A---- C:\Windows\system32\eappcfg.dll
2010-01-28 18:04:32 ----A---- C:\Windows\system32\eapp3hst.dll
2010-01-28 18:04:31 ----A---- C:\Windows\system32\dwm.exe
2010-01-28 18:04:31 ----A---- C:\Windows\system32\dsprop.dll
2010-01-28 18:04:31 ----A---- C:\Windows\system32\dsound.dll
2010-01-28 18:04:30 ----A---- C:\Windows\system32\f3ahvoas.dll
2010-01-28 18:04:30 ----A---- C:\Windows\system32\extmgr.dll
2010-01-28 18:04:30 ----A---- C:\Windows\system32\ExplorerFrame.dll
2010-01-28 18:04:30 ----A---- C:\Windows\system32\evr.dll
2010-01-28 18:04:30 ----A---- C:\Windows\system32\eudcedit.exe
2010-01-28 18:04:30 ----A---- C:\Windows\system32\esent.dll
2010-01-28 18:04:30 ----A---- C:\Windows\explorer.exe
2010-01-28 18:04:29 ----A---- C:\Windows\system32\es.dll
2010-01-28 18:04:29 ----A---- C:\Windows\system32\EncDec.dll
2010-01-28 18:04:29 ----A---- C:\Windows\system32\emdmgmt.dll
2010-01-28 18:04:29 ----A---- C:\Windows\system32\EhStorShell.dll
2010-01-28 18:04:29 ----A---- C:\Windows\system32\EhStorPwdMgr.dll
2010-01-28 18:04:29 ----A---- C:\Windows\system32\EhStorAuthn.dll
2010-01-28 18:04:29 ----A---- C:\Windows\system32\diagperf.dll
2010-01-28 18:04:28 ----A---- C:\Windows\system32\diskraid.exe
2010-01-28 18:04:28 ----A---- C:\Windows\system32\diskpart.exe
2010-01-28 18:04:28 ----A---- C:\Windows\system32\dimsroam.dll
2010-01-28 18:04:28 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2010-01-28 18:04:27 ----A---- C:\Windows\system32\dfsr.exe
2010-01-28 18:04:27 ----A---- C:\Windows\system32\dfshim.dll
2010-01-28 18:04:27 ----A---- C:\Windows\system32\devmgr.dll
2010-01-28 18:04:26 ----A---- C:\Windows\system32\dhcpcsvc.dll
2010-01-28 18:04:25 ----A---- C:\Windows\system32\drvstore.dll
2010-01-28 18:04:25 ----A---- C:\Windows\system32\drvinst.exe
2010-01-28 18:04:25 ----A---- C:\Windows\system32\drmv2clt.dll
2010-01-28 18:04:25 ----A---- C:\Windows\system32\drmmgrtn.dll
2010-01-28 18:04:25 ----A---- C:\Windows\system32\dpapimig.exe
2010-01-28 18:04:25 ----A---- C:\Windows\system32\dot3svc.dll
2010-01-28 18:04:25 ----A---- C:\Windows\system32\dot3msm.dll
2010-01-28 18:04:25 ----A---- C:\Windows\system32\dot3cfg.dll
2010-01-28 18:04:24 ----A---- C:\Windows\system32\hbaapi.dll
2010-01-28 18:04:24 ----A---- C:\Windows\system32\dnsrslvr.dll
2010-01-28 18:04:24 ----A---- C:\Windows\system32\dnsapi.dll
2010-01-28 18:04:24 ----A---- C:\Windows\system32\dmusic.dll
2010-01-28 18:04:24 ----A---- C:\Windows\system32\dmsynth.dll
2010-01-28 18:04:23 ----A---- C:\Windows\system32\gpresult.exe
2010-01-28 18:04:22 ----A---- C:\Windows\system32\iasnap.dll
2010-01-28 18:04:22 ----A---- C:\Windows\system32\IasMigReader.exe
2010-01-28 18:04:22 ----A---- C:\Windows\system32\IasMigPlugin.dll
2010-01-28 18:04:22 ----A---- C:\Windows\system32\iashlpr.dll
2010-01-28 18:04:22 ----A---- C:\Windows\system32\iasdatastore.dll
2010-01-28 18:04:22 ----A---- C:\Windows\system32\iasads.dll
2010-01-28 18:04:22 ----A---- C:\Windows\system32\iasacct.dll
2010-01-28 18:04:22 ----A---- C:\Windows\system32\gpupdate.exe
2010-01-28 18:04:22 ----A---- C:\Windows\system32\gpsvc.dll
2010-01-28 18:04:21 ----A---- C:\Windows\system32\hidserv.dll
2010-01-28 18:04:21 ----A---- C:\Windows\system32\hdwwiz.exe
2010-01-28 18:04:21 ----A---- C:\Windows\system32\fontext.dll
2010-01-28 18:04:21 ----A---- C:\Windows\system32\findstr.exe
2010-01-28 18:04:21 ----A---- C:\Windows\system32\fc.exe
2010-01-28 18:04:21 ----A---- C:\Windows\system32\Faultrep.dll
2010-01-28 18:04:20 ----A---- C:\Windows\system32\gpapi.dll
2010-01-28 18:04:20 ----A---- C:\Windows\system32\gdi32.dll
2010-01-28 18:04:20 ----A---- C:\Windows\system32\feclient.dll
2010-01-28 18:04:20 ----A---- C:\Windows\system32\fdWSD.dll
2010-01-28 18:04:20 ----A---- C:\Windows\system32\fdWCN.dll
2010-01-28 18:04:20 ----A---- C:\Windows\system32\fdSSDP.dll
2010-01-28 18:04:20 ----A---- C:\Windows\system32\fdProxy.dll
2010-01-28 18:04:20 ----A---- C:\Windows\system32\fdeploy.dll
2010-01-28 18:04:20 ----A---- C:\Windows\system32\fdBthProxy.dll
2010-01-28 18:04:20 ----A---- C:\Windows\system32\fdBth.dll
2010-01-28 18:04:19 ----A---- C:\Windows\system32\gpedit.dll
2010-01-28 18:04:19 ----A---- C:\Windows\system32\fundisc.dll
2010-01-28 18:04:18 ----A---- C:\Windows\system32\FwRemoteSvr.dll
2010-01-28 18:04:18 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2010-01-28 18:04:18 ----A---- C:\Windows\system32\FunctionDiscoveryFolder.dll
2010-01-28 18:04:18 ----A---- C:\Windows\system32\ftp.exe
2010-01-28 18:04:18 ----A---- C:\Windows\system32\authui.dll
2010-01-28 18:04:18 ----A---- C:\Windows\system32\audiosrv.dll
2010-01-28 18:04:18 ----A---- C:\Windows\system32\AudioSes.dll
2010-01-28 18:04:17 ----A---- C:\Windows\system32\autoplay.dll
2010-01-28 18:04:17 ----A---- C:\Windows\system32\autochk.exe
2010-01-28 18:04:17 ----A---- C:\Windows\system32\autofmt.exe
2010-01-28 18:04:17 ----A---- C:\Windows\system32\autoconv.exe
2010-01-28 18:04:17 ----A---- C:\Windows\system32\authz.dll
2010-01-28 18:04:17 ----A---- C:\Windows\system32\audiodg.exe
2010-01-28 18:04:15 ----A---- C:\Windows\system32\bthci.dll
2010-01-28 18:04:15 ----A---- C:\Windows\system32\browseui.dll
2010-01-28 18:04:15 ----A---- C:\Windows\system32\brcpl.dll
2010-01-28 18:04:14 ----A---- C:\Windows\system32\blackbox.dll
2010-01-28 18:04:14 ----A---- C:\Windows\system32\bitsigd.dll
2010-01-28 18:04:14 ----A---- C:\Windows\system32\BFE.DLL
2010-01-28 18:04:14 ----A---- C:\Windows\system32\bcrypt.dll
2010-01-28 18:04:14 ----A---- C:\Windows\system32\basecsp.dll
2010-01-28 18:04:14 ----A---- C:\Windows\system32\azroles.dll
Logfile of random's system information tool 1.06 (written by random/random)
Run by Esperian at 2010-02-26 16:22:59
Microsoft® Windows Vista™ Home Basic Service Pack 2
System drive C: has 60 GB (57%) free of 105 GB
Total RAM: 1790 MB (42% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:23:29, on 26. 2. 2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.Exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Ares\Ares.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Crawler\CToolbar.exe
C:\Users\Esperian\Downloads\RSIT.exe
C:\Program Files\trend micro\Esperian.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... io&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatche ... tbid=60347
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dymasearch.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... io&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... io&pf=cnnb
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: dymanet - {0ac89f42-45b9-ab77-69e4-ce07c5a93ec7} - C:\Windows\system32\9bde048a-7ed2-a7ef-69ec-5aec1d017869.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\ctbr.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [B2C_AGENT] C:\ProgramData\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [SpywareTerminatorUpdate] "C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\ctbr.dll
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: Služba Google Update (gupdate1caa5b117bd44c5) (gupdate1caa5b117bd44c5) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 7911 bytes
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\HPCeeScheduleForEsperian.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-23 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0ac89f42-45b9-ab77-69e4-ce07c5a93ec7}]
dymanet - C:\Windows\system32\9bde048a-7ed2-a7ef-69ec-5aec1d017869.dll [2010-01-30 1935360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
C:\PROGRA~1\Crawler\ctbr.dll [2010-01-29 1230184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll [2008-02-22 509328]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2010-01-03 1019128]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
{4B3803EA-5230-4DC3-A7FC-33638F3D3542} - &Crawler Toolbar - C:\PROGRA~1\Crawler\ctbr.dll [2010-01-29 1230184]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-04-17 1049896]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"MSSE"=c:\Program Files\Microsoft Security Essentials\msseces.exe [2009-09-13 1048392]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2010-01-26 2166784]
"B2C_AGENT"=C:\ProgramData\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe [2009-06-15 182208]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-11-10 417792]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2009-07-23 13797920]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-06-27 152872]
"ares"=C:\Program Files\Ares\Ares.exe [2010-01-22 1011712]
"SpywareTerminatorUpdate"=C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [2010-01-26 3037696]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883840]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2007-05-11 40048]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
C:\Program Files\Ares\Ares.exe [2010-01-22 1011712]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-04-15 70912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2006-12-10 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2008-04-15 488752]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
C:\Program Files\ICQ7.0\ICQ.exe [2010-01-12 133368]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2008-02-26 2289664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\MSN Messenger\MsnMsgr.Exe /background []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl.exe]
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2008-03-14 202032]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
C:\Program Files\HP\QuickPlay\QPService.exe [2008-04-01 468264]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe [2009-10-09 25623336]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdate]
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [2010-01-26 3037696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe [2008-02-22 144784]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UCam_Menu]
C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [2007-12-24 222504]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2007-01-02 210520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Esperian^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Stardock ObjectDock.lnk]
C:\PROGRA~1\Stardock\OBJECT~1\OBJECT~1.EXE [2007-04-30 3450608]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======List of files/folders created in the last 1 months======
2010-02-26 16:22:59 ----D---- C:\rsit
2010-02-26 16:22:59 ----D---- C:\Program Files\trend micro
2010-02-26 14:31:48 ----D---- C:\Program Files\Crawler
2010-02-24 11:36:48 ----A---- C:\Windows\system32\tzres.dll
2010-02-24 11:36:17 ----A---- C:\Windows\system32\secproc_isv.dll
2010-02-24 11:36:16 ----A---- C:\Windows\system32\secproc.dll
2010-02-24 11:36:14 ----A---- C:\Windows\system32\RMActivate_isv.exe
2010-02-24 11:36:13 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2010-02-24 11:36:13 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2010-02-24 11:36:13 ----A---- C:\Windows\system32\RMActivate.exe
2010-02-24 11:36:12 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2010-02-24 11:36:12 ----A---- C:\Windows\system32\secproc_ssp.dll
2010-02-24 11:36:12 ----A---- C:\Windows\system32\msdrm.dll
2010-02-24 11:36:10 ----A---- C:\Windows\system32\gameux.dll
2010-02-24 11:36:08 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2010-02-24 11:36:08 ----A---- C:\Windows\system32\Apphlpdm.dll
2010-02-21 02:27:24 ----D---- C:\Program Files\SopCast
2010-02-18 19:00:33 ----D---- C:\72c92e84267b60dea49239
2010-02-16 20:38:44 ----A---- C:\Windows\CmdPrint.INI
2010-02-16 18:48:47 ----A---- C:\Windows\NeroDigital.ini
2010-02-16 18:34:58 ----D---- C:\ProgramData\InstallShield
2010-02-16 18:34:46 ----D---- C:\Users\Esperian\AppData\Roaming\Corel
2010-02-16 18:33:20 ----D---- C:\Program Files\Common Files\Corel
2010-02-16 18:29:23 ----D---- C:\Program Files\Corel
2010-02-14 18:31:28 ----A---- C:\Windows\system32\NCTImageFile.dll
2010-02-14 18:31:22 ----A---- C:\Windows\system32\NCTVideoView.dll
2010-02-14 18:31:19 ----A---- C:\Windows\system32\NCTVideoFile.dll
2010-02-14 18:31:15 ----A---- C:\Windows\system32\NCTQuickTimeFile.dll
2010-02-14 18:31:14 ----A---- C:\Windows\system32\NCTRMFile.dll
2010-02-14 18:31:11 ----A---- C:\Windows\system32\NCTWMVFile.dll
2010-02-14 18:31:03 ----A---- C:\Windows\system32\NCTVideoCoreM.dll
2010-02-14 18:30:56 ----A---- C:\Windows\system32\NCTAVIFile.dll
2010-02-14 18:30:55 ----A---- C:\Windows\system32\NCTVideoCompress.dll
2010-02-14 18:30:55 ----A---- C:\Windows\system32\NCTAudioFormatSettings3.dll
2010-02-14 18:30:54 ----A---- C:\Windows\system32\NCTAudioCompress3.dll
2010-02-14 18:30:53 ----A---- C:\Windows\system32\NCTAudioCompress2.dll
2010-02-14 18:30:53 ----A---- C:\Windows\system32\msvcr70.dll
2010-02-14 18:30:53 ----A---- C:\Windows\system32\msvcp70.dll
2010-02-14 18:30:52 ----A---- C:\Windows\system32\lame_enc.dll
2010-02-14 18:30:45 ----D---- C:\Windows\system32\RMBin
2010-02-14 18:30:45 ----A---- C:\Windows\system32\viscomwave.dll
2010-02-14 18:30:45 ----A---- C:\Windows\system32\viscomqtenc.dll
2010-02-14 18:30:45 ----A---- C:\Windows\system32\SkinCrafter.dll
2010-02-14 18:30:44 ----A---- C:\Windows\system32\viscomqtde.dll
2010-02-14 18:30:37 ----D---- C:\Program Files\A-one Video Convertor
2010-02-14 17:45:05 ----A---- C:\Windows\system32\0dbfcd86-827d-ea0f-cfa6-5a8c9fbfbfa2.exe
2010-02-12 18:20:20 ----D---- C:\Users\Esperian\AppData\Roaming\ABBYY
2010-02-12 18:16:50 ----D---- C:\Program Files\ABBYY FineReader 8.0 Professional Edition
2010-02-12 18:06:07 ----D---- C:\temp
2010-02-12 17:08:31 ----D---- C:\Program Files\Microsoft Silverlight
2010-02-12 17:07:56 ----DC---- C:\Windows\system32\DRVSTORE
2010-02-12 17:06:30 ----D---- C:\Program Files\Microsoft Sync Framework
2010-02-12 17:04:29 ----A---- C:\Windows\system32\d3dx9_32.dll
2010-02-12 17:04:12 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2010-02-12 17:02:08 ----D---- C:\Program Files\Microsoft
2010-02-12 17:01:37 ----D---- C:\Program Files\Windows Live SkyDrive
2010-02-12 17:01:23 ----D---- C:\Program Files\Windows Live
2010-02-12 16:51:10 ----D---- C:\Program Files\Common Files\Windows Live
2010-02-10 19:59:36 ----D---- C:\Users\Esperian\AppData\Roaming\foobar2000
2010-02-10 19:58:59 ----D---- C:\Program Files\foobar2000
2010-02-10 07:36:31 ----A---- C:\Windows\system32\ntoskrnl.exe
2010-02-10 07:36:31 ----A---- C:\Windows\system32\ntkrnlpa.exe
2010-02-10 07:36:15 ----A---- C:\Windows\system32\quartz.dll
2010-02-10 07:36:13 ----A---- C:\Windows\system32\tsbyuv.dll
2010-02-10 07:36:13 ----A---- C:\Windows\system32\msyuv.dll
2010-02-10 07:36:13 ----A---- C:\Windows\system32\msvidc32.dll
2010-02-10 07:36:13 ----A---- C:\Windows\system32\msrle32.dll
2010-02-10 07:36:12 ----A---- C:\Windows\system32\iyuv_32.dll
2010-02-10 07:36:11 ----A---- C:\Windows\system32\mciavi32.dll
2010-02-10 07:36:10 ----A---- C:\Windows\system32\msvfw32.dll
2010-02-10 07:36:10 ----A---- C:\Windows\system32\avifil32.dll
2010-02-08 21:07:24 ----D---- C:\Users\Esperian\AppData\Roaming\Opera
2010-02-08 21:04:00 ----D---- C:\Program Files\Opera
2010-02-07 20:32:06 ----D---- C:\Users\Esperian\AppData\Roaming\CyberLink
2010-02-07 15:54:16 ----D---- C:\ProgramData\Apple Computer
2010-02-07 15:54:16 ----D---- C:\Program Files\QuickTime
2010-02-07 15:53:08 ----D---- C:\Program Files\Common Files\Apple
2010-02-07 15:52:48 ----D---- C:\Program Files\Apple Software Update
2010-02-07 15:52:47 ----D---- C:\ProgramData\Apple
2010-02-05 19:05:42 ----D---- C:\Program Files\DIFX
2010-02-05 19:05:19 ----D---- C:\Program Files\infineon
2010-02-05 19:03:59 ----D---- C:\Program Files\LG Electronics
2010-02-05 19:02:08 ----D---- C:\KP500
2010-02-05 19:01:05 ----A---- C:\Windows\system32\lgAxconfig.ini
2010-02-05 19:01:05 ----A---- C:\Windows\system32\CommonDL.dll
2010-02-05 19:00:50 ----D---- C:\ProgramData\LGMOBILEAX
2010-02-04 20:53:32 ----D---- C:\Users\Esperian\AppData\Roaming\DivX
2010-02-04 16:46:21 ----D---- C:\Program Files\Common Files\PX Storage Engine
2010-02-04 16:45:10 ----D---- C:\Program Files\Google
2010-02-04 16:45:10 ----D---- C:\Program Files\Common Files\DivX Shared
2010-02-04 16:45:09 ----D---- C:\Program Files\DivX
2010-01-31 21:20:21 ----D---- C:\Program Files\Paint.NET
2010-01-30 11:55:32 ----A---- C:\Windows\system32\9bde048a-7ed2-a7ef-69ec-5aec1d017869.dll
2010-01-29 16:56:45 ----D---- C:\Program Files\Windows Portable Devices
2010-01-29 16:52:15 ----A---- C:\Windows\system32\UIAnimation.dll
2010-01-29 16:52:13 ----A---- C:\Windows\system32\UIRibbonRes.dll
2010-01-29 16:52:12 ----A---- C:\Windows\system32\UIRibbon.dll
2010-01-29 16:51:33 ----A---- C:\Windows\system32\WMPhoto.dll
2010-01-29 16:51:30 ----A---- C:\Windows\system32\cdd.dll
2010-01-29 16:51:28 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll
2010-01-29 16:51:28 ----A---- C:\Windows\system32\d3d10warp.dll
2010-01-29 16:51:27 ----A---- C:\Windows\system32\XpsRasterService.dll
2010-01-29 16:51:27 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2010-01-29 16:51:27 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2010-01-29 16:51:27 ----A---- C:\Windows\system32\WindowsCodecs.dll
2010-01-29 16:51:27 ----A---- C:\Windows\system32\dxdiagn.dll
2010-01-29 16:51:27 ----A---- C:\Windows\system32\d2d1.dll
2010-01-29 16:51:26 ----A---- C:\Windows\system32\xpsservices.dll
2010-01-29 16:51:26 ----A---- C:\Windows\system32\XpsPrint.dll
2010-01-29 16:51:26 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
2010-01-29 16:51:26 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
2010-01-29 16:51:26 ----A---- C:\Windows\system32\OpcServices.dll
2010-01-29 16:51:26 ----A---- C:\Windows\system32\dxdiag.exe
2010-01-29 16:51:25 ----A---- C:\Windows\system32\FntCache.dll
2010-01-29 16:51:25 ----A---- C:\Windows\system32\dxgi.dll
2010-01-29 16:51:25 ----A---- C:\Windows\system32\DWrite.dll
2010-01-29 16:51:25 ----A---- C:\Windows\system32\d3d11.dll
2010-01-29 16:51:25 ----A---- C:\Windows\system32\d3d10level9.dll
2010-01-29 16:51:25 ----A---- C:\Windows\system32\d3d10core.dll
2010-01-29 16:51:25 ----A---- C:\Windows\system32\d3d10_1core.dll
2010-01-29 16:51:25 ----A---- C:\Windows\system32\d3d10_1.dll
2010-01-29 16:51:25 ----A---- C:\Windows\system32\d3d10.dll
2010-01-29 16:50:46 ----A---- C:\Windows\system32\WPDShextAutoplay.exe
2010-01-29 16:50:46 ----A---- C:\Windows\system32\BthMtpContextHandler.dll
2010-01-29 16:50:45 ----A---- C:\Windows\system32\wpdbusenum.dll
2010-01-29 16:50:40 ----A---- C:\Windows\system32\PortableDeviceConnectApi.dll
2010-01-29 16:50:34 ----A---- C:\Windows\system32\wpdshext.dll
2010-01-29 16:50:34 ----A---- C:\Windows\system32\wpd_ci.dll
2010-01-29 16:50:33 ----A---- C:\Windows\system32\WPDSp.dll
2010-01-29 16:50:33 ----A---- C:\Windows\system32\WPDShServiceObj.dll
2010-01-29 16:50:33 ----A---- C:\Windows\system32\PortableDeviceWMDRM.dll
2010-01-29 16:50:33 ----A---- C:\Windows\system32\PortableDeviceTypes.dll
2010-01-29 16:50:33 ----A---- C:\Windows\system32\PortableDeviceClassExtension.dll
2010-01-29 16:50:33 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2010-01-29 16:49:31 ----A---- C:\Windows\system32\oleaccrc.dll
2010-01-29 16:49:30 ----A---- C:\Windows\system32\UIAutomationCore.dll
2010-01-29 16:49:30 ----A---- C:\Windows\system32\oleacc.dll
2010-01-29 13:05:16 ----D---- C:\Users\Esperian\AppData\Roaming\Media Player Classic
2010-01-28 18:59:48 ----D---- C:\Windows\system32\vi-VN
2010-01-28 18:59:48 ----D---- C:\Windows\system32\eu-ES
2010-01-28 18:59:48 ----D---- C:\Windows\system32\ca-ES
2010-01-28 18:33:39 ----D---- C:\Windows\system32\SPReview
2010-01-28 18:16:37 ----A---- C:\Windows\system32\scavenge.dll
2010-01-28 18:16:07 ----A---- C:\Windows\system32\compcln.exe
2010-01-28 18:05:04 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2010-01-28 18:05:04 ----A---- C:\Windows\system32\SearchIndexer.exe
2010-01-28 18:05:04 ----A---- C:\Windows\system32\SearchFilterHost.exe
2010-01-28 18:05:03 ----A---- C:\Windows\system32\sdohlp.dll
2010-01-28 18:05:03 ----A---- C:\Windows\system32\sdclt.exe
2010-01-28 18:05:03 ----A---- C:\Windows\system32\rtffilt.dll
2010-01-28 18:05:03 ----A---- C:\Windows\system32\rsaenh.dll
2010-01-28 18:05:02 ----A---- C:\Windows\system32\samlib.dll
2010-01-28 18:05:02 ----A---- C:\Windows\system32\rtutils.dll
2010-01-28 18:05:02 ----A---- C:\Windows\system32\riched20.dll
2010-01-28 18:05:01 ----A---- C:\Windows\system32\scrrun.dll
2010-01-28 18:05:01 ----A---- C:\Windows\system32\rpchttp.dll
2010-01-28 18:05:01 ----A---- C:\Windows\system32\rpcss.dll
2010-01-28 18:05:00 ----A---- C:\Windows\system32\SCardSvr.dll
2010-01-28 18:05:00 ----A---- C:\Windows\system32\scansetting.dll
2010-01-28 18:05:00 ----A---- C:\Windows\system32\samsrv.dll
2010-01-28 18:04:57 ----A---- C:\Windows\system32\schedsvc.dll
2010-01-28 18:04:57 ----A---- C:\Windows\system32\scrobj.dll
2010-01-28 18:04:57 ----A---- C:\Windows\system32\scksp.dll
2010-01-28 18:04:57 ----A---- C:\Windows\system32\scesrv.dll
2010-01-28 18:04:57 ----A---- C:\Windows\system32\scecli.dll
2010-01-28 18:04:55 ----A---- C:\Windows\system32\perfdisk.dll
2010-01-28 18:04:55 ----A---- C:\Windows\system32\PerfCenterCPL.dll
2010-01-28 18:04:55 ----A---- C:\Windows\system32\pdh.dll
2010-01-28 18:04:55 ----A---- C:\Windows\system32\pcaui.dll
2010-01-28 18:04:55 ----A---- C:\Windows\system32\p2psvc.dll
2010-01-28 18:04:55 ----A---- C:\Windows\system32\P2PGraph.dll
2010-01-28 18:04:54 ----A---- C:\Windows\system32\powercpl.dll
2010-01-28 18:04:54 ----A---- C:\Windows\system32\PNPXAssoc.dll
2010-01-28 18:04:54 ----A---- C:\Windows\system32\PnPutil.exe
2010-01-28 18:04:54 ----A---- C:\Windows\system32\PnPUnattend.exe
2010-01-28 18:04:54 ----A---- C:\Windows\system32\pnpui.dll
2010-01-28 18:04:54 ----A---- C:\Windows\system32\pnpsetup.dll
2010-01-28 18:04:54 ----A---- C:\Windows\system32\pnidui.dll
2010-01-28 18:04:53 ----A---- C:\Windows\system32\pidgenx.dll
2010-01-28 18:04:53 ----A---- C:\Windows\system32\photowiz.dll
2010-01-28 18:04:52 ----A---- C:\Windows\system32\PkgMgr.exe
2010-01-28 18:04:52 ----A---- C:\Windows\system32\ntdll.dll
2010-01-28 18:04:52 ----A---- C:\Windows\system32\nslookup.exe
2010-01-28 18:04:51 ----A---- C:\Windows\system32\NlsLexicons0009.dll
2010-01-28 18:04:50 ----A---- C:\Windows\system32\oleaut32.dll
2010-01-28 18:04:50 ----A---- C:\Windows\system32\ole32.dll
2010-01-28 18:04:50 ----A---- C:\Windows\system32\offfilt.dll
2010-01-28 18:04:50 ----A---- C:\Windows\system32\odbc32.dll
2010-01-28 18:04:50 ----A---- C:\Windows\system32\NlsLexicons0007.dll
2010-01-28 18:04:50 ----A---- C:\Windows\system32\nlhtml.dll
2010-01-28 18:04:49 ----A---- C:\Windows\system32\osk.exe
2010-01-28 18:04:49 ----A---- C:\Windows\system32\oobefldr.dll
2010-01-28 18:04:49 ----A---- C:\Windows\system32\onex.dll
2010-01-28 18:04:49 ----A---- C:\Windows\system32\olepro32.dll
2010-01-28 18:04:49 ----A---- C:\Windows\system32\oleprn.dll
2010-01-28 18:04:49 ----A---- C:\Windows\system32\odbccp32.dll
2010-01-28 18:04:49 ----A---- C:\Windows\system32\odbcconf.dll
2010-01-28 18:04:48 ----A---- C:\Windows\system32\rasgcw.dll
2010-01-28 18:04:48 ----A---- C:\Windows\system32\rasdlg.dll
2010-01-28 18:04:48 ----A---- C:\Windows\system32\rasdial.exe
2010-01-28 18:04:48 ----A---- C:\Windows\system32\ocsetup.exe
2010-01-28 18:04:48 ----A---- C:\Windows\system32\occache.dll
2010-01-28 18:04:48 ----A---- C:\Windows\system32\ntprint.dll
2010-01-28 18:04:48 ----A---- C:\Windows\system32\ntmarta.dll
2010-01-28 18:04:47 ----A---- C:\Windows\system32\rastapi.dll
2010-01-28 18:04:47 ----A---- C:\Windows\system32\rasppp.dll
2010-01-28 18:04:47 ----A---- C:\Windows\system32\rasplap.dll
2010-01-28 18:04:47 ----A---- C:\Windows\system32\rasmontr.dll
2010-01-28 18:04:47 ----A---- C:\Windows\system32\rasmans.dll
2010-01-28 18:04:47 ----A---- C:\Windows\system32\raschap.dll
2010-01-28 18:04:47 ----A---- C:\Windows\system32\rasdiag.dll
2010-01-28 18:04:47 ----A---- C:\Windows\system32\rasapi32.dll
2010-01-28 18:04:47 ----A---- C:\Windows\system32\Query.dll
2010-01-28 18:04:47 ----A---- C:\Windows\system32\qedit.dll
2010-01-28 18:04:46 ----A---- C:\Windows\system32\RelMon.dll
2010-01-28 18:04:46 ----A---- C:\Windows\system32\rekeywiz.exe
2010-01-28 18:04:46 ----A---- C:\Windows\system32\regsvc.dll
2010-01-28 18:04:46 ----A---- C:\Windows\system32\RacEngn.dll
2010-01-28 18:04:46 ----A---- C:\Windows\system32\qmgr.dll
2010-01-28 18:04:45 ----A---- C:\Windows\system32\regapi.dll
2010-01-28 18:04:45 ----A---- C:\Windows\system32\reg.exe
2010-01-28 18:04:45 ----A---- C:\Windows\system32\rdpwsx.dll
2010-01-28 18:04:45 ----A---- C:\Windows\system32\rdpencom.dll
2010-01-28 18:04:44 ----A---- C:\Windows\system32\prnntfy.dll
2010-01-28 18:04:44 ----A---- C:\Windows\system32\printui.dll
2010-01-28 18:04:44 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
2010-01-28 18:04:44 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2010-01-28 18:04:44 ----A---- C:\Windows\system32\PresentationHost.exe
2010-01-28 18:04:43 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2010-01-28 18:04:43 ----A---- C:\Windows\system32\powrprof.dll
2010-01-28 18:04:42 ----A---- C:\Windows\system32\puiapi.dll
2010-01-28 18:04:41 ----A---- C:\Windows\system32\qdvd.dll
2010-01-28 18:04:41 ----A---- C:\Windows\system32\QAGENTRT.DLL
2010-01-28 18:04:41 ----A---- C:\Windows\system32\propsys.dll
2010-01-28 18:04:41 ----A---- C:\Windows\system32\propdefs.dll
2010-01-28 18:04:41 ----A---- C:\Windows\system32\profsvc.dll
2010-01-28 18:04:40 ----A---- C:\Windows\system32\psisdecd.dll
2010-01-28 18:04:40 ----A---- C:\Windows\system32\PSHED.DLL
2010-01-28 18:04:39 ----A---- C:\Windows\system32\sendmail.dll
2010-01-28 18:04:38 ----A---- C:\Windows\system32\shlwapi.dll
2010-01-28 18:04:38 ----A---- C:\Windows\system32\shell32.dll
2010-01-28 18:04:38 ----A---- C:\Windows\system32\shdocvw.dll
2010-01-28 18:04:38 ----A---- C:\Windows\system32\sethc.exe
2010-01-28 18:04:38 ----A---- C:\Windows\system32\services.exe
2010-01-28 18:04:37 ----A---- C:\Windows\system32\setupapi.dll
2010-01-28 18:04:33 ----A---- C:\Windows\system32\eapphost.dll
2010-01-28 18:04:33 ----A---- C:\Windows\system32\eappgnui.dll
2010-01-28 18:04:32 ----A---- C:\Windows\system32\EhStorAPI.dll
2010-01-28 18:04:32 ----A---- C:\Windows\system32\eappcfg.dll
2010-01-28 18:04:32 ----A---- C:\Windows\system32\eapp3hst.dll
2010-01-28 18:04:31 ----A---- C:\Windows\system32\dwm.exe
2010-01-28 18:04:31 ----A---- C:\Windows\system32\dsprop.dll
2010-01-28 18:04:31 ----A---- C:\Windows\system32\dsound.dll
2010-01-28 18:04:30 ----A---- C:\Windows\system32\f3ahvoas.dll
2010-01-28 18:04:30 ----A---- C:\Windows\system32\extmgr.dll
2010-01-28 18:04:30 ----A---- C:\Windows\system32\ExplorerFrame.dll
2010-01-28 18:04:30 ----A---- C:\Windows\system32\evr.dll
2010-01-28 18:04:30 ----A---- C:\Windows\system32\eudcedit.exe
2010-01-28 18:04:30 ----A---- C:\Windows\system32\esent.dll
2010-01-28 18:04:30 ----A---- C:\Windows\explorer.exe
2010-01-28 18:04:29 ----A---- C:\Windows\system32\es.dll
2010-01-28 18:04:29 ----A---- C:\Windows\system32\EncDec.dll
2010-01-28 18:04:29 ----A---- C:\Windows\system32\emdmgmt.dll
2010-01-28 18:04:29 ----A---- C:\Windows\system32\EhStorShell.dll
2010-01-28 18:04:29 ----A---- C:\Windows\system32\EhStorPwdMgr.dll
2010-01-28 18:04:29 ----A---- C:\Windows\system32\EhStorAuthn.dll
2010-01-28 18:04:29 ----A---- C:\Windows\system32\diagperf.dll
2010-01-28 18:04:28 ----A---- C:\Windows\system32\diskraid.exe
2010-01-28 18:04:28 ----A---- C:\Windows\system32\diskpart.exe
2010-01-28 18:04:28 ----A---- C:\Windows\system32\dimsroam.dll
2010-01-28 18:04:28 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2010-01-28 18:04:27 ----A---- C:\Windows\system32\dfsr.exe
2010-01-28 18:04:27 ----A---- C:\Windows\system32\dfshim.dll
2010-01-28 18:04:27 ----A---- C:\Windows\system32\devmgr.dll
2010-01-28 18:04:26 ----A---- C:\Windows\system32\dhcpcsvc.dll
2010-01-28 18:04:25 ----A---- C:\Windows\system32\drvstore.dll
2010-01-28 18:04:25 ----A---- C:\Windows\system32\drvinst.exe
2010-01-28 18:04:25 ----A---- C:\Windows\system32\drmv2clt.dll
2010-01-28 18:04:25 ----A---- C:\Windows\system32\drmmgrtn.dll
2010-01-28 18:04:25 ----A---- C:\Windows\system32\dpapimig.exe
2010-01-28 18:04:25 ----A---- C:\Windows\system32\dot3svc.dll
2010-01-28 18:04:25 ----A---- C:\Windows\system32\dot3msm.dll
2010-01-28 18:04:25 ----A---- C:\Windows\system32\dot3cfg.dll
2010-01-28 18:04:24 ----A---- C:\Windows\system32\hbaapi.dll
2010-01-28 18:04:24 ----A---- C:\Windows\system32\dnsrslvr.dll
2010-01-28 18:04:24 ----A---- C:\Windows\system32\dnsapi.dll
2010-01-28 18:04:24 ----A---- C:\Windows\system32\dmusic.dll
2010-01-28 18:04:24 ----A---- C:\Windows\system32\dmsynth.dll
2010-01-28 18:04:23 ----A---- C:\Windows\system32\gpresult.exe
2010-01-28 18:04:22 ----A---- C:\Windows\system32\iasnap.dll
2010-01-28 18:04:22 ----A---- C:\Windows\system32\IasMigReader.exe
2010-01-28 18:04:22 ----A---- C:\Windows\system32\IasMigPlugin.dll
2010-01-28 18:04:22 ----A---- C:\Windows\system32\iashlpr.dll
2010-01-28 18:04:22 ----A---- C:\Windows\system32\iasdatastore.dll
2010-01-28 18:04:22 ----A---- C:\Windows\system32\iasads.dll
2010-01-28 18:04:22 ----A---- C:\Windows\system32\iasacct.dll
2010-01-28 18:04:22 ----A---- C:\Windows\system32\gpupdate.exe
2010-01-28 18:04:22 ----A---- C:\Windows\system32\gpsvc.dll
2010-01-28 18:04:21 ----A---- C:\Windows\system32\hidserv.dll
2010-01-28 18:04:21 ----A---- C:\Windows\system32\hdwwiz.exe
2010-01-28 18:04:21 ----A---- C:\Windows\system32\fontext.dll
2010-01-28 18:04:21 ----A---- C:\Windows\system32\findstr.exe
2010-01-28 18:04:21 ----A---- C:\Windows\system32\fc.exe
2010-01-28 18:04:21 ----A---- C:\Windows\system32\Faultrep.dll
2010-01-28 18:04:20 ----A---- C:\Windows\system32\gpapi.dll
2010-01-28 18:04:20 ----A---- C:\Windows\system32\gdi32.dll
2010-01-28 18:04:20 ----A---- C:\Windows\system32\feclient.dll
2010-01-28 18:04:20 ----A---- C:\Windows\system32\fdWSD.dll
2010-01-28 18:04:20 ----A---- C:\Windows\system32\fdWCN.dll
2010-01-28 18:04:20 ----A---- C:\Windows\system32\fdSSDP.dll
2010-01-28 18:04:20 ----A---- C:\Windows\system32\fdProxy.dll
2010-01-28 18:04:20 ----A---- C:\Windows\system32\fdeploy.dll
2010-01-28 18:04:20 ----A---- C:\Windows\system32\fdBthProxy.dll
2010-01-28 18:04:20 ----A---- C:\Windows\system32\fdBth.dll
2010-01-28 18:04:19 ----A---- C:\Windows\system32\gpedit.dll
2010-01-28 18:04:19 ----A---- C:\Windows\system32\fundisc.dll
2010-01-28 18:04:18 ----A---- C:\Windows\system32\FwRemoteSvr.dll
2010-01-28 18:04:18 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2010-01-28 18:04:18 ----A---- C:\Windows\system32\FunctionDiscoveryFolder.dll
2010-01-28 18:04:18 ----A---- C:\Windows\system32\ftp.exe
2010-01-28 18:04:18 ----A---- C:\Windows\system32\authui.dll
2010-01-28 18:04:18 ----A---- C:\Windows\system32\audiosrv.dll
2010-01-28 18:04:18 ----A---- C:\Windows\system32\AudioSes.dll
2010-01-28 18:04:17 ----A---- C:\Windows\system32\autoplay.dll
2010-01-28 18:04:17 ----A---- C:\Windows\system32\autochk.exe
2010-01-28 18:04:17 ----A---- C:\Windows\system32\autofmt.exe
2010-01-28 18:04:17 ----A---- C:\Windows\system32\autoconv.exe
2010-01-28 18:04:17 ----A---- C:\Windows\system32\authz.dll
2010-01-28 18:04:17 ----A---- C:\Windows\system32\audiodg.exe
2010-01-28 18:04:15 ----A---- C:\Windows\system32\bthci.dll
2010-01-28 18:04:15 ----A---- C:\Windows\system32\browseui.dll
2010-01-28 18:04:15 ----A---- C:\Windows\system32\brcpl.dll
2010-01-28 18:04:14 ----A---- C:\Windows\system32\blackbox.dll
2010-01-28 18:04:14 ----A---- C:\Windows\system32\bitsigd.dll
2010-01-28 18:04:14 ----A---- C:\Windows\system32\BFE.DLL
2010-01-28 18:04:14 ----A---- C:\Windows\system32\bcrypt.dll
2010-01-28 18:04:14 ----A---- C:\Windows\system32\basecsp.dll
2010-01-28 18:04:14 ----A---- C:\Windows\system32\azroles.dll