Удаление вирусов и троянов. Защита компьютера. › Помощь в удалении вирусов, троянов, рекламы и других зловредов › Вирус блокирует все антивирусные программы › Re: Вирус блокирует все антивирусные программы (продолжение)
Просканировала компьютер через Hijack This, ниже файл log.tx:
Logfile of random’s system information tool 1.06 (written by random/random)
Run by Admin at 2001-01-27 14:10:11
Microsoft Windows XP Professional Service Pack 3
System drive C: has 15 GB (39%) free of 38 GB
Total RAM: 3327 MB (82% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:10:46, on 27.01.2001
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18241)
Boot mode: Normal
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSExplorer.EXE
C:Program FilesWindows LiveFamily Safetyfsssvc.exe
C:Program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE
C:WINDOWSsystem32nvsvc32.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSsystem32RUNDLL32.EXE
C:WINDOWSRTHDCPL.EXE
C:Program FilesAmlMapleAmlMaple.exe
C:Program FilesASUSEPU-6 EngineSixEngine.exe
C:Program FilesA4TechMouseAmoumain.exe
C:WINDOWSPixArtPAC207Monitor.exe
C:PROGRA~1SamsungSAMSUN~1LAUNCH~1.EXE
C:PROGRA~1COMMON~1PCSuiteDATALA~1DATALA~1.EXE
C:Program FilesCyberLinkPowerDVDPDVDServ.exe
C:Program FilesWindows LiveFamily Safetyfsui.exe
C:Program FilesVistaDriveIconVistaDrv.exe
C:Program FilesPunto Switcherps.exe
C:WINDOWSsystem32ctfmon.exe
C:Program FilesCommon FilesAheadLibNMBgMonitor.exe
C:Program FilesCommon FilesPCSuiteServicesServiceLayer.exe
C:Program FilesAvira Premium Security Suitesched.exe
C:Program FilesAvira Premium Security Suiteavfwsvc.exe
C:Documents and SettingsAdminLocal SettingsApplication DataGoogleChromeApplicationchrome.exe
C:Documents and SettingsAdminLocal SettingsApplication DataGoogleChromeApplicationchrome.exe
C:Documents and SettingsAdminРабочий столRSIT.exe
C:Program Filestrend microAdmin.exe
R0 — HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = about:blank
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 — HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://mail.ru
R1 — HKCUSoftwareMicrosoftInternet Connection Wizard,ShellNext = http://www.samsung.com/us/consumer/learningresources/monitor/magetune/pop_intro.html
R0 — HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Ссылки
R3 — URLSearchHook: Спутник@Mail.Ru — {09900DE8-1DCA-443F-9243-26FF581438AF} — c:program filesmail.rusputnikMailRuSputnik.dll
R3 — URLSearchHook: (no name) — {83821C2B-32A8-4DD7-B6D4-44309A78E668} — C:Program FilesMail.RuAgentMradllnewmrasearch.dll
O2 — BHO: Skype add-on (mastermind) — {22BF413B-C6D2-4d91-82A9-A0F997BA588C} — C:Program FilesSkypeToolbarsInternet ExplorerSkypeIEPlugin.dll
O2 — BHO: Windows Live Family Safety Browser Helper — {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} — C:Program FilesWindows LiveFamily Safetyfssbho.dll
O2 — BHO: Java(tm) Plug-In SSV Helper — {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} — C:Program FilesJavajre6binssv.dll
O2 — BHO: (no name) — {7E853D72-626A-48EC-A868-BA8D5E23E045} — (no file)
O2 — BHO: Спутник@Mail.Ru — {8984B388-A5BB-4DF7-B274-77B879E179DB} — c:program filesmail.rusputnikMailRuSputnik.dll
O2 — BHO: Помощник по входу в Windows Live — {9030D464-4C02-4ABF-8ECC-5164760863C6} — C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 — BHO: IE 4.x-6.x BHO for Download Master — {9961627E-4059-41B4-8E0E-A7D6B3854ADF} — C:PROGRA~1DOWNLO~1dmiehlp.dll
O2 — BHO: — {A1FB2F9A-D35E-11DD-8935-E46A56D89593} — C:Program Filesoovootbdtx.dll
O2 — BHO: Java(tm) Plug-In 2 SSV Helper — {DBC80044-A445-435b-BC74-9C25C1C588A9} — C:Program FilesJavajre6binjp2ssv.dll
O2 — BHO: MyCentria Internet Mate v2.2 — {FFFC57DB-1DE3-4303-B24D-CEE6DCDD3D86} — C:PROGRA~1MYCENT~1InfoBarMYCENT~1.DLL
O3 — Toolbar: DM Bar — {0E1230F8-EA50-42A9-983C-D22ABC2EED3C} — C:Program FilesDownload Masterdmbar.dll
O3 — Toolbar: Rambler-Ассистент — {468CD8A9-7C25-45FA-969E-3D925C689DC4} — C:Program FilesRambler AssistantramblertoolbarU5090.dll
O3 — Toolbar: ooVoo Toolbar — {A1FB2F9A-D35E-11DD-8935-E46A56D89593} — C:Program Filesoovootbdtx.dll
O3 — Toolbar: Спутник@Mail.Ru — {09900DE8-1DCA-443F-9243-26FF581438AF} — c:program filesmail.rusputnikMailRuSputnik.dll
O4 — HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup
O4 — HKLM..Run: [nwiz] nwiz.exe /install
O4 — HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSsystem32NvMcTray.dll,NvTaskbarInit
O4 — HKLM..Run: [RTHDCPL] RTHDCPL.EXE
O4 — HKLM..Run: [AmlMaple] C:Program FilesAmlMapleAmlMaple.exe
O4 — HKLM..Run: [Six Engine] «C:Program FilesASUSEPU-6 EngineSixEngine.exe» -r
O4 — HKLM..Run: [WheelMouse] C:Program FilesA4TechMouseAmoumain.exe
O4 — HKLM..Run: [QuickTime Task] «C:Program FilesQuickTimeqttask.exe» -atboottime
O4 — HKLM..Run: [PAC207_Monitor] C:WINDOWSPixArtPAC207Monitor.exe
O4 — HKLM..Run: [Monitor] C:WINDOWSPixArtPAC207Monitor.exe
O4 — HKLM..Run: [AVP] «C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0avp.exe»
O4 — HKLM..Run: [S60TrayApplication] C:PROGRA~1SamsungSAMSUN~1LAUNCH~1.EXE -onlytray
O4 — HKLM..Run: [DataLayer] C:PROGRA~1COMMON~1PCSuiteDATALA~1DATALA~1.EXE
O4 — HKLM..Run: [RemoteControl] «C:Program FilesCyberLinkPowerDVDPDVDServ.exe»
O4 — HKLM..Run: [NeroFilterCheck] C:Program FilesCommon FilesAheadLibNeroCheck.exe
O4 — HKLM..Run: [fssui] «C:Program FilesWindows LiveFamily Safetyfsui.exe» -autorun
O4 — HKLM..Run: [MAgent] C:Program FilesMail.RuAgentmagent.exe -LM
O4 — HKLM..Run: [avgnt] «C:Program FilesAvira Premium Security Suiteavgnt.exe» /min
O4 — HKLM..Run: [nod32kui] «C:Program FilesEsetnod32kui.exe» /WAITSERVICE
O4 — HKCU..Run: [VistaIcon] C:Program FilesVistaDriveIconVistaDrv.exe
O4 — HKCU..Run: [Punto Switcher] C:Program FilesPunto Switcherps.exe
O4 — HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe
O4 — HKCU..Run: [Google Update] «C:Documents and SettingsAdminLocal SettingsApplication DataGoogleUpdateGoogleUpdate.exe» /c
O4 — HKCU..Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] «C:Program FilesCommon FilesAheadLibNMBgMonitor.exe»
O4 — HKCU..Run: [EA Core] C:Program FilesElectronic ArtsEADMCore.exe -silent
O4 — HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘LOCAL SERVICE’)
O4 — HKUSS-1-5-19..Run: [VistaIcon] C:Program FilesVistaDriveIconVistaDrv.exe (User ‘LOCAL SERVICE’)
O4 — HKUSS-1-5-19..RunOnce: [ZZZZ1_FirstLogonSetting] %SystemRoot%System32rundll32.exe advpack.dll,LaunchINFSection C:WINDOWSINFcustom.inf,OnceFirstLogonInstall,0 (User ‘LOCAL SERVICE’)
O4 — HKUSS-1-5-19..RunOnce: [IE7_012] rundll32 advpack.dll,LaunchINFSectionEx IE7int.inf,AfterUserStart,,4,N (User ‘LOCAL SERVICE’)
O4 — HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘NETWORK SERVICE’)
O4 — HKUSS-1-5-20..RunOnce: [ZZZZ1_FirstLogonSetting] %SystemRoot%System32rundll32.exe advpack.dll,LaunchINFSection C:WINDOWSINFcustom.inf,OnceFirstLogonInstall,0 (User ‘NETWORK SERVICE’)
O4 — HKUSS-1-5-18..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘SYSTEM’)
O4 — HKUSS-1-5-18..RunOnce: [ZZZZ2_FirstLogonSetting] %SystemRoot%System32rundll32.exe advpack.dll,LaunchINFSection C:WINDOWSINFcustom.inf,NewUserFirstLogonInstall,0 (User ‘SYSTEM’)
O4 — HKUS.DEFAULT..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘Default user’)
O4 — HKUS.DEFAULT..RunOnce: [ZZZZ2_FirstLogonSetting] %SystemRoot%System32rundll32.exe advpack.dll,LaunchINFSection C:WINDOWSINFcustom.inf,NewUserFirstLogonInstall,0 (User ‘Default user’)
O4 — Startup: ЎЎЎЎЎЎ.lnk = C:WINDOWSsystem32F353852B33E1.EXE
O6 — HKCUSoftwarePoliciesMicrosoftInternet ExplorerControl Panel present
O7 — HKCUSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem, DisableRegedit=1
O8 — Extra context menu item: &Экспорт в Microsoft Excel — res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000
O8 — Extra context menu item: Add to Google Photos Screensa&ver — res://C:WINDOWSsystem32GPhotos.scr/200
O8 — Extra context menu item: Закачать ВСЕ при помощи Download Master — C:Program FilesDownload Masterdmieall.htm
O8 — Extra context menu item: Закачать при помощи Download Master — C:Program FilesDownload Masterdmie.htm
O8 — Extra context menu item: Найти с помощью Рамблера — res://C:Program FilesRambler AssistantramblertoolbarU5090.dll/search.htm
O8 — Extra context menu item: Перевести с помощью словарей Рамблера — res://C:Program FilesRambler AssistantramblertoolbarU5090.dll/dic.htm
O9 — Extra button: Cтатистика Веб-Антивируса — {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} — C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0SCIEPlgn.dll
O9 — Extra button: Отправка в блог — {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} — C:Program FilesWindows LiveWriterWriterBrowserExtension.dll
O9 — Extra ‘Tools’ menuitem: &Отправка в блог Windows Live Writer — {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} — C:Program FilesWindows LiveWriterWriterBrowserExtension.dll
O9 — Extra button: Mail.Ru Агент — {7558B7E5-7B26-4201-BEDB-00D5FF534523} — C:Program FilesMail.RuAgentmagent.exe
O9 — Extra ‘Tools’ menuitem: Mail.Ru Агент — {7558B7E5-7B26-4201-BEDB-00D5FF534523} — C:Program FilesMail.RuAgentmagent.exe
O9 — Extra button: Skype — {77BF5300-1474-4EC7-9980-D32B190E9B07} — C:Program FilesSkypeToolbarsInternet ExplorerSkypeIEPlugin.dll
O9 — Extra button: Download Master — {8DAE90AD-4583-4977-9DD4-4360F7A45C74} — C:Program FilesDownload Masterdmaster.exe
O9 — Extra ‘Tools’ menuitem: &Download Master — {8DAE90AD-4583-4977-9DD4-4360F7A45C74} — C:Program FilesDownload Masterdmaster.exe
O9 — Extra button: Справочные материалы — {92780B25-18CC-41C8-B9BE-3C9C571A8263} — C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLL
O9 — Extra button: ICQ Lite — {B863453A-26C3-4e1f-A54D-A2CD196348E9} — C:Program FilesICQLiteICQLite.exe (file missing)
O9 — Extra ‘Tools’ menuitem: ICQ Lite — {B863453A-26C3-4e1f-A54D-A2CD196348E9} — C:Program FilesICQLiteICQLite.exe (file missing)
O9 — Extra button: ICQ6 — {E59EB121-F339-4851-A3BA-FE49C35617C2} — C:Program FilesICQ6.5ICQ.exe
O9 — Extra ‘Tools’ menuitem: ICQ6 — {E59EB121-F339-4851-A3BA-FE49C35617C2} — C:Program FilesICQ6.5ICQ.exe
O16 — DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) — http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O17 — HKLMSystemCCSServicesTcpip..{04C556A2-47B7-4F16-BAEC-93C64388CF59}: NameServer = 195.161.15.19
O17 — HKLMSystemCCSServicesTcpip..{1AA94FF5-804D-41C6-A3EC-C35E8CC59594}: NameServer = 81.25.161.2
O17 — HKLMSystemCS1ServicesTcpip..{04C556A2-47B7-4F16-BAEC-93C64388CF59}: NameServer = 195.161.15.19
O18 — Protocol: skype4com — {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} — C:PROGRA~1COMMON~1SkypeSKYPE4~1.DLL
O23 — Service: Adobe LM Service — Adobe Systems — C:Program FilesCommon FilesAdobe Systems SharedServiceAdobelmsvc.exe
O23 — Service: Avira Premium Security Suite Firewall (AntiVirFirewallService) — Avira GmbH — C:Program FilesAvira Premium Security Suiteavfwsvc.exe
O23 — Service: Защита почты Avira Premium Security Suite (AntiVirMailService) — Avira GmbH — C:Program FilesAvira Premium Security Suiteavmailc.exe
O23 — Service: Планировщик Avira Premium Security Suite (AntiVirScheduler) — Avira GmbH — C:Program FilesAvira Premium Security Suitesched.exe
O23 — Service: Постоянная защита Avira Premium Security Suite (AntiVirService) — Avira GmbH — C:Program FilesAvira Premium Security Suiteavguard.exe
O23 — Service: Вспомогательная служба Защиты почты Avira Premium Security Suite (AVEService) — Avira GmbH — C:Program FilesAvira Premium Security Suiteavesvc.exe
O23 — Service: Kaspersky Anti-Virus 7.0 (AVP) — Kaspersky Lab — C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0avp.exe
O23 — Service: Журнал событий (Eventlog) — Корпорация Майкрософт — C:WINDOWSsystem32services.exe
O23 — Service: Google Updater Service (gusvc) — Google — C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 — Service: InstallDriver Table Manager (IDriverT) — Macrovision Corporation — C:Program FilesCommon FilesInstallShieldDriver11Intel 32IDriverT.exe
O23 — Service: Служба COM записи компакт-дисков IMAPI (ImapiService) — Корпорация Майкрософт — C:WINDOWSsystem32imapi.exe
O23 — Service: NBService — Nero AG — C:Program FilesNeroNero 7Nero BackItUpNBService.exe
O23 — Service: NVIDIA Display Driver Service (NVSvc) — NVIDIA Corporation — C:WINDOWSsystem32nvsvc32.exe
O23 — Service: Plug and Play (PlugPlay) — Корпорация Майкрософт — C:WINDOWSsystem32services.exe
O23 — Service: Диспетчер сеанса справки для удаленного рабочего стола (RDSessMgr) — Корпорация Майкрософт — C:WINDOWSsystem32sessmgr.exe
O23 — Service: Смарт-карты (SCardSvr) — Корпорация Майкрософт — C:WINDOWSSystem32SCardSvr.exe
O23 — Service: ServiceLayer — Nokia. — C:Program FilesCommon FilesPCSuiteServicesServiceLayer.exe
O23 — Service: Журналы и оповещения производительности (SysmonLog) — Корпорация Майкрософт — C:WINDOWSsystem32smlogsvc.exe
O23 — Service: Теневое копирование тома (VSS) — Корпорация Майкрософт — C:WINDOWSSystem32vssvc.exe
O23 — Service: Адаптер производительности WMI (WmiApSrv) — Корпорация Майкрософт — C:WINDOWSsystem32wbemwmiapsrv.exe
—
End of file — 13751 bytes
======Scheduled tasks folder======
C:WINDOWStasksAppleSoftwareUpdate.job
C:WINDOWStasksGoogleUpdateTaskUserS-1-5-21-796845957-1417001333-682003330-500Core.job
C:WINDOWStasksGoogleUpdateTaskUserS-1-5-21-796845957-1417001333-682003330-500UA.job
C:WINDOWStasksUser_Feed_Synchronization-{8380E9F9-E742-4C10-B068-E8C5C1B390E8}.job
======Registry dump======
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) — C:Program FilesSkypeToolbarsInternet ExplorerSkypeIEPlugin.dll [2009-01-29 1088296]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{4f3ed5cd-0726-42a9-87f5-d13f3d2976ac}]
Windows Live Family Safety Browser Helper Class — C:Program FilesWindows LiveFamily Safetyfssbho.dll [2008-12-08 61792]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper — C:Program FilesJavajre6binssv.dll [2008-09-22 320920]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{8984B388-A5BB-4DF7-B274-77B879E179DB}]
MailRuBHO Class — c:program filesmail.rusputnikMailRuSputnik.dll [2009-06-08 826032]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Помощник по входу в Windows Live — C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll [2008-11-18 408952]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{9961627E-4059-41B4-8E0E-A7D6B3854ADF}]
IE 4.x-6.x BHO for Download Master — C:PROGRA~1DOWNLO~1dmiehlp.dll [2007-07-20 152064]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{A1FB2F9A-D35E-11DD-8935-E46A56D89593}]
ooVoo Toolbar — C:Program Filesoovootbdtx.dll [2009-03-16 87512]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper — C:Program FilesJavajre6binjp2ssv.dll [2008-09-22 34816]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{FFFC57DB-1DE3-4303-B24D-CEE6DCDD3D86}]
MyCentria Internet Mate v2.2 — C:PROGRA~1MYCENT~1InfoBarMYCENT~1.DLL [2001-01-26 677888]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolbar]
{0E1230F8-EA50-42A9-983C-D22ABC2EED3C} — DM Bar — C:Program FilesDownload Masterdmbar.dll [2007-11-26 180224]
{468CD8A9-7C25-45FA-969E-3D925C689DC4} — Rambler-Ассистент — C:Program FilesRambler AssistantramblertoolbarU5090.dll [2007-07-30 804336]
{A1FB2F9A-D35E-11DD-8935-E46A56D89593} — ooVoo Toolbar — C:Program Filesoovootbdtx.dll [2009-03-16 87512]
{09900DE8-1DCA-443F-9243-26FF581438AF} — Спутник@Mail.Ru — c:program filesmail.rusputnikMailRuSputnik.dll [2009-06-08 826032]
[HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun]
«NvCplDaemon»=C:WINDOWSsystem32NvCpl.dll [2007-12-05 8523776]
«nwiz»=nwiz.exe /install []
«NvMediaCenter»=C:WINDOWSsystem32NvMcTray.dll [2007-12-05 81920]
«RTHDCPL»=C:WINDOWSRTHDCPL.EXE [2008-04-10 16861184]
«AmlMaple»=C:Program FilesAmlMapleAmlMaple.exe [2008-04-24 91648]
«Six Engine»=C:Program FilesASUSEPU-6 EngineSixEngine.exe [2008-06-03 5964800]
«WheelMouse»=C:Program FilesA4TechMouseAmoumain.exe [2006-12-26 274432]
«QuickTime Task»=C:Program FilesQuickTimeqttask.exe [2007-06-29 356352]
«PAC207_Monitor»=C:WINDOWSPixArtPAC207Monitor.exe [2006-11-03 319488]
«Monitor»=C:WINDOWSPixArtPAC207Monitor.exe [2006-11-03 319488]
«AVP»=C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0avp.exe [2007-06-28 218376]
«S60TrayApplication»=C:PROGRA~1SamsungSAMSUN~1LAUNCH~1.EXE [2007-03-14 311296]
«»= []
«DataLayer»=C:PROGRA~1COMMON~1PCSuiteDATALA~1DATALA~1.EXE [2007-02-22 851968]
«RemoteControl»=C:Program FilesCyberLinkPowerDVDPDVDServ.exe [2003-10-31 32768]
«NeroFilterCheck»=C:Program FilesCommon FilesAheadLibNeroCheck.exe [2006-01-12 233472]
«fssui»=C:Program FilesWindows LiveFamily Safetyfsui.exe [2008-12-08 453984]
«MAgent»=C:Program FilesMail.RuAgentmagent.exe [2009-06-08 7957688]
«avgnt»=C:Program FilesAvira Premium Security Suiteavgnt.exe [2007-04-02 327720]
«nod32kui»=C:Program FilesEsetnod32kui.exe [2001-01-26 949376]
[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]
«VistaIcon»=C:Program FilesVistaDriveIconVistaDrv.exe [2008-01-02 132096]
«Punto Switcher»=C:Program FilesPunto Switcherps.exe [2007-11-14 271360]
«ctfmon.exe»=C:WINDOWSsystem32ctfmon.exe [2008-05-20 30208]
«Google Update»=C:Documents and SettingsAdminLocal SettingsApplication DataGoogleUpdateGoogleUpdate.exe [2008-09-21 210928]
«BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}»=C:Program FilesCommon FilesAheadLibNMBgMonitor.exe [2006-06-01 94208]
«EA Core»=C:Program FilesElectronic ArtsEADMCore.exe [2008-07-22 2850816]
C:Documents and SettingsAdminГлавное менюПрограммыАвтозагрузка
ЎЎЎЎЎЎ.lnk — C:WINDOWSsystem32F353852B33E1.EXE
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonNotifyklogon]
C:WINDOWSsystem32klogon.dll [2007-06-28 206088]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoad]
WPDShServiceObj — {AAA288BA-9A4C-45B0-95D7-94D524869DB5} — C:WINDOWSsystem32WPDShServiceObj.dll [2008-03-02 133632]
[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
«DisableRegistryTools»=1
«DisableTaskMgr»=1
[HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
«dontdisplaylastusername»=0
«legalnoticecaption»=
«legalnoticetext»=
«shutdownwithoutlogon»=1
«undockwithoutlogon»=1
«EnableLUA»=0
[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer]
«NoSharedDocuments»=1
«NoSMConfigurePrograms»=1
«NoDrives»=0
[HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer]
«NoDriveTypeAutoRun»=
«NoDrives»=
«NoDriveAutoRun»=
[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicystandardprofileauthorizedapplicationslist]
«%windir%Network Diagnosticxpnetdiag.exe»=»%windir%Network Diagnosticxpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000»
«%windir%system32sessmgr.exe»=»%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019»
«C:Program FilesuTorrentuTorrent.exe»=»C:Program FilesuTorrentuTorrent.exe:*:Enabled:µTorrent»
«C:Program FilesYahoo!MessengerYahooMessenger.exe»=»C:Program FilesYahoo!MessengerYahooMessenger.exe:*:Enabled:Yahoo! Messenger»
«C:Program FilesFreeCall.comFreeCallFreeCall.exe»=»C:Program FilesFreeCall.comFreeCallFreeCall.exe:*:Enabled:FreeCall»
«C:Program FilesWindows LiveSyncWindowsLiveSync.exe»=»C:Program FilesWindows LiveSyncWindowsLiveSync.exe:*:Enabled:Windows Live Sync»
«C:Program FilesMSN Messengermsnmsgr.exe»=»C:Program FilesMSN Messengermsnmsgr.exe:*:Enabled:Windows Live Messenger 8.1»
«C:Program FilesMSN Messengerlivecall.exe»=»C:Program FilesMSN Messengerlivecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)»
«C:Program FilesICQ6.5ICQ.exe»=»C:Program FilesICQ6.5ICQ.exe:*:Enabled:ICQ6»
«C:WINDOWSsystem32PnkBstrA.exe»=»C:WINDOWSsystem32PnkBstrA.exe:*:Enabled:PnkBstrA»
«C:WINDOWSsystem32PnkBstrB.exe»=»C:WINDOWSsystem32PnkBstrB.exe:*:Enabled:PnkBstrB»
«D:GamesНовая папка (5)Launcher.exe»=»D:GamesНовая папка (5)Launcher.exe:*:Enabled:MotoGP 08»
«C:Program FilesuTorrent [tfile.ru]utorrent.exe»=»C:Program FilesuTorrent [tfile.ru]utorrent.exe:*:Enabled:µTorrent»
«C:Documents and SettingsAdminРабочий столНовый_Net Speakerphone 4.6 by BeN.exe»=»C:Documents and SettingsAdminРабочий столНовый_Net Speakerphone 4.6 by BeN.exe:*:Enabled:ipsec»
«C:WINDOWSExplorer.EXE»=»C:WINDOWSExplorer.EXE:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempebtc.exe»=»C:DOCUME~1AdminLOCALS~1Tempebtc.exe:*:Enabled:ipsec»
«C:WINDOWSsystem32nwiz.exe»=»C:WINDOWSsystem32nwiz.exe:*:Enabled:ipsec»
«C:Program FilesCommon FilesAheadLibNeroCheck.exe»=»C:Program FilesCommon FilesAheadLibNeroCheck.exe:*:Enabled:ipsec»
«C:PROGRA~1COMMON~1PCSuiteDATALA~1DATALA~1.EXE»=»C:PROGRA~1COMMON~1PCSuiteDATALA~1DATALA~1.EXE:*:Enabled:ipsec»
«C:WINDOWSsystem32RUNDLL32.EXE»=»C:WINDOWSsystem32RUNDLL32.EXE:*:Enabled:ipsec»
«C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0avp.exe»=»C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0avp.exe:*:Enabled:ipsec»
«C:WINDOWSPixArtPAC207Monitor.exe»=»C:WINDOWSPixArtPAC207Monitor.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwchjvv.exe»=»C:DOCUME~1AdminLOCALS~1Tempwchjvv.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempkrgg.exe»=»C:DOCUME~1AdminLOCALS~1Tempkrgg.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwinwvbawc.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinwvbawc.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwinrsdkrw.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinrsdkrw.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwinoujrr.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinoujrr.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwinokivtl.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinokivtl.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwinhhhwqo.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinhhhwqo.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Temppkner.exe»=»C:DOCUME~1AdminLOCALS~1Temppkner.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwinksxl.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinksxl.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempuvsn.exe»=»C:DOCUME~1AdminLOCALS~1Tempuvsn.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempgrjh.exe»=»C:DOCUME~1AdminLOCALS~1Tempgrjh.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempivtfr.exe»=»C:DOCUME~1AdminLOCALS~1Tempivtfr.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwintqcphs.exe»=»C:DOCUME~1AdminLOCALS~1Tempwintqcphs.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwinkdog.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinkdog.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempoxyn.exe»=»C:DOCUME~1AdminLOCALS~1Tempoxyn.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempw41efe.exe»=»C:DOCUME~1AdminLOCALS~1Tempw41efe.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwinttyjs.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinttyjs.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwinqvfldr.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinqvfldr.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempgyybal.exe»=»C:DOCUME~1AdminLOCALS~1Tempgyybal.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwinamve.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinamve.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempuutuo.exe»=»C:DOCUME~1AdminLOCALS~1Tempuutuo.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwinlntr.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinlntr.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwinypap.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinypap.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwinuydh.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinuydh.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwinumthbb.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinumthbb.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwingpxfh.exe»=»C:DOCUME~1AdminLOCALS~1Tempwingpxfh.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwintwnfxy.exe»=»C:DOCUME~1AdminLOCALS~1Tempwintwnfxy.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempvrccbk.exe»=»C:DOCUME~1AdminLOCALS~1Tempvrccbk.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwinhuxyv.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinhuxyv.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempjkge.exe»=»C:DOCUME~1AdminLOCALS~1Tempjkge.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwintxdvij.exe»=»C:DOCUME~1AdminLOCALS~1Tempwintxdvij.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Temproawkk.exe»=»C:DOCUME~1AdminLOCALS~1Temproawkk.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Templecna.exe»=»C:DOCUME~1AdminLOCALS~1Templecna.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwf0513d.exe»=»C:DOCUME~1AdminLOCALS~1Tempwf0513d.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempaluy.exe»=»C:DOCUME~1AdminLOCALS~1Tempaluy.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwinxdni.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinxdni.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwincpro.exe»=»C:DOCUME~1AdminLOCALS~1Tempwincpro.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempw4c187.exe»=»C:DOCUME~1AdminLOCALS~1Tempw4c187.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwincoog.exe»=»C:DOCUME~1AdminLOCALS~1Tempwincoog.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempmohv.exe»=»C:DOCUME~1AdminLOCALS~1Tempmohv.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwinnuxblf.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinnuxblf.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwinrtgpf.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinrtgpf.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwinqsce.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinqsce.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwinjxaanw.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinjxaanw.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempw53fb0.exe»=»C:DOCUME~1AdminLOCALS~1Tempw53fb0.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwinaooq.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinaooq.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwingwic.exe»=»C:DOCUME~1AdminLOCALS~1Tempwingwic.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwinxgjh.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinxgjh.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempbpkeag.exe»=»C:DOCUME~1AdminLOCALS~1Tempbpkeag.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempkaxy.exe»=»C:DOCUME~1AdminLOCALS~1Tempkaxy.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Templbefg.exe»=»C:DOCUME~1AdminLOCALS~1Templbefg.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempw4580f.exe»=»C:DOCUME~1AdminLOCALS~1Tempw4580f.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempbfglxo.exe»=»C:DOCUME~1AdminLOCALS~1Tempbfglxo.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwinwojpp.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinwojpp.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempreqs.exe»=»C:DOCUME~1AdminLOCALS~1Tempreqs.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempdsbdr.exe»=»C:DOCUME~1AdminLOCALS~1Tempdsbdr.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempw47b95.exe»=»C:DOCUME~1AdminLOCALS~1Tempw47b95.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwinhqcxp.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinhqcxp.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempeajca.exe»=»C:DOCUME~1AdminLOCALS~1Tempeajca.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwjilts.exe»=»C:DOCUME~1AdminLOCALS~1Tempwjilts.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwinclfs.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinclfs.exe:*:Enabled:ipsec»
«C:WINDOWSRTHDCPL.EXE»=»C:WINDOWSRTHDCPL.EXE:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwingdtei.exe»=»C:DOCUME~1AdminLOCALS~1Tempwingdtei.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwinxcjh.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinxcjh.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwinlcyg.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinlcyg.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwinxfpxux.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinxfpxux.exe:*:Enabled:ipsec»
«C:Program FilesA4TechMouseAmoumain.exe»=»C:Program FilesA4TechMouseAmoumain.exe:*:Enabled:ipsec»
«C:WINDOWSsystem32ctfmon.exe»=»C:WINDOWSsystem32ctfmon.exe:*:Enabled:ipsec»
«C:Program FilesSkypePhoneSkype.exe»=»C:Program FilesSkypePhoneSkype.exe:*:Enabled:Skype»
«C:DOCUME~1AdminLOCALS~1Tempwinpsiuwl.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinpsiuwl.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Temphoaan.exe»=»C:DOCUME~1AdminLOCALS~1Temphoaan.exe:*:Enabled:ipsec»
«C:DOCUME~1AdminLOCALS~1Tempwinpavfn.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinpavfn.exe:*:Enabled:ipsec»
[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicydomainprofileauthorizedapplicationslist]
«%windir%Network Diagnosticxpnetdiag.exe»=»%windir%Network Diagnosticxpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000»
«%windir%system32sessmgr.exe»=»%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019»
«C:Program FilesWindows LiveSyncWindowsLiveSync.exe»=»C:Program FilesWindows LiveSyncWindowsLiveSync.exe:*:Enabled:Windows Live Sync»
«C:Program FilesMSN Messengermsnmsgr.exe»=»C:Program FilesMSN Messengermsnmsgr.exe:*:Enabled:Windows Live Messenger 8.1»
«C:Program FilesMSN Messengerlivecall.exe»=»C:Program FilesMSN Messengerlivecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)»
[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{93d0092c-6f4c-11dd-b438-0022152ccbf3}]
shellAutoRuncommand — L:RECYCLERS-1-5-21-1482476501-1644491937-682003330-1013isi32.exe
shellopencommand — L:RECYCLERS-1-5-21-1482476501-1644491937-682003330-1013isi32.exe
[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{93d00950-6f4c-11dd-b438-0022152ccbf3}]
shellaUTOpLaycommand — J:mooeck.pif
shellAutoRuncommand — J:mooeck.pif
shelleXplorecommand — J:mooeck.pif
shelloPencommand — J:mooeck.pif
[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{98cba4e6-a5b8-11dd-b4e8-0022152ccbf3}]
shellAutoRuncommand — J:RECYCLERS-1-5-21-1482476501-1644491937-682003330-1013isi32.exe
shellopencommand — J:RECYCLERS-1-5-21-1482476501-1644491937-682003330-1013isi32.exe
======List of files/folders created in the last 1 months======
2009-07-04 19:24:03 —-D—- C:Program FilesAvira Premium Security Suite
2009-07-04 19:24:03 —-D—- C:Documents and SettingsAll UsersApplication DataAvira Premium Security Suite
2009-07-04 19:24:03 —-A—- C:WINDOWSsystem32avsda.dll
2009-07-02 17:56:19 —-D—- C:Program FilesMicrosoft Silverlight
2009-06-29 18:44:28 —-D—- C:Program FilesMSECache
2009-06-20 19:35:13 —-D—- C:Program FilesREDEMAX
2009-06-20 17:29:55 —-D—- C:Program FilesmyAC_mtcv
2009-06-18 19:37:45 —-D—- C:Program FilesAlawar.ru
2009-06-13 11:44:36 —-D—- C:Program FilesCommon FilesAdobe Systems Shared
2009-06-13 11:43:49 —-D—- C:Program FilesCommon FilesAdobe
2009-06-13 11:43:48 —-D—- C:Documents and SettingsAll UsersApplication DataAdobe
2009-05-31 17:06:43 —-D—- C:Program FilesuTorrent [tfile.ru]
2009-05-16 15:51:27 —-N—- C:WINDOWSsystem32vxblock.dll
2009-05-16 15:51:27 —-N—- C:WINDOWSsystem32pxwave.dll
2009-05-16 15:51:27 —-N—- C:WINDOWSsystem32pxmas.dll
2009-05-16 15:51:27 —-N—- C:WINDOWSsystem32pxhpinst.exe
2009-05-16 15:51:27 —-N—- C:WINDOWSsystem32pxdrv.dll
2009-05-16 15:51:27 —-N—- C:WINDOWSsystem32px.dll
2009-05-16 15:50:52 —-D—- C:WINDOWSsystem32IOSUBSYS
2009-05-12 11:39:13 —-D—- C:Program FilesElectronic Arts
2009-05-12 11:39:11 —-D—- C:ProgramData
2009-05-12 11:38:45 —-D—- C:Documents and SettingsAdminApplication DataLeadertech
2009-04-23 19:29:27 —-D—- C:Documents and SettingsAdminApplication DataEmailNotifier
2009-04-23 18:42:31 —-D—- C:Documents and SettingsAll UsersApplication DataEmailNotifier
2009-04-23 18:42:30 —-D—- C:Program Filesoovootb
2009-04-23 18:42:30 —-D—- C:Documents and SettingsAdminApplication Dataoovootb
2009-04-01 18:51:26 —-D—- C:Documents and SettingsAdminApplication DataDAEMON Tools Pro
2009-04-01 18:50:36 —-D—- C:Documents and SettingsAll UsersApplication DataDAEMON Tools Lite
2009-04-01 18:49:12 —-D—- C:Program FilesDAEMON Tools Lite
2009-04-01 18:49:08 —-D—- C:Documents and SettingsAdminApplication DataDAEMON Tools Lite
2009-03-29 13:49:22 —-D—- C:Program Filesvalve
2009-03-27 09:19:04 —-A—- C:WINDOWSsystem32PnkBstrB.exe
2009-03-27 09:19:03 —-A—- C:WINDOWSsystem32PnkBstrA.exe
2009-03-27 09:19:03 —-A—- C:WINDOWSsystem32pbsvc.exe
2009-03-25 16:42:32 —-D—- C:Documents and SettingsAll UsersApplication DataAlawarWrapper
2009-03-25 16:41:37 —-D—- C:Program FilesGames.Mail.Ru
2009-03-17 14:38:48 —-HD—- C:WINDOWSsystem32F35385
2009-03-17 14:38:48 —-HD—- C:WINDOWSsystem325D927B
2009-03-17 14:38:48 —-HD—- C:WINDOWSsystem32130AC6
2009-03-16 20:44:57 —-D—- C:Program FilesViewpoint
2009-03-16 20:44:56 —-A—- C:WINDOWScm.ini
2009-03-09 17:13:31 —-D—- C:Documents and SettingsAll UsersApplication DataTest Drive Unlimited
2009-02-25 15:20:52 —-D—- C:Documents and SettingsAll UsersApplication DataSSScanAppDataDir
2009-02-25 15:19:07 —-D—- C:Documents and SettingsAll UsersApplication DataMSScanAppDataDir
2009-02-14 21:10:28 —-D—- C:Program FilesCommon FilesSkype
2009-02-13 20:28:20 —-A—- C:WINDOWSsystem32MPG4c32.dll
2009-02-13 13:20:48 —-RHD—- C:Documents and SettingsAdminApplication DataSecuROM
2009-02-13 13:18:09 —-D—- C:WINDOWSsystem32xlive
2009-02-13 13:18:09 —-D—- C:Program FilesMicrosoft Games for Windows — LIVE
2009-02-13 12:42:24 —-HDC—- C:WINDOWS$NtUninstallXPSEPSCLP$
2009-02-13 12:40:59 —-D—- C:Program FilesMSBuild
2009-02-13 12:40:06 —-D—- C:WINDOWSsystem32XPSViewer
2009-02-13 12:40:04 —-D—- C:WINDOWSsystem32en-us
2009-02-13 12:39:38 —-D—- C:Program FilesReference Assemblies
2009-02-13 12:39:24 —-N—- C:WINDOWSsystem32spmsg2.dll
2009-02-09 16:04:35 —-D—- C:Program FilesPlasma Pong
2009-02-09 15:45:41 —-D—- C:Documents and SettingsAll UsersApplication DataMumboJumbo
2009-02-09 15:45:36 —-D—- C:Program FilesLuxor 2
2009-02-06 12:55:14 —-D—- C:Documents and SettingsAdminApplication Datarambler.ru
2009-02-06 12:55:12 —-D—- C:Program FilesRambler Assistant
2009-02-06 12:50:55 —-D—- C:Program FilesICQ6.5
2009-02-03 16:29:04 —-D—- C:Program FilesArtMoney
2009-01-08 14:06:28 —-D—- C:Program FilesMSN Messenger
2009-01-03 14:35:27 —-A—- C:WINDOWSkalendar.ini
2008-12-29 07:21:49 —-D—- C:Program Filesscilab-4.1.2
2008-12-17 20:52:53 —-A—- C:WINDOWSavisplitter.INI
2008-12-17 20:46:09 —-D—- C:Documents and SettingsAll UsersApplication DataOffice Genuine Advantage
2008-12-17 20:19:22 —-D—- C:Program FilesMicrosoft SQL Server Compact Edition
2008-12-17 20:17:45 —-D—- C:Program FilesMicrosoft
2008-12-17 20:17:27 —-D—- C:Program FilesWindows Live SkyDrive
2008-12-17 19:22:16 —-D—- C:Program FilesCommon FilesWindows Live
2008-12-10 11:05:12 —-A—- C:WINDOWSsystem32vcomp.dll
2008-12-10 11:05:04 —-A—- C:WINDOWSsystem32OpenALwEAX.exe
2008-12-10 11:04:57 —-A—- C:WINDOWSsystem32mfc80KOR.dll
2008-12-10 11:04:57 —-A—- C:WINDOWSsystem32mfc80JPN.dll
2008-12-10 11:04:57 —-A—- C:WINDOWSsystem32mfc80ITA.dll
2008-12-10 11:04:57 —-A—- C:WINDOWSsystem32mfc80FRA.dll
2008-12-10 11:04:57 —-A—- C:WINDOWSsystem32mfc80ESP.dll
2008-12-10 11:04:57 —-A—- C:WINDOWSsystem32mfc80ENU.dll
2008-12-10 11:04:57 —-A—- C:WINDOWSsystem32mfc80DEU.dll
2008-12-10 11:04:57 —-A—- C:WINDOWSsystem32mfc80CHT.dll
2008-12-10 11:04:57 —-A—- C:WINDOWSsystem32mfc80CHS.dll
2008-12-10 11:04:45 —-A—- C:WINDOWSsystem32ATL80.dll
2008-12-09 19:38:51 —-D—- C:Program FilesWMV9_VCM
2008-12-09 19:38:23 —-D—- C:Program Files1C
2008-12-09 19:27:00 —-D—- C:Documents and SettingsAdminApplication DataDAEMON Tools
2008-12-09 18:54:42 —-RA—- C:WINDOWSsystem32tmpF5.tmp
2008-12-09 18:54:42 —-RA—- C:WINDOWSsystem32tmpF4.tmp
2008-12-09 18:54:42 —-D—- C:Program FilesOpenAL
2008-12-09 18:54:24 —-A—- C:WINDOWSsystem32xmlinst.exe
2008-12-09 18:54:24 —-A—- C:WINDOWSsystem32vp6vfw.dll
2008-12-09 18:54:24 —-A—- C:WINDOWSsystem32vp6install.exe
2008-12-09 18:54:22 —-N—- C:WINDOWSsystem32msvcr80.dll
2008-12-09 18:54:22 —-A—- C:WINDOWSsystem32Vb5db.dll
2008-12-09 18:54:22 —-A—- C:WINDOWSsystem32msxml4a.dll
2008-12-09 18:54:22 —-A—- C:WINDOWSsystem32msxml3a.dll
2008-12-09 18:54:21 —-A—- C:WINDOWSsystem32msvcr71d.dll
2008-12-09 18:54:21 —-A—- C:WINDOWSsystem32msvcr70d.dll
2008-12-09 18:54:20 —-N—- C:WINDOWSsystem32msvcp80.dll
2008-12-09 18:54:20 —-A—- C:WINDOWSsystem32msvcp71d.dll
2008-12-09 18:54:20 —-A—- C:WINDOWSsystem32msvcp70d.dll
2008-12-09 18:54:19 —-N—- C:WINDOWSsystem32msvcm80.dll
2008-12-09 18:54:19 —-A—- C:WINDOWSsystem32Msvcp60d.dll
2008-12-09 18:54:19 —-A—- C:WINDOWSsystem32msvci70d.dll
2008-12-09 18:54:18 —-A—- C:WINDOWSsystem32mfcm80u.dll
2008-12-09 18:54:18 —-A—- C:WINDOWSsystem32mfcm80.dll
2008-12-09 18:54:18 —-A—- C:WINDOWSsystem32mfc80u.dll
2008-12-09 18:54:18 —-A—- C:WINDOWSsystem32mfc80.dll
2008-12-09 18:54:16 —-A—- C:WINDOWSsystem32eax.dll
2008-12-09 18:54:16 —-A—- C:WINDOWSsystem32Cc3250mt.dll
2008-12-09 18:54:15 —-A—- C:WINDOWSsystem32xmltok.dll
2008-12-09 18:54:15 —-A—- C:WINDOWSsystem32xmlparse.dll
2008-12-09 18:54:15 —-A—- C:WINDOWSsystem32Borlndmm.dll
2008-11-17 20:25:35 —-A—- C:WINDOWSmafosav.INI
2008-11-17 20:23:34 —-D—- C:Program FilesMario Forever
2008-11-17 20:23:22 —-D—- C:Program FilesRicochet Infinity
2008-11-17 20:23:18 —-A—- C:WINDOWSsystem32BASSMOD.dll
2008-11-17 20:11:19 —-A—- C:WINDOWSPerfectPool.INI
2008-11-10 16:43:13 —-D—- C:Documents and SettingsAll UsersApplication DataNFS Underground
2008-11-10 08:23:29 —-D—- C:Program FilesCommon FilesDirectX
2008-11-08 14:53:24 —-A—- C:WINDOWS_MSRSTRT.EXE
2008-11-07 15:43:19 —-D—- C:WINDOWSDownloaded Installations
2008-11-06 20:26:56 —-D—- C:Program FilesNet Spikerphone 4.6
2008-11-06 20:10:09 —-D—- C:Documents and SettingsAdminApplication DataASCON
2008-10-31 16:06:12 —-D—- C:Program FilesCommon FilesBorland Shared
2008-10-31 15:56:19 —-A—- C:WINDOWSsystem32haspvdd.dll
2008-10-31 15:55:14 —-D—- C:Program FilesCommon FilesASCON Shared
2008-10-31 15:54:52 —-D—- C:Program FilesASCON
2008-10-28 17:41:22 —-A—- C:WINDOWSsystem32xlive.dll
2008-10-28 17:41:20 —-A—- C:WINDOWSsystem32xlivefnt.dll
2008-10-28 17:40:48 —-A—- C:WINDOWSsystem32xlive.dll.cat
2008-10-25 10:37:39 —-D—- C:Documents and SettingsAdminApplication DataOpera
2008-10-25 10:37:36 —-D—- C:Program FilesOpera
2008-10-12 15:13:05 —-D—- C:Documents and SettingsAdminApplication DataCyberLink
2008-10-12 15:12:18 —-D—- C:Documents and SettingsAll UsersApplication DataCyberLink
2008-10-12 15:12:14 —-D—- C:Program FilesCyberLink
2008-10-07 14:07:10 —-A—- C:WINDOWSNeroDigital.ini
2008-10-07 14:05:07 —-D—- C:Documents and SettingsAdminApplication DataAhead
2008-10-07 14:04:30 —-D—- C:Program FilesCommon FilesAhead
2008-10-06 18:02:44 —-D—- C:Documents and SettingsAdminApplication DataSkype
2008-10-06 18:02:37 —-RD—- C:Program FilesSkype
2008-10-06 09:10:44 —-D—- C:Documents and SettingsAdminApplication Datagtk-2.0
2008-10-06 09:09:49 —-D—- C:Documents and SettingsAdminApplication Dataavidemux
2008-10-06 08:48:24 —-D—- C:Documents and SettingsAll UsersApplication DataPinnacle
2008-10-05 19:18:08 —-A—- C:WINDOWSsystem32NCTAudioPlayer2.dll
2008-10-05 19:18:08 —-A—- C:WINDOWSsystem32NCTAudioFormatSettings3.dll
2008-10-05 19:18:08 —-A—- C:WINDOWSsystem32NCTAudioFile2.dll
2008-10-05 19:18:08 —-A—- C:WINDOWSsystem32NCTAudioCompress3.dll
2008-10-05 19:18:08 —-A—- C:WINDOWSsystem32NCTAudioCompress2.dll
2008-10-05 19:18:08 —-A—- C:WINDOWSsystem32lame_enc.dll
2008-10-05 19:18:08 —-A—- C:WINDOWSsystem32gdiplus.dll
2008-10-05 19:18:06 —-D—- C:WINDOWSsystem32RMBin
2008-10-05 19:18:06 —-A—- C:WINDOWSsystem32viscomwave.dll
2008-10-05 19:18:06 —-A—- C:WINDOWSsystem32viscomqtenc.dll
2008-10-05 19:18:06 —-A—- C:WINDOWSsystem32viscomqtde.dll
2008-10-05 19:18:06 —-A—- C:WINDOWSsystem32SkinCrafter.dll
2008-10-04 17:55:55 —-D—- C:Documents and SettingsAll UsersApplication DataAdobe Systems
2008-10-04 17:54:42 —-D—- C:Program FilesAdobe
2008-10-04 15:07:58 —-D—- C:Documents and SettingsAll UsersApplication DataYahoo!
2008-10-04 15:07:56 —-D—- C:Program FilesYahoo!
2008-10-02 13:12:10 —-A—- C:WINDOWSsystem32XAudio2_1.dll
2008-10-02 13:12:10 —-A—- C:WINDOWSsystem32XAPOFX1_0.dll
2008-10-02 13:12:10 —-A—- C:WINDOWSsystem32xactengine3_1.dll
2008-10-02 13:12:09 —-A—- C:WINDOWSsystem32X3DAudio1_4.dll
2008-10-02 13:12:08 —-A—- C:WINDOWSsystem32D3DX9_38.dll
2008-10-02 13:12:08 —-A—- C:WINDOWSsystem32d3dx10_38.dll
2008-10-02 13:12:08 —-A—- C:WINDOWSsystem32D3DCompiler_38.dll
2008-10-02 13:11:25 —-D—- C:WINDOWSsystem32DirectX
2008-10-02 13:09:32 —-D—- C:WINDOWSLogs
2008-09-30 19:10:28 —-D—- C:Documents and SettingsAdminApplication DataMultimedia Player
2008-09-30 19:05:56 —-D—- C:Documents and SettingsAdminApplication DataDatalayer
2008-09-30 19:01:13 —-D—- C:Documents and SettingsAll UsersApplication DataPC Suite
2008-09-30 19:01:13 —-D—- C:Documents and SettingsAdminApplication DataPC Suite
2008-09-30 19:01:09 —-D—- C:Program FilesCommon FilesPCSuite
2008-09-30 19:00:41 —-D—- C:Documents and SettingsAll UsersApplication DataDownloaded Installations
2008-09-30 19:00:07 —-A—- C:WINDOWSsystem32nmwcdcls.dll
2008-09-30 16:22:22 —-D—- C:Documents and SettingsAdminApplication DataUbisoft
2008-09-30 15:20:27 —-SHD—- C:RECYCLER
2008-09-30 13:45:32 —-D—- C:WINDOWStemp
2008-09-26 20:40:18 —-D—- C:WINDOWSerdnt
2008-09-25 18:29:56 —-D—- C:Documents and SettingsAdminApplication DataWildfire
2008-09-25 18:29:19 —-D—- C:Program FilesReflexiveArcade
2008-09-25 17:56:27 —-A—- C:WINDOWSsystem32Remover.ini
2008-09-25 17:56:27 —-A—- C:WINDOWSsystem32Remove.exe
2008-09-25 17:56:27 —-A—- C:WINDOWSsystem32CoInst_071102.dll
2008-09-25 17:56:26 —-D—- C:WINDOWSPixArt
2008-09-25 17:56:26 —-D—- C:Program FilesCommon FilesPAC207
2008-09-25 17:56:26 —-A—- C:WINDOWSsystem32SP207.ini
2008-09-24 19:10:51 —-D—- C:WINDOWSAlbum
2008-09-22 20:25:57 —-D—- C:Program FilesCCleaner
2008-09-22 20:09:10 —-D—- C:Documents and SettingsAdminApplication DataooVoo Details
2008-09-22 20:09:07 —-D—- C:Program FilesooVoo
2008-09-22 18:35:19 —-D—- C:Program FilesSun
2008-09-22 18:34:23 —-A—- C:WINDOWSsystem32deploytk.dll
2008-09-22 09:59:00 —-A—- C:WINDOWSeurope.ini
2008-09-21 16:57:45 —-HDC—- C:WINDOWSie8
2008-09-21 11:57:15 —-HDC—- C:WINDOWSie7
2008-09-21 11:53:28 —-D—- C:Documents and SettingsAdminApplication DataPCF-VLC
2008-09-20 18:28:52 —-D—- C:Documents and SettingsAdminApplication DataSamsung
2008-09-20 18:12:31 —-D—- C:WINDOWSsystem32Samsung PC Studio Codecs
2008-09-20 18:12:23 —-A—- C:WINDOWSsystem32fun_mp4_enc.dll
2008-09-20 18:12:23 —-A—- C:WINDOWSsystem32fun_mp4_dec.dll
2008-09-20 18:12:23 —-A—- C:WINDOWSsystem32fun_avcodec.dll
2008-09-20 18:10:52 —-D—- C:WINDOWSsystem32Samsung_USB_Drivers
2008-09-20 18:10:51 —-D—- C:Program FilesSamsung
2008-09-20 12:37:45 —-D—- C:WINDOWSsystem32appmgmt
2008-09-20 10:35:59 —-D—- C:Documents and SettingsAdminApplication DataParticipatory Culture Foundation
2008-09-20 10:35:38 —-D—- C:Program FilesParticipatory Culture Foundation
2008-09-19 17:36:28 —-D—- C:WINDOWSSun
2008-09-14 09:47:16 —-D—- C:Documents and SettingsAdminApplication DataNero
2008-09-09 21:43:24 —-D—- C:WINDOWSie7updates
2008-09-09 21:42:02 —-HDC—- C:WINDOWS$NtServicePackUninstallIDNMitigationAPIs$
2008-09-09 21:41:50 —-A—- C:WINDOWSsystem32spupdsvc.exe
2008-09-09 21:41:49 —-HDC—- C:WINDOWS$NtServicePackUninstallNLSDownlevelMapping$
2008-09-09 21:41:34 —-HD—- C:WINDOWS$hf_mig$
2008-09-09 21:40:39 —-A—- C:WINDOWSsystem32MRT.exe
2008-09-01 19:21:01 —-D—- C:Documents and SettingsAdminApplication DataMeridian93
2008-08-25 19:52:09 —-D—- C:Documents and SettingsAdminApplication DataDownload Master
2008-08-24 07:49:01 —-D—- C:Documents and SettingsAdminApplication DataskypePM
2008-08-22 02:05:00 —-N—- C:WINDOWSsystem32PrivacIE.dll
2008-08-21 18:46:33 —-D—- C:Documents and SettingsAdminApplication DataWinRAR
2008-08-21 11:50:55 —-D—- C:Documents and SettingsAdminApplication DataHamachi
2008-08-20 18:06:35 —-D—- C:Documents and SettingsAdminApplication DataGoogle
2008-08-20 18:06:15 —-D—- C:Program FilesGoogle
2008-08-18 19:27:02 —-D—- C:Documents and SettingsAdminApplication DataNetSpeakerphone
2008-08-17 16:28:43 —-D—- C:Documents and SettingsAdminApplication DataApple Computer
2008-08-13 18:34:19 —-D—- C:Documents and SettingsAdminApplication DataICQ
2008-08-13 18:33:57 —-D—- C:Program FilesICQ6
2008-08-13 18:33:21 —-D—- C:Documents and SettingsAdminApplication DataInstallShield
2008-08-13 18:32:46 —-D—- C:Program FilesQuickTime
2008-08-13 18:32:45 —-D—- C:Documents and SettingsAll UsersApplication DataApple Computer
2008-08-13 18:32:40 —-D—- C:Program FilesApple Software Update
2008-08-13 18:32:40 —-D—- C:Documents and SettingsAll UsersApplication DataApple
2008-08-13 18:31:42 —-D—- C:Documents and SettingsAdminApplication DataMra
2008-08-13 18:31:42 —-D—- C:Documents and SettingsAdminApplication DataMail.Ru
2008-08-13 18:31:37 —-D—- C:Program FilesMail.Ru
2008-08-13 18:30:51 —-D—- C:Temp
2008-08-13 18:29:01 —-D—- C:Program FilesICQLite
2008-08-13 18:29:01 —-D—- C:Documents and SettingsAdminApplication DataICQLite
2008-08-13 09:33:43 —-D—- C:Documents and SettingsAdminApplication DataGracebyte Software
2008-08-13 09:27:18 —-D—- C:Documents and SettingsAll UsersApplication DatanView_Profiles
2008-08-12 20:16:08 —-D—- C:Documents and SettingsAdminApplication DataSun
2008-08-12 20:05:13 —-D—- C:Documents and SettingsAdminApplication DataMozilla
2008-08-12 18:51:29 —-SHDC—- C:Program FilesCommon FilesWindowsLiveInstaller
2008-08-12 18:51:25 —-D—- C:Program FilesWindows Live
2008-08-12 18:51:21 —-D—- C:Documents and SettingsAll UsersApplication DataWLInstaller
2008-08-12 18:50:39 —-D—- C:Documents and SettingsAll UsersApplication DataSkype
2008-08-12 18:47:27 —-A—- C:WINDOWSsystem32E_DCINST.DLL
2008-08-12 18:47:26 —-A—- C:WINDOWSsystem32E_FLBBEP.DLL
2008-08-12 18:47:26 —-A—- C:WINDOWSsystem32E_FD4BBEP.DLL
2008-08-12 18:45:39 —-D—- C:Documents and SettingsAdminApplication DatauTorrent
2008-08-12 09:36:42 —-A—- C:WINDOWSEPSMTL32.TXT
2008-08-12 09:36:10 —-D—- C:Program Filesepson
2008-08-12 09:35:59 —-A—- C:WINDOWSCDE CX3900ERUK.ini
2008-08-12 09:33:59 —-A—- C:WINDOWSsystem32escwiad.dll
2008-08-12 09:33:59 —-A—- C:WINDOWSsystem32escimgd.dll
2008-08-12 09:33:59 —-A—- C:WINDOWSsystem32esccmd.dll
2008-08-12 09:27:01 —-D—- C:Documents and SettingsAdminApplication DataHelp
2008-08-12 09:25:11 —-D—- C:Program FilesCommon FilesLogitech
2008-08-12 09:24:51 —-A—- C:WINDOWSIsUninst.exe
2008-08-12 09:24:49 —-A—- C:WINDOWS_delis32.ini
2008-08-11 20:06:14 —-D—- C:Documents and SettingsAdminApplication DataMedia Player Classic
2008-08-11 19:38:38 —-D—- C:Downloads
2008-08-11 19:17:46 —-A—- C:WINDOWSsystem32vfwwdm32.dll
2008-08-11 19:11:32 —-D—- C:Documents and SettingsAdminApplication DataMacromedia
2008-08-11 19:11:32 —-D—- C:Documents and SettingsAdminApplication DataAdobe
2008-08-11 19:09:11 —-D—- C:Program FilesA4Tech
2008-08-11 11:14:11 —-D—- C:WINDOWSsystem32LogFiles
2008-08-11 11:13:40 —-D—- C:Program FilesKaspersky Lab
2008-08-11 11:13:40 —-D—- C:Documents and SettingsAll UsersApplication DataKaspersky Lab
2008-08-11 11:12:47 —-D—- C:Documents and SettingsAll UsersApplication DataKaspersky Lab Setup Files
2008-08-09 17:15:14 —-A—- C:WINDOWSsystem32h323log.txt
2008-08-09 17:14:41 —-D—- C:WINDOWSsystem32RTCOM
2008-08-09 17:14:41 —-A—- C:WINDOWSsystem32ksuser.dll
2008-08-09 17:13:52 —-D—- C:WINDOWSnview
2008-08-09 17:13:52 —-D—- C:WINDOWSNV11201604.TMP
2008-08-09 17:13:52 —-A—- C:WINDOWSsystem32nwiz.exe
2008-08-09 17:13:52 —-A—- C:WINDOWSsystem32nvwrsru.dll
2008-08-09 17:13:52 —-A—- C:WINDOWSsystem32nvwimg.dll
2008-08-09 17:13:52 —-A—- C:WINDOWSsystem32nvwdmcpl.dll
2008-08-09 17:13:52 —-A—- C:WINDOWSsystem32nvuninst.exe
2008-08-09 17:13:52 —-A—- C:WINDOWSsystem32nvudisp.exe
2008-08-09 17:13:52 —-A—- C:WINDOWSsystem32nvshell.dll
2008-08-09 17:13:52 —-A—- C:WINDOWSsystem32nvrsru.dll
2008-08-09 17:13:52 —-A—- C:WINDOWSsystem32nvmccsrs.dll
2008-08-09 17:13:52 —-A—- C:WINDOWSsystem32nview.dll
2008-08-09 17:13:52 —-A—- C:WINDOWSsystem32nvexpbar.dll
2008-08-09 17:13:52 —-A—- C:WINDOWSsystem32nvdspsch.exe
2008-08-09 17:13:52 —-A—- C:WINDOWSsystem32nvcpluir.dll
2008-08-09 17:13:52 —-A—- C:WINDOWSsystem32nvcplui.exe
2008-08-09 17:13:52 —-A—- C:WINDOWSsystem32nvcolor.exe
2008-08-09 17:13:52 —-A—- C:WINDOWSsystem32nvappbar.exe
2008-08-09 17:13:52 —-A—- C:WINDOWSsystem32keystone.exe
2008-08-09 17:13:24 —-A—- C:WINDOWSsystem32usbui.dll
2008-08-09 17:11:43 —-SHD—- C:WINDOWSInstaller
2008-08-09 17:11:43 —-A—- C:WINDOWSsystem32PerfStringBackup.INI
2008-08-09 17:11:42 —-D—- C:Program FilesCommon FilesODBC
2008-08-09 17:11:42 —-A—- C:WINDOWSODBCINST.INI
2008-08-09 17:11:40 —-RD—- C:Program Files
2008-08-09 17:11:40 —-D—- C:Program FilesCommon FilesSpeechEngines
2008-08-09 17:11:40 —-D—- C:Program FilesCommon FilesMicrosoft Shared
2008-08-09 17:11:40 —-D—- C:Program FilesCommon Files
2008-08-09 17:11:37 —-RA—- C:WINDOWSsystem32kbdtuq.dll
2008-08-09 17:11:37 —-RA—- C:WINDOWSsystem32kbdtuf.dll
2008-08-09 17:11:37 —-RA—- C:WINDOWSsystem32kbdazel.dll
2008-08-09 17:11:36 —-RA—- C:WINDOWSsystem32kbdhept.dll

