Jeste predtim nez si odepsal tak jsem naformatoval cely HDD nainstalovat novy win v domneni ze se problemy vyresi ale nevyresily doufam ze jsem nenadelal vice skody nez uzitku zjistil jsem ze to co mi zpusobuje tyto problemy je vir DNS changer nedari se mi ho zbavit i kdyz ho v offline modu vymazu pres MBAM tak hned jak zapnu internet tak ho mam zas a kdyz se uz ho zbavim tak mi nejde internet tak dam repair na moje pripojeni internet se sice rozjede ale DNS changer mam zas.Tak jsem davam novy log z MBAM,Combo fix a RSIT.
Malwarebytes' Anti-Malware 1.40
Database version: 2551
Windows 5.1.2600 Service Pack 3
7.8.2009 19:08:34
MBAM_log.txt
Scan type: Quick Scan
Objects scanned: 88239
Time elapsed: 59 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 4
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.224 85.255.112.64 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{758cd463-497d-4e8b-94c2-508262794d3c}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.224 85.255.112.64 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.224 85.255.112.64 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{758cd463-497d-4e8b-94c2-508262794d3c}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.224 85.255.112.64 -> No action taken.
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
----------------------------------------------------------------------------------------------------------------------------------------
info.txt logfile of random's system information tool 1.06 2009-08-07 19:09:31
======Uninstall list======
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
AMD Processor Driver-->C:\Program Files\InstallShield Installation Information\{C151CE54-E7EA-4804-854B-F515368B0798}\setup.exe -runfromtemp -l0x0009 -removeonly
ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_9DE96A29E721D90A.exe" /uninstall
Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
QIP 2005 8090-->"D:\Program Files\QIP\unins000.exe"
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x9 -removeonly
VentriloMIX-->D:\Program Files\VentriloMIX\Uninstal.exe
======System event log======
Computer Name: EXPERIEN-511322
Event Code: 7009
Message: Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect.
Record Number: 170
Source Name: Service Control Manager
Time Written: 20090807172902.000000+060
Event Type: error
User:
Computer Name: EXPERIEN-511322
Event Code: 7009
Message: Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect.
Record Number: 169
Source Name: Service Control Manager
Time Written: 20090807172901.000000+060
Event Type: error
User:
Computer Name: EXPERIEN-511322
Event Code: 7009
Message: Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect.
Record Number: 168
Source Name: Service Control Manager
Time Written: 20090807172742.000000+060
Event Type: error
User:
Computer Name: EXPERIEN-511322
Event Code: 7000
Message: The MSICPL service failed to start due to the following error:
The system cannot find the file specified.
Record Number: 138
Source Name: Service Control Manager
Time Written: 20090807171017.000000+060
Event Type: error
User:
Computer Name: EXPERIEN-511322
Event Code: 7000
Message: The MSICPL service failed to start due to the following error:
The system cannot find the file specified.
Record Number: 137
Source Name: Service Control Manager
Time Written: 20090807171017.000000+060
Event Type: error
User:
=====Application event log=====
Computer Name: EXPERIEN-511322
Event Code: 5603
Message: A provider, Rsop Planning Mode Provider, has been registered in the WMI namespace, root\RSOP, but did not specify the HostingModel property. This provider will be run using the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests. Ensure that provider has been reviewed for security behavior and update the HostingModel property of the provider registration to an account with the least privileges possible for the required functionality.
Record Number: 15
Source Name: WinMgmt
Time Written: 20090807163646.000000+060
Event Type: warning
User: NT AUTHORITY\SYSTEM
Computer Name: EXPERIEN-511322
Event Code: 5603
Message: A provider, Rsop Planning Mode Provider, has been registered in the WMI namespace, root\RSOP, but did not specify the HostingModel property. This provider will be run using the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests. Ensure that provider has been reviewed for security behavior and update the HostingModel property of the provider registration to an account with the least privileges possible for the required functionality.
Record Number: 14
Source Name: WinMgmt
Time Written: 20090807163646.000000+060
Event Type: warning
User: NT AUTHORITY\SYSTEM
Computer Name: EXPERIEN-511322
Event Code: 63
Message: A provider, CmdTriggerConsumer, has been registered in the WMI namespace, Root\cimv2, to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Record Number: 13
Source Name: WinMgmt
Time Written: 20090807163646.000000+060
Event Type: warning
User: NT AUTHORITY\SYSTEM
Computer Name: EXPERIEN-511322
Event Code: 63
Message: A provider, CmdTriggerConsumer, has been registered in the WMI namespace, Root\cimv2, to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Record Number: 12
Source Name: WinMgmt
Time Written: 20090807163646.000000+060
Event Type: warning
User: NT AUTHORITY\SYSTEM
Computer Name: EXPERIEN-511322
Event Code: 63
Message: A provider, HiPerfCooker_v1, has been registered in the WMI namespace, Root\WMI, to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Record Number: 11
Source Name: WinMgmt
Time Written: 20090807163644.000000+060
Event Type: warning
User: NT AUTHORITY\SYSTEM
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 75 Stepping 2, AuthenticAMD
"PROCESSOR_REVISION"=4b02
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"DEVMGR_SHOW_DETAILS"=1
"DEVMGR_SHOW_NONPRESENT_DEVICES"=1
-----------------EOF-----------------
------------------------------------------------------------------------------------------------------------------------------------
Logfile of random's system information tool 1.06 (written by random/random)
Run by Administrator at 2009-08-07 19:09:25
Microsoft Windows XP Professional Service Pack 3
System drive C: has 22 GB (89%) free of 25 GB
Total RAM: 1023 MB (64% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:09:30, on 7.8.2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5508)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Administrator\Desktop\RSIT.exe
C:\Program Files\trend micro\Administrator.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cabO18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
--
End of file - 3200 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-08-07 259696]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll [2009-08-07 668656]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll [2009-08-07 470512]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-08-07 259696]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2008-04-10 16861184]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-08-07 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2008-02-26 126976]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableCAD"=1
"DisableStatusMessages"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoResolveTrack"=1
"NoResolveSearch"=1
"NoSMConfigurePrograms"=1
"MemCheckBoxInRunDlg"=1
"NoSharedDocuments"=1
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"MemCheckBoxInRunDlg"=
"StartMenuFavorites"=
"Start_ShowMyComputer"=
"Start_ShowMyDocs"=
"Start_ShowMyMusic"=
"Start_ShowRun"=
"Start_ShowSearch"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 3 months======
2009-08-07 19:09:25 ----D---- C:\rsit
2009-08-07 19:09:25 ----D---- C:\Program Files\trend micro
2009-08-07 19:03:39 ----D---- C:\WINDOWS\temp
2009-08-07 19:03:38 ----A---- C:\ComboFix.txt
2009-08-07 18:03:41 ----A---- C:\WINDOWS\ntbtlog.txt
2009-08-07 17:51:40 ----D---- C:\Documents and Settings\Administrator\Application Data\Macromedia
2009-08-07 17:51:38 ----D---- C:\Documents and Settings\Administrator\Application Data\Google
2009-08-07 17:51:38 ----D---- C:\Documents and Settings\Administrator\Application Data\Adobe
2009-08-07 17:51:31 ----D---- C:\Program Files\Google
2009-08-07 17:51:31 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\Google
2009-08-07 17:51:21 ----D---- C:\Program Files\NOS
2009-08-07 17:51:21 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\NOS
2009-08-07 17:39:24 ----D---- C:\WINDOWS\system32\xircom
2009-08-07 17:39:24 ----D---- C:\Program Files\xerox
2009-08-07 17:39:24 ----D---- C:\Program Files\microsoft frontpage
2009-08-07 17:34:27 ----A---- C:\WINDOWS\system32\h323log.txt
2009-08-07 17:34:09 ----A---- C:\WINDOWS\system32\hidserv.dll
2009-08-07 17:32:58 ----A---- C:\WINDOWS\system32\usbui.dll
2009-08-07 17:31:45 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-08-07 17:31:44 ----A---- C:\WINDOWS\ODBCINST.INI
2009-08-07 17:31:40 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2009-08-07 17:31:40 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2009-08-07 17:31:40 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2009-08-07 17:31:38 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2009-08-07 17:31:38 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2009-08-07 17:31:38 ----RA---- C:\WINDOWS\system32\kbdur.dll
2009-08-07 17:31:38 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2009-08-07 17:31:38 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2009-08-07 17:31:38 ----RA---- C:\WINDOWS\system32\kbdru.dll
2009-08-07 17:31:38 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2009-08-07 17:31:38 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2009-08-07 17:31:38 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2009-08-07 17:31:38 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2009-08-07 17:31:38 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2009-08-07 17:31:38 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2009-08-07 17:31:36 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2009-08-07 17:31:36 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2009-08-07 17:31:36 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2009-08-07 17:31:36 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2009-08-07 17:31:36 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2009-08-07 17:31:36 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2009-08-07 17:31:36 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2009-08-07 17:31:35 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2009-08-07 17:31:35 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2009-08-07 17:31:35 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2009-08-07 17:31:35 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2009-08-07 17:31:35 ----RA---- C:\WINDOWS\system32\kbdest.dll
2009-08-07 17:31:33 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2009-08-07 17:31:33 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2009-08-07 17:31:33 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2009-08-07 17:31:33 ----RA---- C:\WINDOWS\system32\kbdro.dll
2009-08-07 17:31:33 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2009-08-07 17:31:33 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2009-08-07 17:31:33 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2009-08-07 17:31:33 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2009-08-07 17:31:33 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
2009-08-07 17:31:33 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
2009-08-07 17:31:33 ----RA---- C:\WINDOWS\system32\kbdcz.dll
2009-08-07 17:31:33 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2009-08-07 17:31:33 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2009-08-07 17:31:29 ----A---- C:\WINDOWS\system32\irclass.dll
2009-08-07 17:31:28 ----A---- C:\WINDOWS\system32\spxcoins.dll
2009-08-07 17:31:28 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2009-08-07 17:31:28 ----A---- C:\WINDOWS\system32\dgsetup.dll
2009-08-07 17:31:28 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2009-08-07 17:31:26 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2009-08-07 17:31:26 ----A---- C:\WINDOWS\TASKMAN.EXE
2009-08-07 17:31:26 ----A---- C:\WINDOWS\system32\batt.dll
2009-08-07 17:31:25 ----A---- C:\WINDOWS\NOTEPAD.EXE
2009-08-07 17:31:22 ----A---- C:\WINDOWS\system32\storprop.dll
2009-08-07 17:31:15 ----ASH---- C:\Documents and Settings\All Users.WINDOWS\Application Data\desktop.ini
2009-08-07 17:30:20 ----D---- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2009-08-07 17:30:16 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-08-07 17:30:16 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes
2009-08-07 17:29:31 ----RA---- C:\WINDOWS\SET8.tmp
2009-08-07 17:29:28 ----RA---- C:\WINDOWS\SET4.tmp
2009-08-07 17:29:26 ----RA---- C:\WINDOWS\SET3.tmp
2009-08-07 17:29:15 ----SD---- C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft
2009-08-07 17:28:13 ----A---- C:\WINDOWS\setuplog.txt
2009-08-07 17:28:13 ----A---- C:\pmtimer.exe
2009-08-07 17:28:13 ----A---- C:\mute.exe
2009-08-07 17:28:13 ----A---- C:\makePNF.exe
2009-08-07 17:28:13 ----A---- C:\DSPdsblr.exe
2009-08-07 17:28:13 ----A---- C:\DPsFnshr.ini
2009-08-07 17:28:13 ----A---- C:\DPsFnshr.exe
2009-08-07 17:28:13 ----A---- C:\devcon.exe
2009-08-07 17:27:40 ----A---- C:\DriverPack_MassStorage_wnt5_x86-32.ini
2009-08-07 17:27:40 ----A---- C:\DriverPack_CPU_wnt5_x86-32.ini
2009-08-07 17:27:39 ----D---- C:\D
2009-08-07 17:27:36 ----A---- C:\Boot.bak
2009-08-07 17:27:35 ----RASHD---- C:\cmdcons
2009-08-07 17:26:45 ----A---- C:\WINDOWS\zip.exe
2009-08-07 17:26:45 ----A---- C:\WINDOWS\SWXCACLS.exe
2009-08-07 17:26:45 ----A---- C:\WINDOWS\SWSC.exe
2009-08-07 17:26:45 ----A---- C:\WINDOWS\SWREG.exe
2009-08-07 17:26:45 ----A---- C:\WINDOWS\sed.exe
2009-08-07 17:26:45 ----A---- C:\WINDOWS\PEV.exe
2009-08-07 17:26:45 ----A---- C:\WINDOWS\NIRCMD.exe
2009-08-07 17:26:45 ----A---- C:\WINDOWS\grep.exe
2009-08-07 17:26:40 ----D---- C:\WINDOWS\ERDNT
2009-08-07 17:26:38 ----D---- C:\Qoobox
2009-08-07 17:20:34 ----D---- C:\Documents and Settings\Administrator\Application Data\Ventrilo
2009-08-07 17:18:16 ----D---- C:\WINDOWS\system32\Lang
2009-08-07 17:14:32 ----R---- C:\WINDOWS\system32\ChCfg.exe
2009-08-07 17:14:16 ----D---- C:\WINDOWS\system32\RTCOM
2009-08-07 17:14:15 ----A---- C:\WINDOWS\system32\ksuser.dll
2009-08-07 17:14:11 ----R---- C:\WINDOWS\SoundMan.exe
2009-08-07 17:14:10 ----R---- C:\WINDOWS\SkyTel.exe
2009-08-07 17:14:08 ----R---- C:\WINDOWS\RtlUpd.exe
2009-08-07 17:14:03 ----R---- C:\WINDOWS\RTLCPL.exe
2009-08-07 17:13:50 ----R---- C:\WINDOWS\RTHDCPL.exe
2009-08-07 17:13:49 ----R---- C:\WINDOWS\MicCal.exe
2009-08-07 17:13:46 ----R---- C:\WINDOWS\Alcmtr.exe
2009-08-07 17:13:44 ----R---- C:\WINDOWS\alcwzrd.exe
2009-08-07 17:13:43 ----D---- C:\Program Files\Realtek
2009-08-07 17:12:42 ----R---- C:\WINDOWS\RtlExUpd.dll
2009-08-07 17:12:42 ----A---- C:\WINDOWS\HideWin.exe
2009-08-07 17:12:24 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-08-07 17:12:21 ----D---- C:\Program Files\AMD
2009-08-07 17:11:40 ----D---- C:\Documents and Settings\Administrator\Application Data\InstallShield
2009-08-07 17:11:16 ----RA---- C:\WINDOWS\system32\nvusmb.exe
2009-08-07 17:11:15 ----D---- C:\WINDOWS\system32\ReinstallBackups
2009-08-07 17:11:09 ----A---- C:\WINDOWS\system32\NVUNINST.EXE
2009-08-07 17:05:31 ----SHD---- C:\WINDOWS\Installer
2009-08-07 17:05:30 ----D---- C:\Program Files\Common Files\ODBC
2009-08-07 17:05:27 ----D---- C:\Program Files\Common Files\SpeechEngines
2009-08-07 17:05:26 ----RD---- C:\Program Files
2009-08-07 17:05:26 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-08-07 17:05:26 ----D---- C:\Program Files\Common Files
2009-08-07 17:03:03 ----D---- C:\WINDOWS\system32\CatRoot2
2009-08-07 17:03:03 ----D---- C:\WINDOWS\system32\CatRoot
2009-08-07 17:02:37 ----SHD---- C:\System Volume Information
2009-08-07 17:02:37 ----D---- C:\Documents and Settings
2009-08-07 17:01:43 ----RASH---- C:\boot.ini
2009-08-07 16:57:26 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-08-07 16:57:26 ----RSD---- C:\WINDOWS\Fonts
2009-08-07 16:57:26 ----RD---- C:\WINDOWS\Web
2009-08-07 16:57:26 ----RD---- C:\WINDOWS\Offline Web Pages
2009-08-07 16:57:26 ----HD---- C:\WINDOWS\inf
2009-08-07 16:57:26 ----D---- C:\WINDOWS\WinSxS
2009-08-07 16:57:26 ----D---- C:\WINDOWS\WBEM
2009-08-07 16:57:26 ----D---- C:\WINDOWS\twain_32
2009-08-07 16:57:26 ----D---- C:\WINDOWS\system32\wins
2009-08-07 16:57:26 ----D---- C:\WINDOWS\system32\wbem
2009-08-07 16:57:26 ----D---- C:\WINDOWS\system32\usmt
2009-08-07 16:57:26 ----D---- C:\WINDOWS\system32\spool
2009-08-07 16:57:26 ----D---- C:\WINDOWS\system32\ShellExt
2009-08-07 16:57:26 ----D---- C:\WINDOWS\system32\Setup
2009-08-07 16:57:26 ----D---- C:\WINDOWS\system32\scripting
2009-08-07 16:57:26 ----D---- C:\WINDOWS\system32\ras
2009-08-07 16:57:26 ----D---- C:\WINDOWS\system32\oobe
2009-08-07 16:57:26 ----D---- C:\WINDOWS\system32\npp
2009-08-07 16:57:26 ----D---- C:\WINDOWS\system32\mui
2009-08-07 16:57:26 ----D---- C:\WINDOWS\system32\inetsrv
2009-08-07 16:57:26 ----D---- C:\WINDOWS\system32\IME
2009-08-07 16:57:26 ----D---- C:\WINDOWS\system32\icsxml
2009-08-07 16:57:26 ----D---- C:\WINDOWS\system32\ias
2009-08-07 16:57:26 ----D---- C:\WINDOWS\system32\export
2009-08-07 16:57:26 ----D---- C:\WINDOWS\system32\en-US
2009-08-07 16:57:26 ----D---- C:\WINDOWS\system32\en
2009-08-07 16:57:26 ----D---- C:\WINDOWS\system32\drivers
2009-08-07 16:57:26 ----D---- C:\WINDOWS\system32\dhcp
2009-08-07 16:57:26 ----D---- C:\WINDOWS\system32\config
2009-08-07 16:57:26 ----D---- C:\WINDOWS\system32\3com_dmi
2009-08-07 16:57:26 ----D---- C:\WINDOWS\system32\3076
2009-08-07 16:57:26 ----D---- C:\WINDOWS\system32\2052
2009-08-07 16:57:26 ----D---- C:\WINDOWS\system32\1054
2009-08-07 16:57:26 ----D---- C:\WINDOWS\system32\1042
2009-08-07 16:57:26 ----D---- C:\WINDOWS\system32\1041
2009-08-07 16:57:26 ----D---- C:\WINDOWS\system32\1037
2009-08-07 16:57:26 ----D---- C:\WINDOWS\system32\1033
2009-08-07 16:57:26 ----D---- C:\WINDOWS\system32\1031
2009-08-07 16:57:26 ----D---- C:\WINDOWS\system32\1028
2009-08-07 16:57:26 ----D---- C:\WINDOWS\system32\1025
2009-08-07 16:57:26 ----D---- C:\WINDOWS\system32
2009-08-07 16:57:26 ----D---- C:\WINDOWS\system
2009-08-07 16:57:26 ----D---- C:\WINDOWS\security
2009-08-07 16:57:26 ----D---- C:\WINDOWS\Resources
2009-08-07 16:57:26 ----D---- C:\WINDOWS\repair
2009-08-07 16:57:26 ----D---- C:\WINDOWS\Provisioning
2009-08-07 16:57:26 ----D---- C:\WINDOWS\pchealth
2009-08-07 16:57:26 ----D---- C:\WINDOWS\PeerNet
2009-08-07 16:57:26 ----D---- C:\WINDOWS\Network Diagnostic
2009-08-07 16:57:26 ----D---- C:\WINDOWS\mui
2009-08-07 16:57:26 ----D---- C:\WINDOWS\msapps
2009-08-07 16:57:26 ----D---- C:\WINDOWS\msagent
2009-08-07 16:57:26 ----D---- C:\WINDOWS\Media
2009-08-07 16:57:26 ----D---- C:\WINDOWS\L2Schemas
2009-08-07 16:57:26 ----D---- C:\WINDOWS\java
2009-08-07 16:57:26 ----D---- C:\WINDOWS\ime
2009-08-07 16:57:26 ----D---- C:\WINDOWS\Help
2009-08-07 16:57:26 ----D---- C:\WINDOWS\ehome
2009-08-07 16:57:26 ----D---- C:\WINDOWS\Driver Cache
2009-08-07 16:57:26 ----D---- C:\WINDOWS\Debug
2009-08-07 16:57:26 ----D---- C:\WINDOWS\Cursors
2009-08-07 16:57:26 ----D---- C:\WINDOWS\Connection Wizard
2009-08-07 16:57:26 ----D---- C:\WINDOWS\Config
2009-08-07 16:57:26 ----D---- C:\WINDOWS\AppPatch
2009-08-07 16:57:26 ----D---- C:\WINDOWS\addins
2009-08-07 16:57:26 ----D---- C:\WINDOWS
2009-08-07 16:45:24 ----N---- C:\WINDOWS\system32\ati2sgag.exe
2009-08-07 16:45:15 ----HD---- C:\Program Files\InstallShield Installation Information
2009-08-07 16:45:07 ----D---- C:\Program Files\Common Files\InstallShield
2009-08-07 16:45:04 ----D---- C:\ATI
2009-08-07 16:40:59 ----D---- C:\Documents and Settings\Administrator\Application Data\Identities
2009-08-07 16:40:58 ----HD---- C:\Program Files\Uninstall Information
2009-08-07 16:40:47 ----SD---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2009-08-07 16:40:47 ----ASH---- C:\Documents and Settings\Administrator\Application Data\desktop.ini
2009-08-07 16:40:44 ----D---- C:\WINDOWS\SoftwareDistribution
2009-08-07 16:40:43 ----D---- C:\WINDOWS\Prefetch
2009-08-07 16:40:42 ----SD---- C:\WINDOWS\system32\Microsoft
2009-08-07 16:40:42 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-08-07 16:39:22 ----A---- C:\WINDOWS\control.ini
2009-08-07 16:39:22 ----A---- C:\AUTOEXEC.BAT
2009-08-07 16:39:13 ----A---- C:\WINDOWS\OEWABLog.txt
2009-08-07 16:39:09 ----D---- C:\WINDOWS\system32\dllcache
2009-08-07 16:39:09 ----A---- C:\WINDOWS\system32\mapi32.dll
2009-08-07 16:38:23 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2009-08-07 16:38:17 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2009-08-07 16:38:14 ----HD---- C:\Program Files\WindowsUpdate
2009-08-07 16:37:55 ----D---- C:\WINDOWS\system32\DirectX
2009-08-07 16:37:50 ----A---- C:\WINDOWS\system32\atrace.dll
2009-08-07 16:37:48 ----A---- C:\WINDOWS\system32\desktop.ini
2009-08-07 16:37:48 ----A---- C:\WINDOWS\desktop.ini
2009-08-07 16:37:42 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2009-08-07 16:37:41 ----A---- C:\WINDOWS\system32\acctres.dll
2009-08-07 16:37:40 ----D---- C:\Program Files\Common Files\Services
2009-08-07 16:37:38 ----SD---- C:\WINDOWS\Tasks
2009-08-07 16:37:38 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2009-08-07 16:37:37 ----D---- C:\Program Files\Common Files\MSSoap
2009-08-07 16:37:33 ----D---- C:\WINDOWS\system32\Macromed
2009-08-07 16:37:33 ----D---- C:\WINDOWS\srchasst
2009-08-07 16:37:30 ----A---- C:\WINDOWS\system32\wuweb.dll
2009-08-07 16:37:30 ----A---- C:\WINDOWS\system32\wups.dll
2009-08-07 16:37:30 ----A---- C:\WINDOWS\system32\wucltui.dll
2009-08-07 16:37:30 ----A---- C:\WINDOWS\system32\wuauserv.dll
2009-08-07 16:37:30 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2009-08-07 16:37:30 ----A---- C:\WINDOWS\system32\wuaueng.dll
2009-08-07 16:37:30 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2009-08-07 16:37:30 ----A---- C:\WINDOWS\system32\wuauclt.exe
2009-08-07 16:37:30 ----A---- C:\WINDOWS\system32\wuapi.dll
2009-08-07 16:37:30 ----A---- C:\WINDOWS\system32\bitsprx4.dll
2009-08-07 16:37:29 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2009-08-07 16:37:29 ----A---- C:\WINDOWS\system32\qmgr.dll
2009-08-07 16:37:29 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2009-08-07 16:37:29 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2009-08-07 16:37:26 ----D---- C:\Program Files\Movie Maker
2009-08-07 16:37:10 ----A---- C:\WINDOWS\system32\safrslv.dll
2009-08-07 16:37:10 ----A---- C:\WINDOWS\system32\safrdm.dll
2009-08-07 16:37:10 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2009-08-07 16:37:09 ----A---- C:\WINDOWS\system32\racpldlg.dll
2009-08-07 16:37:07 ----A---- C:\WINDOWS\system32\fltMc.exe
2009-08-07 16:37:07 ----A---- C:\WINDOWS\system32\fltlib.dll
2009-08-07 16:37:06 ----D---- C:\WINDOWS\system32\Restore
2009-08-07 16:37:06 ----A---- C:\WINDOWS\system32\srsvc.dll
2009-08-07 16:37:06 ----A---- C:\WINDOWS\system32\srrstr.dll
2009-08-07 16:37:06 ----A---- C:\WINDOWS\system32\srclient.dll
2009-08-07 16:37:05 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2009-08-07 16:37:05 ----A---- C:\WINDOWS\system32\msconf.dll
2009-08-07 16:37:05 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2009-08-07 16:37:05 ----A---- C:\WINDOWS\system32\mnmdd.dll
2009-08-07 16:37:05 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2009-08-07 16:37:05 ----A---- C:\WINDOWS\system32\ils.dll
2009-08-07 16:37:03 ----D---- C:\Program Files\NetMeeting
2009-08-07 16:37:02 ----A---- C:\WINDOWS\system32\msoert2.dll
2009-08-07 16:37:02 ----A---- C:\WINDOWS\system32\msoeacct.dll
2009-08-07 16:37:02 ----A---- C:\WINDOWS\system32\inetres.dll
2009-08-07 16:37:01 ----A---- C:\WINDOWS\system32\inetcomm.dll
2009-08-07 16:37:00 ----D---- C:\Program Files\Outlook Express
2009-08-07 16:37:00 ----A---- C:\WINDOWS\system32\schedsvc.dll
2009-08-07 16:37:00 ----A---- C:\WINDOWS\system32\mstinit.exe
2009-08-07 16:37:00 ----A---- C:\WINDOWS\system32\mstask.dll
2009-08-07 16:36:59 ----A---- C:\WINDOWS\system32\isign32.dll
2009-08-07 16:36:59 ----A---- C:\WINDOWS\system32\inetcfg.dll
2009-08-07 16:36:59 ----A---- C:\WINDOWS\system32\icwphbk.dll
2009-08-07 16:36:59 ----A---- C:\WINDOWS\system32\icwdial.dll
2009-08-07 16:36:54 ----D---- C:\Program Files\Common Files\System
2009-08-07 16:36:53 ----D---- C:\Program Files\Internet Explorer
2009-08-07 16:36:23 ----D---- C:\Program Files\ComPlus Applications
2009-08-07 16:36:21 ----A---- C:\WINDOWS\vbaddin.ini
2009-08-07 16:36:21 ----A---- C:\WINDOWS\vb.ini
2009-08-07 16:36:17 ----D---- C:\WINDOWS\Registration
2009-08-07 16:36:10 ----D---- C:\Program Files\Windows Media Player
2009-08-07 16:36:10 ----D---- C:\Program Files\Online Services
2009-08-07 16:36:04 ----D---- C:\Program Files\Messenger
2009-08-07 16:36:01 ----D---- C:\Program Files\MSN Gaming Zone
2009-08-07 16:36:01 ----A---- C:\WINDOWS\system32\write.exe
2009-08-07 16:35:52 ----A---- C:\WINDOWS\system32\sndvol32.exe
2009-08-07 16:35:52 ----A---- C:\WINDOWS\system32\hticons.dll
2009-08-07 16:35:52 ----A---- C:\WINDOWS\system32\avwav.dll
2009-08-07 16:35:52 ----A---- C:\WINDOWS\system32\avtapi.dll
2009-08-07 16:35:52 ----A---- C:\WINDOWS\system32\avmeter.dll
2009-08-07 16:35:51 ----A---- C:\WINDOWS\system32\winchat.exe
2009-08-07 16:35:45 ----A---- C:\WINDOWS\system32\charmap.exe
2009-08-07 16:35:45 ----A---- C:\WINDOWS\system32\getuname.dll
2009-08-07 16:35:45 ----A---- C:\WINDOWS\system32\calc.exe
2009-08-07 16:35:44 ----A---- C:\WINDOWS\system32\winmine.exe
2009-08-07 16:35:44 ----A---- C:\WINDOWS\system32\sol.exe
2009-08-07 16:35:44 ----A---- C:\WINDOWS\system32\reset.exe
2009-08-07 16:35:44 ----A---- C:\WINDOWS\system32\mshearts.exe
2009-08-07 16:35:44 ----A---- C:\WINDOWS\system32\freecell.exe
2009-08-07 16:35:43 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2009-08-07 16:35:43 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2009-08-07 16:35:43 ----A---- C:\WINDOWS\system32\tslabels.ini
2009-08-07 16:35:43 ----A---- C:\WINDOWS\system32\tskill.exe
2009-08-07 16:35:43 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2009-08-07 16:35:43 ----A---- C:\WINDOWS\system32\tscon.exe
2009-08-07 16:35:43 ----A---- C:\WINDOWS\system32\shadow.exe
2009-08-07 16:35:43 ----A---- C:\WINDOWS\system32\rwinsta.exe
2009-08-07 16:35:43 ----A---- C:\WINDOWS\system32\regini.exe
2009-08-07 16:35:43 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2009-08-07 16:35:43 ----A---- C:\WINDOWS\system32\qwinsta.exe
2009-08-07 16:35:43 ----A---- C:\WINDOWS\system32\qappsrv.exe
2009-08-07 16:35:43 ----A---- C:\WINDOWS\system32\msg.exe
2009-08-07 16:35:42 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2009-08-07 16:35:42 ----A---- C:\WINDOWS\system32\logoff.exe
2009-08-07 16:35:42 ----A---- C:\WINDOWS\system32\cdmodem.dll
2009-08-07 16:35:37 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2009-08-07 16:35:27 ----D---- C:\Program Files\MSN
2009-08-07 16:35:27 ----A---- C:\WINDOWS\system32\sndrec32.exe
2009-08-07 16:35:27 ----A---- C:\WINDOWS\system32\accwiz.exe
2009-08-07 16:35:26 ----D---- C:\Program Files\Windows NT
2009-08-07 16:35:26 ----A---- C:\WINDOWS\system32\mspaint.exe
2009-08-07 16:35:26 ----A---- C:\WINDOWS\system32\mplay32.exe
2009-08-07 16:35:26 ----A---- C:\WINDOWS\system32\hypertrm.dll
2009-08-07 16:35:26 ----A---- C:\WINDOWS\system32\clipbrd.exe
2009-08-07 16:35:25 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2009-08-07 16:35:25 ----A---- C:\WINDOWS\system32\spider.exe
2009-08-07 16:35:24 ----A---- C:\WINDOWS\system32\tsgqec.dll
2009-08-07 16:35:24 ----A---- C:\WINDOWS\system32\rhttpaa.dll
2009-08-07 16:35:24 ----A---- C:\WINDOWS\system32\mstscax.dll
2009-08-07 16:35:24 ----A---- C:\WINDOWS\system32\mstsc.exe
2009-08-07 16:35:24 ----A---- C:\WINDOWS\system32\aaclient.dll
2009-08-07 16:35:23 ----A---- C:\WINDOWS\system32\termsrv.dll
2009-08-07 16:35:23 ----A---- C:\WINDOWS\system32\sessmgr.exe
2009-08-07 16:35:23 ----A---- C:\WINDOWS\system32\remotepg.dll
2009-08-07 16:35:23 ----A---- C:\WINDOWS\system32\rdshost.exe
2009-08-07 16:35:23 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2009-08-07 16:35:23 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2009-08-07 16:35:23 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2009-08-07 16:35:23 ----A---- C:\WINDOWS\system32\rdpclip.exe
2009-08-07 16:35:23 ----A---- C:\WINDOWS\system32\rdchost.dll
2009-08-07 16:35:23 ----A---- C:\WINDOWS\system32\qprocess.exe
2009-08-07 16:35:23 ----A---- C:\WINDOWS\system32\icaapi.dll
2009-08-07 16:35:22 ----D---- C:\WINDOWS\system32\MsDtc
2009-08-07 16:35:22 ----A---- C:\WINDOWS\system32\xolehlp.dll
2009-08-07 16:35:22 ----A---- C:\WINDOWS\system32\mtxoci.dll
2009-08-07 16:35:22 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2009-08-07 16:35:22 ----A---- C:\WINDOWS\system32\msdtctm.dll
2009-08-07 16:35:22 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2009-08-07 16:35:22 ----A---- C:\WINDOWS\system32\msdtclog.dll
2009-08-07 16:35:22 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2009-08-07 16:35:21 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2009-08-07 16:35:21 ----A---- C:\WINDOWS\system32\mtxex.dll
2009-08-07 16:35:21 ----A---- C:\WINDOWS\system32\mtxdm.dll
2009-08-07 16:35:21 ----A---- C:\WINDOWS\system32\msdtc.exe
2009-08-07 16:35:21 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2009-08-07 16:35:20 ----D---- C:\WINDOWS\system32\Com
2009-08-07 16:35:20 ----A---- C:\WINDOWS\system32\stclient.dll
2009-08-07 16:35:20 ----A---- C:\WINDOWS\system32\comrepl.dll
2009-08-07 16:35:20 ----A---- C:\WINDOWS\system32\comaddin.dll
2009-08-07 16:35:20 ----A---- C:\WINDOWS\system32\colbact.dll
2009-08-07 16:35:20 ----A---- C:\WINDOWS\system32\clbcatex.dll
2009-08-07 16:35:20 ----A---- C:\WINDOWS\system32\catsrvut.dll
2009-08-07 16:35:20 ----A---- C:\WINDOWS\system32\catsrvps.dll
2009-08-07 16:35:20 ----A---- C:\WINDOWS\system32\catsrv.dll
2009-08-07 16:35:19 ----A---- C:\WINDOWS\system32\comuid.dll
2009-08-07 16:35:19 ----A---- C:\WINDOWS\system32\comsvcs.dll
2009-08-07 16:35:19 ----A---- C:\WINDOWS\system32\comsnap.dll
2009-08-07 16:35:19 ----A---- C:\WINDOWS\system32\clbcatq.dll
2009-08-07 16:35:14 ----A---- C:\WINDOWS\system32\servdeps.dll
2009-08-07 16:35:13 ----A---- C:\WINDOWS\system32\mmfutil.dll
2009-08-07 16:35:13 ----A---- C:\WINDOWS\system32\licwmi.dll
2009-08-07 16:35:13 ----A---- C:\WINDOWS\system32\cmprops.dll
======List of files/folders modified in the last 3 months======
2009-08-07 19:03:07 ----A---- C:\WINDOWS\system.ini
2009-08-07 16:39:21 ----A---- C:\WINDOWS\win.ini
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-06-19 36864]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-05-03 14592]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2008-02-26 2863616]
R3 catchme;catchme; \??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\catchme.sys []
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-05-03 144384]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-05-03 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-04-17 4707328]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-05-03 12160]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2008-01-03 105856]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-05-03 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-05-03 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-05-03 59520]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-05-03 17152]
S3 GMSIPCI;GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS []
S3 MSICPL;MSICPL; \??\E:\install4\MSICPL.sys []
S3 NTACCESS;NTACCESS; \??\E:\NTACCESS.sys []
S3 SetupNTGLM7X;SetupNTGLM7X; \??\E:\NTGLM7X.sys []
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2008-02-26 520192]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2008-02-25 593920]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-08-07 182768]
-----------------EOF-----------------