Je to velké, rozdělěno na 1/2.
1. půlka:
OTL logfile created on: 30.8.2009 22:46:49 - Run 1
OTL by OldTimer - Version 3.0.10.7 Folder = C:\Users\Laďa\Desktop
64bit- Ultimate Edition (Version = 6.1.7100) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7100.0)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
2,00 Gb Total Physical Memory | 1,01 Gb Available Physical Memory | 50,39% Memory free
4,00 Gb Paging File | 2,59 Gb Available in Paging File | 64,83% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 40,00 Gb Total Space | 20,07 Gb Free Space | 50,18% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 596,17 Gb Total Space | 382,65 Gb Free Space | 64,19% Space Free | Partition Type: NTFS
Drive F: | 192,88 Gb Total Space | 52,02 Gb Free Space | 26,97% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive J: | 529,18 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Computer Name: NEWWES-PC
Current User Name: newwes
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ========== PRC - C:\Program Files (x86)\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe ()
PRC - C:\Program Files (x86)\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
PRC - C:\Program Files (x86)\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\FlashGet\flashget.exe (FlashGet.com)
PRC - C:\Program Files (x86)\Opera\opera.exe (Opera Software)
PRC - C:\Program Files (x86)\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
PRC - C:\Program Files (x86)\FlashGet\flashget.exe (FlashGet.com)
PRC - C:\Program Files (x86)\PC Connectivity Solution\Transports\NclIrSrv.exe (Nokia)
PRC - C:\Program Files (x86)\PC Connectivity Solution\Transports\NclRSSrv.exe (Nokia)
PRC - C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrv.exe (Nokia)
PRC - C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe (Trend Micro Inc.)
PRC - C:\Users\Laďa\Desktop\OTL.exe (OldTimer Tools)
========== Win32 Services (SafeList) ========== SRV:
64bit: - (AppIDSvc [On_Demand | Stopped]) -- C:\Windows\SysNative\appidsvc.dll (Microsoft Corporation)
SRV:
64bit: - (AppMgmt [On_Demand | Stopped]) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV:
64bit: - (AxInstSV [On_Demand | Stopped]) -- C:\Windows\SysNative\AxInstSV.dll (Microsoft Corporation)
SRV:
64bit: - (BDESVC [Unknown | Stopped]) -- C:\Windows\SysNative\bdesvc.dll (Microsoft Corporation)
SRV:
64bit: - (bthserv [On_Demand | Running]) -- C:\Windows\SysNative\bthserv.dll (Microsoft Corporation)
SRV:
64bit: - (CscService [Auto | Running]) -- C:\Windows\SysNative\cscsvc.dll (Microsoft Corporation)
SRV:
64bit: - (defragsvc [On_Demand | Stopped]) -- C:\Windows\SysNative\defragsvc.dll (Microsoft Corporation)
SRV:
64bit: - (Dhcp [Auto | Running]) -- C:\Windows\SysNative\dhcpcore.dll (Microsoft Corporation)
SRV:
64bit: - (Fax [On_Demand | Stopped]) -- C:\Windows\SysNative\fxssvc.exe (Microsoft Corporation)
SRV:
64bit: - (FontCache [On_Demand | Stopped]) -- C:\Windows\SysNative\FntCache.dll (Microsoft Corporation)
SRV:
64bit: - (HomeGroupListener [On_Demand | Running]) -- C:\Windows\SysNative\ListSvc.dll (Microsoft Corporation)
SRV:
64bit: - (HomeGroupProvider [On_Demand | Running]) -- C:\Windows\SysNative\provsvc.dll (Microsoft Corporation)
SRV:
64bit: - (Irmon [Auto | Running]) -- C:\Windows\SysNative\irmon.dll (Microsoft Corporation)
SRV:
64bit: - (p2pimsvc [On_Demand | Running]) -- C:\Windows\SysNative\pnrpsvc.dll (Microsoft Corporation)
SRV:
64bit: - (PeerDistSvc [On_Demand | Stopped]) -- C:\Windows\SysNative\peerdistsvc.dll (Microsoft Corporation)
SRV:
64bit: - (PNRPAutoReg [On_Demand | Stopped]) -- C:\Windows\SysNative\pnrpauto.dll (Microsoft Corporation)
SRV:
64bit: - (PNRPsvc [On_Demand | Running]) -- C:\Windows\SysNative\pnrpsvc.dll (Microsoft Corporation)
SRV:
64bit: - (Power [Auto | Running]) -- C:\Windows\SysNative\umpo.dll (Microsoft Corporation)
SRV:
64bit: - (RpcEptMapper [Unknown | Running]) -- C:\Windows\SysNative\RpcEpMap.dll (Microsoft Corporation)
SRV:
64bit: - (SensrSvc [On_Demand | Stopped]) -- C:\Windows\SysNative\sensrsvc.dll (Microsoft Corporation)
SRV:
64bit: - (sppsvc [Auto | Stopped]) -- C:\Windows\SysNative\sppsvc.exe (Microsoft Corporation)
SRV:
64bit: - (sppuinotify [On_Demand | Stopped]) -- C:\Windows\SysNative\sppuinotify.dll (Microsoft Corporation)
SRV:
64bit: - (Themes [Auto | Running]) -- C:\Windows\SysNative\themeservice.dll (Microsoft Corporation)
SRV:
64bit: - (TuneUp.Defrag [On_Demand | Stopped]) -- C:\Windows\SysNative\TuneUpDefragService.exe (TuneUp Software GmbH)
SRV:
64bit: - (UmRdpService [On_Demand | Stopped]) -- C:\Windows\SysNative\umrdp.dll (Microsoft Corporation)
SRV:
64bit: - (UxTuneUp [Auto | Stopped]) -- C:\Windows\SysNative\uxtuneup.dll (TuneUp Software GmbH)
SRV:
64bit: - (wbengine [On_Demand | Stopped]) -- C:\Windows\SysNative\wbengine.exe (Microsoft Corporation)
SRV:
64bit: - (WbioSrvc [On_Demand | Stopped]) -- C:\Windows\SysNative\wbiosrvc.dll (Microsoft Corporation)
SRV:
64bit: - (WinDefend [On_Demand | Stopped]) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV:
64bit: - (wlidsvc [Auto | Running]) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV:
64bit: - (WMPNetworkSvc [Auto | Running]) -- C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV:
64bit: - (WwanSvc [On_Demand | Stopped]) -- C:\Windows\SysNative\wwansvc.dll (Microsoft Corporation)
SRV - (AcronisOSSReinstallSvc [Auto | Stopped]) -- C:\Program Files (x86)\Common Files\Acronis\Acronis Disk Director\oss_reinstall_svc.exe ()
SRV - (AcrSch2Svc [Auto | Running]) -- C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_64 [On_Demand | Stopped]) -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Dhcp [Auto | Running]) -- C:\Windows\SysWow64\dhcpcore.dll (Microsoft Corporation)
SRV - (ehRecvr [On_Demand | Stopped]) -- C:\Windows\ehome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [On_Demand | Stopped]) -- C:\Windows\ehome\ehsched.exe (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (HomeGroupProvider [On_Demand | Running]) -- C:\Windows\SysWow64\provsvc.dll (Microsoft Corporation)
SRV - (idsvc [Unknown | Stopped]) -- C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (KeyIso [On_Demand | Running]) -- C:\Windows\SysWow64\keyiso.dll (Microsoft Corporation)
SRV - (Microsoft Office Groove Audit Service [On_Demand | Stopped]) -- C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (MSDTC [Unknown | Stopped]) -- C:\Windows\SysWow64\Msdtc [2009.04.22 09:16:43 | 00,000,000 | ---D | M]
SRV - (Netlogon [On_Demand | Stopped]) -- C:\Windows\SysWow64\netlogon.dll (Microsoft Corporation)
SRV - (Norton Internet Security [Auto | Running]) -- C:\Program Files (x86)\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe (Symantec Corporation)
SRV - (odserv [On_Demand | Stopped]) -- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (ServiceLayer [On_Demand | Running]) -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (TryAndDecideService [Auto | Running]) -- C:\Program Files (x86)\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe ()
SRV - (UxTuneUp [Auto | Stopped]) -- C:\Windows\SysWow64\uxtuneup.dll (TuneUp Software GmbH)
SRV - (vds [On_Demand | Stopped]) -- C:\Windows\SysWow64\Wbem\vds.mof ()
SRV - (VSS [On_Demand | Stopped]) -- C:\Windows\Vss [2009.04.22 09:16:44 | 00,000,000 | ---D | M]
========== Driver Services (SafeList) ========== DRV:
64bit: - (1394ohci [On_Demand | Running]) -- C:\Windows\SysNative\DRIVERS\1394ohci.sys (Microsoft Corporation)
DRV:
64bit: - (AcpiPmi [On_Demand | Stopped]) -- C:\Windows\SysNative\DRIVERS\acpipmi.sys (Microsoft Corporation)
DRV:
64bit: - (ALCXWDM [On_Demand | Running]) -- C:\Windows\SysNative\drivers\RTKVAC64.SYS (Realtek Semiconductor Corp.)
DRV:
64bit: - (AmdPPM [On_Demand | Stopped]) -- C:\Windows\SysNative\DRIVERS\amdppm.sys (Microsoft Corporation)
DRV:
64bit: - (amdsata [On_Demand | Stopped]) -- C:\Windows\SysNative\DRIVERS\amdsata.sys (AMD)
DRV:
64bit: - (amdsbs [On_Demand | Stopped]) -- C:\Windows\SysNative\DRIVERS\amdsbs.sys (AMD Technologies Inc.)
DRV:
64bit: - (amdxata [Boot | Running]) -- C:\Windows\SysNative\DRIVERS\amdxata.sys (AMD)
DRV:
64bit: - (AppID [On_Demand | Stopped]) -- C:\Windows\SysNative\drivers\appid.sys (Microsoft Corporation)
DRV:
64bit: - (b06bdrv [On_Demand | Stopped]) -- C:\Windows\SysNative\DRIVERS\bxvbda.sys (Broadcom Corporation)
DRV:
64bit: - (b57nd60a [On_Demand | Stopped]) -- C:\Windows\SysNative\DRIVERS\b57nd60a.sys (Broadcom Corporation)
DRV:
64bit: - (Beep [System | Running]) -- C:\Windows\SysNative\drivers\beep.sys (Microsoft Corporation)
DRV:
64bit: - (BHDrvx64 [System | Running]) -- C:\Windows\SysNative\drivers\NISx64\1005000.087\BHDrvx64.sys (Symantec Corporation)
DRV:
64bit: - (BthEnum [On_Demand | Running]) -- C:\Windows\SysNative\DRIVERS\BthEnum.sys (Microsoft Corporation)
DRV:
64bit: - (BthPan [On_Demand | Running]) -- C:\Windows\SysNative\DRIVERS\bthpan.sys (Microsoft Corporation)
DRV:
64bit: - (BTHPORT [On_Demand | Stopped]) -- C:\Windows\SysNative\Drivers\BTHport.sys (Microsoft Corporation)
DRV:
64bit: - (BTHUSB [On_Demand | Running]) -- C:\Windows\SysNative\Drivers\BTHUSB.sys (Microsoft Corporation)
DRV:
64bit: - (ccHP [System | Running]) -- C:\Windows\SysNative\Drivers\NISx64\1005000.087\ccHPx64.sys (Symantec Corporation)
DRV:
64bit: - (CmBatt [On_Demand | Stopped]) -- C:\Windows\SysNative\DRIVERS\CmBatt.sys (Microsoft Corporation)
DRV:
64bit: - (CNG [Boot | Running]) -- C:\Windows\SysNative\Drivers\cng.sys (Microsoft Corporation)
DRV:
64bit: - (CompositeBus [On_Demand | Running]) -- C:\Windows\SysNative\DRIVERS\CompositeBus.sys (Microsoft Corporation)
DRV:
64bit: - (CSC [System | Running]) -- C:\Windows\SysNative\drivers\csc.sys (Microsoft Corporation)
DRV:
64bit: - (discache [System | Running]) -- C:\Windows\SysNative\drivers\discache.sys (Microsoft Corporation)
DRV:
64bit: - (ebdrv [On_Demand | Stopped]) -- C:\Windows\SysNative\DRIVERS\evbda.sys (Broadcom Corporation)
DRV:
64bit: - (FsDepends [On_Demand | Stopped]) -- C:\Windows\SysNative\drivers\FsDepends.sys (Microsoft Corporation)
DRV:
64bit: - (fvevol [Boot | Running]) -- C:\Windows\SysNative\DRIVERS\fvevol.sys (Microsoft Corporation)
DRV:
64bit: - (hcw85cir [On_Demand | Stopped]) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:
64bit: - (HidBatt [On_Demand | Stopped]) -- C:\Windows\SysNative\DRIVERS\HidBatt.sys (Microsoft Corporation)
DRV:
64bit: - (HpSAMD [On_Demand | Stopped]) -- C:\Windows\SysNative\DRIVERS\HpSAMD.sys (Hewlett-Packard Company)
DRV:
64bit: - (hwpolicy [Boot | Running]) -- C:\Windows\SysNative\drivers\hwpolicy.sys (Microsoft Corporation)
DRV:
64bit: - (irda [Auto | Running]) -- C:\Windows\SysNative\DRIVERS\irda.sys (Microsoft Corporation)
DRV:
64bit: - (irsir [On_Demand | Running]) -- C:\Windows\SysNative\DRIVERS\irsir.sys (Microsoft Corporation)
DRV:
64bit: - (KSecPkg [Boot | Running]) -- C:\Windows\SysNative\Drivers\ksecpkg.sys (Microsoft Corporation)
DRV:
64bit: - (LSI_SAS2 [On_Demand | Stopped]) -- C:\Windows\SysNative\DRIVERS\lsi_sas2.sys (LSI Corporation)
DRV:
64bit: - (lvpepf64 [On_Demand | Running]) -- C:\Windows\SysNative\DRIVERS\lv302a64.sys (Logitech Inc.)
DRV:
64bit: - (LVRS64 [On_Demand | Running]) -- C:\Windows\SysNative\DRIVERS\lvrs64.sys (Logitech Inc.)
DRV:
64bit: - (LVUSBS64 [On_Demand | Running]) -- C:\Windows\SysNative\drivers\LVUSBS64.sys (Logitech Inc.)
DRV:
64bit: - (mshidkmdf [On_Demand | Stopped]) -- C:\Windows\SysNative\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV:
64bit: - (MTConfig [On_Demand | Stopped]) -- C:\Windows\SysNative\DRIVERS\MTConfig.sys (Microsoft Corporation)
DRV:
64bit: - (NdisCap [On_Demand | Stopped]) -- C:\Windows\SysNative\DRIVERS\ndiscap.sys (Microsoft Corporation)
DRV:
64bit: - (nmwcdcx64 [On_Demand | Stopped]) -- C:\Windows\SysNative\drivers\ccdcmbox64.sys (Nokia)
DRV:
64bit: - (nmwcdx64 [On_Demand | Stopped]) -- C:\Windows\SysNative\drivers\ccdcmbx64.sys (Nokia)
DRV:
64bit: - (NVENETFD [On_Demand | Running]) -- C:\Windows\SysNative\DRIVERS\nvm62x64.sys (NVIDIA Corporation)
DRV:
64bit: - (pccsmcfd [On_Demand | Stopped]) -- C:\Windows\SysNative\DRIVERS\pccsmcfdx64.sys (Nokia)
DRV:
64bit: - (pcw [Boot | Running]) -- C:\Windows\SysNative\drivers\pcw.sys (Microsoft Corporation)
DRV:
64bit: - (PID_PEPI [On_Demand | Running]) -- C:\Windows\SysNative\DRIVERS\LV302V64.SYS (Logitech Inc.)
DRV:
64bit: - (RasAgileVpn [On_Demand | Running]) -- C:\Windows\SysNative\DRIVERS\AgileVpn.sys (Microsoft Corporation)
DRV:
64bit: - (rdpbus [On_Demand | Running]) -- C:\Windows\SysNative\DRIVERS\rdpbus.sys (Microsoft Corporation)
DRV:
64bit: - (RDPREFMP [System | Running]) -- C:\Windows\SysNative\drivers\rdprefmp.sys (Microsoft Corporation)
DRV:
64bit: - (rdyboost [Boot | Running]) -- C:\Windows\SysNative\drivers\rdyboost.sys (Microsoft Corporation)
DRV:
64bit: - (RFCOMM [On_Demand | Running]) -- C:\Windows\SysNative\DRIVERS\rfcomm.sys (Microsoft Corporation)
DRV:
64bit: - (s3cap [On_Demand | Stopped]) -- C:\Windows\SysNative\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV:
64bit: - (scfilter [Unknown | Stopped]) -- C:\Windows\SysNative\DRIVERS\scfilter.sys (Microsoft Corporation)
DRV:
64bit: - (Si3114r5 [Boot | Running]) -- C:\Windows\SysNative\DRIVERS\Si3114r5.sys (Silicon Image, Inc)
DRV:
64bit: - (SiFilter [Boot | Running]) -- C:\Windows\SysNative\DRIVERS\SiWinAcc.sys (Silicon Image, Inc.)
DRV:
64bit: - (SiRemFil [Boot | Running]) -- C:\Windows\SysNative\DRIVERS\SiRemFil.sys (Silicon Image, Inc.)
DRV:
64bit: - (snapman [Boot | Running]) -- C:\Windows\SysNative\DRIVERS\snapman.sys (Acronis)
DRV:
64bit: - (sptd [Boot | Running]) -- C:\Windows\SysNative\Drivers\sptd.sys ()
DRV:
64bit: - (SRTSP [On_Demand | Running]) -- C:\Windows\SysNative\Drivers\NISx64\1005000.087\SRTSP64.SYS (Symantec Corporation)
DRV:
64bit: - (SRTSPX [System | Running]) -- C:\Windows\SysNative\drivers\NISx64\1005000.087\SRTSPX64.SYS (Symantec Corporation)
DRV:
64bit: - (stexstor [On_Demand | Stopped]) -- C:\Windows\SysNative\DRIVERS\stexstor.sys (Promise Technology)
DRV:
64bit: - (storflt [Boot | Running]) -- C:\Windows\SysNative\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV:
64bit: - (storvsc [On_Demand | Stopped]) -- C:\Windows\SysNative\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV:
64bit: - (SymEFA [Boot | Running]) -- C:\Windows\SysNative\drivers\NISx64\1005000.087\SYMEFA64.SYS (Symantec Corporation)
DRV:
64bit: - (SymEvent [On_Demand | Running]) -- C:\Windows\SysNative\Drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:
64bit: - (SYMFW [On_Demand | Running]) -- C:\Windows\SysNative\Drivers\NISx64\1005000.087\SYMFW.SYS (Symantec Corporation)
DRV:
64bit: - (SymIM [System | Running]) -- C:\Windows\SysNative\DRIVERS\SymIMv.sys (Symantec Corporation)
DRV:
64bit: - (SYMNDISV [On_Demand | Running]) -- C:\Windows\SysNative\Drivers\NISx64\1005000.087\SYMNDISV.SYS (Symantec Corporation)
DRV:
64bit: - (SYMTDI [System | Running]) -- C:\Windows\SysNative\Drivers\NISx64\1005000.087\SYMTDI.SYS (Symantec Corporation)
DRV:
64bit: - (tdrpman [Boot | Running]) -- C:\Windows\SysNative\DRIVERS\tdrpman.sys (Acronis)
DRV:
64bit: - (tifsfilter [Auto | Running]) -- C:\Windows\SysNative\DRIVERS\tifsfilt.sys (Acronis)
DRV:
64bit: - (timounter [Boot | Running]) -- C:\Windows\SysNative\DRIVERS\timntr.sys (Acronis)
DRV:
64bit: - (UmPass [On_Demand | Stopped]) -- C:\Windows\SysNative\DRIVERS\umpass.sys (Microsoft Corporation)
DRV:
64bit: - (upperdev [On_Demand | Stopped]) -- C:\Windows\SysNative\DRIVERS\usbser_lowerfltx64.sys (Nokia)
DRV:
64bit: - (usbaudio [On_Demand | Running]) -- C:\Windows\SysNative\drivers\usbaudio.sys (Microsoft Corporation)
DRV:
64bit: - (usbser [On_Demand | Stopped]) -- C:\Windows\SysNative\drivers\usbser.sys (Microsoft Corporation)
DRV:
64bit: - (UsbserFilt [On_Demand | Stopped]) -- C:\Windows\SysNative\DRIVERS\usbser_lowerfltx64j.sys (Nokia)
DRV:
64bit: - (vdrvroot [Boot | Running]) -- C:\Windows\SysNative\DRIVERS\vdrvroot.sys (Microsoft Corporation)
DRV:
64bit: - (vhdmp [On_Demand | Stopped]) -- C:\Windows\SysNative\DRIVERS\vhdmp.sys (Microsoft Corporation)
DRV:
64bit: - (vmbus [On_Demand | Stopped]) -- C:\Windows\SysNative\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV:
64bit: - (VMBusHID [On_Demand | Stopped]) -- C:\Windows\SysNative\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV:
64bit: - (vwifibus [On_Demand | Stopped]) -- C:\Windows\SysNative\drivers\vwifibus.sys (Microsoft Corporation)
DRV:
64bit: - (WfpLwf [System | Running]) -- C:\Windows\SysNative\DRIVERS\wfplwf.sys (Microsoft Corporation)
DRV:
64bit: - (WIMMount [On_Demand | Stopped]) -- C:\Windows\SysNative\drivers\wimmount.sys (Microsoft Corporation)
DRV:
64bit: - (WudfPf [On_Demand | Running]) -- C:\Windows\SysNative\drivers\WudfPf.sys (Microsoft Corporation)
DRV:
64bit: - (yukonw7 [On_Demand | Running]) -- C:\Windows\SysNative\DRIVERS\yk62x64.sys (Marvell)
DRV - (CSC [System | Running]) -- C:\Windows\CSC [2009.08.07 23:00:45 | 00,000,000 | ---D | M]
DRV - (eeCtrl [System | Running]) -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv [On_Demand | Running]) -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (IDSVia64 [System | Running]) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20090810.001\IDSvia64.sys (Symantec Corporation)
DRV - (mpsdrv [On_Demand | Running]) -- C:\Windows\SysWow64\Wbem\mpsdrv.mof ()
DRV - (NAVENG [On_Demand | Running]) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090830.005\ENG64.SYS (Symantec Corporation)
DRV - (NAVEX15 [On_Demand | Running]) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090830.005\EX64.SYS (Symantec Corporation)
DRV - (NetBIOS [System | Running]) -- C:\Windows\SysWow64\netbios.dll (Microsoft Corporation)
DRV - (Tcpip [Boot | Running]) -- C:\Windows\SysWow64\Wbem\tcpip.mof ()
DRV - (WIMMount [On_Demand | Stopped]) -- C:\Windows\SysWow64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (All) ========== ========== Internet Explorer ========== IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157IE - URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009.04.22 11:45:19 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\bkmrksync@nokia.com: C:\Program Files (x86)\Nokia\Nokia PC Suite 7\bkmrksync\ [2009.08.14 13:54:57 | 00,000,000 | ---D | M]
O1 HOSTS File: (824 bytes) - C:\Windows\SysNative\drivers\etc\Hosts
O2:
64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (FGCatchUrl) - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files (x86)\FlashGet\jccatch.dll (
www.flashget.com)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\16.5.0.135\IPSBHO.DLL (Symantec Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (FlashGet GetFlash Class) - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files (x86)\FlashGet\getflash.dll (
www.flashget.com)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [Flashget] C:\Program Files (x86)\FlashGet\FlashGet.exe (FlashGet.com)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
O4 - HKCU..\Run: [PC Suite Tray] C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O8:
64bit: - Extra context menu item: &Stáhnout &vše FlashGetem - C:\Program Files (x86)\FlashGet\jc_all.htm ()
O8:
64bit: - Extra context menu item: &Stáhnout FlashGetem - C:\Program Files (x86)\FlashGet\jc_link.htm ()
O8 - Extra context menu item: &Stáhnout &vše FlashGetem - C:\Program Files (x86)\FlashGet\jc_all.htm ()
O8 - Extra context menu item: &Stáhnout FlashGetem - C:\Program Files (x86)\FlashGet\jc_link.htm ()
O9 - Extra Button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files (x86)\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files (x86)\FlashGet\FlashGet.exe (FlashGet.com)
O9 - Extra 'Tools' menuitem : FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files (x86)\FlashGet\FlashGet.exe (FlashGet.com)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysNative\NLAapi.dll (Microsoft Corporation)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysNative\winrnr.dll (Microsoft Corporation)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysNative\napinsp.dll (Microsoft Corporation)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\SysNative\wshbth.dll (Microsoft Corporation)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysWow64\NLAapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysWow64\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysWow64\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysWow64\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysWow64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\SysWow64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\SysWow64\wshbth.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWow64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWow64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWow64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWow64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWow64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWow64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWow64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWow64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysWow64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysWow64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\SysWow64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\SysWow64\mswsock.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1 192.168.1.1
O18:
64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysNative\msvidctl.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysNative\inetcomm.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysNative\msvidctl.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWow64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysWow64\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWow64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - C:\Program Files (x86)\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll (Symantec Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Filter: - application/octet-stream - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Filter: - application/x-complus - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Filter: - application/x-msdownload - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Filter: - deflate - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Filter: - gzip - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - application/octet-stream - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-complus - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-msdownload - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\SysNative\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\SysWOW64\webcheck.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O29:
64bit: - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
O30:
64bit: - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
O30:
64bit: - LSA: Authentication Packages - (relog_ap) - C:\Windows\SysNative\relog_ap.dll (Acronis)
O30 - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (relog_ap) - C:\Windows\SysWow64\relog_ap.dll (Acronis)
O30:
64bit: - LSA: Security Packages - (kerberos) - C:\Windows\SysNative\kerberos.dll (Microsoft Corporation)
O30:
64bit: - LSA: Security Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
O30:
64bit: - LSA: Security Packages - (schannel) - C:\Windows\SysNative\schannel.dll (Microsoft Corporation)
O30:
64bit: - LSA: Security Packages - (wdigest) - C:\Windows\SysNative\wdigest.dll (Microsoft Corporation)
O30:
64bit: - LSA: Security Packages - (tspkg) - C:\Windows\SysNative\tspkg.dll (Microsoft Corporation)
O30:
64bit: - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)
O30:
64bit: - LSA: Security Packages - (livessp) - C:\Windows\SysNative\livessp.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\Windows\SysWow64\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\Windows\SysWow64\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\Windows\SysWow64\wdigest.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (tspkg) - C:\Windows\SysWow64\tspkg.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (livessp) - C:\Windows\SysWow64\livessp.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004.05.25 18:54:00 | 00,000,049 | R--- | M] () - J:\Autorun.inf -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\SysWow64\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 30 Days ========== [2009.08.30 22:19:53 | 00,000,000 | ---D | C] -- C:\Users\newwes\AppData\Roaming\Malwarebytes
[2009.08.30 22:19:50 | 00,001,009 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009.08.30 22:19:47 | 00,038,160 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2009.08.30 22:19:43 | 00,022,040 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2009.08.30 22:19:43 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2009.08.30 22:19:43 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2009.08.30 22:11:29 | 00,002,093 | ---- | C] () -- C:\Users\newwes\Desktop\HijackThis.lnk
[2009.08.30 22:11:28 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro
[2009.08.30 21:57:29 | 00,001,885 | ---- | C] () -- C:\Users\newwes\Desktop\CCleaner.lnk
[2009.08.30 21:57:28 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\CCleaner
[2009.08.26 13:17:30 | 00,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ListSvc.dll
[2009.08.23 10:01:53 | 00,000,000 | ---D | C] -- C:\Windows\Minidump
[2009.08.23 10:01:48 | 27,262,8283 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2009.08.21 15:25:50 | 00,000,000 | ---D | C] -- C:\Downloads
[2009.08.21 15:21:46 | 00,000,000 | ---D | C] -- C:\Users\newwes\AppData\Roaming\FlashGet
[2009.08.21 15:21:35 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\FlashGet
[2009.08.21 13:22:43 | 00,278,528 | ---- | C] (Real Networks, Inc) -- C:\Windows\SysWow64\pncrt.dll
[2009.08.21 13:22:43 | 00,185,920 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\rmoc3260.dll
[2009.08.21 13:22:43 | 00,006,656 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5016.dll
[2009.08.21 13:22:43 | 00,005,632 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5032.dll
[2009.08.21 13:22:42 | 00,168,448 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2009.08.21 13:22:40 | 00,839,680 | ---- | C] (
http://www.mp3dev.org/) -- C:\Windows\SysWow64\lameACM.acm
[2009.08.21 13:22:40 | 00,000,414 | ---- | C] () -- C:\Windows\SysWow64\lame_acm.xml
[2009.08.21 13:22:39 | 00,217,088 | ---- | C] (
www.helixcommunity.org) -- C:\Windows\SysWow64\yv12vfw.dll
[2009.08.21 13:22:39 | 00,118,784 | ---- | C] (fccHandler) -- C:\Windows\SysWow64\ac3acm.acm
[2009.08.21 13:22:38 | 00,795,648 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2009.08.21 13:22:38 | 00,130,048 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2009.08.21 13:22:37 | 03,596,288 | ---- | C] () -- C:\Windows\SysWow64\qt-dx331.dll
[2009.08.21 13:22:37 | 00,086,016 | ---- | C] (DivX, Inc.) -- C:\Windows\SysWow64\dpl100.dll
[2009.08.21 13:22:36 | 00,684,032 | ---- | C] (DivX, Inc.) -- C:\Windows\SysWow64\divx.dll
[2009.08.21 13:22:35 | 00,067,584 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2009.08.21 13:22:35 | 00,000,547 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll.manifest
[2009.08.21 13:22:33 | 00,060,273 | ---- | C] (Open Source Software community project) -- C:\Windows\SysWow64\pthreadGC2.dll
[2009.08.21 13:22:32 | 00,000,000 | ---D | C] -- C:\Users\newwes\AppData\Roaming\Real
[2009.08.21 13:22:32 | 00,000,000 | ---D | C] -- C:\Users\newwes\AppData\Local\Real
[2009.08.21 13:22:32 | 00,000,000 | ---D | C] -- C:\ProgramData\Real
[2009.08.21 13:22:32 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\K-Lite Codec Pack
[2009.08.21 10:29:21 | 00,402,992 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1007020.00A\SymEFA64.sys
[2009.08.21 10:29:21 | 00,278,576 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1007020.00A\symtdi.sys
[2009.08.21 10:29:21 | 00,120,880 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1007020.00A\symfw.sys
[2009.08.21 10:29:21 | 00,056,880 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1007020.00A\symndisv.sys
[2009.08.21 10:29:21 | 00,044,080 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1007020.00A\symndis.sys
[2009.08.21 10:29:21 | 00,043,568 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1007020.00A\symids.sys
[2009.08.21 10:29:21 | 00,032,304 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1007020.00A\srtspx64.sys
[2009.08.21 10:29:21 | 00,009,415 | ---- | C] () -- C:\Windows\SysNative\drivers\NISx64\1007020.00A\SymNet.cat
[2009.08.21 10:29:21 | 00,007,401 | ---- | C] () -- C:\Windows\SysNative\drivers\NISx64\1007020.00A\srtspx64.cat
[2009.08.21 10:29:21 | 00,007,399 | ---- | C] () -- C:\Windows\SysNative\drivers\NISx64\1007020.00A\SymEFA64.cat
[2009.08.21 10:29:21 | 00,003,373 | ---- | C] () -- C:\Windows\SysNative\drivers\NISx64\1007020.00A\SymEFA.inf
[2009.08.21 10:29:21 | 00,001,480 | ---- | C] () -- C:\Windows\SysNative\drivers\NISx64\1007020.00A\SymNet.inf
[2009.08.21 10:29:21 | 00,001,421 | ---- | C] () -- C:\Windows\SysNative\drivers\NISx64\1007020.00A\srtspx64.inf
[2009.08.21 10:29:20 | 00,476,720 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1007020.00A\srtsp64.sys
[2009.08.21 10:29:20 | 00,334,384 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1007020.00A\BHDrvx64.sys
[2009.08.21 10:29:20 | 00,007,410 | ---- | C] () -- C:\Windows\SysNative\drivers\NISx64\1007020.00A\srtsp64.cat
[2009.08.21 10:29:20 | 00,007,362 | ---- | C] () -- C:\Windows\SysNative\drivers\NISx64\1007020.00A\bhdrvx64.cat
[2009.08.21 10:29:20 | 00,007,345 | ---- | C] () -- C:\Windows\SysNative\drivers\NISx64\1007020.00A\ccHPx64.cat
[2009.08.21 10:29:20 | 00,001,836 | ---- | C] () -- C:\Windows\SysNative\drivers\NISx64\1007020.00A\ccHPx64.inf
[2009.08.21 10:29:20 | 00,001,437 | ---- | C] () -- C:\Windows\SysNative\drivers\NISx64\1007020.00A\srtsp64.inf
[2009.08.21 10:29:20 | 00,000,640 | ---- | C] () -- C:\Windows\SysNative\drivers\NISx64\1007020.00A\BHDrvx64.inf
[2009.08.21 10:29:05 | 00,583,296 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1007020.00A\cchpx64.sys
[2009.08.21 10:29:03 | 00,009,412 | ---- | C] () -- C:\Windows\SysNative\drivers\NISx64\1007020.00A\symnetv.cat
[2009.08.21 10:29:03 | 00,001,481 | ---- | C] () -- C:\Windows\SysNative\drivers\NISx64\1007020.00A\SymNetV.inf
[2009.08.21 10:29:03 | 00,000,172 | ---- | C] () -- C:\Windows\SysNative\drivers\NISx64\1007020.00A\isolate.ini
[2009.08.21 10:29:03 | 00,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\NISx64\1007020.00A
[2009.08.20 00:25:42 | 00,000,000 | ---D | C] -- C:\Users\newwes\AppData\Roaming\Acronis
[2009.08.19 22:37:45 | 02,430,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_41.dll
[2009.08.19 22:37:45 | 01,846,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_41.dll
[2009.08.19 22:37:45 | 00,520,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_41.dll
[2009.08.19 22:37:45 | 00,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_41.dll
[2009.08.19 22:37:43 | 05,425,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_41.dll
[2009.08.19 22:37:43 | 04,178,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_41.dll
[2009.08.19 22:37:42 | 00,521,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_4.dll
[2009.08.19 22:37:42 | 00,517,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_4.dll
[2009.08.19 22:37:42 | 00,073,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_3.dll
[2009.08.19 22:37:42 | 00,069,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_3.dll
[2009.08.19 22:37:41 | 00,235,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_4.dll
[2009.08.19 22:37:41 | 00,174,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_4.dll
[2009.08.19 22:37:40 | 00,024,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_6.dll
[2009.08.19 22:37:40 | 00,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_6.dll
[2009.08.19 22:37:38 | 02,605,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_40.dll
[2009.08.19 22:37:38 | 02,036,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_40.dll
[2009.08.19 22:37:38 | 00,519,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_40.dll
[2009.08.19 22:37:38 | 00,452,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_40.dll
[2009.08.19 22:37:36 | 05,631,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_40.dll
[2009.08.19 22:37:36 | 04,379,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_40.dll
[2009.08.19 22:37:35 | 00,518,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_3.dll
[2009.08.19 22:37:35 | 00,514,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_3.dll
[2009.08.19 22:37:35 | 00,074,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_2.dll
[2009.08.19 22:37:35 | 00,070,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_2.dll
[2009.08.19 22:37:33 | 00,235,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_3.dll
[2009.08.19 22:37:33 | 00,175,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_3.dll
[2009.08.19 22:37:33 | 00,025,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_5.dll
[2009.08.19 22:37:33 | 00,023,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_5.dll
[2009.08.19 22:37:31 | 00,513,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_2.dll
[2009.08.19 22:37:31 | 00,509,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_2.dll
[2009.08.19 22:37:31 | 00,072,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_1.dll
[2009.08.19 22:37:31 | 00,068,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_1.dll
[2009.08.19 22:37:30 | 00,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_2.dll
[2009.08.19 22:37:30 | 00,177,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_2.dll
[2009.08.19 22:37:29 | 01,942,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_39.dll
[2009.08.19 22:37:29 | 01,493,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_39.dll
[2009.08.19 22:37:29 | 00,540,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_39.dll
[2009.08.19 22:37:29 | 00,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_39.dll
[2009.08.19 22:37:28 | 04,992,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_39.dll
[2009.08.19 22:37:28 | 03,851,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_39.dll
[2009.08.19 22:37:26 | 00,511,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_1.dll
[2009.08.19 22:37:26 | 00,507,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_1.dll
[2009.08.19 22:37:26 | 00,068,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_0.dll
[2009.08.19 22:37:26 | 00,065,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_0.dll
[2009.08.19 22:37:25 | 00,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_1.dll