wykonałem polecenia, podaje logi:
1.hijack
Logfile of HijackThis v1.99.1
Scan saved at 11:32:25, on 2007-12-09
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\DialNet\winpppoverethernet.exe
C:\Program Files\DialNet\wrdialer.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\DialNet\WrOS.EXE
E:\simon\hijackthis.com
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [a-winpoet-service] "C:\Program Files\DialNet\winpppoverethernet.exe"
O4 - HKLM\..\Run: [z-wrdialer] "C:\Program Files\DialNet\wrdialer.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - Unknown owner - C:\WINDOWS\System32\nvsvc32.exe (file missing)
O23 - Service: Windows User Mode Driver Framework (UMWdf) - Unknown owner - C:\WINDOWS\System32\wdfmgr.exe (file missing)
O23 - Service: WinPPPoverEthernet - Fine Point Technologies, Inc. - C:\Program Files\DialNet\WrOS.EXE
[code][/code]
2.combofix
[quote]ComboFix 07-12-02.5 - Administrator 2007-12-09 11:28:07.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.0.1250.1.1045.18.16 [GMT 1:00]
Running from: C:\Documents and Settings\Administrator\Pulpit\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Pulpit\CFScript.txt
* Created a new restore point
FILE
C:\WINDOWS\system32\dllcache\msfav32.exe
C:\WINDOWS\System32\irdvxc.exe
C:\WINDOWS\System32\urdvxc.exe
C:\WINDOWS\System32\wbem\scrcs.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\myglobalsearch
C:\Program Files\myglobalsearch\bar\1.bin\M9FFXTBR.JAR
C:\Program Files\myglobalsearch\bar\1.bin\M9FFXTBR.MANIFEST
C:\Program Files\myglobalsearch\bar\1.bin\M9NTSTBR.JAR
C:\Program Files\myglobalsearch\bar\1.bin\M9NTSTBR.MANIFEST
C:\Program Files\myglobalsearch\bar\1.bin\M9PLUGIN.DLL
C:\Program Files\myglobalsearch\bar\1.bin\NPMYGLSH.DLL
C:\Program Files\myglobalsearch\bar\Cache\
00055B56.bin
C:\Program Files\myglobalsearch\bar\Cache\
00056316.bin
C:\Program Files\myglobalsearch\bar\Cache\
00058767.bin
C:\Program Files\myglobalsearch\bar\Cache\files.ini
C:\Program Files\myglobalsearch\bar\History\search
C:\Program Files\myglobalsearch\bar\Settings\knjbjhnr.exe
C:\Program Files\myglobalsearch\bar\Settings\prevcfg.htm
C:\WINDOWS\system32\.exe
C:\WINDOWS\system32\1_exception.nls
C:\WINDOWS\system32\csrs.exe
C:\WINDOWS\system32\dllcache\msfav32.exe
C:\WINDOWS\system32\drivers\ctl_w32.sys
C:\WINDOWS\system32\drivers\secdrv.sys
C:\WINDOWS\system32\firewall.exe
C:\WINDOWS\system32\iexplore.exe
C:\WINDOWS\System32\irdvxc.exe
C:\WINDOWS\system32\isass.exe
C:\WINDOWS\System32\urdvxc.exe
C:\WINDOWS\System32\wbem\scrcs.exe
C:\WINDOWS\system32\win.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_CTL_W32
-------\LEGACY_MSDISK
-------\LEGACY_MSWINDOWS
-------\LEGACY_RUNTIME
-------\LEGACY_WINDOWS_INTERNET_CONNECTION_SHARING
-------\MSDisk
-------\MSWindows
-------\runtime
-------\Windows Internet Connection Sharing
((((((((((((((((((((((((( Files Created from 2007-11-09 to 2007-12-09 )))))))))))))))))))))))))))))))
.
2007-12-07 13:13 . 2007-12-07 13:14 120,832 -r-hs---- C:\WINDOWS\system32\Tilecomfc.com
2007-12-07 13:10 . 2007-12-07 13:10 40,960 --a------ C:\WINDOWS\system32\diiduqc.exe
2007-12-06 21:40 . 2007-12-06 21:40 40,960 --a------ C:\WINDOWS\system32\krdcj.exe
2007-12-06 20:39 . 2007-12-06 20:39 40,960 --a------ C:\WINDOWS\system32\pxyg.exe
2007-12-06 20:18 . 2007-12-06 20:18 40,960 --a------ C:\WINDOWS\system32\bgerbmdh.exe
2007-12-06 18:39 . 2007-12-06 18:39 40,960 --a------ C:\WINDOWS\system32\qayf.exe
2007-12-06 18:10 . 2007-12-06 18:10 40,960 --a------ C:\WINDOWS\system32\bplbhemt.exe
2007-12-06 16:55 . 2007-12-06 16:55 40,960 --a------ C:\WINDOWS\system32\wyfhubjh.exe
2007-12-06 16:44 . 2007-12-06 16:44 490 --a------ C:\1.vbs
2007-12-06 16:41 . 2007-12-06 16:41 40,960 --a------ C:\WINDOWS\system32\jxrfexuo.exe
2007-12-06 16:04 . 2007-12-06 16:04 40,960 --a------ C:\WINDOWS\system32\ionkusw.exe
2007-12-06 11:55 . 2007-12-06 11:55 <DIR> d-------- C:\Program Files\sdfhfgd
2007-12-06 11:55 . 2007-12-06 11:56 547,770 --a------ C:\uryteqa23.exe
2007-12-06 11:50 . 2007-12-06 18:09 1,138,688 --a------ C:\WINDOWS\system32\Gothic.exe
2007-12-06 11:43 . 2007-12-07 22:46 392,704 --a------ C:\WINDOWS\system32\fk.exe
2007-12-06 11:42 . 2007-12-06 11:42 40,960 --a------ C:\WINDOWS\system32\qmrnzbv.exe
2007-12-05 21:49 . 2007-12-06 20:34 <DIR> d-------- C:\Program Files\dfrerter
2007-12-05 21:49 . 2007-12-06 20:34 991,310 --a------ C:\cg.pif
2007-12-05 21:45 . 2007-12-05 21:45 1,134,592 --a------ C:\WINDOWS\system32\SADASDA.exe
2007-12-05 21:18 . 2007-12-06 16:07 547,770 --a------ C:\WINDOWS\system32\ghhgjhjdfg.exe
2007-12-05 20:56 . 2007-12-05 20:56 48,748 --a------ C:\WINDOWS\system32\ttrrtt.exe
2007-12-05 20:56 . 2007-12-05 20:56 35,328 -r-hsc--- C:\WINDOWS\system32\dllcache\wintcps.exe
2007-12-05 19:59 . 2007-12-05 21:16 547,770 --a------ C:\WINDOWS\system32\ghhgjhj.exe
2007-12-05 19:59 . 2007-12-05 21:09 458,752 --a------ C:\WINDOWS\system32\nope.dll
2007-12-05 19:57 . 2007-12-05 19:57 547,770 --a------ C:\wdintoage.exe
2007-12-05 19:57 . 2007-12-05 21:09 458,752 --------- C:\WINDOWS\system32\Wseclayer.exe
2007-12-05 19:57 . 2007-12-05 20:14 27 --a------ C:\WINDOWS\system32\kuki.bat
2007-12-05 19:57 . 2007-12-07 22:15 0 --a------ C:\adware.exe
2007-12-05 19:47 . 2007-12-05 19:47 40,960 --a------ C:\WINDOWS\system32\zfgzt.exe
2007-12-05 17:25 . 2007-12-05 17:26 110,431 --a------ C:\cjntekap.exe
2007-12-05 15:53 . 2007-12-05 15:53 40,960 --a------ C:\WINDOWS\system32\ncbxk.exe
2007-12-05 14:05 . 2007-12-05 14:05 40,960 --a------ C:\WINDOWS\system32\mdetkrq.exe
2007-12-03 18:18 . 2007-12-03 18:18 40,960 --a------ C:\WINDOWS\system32\tlgy.exe
2007-12-03 17:37 . 2007-12-03 17:37 40,960 --a------ C:\WINDOWS\system32\qxgvkzpf.exe
2007-12-03 17:26 . 2007-12-03 17:29 1,159,168 --a------ C:\WINDOWS\system32\Syst3m32.exe
2007-12-03 17:17 . 2007-12-03 17:17 6,546,276 --a------ C:\WINDOWS\system32\setup_53465.exe
2007-12-03 16:45 . 2007-12-03 16:45 6,546,276 --a------ C:\WINDOWS\system32\setup_85355.exe
2007-12-03 16:35 . 2007-12-03 16:35 40,960 --a------ C:\WINDOWS\system32\xjzicuqg.exe
2007-12-03 16:29 . 2007-12-03 16:29 1,253,888 --a------ C:\WINDOWS\system32\afe.exe
2007-12-03 16:25 . 2007-12-03 16:25 6,546,276 --a------ C:\WINDOWS\system32\setup_12482.exe
2007-12-03 16:24 . 2007-12-03 16:24 <DIR> d-------- C:\Program Files\BearShare
2007-12-03 16:24 . 2007-12-03 16:24 <DIR> d-------- C:\My Downloads
2007-12-03 16:23 . 2007-12-03 16:23 569,856 --a------ C:\WINDOWS\system32\tez.exe
2007-12-03 16:10 . 2007-12-03 16:11 995,328 --a------ C:\WINDOWS\system32\load.exe
2007-12-03 15:22 . 2007-12-03 15:27 1,253,888 --a------ C:\WINDOWS\system32\znc.exe
2007-12-03 14:52 . 2007-12-03 17:30 167,936 --a------ C:\WINDOWS\system32\spdemo.exe
2007-12-03 14:52 . 2007-12-03 17:30 167,936 -r-hsc--- C:\WINDOWS\system32\dllcache\mravsc32.exe
2007-12-03 14:44 . 2007-12-03 14:44 6,546,276 --a------ C:\WINDOWS\system32\setup_07444.exe
2007-12-03 14:40 . 2007-12-03 14:40 0 --a------ C:\WINDOWS\system32\eraseme_86885.exe
2007-12-03 09:59 . 2007-12-04 20:43 178,688 --a------ C:\WINDOWS\system32\mpdemo.exe
2007-12-02 23:35 . 2001-07-21 23:23 1,875,968 --a--c--- C:\WINDOWS\system32\dllcache\msir3jp.lex
2007-12-02 23:34 . 2001-10-26 18:28 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll
2007-12-02 23:33 . 2001-10-26 17:29 2,134,528 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_smtpsnap.dll
2007-12-02 23:31 . 2007-12-02 23:31 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
2007-12-02 23:31 . 2007-12-02 23:31 749 -rah----- C:\WINDOWS\system32\wuaucpl.cpl.manifest
2007-12-02 23:31 . 2007-12-02 23:31 749 -rah----- C:\WINDOWS\system32\sapi.cpl.manifest
2007-12-02 23:31 . 2007-12-02 23:31 749 -rah----- C:\WINDOWS\system32\nwc.cpl.manifest
2007-12-02 23:31 . 2007-12-02 23:31 749 -rah----- C:\WINDOWS\system32\ncpa.cpl.manifest
2007-12-02 23:31 . 2007-12-02 23:31 488 -rah----- C:\WINDOWS\system32\logonui.exe.manifest
2007-12-02 23:28 . 2001-10-26 18:30 540,672 --a------ C:\WINDOWS\system32\spider.exe
2007-12-02 23:26 . 2001-08-17 20:12 23,070 --a------ C:\WINDOWS\system32\drivers\RTL8139.sys
2007-12-02 23:23 . 2001-10-26 18:29 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2007-12-02 23:23 . 2001-10-26 18:29 24,661 --a--c--- C:\WINDOWS\system32\dllcache\spxcoins.dll
2007-12-02 23:23 . 2001-10-26 18:29 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2007-12-02 23:23 . 2001-10-26 18:29 13,312 --a--c--- C:\WINDOWS\system32\dllcache\irclass.dll
2007-12-02 23:22 . 2001-10-27 12:35 1,085,938 -ra------ C:\WINDOWS\SET28.tmp
2007-12-02 23:22 . 2001-10-27 12:34 13,923 -ra------ C:\WINDOWS\SET34.tmp
2007-12-02 23:08 . 2001-10-26 18:27 1,041,491 --a--c--- C:\WINDOWS\system32\dllcache\cmnresm.dll
2007-12-02 23:08 . 2001-10-26 18:29 217,160 --a--c--- C:\WINDOWS\system32\dllcache\cmnclim.dll
2007-12-02 23:08 . 2001-10-26 18:29 113,222 --a--c--- C:\WINDOWS\system32\dllcache\zoneclim.dll
2007-12-02 23:08 . 2001-10-26 18:29 41,029 --a--c--- C:\WINDOWS\system32\dllcache\zcorem.dll
2007-12-02 23:08 . 2001-10-26 18:30 36,937 --a--c--- C:\WINDOWS\system32\dllcache\zclientm.exe
2007-12-02 23:08 . 2001-10-26 18:29 32,339 --a--c--- C:\WINDOWS\system32\dllcache\uniansi.dll
2007-12-02 23:08 . 2001-10-26 18:29 29,760 --a--c--- C:\WINDOWS\system32\dllcache\znetm.dll
2007-12-02 23:08 . 2001-10-26 18:29 13,894 --a--c--- C:\WINDOWS\system32\dllcache\zonelibm.dll
2007-12-02 23:08 . 2001-10-26 18:29 4,677 --a--c--- C:\WINDOWS\system32\dllcache\zeeverm.dll
2007-12-02 21:12 . 2007-12-02 21:12 98,304 --a------ C:\WINDOWS\system32\rab.exe
2007-12-02 21:02 . 2007-12-02 21:02 3,072 --ah----- C:\WINDOWS\system32\wker.exe
2007-12-02 20:50 . 2007-12-02 20:50 569,856 --a------ C:\WINDOWS\system32\dxw.exe
2007-12-02 20:08 . 2007-12-02 20:09 1,253,888 --a------ C:\WINDOWS\system32\ykc.exe
2007-12-02 17:28 . 2007-12-02 17:28 129 --a------ C:\WINDOWS\system32\492.reg
2007-12-02 17:20 . 2001-10-26 18:29 694,272 --a--c--- C:\WINDOWS\system32\dllcache\helpsvc.exe
2007-12-02 17:20 . 2001-10-26 18:30 67,072 --a--c--- C:\WINDOWS\system32\dllcache\setup50.exe
2007-12-02 17:18 . 2001-10-26 18:29 99,328 --a--c--- C:\WINDOWS\system32\dllcache\clipbrd.exe
2007-12-02 17:18 . 2001-10-26 18:29 99,328 --a------ C:\WINDOWS\system32\clipbrd.exe
2007-12-02 17:18 . 2001-10-26 18:30 15,360 --a------ C:\WINDOWS\system32\shadow.exe
2007-12-02 17:18 . 2001-10-26 18:30 15,360 --a--c--- C:\WINDOWS\system32\dllcache\shadow.exe
2007-12-02 17:10 . 2001-10-27 12:34 1,622,956 --a--c--- C:\WINDOWS\system32\dllcache\NT5.CAT
2007-12-02 17:10 . 2001-10-27 12:35 1,085,938 -ra------ C:\WINDOWS\SET2A.tmp
2007-12-02 17:10 . 2001-10-27 12:34 609,642 --a--c--- C:\WINDOWS\system32\dllcache\NT5INF.CAT
2007-12-02 17:10 . 2001-10-27 12:34 13,923 -ra------ C:\WINDOWS\SET36.tmp
2007-12-02 15:03 . 2007-12-02 15:03 129 --a------ C:\WINDOWS\system32\353.reg
2007-12-02 15:02 . 2007-12-03 16:29 1,253,888 -r-hs---- C:\WINDOWS\Mrshield.exe
2007-12-02 15:01 . 2007-12-02 15:02 95,232 --ah----- C:\WINDOWS\system32\gknjox.exe
2007-12-02 14:54 . 2007-12-02 14:58 39,212 --ah----- C:\WINDOWS\system32\nzfeg.exe
2007-12-02 14:42 . 2007-12-02 14:42 30,720 --a------ C:\WINDOWS\system32\setup_71031.exe
2007-12-02 14:36 . 2007-12-02 14:37 58,820 -ra------ C:\WINDOWS\system32\scrcs.exe
2007-12-02 14:33 . 2007-12-02 14:33 0 --a------ C:\WINDOWS\system32\hqghumea.dll
2007-12-02 14:32 . 2007-12-02 14:32 129 --a------ C:\WINDOWS\system32\577.reg
2007-12-02 14:29 . 2007-12-02 14:29 129 --a------ C:\WINDOWS\system32\892.reg
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-09 10:19 --------- d-----w C:\Program Files\DialNet
2007-12-02 22:41 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\panels\zeektjlr.exe
2007-12-02 22:41 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\panels\tjsnlncx.exe
2007-12-02 22:41 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\NetDiag\stleqtrb.exe
2007-12-02 22:41 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\NetDiag\bnkrcrqq.exe
2007-12-02 22:41 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\errors\xnejeese.exe
2007-12-02 22:41 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\ErrMsg\nvsbqtlx.exe
2007-12-02 22:41 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\DVDUpgrd\kvzexhbs.exe
2007-12-02 22:41 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\DFS\zwjcbxql.exe
2007-12-02 22:41 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\DFS\jlskvkjt.exe
2007-12-02 22:41 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\DFS\hhktjkel.exe
2007-12-02 22:41 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\CompatCtr\tcjqbtst.exe
2007-12-02 22:41 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\CompatCtr\nrbhslcz.exe
2007-12-02 22:41 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\CompatCtr\eqlrejrl.exe
2007-12-02 22:41 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\CompatCtr\brvhkxjh.exe
2007-12-02 22:41 121,856 ----a-w C:\WINDOWS\Help\tsbjbtvn.exe
2007-12-02 22:41 121,856 ----a-w C:\WINDOWS\Help\Tours\WindowsMediaPlayer\Cnt\tjnbzhbh.exe
2007-12-02 22:41 121,856 ----a-w C:\WINDOWS\Help\Tours\WindowsMediaPlayer\Audio\lllknblj.exe
2007-12-02 22:41 121,856 ----a-w C:\WINDOWS\Help\jjlenkbt.exe
2007-12-02 22:41 121,856 ----a-w C:\WINDOWS\Help\jbnshhqj.exe
2007-12-02 22:41 121,856 ----a-w C:\WINDOWS\Help\hwexrtne.exe
2007-12-02 22:41 121,856 ----a-w C:\WINDOWS\Help\bzehxvnz.exe
2007-12-02 13:09 130,144 ----a-w C:\msets.exe
2007-11-24 15:10 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-11-18 14:26 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-15 21:44 --------- d-----w C:\Program Files\Gadu-Gadu
2007-11-14 20:08 --------- d-----w C:\Program Files\microsoft frontpage
2007-11-13 20:54 --------- d-----w C:\Program Files\directx
2007-11-12 19:10 6,668,248 ----a-w C:\Program Files\Firefox Setup 2.0.0.9.exe
2007-11-12 18:55 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\InstallShield
2007-11-12 18:53 --------- d-----w C:\Program Files\Common Files\Adobe
2007-11-12 18:44 --------- d-----w C:\Program Files\Intel
2007-11-12 18:35 --------- d-----w C:\Program Files\Usługi online
2001-10-26 17:29 1,017,344 --sha-r C:\WINDOWS\system32\dygeqs.exe
2001-10-26 17:29 1,488,896 --sha-r C:\WINDOWS\system32\jjv.exe
2001-10-26 17:29 1,029,679 --sha-r C:\WINDOWS\system32\mavzhh.exe
2001-10-26 17:29 81,408 --sha-r C:\WINDOWS\system32\wbem\scricon.exe
.
((((((((((((((((((((((((((((( snapshot@2007-12-02_ 0.58.53,73 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-20 15:04:32 1,523,536 ----a-w C:\WINDOWS\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe
+ 2007-03-13 09:57:10 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
- 2001-10-26 17:29:58 73,728 ----a-w C:\WINDOWS\NOTEPAD.EXE
+ 2001-10-26 17:29:58 67,072 ----a-w C:\WINDOWS\notepad.exe
- 2001-10-26 17:29:54 700,928 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\HelpSvc.exe
+ 2001-10-26 17:29:54 694,272 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\HelpSvc.exe
- 2007-11-12 18:35:56 8,738 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\Config\Cntstore.bin
+ 2007-12-02 22:31:51 8,738 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\Config\Cntstore.bin
- 2007-11-12 18:35:53 80,007 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\OfflineCache\index.dat
+ 2007-12-02 22:31:50 80,345 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\OfflineCache\index.dat
- 2007-11-25 13:56:45 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\rc\rjzhtwer.exe
+ 2007-12-02 22:41:24 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\rc\rjzhtwer.exe
- 2007-11-25 13:56:45 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Common\jqnsbclx.exe
+ 2007-12-02 22:41:24 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Common\jqnsbclx.exe
- 2007-11-25 13:56:45 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Common\jzrjzkke.exe
+ 2007-12-02 22:41:24 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Common\jzrjzkke.exe
- 2007-11-25 13:56:46 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Common\vtxbneqq.exe
+ 2007-12-02 22:41:24 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Common\vtxbneqq.exe
- 2007-11-25 13:56:46 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Client\cqlwbrtn.exe
+ 2007-12-02 22:41:25 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Client\cqlwbrtn.exe
- 2007-11-25 13:56:46 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Client\hlnbkbjt.exe
+ 2007-12-02 22:41:25 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Client\hlnbkbjt.exe
- 2007-11-25 13:56:46 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Client\jllrjejn.exe
+ 2007-12-02 22:41:25 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Client\jllrjejn.exe
- 2007-11-25 13:56:46 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Client\kcqrjjel.exe
+ 2007-12-02 22:41:25 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Client\kcqrjjel.exe
- 2007-11-25 13:56:46 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Client\resrzjkr.exe
+ 2007-12-02 22:41:25 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Client\resrzjkr.exe
- 2007-11-25 13:56:46 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Client\rlkctexe.exe
+ 2007-12-02 22:41:25 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Client\rlkctexe.exe
- 2007-11-25 13:56:47 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Common\jjtkbtsb.exe
+ 2007-12-02 22:41:25 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Common\jjtkbtsb.exe
- 2007-11-25 13:56:46 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Common\slkweqkr.exe
+ 2007-12-02 22:41:25 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Common\slkweqkr.exe
- 2007-11-25 13:56:47 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Common\xxrlrrck.exe
+ 2007-12-02 22:41:25 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Common\xxrlrrck.exe
- 2007-11-25 13:56:47 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Server\bbcrvske.exe
+ 2007-12-02 22:41:26 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Server\bbcrvske.exe
- 2007-11-25 13:56:47 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Server\brbjhjhb.exe
+ 2007-12-02 22:41:26 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Server\brbjhjhb.exe
- 2007-11-25 13:56:47 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Server\ejjtwclz.exe
+ 2007-12-02 22:41:26 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Server\ejjtwclz.exe
- 2007-11-25 13:56:47 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Server\heclkcje.exe
+ 2007-12-02 22:41:26 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Server\heclkcje.exe
- 2007-11-25 13:56:47 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Server\vhzlshll.exe
+ 2007-12-02 22:41:26 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Server\vhzlshll.exe
- 2007-11-25 13:56:46 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\lbncltew.exe
+ 2007-12-02 22:41:25 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\lbncltew.exe
- 2007-11-25 13:56:47 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\lenvstcw.exe
+ 2007-12-02 22:41:26 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\lenvstcw.exe
- 2007-11-25 13:56:47 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\sljktqsl.exe
+ 2007-12-02 22:41:26 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\sljktqsl.exe
- 2007-11-25 13:56:48 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\cjrhtnee.exe
+ 2007-12-02 22:41:27 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\cjrhtnee.exe
- 2007-11-25 13:56:49 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\cszbbkjb.exe
+ 2007-12-02 22:41:27 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\cszbbkjb.exe
- 2007-11-25 13:56:49 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\hzenbhql.exe
+ 2007-12-02 22:41:27 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\hzenbhql.exe
- 2007-11-25 13:56:48 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\kenjxzsk.exe
+ 2007-12-02 22:41:27 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\kenjxzsk.exe
- 2007-11-25 13:56:48 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\qnkstrhn.exe
+ 2007-12-02 22:41:27 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\qnkstrhn.exe
- 2007-11-25 13:56:49 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\selznkbn.exe
+ 2007-12-02 22:41:28 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\selznkbn.exe
- 2007-11-25 13:56:48 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\tehbbexs.exe
+ 2007-12-02 22:41:27 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\tehbbexs.exe
- 2007-11-25 13:56:49 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\trvnbvzr.exe
+ 2007-12-02 22:41:28 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\trvnbvzr.exe
- 2007-11-25 13:56:49 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\UpdateCtr\ecrvhvjh.exe
+ 2007-12-02 22:41:28 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\UpdateCtr\ecrvhvjh.exe
- 2007-11-25 13:56:49 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\UpdateCtr\ewznktww.exe
+ 2007-12-02 22:41:28 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\UpdateCtr\ewznktww.exe
- 2007-11-25 13:56:49 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\UpdateCtr\hnshlbtv.exe
+ 2007-12-02 22:41:28 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\UpdateCtr\hnshlbtv.exe
- 2007-11-25 13:56:49 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\UpdateCtr\hsxenjvk.exe
+ 2007-12-02 22:41:28 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\UpdateCtr\hsxenjvk.exe
- 2007-11-25 13:56:49 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\UpdateCtr\necxlsbh.exe
+ 2007-12-02 22:41:28 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\UpdateCtr\necxlsbh.exe
- 2007-11-25 13:56:50 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\estewkrn.exe
+ 2007-12-02 22:41:29 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\estewkrn.exe
- 2007-11-25 13:56:50 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\nbbrcrbb.exe
+ 2007-12-02 22:41:29 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\nbbrcrbb.exe
- 2007-11-25 13:56:52 121,856 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\btlekkxb.exe
+ 2007-12-02 22:41:32 121,856 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\btlekkxb.exe
- 2007-11-25 13:56:50 121,856 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\btlekkxb.exe
+ 2007-12-02 22:41:30 121,856 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\btlekkxb.exe
- 2007-11-25 13:56:51 121,856 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\btlekkxb.exe
+ 2007-12-02 22:41:30 121,856 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\btlekkxb.exe
- 2007-11-25 13:56:52 121,856 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\btlekkxb.exe
+ 2007-12-02 22:41:31 121,856 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\btlekkxb.exe
- 2007-11-25 13:56:50 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\tlrrsvlj.exe
+ 2007-12-02 22:41:29 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\tlrrsvlj.exe
- 2007-11-25 13:56:50 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\zejthvxk.exe
+ 2007-12-02 22:41:29 77,312 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\zejthvxk.exe
- 2007-11-22 21:43:48 5,108 ----a-w C:\WINDOWS\rdrive\del2.exe
+ 2007-11-29 23:05:14 5,192 ----a-w C:\WINDOWS\rdrive\del2.exe
- 2007-11-22 21:43:48 5,108 ----a-w C:\WINDOWS\rdrive\del3.exe
+ 2007-11-29 23:05:14 5,192 ----a-w C:\WINDOWS\rdrive\del3.exe
+ 2007-11-30 12:15:56 5,660 ----a-w C:\WINDOWS\rdrive\ju.exe
- 2007-11-23 23:44:48 67,072 ----a-w C:\WINDOWS\rdrive\locop.exe
+ 2007-11-23 23:44:48 60,416 ----a-w C:\WINDOWS\rdrive\locop.exe
- 2007-11-12 18:36:51 237,568 ---ha-w C:\WINDOWS\repair\ntuser.dat
+ 2007-12-02 22:33:00 303,104 ---ha-w C:\WINDOWS\repair\ntuser.dat
- 2007-12-01 22:17:40 922,624 --sh--r C:\WINDOWS\system\msnrav.exe
+ 2007-12-07 21:46:30 898,048 --sh--r C:\WINDOWS\system\msnrav.exe
- 2007-11-21 20:05:07 6,277,261 ----a-w C:\WINDOWS\system32\algs.exe
+ 2001-10-26 17:29:52 53,134 ---h--w C:\WINDOWS\system32\algs.exe
- 2001-10-26 17:29:46 17,920 ----a-w C:\WINDOWS\system32\attrib.exe
+ 2001-10-26 17:29:46 11,264 ----a-w C:\WINDOWS\system32\attrib.exe
- 2005-01-28 12:44:28 294,912 ----a-w C:\WINDOWS\system32\blackbox.dll
+ 2001-10-26 17:29:26 204,800 ----a-w C:\WINDOWS\system32\blackbox.dll
+ 2006-07-25 08:28:06 6,921 ----a-w C:\WINDOWS\system32\cnick.dll
+ 2006-05-12 19:08:54 20,652 ----a-w C:\WINDOWS\system32\colfld.dll
- 2007-12-01 23:49:36 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2007-12-09 10:30:37 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2007-12-01 23:49:36 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Historia\History.IE5\index.dat
+ 2007-12-09 10:30:37 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Historia\History.IE5\index.dat
+ 2007-12-02 22:38:07 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Historia\History.IE5\MSHist012007120220071203\index.dat
- 2007-12-01 23:49:36 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-09 10:30:37 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-06 15:44:33 357,500 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Temporary Internet Files\Content.IE5\UQY2EVXN\84785_winhtb[1].exe
- 2001-10-26 17:29:50 31,232 ----a-w C:\WINDOWS\system32\conime.exe
+ 2001-10-26 17:29:50 24,576 ----a-w C:\WINDOWS\system32\conime.exe
- 2001-10-26 17:29:50 14,848 ----a-w C:\WINDOWS\system32\control.exe
+ 2001-10-26 17:29:50 8,192 ----a-w C:\WINDOWS\system32\control.exe
- 2001-10-26 17:29:50 20,480 ----a-w C:\WINDOWS\system32\convert.exe
+ 2001-10-26 17:29:50 13,824 ----a-w C:\WINDOWS\system32\convert.exe
- 2001-10-26 17:29:50 102,450 ----a-w C:\WINDOWS\system32\cscript.exe
+ 2001-10-26 17:29:50 110,642 ----a-w C:\WINDOWS\system32\cscript.exe
- 2001-10-26 17:29:50 19,968 ----a-w C:\WINDOWS\system32\ctfmon.exe
+ 2001-10-26 17:29:50 13,312 ----a-w C:\WINDOWS\system32\ctfmon.exe
- 2005-01-28 12:44:28 294,912 -c--a-w C:\WINDOWS\system32\dllcache\blackbox.dll
+ 2001-10-26 17:29:26 204,800 -c--a-w C:\WINDOWS\system32\dllcache\blackbox.dll
- 2005-01-28 12:44:28 258,296 -c--a-w C:\WINDOWS\system32\dllcache\drmclien.dll
+ 2001-10-26 17:29:28 258,048 -c--a-w C:\WINDOWS\system32\dllcache\drmclien.dll
- 2005-01-28 12:44:28 96,768 -c--a-w C:\WINDOWS\system32\dllcache\drmstor.dll
+ 2001-10-26 17:29:28 76,830 -c--a-w C:\WINDOWS\system32\dllcache\drmstor.dll
- 2005-01-28 12:44:28 502,272 -c--a-w C:\WINDOWS\system32\dllcache\drmv2clt.dll
+ 2001-10-26 17:29:28 589,824 -c--a-w C:\WINDOWS\system32\dllcache\drmv2clt.dll
- 2005-01-28 12:44:28 6,656 -c--a-w C:\WINDOWS\system32\dllcache\laprxy.dll
+ 2001-10-26 17:29:32 6,656 -c--a-w C:\WINDOWS\system32\dllcache\laprxy.dll
- 2005-01-28 12:44:28 142,336 -c--a-w C:\WINDOWS\system32\dllcache\msnetobj.dll
+ 2001-10-26 17:29:36 174,592 -c--a-w C:\WINDOWS\system32\dllcache\msnetobj.dll
- 2005-01-28 12:44:28 221,184 -c--a-w C:\WINDOWS\system32\dllcache\qasf.dll
+ 2001-10-26 17:29:40 152,576 -c--a-w C:\WINDOWS\system32\dllcache\qasf.dll
- 2005-01-28 12:44:28 224,768 -c--a-w C:\WINDOWS\system32\dllcache\wmasf.dll
+ 2001-10-26 17:29:46 274,432 -c--a-w C:\WINDOWS\system32\dllcache\wmasf.dll
+ 2003-03-16 14:49:00 33,792 --s-a-w C:\WINDOWS\system32\dmans.dll
- 2001-10-26 17:29:52 25,600 ----a-w C:\WINDOWS\system32\dpnsvr.exe
+ 2001-10-26 17:29:52 18,944 ----a-w C:\WINDOWS\system32\dpnsvr.exe
- 2001-10-26 17:29:52 67,072 ----a-w C:\WINDOWS\system32\driverquery.exe
+ 2001-10-26 17:29:52 60,416 ----a-w C:\WINDOWS\system32\driverquery.exe
- 2001-07-24 00:25:14 122,472 ----a-w C:\WINDOWS\system32\drivers\aec.sys
+ 2001-10-26 18:03:24 122,472 ----a-w C:\WINDOWS\system32\drivers\aec.sys
- 2001-08-17 20:58:00 25,472 ----a-w C:\WINDOWS\system32\drivers\AGP440.SYS
+ 2001-10-26 18:03:24 25,472 ----a-w C:\WINDOWS\system32\drivers\agp440.sys
- 2001-08-17 20:51:56 86,656 ----a-w C:\WINDOWS\system32\drivers\atapi.sys
+ 2001-08-17 21:51:54 86,656 ----a-w C:\WINDOWS\system32\drivers\atapi.sys
- 2001-08-17 21:01:20 57,344 ----a-w C:\WINDOWS\system32\drivers\drmk.sys
+ 2001-10-26 18:03:24 57,344 ----a-w C:\WINDOWS\system32\drivers\drmk.sys
- 2001-08-17 21:02:32 9,728 ----a-w C:\WINDOWS\system32\drivers\gameenum.sys
+ 2001-10-26 18:03:24 9,728 ----a-w C:\WINDOWS\system32\drivers\gameenum.sys
- 2001-10-26 15:47:28 36,224 ----a-w C:\WINDOWS\system32\drivers\isapnp.sys
+ 2001-10-26 16:47:26 36,224 ----a-w C:\WINDOWS\system32\drivers\isapnp.sys
- 2001-08-17 21:00:54 159,232 ----a-w C:\WINDOWS\system32\drivers\kmixer.sys
+ 2001-10-26 18:03:24 159,232 ----a-w C:\WINDOWS\system32\drivers\kmixer.sys
- 2001-08-18 05:24:30 134,144 ----a-w C:\WINDOWS\system32\drivers\ks.sys
+ 2001-10-26 18:03:24 134,144 ----a-w C:\WINDOWS\system32\drivers\ks.sys
- 2001-08-17 20:48:48 6,400 ----a-w C:\WINDOWS\system32\drivers\MSKSSRV.sys
+ 2001-10-26 18:03:24 6,400 ----a-w C:\WINDOWS\system32\drivers\mskssrv.sys
- 2001-08-17 20:48:42 5,120 ----a-w C:\WINDOWS\system32\drivers\MSPCLOCK.sys
+ 2001-10-26 18:03:24 5,120 ----a-w C:\WINDOWS\system32\drivers\mspclock.sys
- 2001-08-17 20:48:46 4,608 ----a-w C:\WINDOWS\system32\drivers\MSPQM.sys
+ 2001-10-26 18:03:24 4,608 ----a-w C:\WINDOWS\system32\drivers\mspqm.sys
- 2001-10-26 15:56:44 62,848 ----a-w C:\WINDOWS\system32\drivers\pci.sys
+ 2001-10-26 16:56:42 62,848 ----a-w C:\WINDOWS\system32\drivers\pci.sys
- 2001-10-26 15:56:44 3,456 ----a-w C:\WINDOWS\system32\drivers\pciide.sys
+ 2001-10-26 16:56:42 3,456 ----a-w C:\WINDOWS\system32\drivers\pciide.sys
- 2001-08-17 20:51:50 23,680 ----a-w C:\WINDOWS\system32\drivers\pciidex.sys
+ 2001-08-17 21:51:48 23,680 ----a-w C:\WINDOWS\system32\drivers\pciidex.sys
- 2001-08-18 05:24:38 135,040 ----a-w C:\WINDOWS\system32\drivers\portcls.sys
+ 2001-10-26 18:03:24 135,040 ----a-w C:\WINDOWS\system32\drivers\portcls.sys
- 2001-08-17 21:01:22 42,752 ----a-w C:\WINDOWS\system32\drivers\stream.sys
+ 2001-10-26 18:03:24 42,752 ----a-w C:\WINDOWS\system32\drivers\stream.sys
- 2001-08-17 21:00:52 54,272 ----a-w C:\WINDOWS\system32\drivers\swmidi.sys
+ 2001-10-26 18:03:24 54,272 ----a-w C:\WINDOWS\system32\drivers\swmidi.sys
- 2001-08-18 05:24:44 57,472 ----a-w C:\WINDOWS\system32\drivers\sysaudio.sys
+ 2001-10-26 18:03:24 57,472 ----a-w C:\WINDOWS\system32\drivers\sysaudio.sys
- 2001-08-17 21:03:32 24,960 ----a-w C:\WINDOWS\system32\drivers\usbccgp.sys
+ 2001-08-17 22:03:30 24,960 ----a-w C:\WINDOWS\system32\drivers\usbccgp.sys
- 2001-08-17 21:03:16 50,688 ----a-w C:\WINDOWS\system32\drivers\usbhub.sys
+ 2001-08-17 22:03:14 50,688 ----a-w C:\WINDOWS\system32\drivers\usbhub.sys
- 2001-08-17 21:03:18 123,264 ----a-w C:\WINDOWS\system32\drivers\usbport.sys
+ 2001-08-17 22:03:16 123,264 ----a-w C:\WINDOWS\system32\drivers\usbport.sys
- 2001-08-17 21:03:22 21,760 ----a-w C:\WINDOWS\system32\drivers\USBSTOR.SYS
+ 2001-08-17 22:03:20 21,760 ----a-w C:\WINDOWS\system32\drivers\usbstor.sys
- 2001-08-17 21:03:08 18,944 ----a-w C:\WINDOWS\system32\drivers\usbuhci.sys
+ 2001-08-17 22:03:06 18,944 ----a-w C:\WINDOWS\system32\drivers\usbuhci.sys
- 2001-08-18 05:24:46 79,616 ----a-w C:\WINDOWS\system32\drivers\wdmaud.sys
+ 2001-10-26 18:03:24 79,616 ----a-w C:\WINDOWS\system32\drivers\wdmaud.sys
- 2005-01-28 12:44:28 258,296 ----a-w C:\WINDOWS\system32\drmclien.dll
+ 2001-10-26 17:29:28 258,048 ----a-w C:\WINDOWS\system32\drmclien.dll
- 2005-01-28 12:44:28 96,768 ----a-w C:\WINDOWS\system32\drmstor.dll
+ 2001-10-26 17:29:28 76,830 ----a-w C:\WINDOWS\system32\drmstor.dll
- 2005-01-28 12:44:28 502,272 ----a-w C:\WINDOWS\system32\drmv2clt.dll
+ 2001-10-26 17:29:28 589,824 ----a-w C:\WINDOWS\system32\drmv2clt.dll
- 2001-10-26 17:29:52 36,864 ----a-w C:\WINDOWS\system32\dumprep.exe
+ 2001-10-26 17:29:52 30,208 ----a-w C:\WINDOWS\system32\dumprep.exe
- 2007-12-01 21:08:34 86,260 ----a-w C:\WINDOWS\system32\E0chis.exe
+ 2007-12-06 17:44:00 79,604 ----a-w C:\WINDOWS\system32\E0chis.exe
+ 2005-03-28 13:31:48 88,944 ----a-w C:\WINDOWS\system32\eciysaw.dll
+ 2001-10-26 17:29:30 514,587 ----a-w C:\WINDOWS\system32\edb500.dll
- 2007-11-12 18:32:28 21,856 ----a-w C:\WINDOWS\system32\emptyregdb.dat
+ 2007-12-02 22:29:27 23,040 ----a-w C:\WINDOWS\system32\emptyregdb.dat
- 2001-10-26 17:29:54 9,728 ----a-w C:\WINDOWS\system32\fixmapi.exe
+ 2001-10-26 17:29:54 3,072 ----a-w C:\WINDOWS\system32\fixmapi.exe
- 2007-11-15 21:49:32 181,040 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2007-12-02 22:37:53 181,040 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
- 2007-12-01 22:17:40 403,456 ----a-w C:\WINDOWS\system32\fuck.exe
+ 2007-12-02 22:41:36 922,624 ----a-w C:\WINDOWS\system32\fuck.exe
+ 2006-05-13 04:06:02 696,320 ----a-w C:\WINDOWS\system32\fvist.com
- 2007-11-12 18:59:49 983,040 ----a-w C:\WINDOWS\system32\G0ahic.exe
+ 2007-12-06 15:55:29 983,040 ----a-w C:\WINDOWS\system32\G0ahic.exe
- 2001-10-26 17:29:54 44,544 ----a-w C:\WINDOWS\system32\grpconv.exe
+ 2001-10-26 17:29:54 37,888 ----a-w C:\WINDOWS\system32\grpconv.exe
- 2001-10-26 17:29:54 34,816 ----a-w C:\WINDOWS\system32\ie4uinit.exe
+ 2001-10-26 17:29:54 28,160 ----a-w C:\WINDOWS\system32\ie4uinit.exe
- 2000-06-22 15:31:00 198,144 ----a-w C:\WINDOWS\system32\Ir50_qc.dll
+ 2001-10-26 17:28:12 200,192 ----a-w C:\WINDOWS\system32\ir50_qc.dll
- 2000-06-22 15:31:46 181,760 ----a-w C:\WINDOWS\system32\Ir50_qcx.dll
+ 2001-10-26 17:27:04 183,808 ----a-w C:\WINDOWS\system32\ir50_qcx.dll
- 2001-10-26 17:29:54 29,696 ----a-w C:\WINDOWS\system32\lights.exe
+ 2001-10-26 17:29:54 36,352 ----a-w C:\WINDOWS\system32\lights.exe
- 2001-10-26 17:29:54 33,280 ----a-w C:\WINDOWS\system32\lnkstub.exe
+ 2001-10-26 17:29:54 26,624 ----a-w C:\WINDOWS\system32\lnkstub.exe
- 2001-10-26 17:29:56 11,776 ----a-w C:\WINDOWS\system32\lodctr.exe
+ 2001-10-26 17:29:56 5,120 ----a-w C:\WINDOWS\system32\lodctr.exe
- 2001-10-26 17:29:56 31,232 ----a-w C:\WINDOWS\system32\logagent.exe
+ 2001-10-26 17:29:56 24,576 ----a-w C:\WINDOWS\system32\logagent.exe
+ 2007-11-21 00:04:14 218,496 ----a-r C:\WINDOWS\system32\Macromed\Flash\FlashUtil9e.exe
+ 2007-12-04 12:45:07 74,649 ----a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
+ 2006-01-06 05:39:32 24,065 ----a-w C:\WINDOWS\system32\mansor.exe
- 1999-05-17 11:56:00 135,168 ----a-w C:\WINDOWS\system32\MAPISTUB.DLL
+ 2001-10-26 17:29:34 112,128 ----a-w C:\WINDOWS\system32\mapistub.dll
- 2001-10-26 17:29:56 142,848 ----a-w C:\WINDOWS\system32\mobsync.exe
+ 2001-10-26 17:29:56 136,192 ----a-w C:\WINDOWS\system32\mobsync.exe
+ 2007-12-02 12:59:50 1,109,657 ----a-w C:\WINDOWS\system32\MrSonic.exe
+ 2001-10-26 17:29:58 34,816 ----a-w C:\WINDOWS\system32\msiregmv.exe
- 2005-01-28 12:44:28 142,336 ----a-w C:\WINDOWS\system32\msnetobj.dll
+ 2001-10-26 17:29:36 174,592 ----a-w C:\WINDOWS\system32\msnetobj.dll
+ 2005-01-27 12:53:04 89,005 ----a-w C:\WINDOWS\system32\na4.dll
+ 2003-09-25 18:27:28 35,328 ----a-w C:\WINDOWS\system32\NITE.exe
+ 2006-05-11 05:50:58 13,765 ----a-w C:\WINDOWS\system32\nmessd.dll
- 2001-10-26 17:30:00 38,400 ----a-w C:\WINDOWS\system32\ntsd.exe
+ 2001-10-26 17:30:00 31,744 ----a-w C:\WINDOWS\system32\ntsd.exe
+ 2004-10-30 14:50:04 35,840 ----a-w C:\WINDOWS\system32\NTSX.exe
- 2007-11-25 13:57:09 77,312 ----a-w C:\WINDOWS\system32\oobe\actsetup\blvccbsx.exe
+ 2007-12-02 22:41:51 121,856 ----a-w C:\WINDOWS\system32\oobe\actsetup\blvccbsx.exe
- 2007-11-25 13:57:09 77,312 ----a-w C:\WINDOWS\system32\oobe\actsetup\brvecwcs.exe
+ 2007-12-02 22:41:51 121,856 ----a-w C:\WINDOWS\system32\oobe\actsetup\brvecwcs.exe
- 2007-11-25 13:57:09 77,312 ----a-w C:\WINDOWS\system32\oobe\actsetup\btesnnel.exe
+ 2007-12-02 22:41:51 121,856 ----a-w C:\WINDOWS\system32\oobe\actsetup\btesnnel.exe
- 2007-11-25 13:57:10 77,312 ----a-w C:\WINDOWS\system32\oobe\actsetup\btqkxenz.exe
+ 2007-12-02 22:41:52 121,856 ----a-w C:\WINDOWS\system32\oobe\actsetup\btqkxenz.exe
- 2007-11-25 13:57:10 77,312 ----a-w C:\WINDOWS\system32\oobe\actsetup\cwbbnetr.exe
+ 2007-12-02 22:41:52 121,856 ----a-w C:\WINDOWS\system32\oobe\actsetup\cwbbnetr.exe
- 2007-11-25 13:57:10 77,312 ----a-w C:\WINDOWS\system32\oobe\actsetup\hlrrerkq.exe
+ 2007-12-02 22:41:52 121,856 ----a-w C:\WINDOWS\system32\oobe\actsetup\hlrrerkq.exe
- 2007-11-25 13:57:10 77,312 ----a-w C:\WINDOWS\system32\oobe\actsetup\knkskthw.exe
+ 2007-12-02 22:41:52 121,856 ----a-w C:\WINDOWS\system32\oobe\actsetup\knkskthw.exe
- 2007-11-25 13:57:10 77,312 ----a-w C:\WINDOWS\system32\oobe\actsetup\lrlzztll.exe
+ 2007-12-02 22:41:53 121,856 ----a-w C:\WINDOWS\system32\oobe\actsetup\lrlzztll.exe
- 2007-11-25 13:57:09 77,312 ----a-w C:\WINDOWS\system32\oobe\actsetup\nzzwhebn.exe
+ 2007-12-02 22:41:50 121,856 ----a-w C:\WINDOWS\system32\oobe\actsetup\nzzwhebn.exe
- 2007-11-25 13:57:10 77,312 ----a-w C:\WINDOWS\system32\oobe\actsetup\rkjenssc.exe
+ 2007-12-02 22:41:52 121,856 ----a-w C:\WINDOWS\system32\oobe\actsetup\rkjenssc.exe
- 2007-11-25 13:57:10 77,312 ----a-w C:\WINDOWS\system32\oobe\actsetup\rrthsntk.exe
+ 2007-12-02 22:41:52 121,856 ----a-w C:\WINDOWS\system32\oobe\actsetup\rrthsntk.exe
- 2007-11-25 13:57:10 77,312 ----a-w C:\WINDOWS\system32\oobe\actsetup\tchekrqt.exe
+ 2007-12-02 22:41:52 121,856 ----a-w C:\WINDOWS\system32\oobe\actsetup\tchekrqt.exe
- 2007-11-25 13:57:09 77,312 ----a-w C:\WINDOWS\system32\oobe\actsetup\vrrkkhbn.exe
+ 2007-12-02 22:41:50 121,856 ----a-w C:\WINDOWS\system32\oobe\actsetup\vrrkkhbn.exe
- 2007-11-25 13:57:09 77,312 ----a-w C:\WINDOWS\system32\oobe\actsetup\zvswnlev.exe
+ 2007-12-02 22:41:50 121,856 ----a-w C:\WINDOWS\system32\oobe\actsetup\zvswnlev.exe
- 2007-11-25 13:57:11 77,312 ----a-w C:\WINDOWS\system32\oobe\error\ektltnch.exe
+ 2007-12-02 22:41:54 121,856 ----a-w C:\WINDOWS\system32\oobe\error\ektltnch.exe
- 2007-11-25 13:57:11 77,312 ----a-w C:\WINDOWS\system32\oobe\error\erettxjr.exe
+ 2007-12-02 22:41:53 121,856 ----a-w C:\WINDOWS\system32\oobe\error\erettxjr.exe
- 2007-11-25 13:57:11 77,312 ----a-w C:\WINDOWS\system32\oobe\error\jkhehnjn.exe
+ 2007-12-02 22:41:53 121,856 ----a-w C:\WINDOWS\system32\oobe\error\jkhehnjn.exe
- 2007-11-25 13:57:11 77,312 ----a-w C:\WINDOWS\system32\oobe\error\kbwnhlkk.exe
+ 2007-12-02 22:41:54 121,856 ----a-w C:\WINDOWS\system32\oobe\error\kbwnhlkk.exe
- 2007-11-25 13:57:11 77,312 ----a-w C:\WINDOWS\system32\oobe\error\lktkttrb.exe
+ 2007-12-02 22:41:54 121,856 ----a-w C:\WINDOWS\system32\oobe\error\lktkttrb.exe
- 2007-11-25 13:57:11 77,312 ----a-w C:\WINDOWS\system32\oobe\error\neehnzxl.exe
+ 2007-12-02 22:41:54 121,856 ----a-w C:\WINDOWS\system32\oobe\error\neehnzxl.exe
- 2007-11-25 13:57:11 77,312 ----a-w C:\WINDOWS\system32\oobe\error\sswzlttc.exe
+ 2007-12-02 22:41:54 121,856 ----a-w C:\WINDOWS\system32\oobe\error\sswzlttc.exe
- 2007-11-25 13:57:10 77,312 ----a-w C:\WINDOWS\system32\oobe\error\xenjnbqe.exe
+ 2007-12-02 22:41:53 121,856 ----a-w C:\WINDOWS\system32\oobe\error\xenjnbqe.exe
- 2007-11-25 13:57:11 77,312 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\nevttblh.exe
+ 2007-12-02 22:41:55 121,856 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\nevttblh.exe
- 2007-11-25 13:57:11 77,312 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\qxztllwj.exe
+ 2007-12-02 22:41:54 121,856 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\qxztllwj.exe
- 2007-11-25 13:57:11 77,312 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\slhcezwb.exe
+ 2007-12-02 22:41:54 121,856 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\slhcezwb.exe
- 2007-11-25 13:57:12 77,312 ----a-w C:\WINDOWS\system32\oobe\html\iconnect\jsnsljzh.exe
+ 2007-12-02 22:41:55 121,856 ----a-w C:\WINDOWS\system32\oobe\html\iconnect\jsnsljzh.exe
- 2007-11-25 13:57:12 77,312 ----a-w C:\WINDOWS\system32\oobe\html\iconnect\shrtrsbs.exe
+ 2007-12-02 22:41:55 121,856 ----a-w C:\WINDOWS\system32\oobe\html\iconnect\shrtrsbs.exe
- 2007-11-25 13:57:12 77,312 ----a-w C:\WINDOWS\system32\oobe\html\isptype\lnvlnzbq.exe
+ 2007-12-02 22:41:55 121,856 ----a-w C:\WINDOWS\system32\oobe\html\isptype\lnvlnzbq.exe
- 2007-11-25 13:57:13 77,312 ----a-w C:\WINDOWS\system32\oobe\html\mouse\bccxejnc.exe
+ 2007-12-02 22:41:56 121,856 ----a-w C:\WINDOWS\system32\oobe\html\mouse\bccxejnc.exe
- 2007-11-25 13:57:13 77,312 ----a-w C:\WINDOWS\system32\oobe\html\mouse\bzrbbsrn.exe
+ 2007-12-02 22:41:56 121,856 ----a-w C:\WINDOWS\system32\oobe\html\mouse\bzrbbsrn.exe
- 2007-11-25 13:57:13 77,312 ----a-w C:\WINDOWS\system32\oobe\html\mouse\cjxsjlbr.exe
+ 2007-12-02 22:41:57 121,856 ----a-w C:\WINDOWS\system32\oobe\html\mouse\cjxsjlbr.exe
- 2007-11-25 13:57:12 77,312 ----a-w C:\WINDOWS\system32\oobe\html\mouse\hcvxrtwz.exe
+ 2007-12-02 22:41:56 121,856 ----a-w C:\WINDOWS\system32\oobe\html\mouse\hcvxrtwz.exe
- 2007-11-25 13:57:13 77,312 ----a-w C:\WINDOWS\system32\oobe\html\mouse\jjlhknhh.exe
+ 2007-12-02 22:41:56 121,856 ----a-w C:\WINDOWS\system32\oobe\html\mouse\jjlhknhh.exe
- 2007-11-25 13:57:12 77,312 ----a-w C:\WINDOWS\system32\oobe\html\mouse\jlkshlvl.exe
+ 2007-12-02 22:41:56 121,856 ----a-w C:\WINDOWS\system32\oobe\html\mouse\jlkshlvl.exe
- 2007-11-25 13:57:13 77,312 ----a-w C:\WINDOWS\system32\oobe\html\mouse\khkvhhsb.exe
+ 2007-12-02 22:41:57 121,856 ----a-w C:\WINDOWS\system32\oobe\html\mouse\khkvhhsb.exe
- 2007-11-25 13:57:13 77,312 ----a-w C:\WINDOWS\system32\oobe\html\mouse\klkhkrts.exe
+ 2007-12-02 22:41:57 121,856 ----a-w C:\WINDOWS\system32\oobe\html\mouse\klkhkrts.exe
- 2007-11-25 13:57:12 77,312 ----a-w C:\WINDOWS\system32\oobe\html\mouse\lbzcxver.exe
+ 2007-12-02 22:41:56 121,856 ----a-w C:\WINDOWS\system32\oobe\html\mouse\lbzcxver.exe
- 2007-11-25 13:57:12 77,312 ----a-w C:\WINDOWS\system32\oobe\html\mouse\nrlcnzsh.exe
+ 2007-12-02 22:41:56 121,856 ----a-w C:\WINDOWS\system32\oobe\html\mouse\nrlcnzsh.exe
- 2007-11-25 13:57:13 77,312 ----a-w C:\WINDOWS\system32\oobe\html\mouse\qetvqlnw.exe
+ 2007-12-02 22:41:57 121,856 ----a-w C:\WINDOWS\system32\oobe\html\mouse\qetvqlnw.exe
- 2007-11-25 13:57:13 77,312 ----a-w C:\WINDOWS\system32\oobe\html\mouse\rbnrnnxt.exe
+ 2007-12-02 22:41:57 121,856 ----a-w C:\WINDOWS\system32\oobe\html\mouse\rbnrnnxt.exe
- 2007-11-25 13:57:14 77,312 ----a-w C:\WINDOWS\system32\oobe\html\sconnect\jkhjlhbb.exe
+ 2007-12-02 22:41:58 121,856 ----a-w C:\WINDOWS\system32\oobe\html\sconnect\jkhjlhbb.exe
- 2007-11-25 13:57:14 77,312 ----a-w C:\WINDOWS\system32\oobe\html\sconnect\vznnebet.exe
+ 2007-12-02 22:41:58 121,856 ----a-w C:\WINDOWS\system32\oobe\html\sconnect\vznnebet.exe
- 2007-11-25 13:57:14 77,312 ----a-w C:\WINDOWS\system32\oobe\icserror\vcejlxkt.exe
+ 2007-12-02 22:41:58 121,856 ----a-w C:\WINDOWS\system32\oobe\icserror\vcejlxkt.exe
- 2007-11-25 13:57:15 77,312 ----a-w C:\WINDOWS\system32\oobe\isperror\hkenntsl.exe
+ 2007-12-02 22:41:59 121,856 ----a-w C:\WINDOWS\system32\oobe\isperror\hkenntsl.exe
- 2007-11-25 13:57:15 77,312 ----a-w C:\WINDOWS\system32\oobe\isperror\jjtrkbnj.exe
+ 2007-12-02 22:41:59 121,856 ----a-w C:\WINDOWS\system32\oobe\isperror\jjtrkbnj.exe
- 2007-11-25 13:57:15 77,312 ----a-w C:\WINDOWS\system32\oobe\isperror\knkbrnbn.exe
+ 2007-12-02 22:41:59 121,856 ----a-w C:\WINDOWS\system32\oobe\isperror\knkbrnbn.exe
- 2007-11-25 13:57:14 77,312 ----a-w C:\WINDOWS\system32\oobe\isperror\ktkbeknl.exe
+ 2007-12-02 22:41:59 121,856 ----a-w C:\WINDOWS\system32\oobe\isperror\ktkbeknl.exe
- 2007-11-25 13:57:14 77,312 ----a-w C:\WINDOWS\system32\oobe\isperror\rkeetqew.exe
+ 2007-12-02 22:41:58 121,856 ----a-w C:\WINDOWS\system32\oobe\isperror\rkeetqew.exe
- 2007-11-25 13:57:15 77,312 ----a-w C:\WINDOWS\system32\oobe\isperror\skqbvxsq.exe
+ 2007-12-02 22:41:59 121,856 ----a-w C:\WINDOWS\system32\oobe\isperror\skqbvxsq.exe
- 2007-11-25 13:57:15 77,312 ----a-w C:\WINDOWS\system32\oobe\isperror\tsjhshcj.exe
+ 2007-12-02 22:41:59 121,856 ----a-w C:\WINDOWS\system32\oobe\isperror\tsjhshcj.exe
- 2007-11-25 13:57:14 77,312 ----a-w C:\WINDOWS\system32\oobe\isperror\ztceskls.exe
+ 2007-12-02 22:41:59 121,856 ----a-w C:\WINDOWS\system32\oobe\isperror\ztceskls.exe
- 2007-11-25 13:57:15 77,312 ----a-w C:\WINDOWS\system32\oobe\krcxzncj.exe
+ 2007-12-02 22:42:00 121,856 ----a-w C:\WINDOWS\system32\oobe\krcxzncj.exe
- 2001-10-26 17:29:58 28,160 ----a-w C:\WINDOWS\system32\oobe\msoobe.exe
+ 2001-10-26 17:29:58 34,816 ----a-w C:\WINDOWS\system32\oobe\msoobe.exe
- 2007-11-25 13:57:10 77,312 ----a-w C:\WINDOWS\system32\oobe\qjeejeej.exe
+ 2007-12-02 22:41:53 121,856 ----a-w C:\WINDOWS\system32\oobe\qjeejeej.exe
- 2007-11-25 13:57:15 77,312 ----a-w C:\WINDOWS\system32\oobe\regerror\cetrjwtt.exe
+ 2007-12-02 22:42:00 121,856 ----a-w C:\WINDOWS\system32\oobe\regerror\cetrjwtt.exe
- 2007-11-25 13:57:15 77,312 ----a-w C:\WINDOWS\system32\oobe\regerror\ehxzeshx.exe
+ 2007-12-02 22:42:00 121,856 ----a-w C:\WINDOWS\system32\oobe\regerror\ehxzeshx.exe
- 2007-11-25 13:57:16 77,312 ----a-w C:\WINDOWS\system32\oobe\regerror\etnwxxnv.exe
+ 2007-12-02 22:42:00 121,856 ----a-w C:\WINDOWS\system32\oobe\regerror\etnwxxnv.exe
- 2007-11-25 13:57:16 77,312 ----a-w C:\WINDOWS\system32\oobe\regerror\kjtzrlbb.exe
+ 2007-12-02 22:42:00 121,856 ----a-w C:\WINDOWS\system32\oobe\regerror\kjtzrlbb.exe
- 2007-11-25 13:57:15 77,312 ----a-w C:\WINDOWS\system32\oobe\regerror\rcwnttzv.exe
+ 2007-12-02 22:42:00 121,856 ----a-w C:\WINDOWS\system32\oobe\regerror\rcwnttzv.exe
- 2007-11-25 13:57:16 77,312 ----a-w C:\WINDOWS\system32\oobe\regerror\wlkbbnrq.exe
+ 2007-12-02 22:42:00 121,856 ----a-w C:\WINDOWS\system32\oobe\regerror\wlkbbnrq.exe
- 2007-11-25 13:57:16 77,312 ----a-w C:\WINDOWS\system32\oobe\regerror\wtkkxrlr.exe
+ 2007-12-02 22:42:01 121,856 ----a-w C:\WINDOWS\system32\oobe\regerror\wtkkxrlr.exe
- 2007-11-25 13:57:16 77,312 ----a-w C:\WINDOWS\system32\oobe\regerror\xcjnkske.exe
+ 2007-12-02 22:42:00 121,856 ----a-w C:\WINDOWS\system32\oobe\regerror\xcjnkske.exe
- 2007-11-25 13:57:19 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\bknkjheh.exe
+ 2007-12-03 08:56:45 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\bknkjheh.exe
- 2007-11-25 13:57:19 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\bvqncler.exe
+ 2007-12-03 08:56:46 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\bvqncler.exe
- 2007-11-25 13:57:16 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\crjrhltv.exe
+ 2007-12-02 22:42:02 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\crjrhltv.exe
- 2007-11-25 13:57:18 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\enbsjwre.exe
+ 2007-12-03 08:56:44 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\enbsjwre.exe
- 2007-11-25 13:57:17 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\esjhxblq.exe
+ 2007-12-02 22:42:02 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\esjhxblq.exe
- 2007-11-25 13:57:19 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\eskcxkhr.exe
+ 2007-12-03 08:56:45 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\eskcxkhr.exe
- 2007-11-25 13:57:16 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\hlqstwxz.exe
+ 2007-12-02 22:42:01 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\hlqstwxz.exe
- 2007-11-25 13:57:17 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\hnhkkene.exe
+ 2007-12-03 08:56:43 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\hnhkkene.exe
- 2007-11-25 13:57:17 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\hwncrnhh.exe
+ 2007-12-03 08:56:43 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\hwncrnhh.exe
- 2007-11-25 13:57:19 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\hxckwnzl.exe
+ 2007-12-03 08:56:45 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\hxckwnzl.exe
- 2007-11-25 13:57:17 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\hxxttskn.exe
+ 2007-12-02 22:42:02 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\hxxttskn.exe
- 2007-11-25 13:57:18 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\jejrhnvh.exe
+ 2007-12-03 08:56:44 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\jejrhnvh.exe
- 2007-11-25 13:57:17 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\jtxsbxwn.exe
+ 2007-12-03 08:56:43 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\jtxsbxwn.exe
- 2007-11-25 13:57:17 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\kjqkxtnz.exe
+ 2007-12-02 22:42:02 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\kjqkxtnz.exe
- 2007-11-25 13:57:17 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\kksksesr.exe
+ 2007-12-02 22:42:02 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\kksksesr.exe
- 2007-11-25 13:57:16 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\knkhrczb.exe
+ 2007-12-02 22:42:01 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\knkhrczb.exe
- 2007-11-25 13:57:18 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\lhkhbjzl.exe
+ 2007-12-03 08:56:44 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\lhkhbjzl.exe
- 2007-11-25 13:57:19 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\lkjtrhks.exe
+ 2007-12-03 08:56:45 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\lkjtrhks.exe
- 2007-11-25 13:57:19 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\nkhlvlzt.exe
+ 2007-12-03 08:56:45 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\nkhlvlzt.exe
- 2007-11-25 13:57:17 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\nleevxqj.exe
+ 2007-12-02 22:42:03 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\nleevxqj.exe
- 2007-11-25 13:57:18 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\nstnnnkk.exe
+ 2007-12-03 08:56:44 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\nstnnnkk.exe
- 2007-11-25 13:57:18 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\ntwbjnxv.exe
+ 2007-12-03 08:56:44 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\ntwbjnxv.exe
- 2007-11-25 13:57:16 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\nvbbshss.exe
+ 2007-12-02 22:42:01 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\nvbbshss.exe
- 2007-11-25 13:57:19 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\nwqjkkhn.exe
+ 2007-12-03 08:56:45 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\nwqjkkhn.exe
- 2007-11-25 13:57:16 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\rresnsct.exe
+ 2007-12-02 22:42:01 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\rresnsct.exe
- 2007-11-25 13:57:18 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\rserkten.exe
+ 2007-12-03 08:56:43 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\rserkten.exe
- 2007-11-25 13:57:18 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\sejkhevn.exe
+ 2007-12-03 08:56:45 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\sejkhevn.exe
- 2007-11-25 13:57:18 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\seqtjbee.exe
+ 2007-12-03 08:56:44 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\seqtjbee.exe
- 2007-11-25 13:57:17 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\shbqjhcl.exe
+ 2007-12-03 08:56:43 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\shbqjhcl.exe
- 2007-11-25 13:57:17 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\tnqsbljb.exe
+ 2007-12-02 22:42:02 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\tnqsbljb.exe
- 2007-11-25 13:57:18 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\tqkbrhnx.exe
+ 2007-12-03 08:56:44 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\tqkbrhnx.exe
- 2007-11-25 13:57:17 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\tthzxntk.exe
+ 2007-12-02 16:37:00 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\tthzxntk.exe
- 2007-11-25 13:57:18 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\vjbssbhj.exe
+ 2007-12-03 08:56:44 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\vjbssbhj.exe
- 2007-11-25 13:57:17 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\vkckxhbn.exe
+ 2007-12-02 22:42:02 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\vkckxhbn.exe
- 2007-11-25 13:57:18 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\wnklretl.exe
+ 2007-12-03 08:56:44 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\wnklretl.exe
- 2007-11-25 13:57:18 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\wrbbnjss.exe
+ 2007-12-03 08:56:45 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\wrbbnjss.exe
- 2007-11-25 13:57:19 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\wtenslnj.exe
+ 2007-12-03 08:56:45 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\wtenslnj.exe
- 2007-11-25 13:57:18 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\zeblsxxw.exe
+ 2007-12-03 08:56:44 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\zeblsxxw.exe
- 2007-11-25 13:57:17 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\zhhrrltb.exe
+ 2007-12-02 22:42:02 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\zhhrrltb.exe
- 2007-11-25 13:57:19 77,312 ----a-w C:\WINDOWS\system32\oobe\setup\zhzsnhje.exe
+ 2007-12-03 08:56:45 121,856 ----a-w C:\WINDOWS\system32\oobe\setup\zhzsnhje.exe
- 2007-11-25 13:57:10 77,312 ----a-w C:\WINDOWS\system32\oobe\tttnwshl.exe
+ 2007-12-02 22:41:53 121,856 ----a-w C:\WINDOWS\system32\oobe\tttnwshl.exe
- 2001-10-26 17:30:00 219,648 ----a-w C:\WINDOWS\system32\osk.exe
+ 2001-10-26 17:30:00 212,992 ----a-w C:\WINDOWS\system32\osk.exe
- 2007-11-13 20:24:42 40,128 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2007-12-07 21:37:00 40,128 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2007-11-13 20:24:42 49,712 ----a-w C:\WINDOWS\system32\perfc015.dat
+ 2007-12-07 21:37:00 49,712 ----a-w C:\WINDOWS\system32\perfc015.dat
- 2007-11-13 20:24:42 311,740 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2007-12-07 21:37:00 311,740 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2007-11-13 20:24:42 355,830 ----a-w C:\WINDOWS\system32\perfh015.dat
+ 2007-12-07 21:37:00 355,830 ----a-w C:\WINDOWS\system32\perfh015.dat
- 2001-10-26 17:30:00 22,528 ----a-w C:\WINDOWS\system32\ping.exe
+ 2001-10-26 17:30:00 15,872 ----a-w C:\WINDOWS\system32\ping.exe
- 2001-10-26 17:30:00 214,016 ----a-w C:\WINDOWS\system32\progman.exe
+ 2001-10-26 17:30:00 207,360 ----a-w C:\WINDOWS\system32\progman.exe
- 2001-10-26 17:30:00 52,224 ----a-w C:\WINDOWS\system32\proquota.exe
+ 2001-10-26 17:30:00 45,568 ----a-w C:\WINDOWS\system32\proquota.exe
+ 2006-01-06 05:38:18 38,401 ----a-w C:\WINDOWS\system32\psme2.exe
+ 1999-04-25 22:48:20 21,167 ---ha-w C:\WINDOWS\system32\q8war.exe
- 2001-10-26 17:30:00 17,408 ----a-w C:\WINDOWS\system32\qappsrv.exe
+ 2001-10-26 17:30:00 24,064 ----a-w C:\WINDOWS\system32\qappsrv.exe
+ 2007-12-03 16:13:53 172,544 ----a-w C:\WINDOWS\system32\qe.exe
- 2001-10-26 17:30:00 40,960 ----a-w C:\WINDOWS\system32\rcimlby.exe
+ 2001-10-26 17:30:00 34,304 ----a-w C:\WINDOWS\system32\rcimlby.exe
- 2001-10-26 17:30:02 18,944 ----a-w C:\WINDOWS\system32\runonce.exe
+ 2001-10-26 17:30:02 12,288 ----a-w C:\WINDOWS\system32\runonce.exe
- 2007-11-30 16:37:03 392,704 ----a-w C:\WINDOWS\system32\secur.exe
+ 2007-12-02 13:59:46 392,704 ----a-w C:\WINDOWS\system32\secur.exe
+ 2007-12-02 13:26:12 30,720 ----a-w C:\WINDOWS\system32\setup_73483.exe
- 2001-10-26 17:30:02 21,504 ----a-w C:\WINDOWS\system32\shmgrate.exe
+ 2001-10-26 17:30:02 28,160 ----a-w C:\WINDOWS\system32\shmgrate.exe
- 2001-10-26 17:30:02 70,144 ----a-w C:\WINDOWS\system32\shrpubw.exe
+ 2001-10-26 17:30:02 76,800 ----a-w C:\WINDOWS\system32\shrpubw.exe
- 2001-10-26 17:30:02 18,944 ----a-w C:\WINDOWS\system32\shutdown.exe
+ 2001-10-26 17:30:02 25,600 ----a-w C:\WINDOWS\system32\shutdown.exe
+ 2006-05-13 04:19:44 24,492 ----a-w C:\WINDOWS\system32\sohid.com
+ 2007-04-06 08:11:00 21,167 ----a-w C:\WINDOWS\system32\Sonic.exe
+ 2007-04-06 08:17:38 1,777,664 ----a-w C:\WINDOWS\system32\Sonic22.exe
+ 2003-02-19 22:06:00 35,840 ----a-w C:\WINDOWS\system32\sostop.exe
+ 2007-11-17 16:55:50 16,646 ----a-w C:\WINDOWS\system32\Spex.sys
+ 2005-11-26 07:44:36 25,248 ----a-w C:\WINDOWS\system32\spn1k.dll
- 2007-11-16 14:09:39 6,277,261 ----a-w C:\WINDOWS\system32\spooIsv.exe
+ 2001-10-26 17:29:52 125,354 ---h--w C:\WINDOWS\system32\spooIsv.exe
- 2001-10-26 17:29:52 58,024 ---h--w C:\WINDOWS\system32\spoolsvc.exe
+ 2001-10-26 17:29:52 339,448 ---h--w C:\WINDOWS\system32\spoolsvc.exe
- 2007-11-29 11:27:31 1,185,328 ----a-w C:\WINDOWS\system32\Srb0ty.exe
+ 2007-12-04 09:52:53 1,859,584 ----a-w C:\WINDOWS\system32\Srb0ty.exe
+ 2003-11-15 20:15:30 1,777,664 ----a-w C:\WINDOWS\system32\Start.exe
- 2007-11-25 13:36:43 6,546,276 --sh--r C:\WINDOWS\system32\svshost.exe
+ 2007-12-02 13:42:58 6,546,276 --sh--r C:\WINDOWS\system32\svshost.exe
- 2001-10-26 16:29:46 70,144 ----a-w C:\WINDOWS\system32\usbui.dll
+ 2001-10-26 18:03:24 70,144 ----a-w C:\WINDOWS\system32\usbui.dll
- 2001-10-26 17:30:04 53,248 ----a-w C:\WINDOWS\system32\utilman.exe
+ 2001-10-26 17:30:04 46,592 ----a-w C:\WINDOWS\system32\utilman.exe
- 2001-10-26 17:29:52 58,024 ---h--w C:\WINDOWS\system32\winamp.exe
+ 2001-10-26 17:29:52 339,448 ---h--w C:\WINDOWS\system32\winamp.exe
- 2001-10-26 17:30:06 14,848 ----a-w C:\WINDOWS\system32\winhlp32.exe
+ 2001-10-26 17:30:06 8,192 ----a-w C:\WINDOWS\system32\winhlp32.exe
- 2001-10-26 17:30:06 34,816 ----a-w C:\WINDOWS\system32\xcopy.exe
+ 2001-10-26 17:30:06 28,160 ----a-w C:\WINDOWS\system32\xcopy.exe
+ 2006-05-11 04:03:04 23,490 ----a-w C:\WINDOWS\system32\xl4m3r.dll
+ 2007-04-22 13:21:20 6,636 ----a-w C:\WINDOWS\system32\xxx-spam.dll
+ 2006-07-08 19:08:02 5,185 ----a-w C:\WINDOWS\system32\xxxx-inviter.dll
+ 2006-05-12 19:08:46 21,882 ----a-w C:\WINDOWS\system32\ybn1e.dll
+ 2007-04-22 13:23:06 41,909 ----a-w C:\WINDOWS\system32\ybn2e.dll
+ 2007-04-22 13:23:36 29,359 ----a-w C:\WINDOWS\system32\ybn3e.dll
+ 2006-05-18 23:09:18 5,317 ----a-w C:\WINDOWS\system32\ybn4e.dll
- 2007-11-25 13:57:27 77,312 ----a-w C:\WINDOWS\Web\wcxnjhhj.exe
+ 2007-12-03 08:56:50 121,856 ----a-w C:\WINDOWS\Web\wcxnjhhj.exe
- 2001-10-26 17:30:06 275,456 ----a-w C:\WINDOWS\winhlp32.exe
+ 2001-10-26 17:30:06 268,800 ----a-w C:\WINDOWS\winhlp32.exe
+ 2001-08-18 06:37:18 921,088 ----a-w C:\WINDOWS\WinSxS\InstallTemp\48320\comctl32.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2007-07-09 08:39]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe" [2002-05-03 10:06 C:\WINDOWS\system32\nwiz.exe]
"a-winpoet-service"="C:\Program Files\DialNet\winpppoverethernet.exe" [2007-01-18 10:26]
"z-wrdialer"="C:\Program Files\DialNet\wrdialer.exe" [2007-01-18 13:18]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" []
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41]
"SoundMan"="SOUNDMAN.EXE" [2002-06-14 10:21 C:\WINDOWS\SOUNDMAN.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2001-10-26 18:29]
"HOT FIX"="Gothic.exe" [2007-12-06 18:09 C:\WINDOWS\system32\Gothic.exe]
"WMI Standard Event Consumer - Scripting"="C:\WINDOWS\System32\wbem\scrcons32.exe" [2007-11-12 20:04]
"Microsoft Winedows rpdate"="kegpzv.exe" []
"MicroSoft ssadsadas3s1"="eXtream.exe" [2007-12-01 15:34 C:\WINDOWS\system32\eXtream.exe]
"MicroSoft Legal Service"="Srb0ty.exe" [2007-12-04 10:52 C:\WINDOWS\system32\Srb0ty.exe]
"Auto File System Conversion Utility"="C:\WINDOWS\System32\wbem\scricon.exe" [2001-10-26 18:29]
"syswin.txt"="jjv.exe" [2001-10-26 18:29 C:\WINDOWS\system32\jjv.exe]
"WMI Standard Event Consumer - hosting"="C:\WINDOWS\System32\wbem\scrcs.exe" []
"Windows Secure Update"="load.exe" [2007-12-03 16:11 C:\WINDOWS\system32\load.exe]
"Windows LoL Layer"="osqywtb.exe" []
"MicroSoft Legal Syst3m32"="Syst3m32.exe" [2007-12-03 17:29 C:\WINDOWS\system32\Syst3m32.exe]
"MicroSoft ssas3s1"="SADASDA.exe" [2007-12-05 21:45 C:\WINDOWS\system32\SADASDA.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"HOT FIX"="Gothic.exe" [2007-12-06 18:09 C:\WINDOWS\system32\Gothic.exe]
"MicroSoft ssadsadas3s1"="eXtream.exe" [2007-12-01 15:34 C:\WINDOWS\system32\eXtream.exe]
"MicroSoft Legal Service"="Srb0ty.exe" [2007-12-04 10:52 C:\WINDOWS\system32\Srb0ty.exe]
"tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [2001-10-26 18:30]
"Windows Secure Update"="load.exe" [2007-12-03 16:11 C:\WINDOWS\system32\load.exe]
"MicroSoft Legal Syst3m32"="Syst3m32.exe" [2007-12-03 17:29 C:\WINDOWS\system32\Syst3m32.exe]
"MicroSoft ssas3s1"="SADASDA.exe" [2007-12-05 21:45 C:\WINDOWS\system32\SADASDA.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunServices]
"WMI Standard Event Consumer - Scripting"="C:\WINDOWS\System32\wbem\scrcons32.exe" [2007-11-12 20:04]
"Auto File System Conversion Utility"="C:\WINDOWS\System32\wbem\scricon.exe" [2001-10-26 18:29]
"WMI Standard Event Consumer - hosting"="C:\WINDOWS\System32\wbem\scrcs.exe" []
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"WMI Standard Event Consumer - Scripting"= C:\WINDOWS\System32\wbem\scrcons32.exe
"WMI Standard Event Consumer - hosting"= C:\WINDOWS\System32\wbem\scrcs.exe