Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Outlook 2007 sending spam, kaspersky self defense reporting violations


  • This topic is locked This topic is locked
13 replies to this topic

#1 luap64

luap64

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:03:13 AM

Posted 07 October 2008 - 03:41 PM

I think I've got the same malware running on two systems one XP SP3 and one Vista x64 SP1.
On the XP system Kaspersky seems to be winning as I'm not seeing any SPAM being sent, but do get the following log entries from Kaspersky Self defense

AT PC STARTUP

07/10/2008 20:36:00 Denied Kaspersky Internet Security Modification REGISTRY\MACHINE\SOFTWARE\KasperskyLab\protected\AVP8\Trace\Default
07/10/2008 20:36:00 Denied Kaspersky Internet Security Modification REGISTRY\MACHINE\SOFTWARE\KasperskyLab\protected\AVP8\Trace\Default
07/10/2008 20:36:00 Denied Kaspersky Internet Security Modification REGISTRY\MACHINE\SOFTWARE\KasperskyLab\protected\AVP8\Trace\Default
07/10/2008 20:36:00 Denied Kaspersky Internet Security Modification REGISTRY\MACHINE\SOFTWARE\KasperskyLab\protected\AVP8\Trace\Default
07/10/2008 20:36:00 Denied Kaspersky Internet Security Modification REGISTRY\MACHINE\SOFTWARE\KasperskyLab\protected\AVP8\Trace\Default
07/10/2008 20:36:00 Denied Kaspersky Internet Security Modification REGISTRY\MACHINE\SOFTWARE\KasperskyLab\protected\AVP8\Trace\Default
07/10/2008 20:36:00 Denied Kaspersky Internet Security Modification REGISTRY\MACHINE\SOFTWARE\KasperskyLab\protected\AVP8\Trace\Default
07/10/2008 20:36:00 Denied Kaspersky Internet Security Modification REGISTRY\MACHINE\SOFTWARE\KasperskyLab\protected\AVP8\Trace\Default
07/10/2008 20:36:01 Denied Kaspersky Internet Security Modification REGISTRY\MACHINE\SOFTWARE\KasperskyLab\protected\AVP8\Trace\Default
07/10/2008 20:36:01 Denied Kaspersky Internet Security Modification REGISTRY\MACHINE\SOFTWARE\KasperskyLab\protected\AVP8\Trace\Default

AT OUTLOOK STARTUP
07/10/2008 21:03:30 Denied Microsoft Office Outlook Modification Device\HarddiskVolume1\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\antispam.sfdb


On the VISTA machine I see attempts to send emails, different subjects and to different unknown recipients, think this is down to me foolishly disabling protection when I thought the problem was due to having two copies of the K antispam toolbar installed in outlook

Sounds very much like same problem as previous poster CoachMcGuirk

have done full scan with Kaspersky and Sunbelt Vipre nothing found

HJT log attached



I've XXX'd some data that is sensitive

Will try and post equivalent data from other machine

Attached Files


Edited by luap64, 08 October 2008 - 03:26 PM.


BC AdBot (Login to Remove)

 


m

#2 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,301 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:07:13 PM

Posted 15 October 2008 - 10:59 PM

:thumbsup: to BleepingComputer.com

I want to apologise that it has taken so long to get back to you. We on the HJT Team are working as fast as possible to get your log answered.

If you do not still need help, please let me know, so that I can move on to other users who still need help.

Please take note of the following:
  • While a HJT Team member is working with you, please refrain from making any changes to your computer.
  • Also, even if things appear to be running better, there is no guarantee that everything is finished. Please continue to check this forum post in order to ensure we get your system completely clean. We do not want to clean you part-way up, only to have the system re-infect itself. :)
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
  • Please reply using the Posted Image button in the lower left hand corner of your screen.
  • Old topics are closed after 3 days with no reply, and working topics are closed after 5 days. If for any reason you cannot complete instructions within that time, that's fine, just put a post here so that I know you're still here. We get a lot of people who simply leave, and if there is no contact for that amount of time I will have to assume you have "vanished" :).
If you would still like help, please follow the instructions below:

We need to create an OTViewIt Report
  • Please download OTViewIt by OldTimer.
  • Save it to your desktop.
  • Double click on the Posted Image icon on your desktop.
  • Click the "Scan All Users" checkbox.
  • Push the Posted Image button.
  • Two reports will open, copy and paste them in a reply here:
  • OTViewIt.txt <-- Will be opened
  • Extra.txt <-- Will be minimized
Please do an online scan with Kaspersky WebScanner.
  • Please visit the Kaspersky Online Scanner website.
    Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.
  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
In your next reply, please include the following:
  • OTViewIt.txt
  • Extra.txt
  • Kaspersky's Log

Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#3 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,301 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:07:13 PM

Posted 18 October 2008 - 08:37 PM

Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please send me or another moderator a PM.

Everyone else please begin a new topic.
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#4 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,301 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:07:13 PM

Posted 19 October 2008 - 08:27 PM

Topic reopened. Your logs were cut off in PM, so please post them here :D

Billy3

Edited by Billy O'Neal, 19 October 2008 - 08:28 PM.

Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#5 luap64

luap64
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:03:13 AM

Posted 20 October 2008 - 05:19 AM

Kaspersky online report

, October 19, 2008
Operating System: Microsoft Windows Vista Ultimate Edition, 64-bit Service Pack 1 (build 6001)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Sunday, October 19, 2008 09:17:39
Records in database: 1322947


Scan settings
Scan using the following database extended
Scan archives yes
Scan mail databases yes

Scan area My Computer
A:\
C:\
D:\
E:\
F:\
O:\
P:\
R:\
S:\

Scan statistics
Files scanned 218224
Threat name 5
Infected objects 4
Suspicious objects 3
Duration of the scan 08:22:29

File name Threat name Threats count
C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst Infected: Trojan.Win32.Buzus.vwi 1

C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst Infected: Trojan-Downloader.Win32.Agent.aeza 1

C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst Infected: Trojan-Downloader.Win32.Agent.aevg 1

C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst Suspicious: Trojan-Spy.HTML.Fraud.gen 3

O:\Documents and Settings\XXXX\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Infected: Exploit.Win32.PDF-URI.l 1

The selected area was scanned.


Kaspersky Installed report

Quick Scan: completed 12/10/2008 19:56:49 (events: 95, objects: , time: 00:00:00)
19/10/2008 00:24:51 Task started
19/10/2008 00:28:23 Detected: http://www.viruslist.com/en/advisories/20845 O:\Program Files\Common Files\InterVideo\DVD7\InterActual\bin\pcfpatch
19/10/2008 00:28:25 Detected: http://www.viruslist.com/en/advisories/20845 O:\Program Files\InterActual\InterActual Player\IAResDE.dll
19/10/2008 00:28:25 Detected: http://www.viruslist.com/en/advisories/20845 O:\Program Files\InterActual\InterActual Player\IAResEn.dll
19/10/2008 00:28:25 Detected: http://www.viruslist.com/en/advisories/20845 O:\Program Files\InterActual\InterActual Player\IAResES.dll
19/10/2008 00:28:25 Detected: http://www.viruslist.com/en/advisories/20845 O:\Program Files\InterActual\InterActual Player\IAResFR.dll
19/10/2008 00:28:25 Detected: http://www.viruslist.com/en/advisories/20845 O:\Program Files\InterActual\InterActual Player\IAResIT.dll
19/10/2008 00:28:25 Detected: http://www.viruslist.com/en/advisories/20845 O:\Program Files\InterActual\InterActual Player\IAResJP.dll
19/10/2008 00:28:25 Detected: http://www.viruslist.com/en/advisories/20845 O:\Program Files\InterActual\InterActual Player\bin\IAMime.dll
19/10/2008 00:28:25 Detected: http://www.viruslist.com/en/advisories/20845 O:\Program Files\InterActual\InterActual Player\IAResRU.dll
19/10/2008 00:28:26 Detected: http://www.viruslist.com/en/advisories/20845 O:\Program Files\InterActual\InterActual Player\bin\pcfpatch
19/10/2008 00:28:41 Task completed
Quick Scan: completed 12/10/2008 19:56:49 (events: 95, objects: , time: 00:00:00)
19/10/2008 19:36:55 Task started
19/10/2008 19:39:15 Task completed
Quick Scan: completed 12/10/2008 19:56:49 (events: 95, objects: , time: 00:00:00)
19/10/2008 20:56:49 Task completed
19/10/2008 20:33:26 Task started
Quick Scan: completed 12/10/2008 19:56:49 (events: 95, objects: , time: 00:00:00)
19/10/2008 21:09:21 Task started
19/10/2008 21:21:28 Detected: Trojan.Win32.Buzus.vwi C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\[Google Mail]\All Mail\[From:dcy][Subject:YouTube.com: Makes your day.][Time:8859/01/01 00:00:00]/youtube.rar/YouTube.com.jHsbIqkd.avi.exe
19/10/2008 21:21:28 Untreated: Trojan.Win32.Buzus.vwi C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\[Google Mail]\All Mail\[From:dcy][Subject:YouTube.com: Makes your day.][Time:8859/01/01 00:00:00]/youtube.rar/YouTube.com.jHsbIqkd.avi.exe Postponed
19/10/2008 21:21:29 Detected: Trojan-Downloader.Win32.Agent.aeza C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\[Google Mail]\All Mail\[From:None][Subject:CNN: Mad elephant killed school teacher!][Time:2008/09/29 20:09:18]/Video.rar/My.YouTube.Movie.avi.exe
19/10/2008 21:21:29 Untreated: Trojan-Downloader.Win32.Agent.aeza C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\[Google Mail]\All Mail\[From:None][Subject:CNN: Mad elephant killed school teacher!][Time:2008/09/29 20:09:18]/Video.rar/My.YouTube.Movie.avi.exe Postponed
19/10/2008 21:21:41 Detected: Backdoor.Win32.Hijack.e C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\[Google Mail]\All Mail\[From:ufn][Subject:Funbags][Time:8859/01/01 00:00:00]/movie.rar/movie.avi.exe
19/10/2008 21:21:42 Untreated: Backdoor.Win32.Hijack.e C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\[Google Mail]\All Mail\[From:ufn][Subject:Funbags][Time:8859/01/01 00:00:00]/movie.rar/movie.avi.exe Postponed
19/10/2008 21:25:55 Detected: Trojan-Spy.HTML.Fraud.gen C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\[Google Mail]\All Mail\[From:Fulton Bank CashLink][Subject:Fulton Bank Business Online Banking Important Notice REF: 9575][Time:2008/09/17 03:31:49]/HTMLBody
19/10/2008 21:25:55 Untreated: Trojan-Spy.HTML.Fraud.gen C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\[Google Mail]\All Mail\[From:Fulton Bank CashLink][Subject:Fulton Bank Business Online Banking Important Notice REF: 9575][Time:2008/09/17 03:31:49]/HTMLBody Postponed
19/10/2008 21:26:00 Detected: Trojan-Spy.HTML.Fraud.gen C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\[Google Mail]\All Mail\[From:Fulton Bank CashLink][Subject:Fulton Bank CashLink: Update Your Identity][Time:2008/09/16 02:17:50]/HTMLBody
19/10/2008 21:26:00 Untreated: Trojan-Spy.HTML.Fraud.gen C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\[Google Mail]\All Mail\[From:Fulton Bank CashLink][Subject:Fulton Bank CashLink: Update Your Identity][Time:2008/09/16 02:17:50]/HTMLBody Postponed
19/10/2008 21:26:27 Detected: Trojan-Spy.HTML.Fraud.gen C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\[Google Mail]\All Mail\[From:NatWest Bank Internet Banking][Subject:Natwest OnLine Banking Online Banking Service - User's Data Authorization][Time:2008/10/10 13:17:38]/HTMLBody
19/10/2008 21:26:27 Untreated: Trojan-Spy.HTML.Fraud.gen C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\[Google Mail]\All Mail\[From:NatWest Bank Internet Banking][Subject:Natwest OnLine Banking Online Banking Service - User's Data Authorization][Time:2008/10/10 13:17:38]/HTMLBody Postponed
19/10/2008 21:30:44 Detected: Trojan-Spy.HTML.Fraud.gen C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\Junk E-mail\[From:Fulton Bank CashLink][Subject:Fulton Bank Business Online Banking Important Notice REF: 9575][Time:2008/09/17 03:31:49]/HTMLBody
19/10/2008 21:30:44 Untreated: Trojan-Spy.HTML.Fraud.gen C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\Junk E-mail\[From:Fulton Bank CashLink][Subject:Fulton Bank Business Online Banking Important Notice REF: 9575][Time:2008/09/17 03:31:49]/HTMLBody Postponed
19/10/2008 21:30:49 Detected: Trojan-Spy.HTML.Fraud.gen C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\Junk E-mail\[From:Fulton Bank CashLink][Subject:Fulton Bank CashLink: Update Your Identity][Time:2008/09/16 02:17:50]/HTMLBody
19/10/2008 21:30:49 Untreated: Trojan-Spy.HTML.Fraud.gen C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\Junk E-mail\[From:Fulton Bank CashLink][Subject:Fulton Bank CashLink: Update Your Identity][Time:2008/09/16 02:17:50]/HTMLBody Postponed
19/10/2008 21:30:57 Detected: Trojan-Spy.HTML.Fraud.gen C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\Junk E-mail\[From:NatWest Bank Internet Banking][Subject:Natwest OnLine Banking Online Banking Service - User's Data Authorization][Time:2008/10/10 13:17:38]/HTMLBody
19/10/2008 21:30:57 Untreated: Trojan-Spy.HTML.Fraud.gen C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\Junk E-mail\[From:NatWest Bank Internet Banking][Subject:Natwest OnLine Banking Online Banking Service - User's Data Authorization][Time:2008/10/10 13:17:38]/HTMLBody Postponed
19/10/2008 21:39:34 Untreated C:\Users\XXXX\AppData\Local\Microsoft\Outlook\Outlook.pst Write error
19/10/2008 21:39:34 Untreated C:\Users\XXXX\AppData\Local\Microsoft\Outlook\Outlook.pst Postponed


Bounceback message

This is an automatically generated Delivery Status Notification

Delivery to the following recipient failed permanently:

veronique-amognub@mccormicksys.com

Technical details of permanent failure:
Google tried to deliver your message, but it was rejected by the recipient domain. We recommend contacting the other email provider for further information about the cause of this error. The error that the other server returned was: 550 550 5.1.1 User unknown (state 14).

----- Original message -----

Received: by 10.210.124.8 with SMTP id w8mr554017ebc.164.1224371242430;
Sat, 18 Oct 2008 16:07:22 -0700 (PDT)
Return-Path: <XXXX.XXXXXXXXX@googlemail.com>
Received: from XXXXPC (5aca275c.bb.sky.com [90.202.39.92])
by mx.google.com with ESMTPS id m5sm11481648gve.3.2008.10.18.16.07.20
(version=SSLv3 cipher=RC4-MD5);
Sat, 18 Oct 2008 16:07:21 -0700 (PDT)
From: "XXXX XXXXXXXXX" <XXXX@XXXXXXXXX.com>
To: <veronique-amognub@mccormicksys.com>
Subject: Not read: We have everything to make your love more passionate.
Date: Sun, 19 Oct 2008 00:06:50 +0100
Message-ID: <000301c93176$385dc0a0$a91941e0$@com>
MIME-Version: 1.0
Content-Type: application/ms-tnef;
name="winmail.dat"
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
filename="winmail.dat"
X-Mailer: Microsoft Office Outlook 12.0
Thread-Index: AckgqJmUFVcTAv/HTw2AC0JwQy6NSgQzVFqX
X-MS-TNEF-Correlator: 0000000009B39394B432F146A1BD61CF380338A964754900
Sender: XXXX XXXXXXXXX <XXXX.XXXXXXXXX@googlemail.com>

eJ8+IjkXAQaQCAAEAAAAAAABAAEAAQeQBgAIAAAA5AQAAAAAAADoAAEIgAcAFwAAAFJFUE9SVC5J
UE0uTm90ZS5JUE5OUk4AtwYBCoABACEAAABFMzMyNkFCNEEwNzY0RTQ5QTI4MjkxQTZBRDZDNzlB
NwAyBwEDkAYAtAIAABgAAAALACkAAAAAAEAAMgCwxv7qdTHJAR4ASQABAAAANgAAAFdlIGhhdmUg
ZXZlcnl0aGluZyB0byBtYWtlIHlvdXIgbG92ZSBtb3JlIHBhc3Npb25hdGUuAAAAAgFMAAEAAAB8
AAAAAAAAAIErH6S+oxAZnW4A3QEPVAIAAAGAdgBlAHIAbwBuAGkAcQB1AGUAAABTAE0AVABQAAAA
dgBlAHIAbwBuAGkAcQB1AGUALQBhAG0AbwBnAG4AdQBiAEAAbQBjAGMAbwByAG0AaQBjAGsAcwB5
AHMALgBjAG8AbQAAAB4ATQABAAAACgAAAHZlcm9uaXF1ZQAAAEAATgAAjfldqCDJAUAAVQAAV5SZ
qCDJAR4AcAABAAAANgAAAFdlIGhhdmUgZXZlcnl0aGluZyB0byBtYWtlIHlvdXIgbG92ZSBtb3Jl
IHBhc3Npb25hdGUuAAAAAgFxAAEAAAAbAAAAAckgqJmUFVcTAv/HTw2AC0JwQy6NSgQzVFqXAB4A
cgABAAAAAQAAAAAAAAAeAHMAAQAAAAEAAAAAAAAAHgB0AAEAAAATAAAAcGF1bEBzd2FyYnJvb2su

----- Message truncated -----

#6 luap64

luap64
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:03:13 AM

Posted 20 October 2008 - 05:58 AM

OTVIEWIT reports (note these are not the originals, after Kaspersky has had a go at fixing)

OTViewIt logfile created on: 20/10/2008 11:29:55 - Run 2
OTViewIt by OldTimer - Version 1.0.17.0 Folder = C:\Users\XXXX\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z78DA7PF
Windows Vista An unknown product Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

4.00 Gb Total Physical Memory | 3.05 Gb Available Physical Memory | 76.35% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys;

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 127.99 Gb Total Space | 67.74 Gb Free Space | 52.92% Space Free | Partition Type: NTFS
Drive D: | 337.77 Gb Total Space | 283.96 Gb Free Space | 84.07% Space Free | Partition Type: NTFS
Drive E: | 465.75 Gb Total Space | 110.77 Gb Free Space | 23.78% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive O: | 24.00 Gb Total Space | 1.20 Gb Free Space | 5.01% Space Free | Partition Type: NTFS
Drive P: | 52.68 Gb Total Space | 0.02 Gb Free Space | 0.04% Space Free | Partition Type: NTFS
Drive S: | 76.69 Gb Total Space | 2.51 Gb Free Space | 3.27% Space Free | Partition Type: NTFS

Computer Name: XXXX-PC
Current User Name: XXXX
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days

========== Processes ==========

[2008/07/29 20:20:28 | 00,206,088 | ---- | M] (Kaspersky Lab) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
[2006/09/19 09:07:28 | 00,827,392 | ---- | M] () -- C:\Windows\vsnpstd3.exe
[2007/10/18 11:34:02 | 05,724,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
[2008/10/16 20:04:28 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Users\XXXX\AppData\Local\Google\Update\GoogleUpdate.exe
[2008/07/29 20:20:28 | 00,206,088 | ---- | M] (Kaspersky Lab) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
[2008/10/16 20:24:01 | 00,144,792 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Java\jre6\bin\jusched.exe
[2007/10/18 11:31:54 | 00,098,328 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Live\Messenger\usnsvc.exe
[2008/07/29 20:20:28 | 00,206,088 | ---- | M] (Kaspersky Lab) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
[2008/01/19 08:33:12 | 00,299,520 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Internet Explorer\ieuser.exe
[2008/01/19 08:33:12 | 00,625,664 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2007/09/20 10:35:36 | 00,118,336 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLLoginProxy.exe
[2008/01/19 08:33:12 | 00,625,664 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2007/09/20 10:35:36 | 00,118,336 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLLoginProxy.exe
[2008/10/20 11:29:43 | 00,421,888 | ---- | M] (OldTimer Tools) -- C:\Users\XXXX\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z78DA7PF\OTViewIt[1].exe

========== (O23) Win32 Services ==========

File not found -- -- (Ati External Event Utility [Auto | Running])
[2008/07/29 20:20:28 | 00,206,088 | ---- | M] (Kaspersky Lab) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe -- (AVP [Auto | Running])
File not found -- -- (CertPropSvc [Unknown | Running])
[2008/01/05 12:26:41 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
[2008/01/05 12:25:45 | 00,093,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_64 [On_Demand | Stopped])
File not found -- -- (DcomLaunch [Unknown | Running])
File not found -- -- (DPS [Unknown | Running])
[2008/01/19 09:00:14 | 00,344,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehrecvr.exe -- (ehRecvr [On_Demand | Stopped])
[2008/01/19 09:00:14 | 00,153,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehsched.exe -- (ehSched [On_Demand | Stopped])
[2008/01/05 12:23:12 | 00,036,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
[2006/11/02 10:46:05 | 00,018,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\keyiso.dll -- (KeyIso [On_Demand | Stopped])
[2007/08/24 06:59:20 | 00,068,464 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service [On_Demand | Stopped])
[2006/11/02 14:34:14 | 00,000,000 | ---D | M] -- C:\Windows\System32\Msdtc -- (MSDTC [Unknown | Stopped])
[2008/01/19 08:35:36 | 00,592,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\netlogon.dll -- (Netlogon [On_Demand | Stopped])
[2008/01/05 12:23:05 | 00,122,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
[2007/08/24 03:19:12 | 00,443,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
[2006/10/26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
[2008/01/19 08:33:19 | 00,019,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\perfhost.exe -- (PerfHost [On_Demand | Stopped])
File not found -- -- (RpcSs [Unknown | Running])
[2008/01/19 08:36:19 | 00,095,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SCardSvr.dll -- (SCardSvr [Unknown | Stopped])
File not found -- -- (Schedule [Unknown | Running])
File not found -- -- (SCPolicySvc [Unknown | Stopped])
[2007/10/18 11:31:54 | 00,098,328 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Live\Messenger\usnsvc.exe -- (usnjsvc [On_Demand | Running])
[2006/11/02 07:35:15 | 00,060,994 | ---- | M] () -- C:\Windows\System32\wbem\vds.mof -- (vds [On_Demand | Stopped])
[2006/11/02 07:35:15 | 00,055,846 | ---- | M] () -- C:\Windows\System32\wbem\vss.mof -- (VSS [On_Demand | Stopped])
File not found -- -- (WdiServiceHost [Unknown | Stopped])
File not found -- -- (WdiSystemHost [Unknown | Running])
[2007/10/25 15:27:54 | 00,266,240 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Live\installer\WLSetupSvc.exe -- (WLSetupSvc [On_Demand | Stopped])
[2008/01/19 09:00:47 | 01,216,000 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
[2008/05/27 06:18:43 | 00,439,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SearchIndexer.exe -- (WSearch [Auto | Running])

========== Driver Services ==========

[2008/01/19 09:12:01 | 00,486,456 | ---- | M] (Adaptec, Inc.) -- C:\Windows\WinSxS\amd64_adp94xx.inf_31bf3856ad364e35_6.0.6001.18000_none_5e0fcb9b69814f7b\adp94xx.sys -- (adp94xx [Disabled | Stopped])
[2008/01/19 09:11:40 | 00,342,584 | ---- | M] (Adaptec, Inc.) -- C:\Windows\WinSxS\amd64_adpahci.inf_31bf3856ad364e35_6.0.6001.18000_none_c05c13aa3dfbc961\adpahci.sys -- (adpahci [Disabled | Stopped])
[2008/01/19 09:10:01 | 00,126,520 | ---- | M] (Adaptec, Inc.) -- C:\Windows\WinSxS\amd64_adpu160m.inf_31bf3856ad364e35_6.0.6001.18000_none_f2feed0b63bf261d\adpu160m.sys -- (adpu160m [Disabled | Stopped])
[2008/01/19 09:11:12 | 00,185,912 | ---- | M] (Adaptec, Inc.) -- C:\Windows\WinSxS\amd64_adpu320.inf_31bf3856ad364e35_6.0.6001.18000_none_f4cbbad1148c6b4a\adpu320.sys -- (adpu320 [Disabled | Stopped])
[2008/10/12 18:32:52 | 00,018,488 | ---- | M] (Acer Laboratories Inc.) -- C:\Windows\WinSxS\amd64_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_375215c7dcd73562\aliide.sys -- (aliide [Disabled | Stopped])
[2008/01/19 09:09:34 | 00,090,680 | ---- | M] (Adaptec, Inc.) -- C:\Windows\WinSxS\amd64_arc.inf_31bf3856ad364e35_6.0.6001.18000_none_7bfed8c7803713cf\arc.sys -- (arc [Disabled | Stopped])
[2008/01/19 09:09:37 | 00,091,192 | ---- | M] (Adaptec, Inc.) -- C:\Windows\WinSxS\amd64_arcsas.inf_31bf3856ad364e35_6.0.6001.18000_none_771684264153c2d4\arcsas.sys -- (arcsas [Disabled | Stopped])
File not found -- -- (atikmdag [On_Demand | Running])
[2006/09/18 22:30:15 | 00,018,432 | ---- | M] (Brother Industries, Ltd.) -- C:\Windows\WinSxS\amd64_brmfcsto.inf_31bf3856ad364e35_6.0.6001.18000_none_800ff95700142785\BrFiltLo.sys -- (BrFiltLo [On_Demand | Stopped])
[2006/09/18 22:30:15 | 00,008,704 | ---- | M] (Brother Industries, Ltd.) -- C:\Windows\WinSxS\amd64_brmfcsto.inf_31bf3856ad364e35_6.0.6001.18000_none_800ff95700142785\BrFiltUp.sys -- (BrFiltUp [On_Demand | Stopped])
[2008/10/12 18:32:52 | 00,020,536 | ---- | M] (CMD Technology, Inc.) -- C:\Windows\WinSxS\amd64_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_375215c7dcd73562\cmdide.sys -- (cmdide [Disabled | Stopped])
[2008/10/12 17:58:50 | 00,000,000 | ---D | M] -- C:\Windows\CSC -- (CSC [System | Running])
[2008/01/05 12:22:47 | 00,146,176 | ---- | M] (Intel Corporation) -- C:\Windows\WinSxS\amd64_nete1g3e.inf_31bf3856ad364e35_6.0.6001.18000_none_04b0c96be9c034d3\E1G6032E.sys -- (E1G60 [On_Demand | Stopped])
[2008/01/19 09:11:53 | 00,397,368 | ---- | M] (Emulex) -- C:\Windows\WinSxS\amd64_elxstor.inf_31bf3856ad364e35_6.0.6001.18000_none_08ac13ff69b034ee\elxstor.sys -- (elxstor [Disabled | Stopped])
File not found -- -- (HdAudAddService [On_Demand | Running])
[2008/01/19 09:08:42 | 00,047,672 | ---- | M] (Hewlett-Packard Company) -- C:\Windows\WinSxS\amd64_hpcisss.inf_31bf3856ad364e35_6.0.6001.18000_none_d59c6600292b9522\HpCISSs.sys -- (HpCISSs [Disabled | Stopped])
[2008/01/19 09:11:31 | 00,290,872 | ---- | M] (Intel Corporation) -- C:\Windows\WinSxS\amd64_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_0b2fedfc40256bc5\iaStorV.sys -- (iaStorV [Disabled | Stopped])
File not found -- -- (kl1 [System | Running])
File not found -- -- (KLBG [Boot | Running])
File not found -- -- (KLFLTDEV [On_Demand | Running])
File not found -- -- (KLIF [System | Running])
File not found -- -- (KLIM6 [System | Running])
[2008/01/19 09:09:57 | 00,113,720 | ---- | M] (LSI Logic) -- C:\Windows\WinSxS\amd64_lsi_fc.inf_31bf3856ad364e35_6.0.6001.18000_none_c59b4ac1fa719137\lsi_fc.sys -- (LSI_FC [Disabled | Stopped])
[2008/01/19 09:09:48 | 00,105,016 | ---- | M] (LSI Logic) -- C:\Windows\WinSxS\amd64_lsi_sas.inf_31bf3856ad364e35_6.0.6001.18000_none_5b86b7f9e8ff0dc5\lsi_sas.sys -- (LSI_SAS [Disabled | Stopped])
[2008/01/19 09:09:56 | 00,113,720 | ---- | M] (LSI Logic) -- C:\Windows\WinSxS\amd64_lsi_scsi.inf_31bf3856ad364e35_6.0.6001.18000_none_f883c787da42af0c\lsi_scsi.sys -- (LSI_SCSI [Disabled | Stopped])
[2008/01/19 09:08:18 | 00,035,896 | ---- | M] (LSI Corporation) -- C:\Windows\WinSxS\amd64_megasas.inf_31bf3856ad364e35_6.0.6001.18000_none_8c5ef0c0070fb814\megasas.sys -- (megasas [Disabled | Stopped])
[2008/10/12 18:54:06 | 00,001,088 | ---- | M] () -- C:\Windows\System32\wbem\mpsdrv.mof -- (mpsdrv [On_Demand | Running])
[2008/01/19 09:10:12 | 00,128,056 | ---- | M] (NVIDIA Corporation) -- C:\Windows\WinSxS\amd64_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_95f95eab775c159d\nvraid.sys -- (nvraid [Disabled | Stopped])
[2008/01/19 09:08:50 | 00,054,328 | ---- | M] (NVIDIA Corporation) -- C:\Windows\WinSxS\amd64_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_95f95eab775c159d\nvstor.sys -- (nvstor [Disabled | Stopped])
[2008/01/19 09:12:10 | 01,221,176 | ---- | M] (QLogic Corporation) -- C:\Windows\WinSxS\amd64_ql2300.inf_31bf3856ad364e35_6.0.6001.18000_none_90b29e0f5eb4b0a1\ql2300.sys -- (ql2300 [Disabled | Stopped])
File not found -- -- (RTL8169 [On_Demand | Running])
[2006/09/30 00:51:44 | 00,023,040 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\Windows\WinSxS\amd64_macrovision-protection-safedisc_31bf3856ad364e35_6.0.6000.16386_none_b794b0d578b7ec2e\secdrv.sys -- (secdrv [Auto | Running])
[2008/01/19 09:09:28 | 00,078,392 | ---- | M] (Silicon Integrated Systems) -- C:\Windows\WinSxS\amd64_sisraid4.inf_31bf3856ad364e35_6.0.6001.18000_none_8460e59f708bb476\sisraid4.sys -- (SiSRaid4 [Disabled | Stopped])
[2004/02/27 16:36:18 | 00,015,498 | ---- | M] () -- C:\Windows\snpstd3.ini -- (SNPSTD3 [On_Demand | Running])
[2006/09/18 22:36:40 | 00,003,066 | ---- | M] () -- C:\Windows\System32\wbem\tcpip.mof -- (Tcpip [Boot | Running])
[2008/01/19 09:11:28 | 00,284,728 | ---- | M] (ULi Electronics Inc.) -- C:\Windows\WinSxS\amd64_uliahci.inf_31bf3856ad364e35_6.0.6001.18000_none_a21b1cbb80e47096\uliahci.sys -- (uliahci [Disabled | Stopped])
[2006/11/02 12:51:19 | 00,174,696 | ---- | M] (Promise Technology, Inc.) -- C:\Windows\WinSxS\amd64_ulsata2.inf_31bf3856ad364e35_6.0.6001.18000_none_9ce1027f4768b389\ulsata2.sys -- (ulsata2 [Disabled | Stopped])
[2008/10/12 18:32:52 | 00,020,536 | ---- | M] (VIA Technologies, Inc.) -- C:\Windows\WinSxS\amd64_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_375215c7dcd73562\viaide.sys -- (viaide [Disabled | Stopped])
[2008/01/19 09:10:22 | 00,149,048 | ---- | M] (VIA Technologies Inc.,Ltd) -- C:\Windows\WinSxS\amd64_vsmraid.inf_31bf3856ad364e35_6.0.6001.18000_none_508698a452d25e17\vsmraid.sys -- (vsmraid [Disabled | Stopped])

========== (R ) Internet Explorer ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=http://go.microsoft.com/fwlink/?LinkId=69157
"Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896
"Default_Secondary_Page_URL"=
"Extensions Off Page"=about:NoAdd-ons
"Local Page"=%SystemRoot%\system32\blank.htm
"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896
"Security Risk Page"=about:SecurityRisk
"Start Page"=http://go.microsoft.com/fwlink/?LinkId=69157

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\Windows\system32\blank.htm
"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896
"Start Page"=http://go.microsoft.com/fwlink/?LinkId=69157
"StartPageCache"=

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main]

[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main]

[HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main]

[HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-3899547795-3242998539-2272418043-1000\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\Windows\system32\blank.htm
"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896
"Start Page"=http://go.microsoft.com/fwlink/?LinkId=69157
"StartPageCache"=

[HKEY_USERS\S-1-5-21-3899547795-3242998539-2272418043-1000\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-3899547795-3242998539-2272418043-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\S-1-5-21-3899547795-3242998539-2272418043-1003\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\Windows\system32\blank.htm
"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896
"Start Page"=http://go.microsoft.com/fwlink/?LinkId=69157
"StartPageCache"=

[HKEY_USERS\S-1-5-21-3899547795-3242998539-2272418043-1003\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-3899547795-3242998539-2272418043-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

========== (O1) Hosts File ==========

HOSTS File = (761 bytes) - C:\Windows\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost
::1 localhost

========== (O2) BHO's ==========

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\]
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} (HKLM) -- C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} (HKLM) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll (Kaspersky Lab)
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} (HKLM) -- C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (HKLM) -- C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
{7E853D72-626A-48EC-A868-BA8D5E23E045} (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
{9030D464-4C02-4ABF-8ECC-5164760863C6} (HKLM) -- C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
{DBC80044-A445-435b-BC74-9C25C1C588A9} (HKLM) -- C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)

========== (O4) Run Keys ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
"AVP"="C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" (Kaspersky Lab)
"GrooveMonitor"="C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" (Microsoft Corporation)
"SunJavaUpdateSched"="C:\Program Files (x86)\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\PROGRA~2\WI1F86~1\MESSEN~1\msnmsgr.exe" /background (Microsoft Corporation)
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (Microsoft Corporation)
"WindowsWelcomeCenter"=rundll32.exe oobefldr.dll,ShowWelcomeCenter (Microsoft Corporation)

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=%ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (Microsoft Corporation)
"WindowsWelcomeCenter"=rundll32.exe oobefldr.dll,ShowWelcomeCenter (Microsoft Corporation)

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=%ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (Microsoft Corporation)
"WindowsWelcomeCenter"=rundll32.exe oobefldr.dll,ShowWelcomeCenter (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-3899547795-3242998539-2272418043-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\PROGRA~2\WI1F86~1\MESSEN~1\msnmsgr.exe" /background (Microsoft Corporation)
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (Microsoft Corporation)
"WindowsWelcomeCenter"=rundll32.exe oobefldr.dll,ShowWelcomeCenter (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-3899547795-3242998539-2272418043-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="C:\Users\XXXX\AppData\Local\Google\Update\GoogleUpdate.exe" /c (Google Inc.)
"MsnMsgr"="C:\Program Files (x86)\Windows Live\Messenger\MsnMsgr.Exe" /background (Microsoft Corporation)
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (Microsoft Corporation)
"WindowsWelcomeCenter"=rundll32.exe oobefldr.dll,ShowWelcomeCenter (Microsoft Corporation)

========== (O6 & O7) Current Version Policies ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"NoDriveTypeAutoRun"=28

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"ConsentPromptBehaviorAdmin"=2
"ConsentPromptBehaviorUser"=1
"EnableInstallerDetection"=1
"EnableLUA"=1
"EnableSecureUIAPaths"=1
"EnableVirtualization"=1
"PromptOnSecureDesktop"=1
"ValidateAdminCodeSignatures"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"scforceoption"=0
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"FilterAdministratorToken"=0
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats]
"CF_TEXT"=1
"CF_BITMAP"=2
"CF_OEMTEXT"=7
"CF_DIB"=8
"CF_PALETTE"=9
"CF_UNICODETEXT"=13
"CF_DIBV5"=17

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"LogonHoursAction"=2
"DontDisplayLogonHoursWarnings"=1

[HKEY_USERS\S-1-5-21-3899547795-3242998539-2272418043-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-21-3899547795-3242998539-2272418043-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"LogonHoursAction"=2
"DontDisplayLogonHoursWarnings"=1

[HKEY_USERS\S-1-5-21-3899547795-3242998539-2272418043-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-21-3899547795-3242998539-2272418043-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"LogonHoursAction"=2
"DontDisplayLogonHoursWarnings"=1

========== (O8) IE Context Menu Extensions ==========

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE [2008/07/30 03:25:02 | 17,930,264 | ---- | M] (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-3899547795-3242998539-2272418043-1000\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE [2008/07/30 03:25:02 | 17,930,264 | ---- | M] (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-3899547795-3242998539-2272418043-1003\Software\Microsoft\Internet Explorer\MenuExt\]
Add to Banner Ad Blocker: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm [2008/07/29 20:08:28 | 00,001,411 | ---- | M] ()

========== (O9) IE Extensions ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E}: Button: Web traffic protection statistics -- %ProgramFiles%\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll [2008/07/29 20:22:28 | 00,222,472 | ---- | M] (Kaspersky Lab)
{2670000A-7350-4f3c-8081-5663EE0C6C49}: Button: Send to OneNote -- %ProgramFiles%\Microsoft Office\Office12\ONBttnIE.dll [2007/12/13 02:20:58 | 00,606,288 | ---- | M] (Microsoft Corporation)
{2670000A-7350-4f3c-8081-5663EE0C6C49}: Menu: S&end to OneNote -- %ProgramFiles%\Microsoft Office\Office12\ONBttnIE.dll [2007/12/13 02:20:58 | 00,606,288 | ---- | M] (Microsoft Corporation)
{92780B25-18CC-41C8-B9BE-3C9C571A8263}: Button: Research -- %ProgramFiles%\Microsoft Office\Office12\REFIEBAR.DLL [2006/10/26 20:12:22 | 00,040,424 | ---- | M] (Microsoft Corporation)

========== (O12) Internet Explorer Plugins ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\]
PluginsPage: "" = http://activex.microsoft.com/controls/find...=%s&mime=%s
PluginsPageFriendlyName: "" = Microsoft ActiveX Gallery

========== (O13) Default Prefixes ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=http://

========== (O16) DPF ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\]
{4E62C4DE-627D-4604-B157-4B7D6B09F02E}: https://moneymanager.egg.com/Pinsafe/accounttracking.cab -- Egg Money Manager Digital Safe
{56762DEC-6B0D-4AB4-A8AD-989993B5D08B}: http://www.eset.eu/buxus/docs/OnlineScanner.cab -- OnlineScanner Control
{8AD9C840-044E-11D1-B3E9-00805F499D93}: http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_10
{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_07
{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_10
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_10
{D27CDB6E-AE6D-11CF-96B8-444553540000}: http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab -- Shockwave Flash Object
{F27237D7-93C8-44C2-AC6E-D6057B9A918F}: https://remote.XXXXXXXXX.co.uk/dana-cached/...SetupClient.cab -- JuniperSetupClient Control

========== (O17) DNS Name Servers ==========

{494DD118-F40E-4E35-A476-CB3D5674D581} (Servers: | Description: Realtek RTL8168B/8111B Family PCI-E Gigabit Ethernet NIC (NDIS 6.0))

========== (O20) AppInit_DLLs ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_Dlls"=C:\PROGRA~2\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~2\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~2\KASPER~1\KASPER~1\adialhk.dll
>[2008/07/29 20:22:08 | 00,079,112 | ---- | M] (Kaspersky Lab) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2009\mzvkbd.dll
>[2008/07/29 20:22:12 | 00,079,112 | ---- | M] (Kaspersky Lab) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2009\mzvkbd3.dll
>[2008/07/29 20:20:58 | 00,083,208 | ---- | M] (Kaspersky Lab) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2009\adialhk.dll

========== (O20) HKLM Winlogon Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=explorer.exe
>[2008/01/19 08:33:10 | 02,927,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\explorer.exe


========== (O21) SSODL Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"WebCheck"={E6FB5E20-DE35-11CF-9C87-00AA005127ED} (HKLM) -- C:\Windows\SysWOW64\webcheck.dll (Microsoft Corporation)

========== Shell Execute Hooks ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}" (HKLM) -- C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)

========== HKLM *SecurityProviders* ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders]
"SecurityProviders"=credssp.dll
>[2008/01/19 08:33:59 | 00,015,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\credssp.dll

========== LSA *Security Packages* ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Security Packages"=kerberos,msv1_0,schannel,wdigest,tspkg,
>[2008/01/19 08:36:42 | 00,062,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\TSpkg.dll

========== Safeboot Options ==========

"AlternateShell"=cmd.exe

========== CDRom AutoRun Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1

========== Autorun Files on Drives ==========

AUTOEXEC.BAT []
[2006/08/21 22:19:41 | 00,000,000 | ---- | M] () -- O:\AUTOEXEC.BAT -- [ NTFS ]

========== Files/Folders - Created Within 30 Days ==========

[2008/10/20 00:12:18 | 00,000,250 | ---- | C] () -- C:\Windows\gmer.ini
[2008/10/20 00:12:17 | 00,884,736 | ---- | C] () -- C:\Windows\gmer.dll
[2008/10/20 00:12:17 | 00,811,008 | ---- | C] () -- C:\Windows\gmer.exe
[2008/10/20 00:12:17 | 00,085,969 | ---- | C] (GMER) -- C:\Windows\System32\drivers\gmer.sys
[2008/10/20 00:12:17 | 00,000,080 | ---- | C] () -- C:\Windows\gmer_uninstall.cmd
[2008/10/19 22:13:56 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\EsetOnlineScanner
[2008/10/19 21:53:20 | 00,000,000 | ---D | C] -- C:\New Folder
[2008/10/19 21:51:35 | 00,003,975 | ---- | C] () -- C:\Users\XXXX\Desktop\kasperskyonlinescanreport.html
[2008/10/19 21:48:34 | 00,003,975 | ---- | C] () -- C:\Users\XXXX\Documents\kasperskyonlinescanreport.html
[2008/10/19 20:32:35 | 00,428,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll
[2008/10/19 20:32:35 | 00,217,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisrndr.ax
[2008/10/19 20:32:34 | 00,293,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisdecd.dll
[2008/10/19 20:32:34 | 00,177,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mpg2splt.ax
[2008/10/19 20:32:34 | 00,080,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSNP.ax
[2008/10/19 12:43:01 | 00,700,310 | ---- | C] () -- C:\Windows\System32\PerfStringBackup.INI
[2008/10/19 12:02:38 | 00,000,000 | ---D | C] -- C:\Windows\Sun
[2008/10/16 19:48:08 | 03,578,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.dll
[2008/10/16 19:48:07 | 06,068,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieframe.dll
[2008/10/16 19:48:07 | 01,166,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\urlmon.dll
[2008/10/16 19:48:06 | 00,827,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wininet.dll
[2008/10/16 19:48:06 | 00,671,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll
[2008/10/16 19:48:06 | 00,270,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iertutil.dll
[2008/10/16 19:48:05 | 01,383,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2008/10/16 19:48:05 | 00,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2008/10/14 21:42:38 | 00,000,000 | ---D | C] -- C:\Users\XXXX\Documents\My Received Files
[2008/10/14 21:05:24 | 00,000,000 | -HSD | C] -- C:\Program Files (x86)\Common Files\WindowsLiveInstaller
[2008/10/14 21:05:20 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Live
[2008/10/14 21:04:27 | 00,000,000 | ---D | C] -- C:\ProgramData\WLInstaller
[2008/10/13 23:55:33 | 00,000,904 | ---- | C] () -- C:\Users\Public\Desktop\Acrobat.com.lnk
[2008/10/13 23:55:20 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe AIR
[2008/10/13 23:55:19 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Roaming\Macromedia
[2008/10/13 23:55:18 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Roaming\Adobe
[2008/10/13 23:54:43 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Local\Adobe
[2008/10/13 23:54:01 | 00,001,917 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2008/10/13 23:53:57 | 00,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2008/10/13 23:53:54 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe
[2008/10/13 23:51:02 | 00,000,000 | ---D | C] -- C:\ProgramData\NOS
[2008/10/13 23:51:02 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\NOS
[2008/10/13 23:44:40 | 00,000,000 | ---D | C] -- C:\Windows\System32\Macromed
[2008/10/13 20:39:29 | 00,005,120 | ---- | C] () -- C:\Users\XXXX\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/10/13 19:02:33 | 00,000,418 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2008/10/13 18:19:28 | 00,002,728 | ---- | C] () -- C:\Windows\System32\%LocalXml%
[2008/10/13 17:38:58 | 00,000,000 | ---D | C] -- C:\ProgramData\WindowsSearch
[2008/10/13 17:17:21 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\ulead systems
[2008/10/13 17:17:21 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\steam
[2008/10/13 17:17:19 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\rivatuner v2.06
[2008/10/13 17:17:19 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\quicktime
[2008/10/13 17:16:47 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\adobe
[2008/10/13 02:56:49 | 00,000,000 | ---D | C] -- C:\Windows\Panther
[2008/10/13 02:56:36 | 00,008,192 | R-S- | C] () -- C:\BOOTSECT.BAK
[2008/10/13 02:56:35 | 00,333,203 | RHS- | C] () -- C:\bootmgr
[2008/10/13 02:56:35 | 00,000,000 | -HSD | C] -- C:\Boot
[2008/10/12 22:43:02 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2008/10/12 22:42:34 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2008/10/12 22:41:25 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Roaming\Juniper Networks
[2008/10/12 22:20:20 | 00,106,605 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2008/10/12 22:20:20 | 00,040,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mimefilt.dll
[2008/10/12 22:20:20 | 00,034,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msscb.dll
[2008/10/12 22:20:20 | 00,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008/10/12 22:20:20 | 00,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msshooks.dll
[2008/10/12 22:20:18 | 00,087,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssitlb.dll
[2008/10/12 22:20:17 | 11,967,524 | ---- | C] () -- C:\Windows\System32\korwbrkr.lex
[2008/10/12 22:20:17 | 01,671,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\chsbrkr.dll
[2008/10/12 22:20:17 | 00,754,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\propsys.dll
[2008/10/12 22:20:17 | 00,313,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\thawbrkr.dll
[2008/10/12 22:20:17 | 00,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msshsq.dll
[2008/10/12 22:20:17 | 00,194,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\offfilt.dll
[2008/10/12 22:20:17 | 00,143,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\korwbrkr.dll
[2008/10/12 22:20:17 | 00,136,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\nlhtml.dll
[2008/10/12 22:20:17 | 00,087,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SearchFilterHost.exe
[2008/10/12 22:20:17 | 00,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\propdefs.dll
[2008/10/12 22:20:17 | 00,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msstrc.dll
[2008/10/12 22:20:17 | 00,038,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rtffilt.dll
[2008/10/12 22:20:17 | 00,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssprxy.dll
[2008/10/12 22:20:16 | 06,103,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\chtbrkr.dll
[2008/10/12 22:20:16 | 01,582,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tquery.dll
[2008/10/12 22:20:16 | 01,418,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssrch.dll
[2008/10/12 22:20:16 | 00,670,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssvp.dll
[2008/10/12 22:20:16 | 00,439,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SearchIndexer.exe
[2008/10/12 22:20:16 | 00,350,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssph.dll
[2008/10/12 22:20:16 | 00,203,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssphtb.dll
[2008/10/12 22:20:16 | 00,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msscntrs.dll
[2008/10/12 22:20:16 | 00,056,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xmlfilter.dll
[2008/10/12 22:19:21 | 00,045,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dataclen.dll
[2008/10/12 22:19:20 | 00,677,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rpcrt4.dll
[2008/10/12 22:19:20 | 00,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\traffic.dll
[2008/10/12 22:19:20 | 00,015,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pacerprf.dll
[2008/10/12 22:19:20 | 00,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wshqos.dll
[2008/10/12 22:19:19 | 00,512,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
[2008/10/12 22:19:19 | 00,430,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll
[2008/10/12 22:19:19 | 00,180,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\scrobj.dll
[2008/10/12 22:19:19 | 00,172,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\scrrun.dll
[2008/10/12 22:19:19 | 00,155,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wscript.exe
[2008/10/12 22:19:19 | 00,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wshom.ocx
[2008/10/12 22:19:19 | 00,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cscript.exe
[2008/10/12 22:19:19 | 00,090,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wshext.dll
[2008/10/12 22:15:20 | 00,001,288 | ---- | C] () -- C:\Users\Public\Desktop\World of Warcraft FREE trial.lnk
[2008/10/12 22:15:17 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\ATI
[2008/10/12 22:03:53 | 00,000,000 | ---D | C] -- C:\PerfLogs
[2008/10/12 21:08:09 | 00,000,000 | ---D | C] -- C:\ATI
[2008/10/12 21:01:32 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Local\{6448F0A6-6813-11D6-A77B-00B0D0160070}
[2008/10/12 20:55:54 | 01,541,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\onex.dll
[2008/10/12 20:55:43 | 00,705,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imagesp1.dll
[2008/10/12 20:55:38 | 00,745,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WsmSvc.dll
[2008/10/12 20:55:38 | 00,175,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winrscmd.dll
[2008/10/12 20:55:37 | 00,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2008/10/12 20:55:36 | 01,107,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pidgenx.dll
[2008/10/12 20:55:35 | 02,061,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstscax.dll
[2008/10/12 20:55:33 | 01,076,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vssapi.dll
[2008/10/12 20:55:33 | 00,510,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate.exe
[2008/10/12 20:55:32 | 00,779,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationNative_v0300.dll
[2008/10/12 20:55:32 | 00,523,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_isv.exe
[2008/10/12 20:55:32 | 00,472,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc.dll
[2008/10/12 20:55:31 | 00,065,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\bfsvc.exe
[2008/10/12 20:55:30 | 00,472,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_isv.dll
[2008/10/12 20:55:29 | 00,978,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drmv2clt.dll
[2008/10/12 20:55:28 | 01,675,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xpssvcs.dll
[2008/10/12 20:55:28 | 01,165,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntdll.dll
[2008/10/12 20:55:28 | 00,579,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\icardagt.exe
[2008/10/12 20:55:28 | 00,542,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\blackbox.dll
[2008/10/12 20:55:28 | 00,163,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wecutil.exe
[2008/10/12 20:55:27 | 00,889,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RacEngn.dll
[2008/10/12 20:55:27 | 00,855,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\kernel32.dll
[2008/10/12 20:55:27 | 00,588,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSMPEG2VDEC.DLL
[2008/10/12 20:55:27 | 00,347,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_ssp.exe
[2008/10/12 20:55:27 | 00,346,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_ssp_isv.exe
[2008/10/12 20:55:26 | 08,322,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spwizimg.dll
[2008/10/12 20:55:26 | 01,190,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msxml3.dll
[2008/10/12 20:55:26 | 00,612,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpencom.dll
[2008/10/12 20:55:25 | 01,589,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msjet40.dll
[2008/10/12 20:55:25 | 01,332,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msxml6.dll
[2008/10/12 20:55:24 | 00,634,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\localspl.dll
[2008/10/12 20:55:23 | 00,412,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wcncsvc.dll
[2008/10/12 20:55:23 | 00,282,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscoree.dll
[2008/10/12 20:55:22 | 00,648,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\user32.dll
[2008/10/12 20:55:19 | 10,621,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmp.dll
[2008/10/12 20:55:18 | 03,080,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\explorer.exe
[2008/10/12 20:55:18 | 02,867,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mf.dll
[2008/10/12 20:55:18 | 01,532,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wcnwiz.dll
[2008/10/12 20:55:18 | 01,386,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msvbvm60.dll
[2008/10/12 20:55:18 | 00,677,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstsc.exe
[2008/10/12 20:55:18 | 00,083,456 | ---- | C] (Microsoft) -- C:\Windows\System32\SMBHelperClass.dll
[2008/10/12 20:55:17 | 00,154,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\nlmgp.dll
[2008/10/12 20:55:17 | 00,053,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DfsShlEx.dll
[2008/10/12 20:55:16 | 02,167,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mmcndmgr.dll
[2008/10/12 20:55:16 | 00,798,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\advapi32.dll
[2008/10/12 20:55:16 | 00,729,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IMJP10K.DLL
[2008/10/12 20:55:16 | 00,497,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\kerberos.dll
[2008/10/12 20:55:15 | 01,111,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CertEnroll.dll
[2008/10/12 20:55:15 | 00,534,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapi.dll
[2008/10/12 20:55:15 | 00,391,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSMPEG2ADEC.DLL
[2008/10/12 20:55:15 | 00,151,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\schtasks.exe
[2008/10/12 20:55:14 | 01,381,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Query.dll
[2008/10/12 20:55:14 | 01,315,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ole32.dll
[2008/10/12 20:55:14 | 00,557,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdtcprx.dll
[2008/10/12 20:55:14 | 00,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xolehlp.dll
[2008/10/12 20:55:13 | 00,592,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netlogon.dll
[2008/10/12 20:55:13 | 00,275,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\bcrypt.dll
[2008/10/12 20:55:12 | 00,680,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msvcrt.dll
[2008/10/12 20:55:11 | 02,011,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\milcore.dll
[2008/10/12 20:55:11 | 00,876,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wer.dll
[2008/10/12 20:55:11 | 00,445,952 | ---- | C] (Microsoft) -- C:\Windows\System32\IasMigPlugin.dll
[2008/10/12 20:55:11 | 00,351,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\shlwapi.dll
[2008/10/12 20:55:11 | 00,178,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\clusapi.dll
[2008/10/12 20:55:10 | 01,788,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d9.dll
[2008/10/12 20:55:10 | 00,507,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vdsdyn.dll
[2008/10/12 20:55:10 | 00,351,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WSDApi.dll
[2008/10/12 20:55:09 | 01,792,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mmc.exe
[2008/10/12 20:55:09 | 00,307,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mtxclu.dll
[2008/10/12 20:55:09 | 00,225,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SLC.dll
[2008/10/12 20:55:09 | 00,215,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winrsmgr.dll
[2008/10/12 20:55:09 | 00,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vdsbas.dll
[2008/10/12 20:55:08 | 02,085,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msi.dll
[2008/10/12 20:55:08 | 00,531,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\comctl32.dll
[2008/10/12 20:55:07 | 01,544,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSVidCtl.dll
[2008/10/12 20:55:07 | 00,574,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XPSSHHDR.dll
[2008/10/12 20:55:06 | 01,452,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\esent.dll
[2008/10/12 20:55:06 | 01,160,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42u.dll
[2008/10/12 20:55:06 | 00,595,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FWPUCLNT.DLL
[2008/10/12 20:55:06 | 00,322,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sbe.dll
[2008/10/12 20:55:05 | 01,135,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42.dll
[2008/10/12 20:55:05 | 00,882,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IMJP10.IME
[2008/10/12 20:55:05 | 00,501,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\usp10.dll
[2008/10/12 20:55:05 | 00,297,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cmipnpinstall.dll
[2008/10/12 20:55:05 | 00,128,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\gpresult.exe
[2008/10/12 20:55:05 | 00,064,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cmicryptinstall.dll
[2008/10/12 20:55:04 | 01,208,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\comsvcs.dll
[2008/10/12 20:55:04 | 00,977,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\crypt32.dll
[2008/10/12 20:55:04 | 00,798,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\certutil.exe
[2008/10/12 20:55:04 | 00,188,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WSManMigrationPlugin.dll
[2008/10/12 20:55:03 | 02,927,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\explorer.exe
[2008/10/12 20:55:03 | 01,590,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\setupapi.dll
[2008/10/12 20:55:03 | 00,604,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sqlceqp30.dll
[2008/10/12 20:55:03 | 00,563,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\oleaut32.dll
[2008/10/12 20:55:03 | 00,533,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmdrmsdk.dll
[2008/10/12 20:55:03 | 00,403,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FirewallAPI.dll
[2008/10/12 20:55:03 | 00,229,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\lsm.exe
[2008/10/12 20:55:03 | 00,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mswsock.dll
[2008/10/12 20:55:03 | 00,183,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sdohlp.dll
[2008/10/12 20:55:02 | 00,866,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmpmde.dll
[2008/10/12 20:55:02 | 00,734,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\HelpPane.exe
[2008/10/12 20:55:02 | 00,658,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\p2psvc.dll
[2008/10/12 20:55:02 | 00,466,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netapi32.dll
[2008/10/12 20:55:02 | 00,268,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\schannel.dll
[2008/10/12 20:55:02 | 00,210,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msv1_0.dll
[2008/10/12 20:55:02 | 00,187,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\eapp3hst.dll
[2008/10/12 20:55:02 | 00,080,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\thumbcache.dll
[2008/10/12 20:55:01 | 00,656,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\autoconv.exe
[2008/10/12 20:55:01 | 00,642,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\autochk.exe
[2008/10/12 20:55:01 | 00,634,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\autofmt.exe
[2008/10/12 20:55:01 | 00,496,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imapi2fs.dll
[2008/10/12 20:55:01 | 00,456,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\riched20.dll
[2008/10/12 20:55:01 | 00,389,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2008/10/12 20:55:01 | 00,251,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\authfwcfg.dll
[2008/10/12 20:55:01 | 00,159,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll
[2008/10/12 20:55:01 | 00,126,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vdsutil.dll
[2008/10/12 20:55:00 | 01,985,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\authui.dll
[2008/10/12 20:55:00 | 01,324,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\browseui.dll
[2008/10/12 20:55:00 | 00,593,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\comuid.dll
[2008/10/12 20:55:00 | 00,450,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\comdlg32.dll
[2008/10/12 20:55:00 | 00,250,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wevtapi.dll
[2008/10/12 20:55:00 | 00,208,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll
[2008/10/12 20:55:00 | 00,131,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dmvdsitf.dll
[2008/10/12 20:55:00 | 00,084,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscories.dll
[2008/10/12 20:54:59 | 00,322,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\untfs.dll
[2008/10/12 20:54:59 | 00,181,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\eapphost.dll
[2008/10/12 20:54:59 | 00,177,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WSDMon.dll
[2008/10/12 20:54:59 | 00,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\eappcfg.dll
[2008/10/12 20:54:59 | 00,076,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wevtfwd.dll
[2008/10/12 20:54:59 | 00,056,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\uexfat.dll
[2008/10/12 20:54:58 | 00,464,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pcaui.dll
[2008/10/12 20:54:58 | 00,308,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sqlcese30.dll
[2008/10/12 20:54:58 | 00,180,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iassam.dll
[2008/10/12 20:54:58 | 00,163,840 | ---- | C] (Microsoft Corp.) -- C:\Windows\System32\DfrgNtfs.exe
[2008/10/12 20:54:57 | 01,827,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2008/10/12 20:54:57 | 00,671,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dfrgui.exe
[2008/10/12 20:54:57 | 00,485,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\evr.dll
[2008/10/12 20:54:57 | 00,376,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winhttp.dll
[2008/10/12 20:54:57 | 00,342,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\zipfldr.dll
[2008/10/12 20:54:57 | 00,329,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdrm.dll
[2008/10/12 20:54:57 | 00,169,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssha.dll
[2008/10/12 20:54:56 | 02,386,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMVCORE.DLL
[2008/10/12 20:54:56 | 00,647,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrepl40.dll
[2008/10/12 20:54:56 | 00,418,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmdrmdev.dll
[2008/10/12 20:54:56 | 00,259,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rasppp.dll
[2008/10/12 20:54:56 | 00,234,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\uxtheme.dll
[2008/10/12 20:54:56 | 00,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncrypt.dll
[2008/10/12 20:54:56 | 00,123,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WsmAuto.dll
[2008/10/12 20:54:55 | 01,152,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\themecpl.dll
[2008/10/12 20:54:55 | 00,869,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\printui.dll
[2008/10/12 20:54:55 | 00,531,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\objsel.dll
[2008/10/12 20:54:55 | 00,522,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ddraw.dll
[2008/10/12 20:54:55 | 00,441,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32spl.dll
[2008/10/12 20:54:55 | 00,243,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rastls.dll
[2008/10/12 20:54:55 | 00,196,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WebClnt.dll
[2008/10/12 20:54:55 | 00,175,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WsmWmiPl.dll
[2008/10/12 20:54:55 | 00,132,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msra.exe
[2008/10/12 20:54:55 | 00,128,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dhcpcsvc6.dll
[2008/10/12 20:54:55 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CertEnrollCtrl.exe
[2008/10/12 20:54:54 | 00,798,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dbghelp.dll
[2008/10/12 20:54:54 | 00,520,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sqlsrv32.dll
[2008/10/12 20:54:54 | 00,350,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHost.exe
[2008/10/12 20:54:54 | 00,215,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\icm32.dll
[2008/10/12 20:54:54 | 00,172,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\QAGENT.DLL
[2008/10/12 20:54:54 | 00,147,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iasnap.dll
[2008/10/12 20:54:53 | 01,102,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mmsys.cpl
[2008/10/12 20:54:53 | 00,860,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WerFaultSecure.exe
[2008/10/12 20:54:53 | 00,806,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msctf.dll
[2008/10/12 20:54:53 | 00,756,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\azroles.dll
[2008/10/12 20:54:53 | 00,445,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncryptui.dll
[2008/10/12 20:54:53 | 00,347,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmdrmnet.dll
[2008/10/12 20:54:53 | 00,252,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iprtrmgr.dll
[2008/10/12 20:54:53 | 00,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spoolss.dll
[2008/10/12 20:54:53 | 00,131,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\basecsp.dll
[2008/10/12 20:54:53 | 00,088,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\infocardapi.dll
[2008/10/12 20:54:52 | 00,399,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wlangpui.dll
[2008/10/12 20:54:52 | 00,397,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\AudioEng.dll
[2008/10/12 20:54:52 | 00,357,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\taskschd.dll
[2008/10/12 20:54:52 | 00,140,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\scksp.dll
[2008/10/12 20:54:52 | 00,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstlsapi.dll
[2008/10/12 20:54:52 | 00,076,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\systeminfo.exe
[2008/10/12 20:54:51 | 00,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netprofm.dll
[2008/10/12 20:54:51 | 00,140,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winsta.dll
[2008/10/12 20:54:50 | 01,855,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dbgeng.dll
[2008/10/12 20:54:50 | 00,386,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netcfgx.dll
[2008/10/12 20:54:50 | 00,242,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rsaenh.dll
[2008/10/12 20:54:49 | 00,805,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cdosys.dll
[2008/10/12 20:54:49 | 00,314,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winlogon.exe
[2008/10/12 20:54:49 | 00,270,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\taskcomp.dll
[2008/10/12 20:54:49 | 00,129,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sqmapi.dll
[2008/10/12 20:54:49 | 00,125,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tintlgnt.ime
[2008/10/12 20:54:49 | 00,124,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\quick.ime
[2008/10/12 20:54:49 | 00,124,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qintlgnt.ime
[2008/10/12 20:54:49 | 00,124,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\phon.ime
[2008/10/12 20:54:49 | 00,124,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cintlgnt.ime
[2008/10/12 20:54:49 | 00,124,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\chajei.ime
[2008/10/12 20:54:49 | 00,096,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dfshim.dll
[2008/10/12 20:54:49 | 00,089,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pintlgnt.ime
[2008/10/12 20:54:49 | 00,019,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\perfhost.exe
[2008/10/12 20:54:48 | 01,730,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\apds.dll
[2008/10/12 20:54:48 | 01,067,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\shdocvw.dll
[2008/10/12 20:54:48 | 00,323,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\certcli.dll
[2008/10/12 20:54:48 | 00,302,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wlansec.dll
[2008/10/12 20:54:48 | 00,274,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\AUDIOKSE.dll
[2008/10/12 20:54:48 | 00,258,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\srchadmin.dll
[2008/10/12 20:54:48 | 00,215,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdtcuiu.dll
[2008/10/12 20:54:48 | 00,156,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iasrad.dll
[2008/10/12 20:54:48 | 00,136,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\aaclient.dll
[2008/10/12 20:54:48 | 00,104,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mprddm.dll
[2008/10/12 20:54:48 | 00,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\driverquery.exe
[2008/10/12 20:54:48 | 00,053,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tsgqec.dll
[2008/10/12 20:54:48 | 00,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wscisvif.dll
[2008/10/12 20:54:47 | 01,502,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\certmgr.dll
[2008/10/12 20:54:47 | 00,475,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msidcrl30.dll
[2008/10/12 20:54:47 | 00,289,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Wldap32.dll
[2008/10/12 20:54:47 | 00,165,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dnsapi.dll
[2008/10/12 20:54:47 | 00,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secur32.dll
[2008/10/12 20:54:47 | 00,016,896 | ---- | C] (Microsoft) -- C:\Windows\System32\grb.rs
[2008/10/12 20:54:46 | 03,173,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netshell.dll
[2008/10/12 20:54:46 | 01,548,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMVDECOD.DLL
[2008/10/12 20:54:46 | 01,502,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pla.dll
[2008/10/12 20:54:46 | 00,235,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dot3gpui.dll
[2008/10/12 20:54:46 | 00,171,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxgi.dll
[2008/10/12 20:54:45 | 01,823,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pnidui.dll
[2008/10/12 20:54:45 | 00,704,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PhotoScreensaver.scr
[2008/10/12 20:54:45 | 00,279,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\services.exe
[2008/10/12 20:54:45 | 00,247,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\shsvcs.dll
[2008/10/12 20:54:45 | 00,220,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\comsnap.dll
[2008/10/12 20:54:45 | 00,216,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntprint.dll
[2008/10/12 20:54:45 | 00,189,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winmm.dll
[2008/10/12 20:54:45 | 00,149,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MMDevAPI.dll
[2008/10/12 20:54:45 | 00,097,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cryptnet.dll
[2008/10/12 20:54:45 | 00,075,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\synceng.dll
[2008/10/12 20:54:45 | 00,067,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cmifw.dll
[2008/10/12 20:54:45 | 00,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iashost.exe
[2008/10/12 20:54:44 | 01,382,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMVSDECD.DLL
[2008/10/12 20:54:44 | 00,431,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tdh.dll
[2008/10/12 20:54:44 | 00,320,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imapi2.dll
[2008/10/12 20:54:44 | 00,318,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cmd.exe
[2008/10/12 20:54:44 | 00,299,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msjtes40.dll
[2008/10/12 20:54:44 | 00,286,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rasapi32.dll
[2008/10/12 20:54:44 | 00,258,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winspool.drv
[2008/10/12 20:54:44 | 00,251,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iassdo.dll
[2008/10/12 20:54:44 | 00,184,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dmdskmgr.dll
[2008/10/12 20:54:44 | 00,169,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\taskeng.exe
[2008/10/12 20:54:44 | 00,084,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SessEnv.dll
[2008/10/12 20:54:44 | 00,058,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cipher.exe
[2008/10/12 20:54:44 | 00,045,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dot3api.dll
[2008/10/12 20:54:43 | 04,595,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\AuthFWSnapin.dll
[2008/10/12 20:54:43 | 01,291,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\comres.dll
[2008/10/12 20:54:43 | 00,497,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qdvd.dll
[2008/10/12 20:54:43 | 00,414,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msscp.dll
[2008/10/12 20:54:43 | 00,293,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wlanmsm.dll
[2008/10/12 20:54:43 | 00,163,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wevtutil.exe
[2008/10/12 20:54:43 | 00,153,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuwebv.dll
[2008/10/12 20:54:43 | 00,120,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\diskpart.exe
[2008/10/12 20:54:43 | 00,113,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\loadperf.dll
[2008/10/12 20:54:43 | 00,092,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wlancfg.dll
[2008/10/12 20:54:42 | 00,476,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmled.dll
[2008/10/12 20:54:42 | 00,429,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\localsec.dll
[2008/10/12 20:54:42 | 00,289,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\hnetcfg.dll
[2008/10/12 20:54:42 | 00,147,439 | ---- | C] () -- C:\Windows\System32\gpedit.msc
[2008/10/12 20:54:42 | 00,142,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fontext.dll
[2008/10/12 20:54:42 | 00,127,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rpchttp.dll
[2008/10/12 20:54:42 | 00,064,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wlanapi.dll
[2008/10/12 20:54:41 | 01,689,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wscui.cpl
[2008/10/12 20:54:41 | 01,671,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wlanpref.dll
[2008/10/12 20:54:41 | 00,758,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMADMOD.DLL
[2008/10/12 20:54:41 | 00,712,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WindowsCodecs.dll
[2008/10/12 20:54:41 | 00,444,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dsound.dll
[2008/10/12 20:54:41 | 00,442,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\filemgmt.dll
[2008/10/12 20:54:41 | 00,383,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WinSATAPI.dll
[2008/10/12 20:54:41 | 00,153,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NAPMONTR.DLL
[2008/10/12 20:54:41 | 00,091,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\avifil32.dll
[2008/10/12 20:54:41 | 00,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\whealogr.dll
[2008/10/12 20:54:40 | 01,295,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wsecedit.dll
[2008/10/12 20:54:40 | 00,573,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SLCommDlg.dll
[2008/10/12 20:54:40 | 00,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tracerpt.exe
[2008/10/12 20:54:40 | 00,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dhcpcsvc.dll
[2008/10/12 20:54:40 | 00,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MuiUnattend.exe
[2008/10/12 20:54:40 | 00,033,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHostProxy.dll
[2008/10/12 20:54:39 | 01,186,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\AuxiliaryDisplayCpl.dll
[2008/10/12 20:54:39 | 00,825,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rasdlg.dll
[2008/10/12 20:54:39 | 00,604,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMSPDMOD.DLL
[2008/10/12 20:54:39 | 00,336,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\P2PGraph.dll
[2008/10/12 20:54:39 | 00,317,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\azroleui.dll
[2008/10/12 20:54:39 | 00,171,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\apphelp.dll
[2008/10/12 20:54:39 | 00,158,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscorier.dll
[2008/10/12 20:54:39 | 00,154,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\QSHVHOST.DLL
[2008/10/12 20:54:39 | 00,142,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spp.dll
[2008/10/12 20:54:39 | 00,134,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SmartcardCredentialProvider.dll
[2008/10/12 20:54:39 | 00,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wininit.exe
[2008/10/12 20:54:39 | 00,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iassvcs.dll
[2008/10/12 20:54:39 | 00,034,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdt.exe
[2008/10/12 20:54:38 | 00,413,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imkr80.ime
[2008/10/12 20:54:38 | 00,348,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spwizeng.dll
[2008/10/12 20:54:38 | 00,275,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mcbuilder.exe
[2008/10/12 20:54:38 | 00,272,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceApi.dll
[2008/10/12 20:54:37 | 01,642,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMPEncEn.dll
[2008/10/12 20:54:37 | 00,936,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\gpedit.dll
[2008/10/12 20:54:37 | 00,736,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\unbcl.dll
[2008/10/12 20:54:37 | 00,215,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\oleacc.dll
[2008/10/12 20:54:37 | 00,155,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rasmontr.dll
[2008/10/12 20:54:37 | 00,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tcpmon.dll
[2008/10/12 20:54:37 | 00,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\shrink.dll
[2008/10/12 20:54:37 | 00,091,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IPHLPAPI.DLL
[2008/10/12 20:54:37 | 00,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iashlpr.dll
[2008/10/12 20:54:37 | 00,056,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wecapi.dll
[2008/10/12 20:54:36 | 02,537,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wpdshext.dll
[2008/10/12 20:54:36 | 01,248,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PerfCenterCPL.dll
[2008/10/12 20:54:36 | 01,122,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\appwiz.cpl
[2008/10/12 20:54:36 | 01,020,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wdc.dll
[2008/10/12 20:54:36 | 00,396,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ipsmsnap.dll
[2008/10/12 20:54:36 | 00,339,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\appmgr.dll
[2008/10/12 20:54:36 | 00,281,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\raschap.dll
[2008/10/12 20:54:36 | 00,242,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sysdm.cpl
[2008/10/12 20:54:36 | 00,204,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\framedynos.dll
[2008/10/12 20:54:36 | 00,147,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Faultrep.dll
[2008/10/12 20:54:36 | 00,128,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\advpack.dll
[2008/10/12 20:54:36 | 00,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vsstrace.dll
[2008/10/12 20:54:36 | 00,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fdWSD.dll
[2008/10/12 20:54:36 | 00,063,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntlanman.dll
[2008/10/12 20:54:35 | 00,913,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WlanMM.dll
[2008/10/12 20:54:35 | 00,388,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2008/10/12 20:54:35 | 00,383,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2008/10/12 20:54:35 | 00,376,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sxs.dll
[2008/10/12 20:54:35 | 00,257,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\adsnt.dll
[2008/10/12 20:54:35 | 00,215,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\certreq.exe
[2008/10/12 20:54:35 | 00,202,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\framedyn.dll
[2008/10/12 20:54:35 | 00,170,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tcpipcfg.dll
[2008/10/12 20:54:35 | 00,155,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dssenh.dll
[2008/10/12 20:54:35 | 00,116,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imm32.dll
[2008/10/12 20:54:35 | 00,047,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\l2nacp.dll
[2008/10/12 20:54:34 | 00,970,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cryptui.dll
[2008/10/12 20:54:34 | 00,628,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WLanConn.dll
[2008/10/12 20:54:34 | 00,487,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\catsrvut.dll
[2008/10/12 20:54:34 | 00,412,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\scrptadm.dll
[2008/10/12 20:54:34 | 00,412,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PhotoMetadataHandler.dll
[2008/10/12 20:54:34 | 00,257,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\VAN.dll
[2008/10/12 20:54:34 | 00,217,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WerFault.exe
[2008/10/12 20:54:34 | 00,146,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fundisc.dll
[2008/10/12 20:54:34 | 00,139,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wusa.exe
[2008/10/12 20:54:34 | 00,108,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\userenv.dll
[2008/10/12 20:54:34 | 00,093,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncsi.dll
[2008/10/12 20:54:34 | 00,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2008/10/12 20:54:34 | 00,068,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wlanhlp.dll
[2008/10/12 20:54:34 | 00,054,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WsmProv.dll
[2008/10/12 20:54:33 | 02,225,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netcenter.dll
[2008/10/12 20:54:33 | 00,758,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ipsecsnp.dll
[2008/10/12 20:54:33 | 00,408,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msinfo32.exe
[2008/10/12 20:54:33 | 00,319,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbcjt32.dll
[2008/10/12 20:54:33 | 00,300,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\puiobj.dll
[2008/10/12 20:54:33 | 00,291,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\photowiz.dll
[2008/10/12 20:54:33 | 00,267,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NAPSTAT.EXE
[2008/10/12 20:54:33 | 00,217,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\InkEd.dll
[2008/10/12 20:54:33 | 00,179,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ws2_32.dll
[2008/10/12 20:54:33 | 00,119,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netid.dll
[2008/10/12 20:54:33 | 00,115,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WinSCard.dll
[2008/10/12 20:54:33 | 00,088,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntdsapi.dll
[2008/10/12 20:54:33 | 00,064,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spbcd.dll
[2008/10/12 20:54:33 | 00,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winrs.exe
[2008/10/12 20:54:32 | 08,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ssBranded.scr
[2008/10/12 20:54:32 | 00,551,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\prnntfy.dll
[2008/10/12 20:54:32 | 00,458,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2008/10/12 20:54:32 | 00,451,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\catsrv.dll
[2008/10/12 20:54:32 | 00,388,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dmdlgs.dll
[2008/10/12 20:54:32 | 00,340,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RelMon.dll
[2008/10/12 20:54:32 | 00,242,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pdh.dll
[2008/10/12 20:54:32 | 00,204,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\activeds.dll
[2008/10/12 20:54:32 | 00,128,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cryptsvc.dll
[2008/10/12 20:54:32 | 00,112,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netdiagfx.dll
[2008/10/12 20:54:32 | 00,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dhcpsapi.dll
[2008/10/12 20:54:32 | 00,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iasacct.dll
[2008/10/12 20:54:31 | 02,585,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FirewallControlPanel.exe
[2008/10/12 20:54:31 | 00,506,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSMPEG2ENC.DLL
[2008/10/12 20:54:31 | 00,473,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FXSCOMEX.dll
[2008/10/12 20:54:31 | 00,456,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wvc.dll
[2008/10/12 20:54:31 | 00,243,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qwave.dll
[2008/10/12 20:54:31 | 00,195,122 | ---- | C] () -- C:\Windows\System32\winrm.vbs
[2008/10/12 20:54:31 | 00,131,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cscobj.dll
[2008/10/12 20:54:31 | 00,116,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\AudioSes.dll
[2008/10/12 20:54:31 | 00,112,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netcorehc.dll
[2008/10/12 20:54:31 | 00,096,768 | ---- | C] (Microsoft Corp.) -- C:\Windows\System32\dfrgfat.exe
[2008/10/12 20:54:31 | 00,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dot3msm.dll
[2008/10/12 20:54:31 | 00,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fdWCN.dll
[2008/10/12 20:54:31 | 00,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TSpkg.dll
[2008/10/12 20:54:31 | 00,049,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dot3cfg.dll
[2008/10/12 20:54:30 | 00,103,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NAPHLPR.DLL
[2008/10/12 20:54:30 | 00,029,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ifmon.dll
[2008/10/12 20:54:29 | 00,996,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMNetMgr.dll
[2008/10/12 20:54:29 | 00,586,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\stobject.dll
[2008/10/12 20:54:29 | 00,523,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\hhctrl.ocx
[2008/10/12 20:54:29 | 00,523,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\clbcatq.dll
[2008/10/12 20:54:29 | 00,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntshrui.dll
[2008/10/12 20:54:29 | 00,224,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wscntfy.dll
[2008/10/12 20:54:29 | 00,185,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\adsldp.dll
[2008/10/12 20:54:29 | 00,179,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\els.dll
[2008/10/12 20:54:29 | 00,166,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wdmaud.drv
[2008/10/12 20:54:29 | 00,158,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\net1.exe
[2008/10/12 20:54:29 | 00,101,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\shsetup.dll
[2008/10/12 20:54:29 | 00,098,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iasrecst.dll
[2008/10/12 20:54:29 | 00,080,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wudriver.dll
[2008/10/12 20:54:29 | 00,079,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\QUTIL.DLL
[2008/10/12 20:54:29 | 00,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msacm32.dll
[2008/10/12 20:54:29 | 00,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rastapi.dll
[2008/10/12 20:54:29 | 00,068,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fdSSDP.dll
[2008/10/12 20:54:29 | 00,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iasdatastore.dll
[2008/10/12 20:54:28 | 01,405,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ActiveContentWizard.dll
[2008/10/12 20:54:28 | 00,842,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\systemcpl.dll
[2008/10/12 20:54:28 | 00,564,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msftedit.dll
[2008/10/12 20:54:28 | 00,282,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CompatUI.dll
[2008/10/12 20:54:28 | 00,259,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\upnphost.dll
[2008/10/12 20:54:28 | 00,227,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FXSAPI.dll
[2008/10/12 20:54:28 | 00,202,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wlanui.dll
[2008/10/12 20:54:28 | 00,202,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\P2P.dll
[2008/10/12 20:54:28 | 00,198,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\adsldpc.dll
[2008/10/12 20:54:28 | 00,160,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSAC3ENC.DLL
[2008/10/12 20:54:28 | 00,137,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dsprop.dll
[2008/10/12 20:54:28 | 00,131,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fde.dll
[2008/10/12 20:54:28 | 00,124,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mprmsg.dll
[2008/10/12 20:54:28 | 00,083,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wlgpclnt.dll
[2008/10/12 20:54:28 | 00,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rascfg.dll
[2008/10/12 20:54:28 | 00,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\nci.dll
[2008/10/12 20:54:28 | 00,071,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rasman.dll
[2008/10/12 20:54:28 | 00,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TsWpfWrp.exe
[2008/10/12 20:54:27 | 00,377,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\devmgr.dll
[2008/10/12 20:54:27 | 00,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Wpc.dll
[2008/10/12 20:54:27 | 00,252,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxdiag.exe
[2008/10/12 20:54:27 | 00,245,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\scansetting.dll
[2008/10/12 20:54:27 | 00,168,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wdigest.dll
[2008/10/12 20:54:27 | 00,163,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msutb.dll
[2008/10/12 20:54:27 | 00,155,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\t2embed.dll
[2008/10/12 20:54:27 | 00,126,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\L2SecHC.dll
[2008/10/12 20:54:27 | 00,114,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rtm.dll
[2008/10/12 20:54:27 | 00,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\oleprn.dll
[2008/10/12 20:54:27 | 00,094,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MigAutoPlay.exe
[2008/10/12 20:54:27 | 00,075,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\gpapi.dll
[2008/10/12 20:54:27 | 00,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\loghours.dll
[2008/10/12 20:54:27 | 00,068,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mprdim.dll
[2008/10/12 20:54:26 | 00,632,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CertEnrollUI.dll
[2008/10/12 20:54:26 | 00,332,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msihnd.dll
[2008/10/12 20:54:26 | 00,326,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\actxprxy.dll
[2008/10/12 20:54:26 | 00,312,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mswmdm.dll
[2008/10/12 20:54:26 | 00,208,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WinFXDocObj.exe
[2008/10/12 20:54:26 | 00,123,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ifsutil.dll
[2008/10/12 20:54:26 | 00,073,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wdi.dll
[2008/10/12 20:54:26 | 00,054,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dimsroam.dll
[2008/10/12 20:54:26 | 00,046,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NAPCRYPT.DLL
[2008/10/12 20:54:26 | 00,034,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\usbmon.dll
[2008/10/12 20:54:26 | 00,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wscapi.dll
[2008/10/12 20:54:25 | 02,204,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SyncCenter.dll
[2008/10/12 20:54:25 | 00,498,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wlandlg.dll
[2008/10/12 20:54:25 | 00,485,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mspaint.exe
[2008/10/12 20:54:25 | 00,456,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FXSXP32.dll
[2008/10/12 20:54:25 | 00,229,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mycomput.dll
[2008/10/12 20:54:25 | 00,206,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstask.dll
[2008/10/12 20:54:25 | 00,196,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceWMDRM.dll
[2008/10/12 20:54:25 | 00,183,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\newdev.dll
[2008/10/12 20:54:25 | 00,177,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\scecli.dll
[2008/10/12 20:54:25 | 00,169,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WSTPager.ax
[2008/10/12 20:54:25 | 00,156,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2008/10/12 20:54:25 | 00,153,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imagehlp.dll
[2008/10/12 20:54:25 | 00,130,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\uudf.dll
[2008/10/12 20:54:25 | 00,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\activeds.tlb
[2008/10/12 20:54:25 | 00,095,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SCardSvr.dll
[2008/10/12 20:54:25 | 00,093,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vssadmin.exe
[2008/10/12 20:54:25 | 00,088,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\audiodg.exe
[2008/10/12 20:54:25 | 00,067,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\regapi.dll
[2008/10/12 20:54:25 | 00,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\infocardcpl.cpl
[2008/10/12 20:54:25 | 00,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\lpk.dll
[2008/10/12 20:54:24 | 01,224,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sud.dll
[2008/10/12 20:54:24 | 00,605,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\adtschema.dll
[2008/10/12 20:54:24 | 00,389,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sysmon.ocx
[2008/10/12 20:54:24 | 00,355,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\termmgr.dll
[2008/10/12 20:54:24 | 00,242,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tapisrv.dll
[2008/10/12 20:54:24 | 00,200,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\input.dll
[2008/10/12 20:54:24 | 00,183,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\duser.dll
[2008/10/12 20:54:24 | 00,171,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cic.dll
[2008/10/12 20:54:24 | 00,166,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\puiapi.dll
[2008/10/12 20:54:24 | 00,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\regedit.exe
[2008/10/12 20:54:24 | 00,160,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceTypes.dll
[2008/10/12 20:54:24 | 00,105,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mtxoci.dll
[2008/10/12 20:54:24 | 00,102,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netiohlp.dll
[2008/10/12 20:54:24 | 00,087,552 | ---- | C] (Microsoft) -- C:\Windows\System32\Robocopy.exe
[2008/10/12 20:54:24 | 00,079,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\authz.dll
[2008/10/12 20:54:24 | 00,057,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\samlib.dll
[2008/10/12 20:54:24 | 00,054,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iasads.dll
[2008/10/12 20:54:24 | 00,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\splwow64.exe
[2008/10/12 20:54:24 | 00,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cscapi.dll
[2008/10/12 20:54:24 | 00,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\AzSqlExt.dll
[2008/10/12 20:54:23 | 01,039,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d8.dll
[2008/10/12 20:54:23 | 00,714,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\timedate.cpl
[2008/10/12 20:54:23 | 00,642,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rasgcw.dll
[2008/10/12 20:54:23 | 00,615,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\themeui.dll
[2008/10/12 20:54:23 | 00,481,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cmdial32.dll
[2008/10/12 20:54:23 | 00,347,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2008/10/12 20:54:23 | 00,344,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrd3x40.dll
[2008/10/12 20:54:23 | 00,301,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mmcbase.dll
[2008/10/12 20:54:23 | 00,276,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMPhoto.dll
[2008/10/12 20:54:23 | 00,233,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\webcheck.dll
[2008/10/12 20:54:23 | 00,230,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\diskraid.exe
[2008/10/12 20:54:23 | 00,197,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SndVol.exe
[2008/10/12 20:54:23 | 00,187,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mlang.dll
[2008/10/12 20:54:23 | 00,180,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pnpsetup.dll
[2008/10/12 20:54:23 | 00,171,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wintrust.dll
[2008/10/12 20:54:23 | 00,140,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wpcsvc.dll
[2008/10/12 20:54:23 | 00,121,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntmarta.dll
[2008/10/12 20:54:23 | 00,120,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msaatext.dll
[2008/10/12 20:54:23 | 00,112,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\verifier.exe
[2008/10/12 20:54:23 | 00,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\oledlg.dll
[2008/10/12 20:54:23 | 00,099,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\twext.dll
[2008/10/12 20:54:23 | 00,094,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceClassExtension.dll
[2008/10/12 20:54:23 | 00,088,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dmview.ocx
[2008/10/12 20:54:23 | 00,082,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\nslookup.exe
[2008/10/12 20:54:23 | 00,080,047 | ---- | C] () -- C:\Windows\System32\slmgr.vbs
[2008/10/12 20:54:23 | 00,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rasqec.dll
[2008/10/12 20:54:23 | 00,068,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mpr.dll
[2008/10/12 20:54:23 | 00,063,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\icardie.dll
[2008/10/12 20:54:23 | 00,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\clfsw32.dll
[2008/10/12 20:54:23 | 00,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncobjapi.dll
[2008/10/12 20:54:23 | 00,042,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\slcinst.dll
[2008/10/12 20:54:23 | 00,019,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vdsldr.exe
[2008/10/12 20:54:23 | 00,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\icardres.dll
[2008/10/12 20:54:22 | 02,515,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\accessibilitycpl.dll
[2008/10/12 20:54:22 | 02,153,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\oobefldr.dll
[2008/10/12 20:54:22 | 00,638,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Utilman.exe
[2008/10/12 20:54:22 | 00,626,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sethc.exe
[2008/10/12 20:54:22 | 00,391,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscms.dll
[2008/10/12 20:54:22 | 00,195,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxdiagn.dll
[2008/10/12 20:54:22 | 00,133,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\extmgr.dll
[2008/10/12 20:54:22 | 00,099,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ulib.dll
[2008/10/12 20:54:22 | 00,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fontsub.dll
[2008/10/12 20:54:22 | 00,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cabinet.dll
[2008/10/12 20:54:22 | 00,047,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\syssetup.dll
[2008/10/12 20:54:22 | 00,040,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\lodctr.exe
[2008/10/12 20:54:22 | 00,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\unlodctr.exe
[2008/10/12 20:54:22 | 00,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iaspolcy.dll
[2008/10/12 20:54:22 | 00,026,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wtsapi32.dll
[2008/10/12 20:54:21 | 01,107,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ogldrv.dll
[2008/10/12 20:54:21 | 00,532,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wpcao.dll
[2008/10/12 20:54:21 | 00,306,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\scesrv.dll
[2008/10/12 20:54:21 | 00,201,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\unattend.dll
[2008/10/12 20:54:21 | 00,193,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2008/10/12 20:54:21 | 00,179,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msnetobj.dll
[2008/10/12 20:54:21 | 00,102,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\occache.dll
[2008/10/12 20:54:21 | 00,097,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cabview.dll
[2008/10/12 20:54:21 | 00,093,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\eappgnui.dll
[2008/10/12 20:54:21 | 00,056,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wermgr.exe
[2008/10/12 20:54:21 | 00,040,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\lnkstub.exe
[2008/10/12 20:54:21 | 00,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WSManHTTPConfig.exe
[2008/10/12 20:54:20 | 00,403,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\p2pcollab.dll
[2008/10/12 20:54:20 | 00,394,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dsquery.dll
[2008/10/12 20:54:20 | 00,230,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
[2008/10/12 20:54:20 | 00,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drvinst.exe
[2008/10/12 20:54:20 | 00,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DHCPQEC.DLL
[2008/10/12 20:54:19 | 03,072,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\networkmap.dll
[2008/10/12 20:54:19 | 02,249,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Firewall.cpl
[2008/10/12 20:54:19 | 01,575,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMVENCOD.DLL
[2008/10/12 20:54:19 | 00,505,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qedit.dll
[2008/10/12 20:54:19 | 00,349,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WPDSp.dll
[2008/10/12 20:54:19 | 00,205,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msoeacct.dll
[2008/10/12 20:54:19 | 00,188,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10core.dll
[2008/10/12 20:54:19 | 00,157,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\verifier.dll
[2008/10/12 20:54:19 | 00,151,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_ssp_isv.dll
[2008/10/12 20:54:19 | 00,151,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_ssp.dll
[2008/10/12 20:54:19 | 00,146,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RstrtMgr.dll
[2008/10/12 20:54:19 | 00,131,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WPDShServiceObj.dll
[2008/10/12 20:54:19 | 00,097,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mprapi.dll
[2008/10/12 20:54:19 | 00,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\efsadu.dll
[2008/10/12 20:54:19 | 00,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\setupugc.exe
[2008/10/12 20:54:19 | 00,027,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\icacls.exe
[2008/10/12 20:54:18 | 01,123,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\usercpl.dll
[2008/10/12 20:54:18 | 00,925,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FXSRESM.dll
[2008/10/12 20:54:18 | 00,547,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wiaaut.dll
[2008/10/12 20:54:18 | 00,516,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\autoplay.dll
[2008/10/12 20:54:18 | 00,407,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dpapimig.exe
[2008/10/12 20:54:18 | 00,296,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xwizards.dll
[2008/10/12 20:54:18 | 00,284,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drmmgrtn.dll
[2008/10/12 20:54:18 | 00,208,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfplat.dll
[2008/10/12 20:54:18 | 00,193,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2008/10/12 20:54:18 | 00,160,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrdc.dll
[2008/10/12 20:54:18 | 00,134,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\p2pnetsh.dll
[2008/10/12 20:54:18 | 00,095,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactsrv.dll
[2008/10/12 20:54:18 | 00,088,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wiascanprofiles.dll
[2008/10/12 20:54:18 | 00,081,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\QSVRMGMT.DLL
[2008/10/12 20:54:18 | 00,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cmdl32.exe
[2008/10/12 20:54:18 | 00,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\conime.exe
[2008/10/12 20:54:18 | 00,065,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\resutils.dll
[2008/10/12 20:54:18 | 00,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pnrpnsp.dll
[2008/10/12 20:54:18 | 00,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\findstr.exe
[2008/10/12 20:54:18 | 00,045,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2008/10/12 20:54:18 | 00,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\eappprxy.dll
[2008/10/12 20:54:18 | 00,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdmo.dll
[2008/10/12 20:54:18 | 00,026,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pcadm.dll
[2008/10/12 20:54:18 | 00,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdtcVSp1res.dll
[2008/10/12 20:54:17 | 00,723,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\powercpl.dll
[2008/10/12 20:54:17 | 00,669,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netprof.dll
[2008/10/12 20:54:17 | 00,614,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MFWMAAEC.DLL
[2008/10/12 20:54:17 | 00,409,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbc32.dll
[2008/10/12 20:54:17 | 00,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\intl.cpl
[2008/10/12 20:54:17 | 00,294,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ssText3d.scr
[2008/10/12 20:54:17 | 00,219,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\apircl.dll
[2008/10/12 20:54:17 | 00,169,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\notepad.exe
[2008/10/12 20:54:17 | 00,167,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2008/10/12 20:54:17 | 00,164,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\VBICodec.ax
[2008/10/12 20:54:17 | 00,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dot3ui.dll
[2008/10/12 20:54:17 | 00,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dbnetlib.dll
[2008/10/12 20:54:17 | 00,134,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\regedit.exe
[2008/10/12 20:54:17 | 00,104,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWWIN.EXE
[2008/10/12 20:54:17 | 00,091,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\btpanui.dll
[2008/10/12 20:54:17 | 00,089,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\txflog.dll
[2008/10/12 20:54:17 | 00,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\taskkill.exe
[2008/10/12 20:54:17 | 00,064,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxva2.dll
[2008/10/12 20:54:17 | 00,058,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dfrgifc.exe
[2008/10/12 20:54:17 | 00,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\feclient.dll
[2008/10/12 20:54:17 | 00,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dssec.dll
[2008/10/12 20:54:17 | 00,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dwmapi.dll
[2008/10/12 20:54:17 | 00,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\nshhttp.dll
[2008/10/12 20:54:16 | 01,029,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10.dll
[2008/10/12 20:54:16 | 00,975,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RASMM.dll
[2008/10/12 20:54:16 | 00,777,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\slcc.dll
[2008/10/12 20:54:16 | 00,425,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\shwebsvc.dll
[2008/10/12 20:54:16 | 00,356,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MediaMetadataHandler.dll
[2008/10/12 20:54:16 | 00,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msieftp.dll
[2008/10/12 20:54:16 | 00,191,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\provthrd.dll
[2008/10/12 20:54:16 | 00,175,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\syncui.dll
[2008/10/12 20:54:16 | 00,167,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ActionQueue.dll
[2008/10/12 20:54:16 | 00,148,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\appmgmts.dll
[2008/10/12 20:54:16 | 00,137,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SLCExt.dll
[2008/10/12 20:54:16 | 00,067,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EAPQEC.DLL
[2008/10/12 20:54:16 | 00,042,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dmocx.dll
[2008/10/12 20:54:16 | 00,035,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\slwmi.dll
[2008/10/12 20:54:16 | 00,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\svchost.exe
[2008/10/12 20:54:15 | 02,226,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\networkexplorer.dll
[2008/10/12 20:54:15 | 01,645,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\connect.dll
[2008/10/12 20:54:15 | 00,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMASF.DLL
[2008/10/12 20:54:15 | 00,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\raserver.exe
[2008/10/12 20:54:15 | 00,127,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\aclui.dll
[2008/10/12 20:54:15 | 00,088,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\olepro32.dll
[2008/10/12 20:54:14 | 00,368,640 | ---- | C] () -- C:\Windows\System32\msjetoledb40.dll
[2008/10/12 20:54:14 | 00,244,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\audiodev.dll
[2008/10/12 20:54:14 | 00,195,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\upnp.dll
[2008/10/12 20:54:14 | 00,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\taskmgr.exe
[2008/10/12 20:54:14 | 00,142,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\icsfiltr.dll
[2008/10/12 20:54:14 | 00,127,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mmcshext.dll
[2008/10/12 20:54:14 | 00,103,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\AuxiliaryDisplayApi.dll
[2008/10/12 20:54:14 | 00,087,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msoert2.dll
[2008/10/12 20:54:14 | 00,084,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cmstp.exe
[2008/10/12 20:54:14 | 00,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wlanext.exe
[2008/10/12 20:54:14 | 00,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\atl.dll
[2008/10/12 20:54:14 | 00,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\QCLIPROV.DLL
[2008/10/12 20:54:14 | 00,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\reg.exe
[2008/10/12 20:54:14 | 00,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NapiNSP.dll
[2008/10/12 20:54:14 | 00,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xcopy.exe
[2008/10/12 20:54:14 | 00,025,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dnscacheugc.exe
[2008/10/12 20:54:14 | 00,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ias.dll
[2008/10/12 20:54:14 | 00,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\perfts.dll
[2008/10/12 20:54:14 | 00,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mountvol.exe
[2008/10/12 20:54:13 | 00,767,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMVSENCD.DLL
[2008/10/12 20:54:13 | 00,657,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMVXENCD.DLL
[2008/10/12 20:54:13 | 00,616,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dsuiext.dll
[2008/10/12 20:54:13 | 00,310,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmpdxm.dll
[2008/10/12 20:54:13 | 00,225,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cewmdm.dll
[2008/10/12 20:54:13 | 00,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscandui.dll
[2008/10/12 20:54:13 | 00,208,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qasf.dll
[2008/10/12 20:54:13 | 00,192,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qcap.dll
[2008/10/12 20:54:13 | 00,192,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\bitsadmin.exe
[2008/10/12 20:54:13 | 00,190,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dskquoui.dll
[2008/10/12 20:54:13 | 00,184,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmpsrcwp.dll
[2008/10/12 20:54:13 | 00,180,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netplwiz.dll
[2008/10/12 20:54:13 | 00,153,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sbeio.dll
[2008/10/12 20:54:13 | 00,153,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
[2008/10/12 20:54:13 | 00,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ndfapi.dll
[2008/10/12 20:54:13 | 00,128,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\shimgvw.dll
[2008/10/12 20:54:13 | 00,124,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mtstocom.exe
[2008/10/12 20:54:13 | 00,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dmusic.dll
[2008/10/12 20:54:13 | 00,098,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\makecab.exe
[2008/10/12 20:54:13 | 00,095,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xwtpw32.dll
[2008/10/12 20:54:13 | 00,076,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\adsmsext.dll
[2008/10/12 20:54:13 | 00,052,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetmib1.dll
[2008/10/12 20:54:13 | 00,047,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Sens.dll
[2008/10/12 20:54:13 | 00,043,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dot3gpclnt.dll
[2008/10/12 20:54:13 | 00,042,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rekeywiz.exe
[2008/10/12 20:54:13 | 00,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\auditpol.exe
[2008/10/12 20:54:13 | 00,040,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FXSEXT32.dll
[2008/10/12 20:54:13 | 00,035,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SecEdit.exe
[2008/10/12 20:54:13 | 00,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapp.exe
[2008/10/12 20:54:13 | 00,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\httpapi.dll
[2008/10/12 20:54:13 | 00,019,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\lsmproxy.dll
[2008/10/12 20:54:13 | 00,015,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PING.EXE
[2008/10/12 20:54:12 | 01,329,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMSPDMOE.DLL
[2008/10/12 20:54:12 | 00,443,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wiashext.dll
[2008/10/12 20:54:12 | 00,415,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wiadefui.dll
[2008/10/12 20:54:12 | 00,317,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MP4SDECD.DLL
[2008/10/12 20:54:12 | 00,214,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2008/10/12 20:54:12 | 00,203,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wpdwcn.dll
[2008/10/12 20:54:12 | 00,198,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\apss.dll
[2008/10/12 20:54:12 | 00,180,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msorcl32.dll
[2008/10/12 20:54:12 | 00,159,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdadiag.dll
[2008/10/12 20:54:12 | 00,157,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\keymgr.dll
[2008/10/12 20:54:12 | 00,151,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\notepad.exe
[2008/10/12 20:54:12 | 00,120,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\perfmon.exe
[2008/10/12 20:54:12 | 00,119,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\prntvpt.dll
[2008/10/12 20:54:12 | 00,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msscript.ocx
[2008/10/12 20:54:12 | 00,098,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TapiMigPlugin.dll
[2008/10/12 20:54:12 | 00,081,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\shacct.dll
[2008/10/12 20:54:12 | 00,080,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tasklist.exe
[2008/10/12 20:54:12 | 00,070,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wzcdlg.dll
[2008/10/12 20:54:12 | 00,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\HelpPaneProxy.dll
[2008/10/12 20:54:12 | 00,056,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wscmisetup.dll
[2008/10/12 20:54:12 | 00,053,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rrinstaller.exe
[2008/10/12 20:54:12 | 00,051,712 | ---- | C] (Microsoft) -- C:\Windows\System32\esrb.rs
[2008/10/12 20:54:12 | 00,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ftp.exe
[2008/10/12 20:54:12 | 00,037,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\printcom.dll
[2008/10/12 20:54:12 | 00,034,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\napipsec.dll
[2008/10/12 20:54:12 | 00,027,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sxstrace.exe
[2008/10/12 20:54:12 | 00,025,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\userinit.exe
[2008/10/12 20:54:12 | 00,023,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups.dll
[2008/10/12 20:54:12 | 00,022,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winrshost.exe
[2008/10/12 20:54:12 | 00,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ktmutil.exe
[2008/10/12 20:54:11 | 00,816,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dim700.dll
[2008/10/12 20:54:11 | 00,686,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\colorui.dll
[2008/10/12 20:54:11 | 00,442,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\joy.cpl
[2008/10/12 20:54:11 | 00,396,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\shrpubw.exe
[2008/10/12 20:54:11 | 00,376,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rasplap.dll
[2008/10/12 20:54:11 | 00,352,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\nshipsec.dll
[2008/10/12 20:54:11 | 00,346,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WindowsCodecsExt.dll
[2008/10/12 20:54:11 | 00,280,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\unimdm.tsp
[2008/10/12 20:54:11 | 00,220,672 | ---- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) -- C:\Windows\System32\l3codecp.acm
[2008/10/12 20:54:11 | 00,216,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RESAMPLEDMO.DLL
[2008/10/12 20:54:11 | 00,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIAutomationCore.dll
[2008/10/12 20:54:11 | 00,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ksproxy.ax
[2008/10/12 20:54:11 | 00,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imapi.dll
[2008/10/12 20:54:11 | 00,101,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\luainstall.dll
[2008/10/12 20:54:11 | 00,098,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfps.dll
[2008/10/12 20:54:11 | 00,097,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\powrprof.dll
[2008/10/12 20:54:11 | 00,094,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\logagent.exe
[2008/10/12 20:54:11 | 00,093,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2008/10/12 20:54:11 | 00,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\olecli32.dll
[2008/10/12 20:54:11 | 00,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msiexec.exe
[2008/10/12 20:54:11 | 00,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sendmail.dll
[2008/10/12 20:54:11 | 00,064,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\findnetprinters.dll
[2008/10/12 20:54:11 | 00,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winethc.dll
[2008/10/12 20:54:11 | 00,057,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cryptdll.dll
[2008/10/12 20:54:11 | 00,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fsutil.exe
[2008/10/12 20:54:11 | 00,051,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\takeown.exe
[2008/10/12 20:54:11 | 00,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dnshc.dll
[2008/10/12 20:54:11 | 00,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sfc_os.dll
[2008/10/12 20:54:11 | 00,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msimtf.dll
[2008/10/12 20:54:11 | 00,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfpmp.exe
[2008/10/12 20:54:11 | 00,023,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmiprop.dll
[2008/10/12 20:54:11 | 00,023,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fmifs.dll
[2008/10/12 20:54:11 | 00,022,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netiougc.exe
[2008/10/12 20:54:11 | 00,019,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\perfnet.dll
[2008/10/12 20:54:11 | 00,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\capisp.dll
[2008/10/12 20:54:11 | 00,016,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pots.dll
[2008/10/12 20:54:11 | 00,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\txfw32.dll
[2008/10/12 20:54:11 | 00,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wscproxystub.dll
[2008/10/12 20:54:10 | 01,298,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TMM.dll
[2008/10/12 20:54:10 | 01,118,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMADMOE.DLL
[2008/10/12 20:54:10 | 00,384,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dim.dll
[2008/10/12 20:54:10 | 00,310,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\unregmp2.exe
[2008/10/12 20:54:10 | 00,276,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\compstui.dll
[2008/10/12 20:54:10 | 00,259,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MPG4DECD.DLL
[2008/10/12 20:54:10 | 00,259,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MP43DECD.DLL
[2008/10/12 20:54:10 | 00,205,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mdminst.dll
[2008/10/12 20:54:10 | 00,123,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msvfw32.dll
[2008/10/12 20:54:10 | 00,120,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WLanHC.dll
[2008/10/12 20:54:10 | 00,088,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wiaacmgr.exe
[2008/10/12 20:54:10 | 00,068,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\shgina.dll
[2008/10/12 20:54:10 | 00,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\w32tm.exe
[2008/10/12 20:54:10 | 00,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\getmac.exe
[2008/10/12 20:54:10 | 00,064,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2008/10/12 20:54:10 | 00,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cmmon32.exe
[2008/10/12 20:54:10 | 00,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\net.exe
[2008/10/12 20:54:10 | 00,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rshx32.dll
[2008/10/12 20:54:10 | 00,038,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\runonce.exe
[2008/10/12 20:54:10 | 00,036,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2008/10/12 20:54:10 | 00,035,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dimsjob.dll
[2008/10/12 20:54:10 | 00,034,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RpcPing.exe
[2008/10/12 20:54:10 | 00,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cmlua.dll
[2008/10/12 20:54:10 | 00,029,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dsauth.dll
[2008/10/12 20:54:10 | 00,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\gpscript.dll
[2008/10/12 20:54:10 | 00,024,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\gpscript.exe
[2008/10/12 20:54:10 | 00,020,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\version.dll
[2008/10/12 20:54:10 | 00,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ktmw32.dll
[2008/10/12 20:54:09 | 01,370,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Aurora.scr
[2008/10/12 20:54:09 | 00,368,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\desk.cpl
[2008/10/12 20:54:09 | 00,287,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\modemui.dll
[2008/10/12 20:54:09 | 00,178,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\credui.dll
[2008/10/12 20:54:09 | 00,159,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dinput8.dll
[2008/10/12 20:54:09 | 00,154,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmidx.dll
[2008/10/12 20:54:09 | 00,125,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\softkbd.dll
[2008/10/12 20:54:09 | 00,124,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceWiaCompat.dll
[2008/10/12 20:54:09 | 00,101,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmpshell.dll
[2008/10/12 20:54:09 | 00,095,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\migisol.dll
[2008/10/12 20:54:09 | 00,094,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\diantz.exe
[2008/10/12 20:54:09 | 00,091,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\comrepl.dll
[2008/10/12 20:54:09 | 00,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TpmInit.exe
[2008/10/12 20:54:09 | 00,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\hlink.dll
[2008/10/12 20:54:09 | 00,082,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sdchange.exe
[2008/10/12 20:54:09 | 00,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ACW.exe
[2008/10/12 20:54:09 | 00,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tdc.ocx
[2008/10/12 20:54:09 | 00,063,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tscupgrd.exe
[2008/10/12 20:54:09 | 00,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\colbact.dll
[2008/10/12 20:54:09 | 00,058,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\remotepg.dll
[2008/10/12 20:54:09 | 00,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fwcfg.dll
[2008/10/12 20:54:09 | 00,053,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fdeploy.dll
[2008/10/12 20:54:09 | 00,052,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\expand.exe
[2008/10/12 20:54:09 | 00,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\nlaapi.dll
[2008/10/12 20:54:09 | 00,047,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cmutil.dll
[2008/10/12 20:54:09 | 00,047,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cfgbkend.dll
[2008/10/12 20:54:09 | 00,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pdhui.dll
[2008/10/12 20:54:09 | 00,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TSTheme.exe
[2008/10/12 20:54:09 | 00,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WPDShextAutoplay.exe
[2008/10/12 20:54:09 | 00,029,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\utildll.dll
[2008/10/12 20:54:09 | 00,026,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ipconfig.exe
[2008/10/12 20:54:09 | 00,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ExplorerFrame.dll
[2008/10/12 20:54:09 | 00,015,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sfc.exe
[2008/10/12 20:54:09 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdxm.ocx
[2008/10/12 20:54:09 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxmasf.dll
[2008/10/12 20:54:08 | 00,879,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Bubbles.scr
[2008/10/12 20:54:08 | 00,376,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dpnet.dll
[2008/10/12 20:54:08 | 00,281,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qdv.dll
[2008/10/12 20:54:08 | 00,251,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sti_ci.dll
[2008/10/12 20:54:08 | 00,221,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Mystify.scr
[2008/10/12 20:54:08 | 00,220,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Ribbons.scr
[2008/10/12 20:54:08 | 00,161,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\COLORCNV.DLL
[2008/10/12 20:54:08 | 00,160,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DpiScaling.exe
[2008/10/12 20:54:08 | 00,153,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmvdspa.dll
[2008/10/12 20:54:08 | 00,114,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbccp32.dll
[2008/10/12 20:54:08 | 00,105,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dmsynth.dll
[2008/10/12 20:54:08 | 00,093,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\esentutl.exe
[2008/10/12 20:54:08 | 00,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\bootcfg.exe
[2008/10/12 20:54:08 | 00,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FXSCOM.dll
[2008/10/12 20:54:08 | 00,077,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\olethk32.dll
[2008/10/12 20:54:08 | 00,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
[2008/10/12 20:54:08 | 00,070,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\amstream.dll
[2008/10/12 20:54:08 | 00,064,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iscsiwmi.dll
[2008/10/12 20:54:08 | 00,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfvdsp.dll
[2008/10/12 20:54:08 | 00,056,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\logman.exe
[2008/10/12 20:54:08 | 00,052,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2008/10/12 20:54:08 | 00,050,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wsnmp32.dll
[2008/10/12 20:54:08 | 00,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2008/10/12 20:54:08 | 00,042,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\osblprov.dll
[2008/10/12 20:54:08 | 00,037,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vds_ps.dll
[2008/10/12 20:54:08 | 00,034,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\waitfor.exe
[2008/10/12 20:54:08 | 00,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cmcfg32.dll
[2008/10/12 20:54:08 | 00,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\werdiagcontroller.dll
[2008/10/12 20:54:08 | 00,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdrleakdiag.exe
[2008/10/12 20:54:08 | 00,029,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\shutdown.exe
[2008/10/12 20:54:08 | 00,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iscsium.dll
[2008/10/12 20:54:08 | 00,027,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\olesvr32.dll
[2008/10/12 20:54:08 | 00,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cacls.exe
[2008/10/12 20:54:08 | 00,022,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmpcm.dll
[2008/10/12 20:54:08 | 00,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wfapigp.dll
[2008/10/12 20:54:07 | 00,509,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\AuthFWGP.dll
[2008/10/12 20:54:07 | 00,282,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstext40.dll
[2008/10/12 20:54:07 | 00,222,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wavemsp.dll
[2008/10/12 20:54:07 | 00,163,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\powercfg.cpl
[2008/10/12 20:54:07 | 00,159,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbctrac.dll
[2008/10/12 20:54:07 | 00,151,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rgb9rast.dll
[2008/10/12 20:54:07 | 00,141,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\itss.dll
[2008/10/12 20:54:07 | 00,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\setupcln.dll
[2008/10/12 20:54:07 | 00,095,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mobsync.exe
[2008/10/12 20:54:07 | 00,092,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ufat.dll
[2008/10/12 20:54:07 | 00,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dskquota.dll
[2008/10/12 20:54:07 | 00,084,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msctfui.dll
[2008/10/12 20:54:07 | 00,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\GuidedHelp.dll
[2008/10/12 20:54:07 | 00,052,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rasdiag.dll
[2008/10/12 20:54:07 | 00,050,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fphc.dll
[2008/10/12 20:54:07 | 00,045,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshta.exe
[2008/10/12 20:54:07 | 00,043,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TimeDateMUICallback.dll
[2008/10/12 20:54:07 | 00,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2008/10/12 20:54:07 | 00,040,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegCtrl.dll
[2008/10/12 20:54:07 | 00,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\networkitemfactory.dll
[2008/10/12 20:54:07 | 00,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ocsetup.exe
[2008/10/12 20:54:07 | 00,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\unattendedjoin.exe
[2008/10/12 20:54:07 | 00,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sxproxy.dll
[2008/10/12 20:54:07 | 00,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\AtBroker.exe
[2008/10/12 20:54:07 | 00,026,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\prevhost.exe
[2008/10/12 20:54:07 | 00,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\at.exe
[2008/10/12 20:54:07 | 00,022,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cscdll.dll
[2008/10/12 20:54:07 | 00,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netbtugc.exe
[2008/10/12 20:54:07 | 00,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\convert.exe
[2008/10/12 20:54:07 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xmlprovi.dll
[2008/10/12 20:54:07 | 00,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tbs.dll
[2008/10/12 20:54:07 | 00,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iscsied.dll
[2008/10/12 20:54:06 | 05,714,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\logon.scr
[2008/10/12 20:54:06 | 00,344,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msexcl40.dll
[2008/10/12 20:54:06 | 00,246,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\VIDRESZR.DLL
[2008/10/12 20:54:06 | 00,178,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dmime.dll
[2008/10/12 20:54:06 | 00,173,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dsdmo.dll
[2008/10/12 20:54:06 | 00,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mydocs.dll
[2008/10/12 20:54:06 | 00,126,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdart.dll
[2008/10/12 20:54:06 | 00,083,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\usbui.dll
[2008/10/12 20:54:06 | 00,077,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbccu32.dll
[2008/10/12 20:54:06 | 00,077,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbccr32.dll
[2008/10/12 20:54:06 | 00,072,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wpclsp.dll
[2008/10/12 20:54:06 | 00,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\kstvtune.ax
[2008/10/12 20:54:06 | 00,067,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\napdsnap.dll
[2008/10/12 20:54:06 | 00,064,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\devenum.dll
[2008/10/12 20:54:06 | 00,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vfwwdm32.dll
[2008/10/12 20:54:06 | 00,053,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\l2gpstore.dll
[2008/10/12 20:54:06 | 00,053,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msident.dll
[2008/10/12 20:54:06 | 00,045,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dot3dlg.dll
[2008/10/12 20:54:06 | 00,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\regini.exe
[2008/10/12 20:54:06 | 00,039,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rasphone.exe
[2008/10/12 20:54:06 | 00,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbcbcp.dll
[2008/10/12 20:54:06 | 00,027,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\syskey.exe
[2008/10/12 20:54:06 | 00,027,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mtxlegih.dll
[2008/10/12 20:54:06 | 00,026,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfcsubs.dll
[2008/10/12 20:54:06 | 00,026,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vss_ps.dll
[2008/10/12 20:54:06 | 00,026,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cmpbk32.dll
[2008/10/12 20:54:06 | 00,024,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\amxread.dll
[2008/10/12 20:54:06 | 00,022,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\upnpcont.exe
[2008/10/12 20:54:06 | 00,022,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mtxdm.dll
[2008/10/12 20:54:06 | 00,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msacm32.drv
[2008/10/12 20:54:06 | 00,020,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RacAgent.exe
[2008/10/12 20:54:06 | 00,019,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MsCtfMonitor.dll
[2008/10/12 20:54:06 | 00,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netevent.dll
[2008/10/12 20:54:06 | 00,016,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WINSRPC.DLL
[2008/10/12 20:54:06 | 00,016,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\gpupdate.exe
[2008/10/12 20:54:06 | 00,015,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wsock32.dll
[2008/10/12 20:54:06 | 00,015,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\nbtstat.exe
[2008/10/12 20:54:06 | 00,014,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winnsi.dll
[2008/10/12 20:54:06 | 00,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cmstplua.dll
[2008/10/12 20:54:06 | 00,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\apilogen.dll
[2008/10/12 20:54:06 | 00,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\avrt.dll
[2008/10/12 20:54:06 | 00,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\nsi.dll
[2008/10/12 20:54:05 | 00,450,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msxbde40.dll
[2008/10/12 20:54:05 | 00,376,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mspbde40.dll
[2008/10/12 20:54:05 | 00,245,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msltus40.dll
[2008/10/12 20:54:05 | 00,112,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wiadss.dll
[2008/10/12 20:54:05 | 00,084,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MP3DMOD.DLL
[2008/10/12 20:54:05 | 00,084,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dmscript.dll
[2008/10/12 20:54:05 | 00,053,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\extrac32.exe
[2008/10/12 20:54:05 | 00,053,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dxof.dll
[2008/10/12 20:54:05 | 00,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ksxbar.ax
[2008/10/12 20:54:05 | 00,041,472 | ---- | C] (Microsoft) -- C:\Windows\System32\WlanMmHC.dll
[2008/10/12 20:54:05 | 00,040,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psbase.dll
[2008/10/12 20:54:05 | 00,038,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dmloader.dll
[2008/10/12 20:54:05 | 00,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wshcon.dll
[2008/10/12 20:54:05 | 00,029,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ndfetw.dll
[2008/10/12 20:54:05 | 00,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Netplwiz.exe
[2008/10/12 20:54:05 | 00,019,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\eventcls.dll
[2008/10/12 20:54:05 | 00,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ROUTE.EXE
[2008/10/12 20:54:05 | 00,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PlaySndSrv.dll
[2008/10/12 20:54:05 | 00,015,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\credssp.dll
[2008/10/12 20:54:05 | 00,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\icsunattend.exe
[2008/10/12 20:54:05 | 00,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dmdskres2.dll
[2008/10/12 20:54:04 | 00,097,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\OptionalFeatures.exe
[2008/10/12 20:54:04 | 00,060,124 | ---- | C] () -- C:\Windows\System32\tcpmon.ini
[2008/10/12 20:54:04 | 00,045,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\g711codc.ax
[2008/10/12 20:54:04 | 00,036,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ComputerDefaults.exe
[2008/10/12 20:54:04 | 00,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbisurf.ax
[2008/10/12 20:54:04 | 00,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msvidc32.dll
[2008/10/12 20:54:04 | 00,022,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sxsstore.dll
[2008/10/12 20:54:04 | 00,019,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NcdProp.dll
[2008/10/12 20:54:04 | 00,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dmutil.dll
[2008/10/12 20:54:04 | 00,015,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spopk.dll
[2008/10/12 20:54:04 | 00,015,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\serialui.dll
[2008/10/12 20:54:04 | 00,014,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\fveupdate.exe
[2008/10/12 20:54:04 | 00,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\localui.dll
[2008/10/12 20:54:04 | 00,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WsmRes.dll
[2008/10/12 20:54:04 | 00,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\setupSNK.exe
[2008/10/12 20:54:04 | 00,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\slwga.dll
[2008/10/12 20:54:04 | 00,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sbunattend.exe
[2008/10/12 20:54:04 | 00,011,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\usbperf.dll
[2008/10/12 20:54:04 | 00,009,987 | ---- | C] () -- C:\Windows\System32\RacUR.xml
[2008/10/12 20:54:04 | 00,009,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WSHTCPIP.DLL
[2008/10/12 20:54:04 | 00,009,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wship6.dll
[2008/10/12 20:54:03 | 00,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2008/10/12 20:54:03 | 00,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieencode.dll
[2008/10/12 20:54:03 | 00,062,464 | ---- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) -- C:\Windows\System32\l3codeca.acm
[2008/10/12 20:54:03 | 00,058,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msobjs.dll
[2008/10/12 20:54:03 | 00,040,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbcconf.dll
[2008/10/12 20:54:03 | 00,040,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\hbaapi.dll
[2008/10/12 20:54:03 | 00,036,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\esentprf.dll
[2008/10/12 20:54:03 | 00,027,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WinFax.dll
[2008/10/12 20:54:03 | 00,027,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wsepno.dll
[2008/10/12 20:54:03 | 00,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vdmdbg.dll
[2008/10/12 20:54:03 | 00,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\midimap.dll
[2008/10/12 20:54:03 | 00,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\corpol.dll
[2008/10/12 20:54:03 | 00,015,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rasctrs.dll
[2008/10/12 20:54:03 | 00,014,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\hnetmon.dll
[2008/10/12 20:54:03 | 00,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2008/10/12 20:54:03 | 00,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\InfDefaultInstall.exe
[2008/10/12 20:54:03 | 00,009,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\LogonUI.exe
[2008/10/12 20:54:03 | 00,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iprtprio.dll
[2008/10/12 20:54:02 | 00,019,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\osbaseln.dll
[2008/10/12 20:54:02 | 00,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cfgmgr32.dll
[2008/10/12 20:54:01 | 00,057,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\nlsbres.dll
[2008/10/12 20:54:01 | 00,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dispex.dll
[2008/10/12 20:54:01 | 00,019,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msisip.dll
[2008/10/12 20:54:01 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winusb.dll
[2008/10/12 20:53:59 | 00,026,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\idndl.dll
[2008/10/12 20:53:59 | 00,025,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Nlsdl.dll
[2008/10/12 20:53:59 | 00,008,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msidle.dll
[2008/10/12 20:53:59 | 00,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\riched32.dll
[2008/10/12 20:53:59 | 00,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spwmp.dll
[2008/10/12 20:53:58 | 08,147,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmploc.DLL
[2008/10/12 20:53:58 | 00,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tsddd.dll
[2008/10/12 20:53:58 | 00,011,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDJPN.DLL
[2008/10/12 20:53:58 | 00,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDKOR.DLL
[2008/10/12 20:53:58 | 00,001,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WsmCl.dll
[2008/10/12 20:53:57 | 00,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spwizres.dll
[2008/10/12 20:53:57 | 00,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\f3ahvoas.dll
[2008/10/12 20:53:57 | 00,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wertargets.wtl
[2008/10/12 20:53:56 | 00,144,909 | ---- | C] () -- C:\Windows\System32\fsmgmt.msc
[2008/10/12 20:53:56 | 00,000,150 | ---- | C] () -- C:\Windows\System32\RacUREx.xml
[2008/10/12 20:53:55 | 00,145,455 | ---- | C] () -- C:\Windows\System32\perfmon.msc
[2008/10/12 20:53:46 | 00,183,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xmllite.dll
[2008/10/12 20:53:43 | 00,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wdscore.dll
[2008/10/12 20:53:40 | 00,305,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdelta.dll
[2008/10/12 20:53:40 | 00,258,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dpx.dll
[2008/10/12 20:53:40 | 00,246,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drvstore.dll
[2008/10/12 20:53:40 | 00,035,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mspatcha.dll
[2008/10/12 20:53:39 | 00,357,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wbemcomn.dll
[2008/10/12 20:10:30 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Works
[2008/10/12 20:10:17 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio
[2008/10/12 20:10:17 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2008/10/12 20:10:06 | 00,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2008/10/12 20:10:06 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
[2008/10/12 20:08:29 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 8
[2008/10/12 20:07:45 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Local\Microsoft Help
[2008/10/12 20:07:43 | 00,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2008/10/12 20:07:43 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
[2008/10/12 20:07:20 | 00,000,000 | RH-D | C] -- C:\MSOCache
[2008/10/12 20:03:32 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Local\MigWiz
[2008/10/12 19:51:32 | 00,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
[2008/10/12 19:51:32 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Kaspersky Lab
[2008/10/12 19:50:39 | 00,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab Setup Files
[2008/10/12 19:45:21 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Games
[2008/10/12 19:43:02 | 03,851,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_39.dll
[2008/10/12 19:42:33 | 00,678,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\gpprefcl.dll
[2008/10/12 19:41:39 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight
[2008/10/12 19:41:36 | 00,000,000 | -HSD | C] -- C:\Windows\Installer
[2008/10/12 19:24:05 | 00,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\kbd106n.dll
[2008/10/12 19:24:04 | 00,040,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\srclient.dll
[2008/10/12 19:23:11 | 00,269,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\es.dll
[2008/10/12 19:08:45 | 00,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2008/10/12 19:07:03 | 42,933,86240 | -HS- | C] () -- C:\hiberfil.sys
[2008/10/12 19:04:57 | 01,623,765 | -H-- | C] () -- C:\Users\XXXX\AppData\Local\IconCache.db
[2008/10/12 19:02:45 | 11,580,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\shell32.dll
[2008/10/12 18:55:41 | 00,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Apphlpdm.dll
[2008/10/12 18:55:40 | 04,240,384 | ---- | C] (Microsoft) -- C:\Windows\System32\GameUXLegacyGDFs.dll
[2008/10/12 18:55:40 | 01,695,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\gameux.dll
[2008/10/12 18:50:36 | 01,808,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0046.dll
[2008/10/12 18:50:36 | 01,793,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0045.dll
[2008/10/12 18:50:36 | 01,411,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0047.dll
[2008/10/12 18:50:35 | 07,964,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0024.dll
[2008/10/12 18:50:35 | 05,791,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0026.dll
[2008/10/12 18:50:35 | 05,499,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0022.dll
[2008/10/12 18:50:35 | 02,136,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0021.dll
[2008/10/12 18:50:35 | 01,782,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0039.dll
[2008/10/12 18:50:35 | 01,558,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0049.dll
[2008/10/12 18:50:35 | 01,236,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0020.dll
[2008/10/12 18:50:34 | 06,781,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0019.dll
[2008/10/12 18:50:34 | 06,224,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0027.dll
[2008/10/12 18:50:34 | 04,981,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0013.dll
[2008/10/12 18:50:34 | 04,175,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0010.dll
[2008/10/12 18:50:34 | 03,331,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0018.dll
[2008/10/12 18:50:34 | 02,466,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0011.dll
[2008/10/12 18:50:33 | 12,240,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0007.dll
[2008/10/12 18:50:33 | 11,722,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0001.dll
[2008/10/12 18:50:33 | 04,164,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0002.dll
[2008/10/12 18:50:33 | 01,452,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0003.dll
[2008/10/12 18:50:32 | 06,014,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons001a.dll
[2008/10/12 18:50:32 | 04,093,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons004c.dll
[2008/10/12 18:50:32 | 04,045,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons003e.dll
[2008/10/12 18:50:32 | 03,419,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons004a.dll
[2008/10/12 18:50:32 | 02,644,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0009.dll
[2008/10/12 18:50:32 | 01,972,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons004e.dll
[2008/10/12 18:50:32 | 01,702,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons004b.dll
[2008/10/12 18:50:32 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons002a.dll
[2008/10/12 18:50:31 | 09,892,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons000a.dll
[2008/10/12 18:50:31 | 06,585,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons001b.dll
[2008/10/12 18:50:31 | 06,346,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons001d.dll
[2008/10/12 18:50:31 | 06,237,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons000c.dll
[2008/10/12 18:50:30 | 05,654,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons000f.dll
[2008/10/12 18:50:30 | 05,090,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0416.dll
[2008/10/12 18:50:30 | 05,031,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0816.dll
[2008/10/12 18:50:30 | 04,616,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0414.dll
[2008/10/12 18:50:30 | 01,722,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons000d.dll
[2008/10/12 18:50:29 | 07,042,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons081a.dll
[2008/10/12 18:50:29 | 05,071,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsModels0011.dll
[2008/10/12 18:50:29 | 03,104,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData0049.dll
[2008/10/12 18:50:29 | 03,104,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData0047.dll
[2008/10/12 18:50:29 | 03,104,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData0046.dll
[2008/10/12 18:50:29 | 03,104,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData0045.dll
[2008/10/12 18:50:29 | 03,104,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData0039.dll
[2008/10/12 18:50:28 | 04,495,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData0010.dll
[2008/10/12 18:50:28 | 03,104,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData0020.dll
[2008/10/12 18:50:28 | 01,966,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData0027.dll
[2008/10/12 18:50:28 | 01,965,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData0026.dll
[2008/10/12 18:50:28 | 01,965,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData0024.dll
[2008/10/12 18:50:28 | 01,801,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData0022.dll
[2008/10/12 18:50:28 | 01,801,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData0021.dll
[2008/10/12 18:50:27 | 04,497,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData0019.dll
[2008/10/12 18:50:27 | 03,466,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData0013.dll
[2008/10/12 18:50:27 | 02,657,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData0011.dll
[2008/10/12 18:50:27 | 02,599,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData0001.dll
[2008/10/12 18:50:27 | 01,965,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData0018.dll
[2008/10/12 18:50:27 | 01,965,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData0002.dll
[2008/10/12 18:50:27 | 01,523,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData0000.dll
[2008/10/12 18:50:26 | 04,875,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData0009.dll
[2008/10/12 18:50:26 | 03,104,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData004c.dll
[2008/10/12 18:50:26 | 03,104,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData004b.dll
[2008/10/12 18:50:26 | 03,104,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData004a.dll
[2008/10/12 18:50:26 | 02,243,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData0007.dll
[2008/10/12 18:50:26 | 01,965,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData0003.dll
[2008/10/12 18:50:25 | 04,495,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData001d.dll
[2008/10/12 18:50:25 | 03,104,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData004e.dll
[2008/10/12 18:50:25 | 01,965,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData001b.dll
[2008/10/12 18:50:25 | 01,965,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData001a.dll
[2008/10/12 18:50:25 | 01,801,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData003e.dll
[2008/10/12 18:50:25 | 01,801,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData002a.dll
[2008/10/12 18:50:24 | 09,847,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData000a.dll
[2008/10/12 18:50:24 | 04,495,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData0416.dll
[2008/10/12 18:50:24 | 04,495,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData0414.dll
[2008/10/12 18:50:24 | 02,643,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData000c.dll
[2008/10/12 18:50:24 | 02,342,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData000d.dll
[2008/10/12 18:50:24 | 01,965,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData000f.dll
[2008/10/12 18:50:24 | 00,801,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NaturalLanguage6.dll
[2008/10/12 18:50:23 | 06,917,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0c1a.dll
[2008/10/12 18:50:23 | 04,495,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData0816.dll
[2008/10/12 18:50:23 | 01,965,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData0c1a.dll
[2008/10/12 18:50:23 | 01,965,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData081a.dll
[2008/10/12 18:47:51 | 00,001,820 | ---- | C] () -- C:\Windows\System32\rasctrnm.h
[2008/10/12 18:47:18 | 00,738,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcomm.dll
[2008/10/12 18:47:18 | 00,084,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\INETRES.dll
[2008/10/12 18:46:13 | 00,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2008/10/12 18:45:30 | 00,272,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\polstore.dll
[2008/10/12 18:45:30 | 00,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winipsec.dll
[2008/10/12 18:45:30 | 00,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FwRemoteSvr.dll
[2008/10/12 18:44:05 | 00,302,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\gdi32.dll
[2008/10/12 18:41:53 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Local\WindowsUpdate
[2008/10/12 18:40:08 | 00,053,248 | ---- | C] (Windows XP Bundled build C-Centric Single User) -- C:\Windows\System32\CSVer.dll
[2008/10/12 18:40:08 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Intel
[2008/10/12 18:39:59 | 00,000,000 | ---D | C] -- C:\Intel
[2008/10/12 18:37:04 | 00,303,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmpeffects.dll
[2008/10/12 18:35:40 | 02,455,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2008/10/12 18:35:29 | 00,056,483 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2008/10/12 18:35:28 | 00,180,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2008/10/12 18:34:24 | 00,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Mpeg2Data.ax
[2008/10/12 18:34:24 | 00,057,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSDvbNP.ax
[2008/10/12 18:33:55 | 00,014,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wshrm.dll
[2008/10/12 18:33:30 | 01,314,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\quartz.dll
[2008/10/12 18:22:32 | 00,099,880 | ---- | C] () -- C:\Users\XXXX\AppData\Local\GDIPFONTCACHEV1.DAT
[2008/10/12 18:22:25 | 00,000,402 | -HS- | C] () -- C:\Users\XXXX\Documents\desktop.ini
[2008/10/12 18:22:25 | 00,000,282 | -HS- | C] () -- C:\Users\XXXX\Desktop\desktop.ini
[2008/10/12 18:22:25 | 00,000,174 | -HS- | C] () -- C:\Users\XXXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
[2008/10/12 18:22:15 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Roaming\Identities
[2008/10/12 18:22:10 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Local\VirtualStore
[2008/10/12 18:22:07 | 00,000,732 | ---- | C] () -- C:\Users\XXXX\AppData\Local\d3d9caps64.dat
[2008/10/12 18:22:05 | 00,000,000 | -HSD | C] -- C:\Users\XXXX\Documents\My Videos
[2008/10/12 18:22:05 | 00,000,000 | -HSD | C] -- C:\Users\XXXX\Documents\My Pictures
[2008/10/12 18:22:05 | 00,000,000 | -HSD | C] -- C:\Users\XXXX\Documents\My Music
[2008/10/12 18:22:05 | 00,000,000 | -HSD | C] -- C:\Users\XXXX\AppData\Local\Temporary Internet Files
[2008/10/12 18:22:05 | 00,000,000 | -HSD | C] -- C:\Users\XXXX\AppData\Local\History
[2008/10/12 18:22:05 | 00,000,000 | -HSD | C] -- C:\Users\XXXX\AppData\Local\Application Data
[2008/10/12 18:22:03 | 00,000,000 | --SD | C] -- C:\Users\XXXX\AppData\Roaming\Microsoft
[2008/10/12 18:22:03 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Roaming\Media Center Programs
[2008/10/12 18:22:03 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Local\Temp
[2008/10/12 18:22:03 | 00,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Local\Microsoft
[2008/10/12 17:59:46 | 00,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2008/10/12 17:58:51 | 00,000,000 | ---D | C] -- C:\Windows\Debug
[2008/10/12 17:58:50 | 00,000,000 | ---D | C] -- C:\Windows\CSC
[2008/10/12 17:57:50 | 00,000,000 | ---D | C] -- C:\Windows\Prefetch
[2008/10/12 17:57:40 | 00,000,000 | -HSD | C] -- C:\System Volume Information

========== Files - Modified Within 30 Days ==========

[2008/10/20 11:15:12 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2008/10/20 08:43:29 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2008/10/20 08:43:16 | 42,933,86240 | -HS- | M] () -- C:\hiberfil.sys
[2008/10/20 00:13:45 | 00,000,250 | ---- | M] () -- C:\Windows\gmer.ini
[2008/10/20 00:12:17 | 00,884,736 | ---- | M] () -- C:\Windows\gmer.dll
[2008/10/20 00:12:17 | 00,085,969 | ---- | M] (GMER) -- C:\Windows\System32\drivers\gmer.sys
[2008/10/20 00:12:17 | 00,000,080 | ---- | M] () -- C:\Windows\gmer_uninstall.cmd
[2008/10/20 00:11:41 | 00,811,008 | ---- | M] () -- C:\Windows\gmer.exe
[2008/10/19 21:51:35 | 00,003,975 | ---- | M] () -- C:\Users\XXXX\Desktop\kasperskyonlinescanreport.html
[2008/10/19 21:48:34 | 00,003,975 | ---- | M] () -- C:\Users\XXXX\Documents\kasperskyonlinescanreport.html
[2008/10/19 19:35:48 | 00,002,728 | ---- | M] () -- C:\Windows\System32\%LocalXml%
[2008/10/19 12:43:01 | 00,700,310 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2008/10/14 22:30:32 | 01,623,765 | -H-- | M] () -- C:\Users\XXXX\AppData\Local\IconCache.db
[2008/10/13 23:55:33 | 00,000,904 | ---- | M] () -- C:\Users\Public\Desktop\Acrobat.com.lnk
[2008/10/13 23:54:01 | 00,001,917 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2008/10/13 20:39:30 | 00,005,120 | ---- | M] () -- C:\Users\XXXX\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/10/13 19:02:34 | 00,000,418 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2008/10/13 02:56:36 | 00,008,192 | R-S- | M] () -- C:\BOOTSECT.BAK
[2008/10/12 22:15:20 | 00,001,288 | ---- | M] () -- C:\Users\Public\Desktop\World of Warcraft FREE trial.lnk
[2008/10/12 22:12:40 | 00,099,880 | ---- | M] () -- C:\Users\XXXX\AppData\Local\GDIPFONTCACHEV1.DAT
[2008/10/12 22:11:38 | 00,000,280 | -HS- | M] () -- C:\Users\Public\Documents\desktop.ini
[2008/10/12 22:11:38 | 00,000,174 | -HS- | M] () -- C:\Users\Public\Desktop\desktop.ini
[2008/10/12 22:11:38 | 00,000,174 | -HS- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
[2008/10/12 21:08:44 | 00,101,888 | ---- | M] (Infineon Technologies AG) -- C:\Windows\System32\ifxcardm.dll
[2008/10/12 21:08:44 | 00,082,432 | ---- | M] (Gemalto, Inc.) -- C:\Windows\System32\axaltocm.dll
[2008/10/12 20:31:21 | 00,000,219 | ---- | M] () -- C:\Windows\win.ini
[2008/10/12 19:24:05 | 00,007,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\kbd106n.dll
[2008/10/12 19:24:04 | 00,040,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\srclient.dll
[2008/10/12 19:23:11 | 00,269,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\es.dll
[2008/10/12 19:08:45 | 00,000,000 | ---- | M] () -- C:\Windows\ativpsrm.bin
[2008/10/12 19:02:45 | 11,580,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\shell32.dll
[2008/10/12 18:55:41 | 00,028,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Apphlpdm.dll
[2008/10/12 18:55:40 | 04,240,384 | ---- | M] (Microsoft) -- C:\Windows\System32\GameUXLegacyGDFs.dll
[2008/10/12 18:55:40 | 01,695,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\gameux.dll
[2008/10/12 18:50:36 | 01,808,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0046.dll
[2008/10/12 18:50:36 | 01,793,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0045.dll
[2008/10/12 18:50:36 | 01,558,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0049.dll
[2008/10/12 18:50:36 | 01,411,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0047.dll
[2008/10/12 18:50:35 | 07,964,672 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0024.dll
[2008/10/12 18:50:35 | 05,791,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0026.dll
[2008/10/12 18:50:35 | 05,499,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0022.dll
[2008/10/12 18:50:35 | 02,136,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0021.dll
[2008/10/12 18:50:35 | 01,782,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0039.dll
[2008/10/12 18:50:35 | 01,236,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0020.dll
[2008/10/12 18:50:34 | 06,781,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0019.dll
[2008/10/12 18:50:34 | 06,224,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0027.dll
[2008/10/12 18:50:34 | 04,981,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0013.dll
[2008/10/12 18:50:34 | 04,175,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0010.dll
[2008/10/12 18:50:34 | 03,331,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0018.dll
[2008/10/12 18:50:34 | 02,466,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0011.dll
[2008/10/12 18:50:33 | 12,240,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0007.dll
[2008/10/12 18:50:33 | 11,722,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0001.dll
[2008/10/12 18:50:33 | 04,164,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0002.dll
[2008/10/12 18:50:33 | 02,644,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0009.dll
[2008/10/12 18:50:33 | 01,452,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0003.dll
[2008/10/12 18:50:32 | 06,585,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons001b.dll
[2008/10/12 18:50:32 | 06,014,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons001a.dll
[2008/10/12 18:50:32 | 04,093,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons004c.dll
[2008/10/12 18:50:32 | 04,045,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons003e.dll
[2008/10/12 18:50:32 | 03,419,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons004a.dll
[2008/10/12 18:50:32 | 01,972,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons004e.dll
[2008/10/12 18:50:32 | 01,702,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons004b.dll
[2008/10/12 18:50:32 | 00,004,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons002a.dll
[2008/10/12 18:50:31 | 09,892,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons000a.dll
[2008/10/12 18:50:31 | 06,346,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons001d.dll
[2008/10/12 18:50:31 | 06,237,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons000c.dll
[2008/10/12 18:50:31 | 01,722,368 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons000d.dll
[2008/10/12 18:50:30 | 07,042,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons081a.dll
[2008/10/12 18:50:30 | 05,654,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons000f.dll
[2008/10/12 18:50:30 | 05,090,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0416.dll
[2008/10/12 18:50:30 | 05,031,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0816.dll
[2008/10/12 18:50:30 | 04,616,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0414.dll
[2008/10/12 18:50:29 | 05,071,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsModels0011.dll
[2008/10/12 18:50:29 | 03,104,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData0049.dll
[2008/10/12 18:50:29 | 03,104,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData0047.dll
[2008/10/12 18:50:29 | 03,104,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData0046.dll
[2008/10/12 18:50:29 | 03,104,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData0045.dll
[2008/10/12 18:50:29 | 03,104,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData0039.dll
[2008/10/12 18:50:28 | 04,495,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData0010.dll
[2008/10/12 18:50:28 | 03,104,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData0020.dll
[2008/10/12 18:50:28 | 02,657,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData0011.dll
[2008/10/12 18:50:28 | 01,966,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData0027.dll
[2008/10/12 18:50:28 | 01,965,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData0026.dll
[2008/10/12 18:50:28 | 01,965,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData0024.dll
[2008/10/12 18:50:28 | 01,801,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData0022.dll
[2008/10/12 18:50:28 | 01,801,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData0021.dll
[2008/10/12 18:50:27 | 04,497,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData0019.dll
[2008/10/12 18:50:27 | 03,466,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData0013.dll
[2008/10/12 18:50:27 | 02,599,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData0001.dll
[2008/10/12 18:50:27 | 01,965,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData0018.dll
[2008/10/12 18:50:27 | 01,965,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData0003.dll
[2008/10/12 18:50:27 | 01,965,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData0002.dll
[2008/10/12 18:50:27 | 01,523,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData0000.dll
[2008/10/12 18:50:26 | 04,875,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData0009.dll
[2008/10/12 18:50:26 | 03,104,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData004e.dll
[2008/10/12 18:50:26 | 03,104,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData004c.dll
[2008/10/12 18:50:26 | 03,104,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData004b.dll
[2008/10/12 18:50:26 | 03,104,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData004a.dll
[2008/10/12 18:50:26 | 02,243,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData0007.dll
[2008/10/12 18:50:25 | 09,847,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData000a.dll
[2008/10/12 18:50:25 | 04,495,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData001d.dll
[2008/10/12 18:50:25 | 01,965,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData001b.dll
[2008/10/12 18:50:25 | 01,965,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData001a.dll
[2008/10/12 18:50:25 | 01,801,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData003e.dll
[2008/10/12 18:50:25 | 01,801,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData002a.dll
[2008/10/12 18:50:24 | 04,495,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData0816.dll
[2008/10/12 18:50:24 | 04,495,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData0416.dll
[2008/10/12 18:50:24 | 04,495,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData0414.dll
[2008/10/12 18:50:24 | 02,643,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData000c.dll
[2008/10/12 18:50:24 | 02,342,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData000d.dll
[2008/10/12 18:50:24 | 01,965,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData000f.dll
[2008/10/12 18:50:24 | 00,801,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NaturalLanguage6.dll
[2008/10/12 18:50:23 | 06,917,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0c1a.dll
[2008/10/12 18:50:23 | 01,965,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData0c1a.dll
[2008/10/12 18:50:23 | 01,965,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData081a.dll
[2008/10/12 18:47:51 | 00,001,820 | ---- | M] () -- C:\Windows\System32\rasctrnm.h
[2008/10/12 18:47:18 | 00,738,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inetcomm.dll
[2008/10/12 18:47:18 | 00,084,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\INETRES.dll
[2008/10/12 18:46:13 | 00,002,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2008/10/12 18:45:30 | 00,272,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\polstore.dll
[2008/10/12 18:45:30 | 00,061,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\winipsec.dll
[2008/10/12 18:45:30 | 00,028,672 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\FwRemoteSvr.dll
[2008/10/12 18:44:05 | 00,302,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\gdi32.dll
[2008/10/12 18:37:04 | 00,303,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wmpeffects.dll
[2008/10/12 18:35:40 | 02,455,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2008/10/12 18:35:29 | 00,056,483 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
[2008/10/12 18:35:28 | 00,180,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2008/10/12 18:34:24 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Mpeg2Data.ax
[2008/10/12 18:34:24 | 00,057,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MSDvbNP.ax
[2008/10/12 18:33:55 | 00,014,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wshrm.dll
[2008/10/12 18:33:30 | 01,314,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\quartz.dll
[2008/10/12 18:23:04 | 00,000,732 | ---- | M] () -- C:\Users\XXXX\AppData\Local\d3d9caps64.dat
[2008/10/12 18:22:28 | 00,000,402 | -HS- | M] () -- C:\Users\XXXX\Documents\desktop.ini
[2008/10/12 18:22:28 | 00,000,282 | -HS- | M] () -- C:\Users\XXXX\Desktop\desktop.ini
[2008/10/12 18:22:28 | 00,000,174 | -HS- | M] () -- C:\Users\XXXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
[2008/10/02 04:49:19 | 01,166,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\urlmon.dll
[2008/10/02 04:49:19 | 00,827,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wininet.dll
[2008/10/02 04:49:16 | 00,671,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll
[2008/10/02 04:49:15 | 03,578,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.dll
[2008/10/02 04:49:14 | 06,068,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieframe.dll
[2008/10/02 04:49:14 | 00,270,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iertutil.dll
[2008/10/02 04:49:14 | 00,028,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2008/10/02 02:32:38 | 01,383,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
< End of report >


OTViewIt Extras logfile created on: 20/10/2008 11:29:55 - Run 2
OTViewIt by OldTimer - Version 1.0.17.0 Folder = C:\Users\XXXX\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z78DA7PF
Windows Vista An unknown product Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

4.00 Gb Total Physical Memory | 3.05 Gb Available Physical Memory | 76.35% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys;

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 127.99 Gb Total Space | 67.74 Gb Free Space | 52.92% Space Free | Partition Type: NTFS
Drive D: | 337.77 Gb Total Space | 283.96 Gb Free Space | 84.07% Space Free | Partition Type: NTFS
Drive E: | 465.75 Gb Total Space | 110.77 Gb Free Space | 23.78% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive O: | 24.00 Gb Total Space | 1.20 Gb Free Space | 5.01% Space Free | Partition Type: NTFS
Drive P: | 52.68 Gb Total Space | 0.02 Gb Free Space | 0.04% Space Free | Partition Type: NTFS
Drive S: | 76.69 Gb Total Space | 2.51 Gb Free Space | 3.27% Space Free | Partition Type: NTFS

Computer Name: XXXX-PC
Current User Name: XXXX
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url [@ = InternetShortcut] -- C:\Windows\System32\ieframe.dll (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=1
""=
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av"=1

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"DisableNotifications"=0
"EnableFirewall"=0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\Logging]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

========== (O10) Winsock2 Catalogs ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\]
NameSpace_Catalog5\Catalog_Entries\000000000001 [@%SystemRoot%\system32\nlasvc.dll,-1000] -- C:\Windows\System32\nlaapi.dll (Microsoft Corporation)
NameSpace_Catalog5\Catalog_Entries\000000000002 [@%SystemRoot%\system32\napinsp.dll,-1000] -- C:\Windows\System32\NapiNSP.dll (Microsoft Corporation)
NameSpace_Catalog5\Catalog_Entries\000000000003 [@%SystemRoot%\system32\pnrpnsp.dll,-1000] -- C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
NameSpace_Catalog5\Catalog_Entries\000000000004 [@%SystemRoot%\system32\pnrpnsp.dll,-1001] -- C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)

========== HKEY_LOCAL_MACHINE Protocol Defaults ==========


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults - Default Protocols
ldap -- 4 = Restricted sites (Not a Default Protocol)
news -- 4 = Restricted sites (Not a Default Protocol)
nntp -- 4 = Restricted sites (Not a Default Protocol)
oecmd -- 4 = Restricted sites (Not a Default Protocol)
snews -- 4 = Restricted sites (Not a Default Protocol)

========== HKEY_USERS Protocol Defaults ==========


[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults] - Default Protocols
@ivt -- @ivt protocol not assigned
file -- file protocol not assigned
ftp -- ftp protocol not assigned
http -- http protocol not assigned
https -- https protocol not assigned
shell -- shell protocol not assigned

========== HKEY_USERS Protocol Defaults ==========


[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults] - Default Protocols
@ivt -- @ivt protocol not assigned
file -- file protocol not assigned
ftp -- ftp protocol not assigned
http -- http protocol not assigned
https -- https protocol not assigned
shell -- shell protocol not assigned

========== (O18) Protocol Handlers ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2008/10/02 04:49:15 | 03,578,880 | ---- | M] (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll (about:{3050F406-98B5-11CF-BB82-00AA00BDCE0B} (HKLM) [Microsoft HTML About Pluggable Protocol])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2008/10/02 04:49:19 | 01,166,336 | ---- | M] (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll (cdl:{3dd53d40-7b8b-11D0-b013-00aa0059ce02} (HKLM) [CDL: Asychronous Pluggable Protocol Handler])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2008/01/19 08:35:15 | 01,544,704 | ---- | M] (Microsoft Corporation) C:\Windows\SysWOW64\MSVidCtl.dll (dvd:{12D51199-0DB5-46FE-A120-47A3D7D937CC} (HKLM) [DVD: Pluggable Protocol])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2008/10/02 04:49:19 | 01,166,336 | ---- | M] (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll (file:{79eac9e7-baf9-11ce-8c82-00aa004ba90b} (HKLM) [file:, local: Asychronous Pluggable Protocol Handler])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2008/10/02 04:49:19 | 01,166,336 | ---- | M] (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll (ftp:{79eac9e3-baf9-11ce-8c82-00aa004ba90b} (HKLM) [ftp: Asychronous Pluggable Protocol Handler])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/08/24 07:01:46 | 00,224,128 | ---- | M] (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll (grooveLocalGWS:{88FED34C-F0CA-4636-A375-3CB6248B04CD} (HKLM) [Local Groove Web Services Protocol])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2008/10/02 04:49:19 | 01,166,336 | ---- | M] (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll (http:{79eac9e2-baf9-11ce-8c82-00aa004ba90b} (HKLM) [http: Asychronous Pluggable Protocol Handler])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2008/10/02 04:49:19 | 01,166,336 | ---- | M] (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll (https:{79eac9e5-baf9-11ce-8c82-00aa004ba90b} (HKLM) [https: Asychronous Pluggable Protocol Handler])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2008/10/02 04:49:15 | 03,578,880 | ---- | M] (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll (java script:{3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} (HKLM) [Microsoft HTML Javascript Pluggable Protocol])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/10/18 11:31:54 | 00,066,072 | ---- | M] (Microsoft Corporation) C:\Program Files (x86)\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (livecall:{828030A1-22C1-4009-854F-8E305202313F} (HKLM) [Reg Error: Value does not exist or could not be read.])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2008/10/02 04:49:19 | 01,166,336 | ---- | M] (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll (local:{79eac9e7-baf9-11ce-8c82-00aa004ba90b} (HKLM) [file:, local: Asychronous Pluggable Protocol Handler])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2008/10/02 04:49:15 | 03,578,880 | ---- | M] (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll (mailto:{3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} (HKLM) [Microsoft HTML Mailto Pluggable Protocol])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2008/10/02 04:49:19 | 01,166,336 | ---- | M] (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll (mk:{79eac9e6-baf9-11ce-8c82-00aa004ba90b} (HKLM) [mk: Asychronous Pluggable Protocol Handler])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2006/10/26 13:45:02 | 00,873,216 | ---- | M] (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Help\hxds.dll (ms-help:{314111c7-a502-11d2-bbca-00c04f8ec294} (HKLM) [HxProtocol Class])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/10/18 11:31:54 | 00,066,072 | ---- | M] (Microsoft Corporation) C:\Program Files (x86)\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (msnim:{828030A1-22C1-4009-854F-8E305202313F} (HKLM) [Reg Error: Value does not exist or could not be read.])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2008/10/02 04:49:15 | 03,578,880 | ---- | M] (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll (res:{3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} (HKLM) [Microsoft HTML Resource Pluggable Protocol])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2008/01/19 08:35:15 | 01,544,704 | ---- | M] (Microsoft Corporation) C:\Windows\SysWOW64\MSVidCtl.dll (tv:{CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} (HKLM) [TV: Pluggable Protocol])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2008/10/02 04:49:15 | 03,578,880 | ---- | M] (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll (vbscript:{3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} (HKLM) [Microsoft HTML Javascript Pluggable Protocol])

========== (O18) Protocol Filters ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\] - Protocol Filters
[2008/10/02 04:49:19 | 01,166,336 | ---- | M] (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll deflate:{8f6b0360-b80d-11d0-a9b3-006097942311} (HKLM) [AP encoding/decoding Filters]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\] - Protocol Filters
[2008/10/02 04:49:19 | 01,166,336 | ---- | M] (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll gzip:{8f6b0360-b80d-11d0-a9b3-006097942311} (HKLM) [AP encoding/decoding Filters]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\] - Protocol Filters
[2006/10/26 21:41:48 | 00,044,344 | ---- | M] (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL text/xml:{807563E5-5146-11D5-A672-00B0D022E945} (HKLM) [Microsoft Office InfoPath XML Mime Filter]

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}"=Adobe AIR
"{02EBDBB9-4600-41D3-B566-40CB861511D2}"=World of Warcraft FREE Trial
"{26A24AE4-039D-4CA4-87B4-2F83216010FF}"=Java™ 6 Update 10
"{3248F0A8-6813-11D6-A77B-00B0D0160070}"=Java™ 6 Update 7
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}"=Windows Live Messenger
"{77DCDCE3-2DED-62F3-8154-05E745472D07}"=Acrobat.com
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}"=Microsoft Silverlight
"{8CB14A64-CEF4-4C8F-B1C8-1C3B8752CB55}"=Kaspersky Internet Security 2009
"{90120000-0015-0409-0000-0000000FF1CE}"=Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ULTIMATER_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0016-0409-0000-0000000FF1CE}"=Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ULTIMATER_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0018-0409-0000-0000000FF1CE}"=Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ULTIMATER_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0019-0409-0000-0000000FF1CE}"=Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ULTIMATER_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001A-0409-0000-0000000FF1CE}"=Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ULTIMATER_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001B-0409-0000-0000000FF1CE}"=Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ULTIMATER_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0409-0000-0000000FF1CE}"=Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ULTIMATER_{3EC77D26-799B-4CD8-914F-C1565E796173}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-040C-0000-0000000FF1CE}"=Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ULTIMATER_{430971B1-C31E-45DA-81E0-72C095BAB72C}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0C0A-0000-0000000FF1CE}"=Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ULTIMATER_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-002A-0000-1000-0000000FF1CE}_ULTIMATER_{00C5525B-3CB3-467D-8100-2E6FB306CD86}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-002A-0409-1000-0000000FF1CE}_ULTIMATER_{FAD8A83E-9BAC-4179-9268-A35948034D85}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-002C-0409-0000-0000000FF1CE}"=Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}"=Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ULTIMATER_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-006E-0409-0000-0000000FF1CE}"=Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ULTIMATER_{FAD8A83E-9BAC-4179-9268-A35948034D85}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-00A1-0409-0000-0000000FF1CE}"=Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ULTIMATER_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-00BA-0409-0000-0000000FF1CE}"=Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ULTIMATER_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0114-0409-0000-0000000FF1CE}"=Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ULTIMATER_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0115-0409-0000-0000000FF1CE}"=Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ULTIMATER_{FAD8A83E-9BAC-4179-9268-A35948034D85}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0116-0409-1000-0000000FF1CE}_ULTIMATER_{FAD8A83E-9BAC-4179-9268-A35948034D85}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0117-0409-0000-0000000FF1CE}"=Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ULTIMATER_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{91120000-002E-0000-0000-0000000FF1CE}"=Microsoft Office Ultimate 2007
"{91120000-002E-0000-0000-0000000FF1CE}_ULTIMATER_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{95774351-6087-3A3B-8CA8-70BEE49D2BD5}"=Google Gears
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}"=Windows Live installer
"{AC76BA86-7AD7-1033-7B44-A90000000001}"=Adobe Reader 9
"{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}"=Windows Live Sign-in Assistant
"Adobe AIR"=Adobe AIR
"Adobe Flash Player ActiveX"=Adobe Flash Player ActiveX
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1"=Acrobat.com
"EsetOnlineScanner"=ESET Online Scanner
"InstallWIX_{8CB14A64-CEF4-4C8F-B1C8-1C3B8752CB55}"=Kaspersky Internet Security 2009
"ULTIMATER"=Microsoft Office Ultimate 2007

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Juniper_Term_Services"=Juniper Terminal Services Client
"JuniperSetupClient"=Juniper Networks Setup Client

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-3899547795-3242998539-2272418043-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Juniper_Term_Services"=Juniper Terminal Services Client
"JuniperSetupClient"=Juniper Networks Setup Client

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-3899547795-3242998539-2272418043-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome"=Google Chrome
"JuniperSetupClient"=Juniper Networks Setup Client

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 17/10/2008 15:56:50 | Computer Name = XXXX-PC | Source = Microsoft Office 12 | ID = 2001
Description = Rejected Safe Mode action : Microsoft Office Outlook.

Error - 17/10/2008 17:07:56 | Computer Name = XXXX-PC | Source = Application Error | ID = 1000
Description = Faulting application OUTLOOK.EXE, version 12.0.6316.5000, time stamp
0x4833a470, faulting module ntdll.dll, version 6.0.6001.18000, time stamp 0x4791a783,
exception code 0xc0000005, fault offset 0x0003dbba, process id 0xc4, application
start time 0x01c9309978d1431d.

Error - 18/10/2008 19:07:02 | Computer Name = XXXX-PC | Source = Application Error | ID = 1000
Description = Faulting application OUTLOOK.EXE, version 12.0.6316.5000, time stamp
0x4833a470, faulting module ntdll.dll, version 6.0.6001.18000, time stamp 0x4791a783,
exception code 0xc0000005, fault offset 0x0003dbba, process id 0x954, application
start time 0x01c93175ff29d4e0.

Error - 18/10/2008 19:50:32 | Computer Name = XXXX-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 18/10/2008 19:50:44 | Computer Name = XXXX-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 19/10/2008 07:43:05 | Computer Name = XXXX-PC | Source = Windows Search Service | ID = 3024
Description =

Error - 19/10/2008 15:33:00 | Computer Name = XXXX-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 19/10/2008 15:33:16 | Computer Name = XXXX-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 20/10/2008 05:38:18 | Computer Name = XXXX-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 20/10/2008 05:38:30 | Computer Name = XXXX-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

[ OSession Events ]
Error - 17/10/2008 17:07:55 | Computer Name = XXXX-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 1268
seconds with 0 seconds of active time. This session ended with a crash.

Error - 18/10/2008 19:07:02 | Computer Name = XXXX-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 100
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 19/10/2008 07:56:20 | Computer Name = XXXX-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 19/10/2008 07:56:20 | Computer Name = XXXX-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 19/10/2008 07:56:21 | Computer Name = XXXX-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 19/10/2008 07:56:21 | Computer Name = XXXX-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 19/10/2008 08:24:40 | Computer Name = XXXX-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 19/10/2008 08:24:40 | Computer Name = XXXX-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 19/10/2008 08:24:41 | Computer Name = XXXX-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 19/10/2008 08:24:41 | Computer Name = XXXX-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 20/10/2008 03:05:05 | Computer Name = XXXX-PC | Source = BROWSER | ID = 8007
Description =

Error - 20/10/2008 03:43:29 | Computer Name = XXXX-PC | Source = HTTP | ID = 15016
Description =


< End of report >

#7 luap64

luap64
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:03:13 AM

Posted 20 October 2008 - 05:59 AM

Latest Kaspersky 2009 report - Again stalled at 86% readme.txt


Scan: stopped 20/10/2008 08:04:55 (events: 22, objects: 405938, time: 10:55:34)
19/10/2008 21:09:21 Task started
19/10/2008 21:21:28 Detected: Trojan.Win32.Buzus.vwi C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\[Google Mail]\All Mail\[From:dcy][Subject:YouTube.com: Makes your day.][Time:8859/01/01 00:00:00]/youtube.rar/YouTube.com.jHsbIqkd.avi.exe
19/10/2008 21:21:28 Untreated: Trojan.Win32.Buzus.vwi C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\[Google Mail]\All Mail\[From:dcy][Subject:YouTube.com: Makes your day.][Time:8859/01/01 00:00:00]/youtube.rar/YouTube.com.jHsbIqkd.avi.exe Postponed
19/10/2008 21:21:29 Detected: Trojan-Downloader.Win32.Agent.aeza C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\[Google Mail]\All Mail\[From:None][Subject:CNN: Mad elephant killed school teacher!][Time:2008/09/29 20:09:18]/Video.rar/My.YouTube.Movie.avi.exe
19/10/2008 21:21:29 Untreated: Trojan-Downloader.Win32.Agent.aeza C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\[Google Mail]\All Mail\[From:None][Subject:CNN: Mad elephant killed school teacher!][Time:2008/09/29 20:09:18]/Video.rar/My.YouTube.Movie.avi.exe Postponed
19/10/2008 21:21:41 Detected: Backdoor.Win32.Hijack.e C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\[Google Mail]\All Mail\[From:ufn][Subject:Funbags][Time:8859/01/01 00:00:00]/movie.rar/movie.avi.exe
19/10/2008 21:21:42 Untreated: Backdoor.Win32.Hijack.e C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\[Google Mail]\All Mail\[From:ufn][Subject:Funbags][Time:8859/01/01 00:00:00]/movie.rar/movie.avi.exe Postponed
19/10/2008 21:25:55 Detected: Trojan-Spy.HTML.Fraud.gen C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\[Google Mail]\All Mail\[From:Fulton Bank CashLink][Subject:Fulton Bank Business Online Banking Important Notice REF: 9575][Time:2008/09/17 03:31:49]/HTMLBody
19/10/2008 21:25:55 Untreated: Trojan-Spy.HTML.Fraud.gen C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\[Google Mail]\All Mail\[From:Fulton Bank CashLink][Subject:Fulton Bank Business Online Banking Important Notice REF: 9575][Time:2008/09/17 03:31:49]/HTMLBody Postponed
19/10/2008 21:26:00 Detected: Trojan-Spy.HTML.Fraud.gen C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\[Google Mail]\All Mail\[From:Fulton Bank CashLink][Subject:Fulton Bank CashLink: Update Your Identity][Time:2008/09/16 02:17:50]/HTMLBody
19/10/2008 21:26:00 Untreated: Trojan-Spy.HTML.Fraud.gen C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\[Google Mail]\All Mail\[From:Fulton Bank CashLink][Subject:Fulton Bank CashLink: Update Your Identity][Time:2008/09/16 02:17:50]/HTMLBody Postponed
19/10/2008 21:26:27 Detected: Trojan-Spy.HTML.Fraud.gen C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\[Google Mail]\All Mail\[From:NatWest Bank Internet Banking][Subject:Natwest OnLine Banking Online Banking Service - User's Data Authorization][Time:2008/10/10 13:17:38]/HTMLBody
19/10/2008 21:26:27 Untreated: Trojan-Spy.HTML.Fraud.gen C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\[Google Mail]\All Mail\[From:NatWest Bank Internet Banking][Subject:Natwest OnLine Banking Online Banking Service - User's Data Authorization][Time:2008/10/10 13:17:38]/HTMLBody Postponed
19/10/2008 21:30:44 Detected: Trojan-Spy.HTML.Fraud.gen C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\Junk E-mail\[From:Fulton Bank CashLink][Subject:Fulton Bank Business Online Banking Important Notice REF: 9575][Time:2008/09/17 03:31:49]/HTMLBody
19/10/2008 21:30:44 Untreated: Trojan-Spy.HTML.Fraud.gen C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\Junk E-mail\[From:Fulton Bank CashLink][Subject:Fulton Bank Business Online Banking Important Notice REF: 9575][Time:2008/09/17 03:31:49]/HTMLBody Postponed
19/10/2008 21:30:49 Detected: Trojan-Spy.HTML.Fraud.gen C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\Junk E-mail\[From:Fulton Bank CashLink][Subject:Fulton Bank CashLink: Update Your Identity][Time:2008/09/16 02:17:50]/HTMLBody
19/10/2008 21:30:49 Untreated: Trojan-Spy.HTML.Fraud.gen C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\Junk E-mail\[From:Fulton Bank CashLink][Subject:Fulton Bank CashLink: Update Your Identity][Time:2008/09/16 02:17:50]/HTMLBody Postponed
19/10/2008 21:30:57 Detected: Trojan-Spy.HTML.Fraud.gen C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\Junk E-mail\[From:NatWest Bank Internet Banking][Subject:Natwest OnLine Banking Online Banking Service - User's Data Authorization][Time:2008/10/10 13:17:38]/HTMLBody
19/10/2008 21:30:57 Untreated: Trojan-Spy.HTML.Fraud.gen C:\Users\XXXX\AppData\Local\Microsoft\Outlook\OutlXXXX@XXXXXXXXX.com-00000002.pst/XXXX@XXXXXXXXX.com\Top of Personal Folders\Junk E-mail\[From:NatWest Bank Internet Banking][Subject:Natwest OnLine Banking Online Banking Service - User's Data Authorization][Time:2008/10/10 13:17:38]/HTMLBody Postponed
19/10/2008 21:39:34 Untreated C:\Users\XXXX\AppData\Local\Microsoft\Outlook\Outlook.pst Write error
19/10/2008 21:39:34 Untreated C:\Users\XXXX\AppData\Local\Microsoft\Outlook\Outlook.pst Postponed
20/10/2008 08:04:55 Task stopped
Scan: stopped 20/10/2008 08:04:55 (events: 22, objects: 405938, time: 10:55:34)
20/10/2008 08:46:26 Task started
20/10/2008 09:09:45 Untreated C:\Users\XXXX\AppData\Local\Microsoft\Outlook\Outlook.pst Write error
20/10/2008 09:09:45 Untreated C:\Users\XXXX\AppData\Local\Microsoft\Outlook\Outlook.pst Postponed

#8 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,301 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:07:13 PM

Posted 20 October 2008 - 01:39 PM

Open microsoft outlook, and DELETE every email in both your JUNK email folders, as well as your DELETED EMAILS folders.

All of what Kaspersky has detected is located inside of your Outlook data. I am unable to tell, however, which emails specificly contain the bad data, because you have XXXX ed out that information in the log. Please go through the emails listed in the Kaspersky log, and delete any emails that are listed therein. Once that's done, please attempt to re-run kaspersky.

Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#9 luap64

luap64
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:03:13 AM

Posted 22 October 2008 - 05:22 PM

I use GMAIL with IMAP and had got up to 17000 mails so used this as a reason for a good clean out. After this full scan wasn't detecting anything but I still got the occasional on the fly warning about the banking trojan. Together with delays starting Outlook saying pst being repaired. I ran a scanpst to check and fix pst and then compacted the pst (my suspicion was that email data was still in file even though logically deleted) This reduced the file size from >1GB to 93MB which has had the side effect of speeding things up!. Since then a full Kaspersky scan on custom with all setting at maximum has not revealed anything and there have been no pop up warnings either.

Think we might have got it but I'm keen for extra reassurance to confirm

Thanks

Paul

#10 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,301 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:07:13 PM

Posted 22 October 2008 - 06:29 PM

Hello, luap64.
Hehe.. figured it'd be something like that. Please use this other scanner once to be sure ;)

I would like us to use ESET (NOD32)'s Online Scanner
  • Please go to ESET OnlineScan (NOD32)
  • You will then see the Terms of Use, tick the check-box infront of YES, I accept the Terms of Use
  • Now click Start
  • Should you face a Security Warning that asks if you want to install and run a file called "OnlineScanner.cab", click Yes
  • Click Start
    • Note: (the Onlinescanner will now prepare itself for running on your pc)
  • To do a full-scan, tick: "Remove found threats" and "Scan potentially unwanted applications"
  • Press Scan
  • The Onlinescan will now start and scan your pc (this could take a while)
  • When the scan has finished, it will show a screen with two tabs "overview" and "details" and the option to get information or buy software, just close the window
  • Click Start >> Run... >> type: C:\Program Files\EsetOnlineScanner\log.txt
  • The Scanresults will now open in Notepad
  • Click into the text area, right-click and chose "select all" (or use <Control>+A)
  • Right-click again and chose "Copy" (or <Control>+C)
  • Close/Exit Notepad
  • Navigate to this thread and post your log along with anything else requested from us, by right-clicking and "paste" (or ctrl+v) in the text area of the reply post you just created.
Note: For Vista Users: Eset is compatible but Internet Explorer must be run as Administrator. To do this, right-click on the IE icon in the Start Menu or Quick Launch Bar on the Taskbar and select "Run as Administrator" from the context menu.)

In your next reply, please include the following:
  • ESET OnlineScan's Log

Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#11 luap64

luap64
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:03:13 AM

Posted 23 October 2008 - 03:24 PM

ESET running now, earlier ran Symantec online scan and that came up clear so looking promising.

Seriously considering going back to thunderbird though !

#12 luap64

luap64
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:03:13 AM

Posted 24 October 2008 - 06:52 AM

ESET reported all clear.

general levels of spam and dodgy emails hitting account very high, think this might be a combination of side effects of infection and Outlook IMAP issues mentioned elsewhere. I'll switch to Thunderbird and keep a watch on this site.

Thanks, think we're probably OK to close unless you need any other evidence. (I've got my original infected Windows install on another drive so could do some analysis before trying to clean if helpful)

#13 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,301 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:07:13 PM

Posted 24 October 2008 - 09:33 PM

Hello, luap64.
Congratulations! You now appear clean! :thumbsup:

Are things running okay? Do you have any more questions?

System Still Slow?
You may wish to try StartupLite. Simply download this tool to your desktop and run it. It will explain any optional auto-start programs on your system, and offer the option to stop these programs from starting at startup. This will result in fewer programs running when you boot your system, and should improve preformance.
If that does not work, you can try the steps mentioned in Slow Computer/browser? Check Here First; It May Not Be Malware


We Need to Clean Up Our Mess
  • Please download OTCleanIt from one of the following mirrors and save it to your desktop:
  • Double click the Posted Image icon.
  • Push the large "Cleanup" button.
  • Allow your system to reboot.
Reset System Restore
Windows' "System Restore" feature can cause malware files to be cached and retained by your system. Resetting System Restore will clean these files from your system, and will allow you to use System Restore without fear of reinfection.
  • Go to Start > Programs > Accessories > System Tools and click "System Restore".
  • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Then go to Start > Run and type: Cleanmgr
  • Click "OK".
  • Click the "More Options" Tab.
  • Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.
Note: You should only do this once, not on a regular basis!
You will not be able to restore computer to any earlier than today!

Recommendations
Below are some recommendations to lower your chances of (re)infection.
  • Install and maintain an outbound firewall
  • Install Spyware Blaster and update it regularly
    If you wish, the commercial version provides automatic updating.
  • Install the MVPs hosts file, and update it regularly
    You can use the HostMan host file manager to do this automaticly if you wish.
    For more information on the hosts file, and what it can do for you, you can view the Tutorial on the Hosts file
  • Install an Anti-Spyware program, and update it regularly
    Malware Byte's Anti Malware is an excellent Anti-Spyware scanner. It's scan times are usually under ten minutes, and has excellent detection and removal rates.
    SUPERAntiSpyware is another good scanner with high detection and removal rates.
    Both programs are free for non commercial home use but provide a resident and do not nag if you purchase the paid versions.
  • Keep Windows (and your other Microsoft software) up to date!
    I cannot stress how important this is enough. Often holes are found in Internet Explorer or Windows itself that require patching. Sometimes these holes will allow an attacker unrestricted access to your computer.

    If you are using Windows XP or earlier
    Visit the Microsoft Update Website and follow the on screen instructions to setup Microsoft Update. Also follow the instructions to update your system. Please REBOOT and repeat this process until there are no more updates to install!!

    If you are using Windows Vista
    • Click the "Start Menu" (or Windows Orb)
    • Click "All Programs"
    • Click "Windows Update"
    • On the left, choose "Change Settings"
    • Ensure that the checkbox "Use Microsoft Update" at the bottom of the window is checked.
    • Press OK and accept the UAC prompt.
      Note: You shouldn't need to check this checkbox every single time you update, only the first time.
    • Click "Check for Updates" in the upper left corner.
    • Follow the instructions to install the latest updates.
    • Reboot and repeat the "Check for Updates" until there are no more critical updates to install
  • Keep your other software up to date as well
    Software does not need to be made by Microsoft to be insecure. You can use the Secunia Online Software occasionally to help you check for out of date software on your machine.
  • Stay up to date!
    The MOST IMPORTANT part of any security setup is keeping the software up to date. Malware writers release new variants every single day. If your software updates don't keep up, then the malware will always be one step ahead. Not a good thing :).
Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#14 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,301 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:07:13 PM

Posted 26 October 2008 - 09:54 PM

Hello, luap64.
Since this issue appears resolved, this topic has been closed.

If you need this topic reopened, please send me or another moderator a PM.

Everyone else please begin a new topic.

Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users