
On the DEsktop there is a shortcut for the following program:
c:\Program Data\08517526\08517526.exe.
Norton 360 will not run.
UPDATE: changed name of gmer.exe and was able to run and have attached the file.
DDS (Ver_09-12-01.01) - NTFSx86
Run by Da Quayster at 20:58:34.35 on Sat 02/06/2010
Internet Explorer: 8.0.6001.18865
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1982.1305 [GMT -6:00]
AV: Malware Defense *On-access scanning enabled* (Outdated) {28e00e3b-806e-4533-925c-f4c3d79514b9}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\rundll32.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Sprint\Pantech\Sprint Mobile Broadband (Pantech)\PWIUtilityService.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
F:\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com/
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\3.5.0.30\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\3.5.0.30\IPSBHO.DLL
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_02\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\3.5.0.30\coIEPlg.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [HPAdvisor] c:\program files\hewlett-packard\hp advisor\HPAdvisor.exe autoRun
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [richtx64.exe] c:\users\daquay~1\appdata\local\temp\richtx64.exe
uRun: [Malware Defense] "c:\program files\malware defense\mdefense.exe" -noscan
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [OnScreenDisplay] c:\program files\hewlett-packard\hp quicktouch\HPKBDAPP.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [WAWifiMessage] c:\program files\hewlett-packard\hp wireless assistant\WiFiMsg.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_02\bin\jusched.exe"
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Monitor] "c:\program files\leapfrog\leapfrog connect\Monitor.exe"
mRun: [SynTPStart] c:\program files\synaptics\syntp\SynTPStart.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe
StartupFolder: c:\users\daquay~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\vongot~1.lnk - c:\windows\installer\{8c3ae2d1-854d-4650-a73d-c7cc7ee36b80}\NewShortcut2_DB7E00C96DEF489A8112D8F81614F45A.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_02\bin\ssv.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\norton 360\engine\3.5.0.30\CoIEPlg.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
================= FIREFOX ===================
FF - ProfilePath -
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0305000.01e\SymEFA.sys [2010-1-24 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\n360\0305000.01e\BHDrvx86.sys [2010-1-24 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0305000.01e\cchpx86.sys [2010-1-24 482432]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20090712.001\IDSvix86.sys [2010-1-24 293424]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\system32\drivers\n360\0305000.01e\symndisv.sys [2010-1-24 48688]
S2 N360;Norton 360;c:\program files\norton 360\engine\3.5.0.30\ccSvcHst.exe [2010-1-24 117640]
S3 FlyUsb;FLY Fusion;c:\windows\system32\drivers\FlyUsb.sys [2007-6-18 19456]
=============== Created Last 30 ================
2010-02-07 02:57:26 0 ----a-w- c:\users\da quayster\defogger_reenable
2010-02-07 02:04:24 0 d-----w- c:\program files\Trend Micro
2010-02-07 02:01:14 0 d-----w- c:\users\daquay~1\appdata\roaming\AVG8
2010-01-25 00:56:07 25648 ----a-r- c:\windows\system32\drivers\SymIMV.sys
2010-01-25 00:55:54 806 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2010-01-25 00:55:54 7456 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2010-01-25 00:55:54 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-01-25 00:55:53 0 d-----w- c:\program files\Symantec
2010-01-25 00:55:50 0 d-----w- c:\programdata\Symantec
2010-01-25 00:53:54 0 d-----w- c:\windows\system32\drivers\N360
2010-01-25 00:53:43 0 d-----w- c:\program files\Norton 360
2010-01-25 00:46:38 0 d-----w- c:\users\da quayster\Office Genuine Advantage
2010-01-25 00:43:35 0 d-----w- c:\programdata\PCSettings
2010-01-25 00:43:34 0 d-----w- c:\programdata\Norton
2010-01-25 00:42:49 0 d-----w- c:\programdata\NortonInstaller
2010-01-25 00:42:49 0 d-----w- c:\program files\NortonInstaller
2010-01-10 07:03:12 23090 ----a-w- c:\windows\hpqins15.dat
2010-01-10 03:59:11 378368 ----a-w- c:\windows\system32\winhttp.dll
2010-01-09 21:34:48 0 d-----w- C:\8ffd17ed6056df97f92371a21ae2ff12
2010-01-09 01:26:19 0 d-----w- c:\programdata\Office Genuine Advantage
2010-01-09 01:20:51 494592 ----a-w- c:\windows\system32\kerberos.dll
2010-01-09 01:20:51 272384 ----a-w- c:\windows\system32\schannel.dll
==================== Find3M ====================
2010-01-25 00:56:00 86016 ----a-w- c:\windows\inf\infstor.dat
2010-01-25 00:56:00 51200 ----a-w- c:\windows\inf\infpub.dat
2010-01-25 00:56:00 143360 ----a-w- c:\windows\inf\infstrng.dat
2010-01-22 03:56:56 28409 ----a-w- c:\programdata\nvModes.dat
2010-01-11 00:03:41 174 --sha-w- c:\program files\desktop.ini
2010-01-10 23:51:02 101376 ----a-w- c:\windows\system32\ifxcardm.dll
2010-01-10 23:50:26 79872 ----a-w- c:\windows\system32\axaltocm.dll
2010-01-10 23:40:28 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-12-28 18:59:15 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-12-28 18:58:32 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-12-21 20:44:23 58736 ----a-w- C:\symlcsv1.exe
2009-11-30 05:10:54 268800 ----a-w- c:\windows\system32\es.dll
2009-11-28 19:01:11 61440 ----a-w- c:\windows\system32\winipsec.dll
2009-11-28 19:01:11 28672 ----a-w- c:\windows\system32\FwRemoteSvr.dll
2009-11-28 19:01:10 361984 ----a-w- c:\windows\system32\IPSECSVC.DLL
2009-11-28 19:01:10 272896 ----a-w- c:\windows\system32\polstore.dll
2009-11-28 18:59:46 95232 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2009-11-28 18:59:46 241152 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2009-11-28 18:59:46 160768 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2009-11-28 18:57:55 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-11-28 18:57:55 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-11-28 18:57:55 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-11-28 18:57:55 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-11-28 18:57:55 15360 ----a-w- c:\windows\system32\netevent.dll
2009-11-28 18:57:55 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-11-28 18:57:55 103936 ----a-w- c:\windows\system32\netiohlp.dll
2009-11-28 18:57:55 10240 ----a-w- c:\windows\system32\finger.exe
2009-11-28 18:57:54 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-11-28 18:57:53 22016 ----a-w- c:\windows\system32\netiougc.exe
2009-11-28 18:57:53 167424 ----a-w- c:\windows\system32\tcpipcfg.dll
2009-11-28 18:52:50 704000 ----a-w- c:\windows\system32\PhotoScreensaver.scr
2009-11-28 18:52:50 356352 ----a-w- c:\windows\system32\wbem\wbemcomn.dll
2009-11-28 18:52:44 24064 ----a-w- c:\windows\system32\wtsapi32.dll
2009-11-28 18:52:39 542720 ----a-w- c:\windows\system32\sysmain.dll
2009-11-28 18:51:11 194560 ----a-w- c:\windows\system32\WebClnt.dll
2009-11-28 18:49:51 123904 ----a-w- c:\windows\system32\L2SecHC.dll
2009-11-28 18:49:49 67584 ----a-w- c:\windows\system32\wlanhlp.dll
2009-11-28 18:49:49 502784 ----a-w- c:\windows\system32\wlansvc.dll
2009-11-28 18:49:49 47104 ----a-w- c:\windows\system32\wlanapi.dll
2009-11-28 18:49:49 289280 ----a-w- c:\windows\system32\wlanmsm.dll
2009-11-28 18:49:48 299520 ----a-w- c:\windows\system32\wlansec.dll
2009-11-28 18:49:48 14827 ----a-w- c:\windows\system32\gatherWirelessInfo.vbs
2009-11-28 18:48:13 1260032 ----a-w- c:\windows\system32\msxml3.dll
2009-11-28 18:48:12 2048 ----a-w- c:\windows\system32\msxml6r.dll
2009-11-28 18:48:12 2048 ----a-w- c:\windows\system32\msxml3r.dll
2009-11-28 18:48:12 1406464 ----a-w- c:\windows\system32\msxml6.dll
2009-11-28 18:46:35 72704 ----a-w- c:\windows\system32\fontsub.dll
2009-11-28 18:46:35 34304 ----a-w- c:\windows\system32\atmlib.dll
2009-11-28 18:46:35 289792 ----a-w- c:\windows\system32\atmfd.dll
2009-11-28 18:46:35 24064 ----a-w- c:\windows\system32\lpk.dll
2009-11-28 18:46:35 156160 ----a-w- c:\windows\system32\t2embed.dll
2009-11-28 18:46:35 10240 ----a-w- c:\windows\system32\dciman32.dll
2009-11-28 18:45:06 175104 ----a-w- c:\windows\system32\wdigest.dll
2009-11-28 18:45:05 7680 ----a-w- c:\windows\system32\lsass.exe
2009-11-28 18:45:05 72704 ----a-w- c:\windows\system32\secur32.dll
2009-11-28 18:45:05 216576 ----a-w- c:\windows\system32\msv1_0.dll
2009-11-28 18:45:05 1233920 ----a-w- c:\windows\system32\lsasrv.dll
2009-11-28 18:43:27 2855424 ----a-w- c:\windows\system32\mf.dll
2009-11-28 18:43:26 98816 ----a-w- c:\windows\system32\mfps.dll
2009-11-28 18:43:26 52736 ----a-w- c:\windows\system32\rrinstaller.exe
2009-11-28 18:43:26 24576 ----a-w- c:\windows\system32\mfpmp.exe
2009-11-28 18:43:26 2048 ----a-w- c:\windows\system32\mferror.dll
2009-11-28 18:41:39 2048 ----a-w- c:\windows\system32\tzres.dll
2009-11-28 18:35:01 71680 ----a-w- c:\windows\system32\atl.dll
2009-11-28 18:33:51 297472 ----a-w- c:\windows\system32\gdi32.dll
2009-11-28 18:30:00 3502152 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-11-28 18:30:00 3467864 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-11-28 18:27:35 500736 ----a-w- c:\windows\system32\msdtcprx.dll
2009-11-28 18:27:35 30208 ----a-w- c:\windows\system32\xolehlp.dll
2009-11-28 18:26:26 156160 ----a-w- c:\windows\system32\wkssvc.dll
2009-11-28 18:25:15 36352 ----a-w- c:\windows\system32\tsgqec.dll
2009-11-28 18:25:15 1871872 ----a-w- c:\windows\system32\mstscax.dll
2009-11-28 18:25:15 116736 ----a-w- c:\windows\system32\aaclient.dll
2009-11-28 18:23:59 303616 ----a-w- c:\windows\system32\wmpeffects.dll
2009-11-28 18:20:25 356864 ----a-w- c:\windows\system32\MediaMetadataHandler.dll
2009-11-28 18:16:37 1244672 ----a-w- c:\windows\system32\mcmde.dll
2009-11-28 18:16:36 428032 ----a-w- c:\windows\system32\EncDec.dll
2009-11-28 18:16:36 292352 ----a-w- c:\windows\system32\psisdecd.dll
2009-11-28 18:12:42 696832 ----a-w- c:\windows\system32\localspl.dll
2009-11-28 18:11:37 88576 ----a-w- c:\windows\system32\avifil32.dll
2009-11-28 18:11:37 82944 ----a-w- c:\windows\system32\mciavi32.dll
2009-11-28 18:11:37 65024 ----a-w- c:\windows\system32\avicap32.dll
2009-11-28 18:11:37 31232 ----a-w- c:\windows\system32\msvidc32.dll
2009-11-28 18:11:37 12800 ----a-w- c:\windows\system32\msrle32.dll
2009-11-28 18:11:37 123904 ----a-w- c:\windows\system32\msvfw32.dll
2009-11-28 18:08:18 2923520 ----a-w- c:\windows\explorer.exe
2009-11-28 18:07:17 8704 ----a-w- c:\windows\system32\hcrstco.dll
2009-11-28 18:07:17 8704 ----a-w- c:\windows\system32\hccoin.dll
2009-11-28 18:06:25 24064 ----a-w- c:\windows\system32\netcfg.exe
2009-11-28 17:59:40 1585664 ----a-w- c:\windows\system32\setupapi.dll
2009-11-28 17:56:44 549888 ----a-w- c:\windows\system32\rpcss.dll
2009-11-28 17:56:42 654336 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
2009-11-28 17:56:42 24576 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
2009-11-28 17:56:41 614912 ----a-w- c:\windows\system32\wbem\fastprox.dll
2009-11-28 17:56:41 501760 ----a-w- c:\windows\system32\wbem\WmiPrvSD.dll
2009-11-28 17:56:41 247296 ----a-w- c:\windows\system32\wbem\WmiPrvSE.exe
2009-11-28 17:56:41 130560 ----a-w- c:\windows\system32\wbem\WmiDcPrv.dll
2009-11-28 17:56:40 53248 ----a-w- c:\windows\system32\iasads.dll
2009-11-28 17:56:40 37888 ----a-w- c:\windows\system32\iasdatastore.dll
2009-11-28 17:56:40 158720 ----a-w- c:\windows\system32\sdohlp.dll
============= FINISH: 21:01:27.54 ===============
Attached Files
Edited by shihalud, 07 February 2010 - 02:50 PM.