Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

POSSIBLE ROOTKIT!! Or am I just paranoid?


  • This topic is locked This topic is locked
54 replies to this topic

#1 spot2112

spot2112

  • Members
  • 86 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:33 PM

Posted 14 August 2010 - 03:02 PM

XP HE SP2 (Currently, but have had SP3 and all security updates installed before August 13)
P4 3GHz 1.5GB RAM, 200GB onboard HD with a single basic FAT32 partition (not my choice).

Hi...lots of strange things going on with my desktop.

The short version of the story is, I think I have reinfected my system after a clean install August 13. I wiped the entire drive, including rewriting the MBR and stripping all partitioning data from the drive.

I received help here previously with what I thought was the Win32k rootkit, but I don't think I ever learned what the exact malware was. That was several months ago.

Since the beginning of july, there have been lots of slowdowns and registry modification warning from Teatimer, as well as other things. For example, at one point, I received notice from Spybot SD for something called fsonlinescanner.exe - I think that was the name. Apparently there was only one copy of it, in My DocsOwnerLocal SettingsTemp. There were some locked files in that folder, but I guess that could be just normal in-use tmp files.

I also had Avira installed for a while, but it kept giving lots of false positives for removal tools left over from the previous infection.

Last week, Teatimer notified me of an increasing number of registry changes, including some data in a bootexe key value that looked like: ||?|||||||? |||||||? |||?||||?|| P ||?|||||||||||||| || ||| etc., etc....

(The pipes represent the default character windows uses when you don't have the right character set to display the string. Hopefully you get the idea.)

On 13AUG, I decided I was tired of messing around with av scans, etc., and just wiped the entire hard drive, partition table, boot record, and all. I used boot and nuke to overwrite the entire disk with zeros just to be sure there was no recoverable data that a clever rootkit could use to regenerate...I don't even know if that's possible, but I hoped the effort would prevent me having to come here for help.

But here we are again. I had to install a very few applications in order to re-establish my web connection and provide for malware detection while downloading/installing windows updates.

I tether to my jailbroken iPhone 3G, firmware 3.1.2 (spoofed as 3.1.3, in case you see that in a scan somewhere, so I needed to install iTunes 8.21 at a minimum. I also installed a handful of software that I could use to verify md5 hashes, check for hidden processes, etc. I was pretty paranoid. Also a few pieces to help audit. About 8 or 10 apps altogether.

So my system is pretty spartan at the moment.

As for recent symptoms, on August 6, all of my restore points suddenly vanished. Just prior to my August 13 reinstall, Spybot and privatefirewall 7.0 both began terminating without my interaction. They would run for several hours, then quit within a few seconds of each other. There always seemed to be traffic on my internet connection, even though nothing was being logged by the firewall.

Since the August 13 reinstall, I was only able to reinstall the first 3 (of 77) windows updates. The downloads go okay, but then the install dies. Before I wiped the hard drive, there were lots of errors with installs, too. One thing that was curious was that I never lost admin priviliges, unlike the previous infection.

I think the current malware was something I reintroduced from my external drive. (The programs I had to install to get back on the net came from the external drive, which I assumed to be infected, but I had no way of getting back on line otherwise. I did multiple scans with various types of anti-malware, with up-to-date defs, but nothing ever showed up.)

What I would like, apart from help in cleaning my system, is advice and/or help with a method of setting up a dedicated system-only logical or primary drive and a separate restore partition (if you think its necessary/desireable). I want to set up logical drives for programs, media, etc., so that I can hopefully keep everything segregated and minimize the pain of doing a restore.

When we're done, is there any way to clean my external drive without reinfecting my system drive or having to erase data from the EHD?

Best Regards,

-Gary

Update...I got my drive partitioned and resized the way I had planned, now windows is in a 13GB NTFS partition...there is a 5 GB partition where I plan to build my restore partition, and the rest of the 200 GB is either empty ntsf partitions or unformatted partitions.

I got XP3 installed and all the updates. So we're ready to rock and roll. I am guessing you will be wanting new logs, but its bedtime so I will post tomorrow, or not, if you don't want them.

In other news, I have a name... AGOBOT-KU. Actually, I have seen this name once before and just forgot. Spybot mentions it when it picks up a "blank" entry in the registry somewhere. When you ask for more information to accept/deny, it tells you the name.

Also, there has been a registry change detected by Spybot that was to have added: Autocheck autochk *sprecovr SystemRootsprecovr.txt
I denied it of course, so its not there, but I thought it might give us a clue as to where to look. If this is a memory resident program, does it write a new copy of itself on reboot each time, and then delete it once its loaded again? If so, isn't there some way we could "flash" the pagefile memory? I am sure it would send the system into a tailspin, but I have nothing critical on this drive _yet_ so it wouldn't matter to me if I corrupted something and had to repair...just an idea. I know very little about the system, and nearly nothing about the hardware, so lots of things that are bad would probably sound like a good idea to me. ;)

- Gary

Oh yeah...one more thing...msmessenger showed up in my tray for the first time in several years. You can bet I didn't put it there. I normally uninstall it, but I haven't had time to look up how to do it again. I did have it disabled, though, so someone or something wanted it running, but it wasn't me.

EDIT: Posts merged ~BP

If anyone was waiting for more serious symptoms to appear before responding, we have them. I need my computer to work, so unfortunately I cannot avoid altering the state of the system until someone responds. Please let me know when they are needed, and I will post new logs.

EDIT: Posts merged again ~BP

Attached Files


Edited by Budapest, 17 August 2010 - 04:25 PM.


BC AdBot (Login to Remove)

 


#2 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:02:33 PM

Posted 21 August 2010 - 01:39 PM

Welcome to the BleepingComputer Forums.

Since it has been a few days since you scanned your computer with HijackThis, we will need a new HijackThis log. If you have not already downloaded Random's System Information Tool (RSIT), please download Random's System Information Tool (RSIT) by random/random which includes a HijackThis log and save it to your desktop. If you have RSIT already on your computer, please run it again.
  1. Double click on RSIT.exe to run RSIT.
  2. Click Continue at the disclaimer screen.
  3. Please post the contents of log.txt.
Thank you for your patience.

Please see Preparation Guide for use before posting about your potential Malware problem.

If you have already posted this log at another forum or if you decide to seek help at another forum, please let us know. There is a shortage of helpers and taking the time of two volunteer helpers means that someone else may not be helped.

Please post your HijackThis log as a reply to this thread and not as an attachment. I am always leery of opening attachments so I always request that HijackThis logs are to be posted as a reply to the thread. I do not think that you are attaching anything scary but others may do so.

While we are working on your HijackThis log, please:
  1. Reply to this thread; do not start another!
  2. Do not make any changes on your computer during the cleaning process or download/add programs on your computer unless instructed to do so.
  3. Do not run any other tool until instructed to do so!
  4. Let me know if any of the links do not work or if any of the tools do not work.
  5. Tell me about problems or symptoms that occur during the fix.
  6. Do not run any other programs or open any other windows while doing a fix.
  7. Ask any questions that you have regarding the fix(es), the infection(s), the performance of your computer, etc.
Thanks.
You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.

#3 spot2112

spot2112
  • Topic Starter

  • Members
  • 86 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:33 PM

Posted 23 August 2010 - 01:56 PM

Since you replied on the 21st, I just wanted to send a quick reply and let you know that I am still in need of help. I will be posting the pasted logs you requested shortly.

#4 spot2112

spot2112
  • Topic Starter

  • Members
  • 86 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:33 PM

Posted 23 August 2010 - 09:26 PM

Hi Suebaby41... Below are the pasted logs from Random's sys info tool. Do you want new logs from anything else?

A lot has happened since I posted last week. As I alluded to previously, I am unable to stop working for very long as I have critical items that have to be turned in (by this wednesday, actually).

I kept working over the weekend, and eventually had to do another "clean" install.

This time I was as careful as I knew how to be. Once again, I loaded windows into RAM (from a _possibly_ compromised UBCD4Win 3.6 boot disk) and proceded to wipe every physical sector of hard drive space, including the boot record and partition table.

Different from last time, I did not at any time reconnect the external drive after the clean install. The initial re-install was from the OEM restore disk and a SP3 standalone iso downloaded on 16 JULY, which I believed to have been clean when written to DVD, based on md5 hashes. After SP3 was installed, I created an image of the drive on a hidden partition, just in case.

I could not avoid using two files that spent time, even if no more than a minute, on the infected drive. One was iTunes821.exe and the other was ExactFile-Setup.exe. That is the only weak link in my restore plan as far as I can tell.

I downloaded fresh copies of those at the last possible second straight onto a 2GB Memorex Thumb drive that I had wiped as best as I could. I checked the md5 hashes for both files before download via Virus Total, and again after download to the thumb drive. I disconnected the thumbdrive without asking.

After the clean install, I installed ExactFile from the setup on the thumbdrive, then rechecked the md5's before installing iTunes onto my "clean" C: drive.

Once I had my internet connection re-established, I used IE6 to download Firefox 3.6.8 (including some trusted addons for improving download speed and managing ads) and Privacyware Personal Firewall 7.0. Then I used Firefox to download SpywareBlaster and Spywareguard (per the tutorial on bleepingcomputer.com), Spybot S&D, and Avira anti-virus, all in that order. Then I finished updating windows, including updating to IE7. I do not want to go to IE8.

I didn't check hashes for every download, I did make sure my downloads were "certified" by softpedia, cnet, etc.

I installed some other utilities (filealyzer, regalyzer, runalyzer, filechecker, start up monitor, startup control panel (those last two I have used for years and never had a problem, the others are relatively new to me)etc.)

One thing I have not yet done is to update java runtime. I know there are other things, but I can't think of them at this moment.


After all of this effort, I ran Spybot for the first time, and guess what I saw? the blank name/blank path startup entry attributed to AGOBOT-KU, among others, that I mentioned above. I was unable to locate this entry in the registry, though I have seen it before. I am hoping this is a false positive, somehow. I cannot think how a viral entry could have survived wiping the drive and reinstalling from the OEM disk and files that all matched their hashes.

Sure hope you can help. Please let me know what else you need. I will not install/run clean-up utils as directed until you give the green light.

Logs were generated with all anti-malware/firewall/etc. turned off, or in the case of avira, disabled. My drive is in several partitions, as I am trying to compartmentalize to minimize restore time in the future (I Hope!). I will post immediately following this one to provide a screenshot of disk management to give you an idea of the partitioning scheme.

I realize it may make your task more difficult to have my drive partitioned as I do, but I didn't know for sure. So, if you need me to reconfigure to facilitate your work, just let me know and I will gladly do it.


Thanks for your time.



Logfile of random's system information tool 1.08 (written by random/random)
Run by Bracegirdle at 2010-08-23 20:33:45
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 2 GB (18%) free of 8 GB
Total RAM: 1512 MB (61% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:34:43 PM, on 8/23/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17080)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Privacyware\Privatefirewall 7.0\pfsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\StartupMonitor.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\FileChecker\filechecker.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Recuva\Recuva.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Spybot - Search & Destroy\SDFiles.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Bracegirdle\Desktop\RSIT.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\trend micro\Bracegirdle.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Privatefirewall] C:\Program Files\Privacyware\Privatefirewall 7.0\PFGUI.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FileChecker - Created by javacool. - C:\Program Files\FileChecker\filechecker.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Privacyware network service (PFNet) - Privacyware/PWI, Inc. - C:\Program Files\Privacyware\Privatefirewall 7.0\pfsvc.exe

--
End of file - 3878 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4A368E80-174F-4872-96B5-0B27DDD11DB2}]
SpywareGuardDLBLOCK.CBrowserHelper - C:\Program Files\SpywareGuard\dlprotect.dll [2003-08-02 192512]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-05-26 413696]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-07-13 292128]
""= []
"Privatefirewall"=C:\Program Files\Privacyware\Privatefirewall 7.0\PFGUI.exe [2010-08-16 2445832]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2010-03-02 282792]
"Run StartupMonitor"=C:\WINDOWS\StartupMonitor.exe [2000-05-20 86016]

C:\Documents and Settings\Bracegirdle\Start Menu\Programs\Startup
SpywareGuard.lnk - C:\Program Files\SpywareGuard\sgmain.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{81559C35-8464-49F7-BB0E-07A383BEF910}"=C:\Program Files\SpywareGuard\spywareguard.dll [2003-08-02 126976]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PFNet]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=181
"NoSMHelp"=0x01000000
"NoLogoff"=0x01000000
"NoActiveDesktop"=0x01000000
"NoWinKeys"=0x01000000
"NoRecentDocsNetHood"=0x01000000
"NoSMMyPictures"=0x01000000
"NoNetworkConnections"=0x01000000
"NoUserNameInStartMenu"=0x01000000
"NoSharedDocuments"=0x01000000
"NoDrives"=0x03000000
"NoDriveAutoRun"=0xFFFFFF03

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Disabled:iTunes"
"C:\WINDOWS\system32\mmc.exe"="C:\WINDOWS\system32\mmc.exe:*:Disabled:Microsoft Management Console"
"C:\WINDOWS\Network Diagnostic\xpnetdiag.exe"="C:\WINDOWS\Network Diagnostic\xpnetdiag.exe:*:Disabled:@xpsp3res.dll,-20000"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2010-08-23 13:56:46 ----D---- C:\WINDOWS\LastGood
2010-08-23 13:42:33 ----D---- C:\WINDOWS\ie7updates
2010-08-23 13:41:55 ----D---- C:\WINDOWS\WBEM
2010-08-23 13:40:39 ----HDC---- C:\WINDOWS\ie7
2010-08-23 13:40:22 ----HDC---- C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$
2010-08-23 13:39:57 ----HDC---- C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$
2010-08-23 12:52:31 ----D---- C:\Program Files\Safer Networking
2010-08-23 12:38:41 ----D---- C:\Documents and Settings\Bracegirdle\Application Data\Avira
2010-08-23 12:38:00 ----D---- C:\Program Files\trend micro
2010-08-23 12:37:59 ----D---- C:\rsit
2010-08-23 12:30:37 ----D---- C:\Program Files\Spybot - Search & Destroy
2010-08-23 12:30:37 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2010-08-23 12:22:59 ----HDC---- C:\WINDOWS\$NtUninstallKB979402_WM9$
2010-08-23 12:22:53 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2010-08-23 12:22:46 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2010-08-23 12:22:33 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2010-08-23 12:16:38 ----HDC---- C:\WINDOWS\$NtUninstallKB2183461$
2010-08-23 12:16:30 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2010-08-23 12:16:25 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2010-08-23 12:16:16 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2010-08-23 12:07:18 ----D---- C:\Program Files\Disk Investigator
2010-08-23 11:54:05 ----D---- C:\Program Files\Defraggler
2010-08-23 11:53:31 ----D---- C:\Program Files\Recuva
2010-08-23 11:52:02 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$
2010-08-23 11:51:56 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2010-08-23 11:51:50 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2010-08-23 11:51:43 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2010-08-23 11:51:36 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2010-08-23 11:51:29 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2010-08-23 11:51:21 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2010-08-23 11:51:16 ----HDC---- C:\WINDOWS\$NtUninstallKB982214$
2010-08-23 11:51:11 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2010-08-23 11:51:05 ----HDC---- C:\WINDOWS\$NtUninstallKB980195$
2010-08-23 11:50:59 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-08-23 11:50:54 ----HDC---- C:\WINDOWS\$NtUninstallKB2115168$
2010-08-23 11:50:47 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-08-23 11:50:42 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2010-08-23 11:50:36 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2010-08-23 11:50:30 ----HDC---- C:\WINDOWS\$NtUninstallKB981349$
2010-08-23 11:50:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$
2010-08-23 11:50:18 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2010-08-23 11:50:12 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-08-23 11:50:06 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-08-23 11:50:00 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2010-08-23 11:49:54 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-08-23 11:49:48 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2010-08-23 11:49:43 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-08-23 11:49:38 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2010-08-23 11:49:32 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2010-08-23 11:49:22 ----HDC---- C:\WINDOWS\$NtUninstallKB981852$
2010-08-23 11:49:16 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2010-08-23 11:49:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2079403$
2010-08-23 11:49:04 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2010-08-23 11:48:58 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2010-08-23 11:48:51 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2010-08-23 11:48:46 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2010-08-23 11:48:41 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-08-23 11:48:35 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2010-08-23 11:48:30 ----HDC---- C:\WINDOWS\$NtUninstallKB2160329$
2010-08-23 11:48:25 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2010-08-23 11:48:20 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2010-08-23 11:48:13 ----HDC---- C:\WINDOWS\$NtUninstallKB981793$
2010-08-23 11:48:08 ----HDC---- C:\WINDOWS\$NtUninstallKB980436$
2010-08-23 11:47:04 ----A---- C:\WINDOWS\system32\MRT.exe
2010-08-23 11:46:52 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2010-08-23 11:46:46 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2010-08-23 11:46:40 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
2010-08-23 11:46:33 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-08-23 11:46:26 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2010-08-23 11:46:19 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2010-08-23 11:46:11 ----HDC---- C:\WINDOWS\$NtUninstallKB2286198$
2010-08-23 11:46:05 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2010-08-23 11:45:59 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2010-08-23 11:45:51 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-08-23 11:45:47 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2010-08-23 11:45:42 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2010-08-23 11:45:37 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2010-08-23 11:45:33 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2010-08-23 11:45:29 ----HDC---- C:\WINDOWS\$NtUninstallKB982665$
2010-08-23 11:45:20 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2010-08-23 11:23:12 ----A---- C:\WINDOWS\system32\drivers\ssmdrv.sys
2010-08-23 11:23:09 ----A---- C:\WINDOWS\system32\drivers\avipbb.sys
2010-08-23 11:23:09 ----A---- C:\WINDOWS\system32\drivers\avgntmgr.sys
2010-08-23 11:23:09 ----A---- C:\WINDOWS\system32\drivers\avgntflt.sys
2010-08-23 11:23:09 ----A---- C:\WINDOWS\system32\drivers\avgntdd.sys
2010-08-23 11:23:08 ----D---- C:\Program Files\Avira
2010-08-23 11:23:08 ----D---- C:\Documents and Settings\All Users\Application Data\Avira
2010-08-23 11:20:47 ----N---- C:\WINDOWS\system32\xpsp4res.dll
2010-08-23 03:04:58 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-08-23 03:04:30 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2010-08-23 03:04:03 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2010-08-23 03:03:35 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2010-08-23 03:03:05 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
2010-08-23 03:02:37 ----HDC---- C:\WINDOWS\$NtUninstallKB950760$
2010-08-23 03:02:09 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-08-23 03:01:41 ----HDC---- C:\WINDOWS\$NtUninstallKB981997$
2010-08-23 03:01:13 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2010-08-23 03:00:15 ----HDC---- C:\WINDOWS\$NtUninstallKB971961$
2010-08-22 21:16:08 ----A---- C:\WINDOWS\OutLog.txt
2010-08-22 20:25:26 ----D---- C:\WINDOWS\system32\PreInstall
2010-08-22 20:25:24 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2010-08-22 20:25:24 ----HD---- C:\WINDOWS\$hf_mig$
2010-08-22 20:23:58 ----D---- C:\Program Files\SpywareGuard
2010-08-22 20:20:18 ----D---- C:\Program Files\FileChecker
2010-08-22 20:19:40 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2010-08-22 20:19:36 ----A---- C:\WINDOWS\system32\MSSTDFMT.DLL
2010-08-22 20:19:35 ----D---- C:\Program Files\SpywareBlaster
2010-08-22 08:22:27 ----A---- C:\WINDOWS\system32\PICSDK2.dll
2010-08-22 08:22:27 ----A---- C:\WINDOWS\system32\PICSDK.ini
2010-08-22 08:22:27 ----A---- C:\WINDOWS\system32\PICSDK.dll
2010-08-22 08:22:27 ----A---- C:\WINDOWS\system32\PICEntry.dll
2010-08-22 08:22:27 ----A---- C:\WINDOWS\system32\EpPicPrt.dll
2010-08-22 08:22:27 ----A---- C:\WINDOWS\system32\EpPicMgr.dll
2010-08-22 08:22:04 ----D---- C:\Documents and Settings\All Users\Application Data\UDL
2010-08-22 08:21:32 ----D---- C:\Program Files\Epson Software
2010-08-22 08:21:31 ----HD---- C:\Program Files\InstallShield Installation Information
2010-08-22 08:21:20 ----D---- C:\Documents and Settings\Bracegirdle\Application Data\InstallShield
2010-08-22 08:20:41 ----A---- C:\WINDOWS\system32\E_FLBFCA.DLL
2010-08-22 08:20:41 ----A---- C:\WINDOWS\system32\E_FD4BFCA.DLL
2010-08-22 08:20:22 ----D---- C:\Documents and Settings\All Users\Application Data\EPSON
2010-08-22 08:19:53 ----A---- C:\WINDOWS\system32\eswiaud.dll
2010-08-22 08:19:50 ----D---- C:\Program Files\epson
2010-08-22 08:10:47 ----D---- C:\WINDOWS\Prefetch
2010-08-22 01:41:37 ----D---- C:\Documents and Settings\Bracegirdle\Application Data\Apple Computer
2010-08-22 01:41:33 ----A---- C:\WINDOWS\system32\GEARAspi.dll
2010-08-22 01:41:33 ----A---- C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
2010-08-22 01:41:18 ----D---- C:\Program Files\iPod
2010-08-22 01:41:15 ----D---- C:\Program Files\iTunes
2010-08-22 01:41:15 ----D---- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2010-08-22 01:41:05 ----D---- C:\Program Files\Bonjour
2010-08-22 01:40:43 ----D---- C:\Program Files\QuickTime
2010-08-22 01:40:42 ----D---- C:\Documents and Settings\All Users\Application Data\Apple Computer
2010-08-22 01:40:31 ----D---- C:\Program Files\Apple Software Update
2010-08-22 01:40:20 ----N---- C:\WINDOWS\system32\spmsg.dll
2010-08-22 01:40:17 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2010-08-22 01:40:14 ----HDC---- C:\WINDOWS\$NtUninstallWdf01005$
2010-08-22 01:40:07 ----A---- C:\WINDOWS\system32\wdfcoinstaller01005.dll
2010-08-22 01:40:07 ----A---- C:\WINDOWS\system32\drivers\netaapl.sys
2010-08-22 01:40:04 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-08-22 01:40:04 ----A---- C:\WINDOWS\system32\usbaaplrc.dll
2010-08-22 01:40:04 ----A---- C:\WINDOWS\system32\drivers\usbaapl.sys
2010-08-22 01:39:50 ----D---- C:\Program Files\Common Files\Apple
2010-08-22 01:39:50 ----D---- C:\Documents and Settings\All Users\Application Data\Apple
2010-08-22 01:38:35 ----D---- C:\Program Files\ExactFile
2010-08-22 01:00:22 ----D---- C:\SYSPREP
2010-08-22 01:00:20 ----D---- C:\Documents and Settings\Bracegirdle\Application Data\Identities
2010-08-22 01:00:20 ----ASH---- C:\Documents and Settings\Bracegirdle\Application Data\desktop.ini
2010-08-22 01:00:19 ----SD---- C:\Documents and Settings\Bracegirdle\Application Data\Microsoft
2010-08-22 00:55:53 ----SHD---- C:\RECYCLER
2010-08-22 00:54:25 ----A---- C:\WINDOWS\system32\hidserv.dll
2010-08-22 00:54:22 ----A---- C:\WINDOWS\system32\drivers\kbdhid.sys
2010-08-22 00:54:07 ----A---- C:\WINDOWS\system32\drivers\mouhid.sys
2010-08-22 00:54:05 ----A---- C:\WINDOWS\system32\drivers\usbprint.sys
2010-08-22 00:54:01 ----A---- C:\WINDOWS\system32\drivers\usbstor.sys
2010-08-22 00:53:57 ----A---- C:\WINDOWS\system32\drivers\hidusb.sys
2010-08-22 00:53:56 ----A---- C:\WINDOWS\system32\drivers\usbccgp.sys
2010-08-22 00:53:50 ----A---- C:\WINDOWS\system32\ptpusb.dll
2010-08-22 00:53:49 ----A---- C:\WINDOWS\system32\ptpusd.dll
2010-08-22 00:53:49 ----A---- C:\WINDOWS\system32\drivers\usbscan.sys
2010-08-22 00:53:18 ----A---- C:\WINDOWS\system32\drivers\ohci1394.sys
2010-08-22 00:53:18 ----A---- C:\WINDOWS\system32\drivers\enum1394.sys
2010-08-22 00:53:18 ----A---- C:\WINDOWS\system32\drivers\1394bus.sys
2010-08-22 00:52:46 ----A---- C:\WINDOWS\system32\drivers\usbehci.sys
2010-08-22 00:52:45 ----A---- C:\WINDOWS\system32\hccoin.dll
2010-08-22 00:51:34 ----SHD---- C:\System Volume Information
2010-08-22 00:50:21 ----A---- C:\WINDOWS\system32\wzcsvc.dll
2010-08-22 00:50:21 ----A---- C:\WINDOWS\system32\wzcsapi.dll
2010-08-22 00:50:17 ----A---- C:\WINDOWS\system32\wowfaxui.dll
2010-08-22 00:50:14 ----A---- C:\WINDOWS\system32\wowfax.dll
2010-08-22 00:50:07 ----A---- C:\WINDOWS\system32\usrvpa.dll
2010-08-22 00:50:04 ----A---- C:\WINDOWS\system32\usrvoica.dll
2010-08-22 00:50:01 ----A---- C:\WINDOWS\system32\usrv80a.dll
2010-08-22 00:49:57 ----A---- C:\WINDOWS\system32\usrv42a.dll
2010-08-22 00:49:54 ----A---- C:\WINDOWS\system32\usrsvpia.dll
2010-08-22 00:49:51 ----A---- C:\WINDOWS\system32\usrshuta.exe
2010-08-22 00:49:48 ----A---- C:\WINDOWS\system32\usrsdpia.dll
2010-08-22 00:49:45 ----A---- C:\WINDOWS\system32\usrrtosa.dll
2010-08-22 00:49:41 ----A---- C:\WINDOWS\system32\usrprbda.exe
2010-08-22 00:49:36 ----A---- C:\WINDOWS\system32\usrmlnka.exe
2010-08-22 00:49:33 ----A---- C:\WINDOWS\system32\usrlbva.dll
2010-08-22 00:49:29 ----A---- C:\WINDOWS\system32\usrfaxa.dll
2010-08-22 00:49:26 ----A---- C:\WINDOWS\system32\usrdtea.dll
2010-08-22 00:49:23 ----A---- C:\WINDOWS\system32\usrdpa.dll
2010-08-22 00:49:20 ----A---- C:\WINDOWS\system32\usrcoina.dll
2010-08-22 00:49:16 ----A---- C:\WINDOWS\system32\usrcntra.dll
2010-08-22 00:49:16 ----A---- C:\WINDOWS\system32\usbui.dll
2010-08-22 00:49:12 ----A---- C:\WINDOWS\system32\tsbyuv.dll
2010-08-22 00:49:09 ----A---- C:\WINDOWS\system32\streamci.dll
2010-08-22 00:49:08 ----A---- C:\WINDOWS\system32\storprop.dll
2010-08-22 00:49:05 ----A---- C:\WINDOWS\system32\sprio800.dll
2010-08-22 00:49:02 ----A---- C:\WINDOWS\system32\sprio600.dll
2010-08-22 00:48:57 ----A---- C:\WINDOWS\system32\spnike.dll
2010-08-22 00:48:54 ----A---- C:\WINDOWS\system32\pjlmon.dll
2010-08-22 00:48:54 ----A---- C:\WINDOWS\system32\pid.dll
2010-08-22 00:48:51 ----A---- C:\WINDOWS\system32\paqsp.dll
2010-08-22 00:48:44 ----A---- C:\WINDOWS\system32\nv4_disp.dll
2010-08-22 00:48:43 ----A---- C:\WINDOWS\system32\ntkrnlpa.exe
2010-08-22 00:48:41 ----A---- C:\WINDOWS\system32\msyuv.dll
2010-08-22 00:48:35 ----A---- C:\WINDOWS\system32\mdwmdmsp.dll
2010-08-22 00:48:32 ----A---- C:\WINDOWS\system32\iyuv_32.dll
2010-08-22 00:48:29 ----A---- C:\WINDOWS\system32\hid.dll
2010-08-22 00:48:27 ----A---- C:\WINDOWS\system32\dvdplay.exe
2010-08-22 00:48:24 ----A---- C:\WINDOWS\system32\drivers\vdmindvd.sys
2010-08-22 00:48:24 ----A---- C:\WINDOWS\system32\drivers\usbintel.sys
2010-08-22 00:48:21 ----A---- C:\WINDOWS\system32\drivers\usbcamd2.sys
2010-08-22 00:48:17 ----A---- C:\WINDOWS\system32\drivers\usbcamd.sys
2010-08-22 00:48:17 ----A---- C:\WINDOWS\system32\drivers\tunmp.sys
2010-08-22 00:48:14 ----A---- C:\WINDOWS\system32\drivers\tsbvcap.sys
2010-08-22 00:48:11 ----A---- C:\WINDOWS\system32\drivers\tosdvd.sys
2010-08-22 00:48:11 ----A---- C:\WINDOWS\system32\drivers\termdd.sys
2010-08-22 00:48:10 ----A---- C:\WINDOWS\system32\drivers\swenum.sys
2010-08-22 00:48:10 ----A---- C:\WINDOWS\system32\drivers\stream.sys
2010-08-22 00:48:10 ----A---- C:\WINDOWS\system32\drivers\sonydcam.sys
2010-08-22 00:48:07 ----A---- C:\WINDOWS\system32\drivers\riodrv.sys
2010-08-22 00:48:04 ----A---- C:\WINDOWS\system32\drivers\rio8drv.sys
2010-08-22 00:48:04 ----A---- C:\WINDOWS\system32\drivers\redbook.sys
2010-08-22 00:48:03 ----A---- C:\WINDOWS\system32\drivers\rdpdr.sys
2010-08-22 00:48:03 ----A---- C:\WINDOWS\system32\drivers\processr.sys
2010-08-22 00:48:02 ----A---- C:\WINDOWS\system32\drivers\parport.sys
2010-08-22 00:48:02 ----A---- C:\WINDOWS\system32\drivers\p3.sys
2010-08-22 00:48:01 ----A---- C:\WINDOWS\system32\drivers\nv4_mini.sys
2010-08-22 00:47:59 ----A---- C:\WINDOWS\system32\drivers\nikedrv.sys
2010-08-22 00:47:58 ----A---- C:\WINDOWS\system32\drivers\nic1394.sys
2010-08-22 00:47:57 ----A---- C:\WINDOWS\system32\drivers\ndisuio.sys
2010-08-22 00:47:55 ----A---- C:\WINDOWS\system32\drivers\mxnic.sys
2010-08-22 00:47:54 ----A---- C:\WINDOWS\system32\drivers\mssmbios.sys
2010-08-22 00:47:53 ----A---- C:\WINDOWS\system32\drivers\mouclass.sys
2010-08-22 00:47:53 ----A---- C:\WINDOWS\system32\drivers\modem.sys
2010-08-22 00:47:53 ----A---- C:\WINDOWS\system32\drivers\mf.sys
2010-08-22 00:47:52 ----A---- C:\WINDOWS\system32\drivers\ks.sys
2010-08-22 00:47:50 ----A---- C:\WINDOWS\system32\drivers\fsvga.sys
2010-08-22 00:47:49 ----A---- C:\WINDOWS\system32\drivers\crusoe.sys
2010-08-22 00:47:48 ----A---- C:\WINDOWS\system32\drivers\cpqdap01.sys
2010-08-22 00:47:48 ----A---- C:\WINDOWS\system32\drivers\cinemst2.sys
2010-08-22 00:47:48 ----A---- C:\WINDOWS\system32\drivers\cdaudio.sys
2010-08-22 00:47:47 ----A---- C:\WINDOWS\system32\drivers\viaagp.sys
2010-08-22 00:47:47 ----A---- C:\WINDOWS\system32\drivers\audstub.sys
2010-08-22 00:47:47 ----A---- C:\WINDOWS\system32\drivers\arp1394.sys
2010-08-22 00:47:47 ----A---- C:\WINDOWS\system32\drivers\amdk7.sys
2010-08-22 00:47:47 ----A---- C:\WINDOWS\system32\drivers\amdk6.sys
2010-08-22 00:47:46 ----A---- C:\WINDOWS\system32\drivers\sisagp.sys
2010-08-22 00:47:46 ----A---- C:\WINDOWS\system32\drivers\amdagp.sys
2010-08-22 00:47:45 ----A---- C:\WINDOWS\system32\drivers\alim1541.sys
2010-08-22 00:47:45 ----A---- C:\WINDOWS\system32\drivers\agpcpq.sys
2010-08-22 00:47:45 ----A---- C:\WINDOWS\system32\drivers\agp440.sys
2010-08-22 00:47:44 ----A---- C:\WINDOWS\system32\dmutil.dll
2010-08-22 00:47:08 ----A---- C:\WINDOWS\system32\cnbjmon.dll
2010-08-22 00:46:41 ----D---- C:\WINDOWS\SMINST
2010-08-22 00:46:31 ----A---- C:\WINDOWS\_default.pif
2010-08-22 00:46:30 ----A---- C:\WINDOWS\system32\zipfldr.dll
2010-08-22 00:46:29 ----A---- C:\WINDOWS\system32\xpsp2res.dll
2010-08-22 00:46:29 ----A---- C:\WINDOWS\system32\xpsp1res.dll
2010-08-22 00:46:29 ----A---- C:\WINDOWS\system32\xpob2res.dll
2010-08-22 00:46:28 ----A---- C:\WINDOWS\system32\xolehlp.dll
2010-08-22 00:46:28 ----A---- C:\WINDOWS\system32\xmlprovi.dll
2010-08-22 00:46:28 ----A---- C:\WINDOWS\system32\xmlprov.dll
2010-08-22 00:46:28 ----A---- C:\WINDOWS\system32\xenroll.dll
2010-08-22 00:46:28 ----A---- C:\WINDOWS\system32\xcopy.exe
2010-08-22 00:46:28 ----A---- C:\WINDOWS\system32\xactsrv.dll
2010-08-22 00:46:28 ----A---- C:\WINDOWS\system32\wzcdlg.dll
2010-08-22 00:46:28 ----A---- C:\WINDOWS\system32\wuweb.dll
2010-08-22 00:46:28 ----A---- C:\WINDOWS\system32\wups.dll
2010-08-22 00:46:28 ----A---- C:\WINDOWS\system32\wupdmgr.exe
2010-08-22 00:46:28 ----A---- C:\WINDOWS\system32\wucltui.dll
2010-08-22 00:46:28 ----A---- C:\WINDOWS\system32\wuauserv.dll
2010-08-22 00:46:28 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2010-08-22 00:46:27 ----A---- C:\WINDOWS\system32\wuaueng.dll
2010-08-22 00:46:27 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2010-08-22 00:46:27 ----A---- C:\WINDOWS\system32\wuauclt.exe
2010-08-22 00:46:27 ----A---- C:\WINDOWS\system32\wuapi.dll
2010-08-22 00:46:27 ----A---- C:\WINDOWS\system32\wtsapi32.dll
2010-08-22 00:46:27 ----A---- C:\WINDOWS\system32\wstdecod.dll
2010-08-22 00:46:27 ----A---- C:\WINDOWS\system32\wsock32.dll
2010-08-22 00:46:27 ----A---- C:\WINDOWS\system32\wsnmp32.dll
2010-08-22 00:46:27 ----A---- C:\WINDOWS\system32\wshtcpip.dll
2010-08-22 00:46:27 ----A---- C:\WINDOWS\system32\wshrm.dll
2010-08-22 00:46:27 ----A---- C:\WINDOWS\system32\wshnetbs.dll
2010-08-22 00:46:27 ----A---- C:\WINDOWS\system32\wshisn.dll
2010-08-22 00:46:27 ----A---- C:\WINDOWS\system32\wship6.dll
2010-08-22 00:46:27 ----A---- C:\WINDOWS\system32\wshext.dll
2010-08-22 00:46:27 ----A---- C:\WINDOWS\system32\wshcon.dll
2010-08-22 00:46:27 ----A---- C:\WINDOWS\system32\wshbth.dll
2010-08-22 00:46:27 ----A---- C:\WINDOWS\system32\wshatm.dll
2010-08-22 00:46:27 ----A---- C:\WINDOWS\system32\wscsvc.dll
2010-08-22 00:46:27 ----A---- C:\WINDOWS\system32\wscript.exe
2010-08-22 00:46:27 ----A---- C:\WINDOWS\system32\wscntfy.exe
2010-08-22 00:46:27 ----A---- C:\WINDOWS\system32\ws2help.dll
2010-08-22 00:46:27 ----A---- C:\WINDOWS\system32\ws2_32.dll
2010-08-22 00:46:27 ----A---- C:\WINDOWS\system32\write.exe
2010-08-22 00:46:27 ----A---- C:\WINDOWS\system32\wpnpinst.exe
2010-08-22 00:46:27 ----A---- C:\WINDOWS\system32\wpabaln.exe
2010-08-22 00:46:27 ----A---- C:\WINDOWS\system32\wowexec.exe
2010-08-22 00:46:27 ----A---- C:\WINDOWS\system32\wowdeb.exe
2010-08-22 00:46:27 ----A---- C:\WINDOWS\system32\wow32.dll
2010-08-22 00:46:27 ----A---- C:\WINDOWS\system32\drivers\ws2ifsl.sys
2010-08-22 00:46:26 ----A---- C:\WINDOWS\system32\wmvdmoe2.dll
2010-08-22 00:46:26 ----A---- C:\WINDOWS\system32\wmvdmod.dll
2010-08-22 00:46:26 ----A---- C:\WINDOWS\system32\WMVCore.dll
2010-08-22 00:46:26 ----A---- C:\WINDOWS\system32\wmstream.dll
2010-08-22 00:46:25 ----A---- C:\WINDOWS\system32\wmspdmoe.dll
2010-08-22 00:46:25 ----A---- C:\WINDOWS\system32\wmspdmod.dll
2010-08-22 00:46:25 ----A---- C:\WINDOWS\system32\wmsdmoe2.dll
2010-08-22 00:46:25 ----A---- C:\WINDOWS\system32\wmsdmoe.dll
2010-08-22 00:46:25 ----A---- C:\WINDOWS\system32\wmsdmod.dll
2010-08-22 00:46:25 ----A---- C:\WINDOWS\system32\wmpui.dll
2010-08-22 00:46:25 ----A---- C:\WINDOWS\system32\wmpshell.dll
2010-08-22 00:46:24 ----A---- C:\WINDOWS\system32\wmploc.dll
2010-08-22 00:46:24 ----A---- C:\WINDOWS\system32\wmpdxm.dll
2010-08-22 00:46:24 ----A---- C:\WINDOWS\system32\wmpcore.dll
2010-08-22 00:46:24 ----A---- C:\WINDOWS\system32\wmpcd.dll
2010-08-22 00:46:23 ----A---- C:\WINDOWS\system32\wmpasf.dll
2010-08-22 00:46:23 ----A---- C:\WINDOWS\system32\wmp.dll
2010-08-22 00:46:22 ----A---- C:\WINDOWS\system32\WMNetmgr.dll
2010-08-22 00:46:21 ----A---- C:\WINDOWS\system32\wmiprop.dll
2010-08-22 00:46:21 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2010-08-22 00:46:21 ----A---- C:\WINDOWS\system32\wmidx.dll
2010-08-22 00:46:21 ----A---- C:\WINDOWS\system32\wmi.dll
2010-08-22 00:46:21 ----A---- C:\WINDOWS\system32\wmerror.dll
2010-08-22 00:46:21 ----A---- C:\WINDOWS\system32\wmerrenu.dll
2010-08-22 00:46:21 ----A---- C:\WINDOWS\system32\wmdmps.dll
2010-08-22 00:46:21 ----A---- C:\WINDOWS\system32\wmdmlog.dll
2010-08-22 00:46:21 ----A---- C:\WINDOWS\system32\wmasf.dll
2010-08-22 00:46:21 ----A---- C:\WINDOWS\system32\wmadmoe.dll
2010-08-22 00:46:21 ----A---- C:\WINDOWS\system32\wmadmod.dll
2010-08-22 00:46:21 ----A---- C:\WINDOWS\system32\drivers\wmilib.sys
2010-08-22 00:46:20 ----A---- C:\WINDOWS\system32\wlnotify.dll
2010-08-22 00:46:20 ----A---- C:\WINDOWS\system32\wldap32.dll
2010-08-22 00:46:20 ----A---- C:\WINDOWS\system32\wkssvc.dll
2010-08-22 00:46:20 ----A---- C:\WINDOWS\system32\winver.exe
2010-08-22 00:46:20 ----A---- C:\WINDOWS\system32\wintrust.dll
2010-08-22 00:46:20 ----A---- C:\WINDOWS\system32\winstrm.dll
2010-08-22 00:46:20 ----A---- C:\WINDOWS\system32\winsta.dll
2010-08-22 00:46:20 ----A---- C:\WINDOWS\system32\winsrv.dll
2010-08-22 00:46:20 ----A---- C:\WINDOWS\system32\winspool.exe
2010-08-22 00:46:20 ----A---- C:\WINDOWS\system32\winsock.dll
2010-08-22 00:46:20 ----A---- C:\WINDOWS\system32\winshfhc.dll
2010-08-22 00:46:20 ----A---- C:\WINDOWS\system32\winscard.dll
2010-08-22 00:46:20 ----A---- C:\WINDOWS\system32\winrnr.dll
2010-08-22 00:46:20 ----A---- C:\WINDOWS\system32\winntbbu.dll
2010-08-22 00:46:18 ----A---- C:\WINDOWS\winhlp32.exe
2010-08-22 00:46:18 ----A---- C:\WINDOWS\system32\winnls.dll
2010-08-22 00:46:18 ----A---- C:\WINDOWS\system32\winmsd.exe
2010-08-22 00:46:18 ----A---- C:\WINDOWS\system32\winmm.dll
2010-08-22 00:46:18 ----A---- C:\WINDOWS\system32\winmine.exe
2010-08-22 00:46:18 ----A---- C:\WINDOWS\system32\winlogon.exe
2010-08-22 00:46:18 ----A---- C:\WINDOWS\system32\winipsec.dll
2010-08-22 00:46:18 ----A---- C:\WINDOWS\system32\wininet.dll
2010-08-22 00:46:18 ----A---- C:\WINDOWS\system32\winhttp.dll
2010-08-22 00:46:18 ----A---- C:\WINDOWS\system32\winhlp32.exe
2010-08-22 00:46:17 ----A---- C:\WINDOWS\winhelp.exe
2010-08-22 00:46:17 ----A---- C:\WINDOWS\system32\winfax.dll
2010-08-22 00:46:17 ----A---- C:\WINDOWS\system32\winchat.exe
2010-08-22 00:46:17 ----A---- C:\WINDOWS\system32\winbrand.dll
2010-08-22 00:46:17 ----A---- C:\WINDOWS\system32\win87em.dll
2010-08-22 00:46:17 ----A---- C:\WINDOWS\system32\win32spl.dll
2010-08-22 00:46:16 ----A---- C:\WINDOWS\system32\win32k.sys
2010-08-22 00:46:16 ----A---- C:\WINDOWS\system32\win.com
2010-08-22 00:46:16 ----A---- C:\WINDOWS\system32\wifeman.dll
2010-08-22 00:46:16 ----A---- C:\WINDOWS\system32\wiavusd.dll
2010-08-22 00:46:16 ----A---- C:\WINDOWS\system32\wiavideo.dll
2010-08-22 00:46:16 ----A---- C:\WINDOWS\system32\wiashext.dll
2010-08-22 00:46:16 ----A---- C:\WINDOWS\system32\wiaservc.dll
2010-08-22 00:46:16 ----A---- C:\WINDOWS\system32\wiascr.dll
2010-08-22 00:46:16 ----A---- C:\WINDOWS\system32\wiadss.dll
2010-08-22 00:46:16 ----A---- C:\WINDOWS\system32\wiadefui.dll
2010-08-22 00:46:16 ----A---- C:\WINDOWS\system32\wiaacmgr.exe
2010-08-22 00:46:16 ----A---- C:\WINDOWS\system32\wextract.exe
2010-08-22 00:46:16 ----A---- C:\WINDOWS\system32\webvw.dll
2010-08-22 00:46:16 ----A---- C:\WINDOWS\system32\webhits.dll
2010-08-22 00:46:15 ----A---- C:\WINDOWS\system32\webclnt.dll
2010-08-22 00:46:15 ----A---- C:\WINDOWS\system32\webcheck.dll
2010-08-22 00:46:15 ----A---- C:\WINDOWS\system32\wdigest.dll
2010-08-22 00:46:12 ----A---- C:\WINDOWS\vmmreg32.dll
2010-08-22 00:46:12 ----A---- C:\WINDOWS\system32\wavemsp.dll
2010-08-22 00:46:12 ----A---- C:\WINDOWS\system32\watchdog.sys
2010-08-22 00:46:12 ----A---- C:\WINDOWS\system32\w3ssl.dll
2010-08-22 00:46:12 ----A---- C:\WINDOWS\system32\w32topl.dll
2010-08-22 00:46:12 ----A---- C:\WINDOWS\system32\w32tm.exe
2010-08-22 00:46:12 ----A---- C:\WINDOWS\system32\w32time.dll
2010-08-22 00:46:12 ----A---- C:\WINDOWS\system32\vssvc.exe
2010-08-22 00:46:12 ----A---- C:\WINDOWS\system32\vssapi.dll
2010-08-22 00:46:12 ----A---- C:\WINDOWS\system32\vssadmin.exe
2010-08-22 00:46:12 ----A---- C:\WINDOWS\system32\vss_ps.dll
2010-08-22 00:46:12 ----A---- C:\WINDOWS\system32\vjoy.dll
2010-08-22 00:46:12 ----A---- C:\WINDOWS\system32\drivers\wanarp.sys
2010-08-22 00:46:12 ----A---- C:\WINDOWS\system32\drivers\volsnap.sys
2010-08-22 00:46:12 ----A---- C:\WINDOWS\system32\drivers\videoprt.sys
2010-08-22 00:46:12 ----A---- C:\WINDOWS\system32\drivers\viaide.sys
2010-08-22 00:46:11 ----A---- C:\WINDOWS\system32\vga64k.dll
2010-08-22 00:46:11 ----A---- C:\WINDOWS\system32\vga256.dll
2010-08-22 00:46:11 ----A---- C:\WINDOWS\system32\vga.dll
2010-08-22 00:46:11 ----A---- C:\WINDOWS\system32\vfpodbc.dll
2010-08-22 00:46:11 ----A---- C:\WINDOWS\system32\version.dll
2010-08-22 00:46:11 ----A---- C:\WINDOWS\system32\verifier.exe
2010-08-22 00:46:11 ----A---- C:\WINDOWS\system32\verifier.dll
2010-08-22 00:46:11 ----A---- C:\WINDOWS\system32\ver.dll
2010-08-22 00:46:11 ----A---- C:\WINDOWS\system32\vdmredir.dll
2010-08-22 00:46:11 ----A---- C:\WINDOWS\system32\vdmdbg.dll
2010-08-22 00:46:11 ----A---- C:\WINDOWS\system32\vcdex.dll
2010-08-22 00:46:11 ----A---- C:\WINDOWS\system32\vbscript.dll
2010-08-22 00:46:11 ----A---- C:\WINDOWS\system32\vbajet32.dll
2010-08-22 00:46:11 ----A---- C:\WINDOWS\system32\uxtheme.dll
2010-08-22 00:46:11 ----A---- C:\WINDOWS\system32\drivers\vga.sys
2010-08-22 00:46:10 ----A---- C:\WINDOWS\system32\utilman.exe
2010-08-22 00:46:10 ----A---- C:\WINDOWS\system32\utildll.dll
2010-08-22 00:46:10 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2010-08-22 00:46:10 ----A---- C:\WINDOWS\system32\usp10.dll
2010-08-22 00:46:10 ----A---- C:\WINDOWS\system32\userinit.exe
2010-08-22 00:46:10 ----A---- C:\WINDOWS\system32\userenv.dll
2010-08-22 00:46:10 ----A---- C:\WINDOWS\system32\user32.dll
2010-08-22 00:46:10 ----A---- C:\WINDOWS\system32\user.exe
2010-08-22 00:46:10 ----A---- C:\WINDOWS\system32\usbmon.dll
2010-08-22 00:46:10 ----A---- C:\WINDOWS\system32\drivers\usbuhci.sys
2010-08-22 00:46:10 ----A---- C:\WINDOWS\system32\drivers\usbport.sys
2010-08-22 00:46:10 ----A---- C:\WINDOWS\system32\drivers\usbhub.sys
2010-08-22 00:46:10 ----A---- C:\WINDOWS\system32\drivers\usbd.sys
2010-08-22 00:46:09 ----A---- C:\WINDOWS\system32\urlmon.dll
2010-08-22 00:46:09 ----A---- C:\WINDOWS\system32\url.dll
2010-08-22 00:46:09 ----A---- C:\WINDOWS\system32\ureg.dll
2010-08-22 00:46:09 ----A---- C:\WINDOWS\system32\ups.exe
2010-08-22 00:46:09 ----A---- C:\WINDOWS\system32\upnpui.dll
2010-08-22 00:46:09 ----A---- C:\WINDOWS\system32\upnphost.dll
2010-08-22 00:46:09 ----A---- C:\WINDOWS\system32\upnpcont.exe
2010-08-22 00:46:09 ----A---- C:\WINDOWS\system32\upnp.dll
2010-08-22 00:46:09 ----A---- C:\WINDOWS\system32\drivers\usb8023.sys
2010-08-22 00:46:09 ----A---- C:\WINDOWS\system32\drivers\update.sys
2010-08-22 00:46:08 ----A---- C:\WINDOWS\twunk_32.exe
2010-08-22 00:46:08 ----A---- C:\WINDOWS\twunk_16.exe
2010-08-22 00:46:08 ----A---- C:\WINDOWS\twain_32.dll
2010-08-22 00:46:08 ----A---- C:\WINDOWS\twain.dll
2010-08-22 00:46:08 ----A---- C:\WINDOWS\system32\untfs.dll
2010-08-22 00:46:08 ----A---- C:\WINDOWS\system32\unlodctr.exe
2010-08-22 00:46:08 ----A---- C:\WINDOWS\system32\uniplat.dll
2010-08-22 00:46:08 ----A---- C:\WINDOWS\system32\unimdmat.dll
2010-08-22 00:46:08 ----A---- C:\WINDOWS\system32\umpnpmgr.dll
2010-08-22 00:46:08 ----A---- C:\WINDOWS\system32\umdmxfrm.dll
2010-08-22 00:46:08 ----A---- C:\WINDOWS\system32\umandlg.dll
2010-08-22 00:46:08 ----A---- C:\WINDOWS\system32\ulib.dll
2010-08-22 00:46:08 ----A---- C:\WINDOWS\system32\ufat.dll
2010-08-22 00:46:08 ----A---- C:\WINDOWS\system32\udhisapi.dll
2010-08-22 00:46:08 ----A---- C:\WINDOWS\system32\typelib.dll
2010-08-22 00:46:08 ----A---- C:\WINDOWS\system32\txflog.dll
2010-08-22 00:46:08 ----A---- C:\WINDOWS\system32\twext.dll
2010-08-22 00:46:08 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2010-08-22 00:46:08 ----A---- C:\WINDOWS\system32\tslabels.ini
2010-08-22 00:46:08 ----A---- C:\WINDOWS\system32\tskill.exe
2010-08-22 00:46:08 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2010-08-22 00:46:08 ----A---- C:\WINDOWS\system32\tsddd.dll
2010-08-22 00:46:08 ----A---- C:\WINDOWS\system32\tsd32.dll
2010-08-22 00:46:08 ----A---- C:\WINDOWS\system32\tscupgrd.exe
2010-08-22 00:46:08 ----A---- C:\WINDOWS\system32\tscon.exe
2010-08-22 00:46:08 ----A---- C:\WINDOWS\system32\drivers\ultra.sys
2010-08-22 00:46:08 ----A---- C:\WINDOWS\system32\drivers\udfs.sys
2010-08-22 00:46:07 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2010-08-22 00:46:07 ----A---- C:\WINDOWS\system32\tsappcmp.dll
2010-08-22 00:46:07 ----A---- C:\WINDOWS\system32\trkwks.dll
2010-08-22 00:46:07 ----A---- C:\WINDOWS\system32\tree.com
2010-08-22 00:46:07 ----A---- C:\WINDOWS\system32\traffic.dll
2010-08-22 00:46:07 ----A---- C:\WINDOWS\system32\tracert6.exe
2010-08-22 00:46:07 ----A---- C:\WINDOWS\system32\tracert.exe
2010-08-22 00:46:07 ----A---- C:\WINDOWS\system32\tourstart.exe
2010-08-22 00:46:06 ----A---- C:\WINDOWS\system32\toolhelp.dll
2010-08-22 00:46:06 ----A---- C:\WINDOWS\system32\drivers\toside.sys
2010-08-22 00:46:04 ----A---- C:\WINDOWS\system32\themeui.dll
2010-08-22 00:46:04 ----A---- C:\WINDOWS\system32\tftp.exe
2010-08-22 00:46:04 ----A---- C:\WINDOWS\system32\termsrv.dll
2010-08-22 00:46:04 ----A---- C:\WINDOWS\system32\termmgr.dll
2010-08-22 00:46:04 ----A---- C:\WINDOWS\system32\telnet.exe
2010-08-22 00:46:04 ----A---- C:\WINDOWS\system32\tcpsvcs.exe
2010-08-22 00:46:04 ----A---- C:\WINDOWS\system32\tcpmonui.dll
2010-08-22 00:46:04 ----A---- C:\WINDOWS\system32\tcpmon.ini
2010-08-22 00:46:04 ----A---- C:\WINDOWS\system32\tcpmon.dll
2010-08-22 00:46:04 ----A---- C:\WINDOWS\system32\tcpmib.dll
2010-08-22 00:46:04 ----A---- C:\WINDOWS\system32\drivers\tdtcp.sys
2010-08-22 00:46:04 ----A---- C:\WINDOWS\system32\drivers\tdpipe.sys
2010-08-22 00:46:04 ----A---- C:\WINDOWS\system32\drivers\tdi.sys
2010-08-22 00:46:04 ----A---- C:\WINDOWS\system32\drivers\tcpip6.sys
2010-08-22 00:46:03 ----A---- C:\WINDOWS\TASKMAN.EXE
2010-08-22 00:46:03 ----A---- C:\WINDOWS\system32\tcmsetup.exe
2010-08-22 00:46:03 ----A---- C:\WINDOWS\system32\taskmgr.exe
2010-08-22 00:46:03 ----A---- C:\WINDOWS\system32\taskman.exe
2010-08-22 00:46:03 ----A---- C:\WINDOWS\system32\tapiui.dll
2010-08-22 00:46:03 ----A---- C:\WINDOWS\system32\tapisrv.dll
2010-08-22 00:46:03 ----A---- C:\WINDOWS\system32\tapiperf.dll
2010-08-22 00:46:03 ----A---- C:\WINDOWS\system32\tapi32.dll
2010-08-22 00:46:03 ----A---- C:\WINDOWS\system32\tapi3.dll
2010-08-22 00:46:03 ----A---- C:\WINDOWS\system32\tapi.dll
2010-08-22 00:46:03 ----A---- C:\WINDOWS\system32\t2embed.dll
2010-08-22 00:46:03 ----A---- C:\WINDOWS\system32\systray.exe
2010-08-22 00:46:03 ----A---- C:\WINDOWS\system32\syssetup.dll
2010-08-22 00:46:03 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2010-08-22 00:46:03 ----A---- C:\WINDOWS\system32\drivers\tape.sys
2010-08-22 00:46:02 ----A---- C:\WINDOWS\system32\sysocmgr.exe
2010-08-22 00:46:02 ----A---- C:\WINDOWS\system32\syskey.exe
2010-08-22 00:46:02 ----A---- C:\WINDOWS\system32\sysinv.dll
2010-08-22 00:46:02 ----A---- C:\WINDOWS\system32\sysedit.exe
2010-08-22 00:46:02 ----A---- C:\WINDOWS\system32\syncui.dll
2010-08-22 00:46:02 ----A---- C:\WINDOWS\system32\synceng.dll
2010-08-22 00:46:02 ----A---- C:\WINDOWS\system32\syncapp.exe
2010-08-22 00:46:02 ----A---- C:\WINDOWS\system32\drivers\symc8xx.sys
2010-08-22 00:46:02 ----A---- C:\WINDOWS\system32\drivers\symc810.sys
2010-08-22 00:46:02 ----A---- C:\WINDOWS\system32\drivers\sym_u3.sys
2010-08-22 00:46:02 ----A---- C:\WINDOWS\system32\drivers\sym_hi.sys
2010-08-22 00:46:01 ----A---- C:\WINDOWS\system32\sxs.dll
2010-08-22 00:46:01 ----A---- C:\WINDOWS\system32\swprv.dll
2010-08-22 00:46:01 ----A---- C:\WINDOWS\system32\svcpack.dll
2010-08-22 00:46:01 ----A---- C:\WINDOWS\system32\svchost.exe
2010-08-22 00:46:01 ----A---- C:\WINDOWS\system32\subst.exe
2010-08-22 00:46:01 ----A---- C:\WINDOWS\system32\strmfilt.dll
2010-08-22 00:46:01 ----A---- C:\WINDOWS\system32\strmdll.dll
2010-08-22 00:46:01 ----A---- C:\WINDOWS\system32\storage.dll
2010-08-22 00:46:01 ----A---- C:\WINDOWS\system32\stobject.dll
2010-08-22 00:46:01 ----A---- C:\WINDOWS\system32\stimon.exe
2010-08-22 00:46:01 ----A---- C:\WINDOWS\system32\sti_ci.dll
2010-08-22 00:46:01 ----A---- C:\WINDOWS\system32\sti.dll
2010-08-22 00:46:01 ----A---- C:\WINDOWS\system32\stclient.dll
2010-08-22 00:46:00 ----A---- C:\WINDOWS\system32\ssdpsrv.dll
2010-08-22 00:46:00 ----A---- C:\WINDOWS\system32\ssdpapi.dll
2010-08-22 00:46:00 ----A---- C:\WINDOWS\system32\srvsvc.dll
2010-08-22 00:46:00 ----A---- C:\WINDOWS\system32\srsvc.dll
2010-08-22 00:46:00 ----A---- C:\WINDOWS\system32\drivers\srv.sys
2010-08-22 00:45:59 ----A---- C:\WINDOWS\system32\srrstr.dll
2010-08-22 00:45:59 ----A---- C:\WINDOWS\system32\srclient.dll
2010-08-22 00:45:59 ----A---- C:\WINDOWS\system32\sqlwoa.dll
2010-08-22 00:45:59 ----A---- C:\WINDOWS\system32\sqlwid.dll
2010-08-22 00:45:59 ----A---- C:\WINDOWS\system32\sqlunirl.dll
2010-08-22 00:45:59 ----A---- C:\WINDOWS\system32\sqlsrv32.dll
2010-08-22 00:45:59 ----A---- C:\WINDOWS\system32\spxcoins.dll
2010-08-22 00:45:59 ----A---- C:\WINDOWS\system32\drivers\sr.sys
2010-08-22 00:45:58 ----A---- C:\WINDOWS\system32\sprestrt.exe
2010-08-22 00:45:58 ----A---- C:\WINDOWS\system32\spoolsv.exe
2010-08-22 00:45:58 ----A---- C:\WINDOWS\system32\spoolss.dll
2010-08-22 00:45:58 ----A---- C:\WINDOWS\system32\spnpinst.exe
2010-08-22 00:45:58 ----A---- C:\WINDOWS\system32\spider.exe
2010-08-22 00:45:58 ----A---- C:\WINDOWS\system32\drivers\sparrow.sys
2010-08-22 00:45:57 ----A---- C:\WINDOWS\system32\sort.exe
2010-08-22 00:45:57 ----A---- C:\WINDOWS\system32\sol.exe
2010-08-22 00:45:57 ----A---- C:\WINDOWS\system32\softpub.dll
2010-08-22 00:45:56 ----A---- C:\WINDOWS\system32\snmpsnap.dll
2010-08-22 00:45:56 ----A---- C:\WINDOWS\system32\snmpapi.dll
2010-08-22 00:45:56 ----A---- C:\WINDOWS\system32\sndvol32.exe
2010-08-22 00:45:56 ----A---- C:\WINDOWS\system32\sndrec32.exe
2010-08-22 00:45:56 ----A---- C:\WINDOWS\system32\smss.exe
2010-08-22 00:45:56 ----A---- C:\WINDOWS\system32\smlogsvc.exe
2010-08-22 00:45:56 ----A---- C:\WINDOWS\system32\smlogcfg.dll
2010-08-22 00:45:56 ----A---- C:\WINDOWS\system32\smbinst.exe
2010-08-22 00:45:56 ----A---- C:\WINDOWS\system32\drivers\smclib.sys
2010-08-22 00:45:55 ----A---- C:\WINDOWS\system32\slbrccsp.dll
2010-08-22 00:45:55 ----A---- C:\WINDOWS\system32\slbiop.dll
2010-08-22 00:45:55 ----A---- C:\WINDOWS\system32\slbcsp.dll
2010-08-22 00:45:55 ----A---- C:\WINDOWS\system32\slayerxp.dll
2010-08-22 00:45:55 ----A---- C:\WINDOWS\system32\skeys.exe
2010-08-22 00:45:55 ----A---- C:\WINDOWS\system32\skdll.dll
2010-08-22 00:45:55 ----A---- C:\WINDOWS\system32\sisbkup.dll
2010-08-22 00:45:55 ----A---- C:\WINDOWS\system32\sigverif.exe
2010-08-22 00:45:55 ----A---- C:\WINDOWS\system32\sigtab.dll
2010-08-22 00:45:54 ----A---- C:\WINDOWS\system32\shutdown.exe
2010-08-22 00:45:54 ----A---- C:\WINDOWS\system32\shsvcs.dll
2010-08-22 00:45:54 ----A---- C:\WINDOWS\system32\shscrap.dll
2010-08-22 00:45:54 ----A---- C:\WINDOWS\system32\shrpubw.exe
2010-08-22 00:45:54 ----A---- C:\WINDOWS\system32\shmgrate.exe
2010-08-22 00:45:54 ----A---- C:\WINDOWS\system32\shmedia.dll
2010-08-22 00:45:54 ----A---- C:\WINDOWS\system32\shlwapi.dll
2010-08-22 00:45:54 ----A---- C:\WINDOWS\system32\shimgvw.dll
2010-08-22 00:45:54 ----A---- C:\WINDOWS\system32\shimeng.dll
2010-08-22 00:45:54 ----A---- C:\WINDOWS\system32\shgina.dll
2010-08-22 00:45:54 ----A---- C:\WINDOWS\system32\shfolder.dll
2010-08-22 00:45:53 ----A---- C:\WINDOWS\system32\shell32.dll
2010-08-22 00:45:53 ----A---- C:\WINDOWS\system32\shell.dll
2010-08-22 00:45:53 ----A---- C:\WINDOWS\system32\shdocvw.dll
2010-08-22 00:45:53 ----A---- C:\WINDOWS\system32\shdoclc.dll
2010-08-22 00:45:53 ----A---- C:\WINDOWS\system32\share.exe
2010-08-22 00:45:53 ----A---- C:\WINDOWS\system32\shadow.exe
2010-08-22 00:45:53 ----A---- C:\WINDOWS\system32\sfmapi.dll
2010-08-22 00:45:53 ----A---- C:\WINDOWS\system32\sfc_os.dll
2010-08-22 00:45:53 ----A---- C:\WINDOWS\system32\drivers\sfloppy.sys
2010-08-22 00:45:53 ----A---- C:\WINDOWS\system32\drivers\sffp_sd.sys
2010-08-22 00:45:53 ----A---- C:\WINDOWS\system32\drivers\sffdisk.sys
2010-08-22 00:45:52 ----A---- C:\WINDOWS\system32\sfcfiles.dll
2010-08-22 00:45:52 ----A---- C:\WINDOWS\system32\sfc.exe
2010-08-22 00:45:52 ----A---- C:\WINDOWS\system32\sfc.dll
2010-08-22 00:45:52 ----A---- C:\WINDOWS\system32\setver.exe
2010-08-22 00:45:52 ----A---- C:\WINDOWS\system32\setupdll.dll
2010-08-22 00:45:52 ----A---- C:\WINDOWS\system32\setupapi.dll
2010-08-22 00:45:52 ----A---- C:\WINDOWS\system32\setup.exe
2010-08-22 00:45:52 ----A---- C:\WINDOWS\system32\sethc.exe
2010-08-22 00:45:52 ----A---- C:\WINDOWS\system32\sessmgr.exe
2010-08-22 00:45:52 ----A---- C:\WINDOWS\system32\serwvdrv.dll
2010-08-22 00:45:52 ----A---- C:\WINDOWS\system32\services.msc
2010-08-22 00:45:52 ----A---- C:\WINDOWS\system32\services.exe
2010-08-22 00:45:52 ----A---- C:\WINDOWS\system32\servdeps.dll
2010-08-22 00:45:51 ----A---- C:\WINDOWS\system32\serialui.dll
2010-08-22 00:45:51 ----A---- C:\WINDOWS\system32\senscfg.dll
2010-08-22 00:45:51 ----A---- C:\WINDOWS\system32\sensapi.dll
2010-08-22 00:45:51 ----A---- C:\WINDOWS\system32\sens.dll
2010-08-22 00:45:51 ----A---- C:\WINDOWS\system32\sendmail.dll
2010-08-22 00:45:51 ----A---- C:\WINDOWS\system32\sendcmsg.dll
2010-08-22 00:45:51 ----A---- C:\WINDOWS\system32\security.dll
2010-08-22 00:45:51 ----A---- C:\WINDOWS\system32\secur32.dll
2010-08-22 00:45:51 ----A---- C:\WINDOWS\system32\seclogon.dll
2010-08-22 00:45:51 ----A---- C:\WINDOWS\system32\sdpblb.dll
2010-08-22 00:45:51 ----A---- C:\WINDOWS\system32\sdhcinst.dll
2010-08-22 00:45:51 ----A---- C:\WINDOWS\system32\sdbinst.exe
2010-08-22 00:45:51 ----A---- C:\WINDOWS\system32\scrrun.dll
2010-08-22 00:45:51 ----A---- C:\WINDOWS\system32\scrobj.dll
2010-08-22 00:45:51 ----A---- C:\WINDOWS\system32\scredir.dll
2010-08-22 00:45:51 ----A---- C:\WINDOWS\system32\sclgntfy.dll
2010-08-22 00:45:51 ----A---- C:\WINDOWS\system32\schedsvc.dll
2010-08-22 00:45:51 ----A---- C:\WINDOWS\system32\schannel.dll
2010-08-22 00:45:51 ----A---- C:\WINDOWS\system32\scesrv.dll
2010-08-22 00:45:51 ----A---- C:\WINDOWS\system32\drivers\serial.sys
2010-08-22 00:45:51 ----A---- C:\WINDOWS\system32\drivers\serenum.sys
2010-08-22 00:45:51 ----A---- C:\WINDOWS\system32\drivers\secdrv.sys
2010-08-22 00:45:51 ----A---- C:\WINDOWS\system32\drivers\sdbus.sys
2010-08-22 00:45:51 ----A---- C:\WINDOWS\system32\drivers\scsiport.sys
2010-08-22 00:45:50 ----A---- C:\WINDOWS\system32\scecli.dll
2010-08-22 00:45:50 ----A---- C:\WINDOWS\system32\sccsccp.dll
2010-08-22 00:45:50 ----A---- C:\WINDOWS\system32\sccbase.dll
2010-08-22 00:45:50 ----A---- C:\WINDOWS\system32\scardsvr.exe
2010-08-22 00:45:50 ----A---- C:\WINDOWS\system32\scardssp.dll
2010-08-22 00:45:50 ----A---- C:\WINDOWS\system32\scarddlg.dll
2010-08-22 00:45:50 ----A---- C:\WINDOWS\system32\sc.exe
2010-08-22 00:45:50 ----A---- C:\WINDOWS\system32\sbeio.dll
2010-08-22 00:45:50 ----A---- C:\WINDOWS\system32\sbe.dll
2010-08-22 00:45:50 ----A---- C:\WINDOWS\system32\savedump.exe
2010-08-22 00:45:50 ----A---- C:\WINDOWS\system32\samsrv.dll
2010-08-22 00:45:50 ----A---- C:\WINDOWS\system32\samlib.dll
2010-08-22 00:45:49 ----A---- C:\WINDOWS\system32\safrslv.dll
2010-08-22 00:45:49 ----A---- C:\WINDOWS\system32\safrdm.dll
2010-08-22 00:45:49 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2010-08-22 00:45:49 ----A---- C:\WINDOWS\system32\rwinsta.exe
2010-08-22 00:45:49 ----A---- C:\WINDOWS\system32\runonce.exe
2010-08-22 00:45:49 ----A---- C:\WINDOWS\system32\rundll32.exe
2010-08-22 00:45:49 ----A---- C:\WINDOWS\system32\runas.exe
2010-08-22 00:45:49 ----A---- C:\WINDOWS\system32\rtutils.dll
2010-08-22 00:45:49 ----A---- C:\WINDOWS\system32\rtm.dll
2010-08-22 00:45:49 ----A---- C:\WINDOWS\system32\rtipxmib.dll
2010-08-22 00:45:49 ----A---- C:\WINDOWS\system32\rtcshare.exe
2010-08-22 00:45:49 ----A---- C:\WINDOWS\system32\rsvpsp.dll
2010-08-22 00:45:49 ----A---- C:\WINDOWS\system32\rsvpperf.dll
2010-08-22 00:45:49 ----A---- C:\WINDOWS\system32\rsvpmsg.dll
2010-08-22 00:45:49 ----A---- C:\WINDOWS\system32\rsvp.ini
2010-08-22 00:45:48 ----A---- C:\WINDOWS\system32\rsvp.exe
2010-08-22 00:45:48 ----A---- C:\WINDOWS\system32\rsmui.exe
2010-08-22 00:45:48 ----A---- C:\WINDOWS\system32\rsmsink.exe
2010-08-22 00:45:48 ----A---- C:\WINDOWS\system32\rsmps.dll
2010-08-22 00:45:48 ----A---- C:\WINDOWS\system32\rsm.exe
2010-08-22 00:45:48 ----A---- C:\WINDOWS\system32\rshx32.dll
2010-08-22 00:45:48 ----A---- C:\WINDOWS\system32\rsh.exe
2010-08-22 00:45:48 ----A---- C:\WINDOWS\system32\rsaenh.dll
2010-08-22 00:45:48 ----A---- C:\WINDOWS\system32\rpcss.dll
2010-08-22 00:45:48 ----A---- C:\WINDOWS\system32\rpcrt4.dll
2010-08-22 00:45:48 ----A---- C:\WINDOWS\system32\rpcns4.dll
2010-08-22 00:45:47 ----A---- C:\WINDOWS\system32\routetab.dll
2010-08-22 00:45:47 ----A---- C:\WINDOWS\system32\routemon.exe
2010-08-22 00:45:47 ----A---- C:\WINDOWS\system32\route.exe
2010-08-22 00:45:47 ----A---- C:\WINDOWS\system32\rnr20.dll
2010-08-22 00:45:47 ----A---- C:\WINDOWS\system32\riched32.dll
2010-08-22 00:45:47 ----A---- C:\WINDOWS\system32\riched20.dll
2010-08-22 00:45:47 ----A---- C:\WINDOWS\system32\rexec.exe
2010-08-22 00:45:47 ----A---- C:\WINDOWS\system32\resutils.dll
2010-08-22 00:45:47 ----A---- C:\WINDOWS\system32\reset.exe
2010-08-22 00:45:47 ----A---- C:\WINDOWS\system32\replace.exe
2010-08-22 00:45:47 ----A---- C:\WINDOWS\system32\rend.dll
2010-08-22 00:45:47 ----A---- C:\WINDOWS\system32\remotepg.dll
2010-08-22 00:45:47 ----A---- C:\WINDOWS\system32\regwizc.dll
2010-08-22 00:45:47 ----A---- C:\WINDOWS\system32\regwiz.exe
2010-08-22 00:45:47 ----A---- C:\WINDOWS\system32\regsvr32.exe
2010-08-22 00:45:47 ----A---- C:\WINDOWS\system32\regsvc.dll
2010-08-22 00:45:47 ----A---- C:\WINDOWS\system32\regini.exe
2010-08-22 00:45:47 ----A---- C:\WINDOWS\system32\regedt32.exe
2010-08-22 00:45:47 ----A---- C:\WINDOWS\system32\regapi.dll
2010-08-22 00:45:47 ----A---- C:\WINDOWS\system32\reg.exe
2010-08-22 00:45:47 ----A---- C:\WINDOWS\system32\redir.exe
2010-08-22 00:45:47 ----A---- C:\WINDOWS\system32\drivers\rootmdm.sys
2010-08-22 00:45:47 ----A---- C:\WINDOWS\system32\drivers\rndismp.sys
2010-08-22 00:45:47 ----A---- C:\WINDOWS\system32\drivers\rmcast.sys
2010-08-22 00:45:47 ----A---- C:\WINDOWS\regedit.exe
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\recover.exe
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\rdshost.exe
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\rdpdd.dll
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\rdpclip.exe
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\rdchost.dll
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\rcp.exe
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\rcimlby.exe
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\rcbdyctl.dll
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\rastls.dll
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\rastapi.dll
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\rasser.dll
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\rassapi.dll
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\rasrad.dll
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\rasppp.dll
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\rasphone.exe
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\rasmxs.dll
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\rasmontr.dll
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\rasmans.dll
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\rasman.dll
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\rasdlg.dll
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\rasdial.exe
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\rasctrs.ini
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\rasctrs.dll
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\raschap.dll
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\rasautou.exe
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\rasauto.dll
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\rasapi32.dll
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\rasadhlp.dll
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\racpldlg.dll
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\drivers\rdpwd.sys
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\drivers\rdpcdd.sys
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\drivers\rdbss.sys
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\drivers\rawwan.sys
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\drivers\raspti.sys
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\drivers\raspptp.sys
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\drivers\raspppoe.sys
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\drivers\rasl2tp.sys
2010-08-22 00:45:46 ----A---- C:\WINDOWS\system32\drivers\rasacd.sys
2010-08-22 00:45:45 ----A---- C:\WINDOWS\system32\qwinsta.exe
2010-08-22 00:45:45 ----A---- C:\WINDOWS\system32\query.dll
2010-08-22 00:45:45 ----A---- C:\WINDOWS\system32\quartz.dll
2010-08-22 00:45:45 ----A---- C:\WINDOWS\system32\qprocess.exe
2010-08-22 00:45:45 ----A---- C:\WINDOWS\system32\qosname.dll
2010-08-22 00:45:45 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2010-08-22 00:45:45 ----A---- C:\WINDOWS\system32\qmgr.dll
2010-08-22 00:45:44 ----A---- C:\WINDOWS\system32\qedwipes.dll
2010-08-22 00:45:44 ----A---- C:\WINDOWS\system32\qedit.dll
2010-08-22 00:45:44 ----A---- C:\WINDOWS\system32\qdvd.dll
2010-08-22 00:45:44 ----A---- C:\WINDOWS\system32\qdv.dll
2010-08-22 00:45:44 ----A---- C:\WINDOWS\system32\qcap.dll
2010-08-22 00:45:44 ----A---- C:\WINDOWS\system32\qasf.dll
2010-08-22 00:45:44 ----A---- C:\WINDOWS\system32\qappsrv.exe
2010-08-22 00:45:44 ----A---- C:\WINDOWS\system32\pubprn.vbs
2010-08-22 00:45:44 ----A---- C:\WINDOWS\system32\pstorsvc.dll
2010-08-22 00:45:44 ----A---- C:\WINDOWS\system32\pstorec.dll
2010-08-22 00:45:44 ----A---- C:\WINDOWS\system32\psnppagn.dll
2010-08-22 00:45:44 ----A---- C:\WINDOWS\system32\pschdprf.ini
2010-08-22 00:45:44 ----A---- C:\WINDOWS\system32\pschdprf.dll
2010-08-22 00:45:44 ----A---- C:\WINDOWS\system32\psbase.dll
2010-08-22 00:45:44 ----A---- C:\WINDOWS\system32\psapi.dll
2010-08-22 00:45:44 ----A---- C:\WINDOWS\system32\drivers\ql1280.sys
2010-08-22 00:45:44 ----A---- C:\WINDOWS\system32\drivers\ql1240.sys
2010-08-22 00:45:44 ----A---- C:\WINDOWS\system32\drivers\ql12160.sys
2010-08-22 00:45:44 ----A---- C:\WINDOWS\system32\drivers\ql10wnt.sys
2010-08-22 00:45:44 ----A---- C:\WINDOWS\system32\drivers\ql1080.sys
2010-08-22 00:45:44 ----A---- C:\WINDOWS\system32\drivers\ptilink.sys
2010-08-22 00:45:44 ----A---- C:\WINDOWS\system32\drivers\psched.sys
2010-08-22 00:45:43 ----N---- C:\WINDOWS\system32\pngfilt.dll
2010-08-22 00:45:43 ----A---- C:\WINDOWS\system32\proxycfg.exe
2010-08-22 00:45:43 ----A---- C:\WINDOWS\system32\proquota.exe
2010-08-22 00:45:43 ----A---- C:\WINDOWS\system32\progman.exe
2010-08-22 00:45:43 ----A---- C:\WINDOWS\system32\profmap.dll
2010-08-22 00:45:43 ----A---- C:\WINDOWS\system32\prodspec.ini
2010-08-22 00:45:43 ----A---- C:\WINDOWS\system32\printui.dll
2010-08-22 00:45:43 ----A---- C:\WINDOWS\system32\print.exe
2010-08-22 00:45:43 ----A---- C:\WINDOWS\system32\prflbmsg.dll
2010-08-22 00:45:43 ----A---- C:\WINDOWS\system32\powrprof.dll
2010-08-22 00:45:43 ----A---- C:\WINDOWS\system32\powercfg.exe
2010-08-22 00:45:43 ----A---- C:\WINDOWS\system32\polstore.dll
2010-08-22 00:45:43 ----A---- C:\WINDOWS\system32\pnrpnsp.dll
2010-08-22 00:45:43 ----A---- C:\WINDOWS\system32\pmspl.dll
2010-08-22 00:45:43 ----A---- C:\WINDOWS\system32\plustab.dll
2010-08-22 00:45:42 ----A---- C:\WINDOWS\system32\ping6.exe
2010-08-22 00:45:42 ----A---- C:\WINDOWS\system32\ping.exe
2010-08-22 00:45:42 ----A---- C:\WINDOWS\system32\pifmgr.dll
2010-08-22 00:45:42 ----A---- C:\WINDOWS\system32\pidgen.dll
2010-08-22 00:45:42 ----A---- C:\WINDOWS\system32\photowiz.dll
2010-08-22 00:45:37 ----A---- C:\WINDOWS\system32\perfwci.ini
2010-08-22 00:45:37 ----A---- C:\WINDOWS\system32\perfts.dll
2010-08-22 00:45:37 ----A---- C:\WINDOWS\system32\perfproc.dll
2010-08-22 00:45:37 ----A---- C:\WINDOWS\system32\perfos.dll
2010-08-22 00:45:37 ----A---- C:\WINDOWS\system32\perfnet.dll
2010-08-22 00:45:37 ----A---- C:\WINDOWS\system32\perfmon.msc
2010-08-22 00:45:37 ----A---- C:\WINDOWS\system32\perfmon.exe
2010-08-22 00:45:37 ----A---- C:\WINDOWS\system32\perffilt.ini
2010-08-22 00:45:37 ----A---- C:\WINDOWS\system32\perfdisk.dll
2010-08-22 00:45:37 ----A---- C:\WINDOWS\system32\perfctrs.dll
2010-08-22 00:45:37 ----A---- C:\WINDOWS\system32\perfci.ini
2010-08-22 00:45:37 ----A---- C:\WINDOWS\system32\drivers\perc2hib.sys
2010-08-22 00:45:37 ----A---- C:\WINDOWS\system32\drivers\perc2.sys
2010-08-22 00:45:36 ----A---- C:\WINDOWS\system32\pentnt.exe
2010-08-22 00:45:36 ----A---- C:\WINDOWS\system32\pdh.dll
2010-08-22 00:45:36 ----A---- C:\WINDOWS\system32\drivers\pcmcia.sys
2010-08-22 00:45:36 ----A---- C:\WINDOWS\system32\drivers\pciidex.sys
2010-08-22 00:45:36 ----A---- C:\WINDOWS\system32\drivers\pciide.sys
2010-08-22 00:45:36 ----A---- C:\WINDOWS\system32\drivers\pci.sys
2010-08-22 00:45:35 ----A---- C:\WINDOWS\system32\pautoenr.dll
2010-08-22 00:45:35 ----A---- C:\WINDOWS\system32\pathping.exe
2010-08-22 00:45:35 ----A---- C:\WINDOWS\system32\panmap.dll
2010-08-22 00:45:35 ----A---- C:\WINDOWS\system32\drivers\parvdm.sys
2010-08-22 00:45:35 ----A---- C:\WINDOWS\system32\drivers\partmgr.sys
2010-08-22 00:45:34 ----A---- C:\WINDOWS\system32\packager.exe
2010-08-22 00:45:34 ----A---- C:\WINDOWS\system32\p2psvc.dll
2010-08-22 00:45:34 ----A---- C:\WINDOWS\system32\p2pnetsh.dll
2010-08-22 00:45:34 ----A---- C:\WINDOWS\system32\p2pgraph.dll
2010-08-22 00:45:34 ----A---- C:\WINDOWS\system32\p2pgasvc.dll
2010-08-22 00:45:34 ----A---- C:\WINDOWS\system32\p2p.dll
2010-08-22 00:45:34 ----A---- C:\WINDOWS\system32\osuninst.exe
2010-08-22 00:45:34 ----A---- C:\WINDOWS\system32\osuninst.dll
2010-08-22 00:45:34 ----A---- C:\WINDOWS\system32\osk.exe
2010-08-22 00:45:34 ----A---- C:\WINDOWS\system32\opengl32.dll
2010-08-22 00:45:34 ----A---- C:\WINDOWS\system32\olethk32.dll
2010-08-22 00:45:34 ----A---- C:\WINDOWS\system32\olesvr32.dll
2010-08-22 00:45:34 ----A---- C:\WINDOWS\system32\olesvr.dll
2010-08-22 00:45:34 ----A---- C:\WINDOWS\system32\olepro32.dll
2010-08-22 00:45:34 ----A---- C:\WINDOWS\system32\oleprn.dll
2010-08-22 00:45:34 ----A---- C:\WINDOWS\system32\oledlg.dll
2010-08-22 00:45:34 ----A---- C:\WINDOWS\system32\olecnv32.dll
2010-08-22 00:45:34 ----A---- C:\WINDOWS\system32\drivers\oprghdlr.sys
2010-08-22 00:45:33 ----A---- C:\WINDOWS\system32\olecli32.dll
2010-08-22 00:45:33 ----A---- C:\WINDOWS\system32\olecli.dll
2010-08-22 00:45:33 ----A---- C:\WINDOWS\system32\oleaut32.dll
2010-08-22 00:45:33 ----A---- C:\WINDOWS\system32\oleaccrc.dll
2010-08-22 00:45:33 ----A---- C:\WINDOWS\system32\oleacc.dll
2010-08-22 00:45:33 ----A---- C:\WINDOWS\system32\ole32.dll
2010-08-22 00:45:33 ----A---- C:\WINDOWS\system32\ole2nls.dll
2010-08-22 00:45:33 ----A---- C:\WINDOWS\system32\ole2disp.dll
2010-08-22 00:45:33 ----A---- C:\WINDOWS\system32\ole2.dll
2010-08-22 00:45:33 ----A---- C:\WINDOWS\system32\offfilt.dll
2010-08-22 00:45:27 ----N---- C:\WINDOWS\system32\occache.dll
2010-08-22 00:45:27 ----A---- C:\WINDOWS\system32\odtext32.dll
2010-08-22 00:45:27 ----A---- C:\WINDOWS\system32\odpdx32.dll
2010-08-22 00:45:27 ----A---- C:\WINDOWS\system32\odfox32.dll
2010-08-22 00:45:27 ----A---- C:\WINDOWS\system32\odexl32.dll
2010-08-22 00:45:27 ----A---- C:\WINDOWS\system32\oddbse32.dll
2010-08-22 00:45:27 ----A---- C:\WINDOWS\system32\odbctrac.dll
2010-08-22 00:45:27 ----A---- C:\WINDOWS\system32\odbcp32r.dll
2010-08-22 00:45:27 ----A---- C:\WINDOWS\system32\odbcjt32.dll
2010-08-22 00:45:27 ----A---- C:\WINDOWS\system32\odbcji32.dll
2010-08-22 00:45:27 ----A---- C:\WINDOWS\system32\odbcint.dll
2010-08-22 00:45:27 ----A---- C:\WINDOWS\system32\odbccu32.dll
2010-08-22 00:45:27 ----A---- C:\WINDOWS\system32\odbccr32.dll
2010-08-22 00:45:27 ----A---- C:\WINDOWS\system32\odbccp32.dll
2010-08-22 00:45:27 ----A---- C:\WINDOWS\system32\odbcconf.exe
2010-08-22 00:45:27 ----A---- C:\WINDOWS\system32\odbcconf.dll
2010-08-22 00:45:27 ----A---- C:\WINDOWS\system32\odbcbcp.dll
2010-08-22 00:45:27 ----A---- C:\WINDOWS\system32\odbcad32.exe
2010-08-22 00:45:27 ----A---- C:\WINDOWS\system32\odbc32gt.dll
2010-08-22 00:45:27 ----A---- C:\WINDOWS\system32\odbc32.dll
2010-08-22 00:45:27 ----A---- C:\WINDOWS\system32\odbc16gt.dll
2010-08-22 00:45:27 ----A---- C:\WINDOWS\system32\ocmanage.dll
2010-08-22 00:45:27 ----A---- C:\WINDOWS\system32\objsel.dll
2010-08-22 00:45:26 ----A---- C:\WINDOWS\system32\oakley.dll
2010-08-22 00:45:26 ----A---- C:\WINDOWS\system32\nwprovau.dll
2010-08-22 00:45:26 ----A---- C:\WINDOWS\system32\ntvdmd.dll
2010-08-22 00:45:26 ----A---- C:\WINDOWS\system32\ntvdm.exe
2010-08-22 00:45:26 ----A---- C:\WINDOWS\system32\ntshrui.dll
2010-08-22 00:45:26 ----A---- C:\WINDOWS\system32\ntsdexts.dll
2010-08-22 00:45:26 ----A---- C:\WINDOWS\system32\ntsd.exe
2010-08-22 00:45:26 ----A---- C:\WINDOWS\system32\drivers\nwlnkspx.sys
2010-08-22 00:45:26 ----A---- C:\WINDOWS\system32\drivers\nwlnknb.sys
2010-08-22 00:45:26 ----A---- C:\WINDOWS\system32\drivers\nwlnkipx.sys
2010-08-22 00:45:26 ----A---- C:\WINDOWS\system32\drivers\nwlnkfwd.sys
2010-08-22 00:45:26 ----A---- C:\WINDOWS\system32\drivers\nwlnkflt.sys
2010-08-22 00:45:26 ----A---- C:\WINDOWS\system32\drivers\null.sys
2010-08-22 00:45:25 ----A---- C:\WINDOWS\system32\ntprint.dll
2010-08-22 00:45:24 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2010-08-22 00:45:24 ----A---- C:\WINDOWS\system32\ntmssvc.dll
2010-08-22 00:45:24 ----A---- C:\WINDOWS\system32\ntmsoprq.msc
2010-08-22 00:45:24 ----A---- C:\WINDOWS\system32\ntmsmgr.msc
2010-08-22 00:45:24 ----A---- C:\WINDOWS\system32\ntmsmgr.dll
2010-08-22 00:45:24 ----A---- C:\WINDOWS\system32\ntmsevt.dll
2010-08-22 00:45:24 ----A---- C:\WINDOWS\system32\ntmsdba.dll
2010-08-22 00:45:24 ----A---- C:\WINDOWS\system32\ntmsapi.dll
2010-08-22 00:45:24 ----A---- C:\WINDOWS\system32\ntmarta.dll
2010-08-22 00:45:24 ----A---- C:\WINDOWS\system32\ntlsapi.dll
2010-08-22 00:45:24 ----A---- C:\WINDOWS\system32\ntlanui2.dll
2010-08-22 00:45:24 ----A---- C:\WINDOWS\system32\ntlanui.dll
2010-08-22 00:45:24 ----A---- C:\WINDOWS\system32\ntlanman.dll
2010-08-22 00:45:23 ----A---- C:\WINDOWS\system32\ntio804.sys
2010-08-22 00:45:23 ----A---- C:\WINDOWS\system32\ntio412.sys
2010-08-22 00:45:23 ----A---- C:\WINDOWS\system32\ntio411.sys
2010-08-22 00:45:23 ----A---- C:\WINDOWS\system32\ntio404.sys
2010-08-22 00:45:23 ----A---- C:\WINDOWS\system32\ntio.sys
2010-08-22 00:45:23 ----A---- C:\WINDOWS\system32\ntdsapi.dll
2010-08-22 00:45:23 ----A---- C:\WINDOWS\system32\ntdos804.sys
2010-08-22 00:45:23 ----A---- C:\WINDOWS\system32\ntdos412.sys
2010-08-22 00:45:23 ----A---- C:\WINDOWS\system32\ntdos411.sys
2010-08-22 00:45:23 ----A---- C:\WINDOWS\system32\ntdos404.sys
2010-08-22 00:45:23 ----A---- C:\WINDOWS\system32\ntdos.sys
2010-08-22 00:45:23 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2010-08-22 00:45:22 ----A---- C:\WINDOWS\system32\ntdll.dll
2010-08-22 00:45:21 ----A---- C:\WINDOWS\system32\nslookup.exe
2010-08-22 00:45:21 ----A---- C:\WINDOWS\system32\npptools.dll
2010-08-22 00:45:21 ----A---- C:\WINDOWS\system32\notepad.exe
2010-08-22 00:45:21 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2010-08-22 00:45:21 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2010-08-22 00:45:21 ----A---- C:\WINDOWS\system32\drivers\npfs.sys
2010-08-22 00:45:21 ----A---- C:\WINDOWS\system32\drivers\nmnt.sys
2010-08-22 00:45:21 ----A---- C:\WINDOWS\notepad.exe
2010-08-22 00:45:20 ----A---- C:\WINDOWS\system32\nlsfunc.exe
2010-08-22 00:45:20 ----A---- C:\WINDOWS\system32\nlhtml.dll
2010-08-22 00:45:19 ----A---- C:\WINDOWS\system32\newdev.dll
2010-08-22 00:45:19 ----A---- C:\WINDOWS\system32\netui2.dll
2010-08-22 00:45:19 ----A---- C:\WINDOWS\system32\netui1.dll
2010-08-22 00:45:19 ----A---- C:\WINDOWS\system32\netui0.dll
2010-08-22 00:45:19 ----A---- C:\WINDOWS\system32\netstat.exe
2010-08-22 00:45:19 ----A---- C:\WINDOWS\system32\netshell.dll
2010-08-22 00:45:19 ----A---- C:\WINDOWS\system32\netsh.exe
2010-08-22 00:45:18 ----A---- C:\WINDOWS\system32\netsetup.exe
2010-08-22 00:45:18 ----A---- C:\WINDOWS\system32\netrap.dll
2010-08-22 00:45:18 ----A---- C:\WINDOWS\system32\netplwiz.dll
2010-08-22 00:45:18 ----A---- C:\WINDOWS\system32\netmsg.dll
2010-08-22 00:45:18 ----A---- C:\WINDOWS\system32\netman.dll
2010-08-22 00:45:18 ----A---- C:\WINDOWS\system32\netlogon.dll
2010-08-22 00:45:18 ----A---- C:\WINDOWS\system32\netid.dll
2010-08-22 00:45:18 ----A---- C:\WINDOWS\system32\neth.dll
2010-08-22 00:45:18 ----A---- C:\WINDOWS\system32\netevent.dll
2010-08-22 00:45:18 ----A---- C:\WINDOWS\system32\netdde.exe
2010-08-22 00:45:18 ----A---- C:\WINDOWS\system32\netcfgx.dll
2010-08-22 00:45:17 ----A---- C:\WINDOWS\system32\netapi32.dll
2010-08-22 00:45:17 ----A---- C:\WINDOWS\system32\netapi.dll
2010-08-22 00:45:17 ----A---- C:\WINDOWS\system32\net1.exe
2010-08-22 00:45:17 ----A---- C:\WINDOWS\system32\net.exe
2010-08-22 00:45:17 ----A---- C:\WINDOWS\system32\nddenb32.dll
2010-08-22 00:45:17 ----A---- C:\WINDOWS\system32\nddeapir.exe
2010-08-22 00:45:17 ----A---- C:\WINDOWS\system32\nddeapi.dll
2010-08-22 00:45:17 ----A---- C:\WINDOWS\system32\ncxpnt.dll
2010-08-22 00:45:17 ----A---- C:\WINDOWS\system32\ncobjapi.dll
2010-08-22 00:45:17 ----A---- C:\WINDOWS\system32\nbtstat.exe
2010-08-22 00:45:17 ----A---- C:\WINDOWS\system32\narrhook.dll
2010-08-22 00:45:17 ----A---- C:\WINDOWS\system32\drivers\netbt.sys
2010-08-22 00:45:17 ----A---- C:\WINDOWS\system32\drivers\netbios.sys
2010-08-22 00:45:17 ----A---- C:\WINDOWS\system32\drivers\ndproxy.sys
2010-08-22 00:45:17 ----A---- C:\WINDOWS\system32\drivers\ndiswan.sys
2010-08-22 00:45:17 ----A---- C:\WINDOWS\system32\drivers\ndistapi.sys
2010-08-22 00:45:17 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2010-08-22 00:45:16 ----A---- C:\WINDOWS\system32\narrator.exe
2010-08-22 00:45:16 ----A---- C:\WINDOWS\system32\mydocs.dll
2010-08-22 00:45:16 ----A---- C:\WINDOWS\system32\mycomput.dll
2010-08-22 00:45:15 ----A---- C:\WINDOWS\system32\mtxoci.dll
2010-08-22 00:45:15 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2010-08-22 00:45:15 ----A---- C:\WINDOWS\system32\mtxex.dll
2010-08-22 00:45:15 ----A---- C:\WINDOWS\system32\mtxdm.dll
2010-08-22 00:45:15 ----A---- C:\WINDOWS\system32\mtxclu.dll
2010-08-22 00:45:15 ----A---- C:\WINDOWS\system32\drivers\mup.sys
2010-08-22 00:45:14 ----A---- C:\WINDOWS\system32\msxmlr.dll
2010-08-22 00:45:14 ----A---- C:\WINDOWS\system32\msxml3r.dll
2010-08-22 00:45:14 ----A---- C:\WINDOWS\system32\msxml3.dll
2010-08-22 00:45:14 ----A---- C:\WINDOWS\system32\msxml2r.dll
2010-08-22 00:45:14 ----A---- C:\WINDOWS\system32\msxml2.dll
2010-08-22 00:45:14 ----A---- C:\WINDOWS\system32\msxml.dll
2010-08-22 00:45:14 ----A---- C:\WINDOWS\system32\msxbde40.dll
2010-08-22 00:45:14 ----A---- C:\WINDOWS\system32\mswstr10.dll
2010-08-22 00:45:14 ----A---- C:\WINDOWS\system32\mswsock.dll
2010-08-22 00:45:14 ----A---- C:\WINDOWS\system32\mswmdm.dll
2010-08-22 00:45:13 ----A---- C:\WINDOWS\system32\mswebdvd.dll
2010-08-22 00:45:13 ----A---- C:\WINDOWS\system32\mswdat10.dll
2010-08-22 00:45:13 ----A---- C:\WINDOWS\system32\msw3prt.dll
2010-08-22 00:45:13 ----A---- C:\WINDOWS\system32\msvideo.dll
2010-08-22 00:45:13 ----A---- C:\WINDOWS\system32\msvidctl.dll
2010-08-22 00:45:13 ----A---- C:\WINDOWS\system32\msvidc32.dll
2010-08-22 00:45:13 ----A---- C:\WINDOWS\system32\msvfw32.dll
2010-08-22 00:45:13 ----A---- C:\WINDOWS\system32\msvcrt40.dll
2010-08-22 00:45:13 ----A---- C:\WINDOWS\system32\msvcrt20.dll
2010-08-22 00:45:13 ----A---- C:\WINDOWS\system32\msvcrt.dll
2010-08-22 00:45:13 ----A---- C:\WINDOWS\system32\msvcp60.dll
2010-08-22 00:45:13 ----A---- C:\WINDOWS\system32\msvcp50.dll
2010-08-22 00:45:13 ----A---- C:\WINDOWS\system32\msvcirt.dll
2010-08-22 00:45:12 ----N---- C:\WINDOWS\system32\mstime.dll
2010-08-22 00:45:12 ----A---- C:\WINDOWS\system32\msvbvm60.dll
2010-08-22 00:45:12 ----A---- C:\WINDOWS\system32\msvbvm50.dll
2010-08-22 00:45:12 ----A---- C:\WINDOWS\system32\msv1_0.dll
2010-08-22 00:45:12 ----A---- C:\WINDOWS\system32\msutb.dll
2010-08-22 00:45:12 ----A---- C:\WINDOWS\system32\mstscax.dll
2010-08-22 00:45:12 ----A---- C:\WINDOWS\system32\mstsc.exe
2010-08-22 00:45:12 ----A---- C:\WINDOWS\system32\mstlsapi.dll
2010-08-22 00:45:12 ----A---- C:\WINDOWS\system32\mstinit.exe
2010-08-22 00:45:12 ----A---- C:\WINDOWS\system32\mstext40.dll
2010-08-22 00:45:12 ----A---- C:\WINDOWS\system32\mstask.dll
2010-08-22 00:45:11 ----N---- C:\WINDOWS\system32\msrating.dll
2010-08-22 00:45:11 ----A---- C:\WINDOWS\system32\msswchx.exe
2010-08-22 00:45:11 ----A---- C:\WINDOWS\system32\msswch.dll
2010-08-22 00:45:11 ----A---- C:\WINDOWS\system32\mssip32.dll
2010-08-22 00:45:11 ----A---- C:\WINDOWS\system32\mssign32.dll
2010-08-22 00:45:11 ----A---- C:\WINDOWS\system32\msscp.dll
2010-08-22 00:45:11 ----A---- C:\WINDOWS\system32\mssap.dll
2010-08-22 00:45:11 ----A---- C:\WINDOWS\system32\msrle32.dll
2010-08-22 00:45:11 ----A---- C:\WINDOWS\system32\msrepl40.dll
2010-08-22 00:45:11 ----A---- C:\WINDOWS\system32\msrecr40.dll
2010-08-22 00:45:11 ----A---- C:\WINDOWS\system32\msrd3x40.dll
2010-08-22 00:45:11 ----A---- C:\WINDOWS\system32\msrd2x40.dll
2010-08-22 00:45:11 ----A---- C:\WINDOWS\system32\msrclr40.dll
2010-08-22 00:45:11 ----A---- C:\WINDOWS\system32\msratelc.dll
2010-08-22 00:45:11 ----A---- C:\WINDOWS\system32\msr2cenu.dll
2010-08-22 00:45:11 ----A---- C:\WINDOWS\system32\msr2c.dll
2010-08-22 00:45:11 ----A---- C:\WINDOWS\system32\msprivs.dll
2010-08-22 00:45:11 ----A---- C:\WINDOWS\system32\msports.dll
2010-08-22 00:45:11 ----A---- C:\WINDOWS\system32\mspmsp.dll
2010-08-22 00:45:11 ----A---- C:\WINDOWS\system32\mspmsnsv.dll
2010-08-22 00:45:11 ----A---- C:\WINDOWS\system32\mspbde40.dll
2010-08-22 00:45:11 ----A---- C:\WINDOWS\system32\mspatcha.dll
2010-08-22 00:45:10 ----A---- C:\WINDOWS\system32\mspaint.exe
2010-08-22 00:45:10 ----A---- C:\WINDOWS\system32\msorcl32.dll
2010-08-22 00:45:10 ----A---- C:\WINDOWS\system32\msorc32r.dll
2010-08-22 00:45:10 ----A---- C:\WINDOWS\system32\msoert2.dll
2010-08-22 00:45:10 ----A---- C:\WINDOWS\system32\msoeacct.dll
2010-08-22 00:45:10 ----A---- C:\WINDOWS\system32\msobjs.dll
2010-08-22 00:45:09 ----A---- C:\WINDOWS\system32\msnsspc.dll
2010-08-22 00:45:07 ----A---- C:\WINDOWS\system32\msnetobj.dll
2010-08-22 00:45:02 ----A---- C:\WINDOWS\system32\msltus40.dll
2010-08-22 00:45:02 ----A---- C:\WINDOWS\system32\msls31.dll
2010-08-22 00:45:02 ----A---- C:\WINDOWS\system32\mslbui.dll
2010-08-22 00:45:02 ----A---- C:\WINDOWS\system32\msjtes40.dll
2010-08-22 00:45:02 ----A---- C:\WINDOWS\system32\msjter40.dll
2010-08-22 00:45:02 ----A---- C:\WINDOWS\system32\msjint40.dll
2010-08-22 00:45:02 ----A---- C:\WINDOWS\system32\msjetoledb40.dll
2010-08-22 00:45:01 ----A---- C:\WINDOWS\system32\msjet40.dll
2010-08-22 00:45:01 ----A---- C:\WINDOWS\system32\msisip.dll
2010-08-22 00:45:01 ----A---- C:\WINDOWS\system32\msimtf.dll
2010-08-22 00:45:01 ----A---- C:\WINDOWS\system32\msimsg.dll
2010-08-22 00:45:01 ----A---- C:\WINDOWS\system32\msimg32.dll
2010-08-22 00:45:01 ----A---- C:\WINDOWS\system32\msihnd.dll
2010-08-22 00:45:01 ----A---- C:\WINDOWS\system32\msiexec.exe
2010-08-22 00:45:01 ----A---- C:\WINDOWS\system32\msieftp.dll
2010-08-22 00:45:01 ----A---- C:\WINDOWS\system32\msidntld.dll
2010-08-22 00:45:01 ----A---- C:\WINDOWS\system32\msidle.dll
2010-08-22 00:45:01 ----A---- C:\WINDOWS\system32\msident.dll
2010-08-22 00:45:00 ----A---- C:\WINDOWS\system32\msi.dll
2010-08-22 00:45:00 ----A---- C:\WINDOWS\system32\mshtmler.dll
2010-08-22 00:45:00 ----A---- C:\WINDOWS\system32\mshtmled.dll
2010-08-22 00:45:00 ----A---- C:\WINDOWS\system32\mshtml.dll
2010-08-22 00:45:00 ----A---- C:\WINDOWS\system32\mshta.exe
2010-08-22 00:45:00 ----A---- C:\WINDOWS\system32\msgsvc.dll
2010-08-22 00:44:59 ----A---- C:\WINDOWS\system32\msgina.dll
2010-08-22 00:44:59 ----A---- C:\WINDOWS\system32\msg.exe
2010-08-22 00:44:59 ----A---- C:\WINDOWS\system32\msftedit.dll
2010-08-22 00:44:59 ----A---- C:\WINDOWS\system32\msexcl40.dll
2010-08-22 00:44:59 ----A---- C:\WINDOWS\system32\msexch40.dll
2010-08-22 00:44:59 ----A---- C:\WINDOWS\system32\msencode.dll
2010-08-22 00:44:59 ----A---- C:\WINDOWS\system32\drivers\msgpc.sys
2010-08-22 00:44:59 ----A---- C:\WINDOWS\system32\drivers\msfs.sys
2010-08-22 00:44:58 ----A---- C:\WINDOWS\system32\msdxmlc.dll
2010-08-22 00:44:58 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2010-08-22 00:44:58 ----A---- C:\WINDOWS\system32\msdtctm.dll
2010-08-22 00:44:58 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2010-08-22 00:44:58 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2010-08-22 00:44:58 ----A---- C:\WINDOWS\system32\msdtclog.dll
2010-08-22 00:44:58 ----A---- C:\WINDOWS\system32\msdtc.exe
2010-08-22 00:44:58 ----A---- C:\WINDOWS\system32\msdmo.dll
2010-08-22 00:44:58 ----A---- C:\WINDOWS\system32\msdart.dll
2010-08-22 00:44:58 ----A---- C:\WINDOWS\system32\msdadiag.dll
2010-08-22 00:44:58 ----A---- C:\WINDOWS\system32\msctfp.dll
2010-08-22 00:44:58 ----A---- C:\WINDOWS\msdfmap.ini
2010-08-22 00:44:57 ----A---- C:\WINDOWS\system32\msctf.dll
2010-08-22 00:44:57 ----A---- C:\WINDOWS\system32\mscpxl32.dll
2010-08-22 00:44:57 ----A---- C:\WINDOWS\system32\mscpx32r.dll
2010-08-22 00:44:57 ----A---- C:\WINDOWS\system32\msconf.dll
2010-08-22 00:44:57 ----A---- C:\WINDOWS\system32\mscms.dll
2010-08-22 00:44:57 ----A---- C:\WINDOWS\system32\mscdexnt.exe
2010-08-22 00:44:57 ----A---- C:\WINDOWS\system32\mscat32.dll
2010-08-22 00:44:57 ----A---- C:\WINDOWS\system32\msaudite.dll
2010-08-22 00:44:57 ----A---- C:\WINDOWS\system32\msasn1.dll
2010-08-22 00:44:57 ----A---- C:\WINDOWS\system32\msapsspc.dll
2010-08-22 00:44:57 ----A---- C:\WINDOWS\system32\msafd.dll
2010-08-22 00:44:57 ----A---- C:\WINDOWS\system32\msacm32.dll
2010-08-22 00:44:57 ----A---- C:\WINDOWS\system32\msacm.dll
2010-08-22 00:44:57 ----A---- C:\WINDOWS\system32\msaatext.dll
2010-08-22 00:44:56 ----A---- C:\WINDOWS\system32\mrinfo.exe
2010-08-22 00:44:56 ----A---- C:\WINDOWS\system32\mprui.dll
2010-08-22 00:44:56 ----A---- C:\WINDOWS\system32\mprmsg.dll
2010-08-22 00:44:56 ----A---- C:\WINDOWS\system32\mprdim.dll
2010-08-22 00:44:56 ----A---- C:\WINDOWS\system32\drivers\mrxsmb.sys
2010-08-22 00:44:56 ----A---- C:\WINDOWS\system32\drivers\mrxdav.sys
2010-08-22 00:44:56 ----A---- C:\WINDOWS\system32\drivers\mraid35x.sys
2010-08-22 00:44:55 ----A---- C:\WINDOWS\system32\mprddm.dll
2010-08-22 00:44:55 ----A---- C:\WINDOWS\system32\mprapi.dll
2010-08-22 00:44:55 ----A---- C:\WINDOWS\system32\mpr.dll
2010-08-22 00:44:55 ----A---- C:\WINDOWS\system32\mpnotify.exe
2010-08-22 00:44:55 ----A---- C:\WINDOWS\system32\mplay32.exe
2010-08-22 00:44:55 ----A---- C:\WINDOWS\system32\mpg4dmod.dll
2010-08-22 00:44:55 ----A---- C:\WINDOWS\system32\mp4sdmod.dll
2010-08-22 00:44:55 ----A---- C:\WINDOWS\system32\mp43dmod.dll
2010-08-22 00:44:54 ----A---- C:\WINDOWS\system32\mountvol.exe
2010-08-22 00:44:54 ----A---- C:\WINDOWS\system32\moricons.dll
2010-08-22 00:44:54 ----A---- C:\WINDOWS\system32\more.com
2010-08-22 00:44:54 ----A---- C:\WINDOWS\system32\modex.dll
2010-08-22 00:44:54 ----A---- C:\WINDOWS\system32\modemui.dll
2010-08-22 00:44:54 ----A---- C:\WINDOWS\system32\drivers\mountmgr.sys
2010-08-22 00:44:53 ----A---- C:\WINDOWS\system32\mode.com
2010-08-22 00:44:53 ----A---- C:\WINDOWS\system32\mobsync.exe
2010-08-22 00:44:53 ----A---- C:\WINDOWS\system32\mobsync.dll
2010-08-22 00:44:53 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2010-08-22 00:44:53 ----A---- C:\WINDOWS\system32\mnmdd.dll
2010-08-22 00:44:53 ----A---- C:\WINDOWS\system32\mmutilse.dll
2010-08-22 00:44:53 ----A---- C:\WINDOWS\system32\mmsystem.dll
2010-08-22 00:44:53 ----A---- C:\WINDOWS\system32\drivers\mnmdd.sys
2010-08-22 00:44:52 ----A---- C:\WINDOWS\system32\mmfutil.dll
2010-08-22 00:44:52 ----A---- C:\WINDOWS\system32\mmdrv.dll
2010-08-22 00:44:52 ----A---- C:\WINDOWS\system32\mmcshext.dll
2010-08-22 00:44:52 ----A---- C:\WINDOWS\system32\mmcndmgr.dll
2010-08-22 00:44:52 ----A---- C:\WINDOWS\system32\mmcbase.dll
2010-08-22 00:44:52 ----A---- C:\WINDOWS\system32\mmc.exe
2010-08-22 00:44:52 ----A---- C:\WINDOWS\system32\mll_qic.dll
2010-08-22 00:44:52 ----A---- C:\WINDOWS\system32\mll_mtf.dll
2010-08-22 00:44:52 ----A---- C:\WINDOWS\system32\mll_hp.dll
2010-08-22 00:44:52 ----A---- C:\WINDOWS\system32\mlang.dll
2010-08-22 00:44:52 ----A---- C:\WINDOWS\system32\mimefilt.dll
2010-08-22 00:44:51 ----A---- C:\WINDOWS\system32\migpwd.exe
2010-08-22 00:44:51 ----A---- C:\WINDOWS\system32\miglibnt.dll
2010-08-22 00:44:51 ----A---- C:\WINDOWS\system32\midimap.dll
2010-08-22 00:44:51 ----A---- C:\WINDOWS\system32\mgmtapi.dll
2010-08-22 00:44:51 ----A---- C:\WINDOWS\system32\mfcsubs.dll
2010-08-22 00:44:51 ----A---- C:\WINDOWS\system32\mfc42u.dll
2010-08-22 00:44:51 ----A---- C:\WINDOWS\system32\mfc42.dll
2010-08-22 00:44:50 ----A---- C:\WINDOWS\system32\mfc40u.dll
2010-08-22 00:44:50 ----A---- C:\WINDOWS\system32\mfc40.dll
2010-08-22 00:44:50 ----A---- C:\WINDOWS\system32\mf3216.dll
2010-08-22 00:44:49 ----A---- C:\WINDOWS\system32\mem.exe
2010-08-22 00:44:49 ----A---- C:\WINDOWS\system32\mdminst.dll
2010-08-22 00:44:48 ----A---- C:\WINDOWS\system32\mdhcp.dll
2010-08-22 00:44:48 ----A---- C:\WINDOWS\system32\mciwave.dll
2010-08-22 00:44:48 ----A---- C:\WINDOWS\system32\mciseq.dll
2010-08-22 00:44:48 ----A---- C:\WINDOWS\system32\mciqtz32.dll
2010-08-22 00:44:48 ----A---- C:\WINDOWS\system32\mciole32.dll
2010-08-22 00:44:48 ----A---- C:\WINDOWS\system32\mciole16.dll
2010-08-22 00:44:48 ----A---- C:\WINDOWS\system32\mcicda.dll
2010-08-22 00:44:48 ----A---- C:\WINDOWS\system32\mciavi32.dll
2010-08-22 00:44:48 ----A---- C:\WINDOWS\system32\mchgrcoi.dll
2010-08-22 00:44:48 ----A---- C:\WINDOWS\system32\mcdsrv32.dll
2010-08-22 00:44:48 ----A---- C:\WINDOWS\system32\mcd32.dll
2010-08-22 00:44:48 ----A---- C:\WINDOWS\system32\mcastmib.dll
2010-08-22 00:44:48 ----A---- C:\WINDOWS\system32\mapistub.dll
2010-08-22 00:44:48 ----A---- C:\WINDOWS\system32\makecab.exe
2010-08-22 00:44:48 ----A---- C:\WINDOWS\system32\drivers\mcd.sys
2010-08-22 00:44:47 ----A---- C:\WINDOWS\system32\magnify.exe
2010-08-22 00:44:47 ----A---- C:\WINDOWS\system32\mag_hook.dll
2010-08-22 00:44:47 ----A---- C:\WINDOWS\system32\lzexpand.dll
2010-08-22 00:44:47 ----A---- C:\WINDOWS\system32\lz32.dll
2010-08-22 00:44:47 ----A---- C:\WINDOWS\system32\lusrmgr.msc
2010-08-22 00:44:47 ----A---- C:\WINDOWS\system32\lsass.exe
2010-08-22 00:44:47 ----A---- C:\WINDOWS\system32\lsasrv.dll
2010-08-22 00:44:47 ----A---- C:\WINDOWS\system32\lprmonui.dll
2010-08-22 00:44:47 ----A---- C:\WINDOWS\system32\lprhelp.dll
2010-08-22 00:44:47 ----A---- C:\WINDOWS\system32\lpr.exe
2010-08-22 00:44:47 ----A---- C:\WINDOWS\system32\lpq.exe
2010-08-22 00:44:47 ----A---- C:\WINDOWS\system32\lpk.dll
2010-08-22 00:44:46 ----A---- C:\WINDOWS\system32\logonui.exe
2010-08-22 00:44:46 ----A---- C:\WINDOWS\system32\logoff.exe
2010-08-22 00:44:46 ----A---- C:\WINDOWS\system32\logman.exe
2010-08-22 00:44:46 ----A---- C:\WINDOWS\system32\loghours.dll
2010-08-22 00:44:46 ----A---- C:\WINDOWS\system32\logagent.exe
2010-08-22 00:44:46 ----A---- C:\WINDOWS\system32\lodctr.exe
2010-08-22 00:44:46 ----A---- C:\WINDOWS\system32\locator.exe
2010-08-22 00:44:46 ----A---- C:\WINDOWS\system32\localui.dll
2010-08-22 00:44:46 ----A---- C:\WINDOWS\system32\localspl.dll
2010-08-22 00:44:46 ----A---- C:\WINDOWS\system32\localsec.dll
2010-08-22 00:44:46 ----A---- C:\WINDOWS\system32\loadperf.dll
2010-08-22 00:44:46 ----A---- C:\WINDOWS\system32\loadfix.com
2010-08-22 00:44:46 ----A---- C:\WINDOWS\system32\lnkstub.exe
2010-08-22 00:44:46 ----A---- C:\WINDOWS\system32\lmrt.dll
2010-08-22 00:44:46 ----A---- C:\WINDOWS\system32\lmhsvc.dll
2010-08-22 00:44:46 ----A---- C:\WINDOWS\system32\linkinfo.dll
2010-08-22 00:44:46 ----A---- C:\WINDOWS\system32\lights.exe
2010-08-22 00:44:46 ----A---- C:\WINDOWS\system32\licwmi.dll
2010-08-22 00:44:46 ----A---- C:\WINDOWS\system32\licmgr10.dll
2010-08-22 00:44:46 ----A---- C:\WINDOWS\system32\licdll.dll
2010-08-22 00:44:45 ----A---- C:\WINDOWS\system32\laprxy.dll
2010-08-22 00:44:45 ----A---- C:\WINDOWS\system32\langwrbk.dll
2010-08-22 00:44:00 ----A---- C:\WINDOWS\system32\label.exe
2010-08-22 00:44:00 ----A---- C:\WINDOWS\system32\krnl386.exe
2010-08-22 00:44:00 ----A---- C:\WINDOWS\system32\keymgr.dll
2010-08-22 00:44:00 ----A---- C:\WINDOWS\system32\keyboard.sys
2010-08-22 00:44:00 ----A---- C:\WINDOWS\system32\key01.sys
2010-08-22 00:44:00 ----A---- C:\WINDOWS\system32\drivers\ksecdd.sys
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kernel32.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kerberos.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kdcom.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kd1394.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdycl.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdycc.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbduzb.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdusx.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdusr.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdusl.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdus.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdur.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdukx.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbduk.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdtuq.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdtuf.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdtat.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdsw.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdsp.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdsmsno.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdsmsfi.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdsl1.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdsl.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdsg.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdsf.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdru1.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdru.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdro.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdpo.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdpl1.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdpl.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdno1.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdno.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdnec.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdne.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdmon.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdmlt48.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdmlt47.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdmaori.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdmac.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdlv1.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdlv.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdlt1.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdlt.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdla.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdkyr.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdkaz.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdit142.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdit.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdir.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdinmal.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdinben.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdinbe1.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdic.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdhu1.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdhu.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdhept.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdhela3.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdhela2.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdhe319.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdhe220.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdhe.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdgr1.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdgr.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdgkl.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdgae.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdfr.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdfo.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdfi1.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdfi.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdfc.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdest.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdes.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbddv.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdda.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdcz2.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdcz1.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdcz.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdcr.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdcan.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdca.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdbu.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdbr.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdblr.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdbene.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdbe.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdazel.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kbdaze.dll
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\KBDAL.DLL
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\kb16.com
2010-08-22 00:43:59 ----A---- C:\WINDOWS\system32\drivers\kbdclass.sys
2010-08-22 00:43:58 ----N---- C:\WINDOWS\system32\jsproxy.dll
2010-08-22 00:43:58 ----A---- C:\WINDOWS\system32\jscript.dll
2010-08-22 00:43:58 ----A---- C:\WINDOWS\system32\jobexec.dll
2010-08-22 00:43:58 ----A---- C:\WINDOWS\system32\jgsh400.dll
2010-08-22 00:43:58 ----A---- C:\WINDOWS\system32\jgsd400.dll
2010-08-22 00:43:58 ----A---- C:\WINDOWS\system32\jgpl400.dll
2010-08-22 00:43:58 ----A---- C:\WINDOWS\system32\jgmd400.dll
2010-08-22 00:43:58 ----A---- C:\WINDOWS\system32\jgdw400.dll
2010-08-22 00:43:58 ----A---- C:\WINDOWS\system32\jgaw400.dll
2010-08-22 00:43:58 ----A---- C:\WINDOWS\system32\jet500.dll
2010-08-22 00:43:58 ----A---- C:\WINDOWS\system32\ixsso.dll
2010-08-22 00:43:58 ----A---- C:\WINDOWS\system32\iuengine.dll
2010-08-22 00:43:58 ----A---- C:\WINDOWS\system32\itss.dll
2010-08-22 00:43:58 ----A---- C:\WINDOWS\system32\itircl.dll
2010-08-22 00:43:58 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2010-08-22 00:43:58 ----A---- C:\WINDOWS\system32\isign32.dll
2010-08-22 00:43:58 ----A---- C:\WINDOWS\system32\irclass.dll
2010-08-22 00:43:58 ----A---- C:\WINDOWS\system32\ir50_qcx.dll
2010-08-22 00:43:58 ----A---- C:\WINDOWS\system32\ir50_qc.dll
2010-08-22 00:43:58 ----A---- C:\WINDOWS\system32\ir50_32.dll
2010-08-22 00:43:58 ----A---- C:\WINDOWS\system32\ir41_qcx.dll
2010-08-22 00:43:58 ----A---- C:\WINDOWS\system32\drivers\isapnp.sys
2010-08-22 00:43:58 ----A---- C:\WINDOWS\system32\drivers\irenum.sys
2010-08-22 00:43:57 ----A---- C:\WINDOWS\system32\ir41_qc.dll
2010-08-22 00:43:57 ----A---- C:\WINDOWS\system32\ir32_32.dll
2010-08-22 00:43:57 ----A---- C:\WINDOWS\system32\ipxwan.dll
2010-08-22 00:43:57 ----A---- C:\WINDOWS\system32\ipxsap.dll
2010-08-22 00:43:57 ----A---- C:\WINDOWS\system32\ipxrtmgr.dll
2010-08-22 00:43:57 ----A---- C:\WINDOWS\system32\ipxroute.exe
2010-08-22 00:43:57 ----A---- C:\WINDOWS\system32\ipxrip.dll
2010-08-22 00:43:57 ----A---- C:\WINDOWS\system32\ipxpromn.dll
2010-08-22 00:43:57 ----A---- C:\WINDOWS\system32\ipxmontr.dll
2010-08-22 00:43:57 ----A---- C:\WINDOWS\system32\ipv6mon.dll
2010-08-22 00:43:57 ----A---- C:\WINDOWS\system32\ipv6.exe
2010-08-22 00:43:57 ----A---- C:\WINDOWS\system32\ipsmsnap.dll
2010-08-22 00:43:57 ----A---- C:\WINDOWS\system32\ipsecsvc.dll
2010-08-22 00:43:57 ----A---- C:\WINDOWS\system32\ipsecsnp.dll
2010-08-22 00:43:57 ----A---- C:\WINDOWS\system32\ipsec6.exe
2010-08-22 00:43:57 ----A---- C:\WINDOWS\system32\iprtrmgr.dll
2010-08-22 00:43:57 ----A---- C:\WINDOWS\system32\iprtprio.dll
2010-08-22 00:43:57 ----A---- C:\WINDOWS\system32\iprop.dll
2010-08-22 00:43:57 ----A---- C:\WINDOWS\system32\ippromon.dll
2010-08-22 00:43:57 ----A---- C:\WINDOWS\system32\ipnathlp.dll
2010-08-22 00:43:57 ----A---- C:\WINDOWS\system32\ipmontr.dll
2010-08-22 00:43:57 ----A---- C:\WINDOWS\system32\iphlpapi.dll
2010-08-22 00:43:57 ----A---- C:\WINDOWS\system32\ipconfig.exe
2010-08-22 00:43:57 ----A---- C:\WINDOWS\system32\iologmsg.dll
2010-08-22 00:43:57 ----A---- C:\WINDOWS\system32\drivers\ipsec.sys
2010-08-22 00:43:57 ----A---- C:\WINDOWS\system32\drivers\ipnat.sys
2010-08-22 00:43:57 ----A---- C:\WINDOWS\system32\drivers\ipinip.sys
2010-08-22 00:43:57 ----A---- C:\WINDOWS\system32\drivers\ipfltdrv.sys
2010-08-22 00:43:57 ----A---- C:\WINDOWS\system32\drivers\ip6fw.sys
2010-08-22 00:43:56 ----A---- C:\WINDOWS\system32\inseng.dll
2010-08-22 00:43:56 ----A---- C:\WINDOWS\system32\input.dll
2010-08-22 00:43:56 ----A---- C:\WINDOWS\system32\initpki.dll
2010-08-22 00:43:56 ----A---- C:\WINDOWS\system32\infosoft.dll
2010-08-22 00:43:56 ----A---- C:\WINDOWS\system32\inetres.dll
2010-08-22 00:43:56 ----A---- C:\WINDOWS\system32\inetppui.dll
2010-08-22 00:43:56 ----A---- C:\WINDOWS\system32\inetpp.dll
2010-08-22 00:43:56 ----A---- C:\WINDOWS\system32\inetmib1.dll
2010-08-22 00:43:56 ----A---- C:\WINDOWS\system32\inetcplc.dll
2010-08-22 00:43:56 ----A---- C:\WINDOWS\system32\drivers\intelppm.sys
2010-08-22 00:43:56 ----A---- C:\WINDOWS\system32\drivers\intelide.sys
2010-08-22 00:43:56 ----A---- C:\WINDOWS\system32\drivers\ini910u.sys
2010-08-22 00:43:55 ----A---- C:\WINDOWS\system32\inetcomm.dll
2010-08-22 00:43:55 ----A---- C:\WINDOWS\system32\inetcfg.dll
2010-08-22 00:43:55 ----A---- C:\WINDOWS\system32\imm32.dll
2010-08-22 00:43:55 ----A---- C:\WINDOWS\system32\imgutil.dll
2010-08-22 00:43:55 ----A---- C:\WINDOWS\system32\imeshare.dll
2010-08-22 00:43:55 ----A---- C:\WINDOWS\system32\imapi.exe
2010-08-22 00:43:55 ----A---- C:\WINDOWS\system32\imagehlp.dll
2010-08-22 00:43:55 ----A---- C:\WINDOWS\system32\ils.dll
2010-08-22 00:43:55 ----A---- C:\WINDOWS\system32\igmpagnt.dll
2010-08-22 00:43:55 ----A---- C:\WINDOWS\system32\drivers\imapi.sys
2010-08-22 00:43:54 ----N---- C:\WINDOWS\system32\iernonce.dll
2010-08-22 00:43:54 ----N---- C:\WINDOWS\system32\iepeers.dll
2010-08-22 00:43:54 ----N---- C:\WINDOWS\system32\iedkcs32.dll
2010-08-22 00:43:54 ----N---- C:\WINDOWS\system32\ieakui.dll
2010-08-22 00:43:54 ----N---- C:\WINDOWS\system32\ieaksie.dll
2010-08-22 00:43:54 ----N---- C:\WINDOWS\system32\ieakeng.dll
2010-08-22 00:43:54 ----N---- C:\WINDOWS\system32\ie4uinit.exe
2010-08-22 00:43:54 ----A---- C:\WINDOWS\system32\ifsutil.dll
2010-08-22 00:43:54 ----A---- C:\WINDOWS\system32\ifmon.dll
2010-08-22 00:43:54 ----A---- C:\WINDOWS\system32\iexpress.exe
2010-08-22 00:43:54 ----A---- C:\WINDOWS\system32\iesetup.dll
2010-08-22 00:43:54 ----A---- C:\WINDOWS\system32\ieencode.dll
2010-08-22 00:43:54 ----A---- C:\WINDOWS\system32\idq.dll
2010-08-22 00:43:54 ----A---- C:\WINDOWS\system32\icwphbk.dll
2010-08-22 00:43:54 ----A---- C:\WINDOWS\system32\icwdial.dll
2010-08-22 00:43:54 ----A---- C:\WINDOWS\system32\icmui.dll
2010-08-22 00:43:54 ----A---- C:\WINDOWS\system32\icmp.dll
2010-08-22 00:43:54 ----A---- C:\WINDOWS\system32\icm32.dll
2010-08-22 00:43:54 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2010-08-22 00:43:54 ----A---- C:\WINDOWS\system32\iccvid.dll
2010-08-22 00:43:54 ----A---- C:\WINDOWS\system32\icaapi.dll
2010-08-22 00:43:53 ----A---- C:\WINDOWS\system32\iassvcs.dll
2010-08-22 00:43:53 ----A---- C:\WINDOWS\system32\iassdo.dll
2010-08-22 00:43:53 ----A---- C:\WINDOWS\system32\iassam.dll
2010-08-22 00:43:53 ----A---- C:\WINDOWS\system32\iasrecst.dll
2010-08-22 00:43:53 ----A---- C:\WINDOWS\system32\iasrad.dll
2010-08-22 00:43:53 ----A---- C:\WINDOWS\system32\iaspolcy.dll
2010-08-22 00:43:53 ----A---- C:\WINDOWS\system32\iasnap.dll
2010-08-22 00:43:53 ----A---- C:\WINDOWS\system32\iashlpr.dll
2010-08-22 00:43:53 ----A---- C:\WINDOWS\system32\iasads.dll
2010-08-22 00:43:53 ----A---- C:\WINDOWS\system32\iasacct.dll
2010-08-22 00:43:53 ----A---- C:\WINDOWS\system32\hypertrm.dll
2010-08-22 00:43:53 ----A---- C:\WINDOWS\system32\htui.dll
2010-08-22 00:43:53 ----A---- C:\WINDOWS\system32\httpapi.dll
2010-08-22 00:43:53 ----A---- C:\WINDOWS\system32\hticons.dll
2010-08-22 00:43:53 ----A---- C:\WINDOWS\system32\drivers\i8042prt.sys
2010-08-22 00:43:53 ----A---- C:\WINDOWS\system32\drivers\i2omp.sys
2010-08-22 00:43:53 ----A---- C:\WINDOWS\system32\drivers\i2omgmt.sys
2010-08-22 00:43:53 ----A---- C:\WINDOWS\system32\drivers\http.sys
2010-08-22 00:43:52 ----A---- C:\WINDOWS\system32\hotplug.dll
2010-08-22 00:43:52 ----A---- C:\WINDOWS\system32\hostname.exe
2010-08-22 00:43:52 ----A---- C:\WINDOWS\system32\hnetwiz.dll
2010-08-22 00:43:52 ----A---- C:\WINDOWS\system32\hnetmon.dll
2010-08-22 00:43:52 ----A---- C:\WINDOWS\system32\hnetcfg.dll
2010-08-22 00:43:52 ----A---- C:\WINDOWS\system32\hlink.dll
2010-08-22 00:43:52 ----A---- C:\WINDOWS\system32\drivers\hpn.sys
2010-08-22 00:43:51 ----A---- C:\WINDOWS\system32\himem.sys
2010-08-22 00:43:51 ----A---- C:\WINDOWS\system32\hhsetup.dll
2010-08-22 00:43:51 ----A---- C:\WINDOWS\system32\drivers\hidparse.sys
2010-08-22 00:43:51 ----A---- C:\WINDOWS\system32\drivers\hidclass.sys
2010-08-22 00:43:51 ----A---- C:\WINDOWS\hh.exe
2010-08-22 00:43:50 ----A---- C:\WINDOWS\system32\help.exe
2010-08-22 00:43:50 ----A---- C:\WINDOWS\system32\h323msp.dll
2010-08-22 00:43:49 ----A---- C:\WINDOWS\system32\grpconv.exe
2010-08-22 00:43:49 ----A---- C:\WINDOWS\system32\graphics.com
2010-08-22 00:43:49 ----A---- C:\WINDOWS\system32\graftabl.com
2010-08-22 00:43:49 ----A---- C:\WINDOWS\system32\gpkrsrc.dll
2010-08-22 00:43:49 ----A---- C:\WINDOWS\system32\gpkcsp.dll
2010-08-22 00:43:49 ----A---- C:\WINDOWS\system32\drivers\gmreadme.txt
2010-08-22 00:43:47 ----A---- C:\WINDOWS\system32\glu32.dll
2010-08-22 00:43:47 ----A---- C:\WINDOWS\system32\glmf32.dll
2010-08-22 00:43:47 ----A---- C:\WINDOWS\system32\getuname.dll
2010-08-22 00:43:47 ----A---- C:\WINDOWS\system32\gdi32.dll
2010-08-22 00:43:47 ----A---- C:\WINDOWS\system32\gdi.exe
2010-08-22 00:43:47 ----A---- C:\WINDOWS\system32\gcdef.dll
2010-08-22 00:43:46 ----A---- C:\WINDOWS\system32\fwcfg.dll
2010-08-22 00:43:46 ----A---- C:\WINDOWS\system32\ftsrch.dll
2010-08-22 00:43:46 ----A---- C:\WINDOWS\system32\ftp.exe
2010-08-22 00:43:46 ----A---- C:\WINDOWS\system32\fsutil.exe
2010-08-22 00:43:46 ----A---- C:\WINDOWS\system32\fsusd.dll
2010-08-22 00:43:46 ----A---- C:\WINDOWS\system32\fsquirt.exe
2010-08-22 00:43:46 ----A---- C:\WINDOWS\system32\fsmgmt.msc
2010-08-22 00:43:46 ----A---- C:\WINDOWS\system32\freecell.exe
2010-08-22 00:43:46 ----A---- C:\WINDOWS\system32\framebuf.dll
2010-08-22 00:43:46 ----A---- C:\WINDOWS\system32\drivers\ftdisk.sys
2010-08-22 00:43:46 ----A---- C:\WINDOWS\system32\drivers\fs_rec.sys
2010-08-22 00:43:45 ----A---- C:\WINDOWS\system32\format.com
2010-08-22 00:43:45 ----A---- C:\WINDOWS\system32\forcedos.exe
2010-08-22 00:43:45 ----A---- C:\WINDOWS\system32\fontview.exe
2010-08-22 00:43:45 ----A---- C:\WINDOWS\system32\fontsub.dll
2010-08-22 00:43:45 ----A---- C:\WINDOWS\system32\fontext.dll
2010-08-22 00:43:45 ----A---- C:\WINDOWS\system32\fmifs.dll
2010-08-22 00:43:45 ----A---- C:\WINDOWS\system32\fltmc.exe
2010-08-22 00:43:45 ----A---- C:\WINDOWS\system32\fltlib.dll
2010-08-22 00:43:45 ----A---- C:\WINDOWS\system32\fldrclnr.dll
2010-08-22 00:43:45 ----A---- C:\WINDOWS\system32\drivers\fltmgr.sys
2010-08-22 00:43:45 ----A---- C:\WINDOWS\system32\drivers\flpydisk.sys
2010-08-22 00:43:44 ----N---- C:\WINDOWS\system32\extmgr.dll
2010-08-22 00:43:44 ----A---- C:\WINDOWS\system32\fixmapi.exe
2010-08-22 00:43:44 ----A---- C:\WINDOWS\system32\finger.exe
2010-08-22 00:43:44 ----A---- C:\WINDOWS\system32\findstr.exe
2010-08-22 00:43:44 ----A---- C:\WINDOWS\system32\find.exe
2010-08-22 00:43:44 ----A---- C:\WINDOWS\system32\filemgmt.dll
2010-08-22 00:43:44 ----A---- C:\WINDOWS\system32\feclient.dll
2010-08-22 00:43:44 ----A---- C:\WINDOWS\system32\fc.exe
2010-08-22 00:43:44 ----A---- C:\WINDOWS\system32\faultrep.dll
2010-08-22 00:43:44 ----A---- C:\WINDOWS\system32\fastopen.exe
2010-08-22 00:43:44 ----A---- C:\WINDOWS\system32\exts.dll
2010-08-22 00:43:44 ----A---- C:\WINDOWS\system32\extrac32.exe
2010-08-22 00:43:44 ----A---- C:\WINDOWS\system32\expsrv.dll
2010-08-22 00:43:44 ----A---- C:\WINDOWS\system32\expand.exe
2010-08-22 00:43:44 ----A---- C:\WINDOWS\system32\drivers\fips.sys
2010-08-22 00:43:44 ----A---- C:\WINDOWS\system32\drivers\fdc.sys
2010-08-22 00:43:44 ----A---- C:\WINDOWS\system32\drivers\fastfat.sys
2010-08-22 00:43:44 ----A---- C:\WINDOWS\explorer.exe
2010-08-22 00:43:43 ----A---- C:\WINDOWS\system32\exe2bin.exe
2010-08-22 00:43:43 ----A---- C:\WINDOWS\system32\eventvwr.msc
2010-08-22 00:43:43 ----A---- C:\WINDOWS\system32\eventvwr.exe
2010-08-22 00:43:43 ----A---- C:\WINDOWS\system32\eventlog.dll
2010-08-22 00:43:43 ----A---- C:\WINDOWS\system32\eventcls.dll
2010-08-22 00:43:43 ----A---- C:\WINDOWS\system32\eula.txt
2010-08-22 00:43:43 ----A---- C:\WINDOWS\system32\eudcedit.exe
2010-08-22 00:43:42 ----A---- C:\WINDOWS\system32\esentutl.exe
2010-08-22 00:43:42 ----A---- C:\WINDOWS\system32\esentprf.ini
2010-08-22 00:43:42 ----A---- C:\WINDOWS\system32\esentprf.dll
2010-08-22 00:43:42 ----A---- C:\WINDOWS\system32\esent97.dll
2010-08-22 00:43:42 ----A---- C:\WINDOWS\system32\esent.dll
2010-08-22 00:43:42 ----A---- C:\WINDOWS\system32\es.dll
2010-08-22 00:43:42 ----A---- C:\WINDOWS\system32\ersvc.dll
2010-08-22 00:43:42 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2010-08-22 00:43:42 ----A---- C:\WINDOWS\system32\encdec.dll
2010-08-22 00:43:42 ----A---- C:\WINDOWS\system32\encapi.dll
2010-08-22 00:43:42 ----A---- C:\WINDOWS\system32\els.dll
2010-08-22 00:43:42 ----A---- C:\WINDOWS\system32\edlin.exe
2010-08-22 00:43:42 ----A---- C:\WINDOWS\system32\edit.com
2010-08-22 00:43:41 ----N---- C:\WINDOWS\system32\dxtrans.dll
2010-08-22 00:43:41 ----N---- C:\WINDOWS\system32\dxtmsft.dll
2010-08-22 00:43:41 ----A---- C:\WINDOWS\system32\dxmasf.dll
2010-08-22 00:43:41 ----A---- C:\WINDOWS\system32\dxdiagn.dll
2010-08-22 00:43:41 ----A---- C:\WINDOWS\system32\drivers\dxgthk.sys
2010-08-22 00:43:41 ----A---- C:\WINDOWS\system32\drivers\dxg.sys
2010-08-22 00:43:40 ----A---- C:\WINDOWS\system32\dxdiag.exe
2010-08-22 00:43:40 ----A---- C:\WINDOWS\system32\dx8vb.dll
2010-08-22 00:43:40 ----A---- C:\WINDOWS\system32\dx7vb.dll
2010-08-22 00:43:40 ----A---- C:\WINDOWS\system32\dwwin.exe
2010-08-22 00:43:40 ----A---- C:\WINDOWS\system32\dvdupgrd.exe
2010-08-22 00:43:40 ----A---- C:\WINDOWS\system32\duser.dll
2010-08-22 00:43:40 ----A---- C:\WINDOWS\system32\dumprep.exe
2010-08-22 00:43:40 ----A---- C:\WINDOWS\system32\dswave.dll
2010-08-22 00:43:40 ----A---- C:\WINDOWS\system32\dsuiext.dll
2010-08-22 00:43:40 ----A---- C:\WINDOWS\system32\dssenh.dll
2010-08-22 00:43:40 ----A---- C:\WINDOWS\system32\dssec.dll
2010-08-22 00:43:40 ----A---- C:\WINDOWS\system32\dsquery.dll
2010-08-22 00:43:40 ----A---- C:\WINDOWS\system32\dsprpres.dll
2010-08-22 00:43:40 ----A---- C:\WINDOWS\system32\dsprop.dll
2010-08-22 00:43:40 ----A---- C:\WINDOWS\system32\dsound3d.dll
2010-08-22 00:43:40 ----A---- C:\WINDOWS\system32\dsound.dll
2010-08-22 00:43:40 ----A---- C:\WINDOWS\system32\dskquoui.dll
2010-08-22 00:43:40 ----A---- C:\WINDOWS\system32\dskquota.dll
2010-08-22 00:43:40 ----A---- C:\WINDOWS\system32\drivers\dxapi.sys
2010-08-22 00:43:39 ----A---- C:\WINDOWS\system32\dsdmoprp.dll
2010-08-22 00:43:39 ----A---- C:\WINDOWS\system32\dsdmo.dll
2010-08-22 00:43:39 ----A---- C:\WINDOWS\system32\dsauth.dll
2010-08-22 00:43:39 ----A---- C:\WINDOWS\system32\ds32gt.dll
2010-08-22 00:43:39 ----A---- C:\WINDOWS\system32\ds16gt.dLL
2010-08-22 00:43:39 ----A---- C:\WINDOWS\system32\drwtsn32.exe
2010-08-22 00:43:39 ----A---- C:\WINDOWS\system32\drwatson.exe
2010-08-22 00:43:39 ----A---- C:\WINDOWS\system32\drprov.dll
2010-08-22 00:43:39 ----A---- C:\WINDOWS\system32\drmv2clt.dll
2010-08-22 00:43:39 ----A---- C:\WINDOWS\system32\drmstor.dll
2010-08-22 00:43:39 ----A---- C:\WINDOWS\system32\drmclien.dll
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\drivers\dpti2o.sys
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\drivers\dmload.sys
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\drivers\dmio.sys
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dpwsockx.dll
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dpwsock.dll
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dpvvox.dll
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dpvsetup.exe
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dpvoice.dll
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dpvacm.dll
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dpserial.dll
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dpnwsock.dll
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dpnsvr.exe
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dpnmodem.dll
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dpnlobby.dll
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dpnhupnp.dll
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dpnhpast.dll
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dpnet.dll
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dpnaddr.dll
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dpmodemx.dll
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dplayx.dll
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dplaysvr.exe
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dplay.dll
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dpcdll.dll
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dosx.exe
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\doskey.exe
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\docprop2.dll
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\docprop.dll
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dnsrslvr.dll
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dnsapi.dll
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dmusic.dll
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dmsynth.dll
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dmstyle.dll
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dmserver.dll
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dmscript.dll
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dmremote.exe
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dmocx.dll
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dmloader.dll
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dmintf.dll
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dmime.dll
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dmdskres.dll
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dmdskmgr.dll
2010-08-22 00:43:12 ----A---- C:\WINDOWS\system32\dmdlgs.dll
2010-08-22 00:43:11 ----A---- C:\WINDOWS\system32\drivers\dmboot.sys
2010-08-22 00:43:11 ----A---- C:\WINDOWS\system32\drivers\diskdump.sys
2010-08-22 00:43:11 ----A---- C:\WINDOWS\system32\drivers\disk.sys
2010-08-22 00:43:11 ----A---- C:\WINDOWS\system32\dmconfig.dll
2010-08-22 00:43:11 ----A---- C:\WINDOWS\system32\dmcompos.dll
2010-08-22 00:43:11 ----A---- C:\WINDOWS\system32\dmband.dll
2010-08-22 00:43:11 ----A---- C:\WINDOWS\system32\dmadmin.exe
2010-08-22 00:43:11 ----A---- C:\WINDOWS\system32\dllhst3g.exe
2010-08-22 00:43:11 ----A---- C:\WINDOWS\system32\dllhost.exe
2010-08-22 00:43:11 ----A---- C:\WINDOWS\system32\dispex.dll
2010-08-22 00:43:11 ----A---- C:\WINDOWS\system32\diskperf.exe
2010-08-22 00:43:11 ----A---- C:\WINDOWS\system32\diskpart.exe
2010-08-22 00:43:11 ----A---- C:\WINDOWS\system32\diskmgmt.msc
2010-08-22 00:43:11 ----A---- C:\WINDOWS\system32\diskcopy.dll
2010-08-22 00:43:11 ----A---- C:\WINDOWS\system32\diskcopy.com
2010-08-22 00:43:11 ----A---- C:\WINDOWS\system32\diskcomp.com
2010-08-22 00:43:11 ----A---- C:\WINDOWS\system32\dinput8.dll
2010-08-22 00:43:11 ----A---- C:\WINDOWS\system32\dinput.dll
2010-08-22 00:43:11 ----A---- C:\WINDOWS\system32\dimap.dll
2010-08-22 00:43:10 ----A---- C:\WINDOWS\system32\digest.dll
2010-08-22 00:43:10 ----A---- C:\WINDOWS\system32\diantz.exe
2010-08-22 00:43:10 ----A---- C:\WINDOWS\system32\diactfrm.dll
2010-08-22 00:43:10 ----A---- C:\WINDOWS\system32\dhcpsapi.dll
2010-08-22 00:43:10 ----A---- C:\WINDOWS\system32\dhcpmon.dll
2010-08-22 00:43:09 ----A---- C:\WINDOWS\system32\dhcpcsvc.dll
2010-08-22 00:43:09 ----A---- C:\WINDOWS\system32\dgsetup.dll
2010-08-22 00:43:09 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2010-08-22 00:43:09 ----A---- C:\WINDOWS\system32\dgnet.dll
2010-08-22 00:43:09 ----A---- C:\WINDOWS\system32\dfsshlex.dll
2010-08-22 00:43:09 ----A---- C:\WINDOWS\system32\dfrgui.dll
2010-08-22 00:43:09 ----A---- C:\WINDOWS\system32\dfrgsnap.dll
2010-08-22 00:43:09 ----A---- C:\WINDOWS\system32\dfrgres.dll
2010-08-22 00:43:09 ----A---- C:\WINDOWS\system32\dfrgntfs.exe
2010-08-22 00:43:09 ----A---- C:\WINDOWS\system32\dfrgfat.exe
2010-08-22 00:43:09 ----A---- C:\WINDOWS\system32\dfrg.msc
2010-08-22 00:43:09 ----A---- C:\WINDOWS\system32\devmgr.dll
2010-08-22 00:43:09 ----A---- C:\WINDOWS\system32\devmgmt.msc
2010-08-22 00:43:09 ----A---- C:\WINDOWS\system32\devenum.dll
2010-08-22 00:43:09 ----A---- C:\WINDOWS\system32\deskperf.dll
2010-08-22 00:43:09 ----A---- C:\WINDOWS\system32\deskmon.dll
2010-08-22 00:43:09 ----A---- C:\WINDOWS\system32\deskadp.dll
2010-08-22 00:43:09 ----A---- C:\WINDOWS\system32\defrag.exe
2010-08-22 00:43:09 ----A---- C:\WINDOWS\system32\debug.exe
2010-08-22 00:43:09 ----A---- C:\WINDOWS\system32\ddrawex.dll
2010-08-22 00:43:09 ----A---- C:\WINDOWS\system32\ddraw.dll
2010-08-22 00:43:09 ----A---- C:\WINDOWS\system32\ddeshare.exe
2010-08-22 00:43:09 ----A---- C:\WINDOWS\system32\ddeml.dll
2010-08-22 00:43:09 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2010-08-22 00:43:09 ----A---- C:\WINDOWS\system32\dciman32.dll
2010-08-22 00:43:09 ----A---- C:\WINDOWS\system32\dbnmpntw.dll
2010-08-22 00:43:09 ----A---- C:\WINDOWS\system32\dbnetlib.dll
2010-08-22 00:43:09 ----A---- C:\WINDOWS\system32\dbmsrpcn.dll
2010-08-22 00:43:09 ----A---- C:\WINDOWS\system32\dbghelp.dll
2010-08-22 00:43:09 ----A---- C:\WINDOWS\fonts\desktop.ini
2010-08-22 00:43:08 ----A---- C:\WINDOWS\system32\drivers\dac960nt.sys
2010-08-22 00:43:08 ----A---- C:\WINDOWS\system32\drivers\dac2w2k.sys
2010-08-22 00:43:08 ----A---- C:\WINDOWS\system32\dbgeng.dll
2010-08-22 00:43:08 ----A---- C:\WINDOWS\system32\davclnt.dll
2010-08-22 00:43:08 ----A---- C:\WINDOWS\system32\datime.dll
2010-08-22 00:43:08 ----A---- C:\WINDOWS\system32\dataclen.dll
2010-08-22 00:43:08 ----A---- C:\WINDOWS\system32\danim.dll
2010-08-22 00:43:08 ----A---- C:\WINDOWS\system32\d3dxof.dll
2010-08-22 00:43:08 ----A---- C:\WINDOWS\system32\d3drm.dll
2010-08-22 00:43:08 ----A---- C:\WINDOWS\system32\d3dramp.dll
2010-08-22 00:43:08 ----A---- C:\WINDOWS\system32\d3dpmesh.dll
2010-08-22 00:43:07 ----A---- C:\WINDOWS\system32\d3dim700.dll
2010-08-22 00:43:07 ----A---- C:\WINDOWS\system32\d3dim.dll
2010-08-22 00:43:07 ----A---- C:\WINDOWS\system32\d3d9.dll
2010-08-22 00:43:07 ----A---- C:\WINDOWS\system32\d3d8thk.dll
2010-08-22 00:43:07 ----A---- C:\WINDOWS\system32\d3d8.dll
2010-08-22 00:43:06 ----A---- C:\WINDOWS\system32\ctl3dv2.dll
2010-08-22 00:43:06 ----A---- C:\WINDOWS\system32\ctl3d32.dll
2010-08-22 00:43:06 ----A---- C:\WINDOWS\system32\ctfmon.exe
2010-08-22 00:43:06 ----A---- C:\WINDOWS\system32\csseqchk.dll
2010-08-22 00:43:06 ----A---- C:\WINDOWS\system32\csrss.exe
2010-08-22 00:43:06 ----A---- C:\WINDOWS\system32\csrsrv.dll
2010-08-22 00:43:06 ----A---- C:\WINDOWS\system32\cscui.dll
2010-08-22 00:43:05 ----A---- C:\WINDOWS\system32\drivers\cpqarray.sys
2010-08-22 00:43:05 ----A---- C:\WINDOWS\system32\cscript.exe
2010-08-22 00:43:05 ----A---- C:\WINDOWS\system32\cscdll.dll
2010-08-22 00:43:05 ----A---- C:\WINDOWS\system32\cryptui.dll
2010-08-22 00:43:05 ----A---- C:\WINDOWS\system32\cryptsvc.dll
2010-08-22 00:43:05 ----A---- C:\WINDOWS\system32\cryptnet.dll
2010-08-22 00:43:05 ----A---- C:\WINDOWS\system32\cryptext.dll
2010-08-22 00:43:05 ----A---- C:\WINDOWS\system32\cryptdll.dll
2010-08-22 00:43:05 ----A---- C:\WINDOWS\system32\cryptdlg.dll
2010-08-22 00:43:05 ----A---- C:\WINDOWS\system32\crypt32.dll
2010-08-22 00:43:05 ----A---- C:\WINDOWS\system32\crtdll.dll
2010-08-22 00:43:05 ----A---- C:\WINDOWS\system32\credui.dll
2010-08-22 00:43:04 ----A---- C:\WINDOWS\system32\country.sys
2010-08-22 00:43:04 ----A---- C:\WINDOWS\system32\corpol.dll
2010-08-22 00:43:04 ----A---- C:\WINDOWS\system32\convert.exe
2010-08-22 00:43:04 ----A---- C:\WINDOWS\system32\control.exe
2010-08-22 00:43:04 ----A---- C:\WINDOWS\system32\console.dll
2010-08-22 00:43:04 ----A---- C:\WINDOWS\system32\conime.exe
2010-08-22 00:43:04 ----A---- C:\WINDOWS\system32\confmsp.dll
2010-08-22 00:43:04 ----A---- C:\WINDOWS\system32\comuid.dll
2010-08-22 00:43:03 ----A---- C:\WINDOWS\system32\comsvcs.dll
2010-08-22 00:43:03 ----A---- C:\WINDOWS\system32\comsnap.dll
2010-08-22 00:43:03 ----A---- C:\WINDOWS\system32\comres.dll
2010-08-22 00:43:03 ----A---- C:\WINDOWS\system32\comrepl.dll
2010-08-22 00:43:03 ----A---- C:\WINDOWS\system32\compstui.dll
2010-08-22 00:43:03 ----A---- C:\WINDOWS\system32\compobj.dll
2010-08-22 00:43:03 ----A---- C:\WINDOWS\system32\compmgmt.msc
2010-08-22 00:43:00 ----A---- C:\WINDOWS\system32\compatui.dll
2010-08-22 00:43:00 ----A---- C:\WINDOWS\system32\compact.exe
2010-08-22 00:43:00 ----A---- C:\WINDOWS\system32\comp.exe
2010-08-22 00:43:00 ----A---- C:\WINDOWS\system32\commdlg.dll
2010-08-22 00:43:00 ----A---- C:\WINDOWS\system32\command.com
2010-08-22 00:43:00 ----A---- C:\WINDOWS\system32\comdlg32.dll
2010-08-22 00:42:59 ----A---- C:\WINDOWS\system32\shellstyle.dll
2010-08-22 00:42:59 ----A---- C:\WINDOWS\system32\drivers\cmdide.sys
2010-08-22 00:42:59 ----A---- C:\WINDOWS\system32\drivers\classpnp.sys
2010-08-22 00:42:59 ----A---- C:\WINDOWS\system32\comctl32.dll
2010-08-22 00:42:59 ----A---- C:\WINDOWS\system32\comcat.dll
2010-08-22 00:42:59 ----A---- C:\WINDOWS\system32\comaddin.dll
2010-08-22 00:42:59 ----A---- C:\WINDOWS\system32\colbact.dll
2010-08-22 00:42:59 ----A---- C:\WINDOWS\system32\cnvfat.dll
2010-08-22 00:42:59 ----A---- C:\WINDOWS\system32\cnetcfg.dll
2010-08-22 00:42:59 ----A---- C:\WINDOWS\system32\cmutil.dll
2010-08-22 00:42:59 ----A---- C:\WINDOWS\system32\cmstp.exe
2010-08-22 00:42:59 ----A---- C:\WINDOWS\system32\cmsetacl.dll
2010-08-22 00:42:59 ----A---- C:\WINDOWS\system32\cmprops.dll
2010-08-22 00:42:59 ----A---- C:\WINDOWS\system32\cmpbk32.dll
2010-08-22 00:42:59 ----A---- C:\WINDOWS\system32\cmmon32.exe
2010-08-22 00:42:59 ----A---- C:\WINDOWS\system32\cmdl32.exe
2010-08-22 00:42:59 ----A---- C:\WINDOWS\system32\cmdial32.dll
2010-08-22 00:42:59 ----A---- C:\WINDOWS\system32\cmd.exe
2010-08-22 00:42:59 ----A---- C:\WINDOWS\system32\cmcfg32.dll
2010-08-22 00:42:59 ----A---- C:\WINDOWS\system32\clusapi.dll
2010-08-22 00:42:59 ----A---- C:\WINDOWS\system32\clipsrv.exe
2010-08-22 00:42:59 ----A---- C:\WINDOWS\system32\clipbrd.exe
2010-08-22 00:42:59 ----A---- C:\WINDOWS\system32\cliconfg.exe
2010-08-22 00:42:59 ----A---- C:\WINDOWS\system32\cliconfg.dll
2010-08-22 00:42:59 ----A---- C:\WINDOWS\system32\cleanmgr.exe
2010-08-22 00:42:59 ----A---- C:\WINDOWS\system32\clbcatq.dll
2010-08-22 00:42:59 ----A---- C:\WINDOWS\system32\clbcatex.dll
2010-08-22 00:42:59 ----A---- C:\WINDOWS\system32\clb.dll
2010-08-22 00:42:59 ----A---- C:\WINDOWS\system32\ckcnv.exe
2010-08-22 00:42:59 ----A---- C:\WINDOWS\system32\cisvc.exe
2010-08-22 00:42:59 ----A---- C:\WINDOWS\system32\ciodm.dll
2010-08-22 00:42:58 ----A---- C:\WINDOWS\system32\drivers\cdrom.sys
2010-08-22 00:42:58 ----A---- C:\WINDOWS\system32\cidaemon.exe
2010-08-22 00:42:58 ----A---- C:\WINDOWS\system32\cic.dll
2010-08-22 00:42:58 ----A---- C:\WINDOWS\system32\ciadv.msc
2010-08-22 00:42:58 ----A---- C:\WINDOWS\system32\ciadmin.dll
2010-08-22 00:42:58 ----A---- C:\WINDOWS\system32\chkntfs.exe
2010-08-22 00:42:58 ----A---- C:\WINDOWS\system32\chkdsk.exe
2010-08-22 00:42:58 ----A---- C:\WINDOWS\system32\chcp.com
2010-08-22 00:42:58 ----A---- C:\WINDOWS\system32\charmap.exe
2010-08-22 00:42:58 ----A---- C:\WINDOWS\system32\cfgmgr32.dll
2010-08-22 00:42:58 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2010-08-22 00:42:58 ----A---- C:\WINDOWS\system32\cewmdm.dll
2010-08-22 00:42:58 ----A---- C:\WINDOWS\system32\certmgr.msc
2010-08-22 00:42:58 ----A---- C:\WINDOWS\system32\certmgr.dll
2010-08-22 00:42:58 ----A---- C:\WINDOWS\system32\certcli.dll
2010-08-22 00:42:57 ----A---- C:\WINDOWS\system32\drivers\cdfs.sys
2010-08-22 00:42:57 ----A---- C:\WINDOWS\system32\drivers\cd20xrnt.sys
2010-08-22 00:42:57 ----A---- C:\WINDOWS\system32\drivers\cbidf2k.sys
2010-08-22 00:42:57 ----A---- C:\WINDOWS\system32\cdosys.dll
2010-08-22 00:42:57 ----A---- C:\WINDOWS\system32\cdmodem.dll
2010-08-22 00:42:57 ----A---- C:\WINDOWS\system32\cdm.dll
2010-08-22 00:42:57 ----A---- C:\WINDOWS\system32\cdfview.dll
2010-08-22 00:42:57 ----A---- C:\WINDOWS\system32\ccfgnt.dll
2010-08-22 00:42:57 ----A---- C:\WINDOWS\system32\catsrvut.dll
2010-08-22 00:42:57 ----A---- C:\WINDOWS\system32\catsrvps.dll
2010-08-22 00:42:57 ----A---- C:\WINDOWS\system32\catsrv.dll
2010-08-22 00:42:57 ----A---- C:\WINDOWS\system32\cards.dll
2010-08-22 00:42:57 ----A---- C:\WINDOWS\system32\capesnpn.dll
2010-08-22 00:42:57 ----A---- C:\WINDOWS\system32\camocx.dll
2010-08-22 00:42:57 ----A---- C:\WINDOWS\system32\calc.exe
2010-08-22 00:42:57 ----A---- C:\WINDOWS\system32\cacls.exe
2010-08-22 00:42:57 ----A---- C:\WINDOWS\system32\cabview.dll
2010-08-22 00:42:57 ----A---- C:\WINDOWS\system32\cabinet.dll
2010-08-22 00:42:57 ----A---- C:\WINDOWS\system32\btpanui.dll
2010-08-22 00:42:56 ----A---- C:\WINDOWS\system32\drivers\bridge.sys
2010-08-22 00:42:56 ----A---- C:\WINDOWS\system32\bthserv.dll
2010-08-22 00:42:56 ----A---- C:\WINDOWS\system32\bthci.dll
2010-08-22 00:42:56 ----A---- C:\WINDOWS\system32\browsewm.dll
2010-08-22 00:42:56 ----A---- C:\WINDOWS\system32\browseui.dll
2010-08-22 00:42:56 ----A---- C:\WINDOWS\system32\browser.dll
2010-08-22 00:42:56 ----A---- C:\WINDOWS\system32\browselc.dll
2010-08-22 00:42:55 ----A---- C:\WINDOWS\system32\drivers\beep.sys
2010-08-22 00:42:55 ----A---- C:\WINDOWS\system32\bootvrfy.exe
2010-08-22 00:42:55 ----A---- C:\WINDOWS\system32\bootvid.dll
2010-08-22 00:42:55 ----A---- C:\WINDOWS\system32\bootok.exe
2010-08-22 00:42:55 ----A---- C:\WINDOWS\system32\blastcln.exe
2010-08-22 00:42:55 ----A---- C:\WINDOWS\system32\blackbox.dll
2010-08-22 00:42:55 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2010-08-22 00:42:55 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2010-08-22 00:42:55 ----A---- C:\WINDOWS\system32\bidispl.dll
2010-08-22 00:42:54 ----A---- C:\WINDOWS\system32\batt.dll
2010-08-22 00:42:54 ----A---- C:\WINDOWS\system32\batmeter.dll
2010-08-22 00:42:54 ----A---- C:\WINDOWS\system32\basesrv.dll
2010-08-22 00:42:54 ----A---- C:\WINDOWS\system32\avwav.dll
2010-08-22 00:42:54 ----A---- C:\WINDOWS\system32\avtapi.dll
2010-08-22 00:42:54 ----A---- C:\WINDOWS\system32\avmeter.dll
2010-08-22 00:42:54 ----A---- C:\WINDOWS\system32\avifile.dll
2010-08-22 00:42:54 ----A---- C:\WINDOWS\system32\avifil32.dll
2010-08-22 00:42:54 ----A---- C:\WINDOWS\system32\avicap32.dll
2010-08-22 00:42:54 ----A---- C:\WINDOWS\system32\avicap.dll
2010-08-22 00:42:54 ----A---- C:\WINDOWS\system32\autolfn.exe
2010-08-22 00:42:54 ----A---- C:\WINDOWS\system32\autofmt.exe
2010-08-22 00:42:54 ----A---- C:\WINDOWS\system32\autodisc.dll
2010-08-22 00:42:54 ----A---- C:\WINDOWS\system32\autoconv.exe
2010-08-22 00:42:53 ----A---- C:\WINDOWS\system32\drivers\atmuni.sys
2010-08-22 00:42:53 ----A---- C:\WINDOWS\system32\drivers\atmlane.sys
2010-08-22 00:42:53 ----A---- C:\WINDOWS\system32\drivers\atmepvc.sys
2010-08-22 00:42:53 ----A---- C:\WINDOWS\system32\drivers\atmarpc.sys
2010-08-22 00:42:53 ----A---- C:\WINDOWS\system32\drivers\atapi.sys
2010-08-22 00:42:53 ----A---- C:\WINDOWS\system32\drivers\asyncmac.sys
2010-08-22 00:42:53 ----A---- C:\WINDOWS\system32\autochk.exe
2010-08-22 00:42:53 ----A---- C:\WINDOWS\system32\authz.dll
2010-08-22 00:42:53 ----A---- C:\WINDOWS\system32\auditusr.exe
2010-08-22 00:42:53 ----A---- C:\WINDOWS\system32\audiosrv.dll
2010-08-22 00:42:53 ----A---- C:\WINDOWS\system32\attrib.exe
2010-08-22 00:42:53 ----A---- C:\WINDOWS\system32\atrace.dll
2010-08-22 00:42:53 ----A---- C:\WINDOWS\system32\atmpvcno.dll
2010-08-22 00:42:53 ----A---- C:\WINDOWS\system32\atmlib.dll
2010-08-22 00:42:53 ----A---- C:\WINDOWS\system32\atmfd.dll
2010-08-22 00:42:53 ----A---- C:\WINDOWS\system32\atmadm.exe
2010-08-22 00:42:53 ----A---- C:\WINDOWS\system32\atl.dll
2010-08-22 00:42:53 ----A---- C:\WINDOWS\system32\atkctrs.dll
2010-08-22 00:42:53 ----A---- C:\WINDOWS\system32\at.exe
2010-08-22 00:42:53 ----A---- C:\WINDOWS\system32\asycfilt.dll
2010-08-22 00:42:49 ----A---- C:\WINDOWS\system32\drivers\asc3550.sys
2010-08-22 00:42:49 ----A---- C:\WINDOWS\system32\drivers\asc3350p.sys
2010-08-22 00:42:49 ----A---- C:\WINDOWS\system32\drivers\asc.sys
2010-08-22 00:42:49 ----A---- C:\WINDOWS\system32\asferror.dll
2010-08-22 00:42:47 ----A---- C:\WINDOWS\system32\arp.exe
2010-08-22 00:42:47 ----A---- C:\WINDOWS\system32\apphelp.dll
2010-08-22 00:42:47 ----A---- C:\WINDOWS\system32\append.exe
2010-08-22 00:42:47 ----A---- C:\WINDOWS\system32\apcups.dll
2010-08-22 00:42:47 ----A---- C:\WINDOWS\system32\ansi.sys
2010-08-22 00:42:46 ----A---- C:\WINDOWS\system32\drivers\amsint.sys
2010-08-22 00:42:46 ----A---- C:\WINDOWS\system32\drivers\aliide.sys
2010-08-22 00:42:46 ----A---- C:\WINDOWS\system32\drivers\aic78xx.sys
2010-08-22 00:42:46 ----A---- C:\WINDOWS\system32\drivers\aic78u2.sys
2010-08-22 00:42:46 ----A---- C:\WINDOWS\system32\drivers\aha154x.sys
2010-08-22 00:42:46 ----A---- C:\WINDOWS\system32\drivers\afd.sys
2010-08-22 00:42:46 ----A---- C:\WINDOWS\system32\amstream.dll
2010-08-22 00:42:46 ----A---- C:\WINDOWS\system32\alrsvc.dll
2010-08-22 00:42:46 ----A---- C:\WINDOWS\system32\alg.exe
2010-08-22 00:42:46 ----A---- C:\WINDOWS\system32\ahui.exe
2010-08-22 00:42:46 ----A---- C:\WINDOWS\system32\advpack.dll
2010-08-22 00:42:46 ----A---- C:\WINDOWS\system32\advapi32.dll
2010-08-22 00:42:46 ----A---- C:\WINDOWS\system32\adsnt.dll
2010-08-22 00:42:46 ----A---- C:\WINDOWS\system32\adsmsext.dll
2010-08-22 00:42:46 ----A---- C:\WINDOWS\system32\adsldpc.dll
2010-08-22 00:42:46 ----A---- C:\WINDOWS\system32\adsldp.dll
2010-08-22 00:42:45 ----A---- C:\WINDOWS\system32\drivers\adpu160m.sys
2010-08-22 00:42:45 ----A---- C:\WINDOWS\system32\drivers\acpiec.sys
2010-08-22 00:42:45 ----A---- C:\WINDOWS\system32\drivers\acpi.sys
2010-08-22 00:42:45 ----A---- C:\WINDOWS\system32\drivers\ABP480N5.SYS
2010-08-22 00:42:45 ----A---- C:\WINDOWS\system32\adptif.dll
2010-08-22 00:42:45 ----A---- C:\WINDOWS\system32\admparse.dll
2010-08-22 00:42:45 ----A---- C:\WINDOWS\system32\actxprxy.dll
2010-08-22 00:42:45 ----A---- C:\WINDOWS\system32\actmovie.exe
2010-08-22 00:42:45 ----A---- C:\WINDOWS\system32\activeds.dll
2010-08-22 00:42:45 ----A---- C:\WINDOWS\system32\aclui.dll
2010-08-22 00:42:45 ----A---- C:\WINDOWS\system32\acledit.dll
2010-08-22 00:42:45 ----A---- C:\WINDOWS\system32\accwiz.exe
2010-08-22 00:42:45 ----A---- C:\WINDOWS\system32\acctres.dll
2010-08-22 00:42:45 ----A---- C:\WINDOWS\system32\aaaamon.dll
2010-08-22 00:42:44 ----D---- C:\WINDOWS\I386
2010-08-22 00:42:44 ----A---- C:\WINDOWS\system32\6to4svc.dll
2010-08-22 00:35:19 ----N---- C:\WINDOWS\system32\msxml6r.dll
2010-08-22 00:35:19 ----N---- C:\WINDOWS\system32\msxml6.dll
2010-08-22 00:35:10 ----N---- C:\WINDOWS\system32\credssp.dll
2010-08-22 00:35:10 ----N---- C:\WINDOWS\system32\bitsprx4.dll
2010-08-22 00:35:10 ----N---- C:\WINDOWS\system32\azroles.dll
2010-08-22 00:35:10 ----N---- C:\WINDOWS\system32\ativvaxx.dll
2010-08-22 00:35:10 ----N---- C:\WINDOWS\system32\ativtmxx.dll
2010-08-22 00:35:10 ----N---- C:\WINDOWS\system32\ati3duag.dll
2010-08-22 00:35:10 ----N---- C:\WINDOWS\system32\ati3d1ag.dll
2010-08-22 00:35:10 ----N---- C:\WINDOWS\system32\ati2dvag.dll
2010-08-22 00:35:10 ----N---- C:\WINDOWS\system32\ati2dvaa.dll
2010-08-22 00:35:10 ----N---- C:\WINDOWS\system32\ati2cqag.dll
2010-08-22 00:35:10 ----N---- C:\WINDOWS\system32\aaclient.dll
2010-08-22 00:35:09 ----N---- C:\WINDOWS\system32\kbdbhc.dll
2010-08-22 00:35:09 ----N---- C:\WINDOWS\system32\hsfcisp2.dll
2010-08-22 00:35:09 ----N---- C:\WINDOWS\system32\eapsvc.dll
2010-08-22 00:35:09 ----N---- C:\WINDOWS\system32\eapqec.dll
2010-08-22 00:35:09 ----N---- C:\WINDOWS\system32\eappprxy.dll
2010-08-22 00:35:09 ----N---- C:\WINDOWS\system32\eapphost.dll
2010-08-22 00:35:09 ----N---- C:\WINDOWS\system32\eappgnui.dll
2010-08-22 00:35:09 ----N---- C:\WINDOWS\system32\eappcfg.dll
2010-08-22 00:35:09 ----N---- C:\WINDOWS\system32\eapp3hst.dll
2010-08-22 00:35:09 ----N---- C:\WINDOWS\system32\eapolqec.dll
2010-08-22 00:35:09 ----N---- C:\WINDOWS\system32\dot3ui.dll
2010-08-22 00:35:09 ----N---- C:\WINDOWS\system32\dot3svc.dll
2010-08-22 00:35:09 ----N---- C:\WINDOWS\system32\dot3msm.dll
2010-08-22 00:35:09 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
2010-08-22 00:35:09 ----N---- C:\WINDOWS\system32\dot3dlg.dll
2010-08-22 00:35:09 ----N---- C:\WINDOWS\system32\dot3cfg.dll
2010-08-22 00:35:09 ----N---- C:\WINDOWS\system32\dot3api.dll
2010-08-22 00:35:09 ----N---- C:\WINDOWS\system32\dimsroam.dll
2010-08-22 00:35:09 ----N---- C:\WINDOWS\system32\dimsntfy.dll
2010-08-22 00:35:09 ----N---- C:\WINDOWS\system32\dhcpqec.dll
2010-08-22 00:35:08 ----N---- C:\WINDOWS\system32\mtxparhd.dll
2010-08-22 00:35:08 ----N---- C:\WINDOWS\system32\msshavmsg.dll
2010-08-22 00:35:08 ----N---- C:\WINDOWS\system32\mssha.dll
2010-08-22 00:35:08 ----N---- C:\WINDOWS\system32\mmcperf.exe
2010-08-22 00:35:08 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll
2010-08-22 00:35:08 ----N---- C:\WINDOWS\system32\mmcex.dll
2010-08-22 00:35:08 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll
2010-08-22 00:35:08 ----N---- C:\WINDOWS\system32\mdmxsdk.dll
2010-08-22 00:35:08 ----N---- C:\WINDOWS\system32\l2gpstore.dll
2010-08-22 00:35:08 ----N---- C:\WINDOWS\system32\kmsvc.dll
2010-08-22 00:35:08 ----N---- C:\WINDOWS\system32\kbdpash.dll
2010-08-22 00:35:08 ----N---- C:\WINDOWS\system32\kbdnepr.dll
2010-08-22 00:35:08 ----N---- C:\WINDOWS\system32\kbdiultn.dll
2010-08-22 00:35:07 ----N---- C:\WINDOWS\system32\slserv.exe
2010-08-22 00:35:07 ----N---- C:\WINDOWS\system32\slrundll.exe
2010-08-22 00:35:07 ----N---- C:\WINDOWS\system32\slgen.dll
2010-08-22 00:35:07 ----N---- C:\WINDOWS\system32\slextspk.dll
2010-08-22 00:35:07 ----N---- C:\WINDOWS\system32\slcoinst.dll
2010-08-22 00:35:07 ----N---- C:\WINDOWS\system32\setupn.exe
2010-08-22 00:35:07 ----N---- C:\WINDOWS\system32\s3gnb.dll
2010-08-22 00:35:07 ----N---- C:\WINDOWS\system32\rhttpaa.dll
2010-08-22 00:35:07 ----N---- C:\WINDOWS\system32\rasqec.dll
2010-08-22 00:35:07 ----N---- C:\WINDOWS\system32\qutil.dll
2010-08-22 00:35:07 ----N---- C:\WINDOWS\system32\qcliprov.dll
2010-08-22 00:35:07 ----N---- C:\WINDOWS\system32\qagentrt.dll
2010-08-22 00:35:07 ----N---- C:\WINDOWS\system32\qagent.dll
2010-08-22 00:35:07 ----N---- C:\WINDOWS\system32\photometadatahandler.dll
2010-08-22 00:35:07 ----N---- C:\WINDOWS\system32\onex.dll
2010-08-22 00:35:07 ----N---- C:\WINDOWS\system32\napstat.exe
2010-08-22 00:35:07 ----N---- C:\WINDOWS\system32\napmontr.dll
2010-08-22 00:35:07 ----N---- C:\WINDOWS\system32\napipsec.dll
2010-08-22 00:35:06 ----N---- C:\WINDOWS\system32\wmphoto.dll
2010-08-22 00:35:06 ----N---- C:\WINDOWS\system32\wlanapi.dll
2010-08-22 00:35:06 ----N---- C:\WINDOWS\system32\windowscodecsext.dll
2010-08-22 00:35:06 ----N---- C:\WINDOWS\system32\windowscodecs.dll
2010-08-22 00:35:06 ----N---- C:\WINDOWS\system32\verclsid.exe
2010-08-22 00:35:06 ----N---- C:\WINDOWS\system32\tzchange.exe
2010-08-22 00:35:06 ----N---- C:\WINDOWS\system32\tspkg.dll
2010-08-22 00:35:06 ----N---- C:\WINDOWS\system32\tsgqec.dll
2010-08-22 00:35:05 ----N---- C:\WINDOWS\system32\xpsp3res.dll
2010-08-22 00:35:05 ----N---- C:\WINDOWS\system32\xmllite.dll
2010-08-22 00:35:05 ----N---- C:\WINDOWS\slrundll.exe
2010-08-22 00:35:05 ----D---- C:\WINDOWS\system32\scripting
2010-08-22 00:35:05 ----D---- C:\WINDOWS\system32\en-us
2010-08-22 00:35:05 ----D---- C:\WINDOWS\l2schemas
2010-08-22 00:35:04 ----D---- C:\WINDOWS\system32\en
2010-08-22 00:35:04 ----D---- C:\WINDOWS\system32\bits
2010-08-22 00:33:54 ----D---- C:\WINDOWS\ServicePackFiles
2010-08-22 00:32:24 ----N---- C:\WINDOWS\system32\drivers\adv11nt5.dll
2010-08-22 00:32:24 ----N---- C:\WINDOWS\system32\drivers\adv09nt5.dll
2010-08-22 00:32:24 ----N---- C:\WINDOWS\system32\drivers\adv08nt5.dll
2010-08-22 00:32:24 ----N---- C:\WINDOWS\system32\drivers\adv07nt5.dll
2010-08-22 00:32:24 ----N---- C:\WINDOWS\system32\drivers\adv05nt5.dll
2010-08-22 00:32:24 ----N---- C:\WINDOWS\system32\drivers\adv02nt5.dll
2010-08-22 00:32:24 ----N---- C:\WINDOWS\system32\drivers\adv01nt5.dll
2010-08-22 00:32:24 ----D---- C:\WINDOWS\network diagnostic
2010-08-22 00:32:23 ----N---- C:\WINDOWS\system32\drivers\atintuxx.sys
2010-08-22 00:32:23 ----N---- C:\WINDOWS\system32\drivers\atinttxx.sys
2010-08-22 00:32:23 ----N---- C:\WINDOWS\system32\drivers\atinsnxx.sys
2010-08-22 00:32:23 ----N---- C:\WINDOWS\system32\drivers\atinrvxx.sys
2010-08-22 00:32:23 ----N---- C:\WINDOWS\system32\drivers\atinraxx.sys
2010-08-22 00:32:23 ----N---- C:\WINDOWS\system32\drivers\atinpdxx.sys
2010-08-22 00:32:23 ----N---- C:\WINDOWS\system32\drivers\atinmdxx.sys
2010-08-22 00:32:23 ----N---- C:\WINDOWS\system32\drivers\atinbtxx.sys
2010-08-22 00:32:23 ----N---- C:\WINDOWS\system32\drivers\ati2mtag.sys
2010-08-22 00:32:23 ----N---- C:\WINDOWS\system32\drivers\ati2mtaa.sys
2010-08-22 00:32:23 ----N---- C:\WINDOWS\system32\drivers\ati1xsxx.sys
2010-08-22 00:32:23 ----N---- C:\WINDOWS\system32\drivers\ati1xbxx.sys
2010-08-22 00:32:23 ----N---- C:\WINDOWS\system32\drivers\ati1tuxx.sys
2010-08-22 00:32:23 ----N---- C:\WINDOWS\system32\drivers\ati1ttxx.sys
2010-08-22 00:32:23 ----N---- C:\WINDOWS\system32\drivers\ati1snxx.sys
2010-08-22 00:32:23 ----N---- C:\WINDOWS\system32\drivers\ati1rvxx.sys
2010-08-22 00:32:23 ----N---- C:\WINDOWS\system32\drivers\ati1raxx.sys
2010-08-22 00:32:23 ----N---- C:\WINDOWS\system32\drivers\ati1pdxx.sys
2010-08-22 00:32:23 ----N---- C:\WINDOWS\system32\drivers\ati1mdxx.sys
2010-08-22 00:32:23 ----N---- C:\WINDOWS\system32\drivers\ati1btxx.sys
2010-08-22 00:32:22 ----N---- C:\WINDOWS\system32\drivers\hsfcxts2.sys
2010-08-22 00:32:22 ----N---- C:\WINDOWS\system32\drivers\hsfbs2s2.sys
2010-08-22 00:32:22 ----N---- C:\WINDOWS\system32\drivers\hidir.sys
2010-08-22 00:32:22 ----N---- C:\WINDOWS\system32\drivers\hidbth.sys
2010-08-22 00:32:22 ----N---- C:\WINDOWS\system32\drivers\hdaudbus.sys
2010-08-22 00:32:22 ----N---- C:\WINDOWS\system32\drivers\gagp30kx.sys
2010-08-22 00:32:22 ----N---- C:\WINDOWS\system32\drivers\ch7xxnt5.dll
2010-08-22 00:32:22 ----N---- C:\WINDOWS\system32\drivers\bthusb.sys
2010-08-22 00:32:22 ----N---- C:\WINDOWS\system32\drivers\bthprint.sys
2010-08-22 00:32:22 ----N---- C:\WINDOWS\system32\drivers\bthport.sys
2010-08-22 00:32:22 ----N---- C:\WINDOWS\system32\drivers\bthpan.sys
2010-08-22 00:32:22 ----N---- C:\WINDOWS\system32\drivers\bthmodem.sys
2010-08-22 00:32:22 ----N---- C:\WINDOWS\system32\drivers\bthenum.sys
2010-08-22 00:32:22 ----N---- C:\WINDOWS\system32\drivers\atv10nt5.dll
2010-08-22 00:32:22 ----N---- C:\WINDOWS\system32\drivers\atv06nt5.dll
2010-08-22 00:32:22 ----N---- C:\WINDOWS\system32\drivers\atv04nt5.dll
2010-08-22 00:32:22 ----N---- C:\WINDOWS\system32\drivers\atv02nt5.dll
2010-08-22 00:32:22 ----N---- C:\WINDOWS\system32\drivers\atv01nt5.dll
2010-08-22 00:32:22 ----N---- C:\WINDOWS\system32\drivers\atinxsxx.sys
2010-08-22 00:32:22 ----N---- C:\WINDOWS\system32\drivers\atinxbxx.sys
2010-08-22 00:32:21 ----N---- C:\WINDOWS\system32\drivers\sffp_mmc.sys
2010-08-22 00:32:21 ----N---- C:\WINDOWS\system32\drivers\s3gnbm.sys
2010-08-22 00:32:21 ----N---- C:\WINDOWS\system32\drivers\rndismpx.sys
2010-08-22 00:32:21 ----N---- C:\WINDOWS\system32\drivers\rfcomm.sys
2010-08-22 00:32:21 ----N---- C:\WINDOWS\system32\drivers\recagent.sys
2010-08-22 00:32:21 ----N---- C:\WINDOWS\system32\drivers\ntmtlfax.sys
2010-08-22 00:32:21 ----N---- C:\WINDOWS\system32\drivers\mutohpen.sys
2010-08-22 00:32:21 ----N---- C:\WINDOWS\system32\drivers\mtxparhm.sys
2010-08-22 00:32:21 ----N---- C:\WINDOWS\system32\drivers\mtlstrm.sys
2010-08-22 00:32:21 ----N---- C:\WINDOWS\system32\drivers\mtlmnt5.sys
2010-08-22 00:32:21 ----N---- C:\WINDOWS\system32\drivers\mdmxsdk.sys
2010-08-22 00:32:21 ----N---- C:\WINDOWS\system32\drivers\hsfdpsp2.sys
2010-08-22 00:32:20 ----N---- C:\WINDOWS\system32\drivers\watv10nt.sys
2010-08-22 00:32:20 ----N---- C:\WINDOWS\system32\drivers\watv06nt.sys
2010-08-22 00:32:20 ----N---- C:\WINDOWS\system32\drivers\wadv11nt.sys
2010-08-22 00:32:20 ----N---- C:\WINDOWS\system32\drivers\wadv09nt.sys
2010-08-22 00:32:20 ----N---- C:\WINDOWS\system32\drivers\wadv08nt.sys
2010-08-22 00:32:20 ----N---- C:\WINDOWS\system32\drivers\wadv07nt.sys
2010-08-22 00:32:20 ----N---- C:\WINDOWS\system32\drivers\wacompen.sys
2010-08-22 00:32:20 ----N---- C:\WINDOWS\system32\drivers\vchnt5.dll
2010-08-22 00:32:20 ----N---- C:\WINDOWS\system32\drivers\usbvideo.sys
2010-08-22 00:32:20 ----N---- C:\WINDOWS\system32\drivers\usb8023x.sys
2010-08-22 00:32:20 ----N---- C:\WINDOWS\system32\drivers\uagp35.sys
2010-08-22 00:32:20 ----N---- C:\WINDOWS\system32\drivers\smbali.sys
2010-08-22 00:32:20 ----N---- C:\WINDOWS\system32\drivers\slwdmsup.sys
2010-08-22 00:32:20 ----N---- C:\WINDOWS\system32\drivers\slnthal.sys
2010-08-22 00:32:20 ----N---- C:\WINDOWS\system32\drivers\slntamr.sys
2010-08-22 00:32:20 ----N---- C:\WINDOWS\system32\drivers\slnt7554.sys
2010-08-22 00:32:20 ----N---- C:\WINDOWS\system32\drivers\siint5.dll
2010-08-22 00:31:14 ----A---- C:\WINDOWS\002715_.tmp
2010-08-22 00:31:03 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-08-22 00:29:19 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2010-08-22 00:29:17 ----D---- C:\WINDOWS\EHome
2010-08-22 00:24:02 ----ASH---- C:\pagefile.sys
2010-08-22 00:19:46 ----A---- C:\WINDOWS\BcdLog.txt
2010-08-22 00:18:17 ----A---- C:\WINDOWS\system32\setupempdrv03.exe
2010-08-22 00:18:17 ----A---- C:\WINDOWS\system32\EuGdiDrv.sys
2010-08-22 00:18:17 ----A---- C:\WINDOWS\system32\EuEpmGdi.dll
2010-08-22 00:18:17 ----A---- C:\WINDOWS\system32\epmntdrv.sys
2010-08-22 00:18:17 ----A---- C:\WINDOWS\system32\BootMan.exe
2010-08-22 00:18:11 ----D---- C:\Program Files\EASEUS
2010-08-22 00:17:40 ----D---- C:\Documents and Settings\All Users\Application Data\Privacyware
2010-08-22 00:17:40 ----A---- C:\WINDOWS\ODBC.INI
2010-08-22 00:17:39 ----D---- C:\Program Files\Privacyware
2010-08-22 00:16:05 ----D---- C:\Documents and Settings\Bracegirdle\Application Data\Macromedia
2010-08-22 00:16:05 ----D---- C:\Documents and Settings\Bracegirdle\Application Data\Adobe
2010-08-21 23:56:46 ----D---- C:\WINDOWS\Downloaded Installations
2010-08-21 23:54:48 ----A---- C:\WINDOWS\system32\TweakUI.exe
2010-08-21 23:53:15 ----D---- C:\Documents and Settings\Bracegirdle\Application Data\Mozilla
2010-08-21 23:53:07 ----D---- C:\Program Files\Mozilla Firefox
2010-08-21 23:47:05 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2010-08-10 16:11:50 ----A---- C:\WINDOWS\system32\drivers\pwipf6.sys

======List of files/folders modified in the last 1 months======

2010-08-23 14:32:50 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-08-23 13:58:46 ----D---- C:\WINDOWS\system32\CatRoot
2010-08-23 13:56:58 ----HD---- C:\WINDOWS\inf
2010-08-23 13:56:58 ----D---- C:\WINDOWS
2010-08-23 13:56:57 ----D---- C:\WINDOWS\system32
2010-08-23 13:50:52 ----D---- C:\WINDOWS\Temp
2010-08-23 13:50:14 ----D---- C:\WINDOWS\system32\CatRoot2
2010-08-23 13:49:55 ----D---- C:\WINDOWS\Help
2010-08-23 13:49:55 ----D---- C:\Program Files\Internet Explorer
2010-08-23 13:49:13 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-08-23 13:42:50 ----A---- C:\WINDOWS\imsins.BAK
2010-08-23 13:42:02 ----D---- C:\WINDOWS\system32\config
2010-08-23 13:41:49 ----D---- C:\WINDOWS\Media
2010-08-23 13:03:56 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-08-23 12:59:35 ----D---- C:\WINDOWS\system32\wbem
2010-08-23 12:52:31 ----RD---- C:\Program Files
2010-08-23 12:33:11 ----D---- C:\WINDOWS\system32\drivers\etc
2010-08-23 12:20:25 ----SHD---- C:\WINDOWS\Installer
2010-08-23 12:16:17 ----D---- C:\WINDOWS\system32\drivers
2010-08-23 12:10:09 ----D---- C:\WINDOWS\AppPatch
2010-08-23 11:51:38 ----D---- C:\Program Files\Messenger
2010-08-23 11:51:11 ----D---- C:\WINDOWS\WinSxS
2010-08-23 11:47:06 ----D---- C:\WINDOWS\Debug
2010-08-23 11:46:21 ----D---- C:\Program Files\Outlook Express
2010-08-23 11:18:19 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-08-23 03:01:43 ----D---- C:\Program Files\Movie Maker
2010-08-22 21:40:08 ----D---- C:\Program Files\Online Services
2010-08-22 21:36:08 ----D---- C:\WINDOWS\Registration
2010-08-22 08:19:50 ----D---- C:\WINDOWS\twain_32
2010-08-22 08:11:26 ----A---- C:\WINDOWS\OEWABLog.txt
2010-08-22 08:10:58 ----A---- C:\WINDOWS\setuplog.txt
2010-08-22 08:10:30 ----D---- C:\WINDOWS\system32\Setup
2010-08-22 08:10:28 ----RSD---- C:\WINDOWS\Fonts
2010-08-22 08:09:50 ----D---- C:\WINDOWS\security
2010-08-22 01:39:50 ----D---- C:\Program Files\Common Files
2010-08-22 01:00:19 ----D---- C:\Documents and Settings
2010-08-22 00:57:10 ----A---- C:\WINDOWS\system.ini
2010-08-22 00:55:43 ----D---- C:\WINDOWS\OPTIONS
2010-08-22 00:50:34 ----RSH---- C:\boot.ini
2010-08-22 00:50:27 ----D---- C:\Program Files\Common Files\Services
2010-08-22 00:48:55 ----D---- C:\WINDOWS\system32\ras
2010-08-22 00:48:31 ----D---- C:\WINDOWS\system32\icsxml
2010-08-22 00:48:30 ----D---- C:\WINDOWS\system32\ias
2010-08-22 00:47:03 ----D---- C:\WINDOWS\system32\1033
2010-08-22 00:46:56 ----RD---- C:\WINDOWS\Web
2010-08-22 00:46:42 ----D---- C:\WINDOWS\Cursors
2010-08-22 00:42:32 ----SD---- C:\WINDOWS\Tasks
2010-08-22 00:42:31 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-08-22 00:42:31 ----RD---- C:\WINDOWS\Offline Web Pages
2010-08-22 00:42:27 ----D---- C:\WINDOWS\system32\MsDtc
2010-08-22 00:35:18 ----D---- C:\Program Files\Windows Media Player
2010-08-22 00:35:11 ----D---- C:\WINDOWS\ime
2010-08-22 00:35:05 ----D---- C:\WINDOWS\system32\usmt
2010-08-22 00:35:04 ----D---- C:\WINDOWS\PeerNet
2010-08-22 00:33:51 ----D---- C:\WINDOWS\system32\Restore
2010-08-22 00:33:51 ----D---- C:\WINDOWS\system32\npp
2010-08-22 00:33:50 ----D---- C:\WINDOWS\msagent
2010-08-22 00:33:49 ----D---- C:\WINDOWS\srchasst
2010-08-22 00:33:49 ----D---- C:\Program Files\NetMeeting
2010-08-22 00:33:48 ----D---- C:\WINDOWS\system32\Com
2010-08-22 00:33:46 ----D---- C:\Program Files\Windows NT
2010-08-22 00:33:44 ----D---- C:\Program Files\Common Files\System
2010-08-22 00:33:28 ----D---- C:\WINDOWS\system32\oobe
2010-08-22 00:33:26 ----D---- C:\WINDOWS\system
2010-08-21 23:47:28 ----D---- C:\WINDOWS\SoftwareDistribution

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 agp440;Intel AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\agp440.sys [2008-04-14 42368]
R0 agpCPQ;Compaq AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\agpCPQ.sys [2008-04-14 44928]
R0 alim1541;ALI AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\alim1541.sys [2008-04-14 42752]
R0 amdagp;AMD AGP Bus Filter Driver; C:\WINDOWS\system32\DRIVERS\amdagp.sys [2008-04-14 43008]
R0 cbidf;cbidf; C:\WINDOWS\system32\DRIVERS\cbidf2k.sys [2004-08-04 13952]
R0 ohci1394;OHCI Compliant IEEE 1394 Host Controller; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-14 61696]
R0 sisagp;SIS AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\sisagp.sys [2008-04-14 40960]
R0 viaagp;VIA AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\viaagp.sys [2008-04-14 42240]
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2010-03-01 124784]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 36352]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 pwipf6;pwipf6; C:\WINDOWS\system32\drivers\pwipf6.sys [2010-08-10 119112]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2010-02-16 60936]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-03-19 23400]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 Netaapl;Apple Mobile Device Ethernet Service; C:\WINDOWS\system32\DRIVERS\netaapl.sys [2009-07-09 17408]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
R3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2009-07-09 39424]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
R3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
S1 P3;Intel PentiumIII Processor Driver; C:\WINDOWS\system32\DRIVERS\p3.sys [2008-04-14 42752]
S3 epmntdrv;epmntdrv; \??\C:\WINDOWS\system32\epmntdrv.sys []
S3 EuGdiDrv;EuGdiDrv; \??\C:\WINDOWS\system32\EuGdiDrv.sys []
S3 mxnic;Macronix MX987xx Family Fast Ethernet NT Driver; C:\WINDOWS\system32\DRIVERS\mxnic.sys [2001-08-17 19968]
S3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-03 1897408]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2010-02-24 135336]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2010-04-01 267432]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-07-09 144712]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 PFNet;Privacyware network service; C:\Program Files\Privacyware\Privatefirewall 7.0\pfsvc.exe [2010-08-16 356992]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-07-13 542496]
S2 FileChecker;FileChecker; C:\Program Files\FileChecker\filechecker.exe [2002-09-18 286720]

-----------------EOF-----------------


#5 spot2112

spot2112
  • Topic Starter

  • Members
  • 86 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:33 PM

Posted 23 August 2010 - 09:35 PM

A post.

Attached Files



#6 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:02:33 PM

Posted 26 August 2010 - 06:24 PM

Since you said that Spybot identified the W32/Agobot-KU which is an IRC backdoor Trojan and network worm which establishes an IRC channel to a remote server in order to grant an intruder access to the compromised computer, I need to give you this warning. I understood that the agobot was identified in your latest configuration of your computer. Try not to transfer any .exe files to a new configuration. A clean install is the best way to go which means you will have to download and reinstall your programs. I am trying to understand where you are. The only item that needed to fixed in HijackThis log is O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file). I did not see any obvious signs of malware.

IMPORTANT NOTE: Rootkits, backdoor Trojans, Botnets, and IRCBots are very dangerous because they use advanced techniques (backdoors) as a means of accessing a computer system that bypasses security mechanisms and steal sensitive information which they send back to the hacker. Many rootkits can hook into the Windows 32-bit kernel, and patch several APIs to hide new registry keys and files they install. Remote attackers use backdoor Trojans and rootkits as part of an exploit to gain unauthorized access to a computer and take control of it without your knowledge.

If your computer was used for online banking, has credit card information or other sensitive data on it, you should immediately disconnect from the Internet until your system is cleaned. All passwords should be changed immediately to include those used for banking, email, eBay, paypal and online forums. You should consider them to be compromised. You should change each password by using a different computer and not the infected one. If not, an attacker may get the new passwords and transaction information. If using a router, you need to reset it with a strong logon/password so the malware cannot gain control before connecting again. Banking and credit card institutions should be notified of the possible security breach. Because your computer was compromised, please read How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

Although the rootkit has been identified and may be removed, your computer has likely been compromised and there is no way to be sure the computer can ever be trusted again. It is dangerous and incorrect to assume that because this malware has been removed, the computer is secure. In some instances, an infection may have caused so much damage to your system that it cannot be completely cleaned or repaired. Some infections are difficult to remove completely because of their morphing characteristics which allows the malware to regenerate itself. Sometimes there is another hidden piece of malware which has not been detected by your security tools that protects malicious files and registry keys (which have been detected) so they cannot be permanently deleted. The malware may leave so many remnants behind that security tools cannot find them. Most experts in the security community believe that once infected with this type of malware, the best course of action is to wipe the drive clean, reformat and reinstall the OS. Please read:
When should I re-format? How should I reinstall?
Help: I Got Hacked. Now What Do I Do?
Where to draw the line? When to recommend a format and reinstall?

I strongly recommend that you reformat your computer. Even if we were able to clean the computer of some of the infections, your computer is not trustworthy and the removal of all affected files may not be successful. Tell me what you want to do.

You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.

#7 spot2112

spot2112
  • Topic Starter

  • Members
  • 86 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:33 PM

Posted 27 August 2010 - 10:42 PM

It probably got lost in all the text, but I actually just wiped the internal drive and reinstalled from the OEM disk.

I installed SP3 from an ISO I had previously burned to DVD at a time when I believe my system was clean, July 16. I had just reinstalled the day before.

I probably would have closed this thread by now, except the Spybot keeps

I'd like to try for now to evaluate the physical disk the system drive is on, my internal hard drive. Here is some of the info from my last post that may have gotten lost...

Just this week wiped the drive absolutely clean...I used my UBCD4W 3.6 boot CD to write windows "PE" to RAM and then used an app on that disk - i forget which one - to write zeros over the whole disk. I then used another program on that disk to wipe the mbr with zeros.

Then I installed clean windows XP SP2 to the system drive. So I had a clean drive - I think.

I re-established my internet connection by (before wiping windows off the disk) wiping a thumb drive, then immediately downloading iTunes821.exe and ExactFiles_Setup.exe to the thumb drive and pulled it out of the socket as soon as the downloads were complete. So I can't guarantee you that they were clean, because they had to pass through the compromised system as they were downloaded.

But I checked the files for viruses and calculated their hashes at VirusTotal before I downloaded, then checked their hashes again once on the thumb drive (right before I pulled it out of the socket), and then checked the hashes again when I copied from the thumb drive to the clean system drive. They matched every time.

So I really think they were clean. But who can say, right?

Those were the only two files that had any possibility of being corrupted, as far as I know.

Before wiping the drive I printed off file lists so I could go back and down load clean copies. That is the only place I have been getting files from, is so-called "certified spyware free" DL's from places like CNET and Softpedia, or else I have checked the url and downloaded files at VirusTotal if getting it from a less well-known site.


Once I had my internet connection re-established, I used IE6 to download Firefox 3.6.8 (including some trusted addons for improving download speed and managing ads) and Privacyware Personal Firewall 7.0. Then I used Firefox to download SpywareBlaster and Spywareguard (per the tutorial on bleepingcomputer.com), Spybot S&D, and Avira anti-virus, all in that order. Then I finished updating windows, including updating to IE7. I do not want to go to IE8.

I installed some other utilities (filealyzer, regalyzer, runalyzer, filechecker, start up monitor, startup control panel, etc. (those last two I have used for years and never had a problem, the others are relatively new to me)etc.)

I have updated to the newest version of Java.

Below is the multi-entry information list from Spybot's startup tool...


Current filename:

Database status: Not required - virus, spyware, malware or other resource hog
Value:
Filename: system32.exe

Description
Added by the _AGOBOT-KU_ WORM! Note - has a blank entry under the Startup Item/Name field

Source: Paul Collins Startup list
____________________

Current filename:

Database status: Not required - virus, spyware, malware or other resource hog
Value:
Filename: pathex.exe

Description
Added by the _MKMOOSE-A_ WORM! Note - has a blank entry under the Startup Item/Name field

Source: Paul Collins Startup list
____________________

Current filename:

Database status: Not required - virus, spyware, malware or other resource hog
Value:
Filename: svchost.exe

Description
Added by the _DELF-UX_ TROJAN! Note - this is not the legitimate _svchost.exe_ process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%. Note - has a blank entry under the Startup Item/Name field

Source: Paul Collins Startup list
____________________

Current filename:

Database status: Not required - virus, spyware, malware or other resource hog
Value:
Filename: MSPF.EXE

Description
Added by a variant of the _SDBOT_ WORM! This file is located in the Winnt or Windows folder. Note - has a blank entry under the Startup Item/Name field

Source: Paul Collins Startup list
____________________

Current filename:

Database status: Not required - virus, spyware, malware or other resource hog
Value:
Filename: dllvirtual.exe

Description
Added by the _DADOBRA-IW_ TROJAN! Note - has a blank entry under the Startup Item/Name field

Source: Paul Collins Startup list
____________________

Current filename:

Database status: Not required - virus, spyware, malware or other resource hog
Value:
Filename: dllvirtual.dll

Description
Added by the _DADOBRA-IW_ TROJAN! Note - has a blank entry under the Startup Item/Name field

Source: Paul Collins Startup list
____________________

Current filename:

Database status: Not required - virus, spyware, malware or other resource hog
Value:
Filename: dllvirtual.js

Description
Added by the _DADOBRA-IW_ TROJAN! Note - has a blank entry under the Startup Item/Name field

Source: Paul Collins Startup list
____________________

Current filename:

Database status: Not required - virus, spyware, malware or other resource hog
Value:
Filename: ajsha5.exe

Description
Added by the _SPYBOT-NX_ WORM! Note - has a blank entry under the Startup Item/Name field

Source: Paul Collins Startup list
____________________

Current filename:

Database status: Not required - virus, spyware, malware or other resource hog
Value:
Filename: ne.exe

Description
Added by the _IRCBOT-ZL_ TROJAN! Note - has a blank entry under the Startup Item/Name field

Source: Paul Collins Startup list
____________________

Current filename:

Database status: Not required - virus, spyware, malware or other resource hog
Value:
Filename: iexpl0re.exe

Description
Added by the _RBOT-SD_ WORM! Note - has a blank entry under the Startup Item/Name field

Source: Paul Collins Startup list
____________________

Current filename:

Database status: Not required - virus, spyware, malware or other resource hog
Value:
Filename: gbpm.exe

Description
Added by the _DLOADR.ZZD_ WORM! Note - has a blank entry under the Startup Item/Name field

Source: Paul Collins Startup list
____________________



#8 spot2112

spot2112
  • Topic Starter

  • Members
  • 86 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:33 PM

Posted 27 August 2010 - 10:47 PM

If I'm clean, I need help cleaning a non system external hard drive. It has tons of text and jpg files that I need for my attorney (the text files...the jpgs I want are of my son smile.gif )

#9 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:02:33 PM

Posted 30 August 2010 - 11:46 AM

I am not sure what happened but Spybot indicates your computer is seriously infected.

Current filename:

Database status: Not required - virus, spyware, malware or other resource hog
Value:
Filename: svchost.exe

Description
Added by the _DELF-UX_ TROJAN! Note - this is not the legitimate _svchost.exe_ process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%. Note - has a blank entry under the Startup Item/Name field

Current filename:

Database status: Not required - virus, spyware, malware or other resource hog
Value:
Filename: ne.exe

Description
Added by the _IRCBOT-ZL_ TROJAN! Note - has a blank entry under the Startup Item/Name field

Current filename:

Database status: Not required - virus, spyware, malware or other resource hog
Value:
Filename: iexpl0re.exe

Description
Added by the _RBOT-SD_ WORM! Note - has a blank entry under the Startup Item/Name field


Unfortunately, one or more of the identified infections is a Rootkit/backdoor trojan.

IMPORTANT NOTE: Rootkits, backdoor Trojans, Botnets, and IRCBots are very dangerous because they use advanced techniques (backdoors) as a means of accessing a computer system that bypasses security mechanisms and steal sensitive information which they send back to the hacker. Many rootkits can hook into the Windows 32-bit kernel, and patch several APIs to hide new registry keys and files they install. Remote attackers use backdoor Trojans and rootkits as part of an exploit to gain unauthorized access to a computer and take control of it without your knowledge.

If your computer was used for online banking, has credit card information or other sensitive data on it, you should immediately disconnect from the Internet until your system is cleaned. All passwords should be changed immediately to include those used for banking, email, eBay, paypal and online forums. You should consider them to be compromised. You should change each password by using a different computer and not the infected one. If not, an attacker may get the new passwords and transaction information. If using a router, you need to reset it with a strong logon/password so the malware cannot gain control before connecting again. Banking and credit card institutions should be notified of the possible security breach. Because your computer was compromised, please read How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

Although the rootkit has been identified and may be removed, your computer has likely been compromised and there is no way to be sure the computer can ever be trusted again. It is dangerous and incorrect to assume that because this malware has been removed, the computer is secure. In some instances, an infection may have caused so much damage to your system that it cannot be completely cleaned or repaired. Some infections are difficult to remove completely because of their morphing characteristics which allows the malware to regenerate itself. Sometimes there is another hidden piece of malware which has not been detected by your security tools that protects malicious files and registry keys (which have been detected) so they cannot be permanently deleted. The malware may leave so many remnants behind that security tools cannot find them. Most experts in the security community believe that once infected with this type of malware, the best course of action is to wipe the drive clean, reformat and reinstall the OS. Please read:
When should I re-format? How should I reinstall?
Help: I Got Hacked. Now What Do I Do?
Where to draw the line? When to recommend a format and reinstall?

If you decide to reformat, you can back up all your important documents, personal data files, photos to a CD or DVD drive, not a flash drive or external hard drive as they may become compromised in the process. The safest practice is not to backup any executable files (*.exe), screensavers (*.scr), autorun (.ini) or script files (.php, .asp, and .html) files because they may be infected by malware. Avoid backing up compressed files (.zip, .cab, .rar) that have executable files inside them as some types of malware can penetrate and infect .exe files within compressed files too. Other types of malware may even disguise itself by adding and hiding its extension to the existing extension of file(s) so be sure you look closely at the full file name. After reformatting, scan the backed up data with your anti-virus prior to to copying it back to your hard drive.
I strongly recommend that you reformat your computer. Even if we were able to clean the computer of some of the infections, your computer is not trustworthy and the removal of all affected files may not be successful.

Edited by suebaby41, 30 August 2010 - 11:48 AM.

You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.

#10 spot2112

spot2112
  • Topic Starter

  • Members
  • 86 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:33 PM

Posted 30 August 2010 - 09:22 PM

Suebaby...

Those are just the entries listed in the "more information" sidebar in spybot's startup tool, accessed by clicking tools on the advanced UI. Spybot has never alerted for any of those, it just says I have a single startup entry that was wrtten by them. Its the same entry I mentioned in my first post.

Last night I deleted all the files from drive, then did a simple erase. I deleted the partitions and wiped the MBR, as before. Then, from the RAM drive, I looked at the sectors with disk investigator. There were many, many sectors with code apparently written in the free space.

Most of what I could read just skimming through was dealing with advapi.dll and terminal services. There was also a lot of entries that looked like data for dialers. I saved a bunch of the code to my external drive. Unfortunately, it won't do us any good.

I did "diskpart clear all" from the command line, then reinstalled from the oem dvd-rom. At setup everything went normally. When I logged on the first time, about a half second after I clicked enter, it said it was shutting down. It then rebooted. This time the logon (xp welcome screen) screen was different in small but noticeable ways.

Before I got done setting passwords, disabling unneeded services, etc., things were already going wrong. It may be that I just inadvertantly shutdown the wrong service or it may be that something managed to survive reboot from the clear operation. I have no idea.

At this particular moment, I have just finished a second reinstall today, and am about to log on. I'll be back in a few to let you know what happens. Wish me luck!

Edited by spot2112, 30 August 2010 - 09:30 PM.


#11 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:02:33 PM

Posted 31 August 2010 - 08:04 AM

Good luck!
You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.

#12 spot2112

spot2112
  • Topic Starter

  • Members
  • 86 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:33 PM

Posted 31 August 2010 - 10:34 PM

Suebaby,

I have XP installed from the OEM dvd as described, but am not online. There is no personal data on my machine at this time, so we have a "safe" platform for counter-hacking. Or maybe it would be more accurate to say unhacking?

i am convinced there is an "entity" hiding on my platters. Whatever is on my physical drive must be well-written. I hope we can ID it, as I think it is fascinating.

Can you help me clean my drive, get secure net service, and then figure out a strategy for me to recover my critical legal docs and precious pics of my son?

I think last time there was something waiting for me to come back online and sent me some nice little packets of joy before I could install a decent firewall or patch windows. Is that even possible? Is there a way to see if this is something that has written itself into my bios?



NIST guidance for securing XP home edition.

#13 spot2112

spot2112
  • Topic Starter

  • Members
  • 86 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:33 PM

Posted 31 August 2010 - 10:40 PM

Suebaby,

I have XP installed from the OEM dvd as described, but am not online. There is no personal data on my machine at this time, so we have a "safe" platform for counter-hacking. Or maybe it would be more accurate to say unhacking?

i am convinced there is an "entity" hiding on my platters. Whatever is on my physical drive must be well-written. I hope we can ID it, as I think it is fascinating.

Can you help me clean my drive, get secure net service, and then figure out a strategy for me to recover my critical legal docs and precious pics of my son?

I think last time there was something waiting for me to come back online and sent me some nice little packets of joy before I could install a decent firewall or patch windows. Is that even possible? Is there a way to see if this is something that has written itself into my bios?

On a side note, I came across a techical checklist for XP Home edition users. It was published by NIST. it gives lots of information about how to harden home edition. I think it was written for SP2, but supposedly they were going to keep it up-to-date. Anyway, the link is below if you care to check it out. I didnt see anything about what kind of links we could post, so hopefully its okay.

Pleas let me know how to procede.

Thanks,

Gary

NIST guidance for securing XP home edition.

#14 spot2112

spot2112
  • Topic Starter

  • Members
  • 86 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:33 PM

Posted 31 August 2010 - 11:20 PM

Okay, here's the score so far...after a day osittin idle with no net connection, I cannot access event logs, but I can see events. I can also set counters for alerts but not traces or countes, apparently.

Okay, here's the score so far...after a day osittin idle with no net connection, I cannot access event logs, but I can see events. I can also set counters for alerts but not traces or countes, apparently.

RPC is affected severely.

#15 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:02:33 PM

Posted 02 September 2010 - 01:43 PM

Please post your question(s) regarding RPC and connectivity in BleepingComputer's Computer Forum, Windows XP Home and Professional, where the computer experts may help you. My expertise is dealing with malware and I prefer that you get the help of computer expert(s) in answering your question(s) and/or solving your problem(s). Please include a link to this thread so that the computer experts may see what we have done.
You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users